1. Data Controller
"indie-Software" is the brand name under which Sven Korset operates as a sole proprietor (Einzelunternehmen). It is not a separate legal entity. Our terms of service are available here: https://indie-software.com/en/terms.html
1.1 Scope of This Policy
This Privacy Policy applies to our website indie-software.com, to the product websites we operate for our apps, and to our apps Cali, WoHiT and Lottie Tester (collectively, the "Services").
1.2 Representative in the EU and the UK
We are established in Switzerland and have no establishment in the European Union or the United Kingdom. We have not appointed a representative under Art. 27 GDPR or Art. 27 UK GDPR because our processing of personal data of persons in the EU/UK is only occasional, does not include special categories of data on a large scale, and is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 27(2)(a) GDPR). Persons in the EU and the UK can contact us directly using the details above.
2. Key Definitions
- Personal Data: Any information relating to an identified or identifiable natural person, as defined by the GDPR and the revDSG, including technical identifiers such as IP addresses or device identifiers.
- Processing: Any operation performed on Personal Data, such as collection, storage, use, disclosure, or deletion.
- Pseudonymized Data: Personal Data that can no longer be attributed to a specific individual without additional information (for example, a randomly generated identifier instead of a name). Pseudonymized Data is still Personal Data and is protected accordingly.
- Anonymized / Aggregated Data: Data that can no longer be attributed to a specific individual by anyone, for example statistics that only contain totals. Anonymized Data is not Personal Data.
- Data Controller: The person who determines the purposes and means of the processing of Personal Data. For our Services, this is Sven Korset (indie-Software), see Section 1.
- Data Processor: A service provider that processes Personal Data on our behalf and according to our instructions, bound by a data processing agreement.
3. Our Privacy Commitment
Our privacy practices are designed to comply with the Swiss Federal Act on Data Protection (revDSG) and the EU General Data Protection Regulation (GDPR). We apply these standards to all users, regardless of where you live.
We do not sell, trade, or otherwise commercialize your personal data, and we do not share it with third parties for advertising purposes. Our apps contain no advertising SDKs and no SDKs that track your behavior in the app or across apps and websites. The only third-party SDK in our apps is RevenueCat, which receives pseudonymized purchase events as described in Section 5.4.
4. Legal Basis and Overview
4.1 Legal Foundations for Processing
- Contractual Necessity (Art. 6(1)(b) GDPR): Providing the core functionality of our Services (e.g., app provisioning, syncing via iCloud, delivering downloadable content).
- Your Consent (Art. 6(1)(a) GDPR): Voluntary actions, such as sending us support logs or loading the Spotify player on the WoHiT website.
- Legitimate Interests (Art. 6(1)(f) GDPR): Technical security and abuse prevention, analyzing crash reports to fix errors, and analyzing pseudonymized purchase data to measure our App Store advertising and improve our apps. In each case we balance our interests against your data protection rights.
For users in Switzerland, all processing is conducted in accordance with the principles of the revDSG (lawfulness, good faith, proportionality, purpose limitation). Under Swiss law the processing described here does not require your consent.
4.2 What We Process vs. What Stays on Your Device
We (or our Data Processors on our behalf) only process:
- Server log data when you visit our websites (Section 5.1)
- Crash reports and aggregated usage statistics provided by Apple (Section 5.3)
- Pseudonymized purchase events from apps with In-App Purchases (Section 5.4)
- Emails you send us and support logs you choose to share (Section 5.1.2, 5.3)
Never leaves your device or your personal iCloud account: the content you create in our apps (tasks, workouts, notes) and all data our apps access on your device through iOS (calendar events, contacts, reminders). We have no servers that receive this data. Our apps may download content from our servers (e.g., music files for WoHiT); they never upload your content or device data.
4.3 No Automated Decision-Making or Profiling
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
4.4 Is Providing Your Data Required?
You are never legally obliged to provide us with personal data. Some data is technically required for individual features: without access to your calendars, Cali cannot display or manage your events; without Apple processing your In-App Purchase, paid features cannot be unlocked; without your email address, we cannot answer a support request. Everything else (crash reports, usage statistics, contact access, support logs) is optional and can be withheld or disabled without affecting the core functionality of the apps. The RevenueCat SDK described in Section 5.4 is part of Cali and WoHiT and cannot be switched off individually.
5. Data We Process and Why
5.1 Websites
5.1.1 Hosting and Server Logs
Our websites and our email are hosted by Infomaniak Network AG, Geneva, Switzerland, in data centers located exclusively in Switzerland. When you visit our websites, the web server automatically records technical connection data in log files: your IP address, date and time of the request, the requested page or file, HTTP status code, amount of data transferred, referring page, and your browser and operating system (user agent). This data is required to deliver the website and is used solely for technical operation, error analysis, and security. We do not evaluate these logs to identify individual visitors. Legal basis: legitimate interest in the secure operation of our websites (Art. 6(1)(f) GDPR). Retention: see Section 7.
5.1.2 Contact by Email
Our websites contain no contact forms; you can reach us by email only. If you email us, we process your email address, your name (if you provide it), and the content of your message solely to handle your request. Legal basis: legitimate interest in answering your inquiry, or contractual necessity if your inquiry concerns a purchase. Retention: see Section 7.
5.1.3 No Cookies, Tracking, or Third-Party Resources
We do not use cookies, analytics tools, or tracking technologies on our websites. All resources required to display our websites (fonts, scripts, stylesheets, images) are hosted on our own servers; no requests are made to third-party servers such as Google Fonts or content delivery networks when you visit our pages. The only exception is the optional Spotify player described in Section 5.1.4. Our websites contain links to external sites (e.g., Apple App Store, Apple Music, Spotify, Deezer); once you follow such a link, the privacy policy of the respective operator applies.
5.1.4 Spotify Player on the WoHiT Website (Click-to-Load)
The WoHiT website offers an embedded music player from Spotify AB, Regeringsgatan 19, 111 53 Stockholm, Sweden, to preview the music made for WoHiT. The player is not loaded automatically: you see a placeholder, and the player is only loaded from Spotify's servers after you click "Load Spotify player". Only then are your IP address, browser information, and the referring page transmitted to Spotify; Spotify may set cookies and, if you are logged in to Spotify, link the visit to your Spotify account. Spotify is an independent controller for this processing. Legal basis for loading the player is your consent expressed by clicking the button (Art. 6(1)(a) GDPR); it applies to the current page view only. Spotify's privacy policy: https://www.spotify.com/legal/privacy-policy/
5.2 Apple Services Used by Our Apps
Our apps are distributed exclusively through Apple's App Store. Apple acts as an independent data controller for the App Store, payment processing, and iCloud; we have no access to your payment information, Apple ID, or name. Apple's Privacy Policy: https://www.apple.com/legal/privacy/
The following Apple frameworks and services are used by our apps. In all cases the data is processed by iOS on your device or within your personal Apple/iCloud account; none of it is transmitted to us.
- iCloud Sync (Cali tasks, WoHiT workouts): Syncs your app data across your devices via your personal iCloud account. You manage and delete this data in your iCloud settings; it remains in iCloud after you delete the app until you remove it there. To prevent: disable iCloud for the app in iOS Settings > [Your Name] > iCloud.
- Calendar / EventKit (Cali): Cali reads and writes your calendar events directly in the iOS calendar database, which is shared with Apple's Calendar app and any other calendar apps you have authorized. Calendar access is essential for Cali; without it, the app cannot display or manage events. To revoke: iOS Settings > Privacy & Security > Calendars.
- Contacts (Cali): Reads contact names and birthdays from your address book, read-only, solely to display birthdays. Optional; without it, birthday information may not be displayed correctly. To revoke: iOS Settings > Privacy & Security > Contacts.
- Text-to-Speech / AVSpeechSynthesizer (WoHiT): Generates voice guidance for exercises locally on your device; no data is sent anywhere. Can be disabled in the app's settings.
- Health data: None of our apps access Apple HealthKit or any other health data. Workouts recorded in WoHiT are stored only in the app and in your iCloud account.
5.3 App Diagnostics and Usage Statistics (via Apple)
Apple provides us with technical data about our apps through App Store Connect and Xcode, but only if you have enabled "Share with App Developers" in iOS Settings > Privacy & Security > Analytics & Improvements. You can turn this off at any time. We use no third-party crash reporting or analytics SDKs (purchase analytics via RevenueCat are described separately in Section 5.4).
- Crash reports (pseudonymized): App version, iOS version, device model, and a technical stack trace. They contain no name, Apple ID, or app content, but relate to an individual device and incident, so we treat them as Pseudonymized Data. Used solely to identify and fix errors. Legal basis: legitimate interest.
- App Store Connect analytics (aggregated): Number of installs, sessions, and active devices per country and app version. Apple aggregates and thresholds this data before we see it; we cannot identify or single out individual users, so it is not Personal Data.
- Voluntary support logs: If you send us logs by email for troubleshooting, they may contain technical data and, depending on the issue, excerpts of your app content. Legal basis: your consent, which you can withdraw at any time by asking us to delete the logs.
Retention: see Section 7.
5.4 Purchase Analytics and Advertising Attribution (RevenueCat)
In-App Purchases in Cali and WoHiT are made and processed entirely through Apple (StoreKit). In addition, these two apps contain the SDK of RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA, a subscription analytics platform. RevenueCat is not involved in completing your purchase; it receives a copy of the purchase information for analysis and acts as our Data Processor. Lottie Tester does not contain this SDK.
Purpose and legal basis: We use RevenueCat to analyze aggregated purchase and subscription data and the performance of our Apple Search Ads campaigns, in particular to understand which App Store search terms lead to downloads and subsequent purchases. Legal basis: our legitimate interest in evaluating and improving our apps and marketing (Art. 6(1)(f) GDPR).
Data processed: All of it is pseudonymized: it is linked to a random identifier, not to your name, email address, or Apple ID, and neither we nor RevenueCat can identify you from it. Our apps have no user accounts, and we never pass any identifier of ours to RevenueCat.
- Anonymous App User ID: A random identifier generated by the SDK on your device that links purchase events to your app installation.
- Transaction data: App Store receipt, purchase history, subscription status, and related metadata (product, price tier, currency, dates). The receipt contains no name or payment details.
- Device information: Device type, operating system version, app version, language and region.
- Attribution data: If you installed the app via an Apple Search Ads advertisement, the campaign and keyword that led to the download. This does not involve cross-app tracking and does not use Apple's advertising identifier (IDFA).
- Application state: Date of your last app launch, used for aggregated statistics (e.g., active subscribers).
- IP address: Transmitted technically when the app contacts RevenueCat's servers; used to derive an approximate country for statistics.
What you should know: The SDK contacts RevenueCat's servers when the app starts (to load the available purchase options), even if you never buy anything. This cannot be disabled within the app; the only way to avoid it is not to use Cali or WoHiT. Because the data is pseudonymous, we are unable to identify which records belong to you (Art. 11 GDPR); see Section 10 for what this means for your rights. Data storage and international transfers: see Section 5.5. Retention: see Section 7.
RevenueCat's privacy policy: https://www.revenuecat.com/privacy
5.5 Data Processors and International Transfers
We engage the following service providers as Data Processors under data processing agreements that meet the requirements of Art. 28 GDPR and Art. 9 revDSG. We do not disclose personal data to any other recipients, except where legally obliged to do so (e.g., to authorities on the basis of a binding order).
- Infomaniak Network AG (Geneva, Switzerland): Hosting of our websites and email. Processing takes place exclusively in Switzerland, which the European Commission recognizes as providing an adequate level of data protection.
- Apple Inc. (Cupertino, USA): App Store Connect analytics and crash reporting (Section 5.3); Apple's Developer Program License Agreement and Data Processing Addendum apply. Apple is certified under the EU-US Data Privacy Framework (including the UK Extension) and the Swiss-US Data Privacy Framework, which the European Commission and the Swiss Federal Council recognize as providing adequate protection.
- RevenueCat, Inc. (Brandon, FL, USA): Purchase analytics (Section 5.4). Data is stored on Amazon Web Services servers in the United States. RevenueCat is not certified under the Data Privacy Framework; transfers are based on the EU Standard Contractual Clauses (Module 2, controller to processor), supplemented by the Swiss addendum recognized by the FDPIC and the UK International Data Transfer Addendum, all incorporated in RevenueCat's Data Processing Addendum: https://www.revenuecat.com/dpa
Apple's own services (App Store, iCloud) may also involve transfers to the USA under Apple's responsibility as an independent controller. You can stop the transfer of crash reports and usage statistics at any time by disabling the sharing option described in Section 5.3.
6. Data Usage per App
- Cali: Calendar (EventKit), Contacts (birthdays), iCloud (tasks); In-App Purchases via Apple, reported to RevenueCat (Section 5.4).
- WoHiT: iCloud (workouts), on-device Text-to-Speech, music downloaded from our servers; In-App Purchases via Apple, reported to RevenueCat (Section 5.4). No HealthKit.
- Lottie Tester: Processes no personal data and contains no In-App Purchases or third-party SDKs.
All apps are covered by Apple's opt-in diagnostics described in Section 5.3.
7. Retention Periods
We store personal data only for as long as necessary for the respective purpose or as required by law. This section is the single reference for all retention periods in this policy.
- Website server logs (5.1.1): deleted automatically by our hoster after a short rolling period (currently at least 7 days according to Infomaniak's documentation); we keep no copies.
- Emails (5.1.2, 5.3): deleted after the matter is resolved, at the latest 30 days after the conversation ends, unless statutory retention obligations for business correspondence apply (Art. 958f Swiss Code of Obligations, 10 years).
- Crash reports (5.3): deleted no later than 90 days after receipt.
- Aggregated App Store analytics (5.3): not Personal Data; kept without time limit for long-term trend analysis.
- Voluntary support logs (5.3): deleted no later than 30 days after the issue is resolved.
- Purchase events at RevenueCat (5.4): nothing is stored on our own systems; RevenueCat retains the data for as long as we use its service for the respective app, and it is deleted when we stop doing so.
- Content you create in the apps: never stored by us; you control it on your device and in iCloud.
8. Data Security
We take appropriate technical and organizational measures in accordance with Art. 32 GDPR and Art. 8 revDSG, taking into account the state of the art and the low risk of the processing described in this policy. In particular: all connections between our apps or websites and our servers, Apple, and RevenueCat are encrypted in transit (TLS); our Services have no user accounts, so no passwords or login data of yours exist that could be compromised; personal content stays on your device or in your iCloud account by design; and access to the developer and hosting accounts through which we receive data is restricted to the controller and secured in accordance with the providers' account security requirements. Our service providers are contractually obliged to maintain appropriate security measures; Infomaniak operates ISO 27001-certified data centers in Switzerland.
Should a personal data breach occur that is likely to result in a risk to your rights and freedoms (for example, unauthorized access to our email account or a breach reported to us by a service provider), we will notify the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, where required, the competent EU supervisory authorities within the statutory deadlines. Since we generally hold no contact details of our users, we will inform affected persons directly by email only where we have corresponded with them; in all other cases, we will publish a notice on our website.
9. Children
Our apps are rated for a general audience in the App Store and may be used by younger people under parental supervision, but they are not specifically directed at children and contain no features designed to collect data from them. Since we do not collect names, email addresses, or account data through our apps, we cannot determine a user's age. We do not knowingly collect personal data directly from children under 13 years of age (or under the age of digital consent applicable in your country, which is 16 in some EU member states). If you are under this age, please only contact us or send us support logs with the involvement of a parent or guardian. If we become aware that we have received personal data from a child without the necessary parental consent, we will delete it promptly.
10. Your Data Protection Rights
Under the GDPR (Arts. 15-21) and the revDSG (Arts. 25-29 and 32), you have the right to access the personal data we hold about you, to have it rectified or erased, to receive it in a portable format, and to restrict or object to its processing. To exercise these rights, contact us using the details in Section 1. We will respond within the statutory period of one month.
What we can and cannot do: The only personal data we hold that we can attribute to you is email correspondence with you. Crash reports and purchase events (Sections 5.3 and 5.4) are pseudonymous: neither you nor we know which records belong to you, and we have no means of identifying them. In accordance with Art. 11 GDPR, we are therefore unable to fulfil access, rectification, erasure, or portability requests for this data, unless you can provide additional information that allows identification. You can, however, prevent this processing yourself: crash reports and usage statistics by disabling sharing in your iOS settings (Section 5.3), and purchase events by not using Cali or WoHiT (Section 5.4).
Withdrawing consent: Where processing is based on your consent (support logs, Spotify player), you can withdraw it at any time without affecting the lawfulness of processing before the withdrawal.
Objecting to legitimate interests: Where processing is based on legitimate interests, you have the right to object on grounds relating to your particular situation (Art. 21 GDPR). We will then cease the processing unless we can demonstrate compelling legitimate grounds; the limitation regarding pseudonymous data described above applies.
Right to lodge a complaint: You may lodge a complaint with a supervisory authority: in Switzerland the FDPIC (www.edoeb.admin.ch), in the EU the data protection authority of your country of residence, in the UK the Information Commissioner's Office (ICO).
11. Changes to This Privacy Policy
We may update this Privacy Policy, for example when we add features, apps, or service providers. The authoritative, current version is always the one published at https://indie-software.com/en/privacy.html; the copy included in our apps reflects the version at the time the app was built and may lag behind. The "Last Updated" date shows which version you are reading. As we hold no contact details of our users, we do not send individual notifications of changes; please check the website from time to time.