CTdigital solutions Christian Tonke
🇩🇪 DE·🇺🇸 EN·🇪🇸 ES·🇫🇷 FR·🇮🇹 IT·🇳🇱 NL·🇵🇹 PT
HomeProjectsContactSupportLegal notice

Legal

Data protection notes for apps

Supplementary notes to the general Data protection for the productivity and everyday apps by Christian Tonke. One section per app: what is stored locally, which permissions are used and why, and whether data leaves the device.

Contents

  • Controller
  • Applies to all apps

Apps

  • Contract Clock Local only
  • CrossDevice Drop Local + optional own server
  • Decision Ledger Local + optional cloud sync
  • Doc Memory Local only
  • Emergency Pack Local only
  • FamilyCare Handoff Local + optional own server
  • FieldProof Local + optional own server
  • FollowThrough Local only
  • Home Inventory Snap Local only
  • HomeOps Local only
  • Incident Chronicle Local + optional cloud sync
  • Maintenance Rhythm Local only
  • ManualShelf Local only
  • Meeting Actions Local only
  • MoveProof Local + optional cloud sync
  • Network Change Ledger Local + optional cloud sync
  • People Journal Local only
  • PetCare Circle Local + optional own server
  • Pickup Pass Local + optional own server
  • PrivateScribe Local + optional cloud sync
  • Reading Inbox Local + optional cloud sync
  • Repo Pocket Local + optional cloud sync
  • Return Window Local only
  • SceneRecall Local + optional own server
  • ShiftBridge Local only
  • SoloPortal Local + optional own server
  • ToolCircle Local only
  • Travel Claim Binder Local only
  • Vehicle Passport Local only
  • Warranty Guard Local only
  • App stores
  • Legal basis
  • Your rights

Controller

Christian Tonke
Adelheider Str. 258
27755 Delmenhorst
Germany
Email: christian@tonke.de

Applies to all apps

  • No user account. None of the apps requires registration, an email address or a login with me. I do not know who uses the apps.
  • Local first. All content is stored in a local database on your device; depending on the app, photos, documents and audio are additionally encrypted with a key in the keychain (iOS Keychain or Android Keystore). Deleting the app removes this data.
  • Three classes. (a) Local only: data leaves the device only when you share or back it up yourself. (b) Optional cloud sync: additionally an end-to-end encrypted sync, off by default, via your own iCloud Drive or Google Drive – with no server of mine. (c) Optional server: additionally a self-hosted server for collaboration or web links that you or your team operate. The class is shown at the top of each app section.
  • Usage statistics only with opt-in. Every app offers usage statistics that are off by default. If you turn them on, the app counts anonymous, typed events (such as “export created”) exclusively on the device, without content, without identifiers and without transmission to me or any analytics service. There is no advertising, no tracking SDK and no crash reporting to third parties.
  • Notifications. Reminders are scheduled as local notifications on the device and need no internet connection. Only apps with a server additionally use push notifications without content.
  • Sharing and export only on your request. PDF, CSV, JSON, ZIP or text are created only when you trigger it, with field selection and preview; personal or sensitive fields are deselected by default. Where you share a file is decided in the system share sheet.
  • Backups in your hands. Backups are files that you store and restore yourself. Your operating-system backup (iCloud or Google device backup) is subject to Apple's or Google's terms; some apps exclude particularly sensitive data from it.
  • Deletion. The settings of every app contain “Delete all data”. This removes database, files and keys on the device; with sync or a server enabled, also the cloud files or the workspace on the server if you confirm it.
  • Demo data for trying things out stays on the device and can be removed with one tap.
  • Diagnostics. A diagnostic report in the settings contains only technical details (version, device, error codes), no content – and is only sent if you email it to support yourself.

Contract Clock

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Contracts (provider, term, notice period, prices), reminders, cancellation letters including your signature, proof of dispatch and confirmation, and photos or PDFs of contracts and receipts. Attachments are stored encrypted inside the app.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a contract, a price letter, a cancellation confirmation or a posting receipt.
  • Photos: only when you pick an existing photo of a document.
  • Notifications: to remind you before a notice deadline.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

CrossDevice Drop

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Your drops (text, links, notes, up to five files per drop), the list of your paired devices, expiry rules and a history. The key of your device space lives only in the keychain of your devices; drops marked confidential are additionally protected by the app lock.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you scan the pairing QR code of one of your own devices or take a photo to send.
  • Photos: only when you pick a photo yourself to send it.
  • Face ID / Touch ID / fingerprint: so that only you can open drops marked as confidential.
  • Notifications: to notify you about new drops (push, without content).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

A drop is encrypted on the sending device with AES-256-GCM. The server only relays the encrypted envelope, keeps it until it expires (10 minutes to 30 days, optionally “delete after reading”) and then removes it. It sees the space name, device names, platform, push tokens, who sends to whom and when, expiry dates and the size of the ciphertext – but never titles, text, links, file names or file contents, and never the key. The web receive page decrypts in the browser; the key of a share link sits behind the “#” in the URL and is not transmitted.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

Decision Ledger

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Decisions with context, options, criteria, assumptions, people involved, review dates and learnings, an immutable history, and attachments (files or screenshots you add yourself). Attachments are stored AES-256-GCM encrypted inside the app container.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Face ID / Touch ID / fingerprint: to lock the app if you turn on the app lock.
  • Notifications: to remind you of review dates.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Doc Memory (Local Document Memory)

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Scanned documents (images and PDFs), the text recognised on the device, detected fields such as date, amount or deadline, tags, notes and deadlines. Documents are stored AES-256-GCM encrypted inside the app; the key stays in the device keychain. Text recognition runs entirely on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you scan documents.
  • Photos: only when you import photos you pick yourself, e.g. photographed letters.
  • Face ID / Touch ID / fingerprint: for the optional app lock that protects your documents.
  • Notifications: to remind you of confirmed deadlines.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Emergency Pack

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Emergency profiles with details you enter yourself as self-declared information (e.g. date of birth, blood type, allergies, pre-existing conditions, medications, insurance), emergency contacts, copies of documents such as ID or health card, and action cards. This information is particularly sensitive; the app stores it AES-256 encrypted with the key in the device keychain, and it stays on the device only. The app evaluates nothing and gives no medical advice. The emergency button only opens the phone app; you confirm the call yourself.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a document such as an ID or health card.
  • Photos: only when you pick an image yourself as a document copy.
  • Face ID / Touch ID / fingerprint: to unlock the emergency folder if you turn on the app lock.
  • Notifications: to remind you of expiring documents or review dates.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

FamilyCare Handoff

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Care circles (cared-for person, members, roles), daily handoffs with summary, observations without diagnosis, tasks, appointments and next steps, confirmations, a history, and documents (photos or files) you add yourself. Documents are stored encrypted.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a document such as a plan or a letter.
  • Photos: only when you pick an image yourself as a document.
  • Notifications: to remind you of tasks and – with a server – to notify you about new handoffs (push, without names or content).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

A circle works entirely on one device, for example a family tablet. Only when you choose “Share circle” does the app connect to a family server. The shared circle's content goes there: handoffs, observations, tasks, documents, member names and roles, and the devices' push tokens. Transport is TLS encrypted, but the content is not end-to-end encrypted on the server – whoever runs the server can technically read it. Invitation and pairing codes are stored only as hashes; push notifications and logs contain no content.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

FieldProof

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Customers and jobs, checklists, before/after photos with defect markers, material, working time, summaries, customer signatures and a history. Location data is stored only if you explicitly switch it on for a single photo.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you take proof photos or scan the QR code of a team invitation.
  • Photos: only when you pick a photo yourself as evidence.
  • Location (while in use): to add the position to a single proof photo – only if you switch it on for that photo, never in the background.
  • Notifications: to remind you of jobs and – with a server – to notify you when a customer confirms or objects (push, without content).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

Without a server the app is fully usable (report as PDF instead of a link). A team server enables sync between several technicians and devices with roles, a web proof view for customers via link without a customer account (with optional confirmation or objection in the browser), photo uploads, team templates and push. The workspace's job data goes there, including photos, signatures and customer names, plus push tokens; GPS positions and internal notes appear in the customer view only if the technician explicitly releases them. Transport is TLS encrypted; content is not end-to-end encrypted on the server. Customer link tokens are stored only as hashes; the server keeps an audit log without content.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

FollowThrough

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Your items (title, time window, first step, steps, outcome, blocking reasons), reminder settings, daily reviews and an immutable history.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Microphone: only when you capture an item by voice – nothing is recorded or stored.
  • Speech recognition: turns your speech into text while you dictate. The app uses the system's speech recognition (Apple or Google) and prefers on-device recognition; on devices without on-device support the system may send speech to Apple or Google. The app itself stores no audio recording.
  • Calendar (read only): only when you import events as follow-up items; the app only reads and writes nothing to your calendar.
  • Notifications: to show staged reminders and check-ins.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Home Inventory Snap

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Rooms and items with photos, category, value, purchase date, serial number and receipts, plus exports for your insurer. Photos and receipts are stored encrypted inside the app. Text recognition for rating plates and serial numbers runs on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph items, rating plates or receipts, or scan a serial number.
  • Photos: only when you pick existing pictures of your items or receipts.
  • Notifications: to remind you to update the inventory or make a backup.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

HomeOps

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Your household devices (manufacturer, model, serial number, year), maintenance intervals and history, warranty and purchase data, receipts, manuals and documents as photos or PDFs, spare-part numbers, service contacts and the emergency sheet. Text recognition for rating plates and receipts runs directly on the device; photos are never uploaded.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph rating plates, receipts or documents.
  • Photos: only when you pick existing photos of rating plates, receipts or manuals.
  • Notifications: to remind you on the due date of a maintenance job or before a warranty ends.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice.

Incident Chronicle

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Incidents with timeline, decisions, people involved, actions, postmortem drafts and evidence (screenshots and photos you add yourself). Evidence is stored AES-256-GCM encrypted inside the app container.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph evidence such as screens, dashboards or hardware.
  • Photos: only when you pick existing screenshots or photos as evidence; only those images are copied into the app.
  • Face ID / Touch ID / fingerprint: to lock your incident records if you turn on the app lock.
  • Notifications: to remind you of postmortem dates and open actions.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Maintenance Rhythm

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Objects (devices, vehicles, equipment), maintenance plans, meter readings such as operating hours or mileage, checklists, consumables, completed jobs and proof photos. Photos are stored encrypted inside the app.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a finished maintenance job or a rating plate as proof.
  • Photos: only when you pick an existing photo as proof.
  • Calendar: to add upcoming maintenance dates to a calendar you choose – only after you connect it; the app only changes events it created itself. It does not use your reminders.
  • Notifications: to remind you of due maintenance.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password.

ManualShelf

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Appliances with rating-plate photo, manufacturer, model and serial number, manuals as photos or PDFs, spare and wear parts, maintenance plans and history, and the shopping list. Photos are stored encrypted inside the app; rating-plate text recognition runs on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a rating plate, manual pages or a finished maintenance job, or scan a barcode or QR label.
  • Photos: only when you pick an existing photo of a rating plate, manual pages or a repair.
  • Notifications: to remind you before due maintenance such as descaling or filter changes.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Meeting Actions (Meeting Actions – lokal)

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Meetings with title, participants and agenda, audio recordings, transcripts, suggested and confirmed action items and decisions, and a history. Audio is stored encrypted and you decide how long raw data is kept. Transcription runs with the Whisper speech model directly on the device; the model is downloaded once from huggingface.co (Wi-Fi only if you choose) – no content is transmitted.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Microphone: only when you record a meeting – only while recording.
  • Speech recognition: only for the optional live transcript and for imported audio files in formats Whisper cannot read. For this the app uses the system's speech recognition; on devices without on-device support the system may send speech to Apple or Google – the app shows this. The default is Whisper transcription on the device.
  • Face ID / Touch ID / fingerprint: to lock confidential meetings.
  • Notifications: to remind you on the due date of an action item.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

MoveProof

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Handover reports with property, parties (names), rooms, photos with defect markers, meter readings, keys, signatures and history. Photos are stored without location data and AES-256-GCM encrypted inside the app container.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph rooms, defects, meter readings or keys for a report.
  • Photos: only when you pick existing photos as evidence; only those are copied into the app.
  • Notifications: to remind you of open reports or follow-up dates.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Network Change Ledger

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Change records with devices, ports, VLANs, IP addresses, initial and target state, rollback plans, checklists, reachability checks, snapshots, photos of racks and ports, and a history. Photos are stored encrypted. Credentials for optional NetBox or Jira connections live only in the keychain and are never part of backups, exports or sync.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you scan QR codes or barcodes on network devices or photograph ports and racks.
  • Photos: only when you pick existing photos of ports, racks or labels.
  • Local network: to check whether the addresses you enter in a change record (for example a switch web interface) respond via HTTP(S) before and after the change. There is no port scan and no ping; the app only contacts addresses you entered yourself.
  • Notifications: to remind you of maintenance windows and open steps.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

Optionally you can connect your own NetBox instance (read only) or Jira (take over ticket titles, post proof as a comment after preview). These connections go exclusively to the addresses you enter.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

People Journal

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

People with notes, meetings, topics, promises and reminders, plus images you add through the file picker. These notes concern other people – treat them with care; the app keeps them only on your device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Contacts: to take over a contact or link it to a person – only the contact you pick; your address book is never changed.
  • Calendar (read only): only when you link your calendar, to note appointments as encounters and remind you of the briefing; the app only reads.
  • Face ID / Touch ID / fingerprint: to unlock the app if you turn on the app lock.
  • Notifications: to remind you of promises and briefings.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

PetCare Circle

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Care circles with members and roles, pets with profile and feeding plan, the care log (who fed, walked, watered, gave medication and when), handoffs, tasks, photos and documents such as vaccination records. For walks only duration, distance and a roughly rounded starting point are stored. Photos are stored encrypted.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph your pet, an entry or a document such as a vaccination record.
  • Photos: only when you pick an image yourself for a pet or an entry.
  • Location (while in use): to measure the distance of a walk – only if you switch it on for that walk.
  • Notifications: to remind you of feedings and tasks and – with a server – to notify you about entries by others (push, without names or content).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

A circle also works on a single device. For several people to collaborate, the app connects to a circle server. Pets, care log, handoffs, observations, tasks, documents, member names and push tokens go there. Transport is TLS encrypted; content is not end-to-end encrypted on the server. Sitter links show only the fields the circle owner releases; invitation codes are stored only as hashes, push notifications and logs contain no content.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

Pickup Pass

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Family circles with guardians, children (first name, facility and group only), facilities, authorised pickup persons (name, photo, ID hint, optional code word), pickups with time window, approvals, pickup codes and an immutable history. Photos are stored encrypted; keys and codes live in the keychain.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you scan the QR code of a pickup pass or take a photo of a pickup person for the facility.
  • Photos: only when you pick a picture of a pickup person yourself.
  • Face ID / Touch ID / fingerprint: to protect the app and pickup codes if you turn it on.
  • Notifications: to remind you of pickups and – with a server – to notify you about approvals and confirmations (fixed texts such as “Pickup confirmed”, without names).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice.

Optional server

A circle works entirely on one device, including offline codes that a parent checks in the app. Links for pickup persons, the facility's verification page and approval by two guardians require the server. The shared family circle's data goes there: children's first names, pickup persons with photo, time windows, facilities, approvals and push tokens. Transport is TLS encrypted but not end-to-end – the facility has to be able to see the pickup person's name and photo. Pickup, invitation and pairing codes are stored only as hashes; audit log and logs contain no content.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

PrivateScribe

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Audio recordings, transcripts with speaker assignment, corrections, highlights and tasks. Transcription runs with the Whisper speech model entirely on the device, even in flight mode. The speech model is downloaded once from huggingface.co; no content is transmitted.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Microphone: only when you record a conversation – also while the screen is locked; the recording never leaves the device.
  • Face ID / Touch ID / fingerprint: to protect your confidential recordings and transcripts.
  • Notifications: on Android to show the running recording as a foreground service and to inform you about finished transcriptions.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Reading Inbox

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Saved links with title, author, site and description, offline copies of article text, your own texts and PDFs, highlights, notes, tags, reading progress and reminders. Offline copies are stored AES-256-GCM encrypted; the key lives in the keychain.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Notifications: to show “read later” reminders, the daily prompt and the weekly review.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

To make a saved article available offline, the app fetches the web page you saved – without cookies, images or scripts, Wi-Fi only if you choose. As with any browser visit, that website learns your IP address. Sites that opt out of archiving remain plain links. “Original page” opens the page in an embedded browser view.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Repo Pocket

Local, with optional end-to-end encrypted sync via your own iCloud Drive or Google Drive

What the app stores locally

Offline snapshots of repositories (files and contents, exact commit), bookmarks and notes on lines, checklists and results. Access tokens for private repositories live exclusively in the device keychain and are never part of backups, exports, diagnostics or sync.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Notifications: to remind you of open items or review dates.
  • Photo library: The app does not access your photo library. The permission text exists only because a bundled system library supports the photo library in general; images enter the app only through the file picker or “Share”.

Does data leave the device?

Not by default. All content stays on your device; the app has no user account and no server of its own. Data leaves the device only when you share, export or back it up yourself – or when you turn on the optional sync (see below).

To load a repository the app connects to the host you specify – GitHub, GitLab (including self-hosted), Gitea/Forgejo/Codeberg, Bitbucket or any ZIP address. Public repositories load without an account; for private ones you use your own token or GitHub device login. Tokens are sent only to the respective host.

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional sync via your own cloud

In the settings you can turn on sync between your own devices. On iOS it uses a hidden app folder in your iCloud Drive, on Android the app data folder of your Google Drive (Google sign-in only for that folder, scope drive.appdata). All data is encrypted on the device beforehand with AES-256-GCM; the key is derived from your sync password (PBKDF2-SHA256) and stays in the keychain. Apple, Google and I only see encrypted files. Without your password the data cannot be restored. Sync is off by default and can be switched off at any time; the cloud files can be deleted in the settings.

Return Window

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Purchases with retailer, date, amount and return deadline, receipts and order confirmations as photos or PDFs, returns with proof of shipping and tracking number, and refunds. Receipts are stored encrypted inside the app; text recognition runs on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a receipt, a return label or the item's condition, or scan a tracking number.
  • Photos: only when you pick an existing photo of a receipt or order confirmation.
  • Notifications: to remind you before a return deadline expires and of open refunds.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

SceneRecall

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Your scene descriptions and attributes, candidates with rating and exclusion reasons, episodes, scene positions, watchlist, history, notes (such as where and when you saw the scene) and reference pictures.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a scene on a screen or scan the QR code of an invitation.
  • Photos: only when you pick pictures yourself as reference pictures.
  • Microphone: only when you dictate a scene description.
  • Speech recognition: turns your speech into text while you dictate. The app uses the system's speech recognition (Apple or Google) and prefers on-device recognition; on devices without on-device support the system may send speech to Apple or Google. The app itself stores no audio recording.
  • Notifications: to remind you of follow-ups and – with a server – to notify you about suggestions from friends.

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

Without a server the app works locally (describe scenes, add candidates by hand, watchlist, export). The server does two things. First, metadata search: as a proxy it queries the film and TV catalogues TMDB, TVmaze and Wikidata. Only the search terms and attributes you select (type, period, genre, people) leave the device – never the full description, pictures or private notes. The TMDB API key lives only on the server; catalogue responses are cached there for up to 24 hours, user data is not. This search also works without pairing. Second, optional sync and sharing: after pairing, your searches, candidates, watchlist, reference pictures and push tokens go to the server; share links show friends without the app only the selected parts, expire and can be revoked. Transport is TLS encrypted; content is not end-to-end encrypted on the server.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

Data sources

Film data comes from TMDB (themoviedb.org), TVmaze and Wikidata. SceneRecall uses the TMDB API but is not endorsed or certified by TMDB.

ShiftBridge

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Open items with title, risk, owner (name) and next step, handovers with checklists and notes, confirmations, a history, and photos and files as evidence. The app is designed for a shared team device per shift: all users of that device see the same data.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you take a photo as evidence for a handover point.
  • Photos: only when you pick an existing image as evidence.
  • Notifications: to inform you about due dates and automatically escalated items.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice.

SoloPortal

Local, with an optional self-hosted server – run by you, your team or your family

What the app stores locally

Clients (name, contact details), projects, briefings, deliverables with versions (files and images), comments, approval decisions, handover reports with signature and a history.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a draft or scan the QR code of an invitation.
  • Photos: only when you pick images yourself as a new version.
  • Notifications: to remind you of deadlines and – with a server – to notify you when clients comment, approve or reject (push, without content).

Does data leave the device?

Not by default. Without a server all content stays exclusively on your device; there is no user account with me. Data leaves the device only when you share or back it up yourself – or when you connect the app to a server (see below).

Backup: a backup file that you store and re-import yourself; it leaves the device only via the share sheet to a destination of your choice. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Optional server

Without a server the app is fully usable locally. The server enables the client portal via magic link (no client account), sync between your devices with roles, file uploads, team templates and push. Your workspace's project data goes there – client names, briefings, deliverable files, comments, decisions, signatures – plus push tokens. Your clients enter name, comment and decision in the portal; the portal uses no trackers and no third-party CDNs. Transport is TLS encrypted; content is not end-to-end encrypted on the server. Portal tokens are stored only as hashes; the server keeps an audit log without content.

Push notifications are delivered via Expo's Push Service (with Apple or Google push behind it). For this the server stores a push token of your device; the notifications contain no names and no content.

No server is preset – as delivered, the app works entirely on your device. You can enter your own server in the app at any time. The server is designed as an open-source package (Docker) for self-hosting, for example on a NAS or VPS. Whoever runs the server is responsible for the data stored there. I have no access to data on servers run by you or your team. If I operate the preset server myself, I process the data listed above solely to provide the service to you, do not pass it on and do not analyse it. Pairing works via QR code or short code instead of a user account; you can disconnect in the app and have the entire workspace including files deleted from the server.

ToolCircle (ToolCircle – Verleih-Liste)

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Items with photos and condition, loans with return date, people (name, phone number, email – taken from a contact or entered by hand), loan slips and a history. Photos are stored encrypted inside the app.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph the condition of an item at handover or return, or scan a QR label or loan slip.
  • Photos: only when you pick an existing picture of an item.
  • Contacts: to pick a person as borrower or lender – only name, phone number and email of that one contact are copied; your address book is never changed or uploaded.
  • Notifications: to remind you of due returns.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Travel Claim Binder

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Travel disruptions with timeline, booking details, receipts, tickets and boarding passes as photos or PDFs, provider contacts and the status of your claim. Receipts are stored AES-256-GCM encrypted on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a receipt, ticket or boarding pass.
  • Photos: only when you pick existing photos or screenshots such as delay notices.
  • Notifications: to remind you of claim deadlines.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Vehicle Passport

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Vehicles (including VIN, plate, first registration), service entries, odometer readings, parts, invoices as photos or PDFs, defects, inspection dates and exports. Invoices and documents are stored encrypted; text recognition for registration document, odometer and invoices runs on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph an invoice, the registration document, the odometer or a defect.
  • Photos: only when you pick an existing photo of an invoice, the vehicle or a defect.
  • Add to Photos: to save an image to your photo library – only if you choose “Save Image” while sharing an attachment.
  • Notifications: to remind you of inspections, services and due parts.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

Warranty Guard

Local only – data leaves the device only when you share or back it up yourself

What the app stores locally

Products with retailer, purchase date, price, serial number and warranty deadline, receipts and rating plates as photos or PDFs, defects and claims with history. Receipts are stored encrypted inside the app; text recognition runs on the device.

Permissions

Each permission is requested only when you first use the feature and can be revoked at any time in the system settings.

  • Camera: only when you photograph a receipt, a rating plate or a defect, or scan a serial number.
  • Photos: only when you pick an existing photo of a receipt or defect.
  • Notifications: to remind you before a warranty expires.

Does data leave the device?

No. All content stays exclusively on your device. The app has no user account, no server of its own and no cloud sync. Data leaves the device only when you export it yourself via the share sheet, pass on a PDF or create a backup – and only to the recipient you choose.

Backup: a password-protected, encrypted backup file (AES-256) that you store yourself, for example in your own cloud or on your computer. It cannot be read without your password. Share extension: content handed over via “Share” from other apps is copied only locally into this app.

App stores

When downloading and using an app through the Apple App Store or Google Play, Apple or Google process data independently, for example to operate their stores, install apps, provide updates and handle purchases. Read more in the Apple Privacy Policy and Google Privacy Policy.

Legal basis

Where I process personal data at all – for example when you email me or when I operate a preset server myself – this is done to fulfil the usage relationship (Art. 6(1)(b) GDPR) or on the basis of my legitimate interest in a secure, working service (Art. 6(1)(f) GDPR). Processing on your device, in your own cloud or on a server you operate takes place without my involvement.

Your rights

Subject to applicable law, you have rights of access, rectification, erasure, restriction, portability and objection. You may also lodge a complaint with a data-protection supervisory authority. Because the apps work without an account, I can neither view nor delete data on your device – you do that yourself via “Delete all data” or by uninstalling the app. Questions can be sent to christian@tonke.de.

Last updated: September 2026

The German version is authoritative.

In short

No account, no ads, no tracking. Your data lives on your device. Sync and servers are optional and use your own cloud or your own server.

General Data protection · Questions via the contact form · Technical questions: Support · christian@tonke.de

digital solutions Christian Tonke

Apps, software & digital products

SupportData protectionLegal notice