Eigenzeit

Privacy Policy

This policy covers the Eigenzeit website and server-side services. The iPhone app can be used without a server account.

Last updated: 2 September 2026

1. Controller

Michael Zink
Mannheimer Str. 37
68723 Oftersheim
Germany
Email: info@znk.dev

2. Visiting this website

When you open the website, your browser necessarily sends connection data, particularly the IP address, time, requested address, HTTP method, browser identifier, and amount of data transferred. This processing is necessary to deliver the website securely. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure and reliable operation.

Eigenzeit does not keep a regular access log of page views. Technical faults may create limited entries in the system journal; they are used only for troubleshooting and system security and are removed by automatic log rotation.

The website sets no cookies, uses no analytics, advertising, or profiling services, and does not load fonts, images, video, or scripts from third parties. There is no newsletter or registration form, so no consent banner is required.

3. Hosting

The website and API run on a self-managed server in Germany. The infrastructure provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Hetzner may process connection data as part of operating the infrastructure.

4. Contact by email

If you email us, we process the sender address, content, timestamps, and technical delivery data to handle the enquiry. Depending on the message, the legal basis is Article 6(1)(b) GDPR (contract or pre-contract enquiry) or Article 6(1)(f) GDPR (general communication). We delete the message when the matter is complete unless statutory retention duties or legitimate evidentiary interests require longer storage.

5. Optional Sign in with Apple

An account is required only for optional Pro server features. When you use Sign in with Apple, we verify the identity token issued by Apple. We do not retain the Apple user identifier itself. We store only a server-side pseudonymised one-way value, a random internal account ID, random device IDs, the hardware model, and account/device timestamps. We do not collect or retain names or email addresses supplied by Apple.

Refresh tokens are stored only as one-way values; access tokens expire after 15 minutes and refresh tokens after no more than 60 days. If Apple supplies a revocation token, it is encrypted at rest so that the Apple grant can be revoked when the account is deleted. A hash of the one-time Apple authorisation code is kept only briefly to prevent replay.

The legal basis is Article 6(1)(b) GDPR for providing the account features you choose. Apple processes data under its own responsibility; details are available in Sign in with Apple & Privacy.

6. Encrypted sync

When Pro sync is enabled, the server stores end-to-end encrypted user data only. Keys remain with the devices; the server cannot decrypt the content. Technical metadata is processed to order, limit, and deliver records: random row and device IDs, entity type, schema version, change counter, deletion marker, key epoch, server sequence, receipt time, and ciphertext size.

The protected administration view shows internal account IDs, device and entitlement status, storage use, and aggregate import use only. It cannot display decrypted vault contents.

7. Document conversion

Server-side conversion of work-time documents is currently disabled, so no document is currently sent to an AI provider. If activated, the feature is available only to a valid Pro account and requires an explicit confirmation for every individual request.

The uploaded file is then processed ephemerally for the duration of the request (in memory or the container’s temporary storage). The server extracts text, removes the identity header from recognised statements, and redacts detected email addresses, IBANs, and employee numbers. Remaining text may nevertheless contain personal data. Only this reduced text—not the original file—is sent to the selected AI provider and returned in a fixed JSON schema. Eigenzeit does not persist the file, text, or result; it retains only the date, request/error counts, and aggregate byte and token counts.

Before activation, this policy will identify the provider, processing region, retention, and any international-transfer safeguard. The legal basis for the transfer will be your consent under Article 6(1)(a) GDPR, which can be withdrawn for the future.

8. Abuse prevention and security

Authentication, sync, import, and administration requests are rate-limited. The IP address is immediately transformed with a secret key into a non-reversible, replaceable pseudonymous value. Short-lived rate-limit records are deleted after the relevant protection window. Sign-in security events (account ID, event, time, and pseudonymised IP) are retained for no more than 90 days. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is protecting accounts, the server, and API costs from abuse.

9. Retention and deletion

10. Recipients and international transfers

Recipients are limited to operators needed to provide the service: Hetzner for hosting and Apple if you choose Apple sign-in. Personal data is not sold. No AI transfer currently takes place. If a provider outside the EEA is selected, the provider and applicable transfer safeguards will be named here before activation.

11. Your rights

Under the GDPR, you have rights including access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent at any time for the future. Email info@znk.dev to exercise a right; we request only the information needed to verify identity.

You may also lodge a complaint with the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg, Heilbronner Straße 35, 70191 Stuttgart, Germany.

12. Required information and automated decisions

You do not need to actively provide data to visit the website. Without Apple sign-in, only the optional server features are unavailable. There is no automated decision-making with legal or similarly significant effects and no profiling.

13. Changes

We update this policy when processing activities, providers, or the law change. The current version is always available at this address.