VYC Sahitya app
Privacy policy VYC Sahitya
Mindful with your data, too
All app data stays local on your device: no server, no cloud, no tracking.
Last updated: August 2026
Privacy policy of the websiteThis page applies exclusively to the mobile app VYC Sahitya.1. Data protection at a glance
General notes
This privacy policy informs you about how we process personal data when you use the mobile app VYC SAHITYA.
The app is designed as an offline-first app. Your usage data is processed locally on your device as a matter of principle. The app operates no server of its own, no cloud synchronisation of its own, and uses no analytics, advertising, tracking or crash-reporting SDKs.
Individual data can only leave your device if you use an external function yourself — for example if you open a link to the website, explicitly save the recovery passphrase in the iCloud Keychain, or if your operating system backs up app data as part of your personal device backup. You will find details in the following sections.
2. Responsible party
The party responsible for data processing in the mobile app VYC SAHITYA is:
The VYC SAHITYA app is provided by Vinayaki-Yoga & Coaching GbR, which is solely responsible for the processing that takes place in the app. On the shared website two providers appear side by side: there, Vinayaki-Yoga & Coaching GbR and Anne Böhme (freelance yoga teacher, “Vinayaki-Yoga”) are joint controllers within the meaning of Art. 26 GDPR for the web presence and the shared customer base. Those processing activities are covered by the website's privacy policy, which names both controllers and the agreement made between them.
The responsible party is the natural or legal person who alone or jointly with others decides on the purposes and means of processing personal data.
Technical development and operation
The technical development and operation of the app are carried out by VYC Sahitya IT-Solutions GbR as a processor, exclusively according to our instructions and on the basis of a data processing agreement pursuant to Art. 28 GDPR.
VYC Sahitya IT-Solutions GbR does not process personal data from the app for its own purposes.
3. Locally processed data
Principle of local storage
The app processes your usage data locally on your device as a matter of principle. Unless you actively use one of the external functions described in this policy, the following data is not transmitted to us or to other recipients.
Encrypted database
The app stores essential usage data in a locally encrypted database. The database is protected with SQLCipher and AES-256 encryption.
In particular, the following data can be stored in the encrypted database:
- Drink entries with time, amount, drink type and, where applicable, a drink name you chose yourself
- Individual daily goals, favourites and drinks you created yourself
- Settings for drink reminders, including interval, an individually chosen reminder period and exceptions for individual days
- Breathing exercise profiles with your individual settings: numbers of rounds, inhale, hold and exhale times, and profile names you assigned yourself
Combinations of drinking and reminder data may allow conclusions about daily rhythm or habits. Details on breathing exercises may allow conclusions about individual practice or performance levels.
The app keeps no history of completed exercise sessions. Only your exercise profiles and settings are stored, plus — solely for the quick start — the exercise you last started.
Local app settings
In addition, the app stores settings in the local device storage, in particular:
- Selected language, display mode, font size and accessibility options
- Date, number and navigation settings
- Configurations for breathing exercises and the exercise last used
- Your latest search queries as entered text and the glossary or content areas last opened
- Configuration and synchronisation information for the Apple Watch
- Acceptance of the terms of use
These settings are stored in the app's operating-system settings area. They are not encrypted with the database key but protected solely by the sandbox and the file protection mechanisms of your operating system. This applies in particular to your search queries in plain text.
Apple Watch
If you use the accompanying Apple Watch app, certain data is exchanged locally between the iPhone app, the Apple Watch app and the widget for display and use on the Apple Watch. This can include drinking levels, daily goals, current drink entries, drink names, favourites, reminder status, and breathing exercise profiles and their settings.
The exchange takes place exclusively locally via the Watch connection provided by Apple and a shared app container protected by the operating system. No transmission over the internet takes place.
Drink entries recorded on the Apple Watch are transferred back to the iPhone and stored there in the encrypted database.
The data in the shared app container is not encrypted with the iPhone app's database key but is protected by the file protection mechanisms of iOS. It is not transmitted to our servers or to VYC Sahitya IT-Solutions GbR as a result.
4. Encryption and protective measures
Encryption key and recovery passphrase
The key for the encrypted database is generated on your device and stored in the secure system storage: in the Keychain on iOS, in EncryptedSharedPreferences with the Android Keystore on Android.
For restoring the encrypted database, the app generates a recovery passphrase. It is stored together with the database key in the same secure system storage so that you can view it again in the app settings at any time.
Displaying the passphrase is protected on both platforms by a biometric or device-code check. On Android, the display of sensitive content is additionally protected against screenshots; on iOS the content is hidden in the app switcher. When the passphrase is copied, the clipboard is treated as sensitive.
The app offers no function for exporting, sharing or automatically transmitting your usage data to us or to third parties.
Saving the recovery passphrase in Apple Passwords
On iOS you can voluntarily save the recovery passphrase in the iCloud Keychain via the function “Passphrase in Passwörtern sichern”. This function is only triggered after your active selection.
If you use this function, the passphrase is processed by Apple within the iCloud Keychain and can be made available on your own Apple devices. Apple is responsible for this processing. Apple's privacy information applies in addition.
The app can afterwards neither read nor delete an entry saved this way. Managing or removing it is done exclusively via the settings of your Apple device.
Without your active selection, the recovery passphrase is not transferred to the iCloud Keychain by the app.
5. Device permissions
Notifications
The app can send local reminders for drink breaks. The permission is only requested when you activate reminders.
The reminders are scheduled locally on the device. They contain no personal details and are not sent via a push service or our servers.
The processing is based on your consent pursuant to Art. 6(1)(a) GDPR. You can revoke the permission at any time in the system settings of your device.
Device time zone
So that reminders are triggered at the right time, the app reads the time zone set on your device once when the notification service starts (for example “Europe/Berlin”). No location query and no continuous positioning takes place.
Biometrics and device code
On iOS and Android the app can use your device's biometrics (Face ID, Touch ID, or fingerprint or face recognition) or, alternatively, the device code to check your authorisation before displaying your recovery passphrase. The app receives no biometric data in the process. The check is performed exclusively by the operating system.
Apple Watch and HealthKit
The Apple Watch app can request a HealthKit permission when a guided breathing exercise is started. This serves exclusively to keep the guided exercise reliably active while it runs.
The app reads no health data from Apple Health. It writes no health data to Apple Health and processes no vital signs, step counts, heart-rate values or comparable health information from HealthKit.
If you refuse the permission, the exercise remains fully usable; only the display brightness may be reduced during the exercise.
Camera, microphone, location and further permissions
The app does not access the camera, microphone, location, contacts, photos, calendar, Bluetooth, motion data, Google Fit, Health Connect or comparable device sensors.
6. Device backups and cloud services
Operating-system backups
Depending on your personal device settings, app data can be included in operating-system backups, for example in iCloud on iOS or in Google Drive on Android.
Such backups can include in particular the encrypted database, local settings, the search history, files for restoring the database and, on iOS, possibly data from the shared app container for Apple Watch and widget.
The database key and the locally stored recovery passphrase are not saved in iCloud or Google Drive backups during normal operation, since they reside in the protected system storage of the respective device and, being device-bound, do not leave it.
It follows: if a device backup is restored on a new device, the encrypted database cannot be read without your recovery passphrase. The passphrase is therefore the only way to make your data accessible again on a new device. Keep it correspondingly safe.
The duration and scope of such device backups depend on your settings and on the rules of Apple or Google. We have no influence on the processing by these providers. You will find further information in the privacy information of the respective operating-system or cloud provider.
No cloud synchronisation of its own
The app provides no cloud synchronisation of its own, no user account and no server of its own for storing or synchronising your usage data.
7. External links and website
The app contains links to our website, in particular to the legal notice, privacy policy, contact options, copyright notices and legal information.
When you click such a link, the website is opened in the external system browser of your device. Only this establishes a connection to our web server. The website hoster then processes in particular technical connection data such as IP address, time of access and browser information.
The privacy policy of our website applies to this processing: https://vinayaki-yoga-und-coaching.com/privacy-policy-de-de
The app itself transmits no data to the website when merely displaying these links.
8. Fonts, media and third parties
The fonts, images, icons, audio files, glossary content and other media used in the app are bundled locally in the app package.
Among other things, the app uses locally bundled fonts. Downloading fonts from Google servers is technically deactivated. During normal operation of the app, no connection to Google Fonts or other external font providers is therefore established.
The app uses open-source libraries for local functions, including encrypted data storage, key management, local notifications, biometric or device-code checks, time zones, audio playback and rendering the user interface. These libraries transmit no data to us or to third parties during normal operation.
The app contains no analytics, advertising, tracking, crash-reporting, remote-config, licence-check or push SDKs.
9. Legal bases of processing
Where the app processes personal data locally, this is done on the following legal bases:
- Art. 6(1)(b) GDPR, where processing is necessary to provide the app functions you use, in particular the local storage of your entries, settings and exercise profiles
- Art. 6(1)(a) GDPR, where you consent to local notifications or actively trigger the optional saving of the recovery passphrase in the iCloud Keychain
- Art. 6(1)(f) GDPR, where processing serves the security and integrity of the locally stored data, in particular through encryption, key management, protection against unauthorised access and abuse prevention
The HealthKit permission request of the Apple Watch app leads to no processing of health data by us. It serves solely to technically keep the running exercise active on your device; no health data is read or written.
10. Storage period and deletion
Local usage data
Your usage data, settings and exercise profiles remain stored on your device until you delete them in the app or remove the app data via the system settings of your device.
In the app, under “Einstellungen → Daten & Sicherheit → Alle Daten löschen”, you can delete the contents of the encrypted database, local app settings and scheduled reminders.
Not covered by “Alle Daten löschen” are the database encryption key and the recovery passphrase in the secure system storage. These are deliberately kept separately so that a restore remains possible. On the Apple Watch, individual local queues or data sets can persist until the next synchronisation.
Uninstalling
Uninstalling the app removes all data stored in the app storage from the device — the encrypted database, the app settings and the restore file.
On iOS, the system keychain can keep the database key and the recovery passphrase beyond uninstallation, bound to the device. The app detects a reinstallation and removes these entries on first start; independently of that, you can delete them manually in the device settings at any time. On Android these entries are removed together with the app.
Device backups
Data already included in iCloud, Google Drive or other device backups remains stored there according to the retention and deletion rules you have chosen. Deleting data in the app does not automatically delete existing device backups.
You can manage or delete backups via the settings of your Apple or Google account.
11. Your rights
Since the essential data is processed exclusively locally on your device, in normal operation we hold no content of your drink entries, breathing exercises, search queries or app settings.
You can view, correct or delete your data directly in the app at any time. The app currently offers no export function of its own for usage data.
Where we process personal data in connection with your contacting us or other processing taking place outside the app, you have the following rights in accordance with the statutory provisions:
- Information
- Correction
- Deletion
- Restriction of processing
- Objection to processing
- Data portability
- Revocation of consent with effect for the future
- Complaint to a data protection supervisory authority
The data protection supervisory authority responsible for us is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein · Holstenstraße 98 · 24103 Kiel · https://www.datenschutzzentrum.de/
12. Children
The app is aimed at the general public. No personal data is collected or transmitted to us.
13. Contact
If you have questions about data protection in the app, you can contact us:
datenschutz@vinayaki-yoga-und-coaching.com
This privacy policy applies exclusively to the mobile app VYC SAHITYA. The separate privacy policy published there applies to the website.
14. Changes to this privacy policy
We will adapt this privacy policy if the app's functions, the technologies used or the legal requirements change.
Should future app versions introduce, for example, a user account, server synchronisation, community functions, external analytics tools or further data transfers, this privacy policy will be updated before they are introduced.
