Home
DE EN

Last updated: August 20, 2026

This privacy policy applies to this app and this accompanying website. It describes the processing of personal data based on the product features currently visible in the repository.

1. Controller

The controller responsible for processing personal data in connection with this app and website is Nils Fischer, Am Hauptbahnhof 6, 53111 Bonn, Germany, email: wohnlich@nilsf.de.

2. What the app does

The app helps you aggregate real-estate listings from supported sources, display matches based on your search filter, and optionally notify you by push. It does not use a classic email/password registration, but a device-based identity.

3. Which data is processed

  • Device-based identity: On first launch, the backend creates a random user ID and a device-based authentication token. The token is stored locally on your device; only a hash of that token is stored server-side.
  • Search filter: Stored data includes your selected city, districts or neighbourhoods, listing sources, price limits, room count, seller preferences, and additional filter options such as temporary offers or swap flats.
  • Push notifications: If you allow notifications, your Expo push token is processed together with your search filter so new matching listings can be delivered.
  • Subscription status: The active or inactive state of your subscription is processed so paid features can be unlocked or restricted.
  • PostHog analytics data: If PostHog is configured, the app processes explicitly defined events about onboarding, subscription and push activation, errors, opened listings, saved filters, and account deletion. Events may contain the app user ID, city, listing source, cold rent, room count, subscription and platform data, and technical session and device identifiers. Automatic lifecycle and touch capture, GeoIP, and session replay are disabled.
  • Advertising attribution: If you grant the app tracking prompt, device identifiers and an anonymous app events ID generated by Meta may be processed so completed subscriptions can be attributed to Meta ad campaigns and campaigns can be optimized.
  • Local app storage: The app stores your session, a possibly unsynced filter draft, the latest local subscription verification state, and the notification prompt state on your device.
  • Website usage: This website is static and does not use analytics or advertising cookies. When you click the App Store link, the website sends one aggregate event to a same-origin Cloudflare relay. It contains only the language, page, campaign, and CTA. The visitor IP and incoming request headers are not forwarded to PostHog; neither are the referrer, cookies, user ID, or search-filter data. The relay forwards the four values without creating a person profile to the official PostHog endpoint configured for the project (US or EU). Cloudflare may receive technical network data while processing the request. Navigation to the App Store is not delayed. The language links do not store a language preference in your browser.

4. Purposes and legal bases

  • Providing the app and search functions: Art. 6(1)(b) GDPR.
  • Push notifications: Art. 6(1)(a) GDPR together with your device-level consent.
  • Processing purchases and subscription checks: Art. 6(1)(b) GDPR.
  • Product analytics with PostHog: The app processes explicitly defined events to measure activation, analyse stability, and improve the app. For the website App Store click, one additional aggregate, personless event is processed on the basis described under website usage in this notice. The specific legal basis for this website measurement will be established by the controller before production use.
  • Measuring and optimizing Meta ad campaigns: Art. 6(1)(a) GDPR together with your consent through the app tracking prompt. You can withdraw this consent in your device system settings.
  • Security, abuse prevention, and service stability: Art. 6(1)(f) GDPR.

5. Recipients and service providers

  • Convex: for the app backend, authentication, and database operations.
  • Cloudflare: for website hosting and processing by the website CTA relay.
  • Expo: for delivery of push notifications if you enable them.
  • RevenueCat: for technical processing and synchronization of your subscription status.
  • Apple: for in-app purchases, billing, restores, and App Store related processes.
  • PostHog: PostHog processes the explicitly defined analytics events to measure activation, analyse stability, and improve the app. The app uses the configured PostHog host.
  • PostHog for the website CTA: The official PostHog endpoint configured for the project (US or EU) receives only the app_store_cta_clicked event from the Cloudflare relay, with the language, page, campaign, and CTA. The event uses a fixed technical identifier, does not create a person profile, and disables GeoIP processing.
  • Meta: for measuring and optimizing Meta ad campaigns if you grant the app tracking prompt.
  • Third-party listing platforms: When you open a listing, you are redirected to the respective external website. From that point on, their own privacy information also applies.

Where individual recipients process data outside the European Economic Area, this only takes place subject to applicable data-protection requirements, for example on the basis of adequacy decisions or appropriate safeguards.

6. Retention

  • Server-side profile and filter data is generally kept until you request deletion or it is no longer required for operating the service.
  • The Expo push token remains stored when the search filter changes and is updated when needed. The current code does not remove it automatically when notifications are disabled in system settings. On successful account deletion, the search filter, including the token, is deleted.
  • PostHog data is kept only as long as required for the analytics purposes described here. The intended automatic 90-day limit is not configurable on the current PostHog plan and must therefore be enforced through regular manual review and deletion until that changes. Website CTA events use a fixed technical identifier, do not create a person profile, and are not linked to an app account. After successful account deletion, the server starts deleting the app analytics data after a short delay; temporary network or server failures trigger automatic retries. The deletion attempt may fail after an unrecoverable error.
  • Local app data remains on your device until you remove app data, uninstall the app, or reset onboarding.
  • Billing and purchase data may remain with Apple and RevenueCat according to their own legal or contractual retention periods.
  • Advertising attribution data is processed only as long as required for campaign measurement and optimization or until you withdraw your consent; Meta and RevenueCat may also apply their own retention periods.

7. Your rights

Under the GDPR, you have in particular the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you can withdraw that consent at any time with future effect.

To exercise your rights, simply send an email to wohnlich@nilsf.de. You also have the right to lodge a complaint with a data protection supervisory authority.

8. No automated decision-making in the legal sense

The app uses your search filter to show matching listings or trigger notifications. It does not perform automated decision-making within the meaning of Art. 22 GDPR that produces legal or similarly significant effects for you.