Privacy policy

In short: I collect as little as possible – no tracking cookies, no ads, everything on my own server in Germany.

Last updated: 1 October 2026 · This is a translation for your convenience; the German Datenschutzerklärung is authoritative.

The essentials

This website sets no tracking or advertising cookies (the only exception: an opt-out cookie if you object to the statistics), shows no ads and loads nothing from third-party servers. It runs on a server of my own in Frankfurt am Main. For privacy-friendly visitor statistics my server evaluates page views itself – without a script in your browser, without cookies and without storing IP addresses. The Sailforce app has no account, no analytics and no ads; for current prices and purchases it uses the RevenueCat service at every launch (with a random identifier, without name or email address) – details in the privacy policy for Sailforce.

Personal data is only processed when technically necessary connection data is handled while the website is delivered, when you write to me via the contact form or by email, or when the Sailforce app fetches current prices and your purchase status via RevenueCat at every launch (using a pseudonymous identifier). In-app purchases are handled by Apple under its own responsibility.

1. Controller

The controller for data processing on this website and in the Sailforce app is:

Philipp Masztakowski
PositiveLifeApps
Zonser Str. 23
50733 Köln (Cologne)
Germany
Email: support@positivelifeapps.io

As a one-person business I am not required to appoint a data protection officer. If you have questions about privacy, write to me directly.

2. Hosting and delivery of the website

This website is hosted on a virtual server (VPS) that I rent from Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (“Hostinger”). The server is located in a data centre in Frankfurt am Main, Germany. I set up and operate the operating system and the web server software myself; Hostinger provides the hosting infrastructure to the contractually agreed extent and processes data in the process as my processor (Art. 28 GDPR). The basis is Hostinger’s data processing agreement (Data Processing Addendum), which is part of Hostinger’s terms of service.

When you visit the website, the server necessarily processes the following data:

  • your device’s IP address
  • date and time of the request
  • the requested address (URL), status code and amount of data transferred
  • the previously visited page (referrer), if your browser sends it
  • browser and operating system identifier (user agent)

The purpose is to deliver the website and keep it stable and secure. The legal basis is Art. 6(1)(f) GDPR; my legitimate interest is the secure and reliable provision of the website.

Retention: The web server writes no access logs to disk. The connection data is processed in working memory and – as described in section 4 – evaluated for the visitor statistics, without the IP address being stored. Technical error logs of the server are deleted automatically after 14 days at the latest. To protect against attacks on the server access (not on the website), IP addresses are temporarily blocked after repeated failed login attempts.

Encryption: The connection is encrypted via HTTPS. The certificate comes from Let’s Encrypt; no visitor data is transmitted to Let’s Encrypt in the process.

Domain and DNS: Name resolution for the domain (which server address belongs to positivelifeapps.io) is handled by Cloudflare, Inc. (USA). The page requests themselves do not go through Cloudflare but directly to my server. During name resolution, Cloudflare usually only sees the request from your internet provider’s DNS server, not your own IP address.

3. No tracking cookies, no third-party content

This website sets no cookies and stores nothing in your browser’s storage – with one single exception: if you object to the visitor statistics, your browser stores, at your request, a cookie “plapps_statistik=aus” (valid for two years, no identifier) so that your objection can be honoured (Section 25(2) No. 2 TDDDG). There are no advertising services, no social media plugins, no embedded videos or maps and no third-party fonts. All fonts, images and scripts come from this domain.

Links to other websites (for example Apple) are ordinary links. Only when you click them do you leave this website; the privacy policy of the respective provider applies there.

4. Visitor statistics without cookies and without script

To understand which pages are read and how visitors find the website, I run visitor statistics using the open-source software Umami. I operate it myself on my server in Frankfurt; no external analytics service receives the data. The statistics are generated exclusively on the server: no statistics script runs on this website, no cookies are set for this purpose and no information is read from your device.

To do this, for each page view my server evaluates the information your browser sends with every request anyway: the page visited (of any link parameters appended, only campaign tags such as utm_source; all others are discarded), the previously visited page (referrer, domain and path only), browser identifier (from which browser, operating system and device type are derived) and preferred language. The country is derived from the IP address. I also count how many messages arrive via the contact form and which type and app they relate to – without their content, names or email addresses; like a page view, this event is assigned to the same pseudonymous visit. Automated requests (for example from search engine robots) are filtered out where possible.

The IP address is not stored. So that several page views of the same visit can be added together, Umami creates a hash identifier (an irreversible checksum) from the IP address, browser identifier and a regularly changing secret value. The statistics are therefore not anonymous but pseudonymous: I only evaluate them in aggregate, do not try to identify individuals, and do not track visits across other websites.

The purpose is to improve the website and my offering based on aggregated figures. The legal basis is Art. 6(1)(f) GDPR; my legitimate interest is data-minimising audience measurement. Since nothing is stored on or read from your device, no consent under Section 25 TDDDG is required.

Objection: You can object to this evaluation at any time under Art. 21 GDPR: on the Turn off statistics page, one click is enough. Your browser then stores the opt-out cookie mentioned above, and your page views are not recorded by the server at all. This applies to the respective browser; if you delete your cookies, you will need to object again. I cannot assign data that has already been recorded to any individual and therefore generally cannot delete it selectively (Art. 11 GDPR); if you give me information that makes this possible after all, I will delete it.

Retention: The statistics data is deleted after 24 months at the latest.

5. Contact form and email

Via the contact form you can send me feedback, bug reports, ideas or questions. In doing so I process the type of your message, the app you selected, the message text and – only if you provide them – your name and email address. The information is stored in a database on my server in Frankfurt. Your IP address and your browser identifier are not stored together with the message. To protect against mass automated submissions, a hash identifier is created from the IP address and counted only in working memory; this identifier is discarded automatically after about eleven minutes at the latest.

If you email me or I reply to you, I process your email address, your name (if provided) and the content of the messages. For email I use Google Workspace from Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, as a processor on the basis of Google’s data processing terms (Cloud Data Processing Addendum). It cannot be ruled out that data is also transferred to Google LLC in the USA. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has found an adequate level of data protection (Art. 45 GDPR); the Standard Contractual Clauses also apply (Art. 46(2)(c) GDPR).

The purpose is to handle your request and to improve my apps. The legal basis is Art. 6(1)(b) GDPR if your request concerns a purchase or the use of Sailforce, otherwise Art. 6(1)(f) GDPR (my legitimate interest in answering enquiries and fixing bugs).

Retention: Messages from the contact form are deleted automatically: at the latest twelve months after receipt; submissions marked as spam or automatically flagged as suspected spam and not processed by me after 30 days. I delete them earlier as soon as they are no longer needed. I delete emails once the request has been dealt with – unless statutory retention obligations (for example for business correspondence under German commercial and tax law) require longer storage.

6. The Sailforce app

The Sailforce app has its own privacy policy for Sailforce. In short: no account, no ads, no tracking; settings stay on your device; Apple handles purchases, and the app fetches current prices and your purchase status at every launch via the RevenueCat service, using a random identifier without name or email address (USA, EU Standard Contractual Clauses).

7. Your rights

Under the GDPR you have the right to

  • access the data I hold about you (Art. 15),
  • rectification of inaccurate data (Art. 16),
  • erasure (Art. 17),
  • restriction of processing (Art. 18),
  • data portability (Art. 20) and
  • withdraw consent with effect for the future (Art. 7(3)).

Right to object (Art. 21 GDPR): where I process data on the basis of my legitimate interest (Art. 6(1)(f) GDPR), you may object at any time on grounds relating to your particular situation.

An informal email to support@positivelifeapps.io is enough. As I hold practically no personal data apart from messages you have sent me yourself and the pseudonymous identifier at RevenueCat, the answer is usually short – but you will get one.

8. Right to lodge a complaint

You can lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work. The authority responsible for me is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de

9. No obligation to provide data, no automated decisions

You are not obliged to provide me with any data. Without the technically necessary connection data, however, the website cannot be delivered. There is no automated decision-making or profiling.

10. Changes

I update this privacy policy when the website, the app or the law changes. The version published here applies. Last updated: 1 October 2026.