Privacy Policy for Stillwort
This is an English translation of our German privacy policy (Datenschutzerklärung). In case of any discrepancy, the German version prevails.
1. Controller and scope
This policy applies to the website stillwort.punktdev.com and the Stillwort app. The controller is Real Movement Analytics GmbH, Kleines Everstal 18d, 44388 Dortmund, Germany. Contact: [email protected].
We do not use any analytics, tracking or advertising services in the app or on the website, and we do not create usage profiles. No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place.
2. Website and content delivery
Our website as well as the texts, images and audio of the app are delivered via Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Each online request involves processing your IP address and technical request data, such as the time, the requested address, browser/app information and the response status. This is necessary to send content to your device and to protect the service against disruption and abuse.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and reliable operation. Where a request is necessary to provide purchased premium content, Art. 6(1)(b) GDPR applies. Technical logs are only kept for as long as required for delivery, troubleshooting and defending against specific security incidents. Cloudflare also processes technical operating data in accordance with its privacy policy.
Cloudflare may receive network error reports from supported browsers. These are used to diagnose connection problems.
The app loads quotes, images and audio from our content storage on Cloudflare Pages. In-depth texts and their audio are delivered by our access service on Cloudflare Workers (Section 4). It logs requests at Cloudflare for troubleshooting; these logs may contain the app identifier described in Section 4 and are deleted after 7 days at the latest.
3. Local app data and reminders
The app stores bookmarks, read content, progress, journal notes, language, display and audio settings, reminder times and downloaded content locally on your device. This data is not transmitted to us. Local reminders are scheduled on your device; for this, the app asks for notification permission, which you can revoke at any time in your system settings. The audio consists of pre-produced recordings (MP3 files). The app downloads them from Cloudflare (Section 2) and stores them on your device for offline listening; it does not use your device's speech output for this. When you share content, this happens via your operating system's share function to the recipient you choose.
This storage serves the features you request (Section 25(2) no. 2 of the German TDDDG; where personal data is processed, Art. 6(1)(b) GDPR). The data remains stored until you remove it in the app, delete the relevant app data or uninstall the app. Depending on your system settings, operating-system backups and device transfers may contain copies.
4. Premium, App Store, Google Play and RevenueCat
In the App Store, Apple processes downloads and payments under Apple's privacy policy; in Google Play, Google does so under Google's privacy policy. Each payment provider is independently responsible for its own processing. This also applies to ratings you submit via the store's review dialog offered in the app.
We use RevenueCat, Inc., USA, to process purchases, restore them and verify premium access. This involves processing a pseudonymous app identifier, product and transaction identifiers, purchase times, subscription and entitlement status, and technical device and connection data. RevenueCat generates the pseudonymous app identifier itself, already on the first launch of the app, even if you never buy anything. On every launch the app uses it to check whether a premium entitlement exists. The app also sends it to our access service on Cloudflare Workers when it requests in-depth texts or audio. The access service uses it to ask RevenueCat whether a premium entitlement exists and keeps the result briefly in Cloudflare's cache: a missing entitlement for 5 minutes, an active one for 1 hour and additionally for up to 30 days as a fallback in case RevenueCat cannot be reached. To prevent abuse, Cloudflare counts these requests per IP address for one minute at a time; we do not store the IP address.
The legal basis is Art. 6(1)(b) GDPR for providing and managing the premium offering, Art. 6(1)(f) GDPR for abuse prevention and Art. 6(1)(c) GDPR for statutory retention obligations. Without a purchase, processing by RevenueCat is based on Art. 6(1)(f) GDPR: our legitimate interest is recognising purchased access without an account, for example after reinstalling. For users without a purchase, RevenueCat only holds the random identifier, the app version and technical device data. You can object to this (Art. 21 GDPR); we will then delete the identifier at RevenueCat. Purchase and entitlement data is stored for as long as it is needed for active entitlements, purchase restoration or legal obligations. RevenueCat privacy policy.
5. Browser storage and external links
The website stores your chosen language and display settings in your browser's local storage (keys stillwort-lang and stillwort-theme). This is necessary for the settings you have expressly chosen (Section 25(2) no. 2 TDDDG). You can remove these entries by clearing your browser data.
The website does not measure reach or usage.
When you open external links, for example to the Play Store or to sources, the privacy policy of the respective destination applies. The website's Play Store links contain the referral parameter utm_source=stillwort.punktdev.com so that Google can show us in aggregated form how many visits come from this website.
6. Contact by email
If you email us, for example at [email protected], it arrives in our company mailbox at Microsoft 365 (Microsoft Ireland Operations Ltd., Ireland). For some addresses, Cloudflare first receives the message through its Email Routing service and forwards it there; Cloudflare processes the sender, recipient and time and does not store the content permanently. Microsoft stores the email including its content and attachments as a processor under a data processing agreement (Art. 28 GDPR), generally in data centres in the EU. Microsoft relies on the EU-US Data Privacy Framework and EU Standard Contractual Clauses for transfers to Microsoft Corporation in the USA, for example for support or security.
We process your address, the content and any information you provide voluntarily to answer your request. The legal basis is Art. 6(1)(b) GDPR for contract-related requests and otherwise Art. 6(1)(f) GDPR; our legitimate interest is answering requests. The message is deleted once it is no longer needed for follow-up questions, legal defence or statutory retention duties. The app's feedback feature only opens your email app with a prepared message to us; nothing is sent until you send it yourself. Providing data is voluntary; without a reply address we cannot answer.
7. Recipients and processing outside the EU
For the purposes described, we use these service providers:
- Cloudflare, Inc. (USA): hosting, content delivery, access service and email forwarding as a processor under a data processing agreement (Art. 28 GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses apply in addition.
- RevenueCat, Inc. (USA): purchases and premium access as a processor under a data processing agreement (Art. 28 GDPR). Transfers to the USA are based on the EU Standard Contractual Clauses (Module 2) agreed in it.
- Microsoft Ireland Operations Ltd. (Ireland): Microsoft 365, our email mailbox, as a processor under a data processing agreement (Art. 28 GDPR). Data is generally stored in the EU; transfers to Microsoft Corporation (USA) rely on the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
You can request a copy of the safeguards at [email protected].
The providers explain their contractual data protection terms in the Cloudflare DPA and the RevenueCat DPA.
8. Your data protection rights
Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing and data portability.
Right to object: Where we process personal data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation.
You have the right to lodge a complaint with a data protection supervisory authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
9. Changes and language versions
We update this policy when the app, the website or the legal situation changes. The version published here applies. This English version is a translation; the German version is authoritative.