Privacy policy
Controller
tap & type UG (haftungsbeschränkt), Pestalozzistr. 14, 14943 Luckenwalde, Germany, email: kontakt@waffenschrank.app (see legal notice).
The basic principle: your data stays with you
Waffenschrank is a local-first app: all content (guns, ammunition, training, documents, photos) is stored solely on your device. There is no forced account, no tracking, no advertising and no analysis of how you use the app. Text recognition (OCR), photo cut-out and target analysis run on the device — photos do not leave it for this. Only in the web app does text recognition download its recognition model from a public package network on first use; even there the image itself is analyzed in the browser and is not uploaded.
The shot timer uses the microphone solely to detect shots as volume peaks. The analysis runs in real time on the device; audio is never recorded, stored or transmitted — only the detected points in time (numbers) are saved. Microphone access is active only while the timer is running.
The training coach works out its advice entirely locally from your entries. On devices with built-in on-device AI (Apple Intelligence or Gemini Nano) it can additionally have a short summary phrased — that, too, happens solely on the device. Only aggregated figures go into that summary, never gun, location or personal data, and none of it leaves the device or is stored.
The app's content data — the database (folder “SQLite”), the photos (folder “photos”) and the documents (folder “documents”) — are excluded from the iOS device backup (NSURLIsExcludedFromBackupKey). They are therefore not automatically included in the device or iCloud backup. On Android the system backup is switched off entirely for the app (allowBackup=false), so no content automatically ends up in a Google backup there either. Technical remnants (e.g. app settings in system storage) can still end up in the device backup; gun, ammunition and training data do not. A backup of your content only comes about if you set one up yourself: iCloud backup, account backup/sync or manual export. Without one of these, the data is lost if the device is lost or breaks.
What happens at startup — even without an account
The app is not entirely offline. On iPhone, iPad and Android it asks our own delivery endpoint (updates.waffenschrank.app, delivered by our hosting provider Cloudflare, Inc. — processor, EU standard contractual clauses) at startup whether a program update is available — since version 1.3 no longer Expo. This unavoidably transmits your IP address, the project and update identifier, the release channel, the runtime version as well as platform and operating system version, plus an installation identifier that is created on first launch and stays on the device permanently. If the previous run ended in a fatal error, its message (up to 1024 characters) is sent along once with the next request and deleted from the device in the process. No content from your collection is included. Legal basis: Art. 6(1)(f) GDPR (delivering bug fixes).
On iPhone and iPad the purchase handling also checks in at startup to verify your Pro status — even if you have never bought anything (see “Purchases”). The app opens no further connections on its own: account, backup, showcase, contact form and filling from shop links only happen once you trigger them yourself.
Device permissions
The app only asks for permissions when you use the matching feature: camera and photo library (photos of guns, documents and receipts, barcode and text scanning), microphone (shot timer), NFC (reading tags on cabinets and cases), Face ID or fingerprint (app lock) and notifications (reminders). Whatever this produces stays on the device.
Reminders, widgets and shortcuts
Deadline and maintenance reminders are scheduled and shown by the device itself (local notifications). There is no push service; no server learns what you are being reminded of.
For widgets, live activities, shortcuts and Siri the app places the necessary figures in a shared area of the device (app group): the number of guns, stock per caliber, the title of the next deadline and the needs indicator. These are visible on the home and lock screen, so outside the app lock as well. While the app lock is on, only neutral counters without names are mirrored. None of it leaves the device.
Spotlight search (optional, iOS only)
If you switch on system search under More → Security, iOS remembers the manufacturer, model and caliber of your guns for the device's Spotlight search — even without opening the app and outside the app lock. The setting is off by default. If you switch it off again or turn on the app lock, the system index is emptied and no longer filled. Legal basis: Art. 6(1)(a) GDPR (consent by activation).
iCloud backup (optional, no account)
If you enable the iCloud backup, the app stores encrypted backup files in the iCloud Drive container of your Apple ID (folder “Waffenschrank”). The database as well as your photos and uploaded documents are backed up; those files sit next to the backup, each encrypted individually. Encryption (AES-256-GCM) happens on the device; the key is a random value stored solely in your iCloud keychain and synchronized between your devices. Apple, as the provider of your iCloud account, is responsible for the storage; we receive no data and have no access to the files or the key. Legal basis: Art. 6(1)(a) GDPR (consent by activation).
Google Drive backup on Android (optional, no account)
If you enable the backup on Android, the app stores encrypted backup files in the private app folder (“appDataFolder”) of your Google Drive. That folder is reserved for the app; other apps and the Drive interface cannot reach it. The database as well as your photos and uploaded documents are backed up; those files sit next to the backup, each encrypted individually. Encryption (AES-256-GCM) happens on the device; the key is a random value and is kept in Google Block Store — end-to-end encrypted and therefore unreadable for Google, provided your device has a screen lock. If the device reports no end-to-end encryption, the key stays purely local; only your recovery code then leads back to the backup. Google, as the provider of your Google account, is responsible for the storage; we receive no data and have no access to the files or the key. Access is limited to the “drive.appdata” scope; the app cannot reach the rest of your Drive. Legal basis: Art. 6(1)(a) GDPR (consent by activation).
Optional account, cloud backup & sync
An account is voluntary. You can sign in with an email address and password, with a one-time code sent by email, with “Sign in with Apple” or with your Google account. With “Sign in with Apple”, Apple passes us an identifier and — depending on your choice — your email address and name; the app keeps the name locally in your profile only. With Google we receive an identifier and your email address. The respective provider is responsible for the sign-in procedure on its side.
Cloud backups and device synchronization are end-to-end encrypted (AES-256-GCM; the key is derived from your protection password on the device, PBKDF2 with 600,000 rounds). We cannot decrypt these contents (zero knowledge).
Unencrypted, the server only sees the envelope: your email address, the time and size of the backup files and — for synchronization — which table and which row identifier a record belongs to, plus the identifier of the device it came from. That reveals how many entries you keep in which area, but not what is in them. To guard against abuse, the server additionally derives a short-lived counter from your IP address for some server functions.
If you enable automatic backup, your protection password is placed in your device's protected key store (Keychain or Keystore) so the backup can run without asking; it does not leave the device. The app cleans up older cloud backups itself: the seven most recent are kept, plus the most recent one from four further weeks. Hosting: Supabase, EU region (Frankfurt, eu-central-1). Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Without an account we create none of this.
Showcases (voluntary sharing)
If you actively publish a showcase, only the details you selected (including downsized photos of the selected items) become publicly available at an address that cannot be guessed. Serial numbers, storage locations, stock levels, prices and permit data are technically excluded. A showcase also works without an account.
We count how often a showcase has been opened and show you that counter; individual visits are not logged. The showcase page is delivered by our hosting provider Cloudflare, Inc. (processor, EU standard contractual clauses), which processes the technically necessary connection data of visitors. So that a published showcase does not expire unnoticed, the app refreshes it by itself at most once a month at startup. You can take any showcase offline at any time; the link then becomes permanently invalid. Legal basis: Art. 6(1)(a) GDPR (consent).
Club showcases
If you create a club showcase or join one, we store the club name, the join code, the account identifiers of those involved and the contributions you explicitly submit (competition results, for example). These details are not end-to-end encrypted — the other members have to be able to read them. You can end your membership at any time. Legal basis: Art. 6(1)(a) GDPR (consent).
Purchases (Waffenschrank Pro)
Purchases go through the App Store (Apple) or Google Play; the purchase handling is done by RevenueCat (RevenueCat Inc., USA — EU standard contractual clauses). The RevenueCat SDK checks in at every startup to verify the purchase status; a purchase identifier, your IP address and technical device details go to RevenueCat in the process. Without an account that identifier is an anonymous random one; once you are signed in it is linked to your account identifier so that Pro applies on all your devices. We never receive payment data. Legal basis: Art. 6(1)(b) GDPR.
Crash reports (only with consent)
Crash reports are only sent if you explicitly enable them under More → Security; the default is off. The processor is Sentry (Functional Software, Inc., USA — EU standard contractual clauses); the reports go to the EU ingest point in Germany. One item is unaffected and goes out even without this consent: if the previous run ended in a fatal error, the update request at the next start carries its message along (see “What happens at startup — even without an account”).
A report contains the error message with its stack trace, the app version, device model, operating system version, language and time zone, plus a heavily trimmed trail of the last steps: only screen changes with masked identifiers and network calls with shortened addresses. Screen titles, input, console output and your account identifier are explicitly filtered out, so content from your collection does not make it into a report. The text of the error message itself is the exception: it is transmitted in full, because a bug cannot be found without its message — in rare cases it may contain a value from your data.
Legal basis: Art. 6(1)(a) GDPR; revocable at any time. Revocation takes effect immediately: the app stops collecting crash data in that very moment, without a restart. Freezes and sessions ended by the system are not recorded at all — only genuine crashes.
Contact & reporting a problem
If you use the contact form, we process your message, the category you chose, optionally your email address (for follow-up questions) and — if you leave the checkbox checked — technical details: app version, update identifier, release channel, platform and operating system version. If you are signed in, your account identifier is stored along with it so that we can attribute your request. Legal basis: Art. 6(1)(f) GDPR (handling your request), and for signed-in users also Art. 6(1)(b) GDPR. The data is deleted once the matter is closed.
Filling from shop links
If you paste a shop link and have the details filled in from it, your device calls up that third-party page directly — with no detour through us. As with any page visit, the shop learns your IP address and which page you are requesting; we have no influence on its data processing and receive nothing from it. Legal basis: Art. 6(1)(a) GDPR (consent by triggering).
This website
When you open waffenschrank.app, our hosting provider Cloudflare, Inc. (as a processor, EU standard contractual clauses) processes technically necessary connection data (IP address, time, resource requested) in order to deliver and protect the site. Legal basis: Art. 6(1)(f) GDPR. The site sets no cookies and embeds no resources from third-party servers; it merely remembers your language choice locally in your browser so that the language hint does not come back.
Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR) as well as the right to lodge a complaint with a data protection supervisory authority. You can delete account data in the app; local data is deleted by removing the app or via the export/delete functions. How to do that — in the app or without it — is set out on Delete your account.
This policy describes the app's actual data processing. Questions: kontakt@waffenschrank.app