I would argue it's basically impossible to have an internet connected app that does not run afoul of GDPR in one way or another. It's really just a question of how much of GDPR can you comply with at a reasonable cost or a better strategy is to do your best to comply with the spirit of GDPR, if not the letter.