Privacy Policy · Datenschutzerklärung

Last updated / Stand: 2026-08-13

1. Controller

rApps by Felix Rappmund
[Postal address — to be completed by the publisher]
Privacy contact: [email protected]
General contact: [email protected]

This policy covers the iCali mobile app and the icali.app website.

2. This website (icali.app)

The website sets no cookies and runs no analytics or tracking. The only browser storage used is localStorage for your theme and language choice — a strictly functional setting that never leaves your device (§ 25 (2) TTDSG; no consent banner is required because nothing non-essential is stored). The site is delivered by Cloudflare Pages (Cloudflare, Inc.), which processes IP addresses in server logs for delivery and security (Art. 6 (1)(f) GDPR).

3. The iCali app — what we store

  • Account: email address, display name, optional username. An optional real name is stored privately and shown only to people you allow.
  • Calendar content: calendars, events, to-dos, availability, notes, invitations, group memberships, uploaded files.
  • Social graph: your friend connections and groups.
  • Device data: push-notification tokens and basic device metadata for delivering notifications.

All of this is stored on Firebase / Google Cloud (processor: Google Ireland Ltd.) in the region europe-west3 (Frankfurt, Germany) — Firestore, Authentication, Cloud Storage and Cloud Functions. Data is encrypted in transit (TLS) and at rest. Legal basis: performance of the contract, Art. 6 (1)(b) GDPR.

4. Analytics — opt-in, off by default

App analytics (Firebase Analytics) are disabled by default. They run only after you explicitly opt in (Art. 6 (1)(a) GDPR) and you can revoke the choice at any time in Settings. The app never collects the advertising ID — the corresponding permissions are removed from the app at build level.

5. Crash reporting

Firebase Crashlytics collects crash reports (stack trace, device model, OS version — no advertising ID) so we can keep the app stable. Legal basis: legitimate interest in providing a working product, Art. 6 (1)(f) GDPR.

6. Subscriptions & payments

Pro subscriptions are bought through the Apple App Store or Google Play. We never see your payment details — Apple / Google process the payment as independent controllers. For subscription management we use RevenueCat, Inc. (USA) as a processor: it receives store receipt data and a pseudonymous user ID (no name, no email, no card data). Transfers to RevenueCat rely on the EU Standard Contractual Clauses.

7. External calendar sync — only if you connect it

  • Google Calendar / Microsoft Outlook: if you connect an account, we store the OAuth tokens server-side and sync events between that calendar and iCali in the directions you configure. We access only calendar scopes, never mail or files. Disconnecting deletes the tokens; deleting your account deletes them too. Google/Microsoft process this data under their own terms.
  • Apple Calendar: synced on your device via EventKit — Apple calendar data is not sent to our servers by the sync itself (events you store in iCali are, like any other iCali event).
  • ICS feeds you subscribe to: our servers fetch the feed URL you provide.
  • Your ICS export feed (Pro): if you enable it, anyone who has the secret feed URL can read that calendar. Rotate or disable it anytime in the app.

Legal basis: contract performance for the sync you request, Art. 6 (1)(b) GDPR.

8. Recipients (processors)

Google Ireland Ltd. (Firebase/Google Cloud, hosting in Frankfurt) · Cloudflare, Inc. (website delivery) · RevenueCat, Inc. (subscription management) · Apple / Google (store payments, push delivery). Where a processor operates outside the EU (e.g. push delivery, RevenueCat), the transfer is protected by EU Standard Contractual Clauses (Art. 46 GDPR). We do not sell data and show no advertising.

9. Retention

Your content stays as long as your account exists. Expired invitations, notifications and activity logs are cleaned up automatically (30–90-day windows). Security/audit records are kept up to 7 years. Deleting your account (in-app: Profile → Account → Delete, or see Account Deletion) removes your profile, content, files, sync tokens and connections; residual backups expire on the platform's backup cycle.

10. Your rights (Art. 15–21 GDPR)

Access (the app has a built-in data export under Profile → Account), rectification, erasure, restriction, portability and objection — contact [email protected]. You may also complain to a data-protection supervisory authority.

11. Children

iCali is not directed at children under 16. We do not knowingly process their data without parental consent (Art. 8 GDPR / § national implementation).

12. Changes

We update this policy when the product changes and will announce significant changes in the app. The current version always lives at icali.app/privacy.

1. Verantwortlicher

rApps by Felix Rappmund
[Postanschrift — wird vom Anbieter ergänzt]
Datenschutz-Kontakt: [email protected]
Allgemein: [email protected]

Diese Erklärung gilt für die iCali-App und die Website icali.app.

2. Diese Website (icali.app)

Die Website setzt keine Cookies und nutzt keine Analyse- oder Tracking-Dienste. Einzig deine Theme- und Sprachwahl wird als rein funktionale Einstellung im localStorage deines Browsers gespeichert und verlässt dein Gerät nicht (§ 25 Abs. 2 TTDSG — deshalb ist kein Cookie-Banner nötig). Ausgeliefert wird die Seite über Cloudflare Pages (Cloudflare, Inc.); dabei werden IP-Adressen in Server-Logs zur Auslieferung und Absicherung verarbeitet (Art. 6 Abs. 1 lit. f DSGVO).

3. Die iCali-App — was wir speichern

  • Konto: E-Mail-Adresse, Anzeigename, optionaler Benutzername. Ein optionaler echter Name wird privat gespeichert und nur Personen gezeigt, denen du es erlaubst.
  • Kalenderinhalte: Kalender, Events, To-dos, Verfügbarkeiten, Notizen, Einladungen, Gruppenmitgliedschaften, hochgeladene Dateien.
  • Kontakte: deine Freundschafts-Verbindungen und Gruppen.
  • Gerätedaten: Push-Token und grundlegende Geräteinformationen für Benachrichtigungen.

Gespeichert wird bei Firebase / Google Cloud (Auftragsverarbeiter: Google Ireland Ltd.) in der Region europe-west3 (Frankfurt am Main) — Firestore, Authentication, Cloud Storage und Cloud Functions. Daten sind bei Übertragung (TLS) und Speicherung verschlüsselt. Rechtsgrundlage: Vertragserfüllung, Art. 6 Abs. 1 lit. b DSGVO.

4. Analyse — Opt-in, standardmäßig AUS

App-Analytics (Firebase Analytics) sind standardmäßig deaktiviert und laufen nur nach deiner ausdrücklichen Einwilligung (Art. 6 Abs. 1 lit. a DSGVO), widerrufbar jederzeit in den Einstellungen. Die Werbe-ID wird nie erhoben — die entsprechenden Berechtigungen sind auf Build-Ebene entfernt.

5. Absturzberichte

Firebase Crashlytics erfasst Absturzberichte (Stacktrace, Gerätemodell, OS-Version — keine Werbe-ID), damit die App stabil bleibt. Rechtsgrundlage: berechtigtes Interesse an einem funktionierenden Produkt, Art. 6 Abs. 1 lit. f DSGVO.

6. Abos & Zahlungen

Pro-Abos kaufst du über den Apple App Store oder Google Play. Deine Zahlungsdaten sehen wir nie — Apple/Google verarbeiten die Zahlung als eigenständige Verantwortliche. Für die Abo-Verwaltung setzen wir RevenueCat, Inc. (USA) als Auftragsverarbeiter ein: RevenueCat erhält Store-Belegdaten und eine pseudonyme Nutzer-ID (kein Name, keine E-Mail, keine Kartendaten). Die Übermittlung ist über EU-Standardvertragsklauseln abgesichert.

7. Externe Kalender-Synchronisation — nur wenn du sie verbindest

  • Google Kalender / Microsoft Outlook: verbindest du ein Konto, speichern wir die OAuth-Token serverseitig und synchronisieren Events in den von dir gewählten Richtungen. Wir greifen nur auf Kalender-Berechtigungen zu — nie auf Mail oder Dateien. Beim Trennen (und beim Kontolöschen) werden die Token gelöscht. Google/Microsoft verarbeiten diese Daten nach ihren eigenen Bedingungen.
  • Apple Kalender: wird auf deinem Gerät über EventKit synchronisiert — Apple-Kalenderdaten werden durch die Synchronisation selbst nicht an unsere Server gesendet.
  • Abonnierte ICS-Feeds: unsere Server rufen die von dir angegebene Feed-URL ab.
  • Dein ICS-Export-Feed (Pro): aktivierst du ihn, kann jeder mit der geheimen Feed-URL diesen Kalender lesen. In der App jederzeit rotierbar oder abschaltbar.

Rechtsgrundlage: Vertragserfüllung, Art. 6 Abs. 1 lit. b DSGVO.

8. Empfänger (Auftragsverarbeiter)

Google Ireland Ltd. (Firebase/Google Cloud, Hosting in Frankfurt) · Cloudflare, Inc. (Website-Auslieferung) · RevenueCat, Inc. (Abo-Verwaltung) · Apple/Google (Store-Zahlungen, Push-Zustellung). Soweit ein Dienst außerhalb der EU verarbeitet (z. B. Push-Zustellung, RevenueCat), sichern EU-Standardvertragsklauseln (Art. 46 DSGVO) die Übermittlung ab. Wir verkaufen keine Daten und zeigen keine Werbung.

9. Speicherdauer

Deine Inhalte bleiben, solange dein Konto besteht. Abgelaufene Einladungen, Benachrichtigungen und Aktivitätsprotokolle werden automatisch bereinigt (30–90 Tage). Sicherheits-/Audit-Einträge werden bis zu 7 Jahre aufbewahrt. Beim Kontolöschen (in der App: Profil → Konto → Löschen, oder siehe Account Deletion) werden Profil, Inhalte, Dateien, Sync-Token und Verbindungen entfernt; Reste in Backups laufen mit dem Backup-Zyklus der Plattform aus.

10. Deine Rechte (Art. 15–21 DSGVO)

Auskunft (die App hat einen eingebauten Datenexport unter Profil → Konto), Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch — wende dich an [email protected]. Außerdem kannst du dich bei einer Datenschutz-Aufsichtsbehörde beschweren.

11. Kinder

iCali richtet sich nicht an Kinder unter 16 Jahren. Ohne elterliche Einwilligung verarbeiten wir ihre Daten wissentlich nicht (Art. 8 DSGVO).

12. Änderungen

Wir aktualisieren diese Erklärung, wenn sich das Produkt ändert, und kündigen wesentliche Änderungen in der App an. Die aktuelle Fassung findest du immer unter icali.app/privacy.