Privacy Policy

AnklePath • Last updated: 12 August 2026

This Privacy Policy explains what information the AnklePath mobile application ("AnklePath", "the app", "we", "us") collects, how we use it, and the choices you have.

Who we are (data controller)

The controller responsible for your data under the GDPR is:

Timothy Wasswa
Dachauer Straße 109
80335 München
Germany
E-mail: 24.stom.wasswatimothy@gmail.com

See also our Impressum.

Information we collect

CategoryExamplesWhy
Account informationEmail address and name when you sign in with Apple, Google, or email. Guest sign-in uses an anonymous identifier with no email.To create and secure your account and sync your data.
Health data you provideInjury type and timing, symptoms, walking ability, recovery goals, pain check-ins, free-text notes, and completed exercises.To generate and adjust your recovery plan and show your progress.
Profile photo (optional)An image you choose from your photo library. It stays on your device and is not uploaded to our servers.Shown only as your in-app profile picture.
Consent recordsWhether you granted or withdrew health-data and analytics consent, the version of this policy, and the time.To demonstrate that we obtained consent, as the GDPR requires.
Product analyticsApp events such as screens viewed and features used, linked to a pseudonymous account identifier. We do not send your name, email, or photo to our analytics provider.To understand usage and improve the app.
Diagnostics & crash dataCrash reports, error messages, app version, device model, and operating system.To find and fix bugs and keep the app stable.
Subscription dataAnonymised purchase and entitlement status from the App Store or Google Play. We never see your card details.To unlock and restore premium features you have paid for.

We do not sell your personal information. We do not use your free-text health notes for advertising, and we avoid sending detailed health notes to our diagnostics tools.

Legal basis for processing

Health data is a special category under Article 9 GDPR and receives extra protection. We rely on the following legal bases:

PurposeLegal basis
Processing your injury, symptoms, pain scores and notes to build your recovery planYour explicit consent — Art. 9(2)(a) GDPR, given on the consent screen before onboarding. You may withdraw it at any time.
Creating and running your account, and providing the app's core featuresPerformance of a contract — Art. 6(1)(b) GDPR.
Product analyticsYour consent — Art. 6(1)(a) GDPR. Optional, off by default, and revocable in Profile at any time.
Crash and error diagnostics, and keeping the service secureOur legitimate interest in a stable, secure app — Art. 6(1)(f) GDPR.
Subscriptions and billingPerformance of a contract — Art. 6(1)(b) GDPR — and our legal record-keeping obligations, Art. 6(1)(c).

Withdrawing consent

Open Profile → Health data consent to withdraw your health-data consent, or Profile → Product analytics to turn analytics off. Withdrawal takes effect immediately and does not affect the lawfulness of processing carried out beforehand. Because the recovery plan cannot be personalised without health data, withdrawing consent stops that personalisation; to remove the data already stored, delete your account (below).

How your information is used

Service providers we use

We share limited information with trusted providers who process it on our behalf under data processing agreements:

International transfers

Some of these providers process data outside the European Economic Area, including in the United States. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses together with the provider's supplementary technical measures. You may request a copy of the safeguards that apply by contacting us.

Data retention

DataKept for
Account and health data (plan answers, pain logs, notes)Until you delete your account. Deletion is immediate and irreversible.
Data on your deviceUntil you sign out or delete the app.
Consent recordsUp to 3 years after your account ends, as evidence that consent was obtained.
Crash diagnostics90 days.
Analytics eventsUp to 12 months.
Purchase and invoice recordsAs required by tax and commercial law, typically up to 10 years.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, to object to processing based on legitimate interests, and to withdraw consent at any time. In the app:

Right to complain

If you believe we have handled your data unlawfully, you may lodge a complaint with a supervisory authority — either the one where you live or work, or the one responsible for us:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de

Children

AnklePath is not directed to children under 16 (or the minimum age required in your country), and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

Security

All communication with our providers is encrypted in transit using TLS. Your data is stored in Google Firebase with access restricted to your own account, and access on our side is limited to what is needed to operate and support the app. No method of transmission or storage is completely secure, but we work to safeguard your data.

Medical disclaimer

AnklePath provides educational guidance and general recovery information. It is not medical advice and does not replace assessment, diagnosis, or treatment by a qualified clinician.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above, and where the change affects what you consented to, we will ask for your consent again in the app.

Contact

Questions or requests: 24.stom.wasswatimothy@gmail.com