Never Too Late · Information under Art. 13 / 14 GDPR
This page is a translation provided for your convenience. The German original is the legally binding version. German original →
Last updated: August 2026
This privacy policy explains which personal data is processed when you use "Never Too Late" (web app and native apps for Android and iOS), for what purposes, and what rights you have.
The controller responsible for data processing under the General Data Protection Regulation (GDPR) and other applicable data-protection laws is:
Coverset Studios Produktgesellschaft mbH
Alt-Marienfelde 26
12277 Berlin
Germany
Email: visitors@coverset.eu
Never Too Late is available as a web app and as native apps for Android and iOS. In all variants, processing takes place exclusively on your device; we do not operate servers that process or store your calendar or location data.
Any data processing triggered by requests the app makes to Google services happens directly between your device (browser or native app) and Google. The operator of this site never has access to the content of that communication.
After your explicit consent via Google Sign-In (Google Identity Services), the
app fetches events from your Google Calendar on your behalf (scope
calendar.readonly). In particular, the following information is
processed:
This data is kept exclusively in your device's working memory (browser or app) and is no longer available once the tab is closed, the app is exited, or the OAuth access token expires. It is not transmitted to any third party other than Google, the source of the data.
For participants in the server beta (Pro+), section 3.6 additionally applies: there, appointment data is also processed on our server.
With your consent given via the browser dialog, the app continuously reads your current location using the Geolocation API. The following is processed:
Your location is:
By way of exception, if you participate in the server beta (Pro+), your most recent known position is stored on our server (see section 3.6).
App preference data (buffer time, mode of transport, look-ahead period, chosen
display language) is stored in your browser's local storage (web app, e.g.
localStorage) or your device's local app storage (Android/iOS).
This data never leaves your device and can be deleted at any time via your
browser settings or your device's app/system settings.
In the web app, notifications are generated via the browser's own Notifications API; in the native apps, reminders are delivered via operating system notifications and alarms (Android/iOS), which can trigger even when the app is closed. Content and trigger time are calculated locally on your device; no data is sent to external push services.
If you participate in the server beta (Pro+), reminders are additionally delivered via the push services of the operating-system vendors (Apple/Google) (see section 3.6).
On our website you can voluntarily join a waiting list ("Early Bird"). We process the data you provide in the form:
Purposes: notifying you when the app launches, sending the announced benefit code, possibly inviting you as a tester, and occasional information about the app around the launch. Your data is not shared with third parties for advertising purposes.
The form is provided via Google Forms; responses are stored in Google Sheets (processing by Google, see section 4.4 on third-country transfers). The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future and request deletion of your data — informally by email to visitors@coverset.eu.
As part of a voluntary, free beta phase of the "Pro+" feature set, we offer a server-assisted reminder function. Unlike the standard feature set (sections 3.1, 3.2 and 3.4), a server operated by us processes certain data even while the app is closed — this is the only way departure reminders can be delivered reliably as push notifications without the app having to be open.
Participation is voluntary. The processing described below takes place only if you explicitly sign up for the beta and give your consent when doing so. For all other users, processing remains entirely local as described in sections 3.1 to 3.4.
If you participate in the beta, our server processes the following data:
calendar.readonly) that allows the server to retrieve appointments on your behalf.The sole purpose of this processing is to calculate and deliver departure reminders taking the current traffic situation into account. For route calculation, the server transmits your last known position as the starting point and the appointment location as the destination to Google (see sections 4.3 and 4.4); in the server beta this happens from our server instead of from your device. There is no use for advertising purposes, no profiling and no disclosure to third parties beyond the service providers named here.
The legal basis is your consent (Art. 6(1)(a) GDPR), given when you sign up for the beta. You can withdraw it at any time with effect for the future — by leaving the beta in the app, by revoking the app's permission at myaccount.google.com/permissions or informally by email to visitors@coverset.eu. After withdrawal, we delete the server data stored for your account (see section 7).
Hosting: the server is operated on the platform of Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA — a US provider whose infrastructure for our application runs in the EU region of Amsterdam (Netherlands). The data is therefore stored within the EU; however, as the provider is a US company, access from a third country cannot be entirely ruled out. We have concluded a data processing agreement with Railway pursuant to Art. 28 GDPR, including the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). More information: railway.com/legal/privacy.
The app's functionality relies on Google services. Using them transmits data to Google. The provider within the European Economic Area is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
calendar.readonly scopeData is transferred to Google in the USA on the basis of the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR) and, where required, on the basis of Standard Contractual Clauses under Art. 46 GDPR.
More information on data processing by Google can be found at: policies.google.com/privacy.
The app is delivered via the platform Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Accessing the site inevitably causes technical data to be processed in the host's server logs, in particular:
The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the technical provision and security of the app. More information: vercel.com/legal/privacy-policy.
For participants in the server beta (Pro+), we additionally operate an application server with Railway Corporation (USA, EU hosting region Amsterdam); for details including the third-country notice, see section 3.6. Technical server logs (IP address, timestamp, user agent, requested resource) are also generated there; the legal basis in this respect is Art. 6(1)(f) GDPR (technical provision and security).
Audience measurement (Vercel Web Analytics): On our website (landing page and information pages) we use Vercel Web Analytics, a privacy-friendly visitor statistics service provided by the hosting provider named above. No cookies are set and no cross-site user profiles are created; visits are evaluated in aggregated form only (e.g. page views, referrer, country, browser type). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the statistical evaluation and improvement of our website).
You may withdraw any consent you have given at any time, with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.
localStorage; Android/iOS: local app storage): until manually deleted by you (e.g. via browser or app/system settings, or by disconnecting the app from your Google account).The app does not set its own cookies and performs no tracking, analytics, or profiling. When Google services are invoked, Google may set its own cookies as part of authentication — the controller has no direct influence over this.
Transmission between your device and Google, as well as to the hosting provider, is consistently encrypted via HTTPS (TLS). Because no own server components or databases are used, the corresponding additional storage and protection obligations do not apply to the controller.
To the extent personal data is processed, you have the following rights:
To exercise your rights, please contact us using the details given in Section 1. An overview of the competent data-protection supervisory authorities in Germany is available at bfdi.bund.de.
This privacy policy may be updated whenever legal requirements, the app's functionality, or the services used change. The current version is always available on this page.