Privacy policy

This English version is a convenience translation. The German privacy policy is legally binding.

This policy covers the website zeitlicht.app, the application at start.zeitlicht.app and the iOS and Android apps (together “Zeitlicht”). Last updated: 23 September 2026.

1. Controller

Vincent Oswald
Bernstorffstraße 118
22767 Hamburg
Germany
Email: hello@zeitlicht.app

No data protection officer has been appointed; the thresholds of section 38 of the German Federal Data Protection Act (BDSG) are not met.

2. Overview

The marketing website zeitlicht.app sets no cookies, uses no local or session storage, runs no tracking, and loads no analytics or advertising. There is no profiling. No consent under section 25 TDDDG is required for this website.

The application at start.zeitlicht.app processes personal data as needed for registration, the contract, workspace content, invitations, and transactional email. No analytics, crash-reporting, push or advertising services are included.

3. Where your data is stored

Zeitlicht is operated from Germany. Where we can choose the location ourselves, the data is stored in Germany:

Some services required to run the product are outside Germany. They are covered by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework:

Details of the processors are in section 12.

4. Website hosting (ALL-INKL)

This website is hosted by ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. We have an Art. 28 GDPR processing agreement with ALL-INKL.

When you request a page, the web server writes log files. These typically include IP address, date and time, URL, amount of data transferred, HTTP status, referrer (if sent) and user agent. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stability, security and abuse prevention). Logs are deleted after 7 days at the latest unless a concrete security review requires a shorter or longer period. They are not combined with other datasets.

5. Application hosting (Firebase Hosting)

The application at start.zeitlicht.app is delivered through Firebase Hosting (Google Ireland Limited). The static files are served from Google’s worldwide CDN. Requests produce technical access data (in particular IP address, date and time, URL, user agent). Legal basis: Art. 6(1)(f) GDPR (operating and securing the application). We have an Art. 28 GDPR processing agreement with Google.

The application loads fonts and its graphics library locally from start.zeitlicht.app. It does not load third-party analytics or advertising scripts.

6. Email contact

If you write to hello@zeitlicht.app, we process the data you send in order to reply. Legal basis: Art. 6(1)(b) GDPR where the message relates to a contract or pre-contract enquiry, otherwise Art. 6(1)(f). Emails are deleted when the matter is closed, unless a legal retention duty applies.

7. Registration and account (application)

Using start.zeitlicht.app requires an account (email, password, display name, optional avatar). Authentication uses Firebase Authentication (Google Ireland Limited); that service processes account data in the United States. We also store your profile in Frankfurt (display name, avatar, email in the private profile, language, onboarding status). Legal basis: Art. 6(1)(b) GDPR.

Your email address is used to verify the account and to reset the password. Firebase Authentication also stores IP addresses and user agents for a few weeks to prevent abuse (Art. 6(1)(f) GDPR).

After sign-in the app stores technical data locally so you stay signed in and the interface works. That storage is strictly necessary for the service (section 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR). It is not a tracking cookie. In particular:

You can remove this local data by signing out, clearing browser storage or deleting the app.

8. Workspace content

Tasks, notes, checklists, topics, comments, attachments, memberships and timer sessions are stored because you create them. Legal basis: Art. 6(1)(b) GDPR. Workspace members can see that content according to their role, including the display name and email of other members. Do not upload special categories of data (Art. 9 GDPR) unless necessary.

Attachments are stored in Cloud Storage in Frankfurt. Images and documents may be at most 10 MB, audio and video at most 50 MB, and thumbnails at most 300 KB. Permitted types include images, PDF, text, ZIP, MP3 and MP4. File name, type and size are stored with the item.

After you cancel or delete the account, personal data is deleted or anonymised once it is no longer needed for the contract and no retention duty applies. Workspace content that other members continue to use may remain in their workspace where the contract or joint use requires it. You can request account deletion and access by email to hello@zeitlicht.app.

9. Invitations

If a member invites another person to a workspace by email, we store the entered email address, the workspace, the role, the inviter and the invitation link. The invited person receives an email with the link. Legal basis towards the invited person: Art. 6(1)(f) GDPR (the inviting member’s legitimate interest in collaborating). The invitation email informs them of the processing (Art. 14 GDPR). Anyone who does not want to be invited can ignore the email or ask us at hello@zeitlicht.app to delete the data.

The invitation is stored until it is accepted, withdrawn or no longer needed. We then delete it.

10. Payment data

For paid subscriptions, payment data is processed by the payment service for that purchase. We do not store full card numbers. Legal basis: Art. 6(1)(b) GDPR and, for tax retention of invoices, Art. 6(1)(c) GDPR with German tax law (generally 10 years).

Depending on where you subscribe:

We also store your referral code and, if you redeem one, the link to the inviting account. That is how the referral credit is applied (Art. 6(1)(b) GDPR). The code is kept for as long as the account exists.

11. Abuse protection for email

To stop invitations, confirmations and password resets being abused, we briefly store a checksum (SHA-256) of the relevant request together with a counter, in Frankfurt. The original email address cannot be read from it. Legal basis: Art. 6(1)(f) GDPR (security and abuse prevention). The entries lapse when the time window ends.

12. Processors

We use the following processors (each with an Art. 28 GDPR agreement):

13. Transfers outside the EEA

Where Google, Resend, Stripe or Apple involve a transfer to the United States or another third country, it is based on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) or an adequacy decision where the recipient is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). For Resend the SCCs apply as Module 2 (controller to processor). You may request a copy of the safeguards via the contact details above.

14. Storage periods

15. No cookies on zeitlicht.app, no tracking

This marketing website sets no cookies, stores nothing in the browser, and loads no third-party scripts, fonts or media. Fonts are hosted locally. The language switch is an ordinary link with no stored preference. There is no consent banner because there is no non-essential storage and no tracking.

The application at start.zeitlicht.app uses only the technical storage needed for sign-in and operation, not for advertising or reach measurement. No analytics, crash-reporting, push or advertising services are included.

16. Security

We take technical and organisational measures appropriate to the risk. These include in particular:

17. No automated decision-making

There is no automated decision-making including profiling within the meaning of Art. 22 GDPR.

18. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and to object to processing based on Art. 6(1)(f) (Art. 21). Object informally at hello@zeitlicht.app. Where processing is based on consent, you may withdraw it with effect for the future.

You can request access and deletion of the account by email to hello@zeitlicht.app. We will handle this without undue delay.

You may lodge a complaint with a supervisory authority, in particular where you live or where we are established. Ours is: Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, https://datenschutz.hamburg.de.

19. Requirement to provide data

Without the account data needed for the service (in particular email and password) we cannot perform the contract for the application. You can read the marketing website without providing data; your browser still transmits the request data in section 4.

20. Changes

We update this policy when processing or the law changes. The version published on this page applies.