gyokuro

Privacy Policy

1. Controller

Sven Hanold Falkenweg 27 89129 Langenau Germany Email: info@hanold.info

2. General information on data processing

This website is predominantly a static information page. No cookies are set and no data is transmitted to advertising networks. All content, including fonts, is served from my own server; no content is loaded from third-party servers. To anonymously count page views, a self-operated, non-personal counting mechanism is used — see section 4 for details. No analysis of user behaviour, no cross-page tracking and no profiling takes place.

3. Hosting

This website is hosted on a virtual server that we rent from STRATO GmbH (Berlin) and operate ourselves; the data centres are located in Germany. STRATO processes data as a processor solely on our behalf; a data processing agreement pursuant to Art. 28 GDPR is in place with STRATO. The data processing agreement is available at strato.de/agb/avv.

When you visit the site, the web server processes the technical information required to deliver it, in particular your IP address. Access is not recorded in log files; this data is only processed for the duration of the connection. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation).

4. Anonymous page-view counter

To see how often individual pages are viewed, this website counts page views. Only the site name, the requested page path, the language version and the date are processed — aggregated into a daily counter per page. In the same way, the site counts how often the App Store link is clicked (with its placement on the page) and how often the support form is submitted successfully — again only as a daily counter, with no link to a person or to the content of a message.

No IP addresses, cookies, device or browser identifiers, or any other personal data are stored. Individual visits cannot be traced back to a person or device afterwards. The counting runs on infrastructure we operate ourselves; no third parties are involved. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in measuring the reach of our own offering).

5. Support form

You can contact us directly through the form on our support page. The data you enter (name, email address, topic, message and, optionally, an attached file — image or text file) is sent from your browser directly to an automation we operate ourselves (n8n). This creates a support ticket in our internal ticketing system and triggers a notification to us.

For short-term abuse detection (rate limiting), your IP address is stored for a maximum of 5 minutes and then automatically overwritten. In addition, the IP address is contained, together with the form data, in the technical logs of the automation, which are used solely for troubleshooting and are automatically deleted after 7 days; it is not analysed.

To protect against automated abuse (spam bots), the form contains an invisible control field and a self-hosted verification mechanism (ALTCHA). While you fill in the form, your browser solves a small computational task that it has previously fetched from our automation; in addition, the time between loading the page and submitting the form is transmitted. For this check, no cookies are set, no third parties are involved and no characteristics of your device or browser are collected; the required script is served from our own server. When the task is fetched, your IP address is processed only for the duration of the connection for technical reasons and is not stored. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse).

After submitting, you will receive an automatic confirmation with a reference number at the email address you entered; in addition, your request is forwarded by email to our support mailbox. To send and store these emails, we use an email service provider that processes the data as a processor solely on our behalf.

An attached file is stored together with your request in our ticketing system and forwarded by email to our support mailbox. It is not transmitted to the AI service named below. Please do not upload files containing passwords, access credentials or other confidential information.

To answer more quickly, we have a draft reply for support requests prepared by the AI service Claude from Anthropic PBC (USA), which we review and edit ourselves before sending. Transmitted for this purpose are the app, the topic and the message text, but not your name, your email address or an attached file. Email addresses within the message text are removed automatically before transmission. Anthropic processes the data as a processor on the basis of a data processing agreement. The transfer to the USA is safeguarded by the EU standard contractual clauses. The data is not used to train AI models. If the service is unavailable, the draft is created on our own infrastructure. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the prompt handling of support requests).

The submitted form data is used exclusively to process your request. It is not passed on to any recipients other than those named here. After the request has been dealt with, the data is deleted unless statutory retention obligations apply. The legal basis is Art. 6 (1) (b) GDPR (processing your request) or Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse).

6. The gyokuro app

gyokuro is a client for self-hosted Gitea and Forgejo servers. The app connects exclusively to the servers you configure yourself. Your repository, issue and code data stays entirely between the app and your own server. No third-party analytics, tracking, or advertising services are embedded, and no crash reports are transmitted to third parties. Credentials (tokens) are stored exclusively locally on your device in the iOS Keychain. Data is transmitted to systems operated by the developer exclusively in the two cases fully described below: the anonymous usage statistics, which can be switched off at any time, and — only if you enable them — push notifications via the gyokuro push relay.

Anonymous usage statistics (from version 3.0)

To understand how well setup, the free trial and the purchase flow work in the app — and to base improvements and pricing decisions on that — gyokuro collects a small, fixed set of events from version 3.0 onwards and transmits them TLS-encrypted to a server we operate ourselves in Germany (telemetry.hanold.online). It is exclusively these five events; there are no others:

  1. First launch of the app after installation
  2. First successful connection to a Gitea or Forgejo server
  3. Start of the free trial
  4. Display of the purchase screen
  5. Completed purchase of the Unlimited unlock

Each event technically contains exactly these fields: a randomly generated installation ID (a UUID rolled on first launch — it contains no reference whatsoever to your device, account or person, and is deleted along with the app when you uninstall it), a timestamp, the app version, the coarse operating-system version (e.g. “iOS 26”), the platform (iPhone or iPad), and, where applicable, a short context hint (e.g. at which point in the app the purchase screen was shown, or how many days passed between installation and purchase).

What is explicitly not collected and not stored: IP addresses (the receiving endpoint deliberately writes no access log), device or advertising identifiers (no IDFA, no IDFV), the name or address of your Gitea or Forgejo server, your credentials or tokens, the contents or size of your repositories, issues and pull requests, your development activity, and any other personal data. The events can neither be linked across devices nor traced back to a person afterwards.

Processing runs entirely on our own infrastructure in Germany (received by a self-operated automation, stored in a self-operated database); no third parties are involved at any point. Evaluation is exclusively aggregated — for example: “How many of the installations from a given month started the trial, and how many of those later purchased?”

You can switch the usage statistics off at any time in the app settings (“Anonymous usage statistics”); transmission then stops immediately. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving our own offering). As the data is anonymous, there is no personal reference — we offer the opt-out switch regardless, because it is what we would expect ourselves.

Push notifications via the gyokuro push relay (from version 3.0)

Optionally, gyokuro can notify you about activity in selected repositories (e.g. new issues, comments, pull requests, reviews). Push notifications are disabled by default and only become active if you enable them in the app settings and select repositories.

Technically it works like this: the app creates a webhook in the repositories you select on your own Gitea or Forgejo server (recognisable by the name “gyokuro Notifications” or the target address push.gyokuro.app); you can view these webhooks per repository in the app and remove them at any time. On relevant activity, your own server sends a message to a relay server we operate ourselves in Germany, which runs on the same server rented from STRATO as this website (see section 3). The relay verifies the signature, builds a compact summary from the message (repository name, event type, acting person, title or number of the issue or pull request — and, only if you have enabled the “content in notifications” option, a short excerpt of the comment or review; deleted comments are always delivered without an excerpt) and delivers it to your device via Apple’s push service (Apple Push Notification service). To display further details, the app then connects directly to your own server; the relay is not involved in that.

The relay permanently stores only the mapping between your device (the app-specific push token assigned by Apple) and a randomly generated channel identifier — no names, no accounts, no server addresses. The content of the webhook messages is processed only transiently in memory for delivery and is not stored; after delivery (or after a few failed delivery attempts) it is discarded. Your server’s IP address is processed as technically required on receipt, but is neither linked to the stored data nor evaluated.

Apple’s push service is used for delivery; Apple’s privacy policy applies in addition. If you disable push notifications in the app, your device’s registration is deleted from the relay. The legal basis is Art. 6 (1) (b) GDPR (provision of the feature you enabled).

Purchases via the App Store

The app is distributed via the Apple App Store. Any purchases or unlocks within the app are processed exclusively through the App Store; the developer does not receive any payment data, only anonymized, aggregated statistics from Apple. Apple’s privacy policy applies in addition.

7. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority; the competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Germany.

Note on the usage statistics: as the events processed there are anonymous and we cannot attribute them to any person, we cannot apply access, rectification or erasure requests to individual events (Art. 11 GDPR). The most effective means is the opt-out switch in the app.

8. Last updated

September 2026. This policy will be updated as necessary.