Privacy Policy

Never Too Late · Information under Art. 13 / 14 GDPR

This page is a translation provided for your convenience. The German original is the legally binding version. German original →

Last updated: August 2026

This privacy policy explains which personal data is processed when you use "Never Too Late" (web app and native apps for Android and iOS), for what purposes, and what rights you have.

1. Controller

The controller responsible for data processing under the General Data Protection Regulation (GDPR) and other applicable data-protection laws is:

Coverset Studios Produktgesellschaft mbH
Alt-Marienfelde 26
12277 Berlin
Germany
Email: visitors@coverset.eu

2. General information on data processing

Never Too Late is available as a web app and as native apps for Android and iOS. In all variants, processing takes place exclusively on your device; we do not operate servers that process or store your calendar or location data.

Any data processing triggered by requests the app makes to Google services happens directly between your device (browser or native app) and Google. The operator of this site never has access to the content of that communication.

3. What data is processed?

3.1 Calendar data from Google Calendar

After your explicit consent via Google Sign-In (Google Identity Services), the app fetches events from your Google Calendar on your behalf (scope calendar.readonly). In particular, the following information is processed:

This data is kept exclusively in your device's working memory (browser or app) and is no longer available once the tab is closed, the app is exited, or the OAuth access token expires. It is not transmitted to any third party other than Google, the source of the data.

For participants in the server beta (Pro+), section 3.6 additionally applies: there, appointment data is also processed on our server.

3.2 GPS location

With your consent given via the browser dialog, the app continuously reads your current location using the Geolocation API. The following is processed:

Your location is:

By way of exception, if you participate in the server beta (Pro+), your most recent known position is stored on our server (see section 3.6).

3.3 Settings

App preference data (buffer time, mode of transport, look-ahead period, chosen display language) is stored in your browser's local storage (web app, e.g. localStorage) or your device's local app storage (Android/iOS). This data never leaves your device and can be deleted at any time via your browser settings or your device's app/system settings.

3.4 Reminder notifications

In the web app, notifications are generated via the browser's own Notifications API; in the native apps, reminders are delivered via operating system notifications and alarms (Android/iOS), which can trigger even when the app is closed. Content and trigger time are calculated locally on your device; no data is sent to external push services.

If you participate in the server beta (Pro+), reminders are additionally delivered via the push services of the operating-system vendors (Apple/Google) (see section 3.6).

3.5 Email address for the early-bird registration (waiting list)

On our website you can voluntarily join a waiting list ("Early Bird"). We process the data you provide in the form:

Purposes: notifying you when the app launches, sending the announced benefit code, possibly inviting you as a tester, and occasional information about the app around the launch. Your data is not shared with third parties for advertising purposes.

The form is provided via Google Forms; responses are stored in Google Sheets (processing by Google, see section 4.4 on third-country transfers). The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future and request deletion of your data — informally by email to visitors@coverset.eu.

3.6 Server beta (Pro+): server-side processing

As part of a voluntary, free beta phase of the "Pro+" feature set, we offer a server-assisted reminder function. Unlike the standard feature set (sections 3.1, 3.2 and 3.4), a server operated by us processes certain data even while the app is closed — this is the only way departure reminders can be delivered reliably as push notifications without the app having to be open.

Participation is voluntary. The processing described below takes place only if you explicitly sign up for the beta and give your consent when doing so. For all other users, processing remains entirely local as described in sections 3.1 to 3.4.

If you participate in the beta, our server processes the following data:

The sole purpose of this processing is to calculate and deliver departure reminders taking the current traffic situation into account. For route calculation, the server transmits your last known position as the starting point and the appointment location as the destination to Google (see sections 4.3 and 4.4); in the server beta this happens from our server instead of from your device. There is no use for advertising purposes, no profiling and no disclosure to third parties beyond the service providers named here.

The legal basis is your consent (Art. 6(1)(a) GDPR), given when you sign up for the beta. You can withdraw it at any time with effect for the future — by leaving the beta in the app, by revoking the app's permission at myaccount.google.com/permissions or informally by email to visitors@coverset.eu. After withdrawal, we delete the server data stored for your account (see section 7).

Hosting: the server is operated on the platform of Railway Corporation, 548 Market St PMB 68956, San Francisco, CA 94104, USA — a US provider whose infrastructure for our application runs in the EU region of Amsterdam (Netherlands). The data is therefore stored within the EU; however, as the provider is a US company, access from a third country cannot be entirely ruled out. We have concluded a data processing agreement with Railway pursuant to Art. 28 GDPR, including the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). More information: railway.com/legal/privacy.

4. Data shared with Google

The app's functionality relies on Google services. Using them transmits data to Google. The provider within the European Economic Area is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.

4.1 Google Identity Services (OAuth)

4.2 Google Calendar API

4.3 Google Maps JavaScript API / Directions API

4.4 Data transfers to third countries

Data is transferred to Google in the USA on the basis of the EU-US Data Privacy Framework (adequacy decision under Art. 45 GDPR) and, where required, on the basis of Standard Contractual Clauses under Art. 46 GDPR.

More information on data processing by Google can be found at: policies.google.com/privacy.

5. Hosting

The app is delivered via the platform Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Accessing the site inevitably causes technical data to be processed in the host's server logs, in particular:

The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the technical provision and security of the app. More information: vercel.com/legal/privacy-policy.

For participants in the server beta (Pro+), we additionally operate an application server with Railway Corporation (USA, EU hosting region Amsterdam); for details including the third-country notice, see section 3.6. Technical server logs (IP address, timestamp, user agent, requested resource) are also generated there; the legal basis in this respect is Art. 6(1)(f) GDPR (technical provision and security).

Audience measurement (Vercel Web Analytics): On our website (landing page and information pages) we use Vercel Web Analytics, a privacy-friendly visitor statistics service provided by the hosting provider named above. No cookies are set and no cross-site user profiles are created; visits are evaluated in aggregated form only (e.g. page views, referrer, country, browser type). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the statistical evaluation and improvement of our website).

6. Legal bases

You may withdraw any consent you have given at any time, with effect for the future, without affecting the lawfulness of processing carried out before the withdrawal.

7. Storage period

8. Cookies and tracking

The app does not set its own cookies and performs no tracking, analytics, or profiling. When Google services are invoked, Google may set its own cookies as part of authentication — the controller has no direct influence over this.

9. Data security

Transmission between your device and Google, as well as to the hosting provider, is consistently encrypted via HTTPS (TLS). Because no own server components or databases are used, the corresponding additional storage and protection obligations do not apply to the controller.

10. Your rights as a data subject

To the extent personal data is processed, you have the following rights:

To exercise your rights, please contact us using the details given in Section 1. An overview of the competent data-protection supervisory authorities in Germany is available at bfdi.bund.de.

11. Withdrawing consent — practical notes

12. Changes to this privacy policy

This privacy policy may be updated whenever legal requirements, the app's functionality, or the services used change. The current version is always available on this page.