Privacy Policy

Last updated: August 13, 2026

1. Data Controller

The data controller for data processing on kramli.de, the associated mobile app, the Apple Watch app, and the browser extensions (collectively "Kramli") is:

Johannes Häusler
c/o flexdienst – #20367
Kurt-Schumacher-Straße 76
67663 Kaiserslautern
Germany

Email: [email protected]

Full provider identification: kramli.de/impressum.

2. Data We Collect

2.1 Account Data

During registration and login we store:

  • Firebase UID (technical identifier)
  • Email address
  • Display name
  • Profile picture URL (if provided by the login service)
  • Email verification status

Passwords are not stored by Kramli itself but managed exclusively by Firebase Authentication (Google).

For password leak checks with Have I Been Pwned, Kramli uses k-anonymity: only the SHA-1 prefix (the first 5 characters of the hash) is sent to the service, never the plaintext password and never the full hash.

When using a guest account (without email address), a one-time recovery code is generated and stored server-side so you can transfer your account to another device later.

2.2 Lists & Items

All content you create in Kramli is stored in our database:

  • List names, icons, and colours
  • Items (text, quantity, notes, due date, priority, tags)
  • Uploaded images attached to items
  • Sharing tokens for shared lists
  • Memberships and invitations

2.3 Passkeys (WebAuthn)

When you register a passkey we store the credential ID, the public key, and the sign count. The private key remains exclusively on your device.

2.4 Sessions & Security Alerts

For session management and detection of unusual logins we store and update during active use:

  • Session token
  • IP address (updated during ongoing use)
  • User agent (browser and device information)
  • Device label (e.g. "Chrome on macOS")
  • Timestamp of last activity

Security emails are sent only when the IP address or device differs from the previous session.

2.5 Push Notifications (App and Browser)

When you enable push notifications in the mobile app, a device-specific FCM token (Firebase Cloud Messaging) is generated and stored on our server together with the platform (iOS/Android). The token is used solely to deliver notifications to you. It is deleted on logout or account deletion.

When you enable push notifications in your browser, we store the browser's push subscription. This includes the technical endpoint and the public keys supplied by your browser for encrypted delivery. The subscription is linked to your account. You can disable and remove it in notification settings. It is also removed when you delete your account.

2.6 Device Permissions (App)

The mobile app may request the following device permissions, each of which you can grant or deny individually:

  • Camera – to add photos to items
  • Photo library – to select existing images or share saved images
  • Notifications – for push notifications and reminders
  • Exact alarms & autostart (Android) – so that scheduled reminders fire reliably even after a device restart

None of these features are accessed without your explicit consent.

2.7 Apple Watch App

When you use the Apple Watch app, list and item data as well as timer information are synchronised between iPhone and Apple Watch via Apple Watch Connectivity. We store the connection status and a technical Watch ID locally on the iPhone.

2.8 Feedback

When you send us feedback via the app we process your message and optionally your name and email address. If available, a technical event ID is included for debugging. You may optionally attach a screenshot. Transmission is via Sentry (see section 3.9).

2.9 AI Features (Apple Intelligence & Gemini Nano)

On supported devices (iOS 26+ with Apple Intelligence enabled, or Android with Gemini Nano enabled), Kramli offers optional AI features such as speech recognition with automatic task structuring, tag suggestions, and text extraction. These features use exclusively on-device models (Apple Intelligence Foundation Models or Gemini Nano) that run locally on your device.

No data is transmitted to Kramli servers or any third party. Processing (e.g. transcription, task structuring, tag suggestions) happens entirely on-device. Kramli only stores the results you confirm (e.g. created list items), not the raw AI processing data.

Before first use of an AI feature you are informed about on-device processing and asked for consent.

2.10 Google Tasks (optional)

By default, no list data is exchanged with Google Tasks. Connection is voluntary and only occurs after you explicitly link a Google account in the list settings, choose a Google task list, and set a sync direction (for example import from Google Tasks only, export to Google Tasks only, or two-way sync).

For this connection we store OAuth tokens issued by Google (encrypted), the API scopes you granted, and mappings between Kramli items and Google Tasks IDs. Which task content and metadata is transferred depends on the direction you choose. Google's processing is governed by the Google privacy policy.

2.11 Kramli Protection Signal (Apple Trust Insights)

On supported Apple devices, Kramli can request an Apple Trust Insights evaluation before selected actions after you grant permission. These actions include deleting or exporting an account, creating broad API keys, deleting a passkey, transferring list ownership, and creating new sharing links.

The framework processes interaction patterns, timing, context, and basic sensor data. It does not inspect content from Photos, Messages, or Mail. Device-derived inputs remain on the device and are discarded after the evaluation. Kramli receives an outcome (unknown, medium, or high), technical identifiers, timestamps, and model versions. The outcome indicates signs that another person may be coaching the action. It does not confirm fraud or state that an action is safe.

Evaluation runs partly on the device and partly on Apple servers and requires an internet connection. Kramli uses the result for the current action only. The app then tells Apple whether and how the result changed the flow.

2.12 Health Data (Apple Health / Health Connect)

If you mark a list item as a habit in the mobile app and link it to a health goal (e.g. steps, exercise minutes, workouts, or active calories per day), the app asks for an explicit, separate consent before requesting access to Apple Health (iOS) or Health Connect (Android). This consent is separate from agreeing to the Terms and this Privacy Policy and can be withdrawn at any time.

The app requests only the data type your chosen goal needs and reads it read-only. Your daily value is compared against your chosen threshold on your device; only once you reach the goal does the app mark the item as done automatically. Manually checking it off remains possible at any time.

We only send the item's done status to our servers, plus optionally the underlying daily value for display in the app — your full health history never leaves your device. On supported devices the app can perform this check in the background too (iOS: HealthKit background delivery; Android: periodic checks via Health Connect), without you having to open the app.

Kramli does not use health data for advertising, share it with third parties, or sell it. Kramli makes no medical claims and does not replace medical advice. You can unlink it at any time in your device settings (Apple Health / Health Connect) or in Kramli's settings; already-stored completion history is unaffected.

The web version only shows a linked goal's status read-only (e.g. "8,000 steps"); it does not access Apple Health or Health Connect through the browser.

3. Third-Party Services

3.1 Firebase Authentication (Google)

We use Firebase Authentication by Google for account management and login. Data is transmitted to Google servers. The Firebase privacy policy applies.

3.2 OAuth Providers

When you sign in via Google, GitHub, Microsoft, or Apple, Kramli receives your email address, display name, and, if available, profile picture URL. No additional data is retrieved.

3.3 Firebase Cloud Messaging (App)

The mobile app uses Firebase Cloud Messaging (FCM) by Google to send push notifications. A device-specific token is transmitted to Google servers. The Firebase privacy policy applies.

3.4 Cap CAPTCHA (Website)

To protect against automated access we use Cap on the login and registration pages and in the public-list report form. Cap is operated by us at captcha.kramli.de. Technical data (for example IP address, browser characteristics, and the generated CAPTCHA token) is transmitted to this Cap instance and processed there for bot protection. According to Cap documentation, Cap operates without telemetry and without cookies by default. In our current setup, the Cap widget script is loaded via jsDelivr; this may transmit your IP address to the CDN operator. The mobile app does not use this web CAPTCHA.

3.5 Bootstrap Icons (Website)

The website loads icons via the jsDelivr CDN. Your IP address may be transmitted to the CDN operator. In the mobile app, icons are bundled locally; no CDN request is made. The jsDelivr privacy policy applies.

3.6 Gravatar (optional)

If you choose Gravatar as your profile picture source in the profile settings, Kramli creates a cryptographic hash (MD5) of your email address server-side and retrieves your Gravatar profile picture from Automattic Inc. through a Kramli proxy. This means your IP address is not transmitted directly to Automattic/Gravatar; Automattic receives the hash and Kramli's server IP address. This feature is voluntary and is only activated when you explicitly select it. The Automattic privacy policy applies.

3.7 Email Delivery

System emails (e.g. verification, password reset, invitations, security alerts) are sent via a mail server. Your email address and the message content are transmitted to the mail server.

3.8 Fonts

The website loads fonts via Bunny Fonts, a GDPR-compliant European service. Your IP address may be transmitted to the operator (BunnyWay d.o.o., Slovenia). According to the provider, no personal data is stored or shared. The bunny.net privacy policy applies.

In the mobile app, fonts are bundled locally; no external server requests are made.

3.9 Sentry

For error detection and performance monitoring, both the mobile app and the web server use Sentry. The following data may be transmitted:

  • Crash reports and error messages
  • Performance data (load times, transactions)
  • Device and operating system information
  • IP address
  • User identifier (Firebase UID, email address, display name)
  • Feedback content (message, optional name/email, event ID)
  • Feedback screenshots (optional)
  • Session replays (UI screenshots, app only)

Data is processed on Sentry servers in the EU (de.sentry.io). Collection serves exclusively for bug fixing and stability improvement, not for advertising or tracking. The Sentry privacy policy applies.

3.10 Google Tasks API (optional)

When you enable the Google Tasks integration, Kramli communicates with Google via the Google Tasks API as an application you authorised: we read tasks from the task list you selected and, depending on your sync settings, create, update, or delete corresponding tasks in your Google account.

Data transferred is limited to what is technically necessary to sync the linked list (for example task titles, completion status, due dates, and association with the chosen task list). We do not use data from Google Tasks for advertising, profiling, or purposes other than the sync you enabled. The Google privacy policy and the Google API Services User Data Policy apply. You can disconnect at any time in the settings; stored tokens are revoked or removed where technically possible.

3.11 Apple Intelligence & Gemini Nano (On-Device AI)

The optional AI features in the Kramli app use either Apple Intelligence Foundation Models (iOS) or Gemini Nano (Android), depending on platform. These models are provided by Apple or Google and run exclusively on the user's device. No input data (voice recordings, list text, tag queries) is transmitted to Apple servers, Google servers, Kramli servers, or any third party.

Kramli has no access to the internal models or their processing. Responsibility for on-device AI processing lies with Apple or Google. The Apple privacy policy and the Google privacy policy apply.

3.12 Apple Trust Insights

Apple provides Trust Insights for Kramli Protection Signal. Permission is managed by iOS and covers the operation categories used by Kramli. You can change it in system settings; Apple may apply a cooldown after it is disabled. See the Apple privacy policy for information about Apple's processing.

4. No Advertising, No Ad-Tracking

Kramli displays no advertising and uses no ad-tracking or analytics cookies. No data is shared with advertising networks or analytics services. The error monitoring via Sentry (see section 3.9) serves exclusively for technical stability and bug fixing, not for advertising or profiling purposes.

5. Cookies & Local Storage

The website uses only technically necessary session cookies to maintain your login. The service worker may cache data in browser local storage to make the app available offline. Cap (at captcha.kramli.de) is operated without cookies by default in our setup. Other third parties (e.g. Google/Firebase or CDN providers such as jsDelivr) may set their own cookies.

The mobile app stores the following data locally on your device:

  • Cached lists and items for offline use
  • Queue of changes made without an internet connection
  • Downloaded images in the device cache
  • Widget data (list names, colours, icons) for the home screen widget

This data remains on your device and is not transmitted unencrypted to third parties.

The Apple Watch app stores on the watch:

  • List and item data for display
  • Timer state (focus timer), if used

This data remains locally on the watch and is deleted when the watch connection is severed.

The browser extensions (Chrome, Firefox, Edge, Opera) store the following in local browser storage (browser.storage.local):

  • A session token for authentication with kramli.de
  • The last used list
  • Cached drafts (text, notes, source URL)

This data remains locally in the browser and is automatically deleted when the extension is uninstalled. No cookies are set.

6. Data Sharing

Your data is not sold to third parties or shared for advertising purposes. Sharing occurs only:

  • With the service providers listed in section 3 as part of technical operation
  • With Google via the Google Tasks API only if you have set up the optional Google Tasks connection for a list (see sections 2.10 and 3.10)
  • With other Kramli users when you actively share a list with them
  • Where we are legally required to do so

7. Data Security

All connections to Kramli use HTTPS exclusively. Passwords are not stored by Kramli itself but managed via Firebase Authentication.

8. Your Rights

You have the right at any time to:

  • Access your stored data
  • Rectification of inaccurate data
  • Deletion of your account and all associated data
  • Data portability
  • Object to processing

Contact us at: [email protected].

9. Changes

We reserve the right to update this privacy policy as needed, for example when functionality or legal requirements change. The current version is always available at kramli.de/datenschutz.