Privacy Policy for the Maru App
Last updated: 29 August 2026
This Privacy Policy explains how personal data is processed when you use the Maru mobile app. A separate privacy policy applies to the heymaru.com website.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Manuel Beyerc/o Impressumservice Dein-Impressum
Stettiner Str. 41
35410 Hungen
Germany
Privacy enquiries: privacy@heymaru.com
General contact: hello@heymaru.com
Website: https://heymaru.com
Imprint: https://heymaru.com/imprint
2. Data processed by Maru
Account and sign-in
When you sign in to Maru, we process data including a technical user ID, your email address, display name, language setting, account creation or sign-in timestamps and technical authentication data. Maru does not store passwords in plain text.
We use this data to create and secure your account and provide your personal settings. The legal basis is Art. 6(1)(b) GDPR.
Personal content and memories
Maru lets you voluntarily record personal text and moments. These may include text, local date, creation and modification timestamps, and technical display data such as pebble, wave and layout parameters. This content is currently stored locally on your device. It is not used for advertising, profiling, topic analysis or training generative models. If we offer private cloud sync in the future, we will update this policy before activation to explain its scope, recipients and retention period.
Local processing is necessary to provide the app functions you request under Art. 6(1)(b) GDPR. You decide whether to enter personal text.
Stories and usage progress
The app downloads editorial stories, images and, where available, audio. To provide your library and let you continue a story, we may process the story ID, language version, opening timestamps, reading progress and audio position. A successfully opened item may be associated with your account; this does not turn the editorial text itself into a private profiling record.
We process this data to provide and synchronise story features under Art. 6(1)(b) GDPR.
Notifications
If you enable notifications, Maru processes a technical device or push token, platform, app ID, language and opt-in status. These data are needed to deliver the morning story notification. Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM) act as technical delivery services. The evening reminder is scheduled locally on your device.
Processing takes place only after you enable notifications and is based on your consent under Art. 6(1)(a) GDPR. You can withdraw consent at any time in Maru or the iOS settings with effect for the future. Personal text is never included in push notifications.
Technical security and App Check
To protect the app and its interfaces, we may process technical data such as app instance, app version, platform, device-integrity signals, authentication status, IP address, request timestamp and limited error or security logs. Firebase App Check uses App Attest and, where necessary, DeviceCheck on Apple devices to recognise authorised app instances.
The purpose is secure and reliable operation and the prevention and detection of misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the security and availability of Maru.
Local storage and cache
Maru stores settings, personal content, library and reading progress, and downloaded images and audio locally on your device. This provides the requested features and some offline use. You can remove these data using the available deletion functions. When you delete the app, iOS removes local app data in accordance with its platform rules.
3. No advertising profiles or content analysis
Maru does not sell personal data. We do not use your personal text for advertising, semantic evaluation, mood analysis or automated decisions. No production analytics or crash-reporting service is currently active in the app. If this changes, we will update this policy before activation; personal text must never be collected by such a service.
4. Recipients and service providers
We use Google Firebase or Google Cloud and Apple services for operation, authentication, databases, file delivery, app-integrity checks and push delivery:
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland;
- Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA;
- Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, and affiliated Apple companies.
These providers process data on our behalf or as independent controllers where required for their platform services. For further information, see the privacy policies of Google and Apple.
Editorial service accounts have no access to personal Maru data.
5. International transfers
When Google and Apple services are used, processing outside the European Union or European Economic Area, particularly in the United States, cannot be fully excluded. Where no adequacy decision applies, such transfers are based on appropriate safeguards, in particular Standard Contractual Clauses under Art. 46 GDPR. Google LLC and Apple Inc. are certified under the EU-US Data Privacy Framework to the extent the relevant processing is covered.
6. Retention
We retain personal data only for as long as necessary for its purpose:
- account and profile data: until account deletion, unless statutory duties require longer retention;
- push registration: until opt-out, device deregistration or account deletion; invalid tokens are removed;
- story progress and library: until you delete them or delete your account;
- local personal content and caches: until deletion in the app, account deletion or removal of the app;
- security logs: only for the limited period required for security and error analysis, or longer where necessary to pursue a specific incident;
- data subject to statutory retention: for the applicable statutory period.
7. Deleting your account and data
You can start deletion of your account and associated data in the app under “My Maru”, or contact privacy@heymaru.com. If the app requires you to sign in again, this protects against unauthorised deletion. Account-related cloud data and local private Maru data are removed as part of the deletion process unless a legal retention duty or another statutory exception applies. Backups may remain until their scheduled overwrite and will not be restored to productive use.
8. Your rights
Subject to the statutory requirements, you have the right to:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR), and
- withdraw consent with future effect (Art. 7(3) GDPR).
To exercise your rights, email privacy@heymaru.com.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for the controller's registered location is:
The Hessian Commissioner for Data Protection and Freedom of Information (HBDI)Gustav-Stresemann-Ring 1
65189 Wiesbaden
Germany
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
https://datenschutz.hessen.de
9. Automated decision-making
Maru does not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
10. Security and updates
We use appropriate technical and organisational measures to protect your data. However, no data transmission or storage can be guaranteed to be entirely risk-free.
We update this policy when Maru, the services we use or applicable law changes. The current version is available at https://heymaru.com/app/privacy.