Privacy policy
This English version is a convenience translation. The German privacy policy is legally binding.
This policy covers the website zeitlicht.app, the application at start.zeitlicht.app and the iOS and Android apps (together “Zeitlicht”). Last updated: 23 September 2026.
1. Controller
Vincent OswaldBernstorffstraße 118
22767 Hamburg
Germany
Email: hello@zeitlicht.app
No data protection officer has been appointed; the thresholds of section 38 of the German Federal Data Protection Act (BDSG) are not met.
2. Overview
The marketing website zeitlicht.app sets no cookies, uses no local or session storage, runs no tracking, and loads no analytics or advertising. There is no profiling. No consent under section 25 TDDDG is required for this website.
The application at start.zeitlicht.app processes personal data as needed for registration, the contract, workspace content, invitations, and transactional email. No analytics, crash-reporting, push or advertising services are included.
3. Where your data is stored
Zeitlicht is operated from Germany. Where we can choose the location ourselves, the data is stored in Germany:
- Website zeitlicht.app: ALL-INKL, Friedersdorf, Germany.
- Tasks, notes, attachments, timer sessions and server functions: Google Cloud, region europe-west3, Frankfurt.
Some services required to run the product are outside Germany. They are covered by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework:
- Sign-in (Firebase Authentication): United States only.
- Delivery of the application (Firebase Hosting): Google CDN, worldwide.
- Transactional email (Resend): sent from Ireland, stored in the United States.
Details of the processors are in section 12.
4. Website hosting (ALL-INKL)
This website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. We have an Art. 28 GDPR processing agreement with ALL-INKL.
When you request a page, the web server writes log files. These typically include IP address, date and time, URL, amount of data transferred, HTTP status, referrer (if sent) and user agent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability, security and abuse prevention). Logs are deleted after 7 days at the latest unless a concrete security review requires a shorter or longer period. They are not combined with other datasets.
5. Application hosting (Firebase Hosting)
The application at start.zeitlicht.app is delivered through Firebase Hosting (Google Ireland Limited). The static files are served from Google’s worldwide CDN. Requests produce technical access data (in particular IP address, date and time, URL, user agent). Legal basis: Art. 6(1)(f) GDPR (operating and securing the application). We have an Art. 28 GDPR processing agreement with Google.
The application loads fonts and its graphics library locally from start.zeitlicht.app. It does not load third-party analytics or advertising scripts.
6. Email contact
If you write to hello@zeitlicht.app, we process the data you send in order to reply. Legal basis: Art. 6(1)(b) GDPR where the message relates to a contract or pre-contract enquiry, otherwise Art. 6(1)(f). Emails are deleted when the matter is closed, unless a legal retention duty applies.
7. Registration and account (application)
Using start.zeitlicht.app requires an account (email, password, display name, optional avatar). Authentication uses Firebase Authentication (Google Ireland Limited); that service processes account data in the United States. We also store your profile in Frankfurt (display name, avatar, email in the private profile, language, onboarding status). Legal basis: Art. 6(1)(b) GDPR.
Your email address is used to verify the account and to reset the password. Firebase Authentication also stores IP addresses and user agents for a few weeks to prevent abuse (Art. 6(1)(f) GDPR).
After sign-in the app stores technical data locally so you stay signed in and the interface works. That storage is strictly necessary for the service (section 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR). It is not a tracking cookie. In particular:
- The sign-in session via Firebase Authentication, typically in IndexedDB.
- A Firestore offline cache (up to 40 MB, typically IndexedDB) so content remains available on a weak connection.
- On the device via Shared Preferences: last used workspace and board, a pending invitation link, the “Hyperfocus” setting and the chosen timer sound.
You can remove this local data by signing out, clearing browser storage or deleting the app.
8. Workspace content
Tasks, notes, checklists, topics, comments, attachments, memberships and timer sessions are stored because you create them. Legal basis: Art. 6(1)(b) GDPR. Workspace members can see that content according to their role, including the display name and email of other members. Do not upload special categories of data (Art. 9 GDPR) unless necessary.
Attachments are stored in Cloud Storage in Frankfurt. Images and documents may be at most 10 MB, audio and video at most 50 MB, and thumbnails at most 300 KB. Permitted types include images, PDF, text, ZIP, MP3 and MP4. File name, type and size are stored with the item.
After you cancel or delete the account, personal data is deleted or anonymised once it is no longer needed for the contract and no retention duty applies. Workspace content that other members continue to use may remain in their workspace where the contract or joint use requires it. You can request account deletion and access by email to hello@zeitlicht.app.
9. Invitations
If a member invites another person to a workspace by email, we store the entered email address, the workspace, the role, the inviter and the invitation link. The invited person receives an email with the link. Legal basis towards the invited person: Art. 6(1)(f) GDPR (the inviting member’s legitimate interest in collaborating). The invitation email informs them of the processing (Art. 14 GDPR). Anyone who does not want to be invited can ignore the email or ask us at hello@zeitlicht.app to delete the data.
The invitation is stored until it is accepted, withdrawn or no longer needed. We then delete it.
10. Payment data
For paid subscriptions, payment data is processed by the payment service for that purchase. We do not store full card numbers. Legal basis: Art. 6(1)(b) GDPR and, for tax retention of invoices, Art. 6(1)(c) GDPR with German tax law (generally 10 years).
Depending on where you subscribe:
- Stripe Payments Europe, Ltd., Ireland, for web subscriptions. Card data stays with Stripe. We store the Stripe customer id, the subscription id and the resulting plan.
- Apple (App Store) and Google (Google Play) for subscriptions in the apps. The stores process the payment as independent controllers. We store the transaction id or purchase token only to attach the subscription to your account, plus plan and term.
We also store your referral code and, if you redeem one, the link to the inviting account. That is how the referral credit is applied (Art. 6(1)(b) GDPR). The code is kept for as long as the account exists.
11. Abuse protection for email
To stop invitations, confirmations and password resets being abused, we briefly store a checksum (SHA-256) of the relevant request together with a counter, in Frankfurt. The original email address cannot be read from it. Legal basis: Art. 6(1)(f) GDPR (security and abuse prevention). The entries lapse when the time window ends.
12. Processors
We use the following processors (each with an Art. 28 GDPR agreement):
- ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany: hosting the website zeitlicht.app, servers in Germany.
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland:
- Cloud Firestore, Cloud Storage and Cloud Functions: storing and processing workspace content and server functions in region europe-west3 (Frankfurt).
- Firebase Hosting: delivering start.zeitlicht.app via the Google CDN.
- Firebase Authentication: sign-in and account security. This service runs only in US data centres and processes email, password (hashed), display name and, for a limited time, IP address and user agent. After deletion, Google typically removes authentication data from live and backup systems within 180 days; IP addresses are deleted after a few weeks.
- Resend, Inc., United States: sending transactional email (verification, password reset, invitations). Recipient address and mail content are transmitted to Resend. Email is sent from Ireland (eu-west-1); Resend stores account data, metadata and logs in the United States. A pre-signed Art. 28 GDPR processing agreement is in place with Resend.
- Stripe Payments Europe, Ltd., Ireland: payment processing for web subscriptions, under an Art. 28 GDPR agreement. Stripe handles card data as an independent controller or as a processor, depending on the step.
- Apple Distribution International Ltd., Ireland, and Google Ireland Limited (Google Play): in-app purchases. Apple and Google are independent controllers of the store account, not our processors.
13. Transfers outside the EEA
Where Google, Resend, Stripe or Apple involve a transfer to the United States or another third country, it is based on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision where the recipient is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). For Resend the SCCs apply as Module 2 (controller to processor). You may request a copy of the safeguards via the contact details above.
14. Storage periods
- Website server logs: see section 4.
- Account data: until account deletion, then residual deletion after any retention periods.
- Firebase Authentication data: see section 12.
- Invitations: until accepted, withdrawn or no longer needed.
- Contract and invoice data: statutory periods, typically 6 years (German Commercial Code) or 10 years (German Fiscal Code).
- Email correspondence: until the matter is closed, unless a longer duty applies.
- Local storage in the browser or on the device: until you delete it or sign out.
15. No cookies on zeitlicht.app, no tracking
This marketing website sets no cookies, stores nothing in the browser, and loads no third-party scripts, fonts or media. Fonts are hosted locally. The language switch is an ordinary link with no stored preference. There is no consent banner because there is no non-essential storage and no tracking.
The application at start.zeitlicht.app uses only the technical storage needed for sign-in and operation, not for advertising or reach measurement. No analytics, crash-reporting, push or advertising services are included.
16. Security
We take technical and organisational measures appropriate to the risk. These include in particular:
- Transfer only over TLS; HTTP Strict Transport Security.
- Security headers on the application (including Content-Security-Policy, X-Frame-Options, Referrer-Policy).
- Access to content through server-side Firestore and Storage rules with a role model.
- Revocation of sign-in tokens when a member is removed from a workspace.
- Limits on email frequency and attachment size.
17. No automated decision-making
There is no automated decision-making including profiling within the meaning of Art. 22 GDPR.
18. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Object informally at hello@zeitlicht.app. Where processing is based on consent, you may withdraw it with effect for the future.
You can request access and deletion of the account by email to hello@zeitlicht.app. We will handle this without undue delay.
You may lodge a complaint with a supervisory authority, in particular where you live or where we are established. Ours is: Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, https://datenschutz.hamburg.de.
19. Requirement to provide data
Without the account data needed for the service (in particular email and password) we cannot perform the contract for the application. You can read the marketing website without providing data; your browser still transmits the request data in section 4.
20. Changes
We update this policy when processing or the law changes. The version published on this page applies.