EZZMOVE

Privacy Policy

This page describes what the EzzMove mobile app actually collects and stores. It is written from the app's real behaviour, not from a template.

Last updated

Needs legal reviewThis policy has not yet been reviewed by a lawyer. The factual descriptions of what the app does are accurate; the legal framing — legal bases, retention periods and the sections marked below — is not yet settled.

Who is responsible

The controller under Art. 4(7) GDPR is:

Mouhiyoudin Soulemana
Heilmannstraße 4B
70190 Stuttgart
Germany

Contact: ezzmovesupport@gmail.com — see also the Imprint.

EzzMove is operated by an individual, not a company. No data protection officer has been appointed.

Needs legal reviewThe sentence above states a fact and stops there. It previously went on to explain that the Art. 37 GDPR and § 38 BDSG thresholds are not met — that is a legal conclusion about our own obligations, not something we should assert unreviewed in a published policy. Legal review should confirm no DPO is required and may then restore the reasoning.

The short version

EzzMove stores the profile you create, who you follow, the events you mark, the classes you join and the schedule entries you write. Everything you import into Practice — your own videos and audio — stays on your device and is never uploaded by Practice.

EzzMove does not request your GPS location, does not read your contacts, and does not sell data to anyone.

Accounts and authentication

Authentication runs on Firebase Authentication, a Google service. You can use EzzMove in three states:

  • Guest. Opening the app creates an anonymous Firebase account. It has no email and no password. It exists only on that device — if you delete and reinstall the app, that guest account and its data cannot be recovered by us or by you.
  • Email and password. We store your email address. Passwords are handled by Firebase Authentication and are never visible to EzzMove.
  • Google Sign-In. Google provides your email address, display name and profile picture URL to EzzMove. We do not receive your Google password or access anything else in your Google account.

Upgrading a guest account to a permanent one keeps the same internal user ID, so the data you already created stays attached to you.

What is stored in the cloud

The following is stored in Google Cloud Firestore, keyed to your user ID:

  • Profile — display name, email address, avatar image, biography text, and a location you type yourself as free text (for example a city name). This is a text field, not a GPS reading.
  • Follows — which dancers, organizers and creators you follow, and who follows you.
  • Event interactions — which events you marked as Going, Interested or Saved. Going and Interested counts are visible publicly on the event.
  • Studio and class memberships — which studios and classes you belong to and in which role. Studio owners and teachers can see the members of their own studio and classes.
  • Personal schedule — the entries you create in My Schedule, including title, date, time, optional location and optional notes. These are private to you and are not readable by other users.
  • Notification preferences — which kinds of notification you have switched on.
  • Uploaded images — avatars and event cover images you upload are stored in Firebase Storage.

What stays on your device

Media you bring into Practice — videos from your gallery and audio from Files — is copied into EzzMove’s own storage on your device and is used only for playback there. Practice does not upload it. Your Practice library, your app language and which tips you have dismissed are stored locally on the device as well.

Because this data is local, uninstalling the app deletes it, and it does not transfer to a new device.

Camera and microphone

The Record feature uses your camera and microphone to capture practice footage. Recording happens on your device and the result is saved to your local Practice library. EzzMove does not upload your recordings.

You are asked for these permissions the first time you use Record, and you can decline. Declining disables Record; the rest of the app continues to work.

Push notifications

Notifications are optional. If you allow them, Firebase Cloud Messaging issues a device token, which we store together with your user ID and the platform (iOS or Android) so we know where to send a notification. One account can have several devices registered.

Notifications are sent by our own Cloud Functions and are limited to: reminders before an event you are going to, changes and cancellations for such an event, new assignments and changes in classes you are enrolled in, and new followers. Your preferences are checked on the server before anything is sent, so a notification you switched off is never dispatched.

If you decline notification permission, no token is stored and no push is sent. Notifications still appear inside the app.

Processors and where data is held

EzzMove uses Google Firebase (Authentication, Firestore, Storage, Cloud Messaging and Cloud Functions) as its backend. Our Cloud Functions are deployed to Google’s europe-west3 region (Frankfurt).

Firestore and Storage location: [to be confirmed in the Firebase Console]

Verify, then fill inThe Firestore and Storage location is a lookup in the Firebase Console — Project settings → General — and must replace the placeholder above with the actual value. It is a different setting from the Functions region, so it cannot be inferred from it, and guessing it would be a factual claim about where user data physically lives.
Needs legal reviewThe Google Cloud data processing agreement reference, and any statement about international transfers, need legal review — and depend on the answer above.

Legal basis and retention

Needs legal reviewThe GDPR legal bases (Art. 6) for each processing purpose, and the retention periods, need legal review before publication. As a factual input for that review: profile, follows, interactions, memberships and schedule entries are retained until you delete your account; device tokens are removed on sign-out, on account deletion, and automatically when the messaging service reports them as no longer valid.

Your rights

Under the GDPR you have the right to access, rectify and erase your data, to restrict or object to processing, and to data portability. You can exercise these by writing to ezzmovesupport@gmail.com.

You can delete your account and its data yourself — see Delete your account.

You also have the right to lodge a complaint with a supervisory authority. For EzzMove, established in Stuttgart, the competent authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
baden-wuerttemberg.datenschutz.de

Only the authority’s name and official website are given here. Postal address, telephone and email are intentionally omitted rather than reproduced from memory — the authority publishes its current contact details itself, and a stale address in a privacy policy sends complaints nowhere.

Children

Founder decisionOne decision, four places — and one is already answered. The live App Store listing declares a content rating of 4+. Nothing in these policies states a minimum age, so the two do not currently agree. Whatever is decided must be stated identically here, in the other policy page, in the App Store rating and in the Google Play target-audience declaration — a mismatch is a review rejection. Note what 4+ implies: it puts children in scope, so if it stands, parental-consent wording under Art. 8 GDPR is required, and Google Play’s Families policy will apply to the Android release.

Contact

Questions about this policy: ezzmovesupport@gmail.com