Privacy Policy - alligkeit

Privacy Policy for alligkeit

This Privacy Policy applies to the alligkeit app, the legal website at https://legal.alligkeit.com, and the future landing page at https://alligkeit.com once it is published.

1. Data controller and contact

The data controller for alligkeit and this Privacy Policy is:

Maximilian Benedikt Pöpping
Birkenweg 14
84061 Ergoldsbach
Deutschland
Email: info@alligkeit.com

2. Data Protection Officer

No Data Protection Officer has currently been appointed for alligkeit. Based on the current setup, the legal thresholds under Article 37 GDPR and Section 38 BDSG are not met.

3. What data we process, why we process it, and the lawful basis

Data category Purpose Lawful basis Recipient / location
Raw voice recording (D1) Transcribing your recording into text Explicit consent, Article 9(2)(a) GDPR and Article 6(1)(a) GDPR AssemblyAI, EU Dublin, via the alligkeit proxy
Transcript text (D2) Transforming your transcript into confirmable affirmations Article 6(1)(a) GDPR Anthropic, USA, via the alligkeit proxy
Confirmed affirmation text (D3) Generating synthetic voice output Article 6(1)(a) GDPR ElevenLabs, USA, via the alligkeit proxy
Reminder settings and local notification payloads (D4) Sleep / wake reminders on your device Article 6(1)(a) GDPR and your operating-system permission No external transfer; on-device only
Session metadata, audio files, consent state, and app settings (D5) Local playback, library, recovery, settings Purely local processing on your device; no separate external transfer No external transfer; on-device only
Technical safeguard data (D6): IP address, random installation identifier, and platform Abuse and cost protection for the alligkeit proxy (rate limits, daily caps, binding requests to an app installation) Legitimate interest, Article 6(1)(f) GDPR (protecting the infrastructure against abuse and cost explosion) alligkeit proxy on Cloudflare infrastructure (see section 4)
Apple subscription and live credit data (D7a): signed Apple transaction (JWS), pseudonymous subscription key, product, subscription/entitlement status and expiry, credit balance and reservations Verify the subscription, provide the monthly usage allowance across devices, and record consumption Performance of the contract, Article 6(1)(b) GDPR Apple (verification through the App Store Server API) and the alligkeit proxy, including Cloudflare Durable Objects (see section 4)
Pseudonymous grant/operation records (D7b) Keep grants and consumption idempotent and prevent duplicate grants, repeat charges, and manipulation Legitimate interests, Article 6(1)(f) GDPR (integrity and abuse protection of the credit system) alligkeit proxy, including Cloudflare Durable Objects
Minimal suppression record (D7c): pseudonymous ledger key, deletion cutoff, and review metadata After deletion, prevent old Apple subscription periods for the same subscription from being granted again as credits Legitimate interests, Article 6(1)(f) GDPR; the documented balancing assessment is set out in docs/privacy/LIA-CREDIT-SUPPRESSION.md alligkeit proxy, including Cloudflare Durable Objects
Deletion evidence and scope-limited legal-hold data (D7d): pseudonymous request, time, outcome, retention and hold metadata, plus only the specifically retained data subset Evidence erasure requests; comply with legal obligations; establish, exercise, or defend legal claims Article 6(1)(c) GDPR where a legal obligation applies; otherwise Article 6(1)(f) GDPR and the exceptions in Article 17(3) GDPR alligkeit proxy, including Cloudflare Durable Objects; access restricted to the responsible operator/legal role
Feedback content (D8): the feedback text you wrote, your selected language and platform, and — only if you enter it voluntarily — your email address Handling your feedback about the app (bug reports, suggestions) and, if you leave an address, replying to you Legitimate interest, Article 6(1)(f) GDPR (handling feedback to fix and improve the app); additionally consent under Article 6(1)(a) GDPR for the voluntary provision of your email address alligkeit proxy on Cloudflare infrastructure (see section 4)

alligkeit does not use a user account or advertising identifier for this core processing. The proxy does not persist voice, transcript, or affirmation content in its own infrastructure. Technical safeguard data (D6) is short-lived; the pseudonymous credit ledger (D7) and voluntarily submitted feedback (D8) are the two expressly identified exceptions with their own longer retention and different deletion rules (see section 5). The installation identifier is a random ID with no link to your name, any account, or advertising identifiers.

The feedback function (D8) is entirely voluntary and is triggered only when you write something yourself on the app's feedback screen and confirm "Send". Only the text you wrote, your selected language and platform, and — if you enter it — your email address are transmitted. Sessions, audio files, voice recordings, transcripts, and affirmations are not transmitted. Providing an email address is optional: without one your feedback still reaches us, but we cannot reply to you. As with every request to the alligkeit proxy, the random installation identifier (D6) is transmitted technically so that abuse protection and daily caps can take effect; it is not stored together with your feedback. What you type into the free-text field is entirely up to you — please do not disclose information there that you do not want us to hold. You can request deletion of your feedback at any time using the contact address in section 1.

Your feedback is stored exclusively within the Cloudflare infrastructure of the alligkeit proxy (see section 4) — it does not leave that boundary. So that we notice a message has arrived at all, the proxy additionally creates a notification in our internal, non-public task system at GitHub. That notification deliberately contains no personal data whatsoever: neither your text, nor your email address, nor any identifier that could be traced back to your entry — it states only the chosen category and the date of receipt. GitHub therefore receives no personal data about you.

For D7, the app sends the Apple-signed transaction (JWS) to the alligkeit proxy. The proxy cryptographically verifies its signature, app identity, and product and checks entitlement status and transaction history through the App Store Server API. The verified appTransactionId is HMAC-derived with a secret server value into the stable pseudonymous ledger key. The originalTransactionId is used only transiently and with domain separation for the idempotency of individual subscription/grant chains. Neither the raw JWS nor either raw Apple transaction identifier, your Apple ID, or payment data is persistently stored in the alligkeit proxy or logged by us. Apple can still associate the transaction with your Apple account; to us, the ledger key remains pseudonymous.

The in-app export exposes this pseudonymous ledger key as a support code and includes the actually stored grant and operation IDs, timestamps, suppression, deletion, and hold data in a versioned JSON schema. It states the export time, UTC/ISO-8601, the credit unit, and a versioned field and status legend; an expired hold awaiting alarm cleanup is marked inactive. If you no longer have access to the previous device, support may verify another equivalent Apple-signed purchase proof instead of an account. This manually protected exception path may also verify an older cryptographically valid Apple JWS; a name, email address, or screenshot alone is not sufficient to identify a ledger.

3a. Minimum age and children

The cloud processing in alligkeit (D1–D3, see section 3) relies on your consent. alligkeit is intended for people aged 16 and over.

If you are under 16, your consent to cloud processing is not valid in Germany without the authorization of a holder of parental responsibility (Article 8 GDPR). For that reason, the app asks for a minimum-age self-declaration before every grant of consent: you actively confirm that you are at least 16 years old before you can consent to cloud processing. We do not offer cloud processing to anyone under 16. The app's purely local features are not affected by this.

We do not collect a date of birth or any other proof of age. We only store the time of your self-confirmation, and we store it solely on your device (as part of your local consent state, see section 6). This timestamp is not transmitted to the alligkeit proxy or to any external recipient; it serves only to demonstrate that consent was validly given (Article 7 GDPR).

4. Recipients and international transfers

The following recipients may be involved in your use of the app:

For Anthropic, we currently do not rely on a verified DPF claim in end-user text. Instead, the transfer is based on appropriate safeguards in the form of Standard Contractual Clauses under Article 46(2)(c) GDPR (part of the Anthropic Commercial Terms / DPA).

For ElevenLabs, we rely primarily on the provider's documented certification under the EU-US Data Privacy Framework. The ElevenLabs Data Processing Addendum additionally contains Standard Contractual Clauses under Article 46(2)(c) GDPR. If the Data Privacy Framework ceases to apply or is declared invalid, we will continue transfers only if the Standard Contractual Clauses apply and the then-required transfer assessment, including any supplementary measures, confirms an adequate level of protection; otherwise, we will suspend the affected processing path.

You have the right to obtain a copy of, or to inspect, the appropriate safeguards relied upon for the third-country transfer (Article 13(1)(f) GDPR). To do so, contact the address named in section 1.

5. Retention periods

Processing activity Retention / deletion logic
AssemblyAI (D1) alligkeit triggers a best-effort deletion after transcription has completed. If that deletion fails, retention may temporarily continue under the provider's policy.
Anthropic (D2) Current standard retention according to Anthropic's policy: 30 days for API inputs and outputs. If a usage-policy flag is triggered, retention may be longer.
ElevenLabs (D3) No publicly documented fixed TTL for standard request history. Request data may remain in the account history under the provider's standard policy.
Local app data (D4/D5) Until you delete it in the app or uninstall the app.
Technical safeguard data in the proxy (D6) Automatic expiry: installation binding data no later than 7 days after last use, daily-cap counters no later than 48 hours, rate-limit windows after 10 minutes. No manual deletion required.
Apple JWS during reconciliation (D7) Only for the duration of the request and cryptographic verification; no persistent storage or logging by alligkeit.
Live credit ledger (D7a) and idempotency data (D7b) The current credit and subscription state is retained while the verified subscription or existing contractually usable credits remain, unless you trigger voluntary server-side deletion. Reservations expire after 24 hours. An unresolved own-voice operation remains open for no more than 30 days from reservation start and is then finally released without a later charge. Completed or finally released operations are deleted after a further 90 days.
Suppression record (D7c) The first documented review takes place no later than 12 months after the deletion cutoff and at least annually thereafter; review may be system-wide. The minimal record is retained only while historical Apple replay remains technically possible. It is automatically deleted within 30 days after replay has demonstrably and irreversibly ended, unless a matching legal hold applies.
Deletion evidence record (D7d) Retained until 31 December of the third calendar year following the relevant erasure request, then automatically deleted unless a specifically documented legal hold applies.
Legal hold (D7d) Limited to the named ledger, defined scope, reason, and documented legal basis. Every hold has a responsible role, review date, and expiry. The retained subset is deleted when the hold is released or expires; there is no blanket precautionary hold.
Feedback content in the proxy (D8) No automatic expiry: your feedback is retained while your matter is open and deleted afterwards. On your request we delete it sooner. The personal-data-free arrival notification in our internal task system is unaffected, because it contains no data about you.

6. Local storage on your device

alligkeit stores most of your data locally on your device, in particular:

The Settings screen includes a Lokale App-Daten löschen / Delete local app data action. This removes local session data, local audio files, settings, and the local consent state. The action does not delete the server-side pseudonymous credit ledger (D7), because that ledger provides the cross-device balance for the same verified Apple subscription. Independently of this, the short-lived technical safeguard data in the proxy (D6, sections 3 and 5) expires automatically.

Device backup. This local data is part of your operating system's regular backup (for example the iCloud backup on iOS or the device backup on Android), provided you have enabled it. As a result, your sessions may be preserved across a restore or a device change. This backup is entirely under your control and stored in the typically encrypted storage of your operating-system provider; alligkeit never transmits your sessions to its own servers and has no access to your device backup. You can disable the backup, or exclude alligkeit from it, at any time in your operating system's settings.

6b. Your rights

Under the GDPR, you have the following data subject rights in particular:

Right What it means for alligkeit How to exercise it
Right of access (Art. 15 GDPR) You may request information about the processing of your personal data. You can inspect the pseudonymous credit ledger in the app under Settings → Subscription → Your data on the server. For other processing, contact us at info@alligkeit.com.
Right to rectification (Art. 16 GDPR) You may request correction of inaccurate personal data. Contact us at info@alligkeit.com.
Right to erasure (Art. 17 GDPR) You may request deletion of personal data where the legal requirements are met. Local deletion does not automatically remove the pseudonymous credit ledger. Legal obligations or the establishment, exercise, or defence of legal claims may temporarily restrict erasure of a precisely limited subset under Article 17(3) GDPR. You can delete local data directly in the app. Delete credit balance for good is at the bottom of the in-app ledger screen and requires fresh or equivalent signed Apple purchase proof plus a transparent acknowledgement of the technical consequences, but no blanket waiver of rights. If deletion is restricted, the app tells you and you can contact info@alligkeit.com with the pseudonymous support code.
Right to restriction of processing (Art. 18 GDPR) You may request that processing be restricted. Contact us at info@alligkeit.com.
Right to data portability (Art. 20 GDPR) Where the legal requirements are met, you may request a structured export of the data you provided. You can export local sessions from each session's detail view and share the pseudonymous credit ledger as a JSON file from the in-app ledger screen. For other matters, contact us at info@alligkeit.com.
Right to object (Art. 21 GDPR) You may object where processing is based on Article 6(1)(e) or (f) GDPR. For alligkeit, this mainly concerns abuse prevention for D6/D7 and the website/security processes described in section 14.
Right to withdraw consent (Art. 7(3) GDPR) You may withdraw consent at any time with effect for the future. In the app via the consent settings or by emailing info@alligkeit.com.

When sharing the credit-ledger export, the app temporarily stages a unique file matching alligkeit-credit-ledger-<wall-ms>-<uuid>.json in its own subdirectory of the operating system's temporary directory. The shared file name deliberately carries no boot-relative uptime value: a device-wide signal like that must not leave the device through a file name. Unique names prevent an older timer or a later dismissed share from removing the Android cache copy of a newer export. On a successful share, or when the platform outcome cannot be clearly determined, the file becomes due for deletion after 24 hours. Actual removal takes place at the next cleanup run that the app or the operating system is able to execute, and can happen later if the app has since closed or the device has restarted. If cancellation or failure is unambiguous, the app deletes the file immediately. Additional cleanup on app start, foreground resume, the next export, and an operating-system-reported app detach uses operating-system uptime, which cannot be changed through the device calendar clock. Correcting the device clock therefore cannot delete a fresh file early. The local staging directory, which never leaves the device, still carries this uptime directly in its own name; if the app detects a device reboot there from a reset uptime, it conservatively starts one new 24-hour window. Every private Android share_plus cache copy instead anchors uptime in a separate, likewise purely local marker-file timestamp, because its own file name no longer carries one: this applies to the current export's copy just as much as to older export artifacts using the previous fixed filename or the old wall-time/uptime/UUID naming scheme. Each such copy receives a one-time uptime quarantine marker when first seen or after a reboot and is removed after a further 24 hours. A concurrent resume waits for detach cleanup and then re-enables new exports. On uninstall, the operating system removes the app sandbox. Before server-side credit deletion, the app removes every credit-export staging and private Android share_plus cache copy it still owns; if this fails, server deletion does not start. On iOS, the app applies NSFileProtectionComplete and excludes the file from backups before writing the first export payload byte; if that fails, no file is shared. A share result confirms only the platform operation's completion as visible to alligkeit and cannot prove when another destination app performed its final file read. A destination may create its own copy under your control; alligkeit does not delete such copies.

7. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.

For the current operator location in Bavaria, the competent authority is:

Bayerisches Landesamt fuer Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Email: poststelle@lda.bayern.de
Web: https://www.lda.bayern.de/

8. Security

We use appropriate technical and organizational measures to protect your data. This includes in particular:

However, no electronic transmission or storage can ever be completely risk-free.

9. AI-generated audio content

The voice tracks generated by alligkeit are synthetic audio content. The app visibly labels them as an "AI voice" and adds an unsigned, machine-readable origin field to the audio metadata. This metadata can be removed during conversion or sharing and is not, by itself, a robust guarantee of origin. In addition, the speech-synthesis provider ElevenLabs offers its own detection tool for audio generated with its technology.

10. No analytics, no tracking, and no advertising cookies in the app

At the current stage, the app itself does not use analytics SDKs, advertising tracking, or marketing cookies. alligkeit does not create user profiles inside the app for advertising or tracking purposes.

The feedback function (D8, section 3) is not tracking either: it collects nothing in the background and transmits only what you wrote and actively sent yourself.

This statement applies to the app itself. For the separate websites, see section 14.

11. Changes to this Privacy Policy

We may update this Privacy Policy if the app, the service providers, the legal framework, or the processing flows change. The current version will be published at https://legal.alligkeit.com. We will notify you in the app of material changes before the affected processing; where renewed consent is required, that cloud processing will not take place until you consent again. Since alligkeit does not operate user accounts, there is no separate email notification flow.

12. Voluntariness and the consequences of your choices

Using alligkeit is voluntary. Consent to cloud processing is also voluntary.

If you do not grant consent for cloud processing, or if you later withdraw it:

13. No automated decision-making and no profiling

alligkeit does not use automated decision-making within the meaning of Article 22 GDPR. It also does not perform profiling that produces legal effects or similarly significant effects for you.

14. Notice about the websites (legal.alligkeit.com / alligkeit.com)

The legal website is hosted on Cloudflare Pages. These notices also apply to a future landing page at https://alligkeit.com to the extent that it is delivered in the same or a comparable technical setup. When you access these websites, technical connection data may be processed, in particular your IP address, time of access, requested URL, referrer, browser / user-agent data, and security / request metadata. This serves the secure and stable delivery of the sites and abuse prevention.

Cloudflare may set strictly necessary cookies, in particular __cf_bm for bot-management functions and _cfuvid for certain rate-limiting or security functions, if those functions are active. alligkeit currently does not use its own analytics or marketing technology on the legal website. If the landing page later uses additional features, first-party tracking, or different hosting, this Privacy Policy will be updated before those changes go live.

The lawful basis for the technically necessary hosting and protection of this website is Article 6(1)(f) GDPR (legitimate interests in the secure, stable, and abuse-resistant delivery of legally required information).

15. Status of this Privacy Policy

This Privacy Policy is available in a German and an English version. To the extent permitted by law, the German version is authoritative; mandatory data-subject rights remain unaffected.

Last updated: 2026-08-03 Version: v2.6