Privacy Policy
Last updated: August 18, 2026
1. Who is responsible
Dipl.-Ing. Alexander Kainzinger, BSc, Wildbergstraße 18, 4040 Linz, Austria, is the controller for the personal data described in this policy. Contact the controller at contact@kountdown.app.
2. What Kountdown does and what this policy covers
This policy covers the Kountdown website, iPhone app, and cloud features. Kountdown is local first: you can create and use local iPhone Kountdowns without an account. An account is needed for cloud sync, collaboration, public sharing, calendar feeds, and safety tools. Signed-in users can report shared content and block other users. Paid iPhone features are sold through Apple's App Store.
3. Information we process
- Local iPhone data: Kountdown titles, descriptions, dates, time zones, themes, settings, and a random installation identifier. This remains on your device unless you sync, share, or add it to a calendar feed.
- Account and cloud data: Cognito account ID, email, name and profile information supplied through Google or Apple, synced Kountdowns, permissions, subscription tier, and cloud settings. Sign-in tokens are stored in iOS Secure Store or necessary browser storage.
- Sharing and calendar-feed data: public Kountdowns, collaboration links and access permissions, and calendar-feed tokens. Public content is available without sign-in. Anyone with a collaboration or calendar-feed URL may use it as permitted by that feature; recipients may copy it, and public pages may be indexed or cached by third parties.
- Purchase data: entitlement and transaction status, product and subscription information, and a pseudonymous customer identifier. Apple processes payment credentials; Kountdown never receives or stores full payment-card details.
- Safety and moderation data: when you report a shared Kountdown, the report contains the reporter and owner account IDs, Kountdown ID, report reason, optional details, status, and creation time. When you block a user, we store the two account IDs and the creation time. Your block list shows only a neutral “Blocked account” label and the block date; it does not show the other person's name, email, profile, or account identifier. We send an AWS SNS email alert containing the report and Kountdown IDs, but not Kountdown content or optional report details.
- Security, access, and support data: IP address, requested URL, timestamps, browser/device information, referrer, response status, and limited operational event data in access and security logs. For state changes and faults, this can include raw account UUIDs, Kountdown UUIDs, and RevenueCat event IDs to investigate faults, prevent misuse, and protect the service. We do not log bearer links, authentication headers, request bodies, Kountdown content, or raw error objects. If you email us, we process your name, email address, and message.
What we do not collect: passwords, payment-card details, contact lists, address books, precise location, advertising identifiers, or analytics data. Kountdown does not use AI models or use your data to train, improve, or fine-tune AI systems.
4. Why we process it and our legal bases
- To provide the app, authenticate you, sync Kountdowns, share content, run feeds, and restore purchases — performance of our contract with you.
- To maintain security, prevent misuse, investigate faults, and improve core reliability — our legitimate interests in operating a dependable service.
- To operate safety tools, review content reports, enforce these Terms, and protect users and the service from abuse — our legitimate interests in safety and service integrity.
- To meet accounting, tax, and other legal obligations — compliance with a legal obligation.
- Where required, with your consent, which you may withdraw through the relevant device or service settings.
We do not send marketing communications or use information for advertising or AI-model training.
5. Cookies and similar browser storage
| Storage | Purpose | Duration | Your choices |
|---|---|---|---|
| Cognito sign-in cookies and browser storage | Complete and maintain a Google, Apple, or Cognito sign-in session. | Session or token lifetime managed by Cognito. | Sign out and clear browser data; cloud features will no longer work. |
We do not use analytics, advertising, or cross-site-tracking cookies, and do not sell or share data for targeted advertising. We therefore do not operate an optional-cookie banner. Because we do not use non-essential tracking, Do Not Track is not needed as a separate opt-out mechanism.
6. Third-party processors
| Provider | Purpose | Privacy policy |
|---|---|---|
| Amazon Web Services | Hosting, CloudFront delivery, Cognito authentication, APIs, database, logs, and content-report alert delivery through SNS. | AWS Privacy Notice |
| Google account sign-in and the account profile information you approve. | Google Privacy Policy | |
| RevenueCat | In-app purchase offerings, entitlement status, and subscription validation. | RevenueCat Privacy Policy |
| Apple | Sign in with Apple, App Store distribution, billing, purchases, and subscription management. | Apple Privacy Policy |
We do not use an analytics, advertising, email-marketing, or AI-processing provider.
7. Retention and deletion
- Local iPhone data remains on your device until you delete it or remove the app.
- Cloud account, synced content, sharing, calendar-feed, and purchase-entitlement records remain while your account is active.
- User-block records remain while the blocking account is active.
- Identifiable content-report records remain while a report is open and for 90 days after it is resolved. We then delete them unless a documented legal, safety, fraud-prevention, or dispute-related need requires longer retention; in that case, we remove account identifiers and optional details where they are not needed.
- We retain operational access and security logs, including diagnostic identifiers where described above, for 30 days.
- After a verified deletion request, we delete active cloud account data, including related user-block records and identifiable content-report data, within 30 days, except for a narrow legal, security, fraud-prevention, or dispute-related retention obligation. DynamoDB point-in-time-recovery copies are inaccessible in normal operations and expire within up to 30 additional days.
Request deletion from the Profile screen in the iPhone app or by emailing account-deletion@kountdown.app from the account's email address. Deletion does not cancel an Apple subscription; manage subscriptions through your Apple Account settings.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing, and to receive a portable copy of certain data. To exercise a right, contact contact@kountdown.app. We may ask for information needed to verify your identity and normally respond within 30 days. You may also complain to your local data protection authority; in Austria, this is the Austrian Data Protection Authority.
9. International transfers
Kountdown's AWS account services are configured primarily in the EU (Ireland); CloudFront and our providers may process information in other countries, including the United States. Where required, we use an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism with appropriate safeguards.
10. Children
Kountdown is not directed to children under 13, or under the age at which they may lawfully consent to data processing in their country (16 in many EEA countries). We do not knowingly collect their personal data. If you believe a child has provided us information, contact contact@kountdown.app so we can delete it.
11. Security
We use HTTPS/TLS for data in transit and provider-managed encryption at rest for cloud services. Access is limited to what is needed to operate Kountdown. No security measure is perfect, but we will address and notify affected people of a breach where required by law.
12. Changes to this policy
We may update this policy when the service or law changes. We will publish the updated version here and revise the date above. Material changes will be communicated through the app or another appropriate channel where required.
13. Contact
For privacy questions or rights requests, email contact@kountdown.app. For an account-deletion request, use account-deletion@kountdown.app. We normally respond within 30 days.
14. Regional supplements
EEA and UK
Our legal bases are performance of a contract, legitimate interests in secure and reliable service operation, compliance with legal obligations, and consent where required. You have the rights described in Articles 15–22 GDPR, including access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with your local supervisory authority. The controller is established in Austria, so no separate EU representative is appointed.
California
During the preceding 12 months, we may have collected identifiers (account ID, email, name), internet or electronic activity (access logs and browser/device information), customer records (support messages), commercial information (purchase and entitlement status), and user content (Kountdown details and optional report details). We may also collect identifiers and electronic activity in connection with content reports and user blocks. We collect these directly from you, Google, Apple, RevenueCat, and service operation. We disclose them to the processors listed above only to operate Kountdown. We do not sell or share personal information for cross-context behavioral advertising and do not use sensitive personal information to infer characteristics. California residents may request to know, correct, or delete personal information, or use an authorized agent, by contacting contact@kountdown.app. We will not discriminate for exercising these rights.