Privacy policy
Last updated: June 2026 · App version 1.2.4 · Applies to the “Kreise” mobile app and this website
We take the protection of your personal data seriously. Below we inform you under Articles 13 and 14 GDPR about the nature, scope and purpose of processing — clearly and transparently.
1. Controller
Controller within the meaning of the GDPR:
Marco Wilka
Stresemannstr. 309
22761 Hamburg
Email: m.wilka@gmail.com
Support requests (including privacy): https://kreise.marcowilka.de/support
2. Scope
This policy applies to the iOS app “Kreise”, the API service at https://kreise.marcowilka.de and the related websites (support, privacy, legal notice). It does not apply to third-party websites or services (Apple, Google, payment providers) that we link to or that you use via the app.
3. Overview of processing
| Processing | Data | Legal basis |
|---|---|---|
| Account & login | Email, name, password hash, OAuth IDs | Art. 6(1)(b) GDPR |
| Circle features | Events, documents, roles, invites | Art. 6(1)(b) GDPR |
| Push notifications | Device push token, event type | Art. 6(1)(a) GDPR (iOS consent) |
| Kreise Pro | Subscription status, entitlement IDs (via Apple/RevenueCat) | Art. 6(1)(b) GDPR |
| AI extraction | Uploaded files/content for analysis | Art. 6(1)(b)/(a) GDPR (on request) |
| Email delivery | Email address, invite text | Art. 6(1)(b)/(f) GDPR |
| Support form | Name, email, message | Art. 6(1)(b)/(f) GDPR |
| Error analysis | Crash data, device type, app version | Art. 6(1)(f) GDPR |
| Server log files | IP, timestamp, request metadata | Art. 6(1)(f) GDPR |
4. Account & authentication
When you register and use the app we process:
- Email address and display name
- Password as a cryptographic hash (email login) — we never store plaintext passwords
- For Apple/Google Sign-In: identifiers and possibly email provided by the provider (depending on their settings)
- JWT session tokens for authenticated use
Apple privacy: apple.com/legal/privacy · Google: policies.google.com/privacy
5. Content in circles
Events, documents (metadata and files), folders, participants and invites are stored on our servers so authorised circle members can access them. You and your circle members decide which content is uploaded — e.g. school notes may contain personal data.
Important: Only upload content you are entitled to process. For content relating to minors, guardians are responsible.
6. AI event detection (OpenAI)
When you start AI extraction, we send the selected document (image/PDF/text) to OpenAI to generate event suggestions. Processing only happens on your active request. OpenAI processes the content as a processor or independent provider under its terms.
OpenAI privacy: openai.com/policies/privacy-policy
Extraction jobs are logged internally (status, time, user ID) and count against your monthly quota.
7. Subscriptions (Apple & RevenueCat)
Kreise Pro is billed through the Apple App Store. Payment data (card details etc.) is processed only by Apple — we do not receive full payment information.
We use RevenueCat to sync subscription status and entitlements (“Kreise Pro”). This may include an anonymous app user ID, product IDs and expiry dates.
RevenueCat: revenuecat.com/privacy
8. Push notifications
With your iOS consent we store a push token (Expo/Apple Push Notification Service) to notify you about relevant events. You can disable push anytime in iOS app settings.
9. Email communication
For invites and transactional email we use Mailgun. For support requests via our form we process the data you enter to handle your request.
10. Error analysis (Sentry)
For app stability, anonymised or pseudonymised crash and error data may be sent to Sentry (device type, OS version, stack traces). Sentry helps us fix bugs.
Sentry: sentry.io/privacy
11. Servers, hosting & log files
The app communicates with our backend at https://kreise.marcowilka.de. Technically necessary log data is created (IP address, time, URL, user agent, status codes) — for security, troubleshooting and abuse prevention.
Documents are stored on the server filesystem; metadata in a MongoDB database. Transmission uses HTTPS/TLS encryption.
12. Cookies & tracking on this website
The support, privacy and marketing pages do not use marketing cookies or advertising tracking. Tailwind CSS is loaded from a CDN for layout; the CDN provider may process technical connection data. The app itself does not use advertising profiling.
13. Transfers to third countries
Some providers (e.g. OpenAI, Apple, Google, Mailgun, Sentry, RevenueCat) are based in the USA or process data globally. Where no EU adequacy decision applies, we rely — where required — on EU Commission Standard Contractual Clauses (SCCs) and supplementary measures under Art. 46 GDPR.
14. Retention
- Account & circle content: until deleted by you or a circle admin
- Session tokens: according to configured expiry (access/refresh)
- Push tokens: until sign-out or disable
- Support requests: until resolved, then possibly archived under legal deadlines
- Server logs: rolling, typically a few weeks
- Extraction jobs: for quota counting and traceability in the current month or until deletion
15. Obligation to provide data
Email and sign-in are required to use the app. Without this data we cannot provide an account. Push, AI extraction and Kreise Pro are optional features.
16. Automated decisions
We do not make automated decisions under Art. 22 GDPR that have legal or similarly significant effects on you. AI event suggestions always require your confirmation.
17. Security
We apply appropriate technical and organisational measures (including TLS encryption, access controls, password hashing, role-based permissions in circles). Absolute security cannot be guaranteed technically.
18. Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) — e.g. push
To exercise your rights, email m.wilka@gmail.com or use the support form (topic: Privacy).
19. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority — in particular in the EU member state of your residence or of the alleged infringement. In Germany, e.g. the data protection authority of your federal state (list: bfdi.bund.de).
20. Children & minors
Kreise is primarily aimed at adults (parents, teachers, organisers). Minors should generally use the app via an account managed by a guardian or an invite into a circle. We do not knowingly collect data from children under 16 without parental consent.
21. Changes to this policy
We update this privacy policy when the law, features or providers change. The current version is available at this URL. For material changes we will inform you in the app or by email where required.