This Privacy Policy applies to the alligkeit app, the
legal website at https://legal.alligkeit.com, and the
future landing page at https://alligkeit.com once it is
published.
The data controller for alligkeit and this Privacy
Policy is:
Maximilian Benedikt Pöpping
Birkenweg 14
84061 Ergoldsbach
Deutschland
Email: info@alligkeit.com
No Data Protection Officer has currently been appointed for
alligkeit. Based on the current setup, the legal thresholds
under Article 37 GDPR and Section 38 BDSG are not met.
| Data category | Purpose | Lawful basis | Recipient / location |
|---|---|---|---|
| Raw voice recording (D1) | Transcribing your recording into text | Explicit consent, Article 9(2)(a) GDPR and Article 6(1)(a) GDPR | AssemblyAI, EU Dublin, via the alligkeit proxy |
| Transcript text (D2) | Transforming your transcript into confirmable affirmations | Article 6(1)(a) GDPR | Anthropic, USA, via the alligkeit proxy |
| Confirmed affirmation text (D3) | Generating synthetic voice output | Article 6(1)(a) GDPR | ElevenLabs, USA, via the alligkeit proxy |
| Reminder settings and local notification payloads (D4) | Sleep / wake reminders on your device | Article 6(1)(a) GDPR and your operating-system permission | No external transfer; on-device only |
| Session metadata, audio files, consent state, and app settings (D5) | Local playback, library, recovery, settings | Purely local processing on your device; no separate external transfer | No external transfer; on-device only |
| Technical safeguard data (D6): IP address, random installation identifier, and platform | Abuse and cost protection for the alligkeit proxy (rate limits, daily caps, binding requests to an app installation) | Legitimate interest, Article 6(1)(f) GDPR (protecting the infrastructure against abuse and cost explosion) | alligkeit proxy on Cloudflare infrastructure (see section 4) |
| Apple subscription and live credit data (D7a): signed Apple transaction (JWS), pseudonymous subscription key, product, subscription/entitlement status and expiry, credit balance and reservations | Verify the subscription, provide the monthly usage allowance across devices, and record consumption | Performance of the contract, Article 6(1)(b) GDPR | Apple (verification through the App Store Server API) and the alligkeit proxy, including Cloudflare Durable Objects (see section 4) |
| Pseudonymous grant/operation records (D7b) | Keep grants and consumption idempotent and prevent duplicate grants, repeat charges, and manipulation | Legitimate interests, Article 6(1)(f) GDPR (integrity and abuse protection of the credit system) | alligkeit proxy, including Cloudflare Durable Objects |
| Minimal suppression record (D7c): pseudonymous ledger key, deletion cutoff, and review metadata | After deletion, prevent old Apple subscription periods for the same subscription from being granted again as credits | Legitimate interests, Article 6(1)(f) GDPR; the documented balancing
assessment is set out in
docs/privacy/LIA-CREDIT-SUPPRESSION.md |
alligkeit proxy, including Cloudflare Durable Objects |
| Deletion evidence and scope-limited legal-hold data (D7d): pseudonymous request, time, outcome, retention and hold metadata, plus only the specifically retained data subset | Evidence erasure requests; comply with legal obligations; establish, exercise, or defend legal claims | Article 6(1)(c) GDPR where a legal obligation applies; otherwise Article 6(1)(f) GDPR and the exceptions in Article 17(3) GDPR | alligkeit proxy, including Cloudflare Durable Objects; access restricted to the responsible operator/legal role |
| Feedback content (D8): the feedback text you wrote, your selected language and platform, and — only if you enter it voluntarily — your email address | Handling your feedback about the app (bug reports, suggestions) and, if you leave an address, replying to you | Legitimate interest, Article 6(1)(f) GDPR (handling feedback to fix and improve the app); additionally consent under Article 6(1)(a) GDPR for the voluntary provision of your email address | alligkeit proxy on Cloudflare infrastructure (see section 4) |
alligkeit does not use a user account or advertising
identifier for this core processing. The proxy does not persist voice,
transcript, or affirmation content in its own infrastructure. Technical
safeguard data (D6) is short-lived; the pseudonymous credit ledger (D7)
and voluntarily submitted feedback (D8) are the two expressly identified
exceptions with their own longer retention and different deletion rules
(see section 5). The installation identifier is a random ID with no link
to your name, any account, or advertising identifiers.
The feedback function (D8) is entirely voluntary and is triggered only when you write something yourself on the app's feedback screen and confirm "Send". Only the text you wrote, your selected language and platform, and — if you enter it — your email address are transmitted. Sessions, audio files, voice recordings, transcripts, and affirmations are not transmitted. Providing an email address is optional: without one your feedback still reaches us, but we cannot reply to you. As with every request to the alligkeit proxy, the random installation identifier (D6) is transmitted technically so that abuse protection and daily caps can take effect; it is not stored together with your feedback. What you type into the free-text field is entirely up to you — please do not disclose information there that you do not want us to hold. You can request deletion of your feedback at any time using the contact address in section 1.
Your feedback is stored exclusively within the Cloudflare infrastructure of the alligkeit proxy (see section 4) — it does not leave that boundary. So that we notice a message has arrived at all, the proxy additionally creates a notification in our internal, non-public task system at GitHub. That notification deliberately contains no personal data whatsoever: neither your text, nor your email address, nor any identifier that could be traced back to your entry — it states only the chosen category and the date of receipt. GitHub therefore receives no personal data about you.
For D7, the app sends the Apple-signed transaction (JWS) to the
alligkeit proxy. The proxy cryptographically verifies its signature, app
identity, and product and checks entitlement status and transaction
history through the App Store Server API. The verified
appTransactionId is HMAC-derived with a secret server value
into the stable pseudonymous ledger key. The
originalTransactionId is used only transiently and with
domain separation for the idempotency of individual subscription/grant
chains. Neither the raw JWS nor either raw Apple transaction identifier,
your Apple ID, or payment data is persistently stored in the alligkeit
proxy or logged by us. Apple can still associate the transaction with
your Apple account; to us, the ledger key remains pseudonymous.
The in-app export exposes this pseudonymous ledger key as a support code and includes the actually stored grant and operation IDs, timestamps, suppression, deletion, and hold data in a versioned JSON schema. It states the export time, UTC/ISO-8601, the credit unit, and a versioned field and status legend; an expired hold awaiting alarm cleanup is marked inactive. If you no longer have access to the previous device, support may verify another equivalent Apple-signed purchase proof instead of an account. This manually protected exception path may also verify an older cryptographically valid Apple JWS; a name, email address, or screenshot alone is not sufficient to identify a ledger.
The cloud processing in alligkeit (D1–D3, see section 3)
relies on your consent. alligkeit is intended for people
aged 16 and over.
If you are under 16, your consent to cloud processing is not valid in Germany without the authorization of a holder of parental responsibility (Article 8 GDPR). For that reason, the app asks for a minimum-age self-declaration before every grant of consent: you actively confirm that you are at least 16 years old before you can consent to cloud processing. We do not offer cloud processing to anyone under 16. The app's purely local features are not affected by this.
We do not collect a date of birth or any other proof of age. We only store the time of your self-confirmation, and we store it solely on your device (as part of your local consent state, see section 6). This timestamp is not transmitted to the alligkeit proxy or to any external recipient; it serves only to demonstrate that consent was validly given (Article 7 GDPR).
The following recipients may be involved in your use of the app:
alligkeit, this path is configured to the EU endpoint in
Dublin.For Anthropic, we currently do not rely on a verified DPF claim in end-user text. Instead, the transfer is based on appropriate safeguards in the form of Standard Contractual Clauses under Article 46(2)(c) GDPR (part of the Anthropic Commercial Terms / DPA).
For ElevenLabs, we rely primarily on the provider's documented certification under the EU-US Data Privacy Framework. The ElevenLabs Data Processing Addendum additionally contains Standard Contractual Clauses under Article 46(2)(c) GDPR. If the Data Privacy Framework ceases to apply or is declared invalid, we will continue transfers only if the Standard Contractual Clauses apply and the then-required transfer assessment, including any supplementary measures, confirms an adequate level of protection; otherwise, we will suspend the affected processing path.
You have the right to obtain a copy of, or to inspect, the appropriate safeguards relied upon for the third-country transfer (Article 13(1)(f) GDPR). To do so, contact the address named in section 1.
| Processing activity | Retention / deletion logic |
|---|---|
| AssemblyAI (D1) | alligkeit triggers a best-effort deletion after
transcription has completed. If that deletion fails, retention may
temporarily continue under the provider's policy. |
| Anthropic (D2) | Current standard retention according to Anthropic's policy: 30 days for API inputs and outputs. If a usage-policy flag is triggered, retention may be longer. |
| ElevenLabs (D3) | No publicly documented fixed TTL for standard request history. Request data may remain in the account history under the provider's standard policy. |
| Local app data (D4/D5) | Until you delete it in the app or uninstall the app. |
| Technical safeguard data in the proxy (D6) | Automatic expiry: installation binding data no later than 7 days after last use, daily-cap counters no later than 48 hours, rate-limit windows after 10 minutes. No manual deletion required. |
| Apple JWS during reconciliation (D7) | Only for the duration of the request and cryptographic verification; no persistent storage or logging by alligkeit. |
| Live credit ledger (D7a) and idempotency data (D7b) | The current credit and subscription state is retained while the verified subscription or existing contractually usable credits remain, unless you trigger voluntary server-side deletion. Reservations expire after 24 hours. An unresolved own-voice operation remains open for no more than 30 days from reservation start and is then finally released without a later charge. Completed or finally released operations are deleted after a further 90 days. |
| Suppression record (D7c) | The first documented review takes place no later than 12 months after the deletion cutoff and at least annually thereafter; review may be system-wide. The minimal record is retained only while historical Apple replay remains technically possible. It is automatically deleted within 30 days after replay has demonstrably and irreversibly ended, unless a matching legal hold applies. |
| Deletion evidence record (D7d) | Retained until 31 December of the third calendar year following the relevant erasure request, then automatically deleted unless a specifically documented legal hold applies. |
| Legal hold (D7d) | Limited to the named ledger, defined scope, reason, and documented legal basis. Every hold has a responsible role, review date, and expiry. The retained subset is deleted when the hold is released or expires; there is no blanket precautionary hold. |
| Feedback content in the proxy (D8) | No automatic expiry: your feedback is retained while your matter is open and deleted afterwards. On your request we delete it sooner. The personal-data-free arrival notification in our internal task system is unaffected, because it contains no data about you. |
alligkeit stores most of your data locally on your
device, in particular:
The Settings screen includes a Lokale App-Daten löschen
/ Delete local app data action. This removes local session
data, local audio files, settings, and the local consent state. The
action does not delete the server-side pseudonymous
credit ledger (D7), because that ledger provides the cross-device
balance for the same verified Apple subscription. Independently of this,
the short-lived technical safeguard data in the proxy (D6, sections 3
and 5) expires automatically.
Device backup. This local data is part of your
operating system's regular backup (for example the iCloud backup on iOS
or the device backup on Android), provided you have enabled it. As a
result, your sessions may be preserved across a restore or a device
change. This backup is entirely under your control and stored in the
typically encrypted storage of your operating-system provider;
alligkeit never transmits your sessions to its own servers
and has no access to your device backup. You can disable the backup, or
exclude alligkeit from it, at any time in your operating
system's settings.
Under the GDPR, you have the following data subject rights in particular:
| Right | What it means for alligkeit |
How to exercise it |
|---|---|---|
| Right of access (Art. 15 GDPR) | You may request information about the processing of your personal data. | You can inspect the pseudonymous credit ledger in the app under
Settings → Subscription → Your data on the server. For
other processing, contact us at info@alligkeit.com. |
| Right to rectification (Art. 16 GDPR) | You may request correction of inaccurate personal data. | Contact us at info@alligkeit.com. |
| Right to erasure (Art. 17 GDPR) | You may request deletion of personal data where the legal requirements are met. Local deletion does not automatically remove the pseudonymous credit ledger. Legal obligations or the establishment, exercise, or defence of legal claims may temporarily restrict erasure of a precisely limited subset under Article 17(3) GDPR. | You can delete local data directly in the app.
Delete credit balance for good is at the bottom of the
in-app ledger screen and requires fresh or equivalent signed Apple
purchase proof plus a transparent acknowledgement of the technical
consequences, but no blanket waiver of rights. If deletion is
restricted, the app tells you and you can contact info@alligkeit.com with the
pseudonymous support code. |
| Right to restriction of processing (Art. 18 GDPR) | You may request that processing be restricted. | Contact us at info@alligkeit.com. |
| Right to data portability (Art. 20 GDPR) | Where the legal requirements are met, you may request a structured export of the data you provided. | You can export local sessions from each session's detail view and share the pseudonymous credit ledger as a JSON file from the in-app ledger screen. For other matters, contact us at info@alligkeit.com. |
| Right to object (Art. 21 GDPR) | You may object where processing is based on Article 6(1)(e) or (f) GDPR. | For alligkeit, this mainly concerns abuse prevention
for D6/D7 and the website/security processes described in section
14. |
| Right to withdraw consent (Art. 7(3) GDPR) | You may withdraw consent at any time with effect for the future. | In the app via the consent settings or by emailing info@alligkeit.com. |
When sharing the credit-ledger export, the app temporarily stages a
unique file matching
alligkeit-credit-ledger-<wall-ms>-<uuid>.json
in its own subdirectory of the operating system's temporary directory.
The shared file name deliberately carries no boot-relative uptime value:
a device-wide signal like that must not leave the device through a file
name. Unique names prevent an older timer or a later dismissed share
from removing the Android cache copy of a newer export. On a successful
share, or when the platform outcome cannot be clearly determined, the
file becomes due for deletion after 24 hours. Actual removal takes place
at the next cleanup run that the app or the operating system is able to
execute, and can happen later if the app has since closed or the device
has restarted. If cancellation or failure is unambiguous, the app
deletes the file immediately. Additional cleanup on app start,
foreground resume, the next export, and an operating-system-reported app
detach uses operating-system uptime, which cannot be changed through the
device calendar clock. Correcting the device clock therefore cannot
delete a fresh file early. The local staging directory, which never
leaves the device, still carries this uptime directly in its own name;
if the app detects a device reboot there from a reset uptime, it
conservatively starts one new 24-hour window. Every private Android
share_plus cache copy instead anchors uptime in a separate,
likewise purely local marker-file timestamp, because its own file name
no longer carries one: this applies to the current export's copy just as
much as to older export artifacts using the previous fixed filename or
the old wall-time/uptime/UUID naming scheme. Each such copy receives a
one-time uptime quarantine marker when first seen or after a reboot and
is removed after a further 24 hours. A concurrent resume waits for
detach cleanup and then re-enables new exports. On uninstall, the
operating system removes the app sandbox. Before server-side credit
deletion, the app removes every credit-export staging and private
Android share_plus cache copy it still owns; if this fails,
server deletion does not start. On iOS, the app applies
NSFileProtectionComplete and excludes the file from backups
before writing the first export payload byte; if that fails, no file is
shared. A share result confirms only the platform operation's completion
as visible to alligkeit and cannot prove when another destination app
performed its final file read. A destination may create its own copy
under your control; alligkeit does not delete such copies.
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
For the current operator location in Bavaria, the competent authority is:
Bayerisches Landesamt fuer Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Email: poststelle@lda.bayern.de
Web: https://www.lda.bayern.de/
We use appropriate technical and organizational measures to protect your data. This includes in particular:
However, no electronic transmission or storage can ever be completely risk-free.
The voice tracks generated by alligkeit are synthetic
audio content. The app visibly labels them as an "AI voice" and adds an
unsigned, machine-readable origin field to the audio metadata. This
metadata can be removed during conversion or sharing and is not, by
itself, a robust guarantee of origin. In addition, the speech-synthesis
provider ElevenLabs offers its own detection tool for audio generated
with its technology.
At the current stage, the app itself does not use analytics SDKs,
advertising tracking, or marketing cookies. alligkeit does
not create user profiles inside the app for advertising or tracking
purposes.
The feedback function (D8, section 3) is not tracking either: it collects nothing in the background and transmits only what you wrote and actively sent yourself.
This statement applies to the app itself. For the separate websites, see section 14.
We may update this Privacy Policy if the app, the service providers,
the legal framework, or the processing flows change. The current version
will be published at https://legal.alligkeit.com. We will
notify you in the app of material changes before the affected
processing; where renewed consent is required, that cloud processing
will not take place until you consent again. Since
alligkeit does not operate user accounts, there is no
separate email notification flow.
Using alligkeit is voluntary. Consent to cloud
processing is also voluntary.
If you do not grant consent for cloud processing, or if you later withdraw it:
alligkeit does not use automated decision-making within
the meaning of Article 22 GDPR. It also does not perform profiling that
produces legal effects or similarly significant effects for you.
legal.alligkeit.com /
alligkeit.com)The legal website is hosted on Cloudflare Pages. These notices also
apply to a future landing page at https://alligkeit.com to
the extent that it is delivered in the same or a comparable technical
setup. When you access these websites, technical connection data may be
processed, in particular your IP address, time of access, requested URL,
referrer, browser / user-agent data, and security / request metadata.
This serves the secure and stable delivery of the sites and abuse
prevention.
Cloudflare may set strictly necessary cookies, in particular
__cf_bm for bot-management functions and
_cfuvid for certain rate-limiting or security functions, if
those functions are active. alligkeit currently does not
use its own analytics or marketing technology on the legal website. If
the landing page later uses additional features, first-party tracking,
or different hosting, this Privacy Policy will be updated before those
changes go live.
The lawful basis for the technically necessary hosting and protection of this website is Article 6(1)(f) GDPR (legitimate interests in the secure, stable, and abuse-resistant delivery of legally required information).
This Privacy Policy is available in a German and an English version. To the extent permitted by law, the German version is authoritative; mandatory data-subject rights remain unaffected.
Last updated: 2026-08-03 Version: v2.6