App Privacy

Privacy Information for the MyMilo App

Version: 14 April 2026 · This privacy information explains how we process personal data when you use the MyMilo app.

1. Controller

Herotion GmbH Friedrichstraße 16 72072 Tübingen (Germany) Email: info@mymiloapp.com

2. Data Protection Officer / Privacy Contact

You can reach our privacy contact at info@mymiloapp.com or by post at the address given above, marked "Datenschutz" (data protection).

3. Important Note on Use

The MyMilo app does not make any medical decisions and does not replace medical advice or treatment. Medical instructions always take precedence. If in doubt, please seek medical advice before using the app. The app is intended for use by children only if it is set up and consented to by parents/legal guardians.

4. Who Does This Information Apply To?

This information applies to the general use of the MyMilo app.

5. Purposes of Data Processing

We process personal data in order to: 1. provide and operate the app and enable its use (including account/profile management), 2. technically implement content and training features, 3. ensure the security, stability and proper functioning of the app (e.g. abuse prevention, error analysis), 4. handle support requests, 5. optionally: improve the app (e.g. analytics), provided consent has been given for this.

6. What Data We Process

Depending on how the app is used, the following categories of data may be processed: 6.1 Account data / master data • Email address (parent/legal guardian) • Login/account management data (e.g. times of registration, consents, deletion requests) 6.2 Child's profile data (created by you) • Nickname (pseudonym) • Age range (no requirement to provide an exact date of birth) 6.3 Usage and training data • completed exercises, training duration, inputs in the app, progress/history data 6.4 Well-being data (entries via smileys) • daily mood/well-being (where used) Note: Information about well-being may – depending on the context – relate to health and is therefore processed by us with special protection (see legal bases). 6.5 Technical data (log and device data) • pseudonymous device/app IDs (e.g. internal identifiers) • operating system, app version • times of access • IP address (in particular for server access) • error and security logs 6.6 Communication and support data • the content of your support requests (e.g. email), contact address and, where applicable, technical information for troubleshooting

7. Legal Bases for Processing

We process personal data on the following legal bases: 7.1 Contract/usage relationship (Art. 6(1)(b) GDPR) For providing the app and its core functions (account, use, training features). 7.2 Legal obligations (Art. 6(1)(c) GDPR) Where statutory retention or documentation obligations exist. 7.3 Legitimate interest (Art. 6(1)(f) GDPR) For IT security, abuse prevention, error analysis, system stability and documenting consents/deletion requests. 7.4 Consent (Art. 6(1)(a) GDPR) For optional features, in particular analytics/app improvement, where used. 7.5 Health-related data (Art. 9(2)(a) GDPR – explicit consent) Where we process information that may relate to health (e.g. well-being entered via smileys, study-related content where applicable), this is done only with your explicit consent. Withdrawal: Consent may be withdrawn at any time with effect for the future. Processing carried out before withdrawal remains lawful. (The information requirements, including those regarding profiling/automation, follow from Art. 13 GDPR.) Note on children Where processing is based on consent and the app is offered as an information society service directly to children, consent for children under 16 years of age is only valid if it is given or authorised by the person holding parental responsibility.

8. Whether You Are Required to Provide Data

Required for use: The app cannot be used without an email address (account).

9. Device Access, Push Notifications and Consents (Section 25 TDDDG)

9.1 Device access For technical operation, the app may store information on your device or access information already stored there (e.g. login status, app settings, push token). Such access is generally only permitted if you have given your consent on the basis of clear information, unless it is strictly technically necessary. 9.2 Push notifications Push notifications are short messages that the MyMilo app can send to your device, even when the app is not currently active. They serve, for example, to remind you of exercises or to inform you about important app-related matters. Receiving push notifications is voluntary and requires your prior consent. When activated, technically necessary information is processed, in particular a so-called push token (a pseudonymous device identifier) provided by your device's operating system. Push notifications are activated and managed by the person holding parental responsibility via the respective device. To deliver push notifications, we use the technical push services of the respective operating system providers (e.g. Apple Push Notification Service or Firebase Cloud Messaging). These providers receive only the data required for technical delivery. We do not send any sensitive content via push notifications, in particular no health data or individual training information. You can deactivate push notifications at any time via your device settings or within the app. Withdrawal of consent takes effect for the future. 9.3 No pre-ticked consents Where consents are required, they are obtained actively, not through pre-ticked boxes.

10. Recipients, Service Providers and Data Processing on Our Behalf

To provide and operate the app, we may use service providers (e.g. for hosting, maintenance, support systems, sending technical notifications). They process data on our behalf, bound by our instructions, as processors on the basis of contracts pursuant to Art. 28 GDPR. This includes in particular: Hosting / data centre: Hetzner Online GmbH Industriestraße 25 91710 Gunzenhausen Germany Processing takes place exclusively in data centres within Germany or the European Union. A data processing agreement pursuant to Art. 28 GDPR is in place with the hosting provider. In addition, further service providers (e.g. for email delivery, technical support or system maintenance) may be used where this is necessary for the operation of the app. Corresponding data processing agreements are also in place with these providers. Personal data is not shared with other third parties unless we are legally obliged to do so or you have expressly consented.

11. App Store / Platform Providers (Note)

When the app is downloaded via app stores (e.g. Apple App Store/Google Play), data is processed by the respective platform providers. The platform providers are independently responsible for this processing.

12. Transfers to Third Countries (Outside the EU/EEA)

We intend to process data within the EU/EEA as a matter of principle. If, in exceptional cases, processing takes place in third countries (e.g. with certain technical service providers), this is done only under the conditions of Art. 44 et seq. GDPR (e.g. adequacy decision or EU standard contractual clauses) and is made transparent.

13. Retention Periods and Deletion

We store personal data only for as long as necessary for the respective purposes: • Account and usage data: in principle until the account is deleted or the data is no longer required to provide the app; statutory retention periods remain unaffected. • Technical logs/security data: generally only temporarily and for specific purposes; security and error logs are deleted or anonymised as soon as they are no longer required (typically within 90 days).

14. Data Security

We protect data through appropriate technical and organisational measures pursuant to Art. 32 GDPR (e.g. access restrictions, encryption, logging, role and permission concepts).

15. No Automated Decision-Making / Profiling

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. (The information requirements on this point follow from Art. 13 GDPR.)

16. Your Rights

Provided the legal requirements are met, you have the following rights: • Access (Art. 15 GDPR) • Rectification (Art. 16 GDPR) • Erasure (Art. 17 GDPR) • Restriction of processing (Art. 18 GDPR) • Data portability (Art. 20 GDPR) • Objection (Art. 21 GDPR), where processing is based on Art. 6(1)(f) GDPR • Withdrawal of consent at any time with effect for the future (Art. 7(3) GDPR)

17. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority is in particular the supervisory authority at the registered office of Herotion GmbH or at your habitual place of residence or place of work. For Baden-Württemberg: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg (LfDI BW), Postfach 10 29 32, 70025 Stuttgart, Germany, Tel.: +49 711 615541-0, Email: poststelle@lfdi.bwl.de.

18. Contact

Herotion GmbH, Friedrichstraße 16, 72072 Tübingen, Germany Privacy contact/Data Protection Officer: info@mymiloapp.com