Privacy

Draft – will be legally reviewed and completed before launch. The German version is binding.

Last updated: September 2026

In short

No ads, no tracking, no accounts. Your exact location is never stored: our server immediately converts the coordinates into an area of about 5 × 5 km and discards them. You can delete everything we store from within the app at any time.

Controller

Gerhard Kanzler, Ahornweg 1, 83410 Laufen, Germany · tellstack@rz-solutions.dev

Location and weather

The app only asks for your location while you use it. The coordinates are sent encrypted to our server, which turns them into an area (geohash, approx. 5 × 5 km). We request weather data for the centre of that area from Apple Weather (WeatherKit, Apple Inc.) – never for your location. The place name shown in the app is looked up by your device itself using Apple's map service.

Device ID and abuse protection

To make sure only genuine Grantwetter apps can use our server, the app creates a random device ID. The server only stores a hash of it. In addition, Apple's "App Attest" confirms that requests come from an unmodified app. For rate limits we use your IP address only in hashed form and only briefly.

What is stored

The hashed device ID, the area, language, time zone, chosen persona and design, a push token if you enable notifications, and the status and expiry of your Grant Pass. Everything is deleted automatically after 180 days of inactivity. To delete it right away: Settings › Privacy in the app.

Comfort push

Only if you turn it on: notifications are delivered by Apple through its Apple Push Notification service. For this we additionally store your chosen times and, per day, a short entry of which line was sent – so you get at most one push a day. These entries are deleted after 30 days; when you turn push off, we remove the push token and the area right away.

Grant Pass (subscription)

Purchase and payment are handled entirely by Apple. We only receive the purchase receipt signed by Apple to check whether your Grant Pass is active – no payment details, no name, no Apple ID.

Personal comfort (AI)

Only when you tap "Personal comfort" with the Grant Pass do we send the chosen persona, weather condition, temperature, grant score, time of day and the displayed place name to Anthropic PBC (USA), which writes the text using the Claude model. No device ID or other identifier is sent. We do not store the text, only how many requests were made (for costs and limits). The transfer to the USA is based on the EU Standard Contractual Clauses.

Only on your device

Your sticker album, poke streak, recently shown lines, saved places and settings stay on your device (and in the app group used by widgets). Settings are synced between iPhone and Apple Watch directly via Apple, not through our server.

Website

The website runs on our own server in a data centre in Germany. When you visit it, technically necessary data (IP address, time, requested page, browser) is processed in server logs to keep the service secure. The logs are rotated automatically and not analysed. The website sets no tracking cookies – only cookies for your chosen language and design and, in the admin area, login cookies for administrators.

Contact

Messages sent through the contact form on the website and through “Send feedback” in the app are processed with Tellstack (tellstack.app), solely to answer and evaluate your feedback. From the app we only send your text, the type you picked (if any), your e-mail address (only if you enter it), the app version, iOS version, device type (iPhone or iPad) and language setting. No device ID, no location.

Legal bases

Providing the app and the Grant Pass: Art. 6(1)(b) GDPR. Abuse protection, server logs and rate limits: legitimate interest under Art. 6(1)(f) GDPR. Personal comfort and push notifications: your request or consent (Art. 6(1)(a) and (b) GDPR).

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Just contact us using the details above. You can also lodge a complaint with a supervisory authority, for example the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.