How personal data is processed in the app and on this website.
Last updated: 5 August 2026
Version: 1.0
This is an English translation of the German "Datenschutzerklärung". In case of discrepancies, the German version prevails.
This Privacy Policy explains how personal data is processed when using the "Tennis Mentor" Android app, the website at https://www.tennismentor.net and the associated support and deletion pages.
The controller within the meaning of the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP) is:
Sebastian Münz
Augsburger Str. 1
82194 Gröbenzell
Germany
Website: https://www.tennismentor.net
No data protection officer has been appointed.
Tennis Mentor allows users in particular to record tennis matches, training sessions, personal thoughts, goals, statistics and other tennis-related information.
The minimum age for use is 16. The service is not offered to persons under 16. There is no technical age verification; the user's confirmation on first launch of the app is decisive.
The app is not intended to store medical data, diagnoses, injury records, biometric data or other particularly sensitive information. Users should not enter such data into free-text fields.
Depending on use, we process the following data:
This content may allow conclusions to be drawn about performance, behaviour or wellbeing. It is not processed as a medical diagnosis. Users may not enter other people's data unless they are authorized to do so. Opponents' names should be recorded as a nickname or pseudonym wherever possible.
Tennis Mentor is currently offered free of charge. We do not process any payment or subscription data.
We process data for the following purposes:
| Purpose | Typical data | Legal basis EU/EEA |
|---|---|---|
| Create, sign in to and manage an account | account and authentication data | Art. 6 (1) (b) GDPR |
| Store and synchronize matches, training sessions, thoughts and settings | user input and account identifier | Art. 6 (1) (b) GDPR |
| Security, fraud and abuse prevention | technical data, logs and identifiers | Art. 6 (1) (f) GDPR |
| Support and handling of requests | contact and communication data | Art. 6 (1) (b), (c) or (f) GDPR |
| Compliance with legal obligations | necessary account and communication data | Art. 6 (1) (c) GDPR |
| Improve the service and fix errors | crash reports, error and usage logs, performance data | Art. 6 (1) (f) GDPR or, where required, consent under Art. 6 (1) (a) GDPR |
| Marketing or newsletters | not currently carried out | – |
Our legitimate interest lies in particular in the secure, stable and economical operation of the service, in preventing abuse and in error analysis. Where consent is required, it can be withdrawn at any time with effect for the future.
For users in Switzerland, processing takes place in accordance with the principles of the Swiss FADP, in particular lawfully, in good faith, proportionately, for a specified purpose and transparently.
Data marked as required is needed to create an account or to provide the respective function. Without this data we cannot offer the service in question, or can offer it only to a limited extent. Voluntary information is identifiable as such or is not strictly necessary for the function.
We use services from the Google group. The contracting party and the specific roles may depend on the product chosen and the location.
The contracting parties are Google Ireland Limited and/or Google Cloud EMEA Limited for customers in the EEA; the exact allocation depends on the product used.
The standard data processing terms with Google Cloud and Firebase apply, including standardized contractual clauses on data protection.
Selected Firebase and Google Cloud regions: primary data is stored in the EU region europa-west1 (Belgium). Backups and secondary replication may involve other regions.
Purpose: registration, sign-in, session management and account security.
Data processed may include:
Sign-in methods used:
Retention: until the account is deleted, and beyond that only where security, abuse-prevention or statutory retention grounds exist. After account deletion, authentication data is removed from active systems within 30 days; any further processing then serves only to fulfil statutory retention obligations.
Purpose: storage and synchronization of account, tennis, settings and app data.
Documents and information stored:
Firestore location: europa-west1 (Belgium); backups and secondary replication may use additional regions.
Retention: in principle until the user deletes the data or their account, unless statutory obligations or legitimate grounds prevent this. For individual periods see section 12.
Purpose: configuring features, gradual rollout, technical testing and adjusting app behaviour.
Remote Config may process app instance information, device properties, language, country/region, app version and technical retrieval data. We do not use Remote Config for personalized advertising or sensitive profiling.
Actual conditions and audiences:
Purpose: provision of the website and of the legal, support and deletion pages.
When the site is accessed, the IP address, date and time, requested URL, referrer, browser and device information and status codes in particular may be processed in server or CDN logs.
Hosting domain: https://www.tennismentor.net and associated subdomains (privacy, deletion, support and legal notice pages).
Log retention: standard logs are deleted automatically after 30 days; extended logs (if enabled) after 90 days.
The following additional Firebase services are used:
Firebase Crashlytics
Google Analytics for Firebase (GA4)
Firebase Cloud Messaging (FCM)
Cloud Storage for Firebase
Firebase AI (Genkit) – coach advice feature
Firebase App Check
Where necessary, data may be transmitted to the following categories:
Key service providers:
| Provider | Purpose | Type of data |
|---|---|---|
| Google Ireland Limited / Google Cloud EMEA Limited | Firebase infrastructure, storage, authentication | account, content and technical data |
| Google LLC / Google Cloud US | Firebase services, in particular Analytics and Crashlytics | telemetry and error analysis |
| Firebase Hosting (Google Cloud) | website and static pages | access logs |
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. No advertising SDKs are used and no data is passed to advertising networks.
When using global cloud services, data may be processed outside Germany, the EEA or Switzerland, in particular in the USA and other countries in which Google or its subprocessors operate facilities.
Where necessary, we base transfers on:
Specific transfer mechanisms and subprocessors:
The website may use technically necessary cookies or local storage mechanisms to provide security, language, form state or sessions. The legal basis is the necessity of providing the service expressly requested, together with Art. 6 (1) (b) or (f) GDPR.
No optional analytics, marketing or advertising cookies are currently used on the website. All cookies are technically necessary.
Should such technologies be used in future, valid consent will be obtained, a consent management system implemented and a complete provider list published before activation.
The app requests only those permissions needed for the features that are enabled.
Android permissions used:
| Permission | Purpose | Required / Optional | Can be disabled |
|---|---|---|---|
INTERNET | connection to Firebase servers, synchronization | required | no |
POST_NOTIFICATIONS | push notifications (reminders, debrief prompts) | quasi-required | yes (in Android settings) |
The INTERNET permission cannot be disabled because it is required for basic functionality. Users can revoke POST_NOTIFICATIONS at any time in the Android system settings.
The app does not request any permissions for health, fitness or activity data and does not access Health Connect. Likewise, no location, contact, camera or microphone data is collected.
We store data only for as long as this is necessary for the respective purpose or required by law.
| Data category | Intended period |
|---|---|
| Account and profile data | until account deletion; technical residual period of no more than 30 days |
| Matches, training sessions, thoughts and settings | until individual deletion or account deletion |
| Firebase authentication data | until account deletion; residual period of no more than 30 days |
| Support communication | 12 months after completion |
| Security and server logs | 30–90 days |
| Crash and error reports (Crashlytics) | 90 days |
| Analytics data (Firebase Analytics, only with consent) | 14 months |
| Backups | regular overwrite or deletion within 30 days of account deletion |
| Deletion and privacy requests | 3 years as evidence |
After expiry, data is deleted or anonymized unless statutory or compelling security grounds prevent this. Data in backups is removed from the active system and overwritten in the regular backup cycle; it is not returned to productive use except where restoration is necessary.
Users can request deletion of their account and the linked data:
Account deletion generally covers:
Analytics and crash data (Firebase Analytics, Crashlytics) are stored pseudonymously and are not linked to the deleted account. They are not removed as part of the account deletion but are deleted automatically once the periods stated in section 12 expire (14 months and 90 days respectively). On request we will additionally arrange for the deletion of this data, insofar as it can still be attributed to a user.
Data that we are required to retain by law, or that is necessary to establish, exercise or defend legal claims, may be excluded. Details are set out on the "Account and Data Deletion" page.
We use appropriate technical and organizational measures, including where applicable:
No procedure can guarantee complete security.
Subject to the statutory requirements, users have in particular the right to:
Requests can be sent to hello.tennismentor@gmail.com. We may require proof of identity in order to prevent unauthorized disclosure.
Competent German supervisory authority:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Under the Swiss FADP, persons in Switzerland may in particular request information about their personal data being processed and, where the statutory requirements are met, request rectification, deletion or the release or transfer of that data. They may contact the controller or the Federal Data Protection and Information Commissioner.
Where data is disclosed abroad, we provide information about the country or region and the safeguards used, insofar as this is legally required. For specific countries and safeguards see section 9.
We do not sell personal data and do not share it for cross-context behavioural advertising. We do not discriminate against users for exercising privacy rights. Regardless of where you live, you can send access, deletion or rectification requests to hello.tennismentor@gmail.com.
Tennis Mentor is not directed at persons under 16. We do not knowingly collect data from persons under 16.
If a parent or legal guardian becomes aware that a person under 16 has created an account, they can contact hello.tennismentor@gmail.com. We will delete the account and the associated data without undue delay.
The target audience selected in the Google Play Console covers only the age groups 16–17 and 18+; younger age groups are not selected. The app therefore does not fall under the Google Play Families policies or under COPPA.
We may adapt this Privacy Policy if features, service providers or the legal situation change. Material changes will be announced in the app, on the website or by email, insofar as this is required. The date of the last update appears at the beginning of this policy.
Please send privacy and support enquiries to hello.tennismentor@gmail.com