privacy policy
Last changed 29.06.2026
In connection with providing the Mirrolizer App, Vertify GmbH (“we”, “us”) processes personal data within the meaning of the EU General Data Protection Regulation (“GDPR”), the Austrian Data Protection Act (“DSG”) and the Austrian Telecommunications Act 2021 (“TKG 2021”). This Privacy Policy explains how we process personal data and informs you about your rights as a data subject.
Due to the ongoing development of our Mirrolizer app or possible legal changes, it may become necessary to adapt this privacy policy. The version published on mirrolizer.com/privacy-policy shall apply.
1. Categories of data subjects
When providing the Mirrolizer App, we process personal data of app users, meaning individuals who download and use the app on their mobile device.
2. Processing activities
2.1 Mirrolizer App services
The core functions of the Mirrolizer App do not require you to create an account, provide your name or contact details, or actively submit any other personal data to us.
The camera feed processed by the Mirrolizer App is processed exclusively on your smartphone. We do not record photos or videos; this is not technically intended.
2.2 Technical provision, error analysis and further development of the app
For the technical provision, error analysis, stability improvement, performance optimization, app configuration, usage analysis and management of in-app purchases, we use the services described below.
2.2.1 Firebase Core Services
We use services of the Google Firebase platform, provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and affiliated Google companies.
Firebase may process technical identifiers and device data to provide individual Firebase services, in particular Firebase Installation IDs, IP addresses, app ID, package name, app version, operating system, device model, language, country/region and technical usage data. The specific data processed depends on the Firebase service used.
2.2.2 Firebase Crashlytics
We use Firebase Crashlytics to detect, analyze and fix crashes and stability issues in the Mirrolizer App in future app versions.
For this purpose, the following data may be processed in particular:
- Crashlytics Installation UUIDs
- Firebase Installation ID
- crash stack traces and technical crash reports
- time of the crash
- app bundle ID, package name, app version and build information
- operating system, operating system version and device model
- technical device information such as CPU architecture, RAM, storage space and device state
- information about whether the app was in the foreground or background
- for certain native crashes, temporary minidump data where required to process the crash report
The purpose of this processing is troubleshooting, stability analysis, prioritization of issues and improvement of app quality.
Retention period: According to Google, Firebase Crashlytics stores crash stack traces, extracted minidump data and associated identifiers for 90 days before deletion from live and backup systems is initiated.
2.2.3 Firebase Performance Monitoring
We use Firebase Performance Monitoring to detect performance issues in the Mirrolizer App and optimize the app, for example in relation to long loading times, slow processes, network issues or unusual runtime metrics.
For this purpose, the following data may be processed in particular:
- Firebase Installation ID
- Firebase Session ID
- IP address for approximate country-level attribution of performance events
- app version, app package name and whether the app is in the foreground or background
- operating system, device model, device orientation and general device information
- language/locale, country/region, mobile carrier and network type, such as Wi-Fi, LTE or 3G
- RAM and storage size, CPU usage
- duration of automatic performance traces
- for network performance measurements, URL without URL parameters and without payload content, response codes, response times and payload sizes
The purpose of this processing is to measure and improve the technical performance of the app. Google uses Firebase Installation IDs, among other things, to calculate sufficiently anonymous access patterns and to manage the rate of performance events.
Retention period: According to Google, Firebase Performance Monitoring stores IP-related events for 30 days and installation-related as well as de-identified performance data for 60 days before deletion from live and backup systems is initiated.
2.2.4 Firebase Remote Config
We use Firebase Remote Config as a separate service to deliver configuration values to the app and adjust certain app settings, feature parameters or technical thresholds without necessarily publishing a new app version.
For this purpose, the following data may be processed in particular:
- Firebase Installation ID
- app ID, package name and app version
- platform, operating system and SDK version
- language, country/region and time zone
- technical information required to deliver suitable configuration values to the respective app installation
The purpose of this processing is to deliver appropriate configuration values to the app and technically control app functions.
Retention period: According to Google, Firebase stores Firebase Installation IDs until the Firebase customer requests deletion of the ID via an API. After such a deletion request, the data is removed from live and backup systems within 180 days.
2.2.5 Google Analytics for Firebase
We use Google Analytics for Firebase to better understand how the Mirrolizer App is used, which features are relevant and how we can improve the app in future versions.
For this purpose, the following data may be processed in particular:
- app instance identifier used to identify a unique app installation
- number of users and sessions
- session duration
- app starts, first opens, app opens and app updates
- operating systems and device models
- approximate geography
- screen and usage events within the app
- in-app purchase events and information about whether the Pro version is activated
- technical metrics such as screen resolution or performance-related events where collected in Analytics
The purpose of this processing is usage analysis, statistical evaluation, improvement of app functions and further development of the app.
Where the app provides the relevant settings, the collection of Crashlytics, Performance and Analytics data can be disabled in the app settings. This does not affect the core functionality of the Mirrolizer App.
2.2.6 RevenueCat
We use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, for the technical management of in-app purchases, subscriptions, entitlements and cross-device or cross-platform restoration of purchased content or Pro features.
RevenueCat is not only relevant after a purchase has been completed. The service may process technical end-user information when the app is used or when purchase or entitlement status is checked. This allows the app to determine whether a product has been purchased, whether a Pro version is active, whether a purchase can be restored or which purchase options should be displayed.
For this purpose, the following data may be processed in particular:
- technical information about the end device, in particular device type and operating system
- technical app and SDK information
- pseudonymous RevenueCat or app user identifier, where used by the app
- time when the app or a digital product was last used
- transaction and entitlement information related to in-app purchases and subscriptions
- Apple receipt files or Google purchase tokens where a purchase or restoration is processed
- optional metadata or attribution data where configured in RevenueCat
The purpose of this processing is to provide, verify, restore and manage in-app purchases, subscriptions and Pro entitlements, and to create aggregated statistics that are not directly personal regarding app usage and monetization.
According to RevenueCat, RevenueCat generally processes end-user information as a processor for its customers. RevenueCat states that it stores customer data on Amazon Web Services infrastructure in the United States. For transfers from the EEA to third countries, RevenueCat provides Standard Contractual Clauses.
3. Recipients of personal data
In connection with the processing activities described above, personal data may be transferred in particular to the following recipients:
- Google LLC and affiliated Google companies in connection with Firebase Crashlytics, Firebase Performance Monitoring, Firebase Remote Config and Google Analytics for Firebase
- RevenueCat, Inc. in connection with in-app purchases, subscriptions, entitlements and purchase restoration
- technical service providers and subprocessors of these recipients, where required to provide the respective services
According to Google, Google generally acts as a processor for Firebase services. Google Analytics is a separate service that may be used together with Firebase and is subject to its own terms.
4. Transfer to third countries
The recipients named above may process personal data in the United States or in other countries outside the European Economic Area. Where no adequacy decision by the European Commission exists for a third country, we rely on appropriate safeguards, in particular Standard Contractual Clauses pursuant to Art. 46 GDPR, where required.
According to Google, Google LLC is certified under the EU-U.S. Data Privacy Framework. Firebase services may also be processed on global Google infrastructure where no specific data location has been selected or is available.
5. Legal bases
Unless otherwise stated, the processing of the technical data described above is based on our legitimate interests pursuant to Art. 6(1)(f) GDPR. Our legitimate interests are the secure and stable provision of the app, error analysis, improvement of technical performance, further development of the app, statistical usage analysis and management of in-app purchases and Pro entitlements.
Where processing is necessary for the performance of a contract with users, in particular to provide, verify or restore purchased app content or subscriptions, the processing is based on Art. 6(1)(b) GDPR.
Where consent is required for individual processing activities, processing is based on Art. 6(1)(a) GDPR. Consent may be withdrawn at any time with effect for the future.
6. Your rights
You have the following rights in relation to the processing of your personal data, subject to the statutory requirements and limitations of applicable law:
Right of access — You have the right to request information about the personal data we process about you. This includes, in particular, information about the purposes of processing, the categories of personal data concerned, the recipients or categories of recipients, and the planned storage period, where applicable.
Right to rectification — If we process data about you that is inaccurate or incomplete, you may request that it be corrected or completed.
Right to erasure — You have the right to request the erasure of personal data relating to you, provided that the statutory requirements are met. This right may not apply where processing is necessary, for example, to comply with a legal obligation or to establish, exercise or defend legal claims.
Right to restriction of processing — You have the right to request the restriction of the processing of your personal data where the applicable legal requirements are met. In such cases, the data may generally only be processed in a limited manner.
Right to data portability — Where the statutory requirements are met, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format. You may also request that we transmit this data to another controller, where technically feasible.
Right to object to processing based on legitimate interest — Where we process your personal data on the basis of legitimate interests, you have the right to object to such processing on grounds relating to your particular situation. In that case, we will no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or where the processing serves to establish, exercise or defend legal claims.
Right to withdraw consent with effect for the future — Where we process your personal data on the basis of your consent, you have the right to withdraw this consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to lodge a complaint with a data protection supervisory authority — If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a competent data protection supervisory authority.
In Austria, the competent authority is:
Austrian Data Protection Authority Barichgasse 40-42 1030 Vienna Austria https://www.dsb.gv.at/
7. Contact
The data controller for the data processing activities described in this privacy policy is:
Vertify GmbH Europastraße 1 7540 Güssing Austria
For all your data protection concerns, in particular to exercise your rights, please contact us in writing (by e-mail) at dataprotection@vertifymed.com.
8. Further information
Please note that there may be other data processing activities in connection with the use of the Mirrolizer App for which third parties are responsible.
For detailed information on how these possible recipients process your personal data, please contact them as their respective controllers.