PathCraft

Legal Documents

Terms of Use, Privacy Notice, and Notice on External AI, Speech, and Translation Services
As of: 18 April 2026

Provider:
Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu
VAT identification number pursuant to Section 27a of the German VAT Act: DE460849192


Terms of Use and Safety Notices for PathCraft

As of: 18 April 2026
Contact: kontakt@SuGreenX.eu

1. Provider and Scope

PathCraft is provided, and the contractual partner for the use of PathCraft, by:

Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu
VAT identification number pursuant to Section 27a of the German VAT Act: DE460849192

  1. These Terms of Use govern the use of the PathCraft app, including the core functions provided within the app, optional feature unlocks, trial access, credits, entitlements, consent dialogs, and integrated third-party functions.
  2. In addition, the Privacy Notice for PathCraft and, for separately activated AI, speech, or translation functions, the Terms and Privacy Notice for External AI, Speech, and Translation Services apply.
  3. To the extent the app is obtained through an app store or purchases are processed through an app store, the terms of the respective store may apply in addition. Mandatory statutory consumer rights remain unaffected.
  4. PathCraft is intended for users who use the app at their own responsibility for lawful purposes. Any use contrary to applicable law or contrary to these terms is not permitted.

2. Nature of the App and Description of Services

  1. PathCraft is a digital leisure, planning, communication, and assistance tool.
  2. In particular, the app may be used to display maps, play back and plan routes, use imported GPX or KML files, display POI information, and, optionally, use external AI, speech, translation, weather, video, or feature-unlock functions.
  3. According to the described system architecture, the core use of the app is largely designed to operate locally. Many contents and settings remain on the user's device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used by the user.
  4. Certain functions depend on third-party platforms or the operator backend. These may include, in particular, Apple Maps or MapKit, Apple Weather or WeatherKit, Sign in with Apple, the App Store, optional Google Street View functions, optional YouTube functions, user-selected external AI, speech, or translation services, as well as optional operator functions for trial access, entitlements, credits, or consent records.
  5. There is no claim to a specific third-party integration, to an unchanged operation of individual external services at all times, or to the permanent availability of every optional additional function, unless mandatory law provides otherwise.
  6. The app operator has no general duty to individually pre-check, continuously monitor in real time, or substantively verify imported files, user content, routes, attachments, translations, or AI outputs, unless such a duty is expressly required by law.

3. Route Playback; No Navigation

  1. The route playback shown in PathCraft serves solely as a non-binding assistance feature for orientation along a route imported by the user or created within the app.
  2. PathCraft is not an officially approved product, not a product reviewed under safety law, and not a product intended as navigation that complies with traffic-law standards or approvals. In particular, the app is not provided as navigation approved for road traffic use.
  3. The app does not replace navigation in the legal or technical sense, official signage, traffic rules, closure information, weather warnings, emergency information, nature conservation rules, access restrictions, or the user's own safe assessment of the situation on site.
  4. For imported GPX or KML files, routes created within the app, and walking or cycling routes suggested by Apple Maps or comparable services, the following applies: they are merely route suggestions or playback aids. In particular, no assurance is given that a route is current, complete, legally permissible, safe, walkable, rideable, barrier-free, free of closures, or compatible with local traffic, access, conservation, ownership, or usage rules.
  5. The actual conditions on site, official or local signage, orders by authorities, ownership situations, protected-area rules, weather and hazard conditions, and the user's own decision are always decisive.
  6. Route playback must not be used as the sole basis for safety, traffic, rescue, emergency, or other consequential decisions.
  7. The app must not be used in a manner that endangers the user or third parties, unlawfully impairs attention, or violates traffic, safety, or other legal requirements.

4. Maps, Weather, Street View, YouTube, and Other Third-Party Sources

  1. Map display, place or address search, geocoding, map object resolution, Look Around, route calculation, and comparable map functions may depend wholly or partly on Apple services.
  2. Weather functions may depend on Apple Weather, WeatherKit, or connected weather data sources.
  3. To the extent PathCraft offers a credit-based weather function, the currently described setup may consume one credit per weather location per calendar month. In order to calculate usage correctly, recognise weather locations already billed within the same month, prevent misuse, and keep the credit balance traceable, a pseudonymous software or installation ID may be used together with a month and location reference. Details are set out in the privacy notice.
  4. Optional Street View functions or Street View metadata may depend on Google services and may require a Google API key supplied by the user.
  5. Optional YouTube functions are not a mandatory part of the core app. To the extent the app offers optional YouTube search or video opening, such access only takes place after explicit activation by the user and usually by passing a target URL or search parameters to the external service. YouTube is not required for maps, GPX, routes, or local content.
  6. Third-party sources may be incomplete, delayed, regionally restricted, technically disrupted, or inaccurate and may be subject to their own contractual, licence, and privacy terms.

5. AI, Speech, and Translation Functions

  1. PathCraft may provide optional AI, speech, transcription, text-to-speech, or translation functions or technical interfaces for them.
  2. Such functions serve solely to assist with communication, understanding, orientation, information preparation, or operation. They do not replace professional review and do not make independent legally binding, medical, emergency-related, or other safety-critical decisions for the user.
  3. Outputs from such functions may be incomplete, inaccurate, misleading, biased, out of context, or linguistically or legally unsuitable. The user must independently verify the results before using them.
  4. The app operator does not owe the factual accuracy, completeness, usability, or legal suitability of individual AI, speech, or translation outputs.

6. Duties and Responsibility of the User

  1. The user is responsible for ensuring that they have all necessary rights, permissions, and legal bases to import files, routes, images, attachments, audio, conversation content, API keys, or other content into the app, store it locally, transfer it to third parties, or otherwise use it through the app.
  2. Before and during use, the user must independently check the actual situation. This applies in particular to terrain, weather, visibility, closures, construction sites, water levels, traffic, private property, protected areas, animals, rescue situations, and all local rules or prohibitions.
  3. If the user uses live translation, audio transcription, speech-to-text, text-to-speech, conversation history, or similar functions, the user is solely responsible for informing affected conversation partners in advance and obtaining any consents, permissions, or other legal bases required under the applicable law.
  4. The user is responsible for complying with the terms, age requirements, territorial restrictions, tariff requirements, and privacy documents of the third-party providers selected by the user.
  5. If iCloud sync is enabled or the same Apple account is used on multiple devices, routes, files, histories, and other app contents may become visible on those devices. The user is responsible for determining which devices and persons have access to the Apple account or to those devices.
  6. The user must adequately protect their devices, credentials, and, where applicable, API keys stored by the user.

7. User-Supplied API Keys and External Services

  1. Certain functions may require or support an API key of an external service that is supplied by the user (BYOK, Bring Your Own Key).
  2. To the extent the user uses their own API key and the app transmits the request directly to the selected third-party provider, the app operator essentially provides the technical interface, local management logic, and the limited operator functions described in the legal texts.
  3. The subsequent processing by the selected third-party provider is governed by that provider's own contractual, usage, and privacy documents.
  4. The enabling of certain BYOK functions may depend on separate consent, permission, or notice dialogs. For security, misuse-prevention, or evidentiary reasons, the app operator may make use of such functions conditional on such confirmations.

8. Trials, Purchases, Entitlements, and Credits

  1. PathCraft may offer optional trials, in-app purchases, tip or support purchases, credits, usage-based services, and server-side entitlements.
  2. Whether a service is provided free of charge, on a trial basis, as a one-time purchase, on a subscription term, on a usage basis, or otherwise is determined by the description shown in the respective purchase, trial, or unlock dialog.
  3. To the extent purchases are processed via the App Store, payment processing, cancellation, refunds, and store-side contract handling are additionally governed by the terms of the respective store. Statutory rights of the user remain unaffected.
  4. Entitlements, feature unlocks, and credits may be technically managed, verified, restored, synchronised, or protected against misuse on the server side.
  5. To the extent usage-based services are offered, use may be limited or tracked by credits, quotas, usage levels, or comparable entitlement logic.
  6. For credit-based weather queries, the current usage logic may provide that one credit covers one weather location for one calendar month. The description of the respective function shown in the app is decisive. The required proof of consumption does not serve to continuously monitor the user's actual movements and does not serve to substantively control the weather data.
  7. There is no entitlement to free restoration, goodwill credit, or manual correction outside mandatory statutory claims unless this has been expressly promised.

9. Right to Use the App

  1. The user receives a non-exclusive, non-transferable right to use PathCraft for their own lawful purposes within the scope of these terms and the technical purpose of the app.
  2. To the extent permitted by law, the user is prohibited from copying, selling, renting, sublicensing, decompiling, circumventing security measures, misusing automation, or using the app or parts of it in a way that violates the rights of third parties or the security of the service.
  3. Mandatory statutory rights, in particular legally permitted acts for interoperability or error correction, remain unaffected.

10. Availability, Further Development, and Changes

  1. The app and individual functions may be updated, adjusted, restricted, or discontinued for error correction, security, compatibility, further development, legal adaptation, or in response to changes made by third-party platforms.
  2. To the extent a paid digital product is permanently provided to the user, changes will be made within the statutory framework applicable to digital products. Mandatory statutory rights of the user remain unaffected.
  3. The app operator is entitled to block or restrict functions if this is required for security reasons, to prevent misuse, to comply with legal obligations, or because of serious violations of these terms.

11. Liability

  1. The app operator shall be liable without limitation in cases of intent and gross negligence, for damage arising from injury to life, body, or health, under the German Product Liability Act, and to the extent the app operator has exceptionally assumed an express guarantee.
  2. In the event of slightly negligent breach of a material contractual obligation, liability is limited to the foreseeable damage typical for the contract. Material contractual obligations are obligations whose fulfilment makes the proper performance of the contract possible in the first place and on whose compliance the user may regularly rely.
  3. In all other respects, the liability of the app operator for slight negligence is excluded.
  4. The above liability rules apply accordingly to the legal representatives, employees, and vicarious agents of the app operator.
  5. Mandatory statutory defect rights of the user in relation to paid digital products remain unaffected. Mandatory data protection, consumer protection, or other statutory claims also remain unaffected.
  6. Irrespective of the app operator's liability, safety-related decisions, the selection and use of real routes and areas, and the actual use of routes, translations, AI outputs, or other notices remain the responsibility of the user.

12. Term and Termination

  1. The user may stop using the app at any time by no longer using it and, if desired, deleting locally stored content.
  2. To the extent server-side authorisations for optional functions exist, the app operator may block or terminate them in whole or in part if there is good cause. Good cause exists in particular in cases of serious misuse, significant security risks, criminal or unlawful use, deception regarding authorisations, or a sustained disruption of service operations.
  3. Statutory payment, record-keeping, or retention obligations that have already arisen remain unaffected by termination.

13. Governing Law and Final Provisions

  1. The law of the Federal Republic of Germany applies, excluding the UN Convention on Contracts for the International Sale of Goods. In relation to consumers, this choice of law applies only to the extent that it does not deprive the consumer of the protection afforded by mandatory provisions of the law of the state of the consumer's habitual residence.
  2. Should individual provisions of these terms be or become wholly or partly invalid, the validity of the remaining provisions shall remain unaffected. The statutory provisions shall apply in place of the invalid provision.
  3. Changes to these terms will be communicated to the user in an appropriate manner. Mandatory statutory limits on amendments to contracts remain unaffected with respect to services already provided for consideration.

14. Contact and Provider Information

Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu
VAT identification number pursuant to Section 27a of the German VAT Act: DE460849192


Privacy Notice for PathCraft

As of: 18 April 2026
Contact for privacy inquiries: kontakt@SuGreenX.eu

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in this privacy notice is:

Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu

Privacy-related inquiries may be sent to the contact details above.

2. Short Overview

3. Scope and Allocation of Roles

  1. This privacy notice describes the processing of personal data by the app operator in connection with PathCraft.
  2. According to the described architecture, PathCraft is largely designed to operate locally. Many contents and settings remain on the user's device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used by the user.
  3. This privacy notice distinguishes between local storage on the device or in the user's private iCloud area, technical, purchase-related, consent-related, and security-related data processed online by the app operator, and processing operations that the user directly triggers with the respective third-party provider by using external third-party functions.
  4. To the extent data is transmitted directly from the app to a third-party provider selected by the user and the app operator does not receive that content through its own backend, this notice describes the data flow and the role of the app only in a supplementary manner. The third-party provider's own privacy and contractual documents are decisive for the subsequent processing by that provider.

4. Basic Processing Principles in PathCraft

  1. The core functions of the app do not require a general online account or a permanent online content profile with the app operator.
  2. According to the described system architecture, local file contents, conversation contents, translations, attachments, routes, imported GPX or KML files, images, audio, and comparable content data are not collected, analysed, or shared online by the app operator for its own advertising, profiling, or general tracking purposes.
  3. This does not preclude the app operator from processing limited technical data relating to feature unlocks, purchases, credits, weather credit usage, consent records, misuse prevention, integrity checks, error analysis, or simple usage aggregates to the extent this is necessary to provide and secure the functions offered.
  4. Where conversation, translation, or transcription histories are stored in the app, this is generally done locally on the device or—if iCloud synchronisation is enabled—in the private iCloud area of the user's Apple account, until the user changes or deletes them.

5. Operator-Side Online Processing and Storage Areas

5.1 User Mapping, Trials, and Activations

Technical storage areas: users, trial_grants, apple_transactions, entitlements

Processed data: Depending on usage, this includes in particular a pseudonymous Apple identifier derived from Sign in with Apple, internal user ID, session or access tokens, trial start and end times, product and product type, transaction ID, original transaction ID, app account token, purchase, expiry, revocation, or unlock times, as well as authorisation and status data.

Purposes:

Legal bases:

Retention period or criteria: The data is stored for as long as it is required for the respective trial, purchase, unlock, restoration, or evidentiary function. It is then deleted or anonymised unless statutory retention obligations or legitimate interests in asserting, exercising, or defending legal claims prevent this.

5.2 Credits, Weather Credit Usage, Tip Purchases, and Managed Usage Events

Technical storage areas: credit_ledger, managed_usage_events, tip_purchases, and—where implemented separately for technical reasons—functionally comparable storage areas for monthly weather credit usage records

Processed data: Depending on the function, this includes in particular internal user or installation references, pseudonymous software or installation ID, credit bookings, debit or credit events, product reference, functional area, timestamps, month period, usage-related counters, billing data relating to models, providers, or weather functions, technical location references for weather requests, references to purchases or feature unlocks, as well as status and verification data.

Purposes:

Legal bases:

Retention period or criteria: Booking, purchase, and billing-related data is regularly stored until the respective contractual, evidentiary, or retention purpose no longer applies; statutory commercial, tax, or other retention obligations remain unaffected. Purely technical usage events are deleted, condensed, or anonymised as soon as they are no longer required for billing, prevention of misuse, or defence of rights. Weather credit usage records are kept in a personal or pseudonymous form only for as long as required for the ongoing monthly logic, credit calculation, restoration, error resolution, prevention of misuse, or defence of rights; they are then deleted, condensed, or anonymised unless overriding evidentiary or retention obligations apply.

Special note on weather credits: To the extent PathCraft offers a credit-based weather function, the currently described setup may allow one credit to cover one weather location for one calendar month. In order for the app to calculate usage correctly, recognise weather locations already billed within the same month, keep credit balances traceable, and prevent misuse, the operator backend may store, per pseudonymous software or installation ID, whether a weather query for a particular weather location or technical location reference has already been billed in a given monthly period. To the extent technically possible and sufficient for billing, full clear-text addresses should not be stored as the location reference; instead, minimised references such as normalised, truncated, or gridded coordinates, hash, geohash, or provider location identifiers should be used. This processing does not serve to create a movement profile, presence profile, or advertising profile.

No separate consent is obtained for this necessary credit and usage record to the extent the processing is required exclusively to provide the credit-based weather function requested by the user, to maintain the credit balance, to restore usage status, to clarify errors, or to prevent misuse. Should any additional, non-essential analysis, convenience history, profiling, or advertising use of such weather usage data be planned in the future, this would only take place on a separate legal basis and, where legally required, after separate consent.

If a software or installation ID is stored on or read from the device for this function, this occurs, for the required credit function, only to the extent necessary to provide the expressly requested digital service. Non-essential device access, for example for general analytics or advertising purposes, is not covered by this.

Important note: To the extent the app operator offers managed AI usage, managed_usage_events according to this notice refers to billing-related and usage-related event data. This does not automatically describe storage of the actual content data such as prompts, audio, responses, images, or attachments in the operator backend, and such storage would have to be disclosed separately if it actually takes place.

5.3 Consent and Policy Records

Technical storage areas: byok_consents, byok_consent_events, service_consent_policies, service_consents, service_consent_events, route_playback_consent_policies, route_playback_consent_events

Processed data: Depending on the function, this includes in particular installation or subject identifier, provider, functional area, policy version, text version, language, region, platform, app version, build, UI context, hash values, links to the legal texts shown, event type such as shown, accepted, declined, or withdrawn, time, and limited evidentiary data.

Purposes:

Legal bases:

Retention period or criteria: The data remains stored for as long as the relevant function is used or can be reactivated and for as long as records of display, consent, withdrawal, or permission events are required for legal, security, or defence purposes. Policy text versions and hash values may be retained for longer to the extent event logs refer to them.

5.4 Installation Authenticity, Technical Integrity, and Simple Usage Aggregates

Technical storage areas: route_playback_app_attest_installations, route_playback_usage_daily

Processed data: Depending on the function, this includes in particular technical installation identifiers, attestation-related or registration-related verification data, event type, timestamps, platform and language data, and daily usage aggregates or counters.

Purposes:

Legal bases:

Retention period or criteria: Security and installation data is stored for as long as required for integrity checks and misuse prevention. Simple daily usage aggregates are deleted, condensed, or anonymised as soon as they are no longer needed for monitoring, capacity planning, or security evaluation.

5.5 Support and Communication

If the user contacts the app operator, for example by email at kontakt@SuGreenX.eu, the app operator may process the contact details communicated by the user, the content of the request, attachments, as well as processing and response data.

Purposes: handling support inquiries, error analysis, performance of the contract, communication, and defence of rights.
Legal bases: Article 6(1)(b) GDPR to the extent the request relates to a contractual relationship or pre-contractual measures; otherwise Article 6(1)(f) GDPR.
Retention period: until final handling of the inquiry and beyond only to the extent statutory retention obligations or legitimate interests in documentation and defence of rights apply.

6. Third-Party Processing Triggered Directly from the App

6.1 Apple Services

When using map, search, geocoding, Look Around, route calculation, weather, Sign in with Apple, App Store, or iCloud-related functions, search texts, addresses, coordinates, start and destination points, location data, query context, Apple-related identifiers, purchase or sign-in information, as well as synchronised app content may, depending on the function, be transmitted directly to Apple or to services connected via Apple.

To the extent the app operator does not receive this content through its own backend, Apple's own documents govern the subsequent processing by Apple. The technical maintenance of a weather credit usage record by the app operator must be distinguished from this and does not mean that the app operator monitors the accuracy of the weather data or controls actual on-site use.

6.2 Google Services and YouTube

For optional Street View or Street View metadata functions, search terms, coordinates, metadata queries, and, where applicable, a Google API key used by the user may, depending on the function, be transmitted directly to Google services.

Upon the explicit invocation of optional YouTube functions, the app may pass search terms, target URLs, coordinates, search radius, or other parameters selected by the user to a Google or YouTube link and open the external YouTube app or an external website. Any further processing from the moment the external service is opened is carried out by the respective provider under its own terms and privacy notices.

6.3 External AI, Speech, and Translation Services

When using external AI, speech, transcription, text-to-speech, or translation services, texts, audio data, voices, images, attachments, transcriptions, translations, speech outputs, system instructions, conversation states, and, where applicable, contextual data may, depending on the function, be transmitted directly to the third-party provider selected by the user.

Where the user uses their own API key and the app sends the request directly to the third-party provider, the app operator, according to the described architecture, generally does not receive this content data through its own backend. This does not affect the limited operator-side processing described in Section 5, for example for consent records, feature unlocks, credits, security events, or managed billing data.

The subsequent processing by the respective third-party provider is governed by that provider's current privacy and contractual documents.

7. Categories of Recipients

Depending on the function, personal data may be transmitted to the following recipients or categories of recipients:

Should additional technical processors be added in the future for operator purposes, this privacy notice will be updated in the event of material changes.

8. Transfers to Third Countries

  1. Depending on the third-party function used and on the operator service provider involved, personal data may be transferred to countries outside the European Union or the European Economic Area, in particular to the United States or to other countries in which the respective provider or its subprocessors operate.
  2. To the extent the app operator uses its own service providers with a third-country nexus—currently in particular Cloudflare for hosting, edge delivery, security, and backend functions—such transfers take place only in accordance with Articles 44 et seq. GDPR.
  3. Depending on the recipient and data flow, the legal transfer mechanisms may include in particular:
    • an adequacy decision pursuant to Article 45 GDPR,
    • appropriate safeguards pursuant to Article 46 GDPR, in particular EU Standard Contractual Clauses,
    • and, where required, supplementary technical and organisational protection measures.
  4. To the extent a recipient is validly certified under a relevant adequacy framework such as the EU-U.S. Data Privacy Framework, the transfer may also be based on that framework.
  5. For third-party providers that the user selects themselves or uses directly via their own API keys or external links, transfers to third countries take place directly to the respective third-party provider or service opened by the user. The concrete processing locations, storage practices, and protection mechanisms are then determined by the current documents of that provider.

9. Requirement to Provide Data

  1. For the mere core use of local functions, only a limited amount of personal data must be provided to the app operator.
  2. Certain data is, however, required if the user wishes to use optional trial, purchase, unlock, restoration, credit, weather credit, or consent functions. Without this data, the relevant functions cannot be provided technically or legally. For credit-based weather functions, this may in particular include a pseudonymous software or installation ID and a month and location reference for usage calculation.
  3. Anyone wishing to use external third-party functions must transmit the data required for that function directly to the respective third-party provider or external service; otherwise the respective function cannot be performed.

10. Retention Periods at a Glance

Unless a specific period is stated in this privacy notice, personal data is deleted or anonymised once the respective processing purpose no longer applies and no statutory retention obligations or legitimate interests of the app operator in further storage—especially for the defence of rights, prevention of misuse, IT security, or documentation—prevent this.

11. Legal Bases at a Glance

The app operator processes personal data in particular on the basis of:

12. Rights of Data Subjects

Subject to the statutory requirements, data subjects have in particular the right:

13. Right to Object under Article 21 GDPR

To the extent the app operator processes personal data on the basis of Article 6(1)(f) GDPR, the user has the right to object to such processing at any time on grounds relating to the user's particular situation. The app operator will then no longer process the data concerned unless it can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or unless the processing serves the establishment, exercise, or defence of legal claims.

14. Automated Decisions

Automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the user or similarly significantly affects the user is not intended under the currently described system. Technical checks and automated security, authorisation, or misuse-prevention mechanisms may nevertheless be used to manage feature unlocks, prevent manipulation, or protect the integrity of the app.

15. Current Version and Changes

This privacy notice reflects the currently described state of the app architecture and operator-side processing. If the technical or legal design of PathCraft changes materially, this privacy notice will be updated accordingly.


Terms and Privacy Notice for External AI, Speech, and Translation Services

As of: 18 April 2026
Contact: kontakt@SuGreenX.eu

1. Subject Matter of this Document

  1. This document concerns the optional use of external AI, speech, transcription, text-to-speech, and translation services within PathCraft.
  2. It applies in particular to the direct use of such services through API access or API keys supplied by the user, the optional local storage of conversation, translation, or transcription histories, and—where offered—managed AI usage technically or for billing purposes facilitated by the app operator.
  3. In this context, PathCraft primarily provides a technical interface for communication, mutual understanding, and function triggering. The actual AI, speech, or translation processing takes place with the respective third-party provider used.
  4. Separate optional video or YouTube link functions are not the subject matter of this document; the general Terms of Use and the Privacy Notice for PathCraft apply to them.

2. Allocation of Roles and Data Paths

  1. If the user employs an API key stored by the user (BYOK), requests are, according to the described architecture, generally transmitted directly from the app to the third-party provider selected by the user.
  2. According to the described system architecture, the app operator generally does not receive the actual content data of such BYOK requests through its own backend unless otherwise expressly stated for a specific function.
  3. However, the app operator may process limited technical data relating to activations, credits, consent records, security events, integrity checks, or managed billing events. This operator-side processing is described in the general Privacy Notice for PathCraft.
  4. To the extent managed AI usage is offered, the app operator may process usage-related or billing-related event data relating to provider, model, time, user or installation reference, and cost or credit allocation. This does not automatically describe any processing of the actual content data in the operator backend and would need to be disclosed separately if it in fact takes place.

3. Which Data May Be Transmitted to External Services

Depending on the function, the following data in particular may be transmitted to the selected external service:

Depending on the provider, tariff, region, API function, live mode, conversation mode, storage or history function, additional state data as well as misuse and security logs may arise with the provider.

4. Local Storage of Histories

  1. If conversation, translation, or transcription histories are enabled in PathCraft, these contents are, according to the described architecture, stored locally on the device or—if iCloud synchronisation is enabled—in the private iCloud area of the Apple account used by the user.
  2. Such locally stored histories may contain personal data, conversation contents, voices, or sensitive information.
  3. If the same Apple account is used on multiple devices, these contents may be visible there.
  4. The user is responsible for determining which devices and persons have access to their device or Apple account.

5. Limits of Reliability

  1. AI, speech, and translation services may produce incomplete, inaccurate, misleading, delayed, biased, or otherwise unsuitable results.
  2. This applies in particular to live translations, transcriptions, speech-to-text, text-to-speech, summaries, classifications, image or document analysis, and multilingual contexts.
  3. Results must therefore be independently checked before use.
  4. PathCraft does not make independent legally binding, medical, emergency-related, or other safety-critical decisions for the user on that basis.
  5. External AI or translation services must not be used as the sole basis for legal advice, medical assessments, emergency decisions, traffic decisions, or other particularly consequential decisions.

6. User's Legal Obligations

  1. Before transmitting content to an external service, the user must ensure that an adequate legal basis exists for doing so and that third-party rights, confidentiality obligations, contractual restrictions, and local laws are complied with.
  2. This applies in particular where conversation contents, voices, or personal data of other persons are processed, special categories of personal data may be involved, trade secrets, confidential documents, or third-party files are included, or recording, interception, telecommunications, or confidentiality rules may apply.
  3. Affected conversation partners must be informed in advance where required by applicable law. Any required consents, clearances, or other permissions must be in place before voices or conversation contents of other persons are captured, stored, transcribed, translated, synthesised, or transmitted to an external service.
  4. Functions for the historical capture, logging, or storage of conversations must not be used where this is unlawful under the applicable law.
  5. The user is solely responsible for selecting the provider, tariff, regional status, privacy mode, and, where applicable, an account configuration suitable for the user's purpose and compliant with data protection requirements.

7. Provider-Dependent Differences and Third-Country Processing

  1. The data protection and contractual frameworks of external AI, speech, and translation services differ significantly depending on the provider, tariff, region, account or billing status, and the specific API function used.
  2. Depending on the provider and configuration, inputs or outputs may be logged for misuse or security purposes, stored temporarily in session or conversation state, retained for longer in particular live, grounding, history, or state features, or used for product improvement in certain free-tier, opt-in, or otherwise configured scenarios.
  3. Depending on the selected provider, processing may also take place in countries outside the European Union or the European Economic Area, in particular in the United States or other third countries.
  4. In direct BYOK use, the place of processing, storage practice, and transfer mechanisms are governed by the current documents of the respective third-party provider selected by the user. The user must review those documents separately.

8. Providers Selected by the User

Depending on the stage of development of the app, PathCraft may provide or prepare interfaces to third-party providers such as OpenAI, Google Gemini, Soniox, or comparable services. Mentioning a provider does not constitute a guarantee of its permanent availability or an assurance of particular privacy, retention, or training conditions. Only the documents of the selected third-party provider that apply at the time of the specific use are authoritative.

9. No Operator Profiling Based on Content Data

According to the described architecture, the app operator does not collect content data from direct BYOK requests in parallel for its own advertising, profiling, or general tracking purposes. This does not affect histories stored locally on the device or in the private iCloud area, the technical operator data described in the general Privacy Notice, or any separately disclosed cases of managed usage.

10. Relationship to the Other Legal Texts

  1. The Terms of Use and Safety Notices for PathCraft and the general Privacy Notice for PathCraft apply in addition.
  2. To the extent an external third-party provider provides its own contractual or privacy documents, those documents apply in addition and take precedence for processing within that provider's area of responsibility.

11. Contact and Provider Information

Christian Techmer
Mühlbachstr. 29
88697 Bermatingen
Germany
Email: kontakt@SuGreenX.eu
VAT identification number pursuant to Section 27a of the German VAT Act: DE460849192