Privacy Policy
1. Data Controller
Controller: Michael Murr. Contact: contact@michaelmurr.de
2. What Data We Collect
Input data: Dimensions, wood types, project names, and cut lists are processed locally on your device.
Feedback & Suggestions: If you use the feedback feature, your suggestions and votes are transmitted to our server. A pseudonymous Device ID is sent to prevent abuse and duplicate voting. The Device ID on its own is not linked to your identity; however, if you additionally provide an email address, the email address and Device ID are transmitted in the same request.
Technical data: We use Google Firebase Analytics for pseudonymized analysis of app usage and Google Firebase Crashlytics to collect crash reports. See section 5 for details. When the app starts, a basic launch event is also sent to Expo (EAS Insights). See section 6 for details.
Website analytics: With your consent, we use Google Analytics 4 for website analytics. We also use self-hosted Pathlight for privacy-preserving reach measurement and count download redirects without browser identifiers as described in sections 3 and 4.
3. Hosting and Server Log Files
This website is hosted on servers operated by netcup GmbH, Daimlerstrasse 25, 76185 Karlsruhe, Germany. The hosting processing described in this section takes place in Germany. We have concluded a data processing agreement (DPA) with netcup GmbH in accordance with Art. 28 GDPR.
When you visit this website, the hosting provider automatically records server log files, which may include:
- IP address of the requesting device
- Date and time of the request
- Name and URL of the requested file
- Browser type and version
- Operating system of the requesting device
- Referrer URL (previously visited page)
Collecting this data is technically necessary to deliver the website and ensure its security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest). The data is deleted after at most 30 days.
4. Cookies, Website Analytics, and Download Redirect Counting
We use Google Analytics 4 only after you explicitly allow analytics in the consent dialog. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. If you decline, the Google tag is not loaded and no analytics request is sent to Google.
If you consent, Google Analytics may set cookies such as _ga and process a pseudonymous client ID, page URL and title, referrer, campaign parameters, browser and device information, approximate location, and technical connection data. We use this data to understand which pages and campaigns lead visitors to the store buttons. We do not send a user ID. Advertising storage, advertising user data, advertising personalization, Google Signals, and advertising personalization signals remain disabled in our tag configuration.
The legal basis for Google Analytics is your consent under Art. 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. We store your choice in local storage under sawmill_analytics_consent_v1. You can change or withdraw it at any time using “Analytics settings” in the footer. Withdrawing consent stops further collection and removes the Google Analytics cookies that are accessible to this website. It does not affect processing that occurred before the withdrawal.
Google may process data outside the European Economic Area, including in the United States. Google states in its data transfer information that it relies on the EU-US Data Privacy Framework in applicable cases and on Standard Contractual Clauses where required. Further information is available in Google's privacy policy. User and event data retention in the GA4 property must be set to the shortest available period, currently two months, before this integration is enabled. Aggregated reports may be retained for longer.
Independently of Google Analytics, we use our self-hosted service Pathlight for reach measurement and technical diagnostics. It records page views and /download redirects without cookies, local storage, session storage, IndexedDB, persistent visitor IDs, fingerprinting, or cross-site tracking. Pathlight stores normalized paths and campaign fields, referrer domains, coarse device, browser, and operating-system categories, country, bot status, and a daily rotating HMAC-based visitor estimate. The collector processes connection data such as the IP address transiently to derive that estimate, but does not store the raw IP address. The browser sends these events only to this website, and the Pathlight API key is never exposed to it.
The legal basis for Pathlight is Art. 6(1)(f) GDPR. Our legitimate interests are measuring aggregate reach, checking that store links work, and diagnosing technical problems without creating cross-site visitor profiles. Pathlight is independent of the Google Analytics consent choice and uses no consent cookie. Raw events are deleted according to the Pathlight site retention setting, up to 365 days; aggregated reports may be retained longer. This processing is subject to the documented legitimate- interest assessment and the safeguards described above.
Independently of Google Analytics, the /download route records one server-side redirect event. It contains only the UTC date, destination (App Store, Google Play, or website), platform category (iOS, Android, or other), and normalized source, medium, campaign, and content values. It does not store IP addresses, referrer URLs, raw user agents, cookies, persistent identifiers, or click IDs. The daily files are stored on our server in Germany and automatically deleted after 90 days.
The legal basis for this identifier-free redirect count is Art. 6(1)(f) GDPR. Our legitimate interest is checking that store links work and comparing aggregate campaign performance without creating visitor profiles. This count runs whether you allow or decline Google Analytics.
5. Firebase Analytics and Crashlytics
We use the services “Firebase Analytics” and “Firebase Crashlytics” by Google in our app. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Firebase Analytics:
Firebase Analytics collects pseudonymized usage data to help us understand how the app is used and to improve it. Data collected includes: app opens, screen views, session duration, device model, operating system version, app version, language, country/region, and a pseudonymized app instance ID. No personal data such as name, email address, or precise location is collected.
Firebase Crashlytics:
Firebase Crashlytics collects crash reports so we can find and fix errors in the app. When a crash or serious error occurs, the following is transmitted, among other things: the technical error report (stack trace), device model, operating system version, app version, the device state at the time of the crash (e.g. free memory), and a pseudonymized installation ID. The contents of your projects (measurements, customers, cut lists) are not part of crash reports.
Legal basis:
Processing is based on our legitimate interest in the stability, security, and improvement of our app pursuant to Art. 6(1)(f) GDPR. Our legitimate interest lies in providing a reliable and user-friendly app.
Data transfer to a third country:
Google may process data on servers in the United States. For transfers to the USA, Google relies on the adequacy decision of the European Commission (EU-US Data Privacy Framework) as well as EU Standard Contractual Clauses. For more information, see Google's privacy policy and Firebase privacy information.
Right to object / Opt-out:
You can disable the collection of analytics data and crash reports together at any time in the app settings. Once disabled, no further analytics data or crash reports are sent to Firebase.
6. App Launch Statistics via Expo (EAS Insights)
We use the service “EAS Insights” in our app to obtain basic, aggregated usage statistics, for example how many devices open the app and which app versions are in use. The provider of this service is Expo (650 Industries, Inc.), USA.
Processed data:
Each time the app starts, a single event is transmitted to Expo. It contains: the event type (app launch), a randomly generated installation ID that is not linked to your identity, the app version, the platform (iOS or Android), the operating system version, and our project ID. Your IP address is transmitted with the request for technical reasons. No names, email addresses, location data, or contents of your projects are transmitted.
Legal basis:
Processing is based on our legitimate interest in understanding the usage and reach of our app pursuant to Art. 6(1)(f) GDPR.
Data transfer to a third country:
Expo processes this data on servers in the United States. The transfer is based on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework. For more information, see Expo's privacy policy.
Right to object:
This launch event is sent automatically when the app starts and is not covered by the analytics toggle in the app settings. You can object to this processing at any time (Art. 21 GDPR) by contacting contact@michaelmurr.de.
7. In-App Purchases and Subscriptions via RevenueCat
We use the “RevenueCat” service in our app to manage, validate, and restore in-app purchases and subscriptions. The provider of this service is RevenueCat, Inc., 1032 E Avenue J Ste Z4 #133, Lancaster, CA 93535, USA.
If you make a purchase in our app, start a subscription, or check the status of a subscription, the app connects to RevenueCat's servers. In doing so, data is transmitted to RevenueCat in order to verify the transaction and unlock the purchased content for you.
Processed data:
- Anonymized user ID (App User ID)
- Information about purchase and subscription status (receipts/proof of purchase)
- Device information (e.g. operating system, app version)
- IP address (for technical reasons related to server communication)
Legal basis:
The processing of this data is necessary for the performance of a contract or in order to take steps prior to entering into a contract. The legal basis is Art. 6(1)(b) GDPR (performance of a contract). Without this data processing, we cannot technically provide in-app purchases and subscriptions to you.
Data transfer to a third country & data processing agreement:
RevenueCat processes your data on servers in the United States. We have concluded a data processing agreement with RevenueCat in accordance with Art. 28 GDPR. For transfers to the United States, RevenueCat relies on the adequacy decision of the European Commission (EU-US Data Privacy Framework) as well as EU Standard Contractual Clauses in order to ensure an adequate level of data protection. Further information about RevenueCat's data processing can be found in its privacy policy.
8. Feedback and Feature Request Function
We offer you the option in our app to send us suggestions for improvement or feature requests via a form.
Processed data and purpose:
If you use this function, we collect the title and description of your request that you enter. We use this data exclusively to improve our app and our services.
In addition, you provide your email address when submitting feedback. We will use your email address only to contact you with any follow-up questions regarding your suggestion or to inform you about its implementation. Your email address will be treated confidentially and will not be published.
Legal basis:
The processing of the title and description is based on our legitimate interest in the further development and improvement of our app (Art. 6(1)(f) GDPR).
The processing of your provided email address is based on your consent (Art. 6(1)(a) GDPR), which you give by entering and submitting your email address. You may revoke this consent at any time with future effect, for example by contacting us via email.
Retention period:
The transmitted data will be deleted as soon as it is no longer required for the purpose for which it was collected, for example when the feature has been implemented or rejected, or when you revoke your consent to store your email address, provided that no statutory retention obligations apply.
Short and cancellation feedback:
In some places you can give quick feedback with an emoji rating and optional keywords. If you submit it, the rating, selected keywords, the relevant screen, app version, language and unit system, a pseudonymous device ID, and your RevenueCat user ID are transmitted to our server. Optional free text or an email address is only transmitted if you actively submit the feedback. If you dismiss or skip the prompt, nothing is sent to our server; only a pseudonymized usage event is recorded via Firebase Analytics (see section 5).
When you cancel a subscription, you can select a reason for cancelling. The selected reason, your subscription type (trial or paid), a pseudonymous device ID, and your RevenueCat user ID are transmitted to our server once you complete the step with the optional message, and this also happens if you skip that message. The reason and subscription type are additionally recorded in Firebase Analytics. The optional message itself is only transmitted if you actively submit it. If you leave the cancellation flow before that, nothing is sent.
Processor (hosting):
The data entered as part of the feedback function is stored with our processor Supabase, Inc. (hosting region: EU). We have concluded a data processing agreement with Supabase in accordance with Art. 28 GDPR to ensure the secure handling of your data. Where data is thereby transferred to a third country (e.g. the USA), this is based on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
9. Legal Basis for Processing
Contractual necessity: Processing of measurements is necessary to provide the service (Art. 6(1)(b) GDPR). Processing of feedback data, download redirect counts, and analytics data and crash reports via Firebase is based on our legitimate interest (Art. 6(1)(f) GDPR) to improve the app and website, prevent abuse, ensure stability, and measure whether download links work. Website analytics through Google Analytics is based on your consent (Art. 6(1)(a) GDPR).
10. Data Storage and Retention
Local vs. Cloud: Projects and measurements are stored only locally on your device. Feedback data is stored on our servers. Analytics and crash data is processed by Google (Firebase) on servers that may also be located in the USA (see section 5).
Consented website analytics is processed by Google as described in section 4. Identifier-free download redirect files are deleted automatically after 90 days. Technical server logs are handled as described in section 3 and deleted after at most 30 days.
11. Your Rights (GDPR)
You have the following rights regarding your personal data under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure / right to be forgotten (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
Please direct requests to contact@michaelmurr.de.
12. Competent Supervisory Authority
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority (Art. 77 GDPR). The authority competent for Bavaria is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
13. Changes to This Privacy Policy
We reserve the right to update this privacy policy to ensure it always complies with current legal requirements or to reflect changes to our services.
Last updated: July 2026