Privacy Policy

This project is privately and non-commercially operated.

Usage Statistics (Umami Analytics)

This website uses Umami Analytics (umami.is) for anonymous visitor statistics. Umami sets no cookies, stores no personal data, and is fully compliant with GDPR and the Swiss nFADP.

Only aggregated, non-personal metrics are collected (page visited, approximate browser language/region, device type). Identification of individual persons is not possible. Data is processed on Umami Cloud servers (USA); Umami explicitly does not store IP addresses or other identifying attributes.

Legal basis: legitimate interest pursuant to Art. 31 nFADP (improving the service). Consent is not required given the privacy-friendly nature of the method.

Server Log Data

When visiting this website, server log data (IP address, timestamp, requested page) is collected for technical reasons and automatically deleted after 7 days.

Portal and Hosted Instances

This section applies to the portal (portal.chastitytracker.ch) and to the tracker instances operated through the portal. It does not apply to self-hosted installations: whoever runs the tracker on their own infrastructure is responsible for the data processing there.

Location

The portal, hosted instances and the mail server run on servers in Germany.

Portal Account

For a portal account, the following is stored:

Sign-in additionally requires a one-time code sent by email. For each instance, the portal stores the name and subdomain. The instance admin's credentials (username, optionally an email address) are handed over to the instance when it is created.

The portal keeps an activity log of sign-ins (successful and failed, including failed one-time codes), registrations, and the creation and deletion of instances, each with email address and IP address. These entries are currently without a fixed deletion period.

The portal's feedback form stores the message, the page it was sent from, optionally a contact email address, and the IP address only as a hash.

Usage Signal and Clean-up

The portal reads from each instance when it was last used or changed, how many entries it contains, when the latest one was recorded, and the language its users have set. It also stores the emails it sent the owner about the clean-up and the owner's answer (yes/no). This is used to tidy up unused instances: the owner of the instance is first notified by email, then the instance is stopped and placed on a deletion list. An instance is not deleted automatically; a person makes that decision.

Data in a Hosted Instance

Each instance runs separately with its own database. It stores what its users record:

The users of that instance can see this data according to their role (wearer, keyholder, admin). The operator of the servers has technical access to the stored data and uses it for operation, maintenance and troubleshooting.

Photo Checking

Photo checking automatically analyses submitted photos (reading a handwritten code, recognising seal and device). It is switched off by default for new instances. The admin of an instance can switch it on:

Users of the instance see a small ⓘ next to the affected photo fields naming the provider; keyholders and admins receive a one-time notice.

Transition:instances that existed before this change keep photo checking via Anthropic with the operator's key for 30 days after their update. After that, it only runs with the admin's own key.

AI Keyholder

A user can connect any AI assistant that supports the connection (MCP) to their instance. The assistant can then read the instance data, and images only if image access has been explicitly enabled. In that case, the data reaches the assistant's provider through that user's own account (for Claude via claude.ai: Anthropic).

Notifications

Logs and Backups

Deleting an Instance

When an instance is deleted in the portal, its data is first archived and later removed permanently by hand.

Access and Deletion Requests

Requests for access or deletion can be sent to info@trublue.ch.

Update Check of the Tracker App

This section applies to all tracker installations, both hosted and self-hosted. Each instance asks a project server at most once an hour whether a new version is available.

These requests are counted:

For instances hosted through the portal, the count is not anonymous towards the operator: the portal knows the identifier of each hosted instance and can assign the count to that instance. For self-hosted installations, the count is not linked to a person or an account; the operator does not evaluate the IP check value to identify installations.

Self-hosters can switch the counting off with the environment variable DISABLE_UPDATE_CENSUS=trueor by configuring their own changelog source. If the counting is switched off or the project server is unreachable, the instance fetches the version information directly from GitHub instead; GitHub then sees the instance's IP address.

Responsible Party

Responsible: TruBlue — info@trublue.ch

Swiss law applies, in particular the Swiss Federal Act on Data Protection (nFADP). The supervisory authority is the FDPIC.