Privacy Policy
Courtesy translation — the German version is legally binding.
1. Controller
Sanel Hasic
Schillstraße 104a, 86169 Augsburg, Germany
Email: support@shliff.app
2. Hosting (Firebase Hosting)
This website is hosted by Firebase Hosting (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland). When you access the site, the provider processes technically necessary data (including IP address, time, requested file, browser/device information) in server logs to ensure delivery and security. The legal basis is my legitimate interest in secure, stable operation (Art. 6(1)(f) GDPR). A data processing agreement is in place with Google.
3. Newsletter “development updates” (form sign-up)
When you sign up for the updates, I process your email address, the time and the confirmation status of your sign-up, plus two technical form attributes that keep the entries distinguishable in Brevo. Sign-up uses a double opt-in procedure: after submitting, you receive a confirmation email; only after clicking the confirmation link are you added to the list.
- Purpose: sending occasional emails with news about the development of Shliff.
- Legal basis: your consent (Art. 6(1)(a) GDPR, sec. 7(2) no. 3 UWG).
- Processing/delivery: via the service Brevo (see section 5).
- Storage period: until withdrawal; the address is then removed from the list.
- Withdrawal/unsubscribe: at any time via the unsubscribe link at the end of every email or informally by email to the address above; the lawfulness of processing carried out up to the point of withdrawal remains unaffected.
Former beta tester sign-up: Until September 2026 you could sign up as a beta tester on this site; that form no longer exists. The addresses collected back then with consent are still held at Brevo and carry a tester flag. They are used only for that original purpose and are not moved into the newsletter without fresh consent. Here too: unsubscribe at any time via the link in every email or informally by email.
4. Contact form on this website
The contact form lets you send me a message. In doing so I process your email address and the content of your message. Neither is stored in a database; both are delivered solely as an email to my support address (sent via Brevo, see section 5).
- Purpose: handling and answering your enquiry.
- Legal basis: my legitimate interest in answering enquiries (Art. 6(1)(f) GDPR); where a contract or its initiation is involved, Art. 6(1)(b) GDPR.
- Storage period: until your enquiry has been dealt with — after that I delete the correspondence unless statutory retention periods apply.
- No marketing: the address from the contact form is not added to the newsletter; that requires the separate sign-up described in section 3.
- Spam protection: the form contains a field invisible to you (a “honeypot”) that only automated submissions fill in. No additional data about you is collected.
5. Processors
Hosting (Google): The website is provided via Firebase Hosting (Google Ireland Ltd.) (see section 2); a data processing agreement is in place. Processing in third countries (including the USA) cannot be ruled out; Google bases such transfers on the EU Standard Contractual Clauses (Art. 46 GDPR).
Email delivery & newsletter (Brevo): For the newsletter list, for sending the confirmation and newsletter emails and for delivering the messages from the contact form I use the service Brevo by Brevo GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. The data you provide in the form is transmitted to Brevo and stored there (servers in the EU). A data processing agreement is in place with Brevo; for details see Brevo's privacy notice (brevo.com).
6. Fonts
The fonts used (Space Grotesk, Space Mono) are served locally from this server. No connection to Google servers is made and your IP address is not transmitted to third parties.
7. Cookies & local storage (localStorage)
For purely functional purposes, entries are set in your browser's local storage (localStorage): your language choice (DE/EN) and your decision in the cookie banner. These entries are technically necessary, are not used for analytics or tracking, are not transmitted to me, and do not require consent (Section 25(2) German TDDDG). Analytics cookies (Google Analytics, see section 9), by contrast, are set only after your consent via the cookie banner.
8. The “Shliff” app (analytics, crash reports, AI, account & purchases)
The Shliff mobile app (iOS/Android) processes data primarily locally on your device; your idea content is not transmitted to me or third parties — unless you use the optional AI features (see below).
- Anonymous usage analytics (Firebase Analytics): only after your explicit consent (opt-in; OFF by default, revocable at any time in the app settings). Only anonymous usage events (e.g. “idea created”) and device/usage metadata are collected — no idea content, no titles/descriptions, no personal data. Provider: Google (Firebase). Legal basis: consent (Art. 6(1)(a) GDPR).
- Crash reports (Firebase Crashlytics): likewise only with consent. Technical crash/ error diagnostics (stack traces, device/OS info) are transmitted to improve stability — no idea content. Provider: Google (Firebase).
- AI with your own API key (optional): If you enable the AI features with your own key (structuring, research and test suggestions, chat), the text you type or speak is transmitted directly to the AI provider you choose and processed there to generate the response — available providers are Google Gemini, Anthropic (Claude), OpenAI (ChatGPT), Perplexity and xAI (Grok). These features are OFF by default. Your API key is stored only locally in the device’s secure key store. The respective provider’s privacy notice also applies. Legal basis: consent/performance of a contract (Art. 6(1)(a)/(b) GDPR).
- Managed AI (sample, trial, subscription): If you use the AI features without your own key, the app sends your input to my own server function (Google Cloud Functions/Firebase, Frankfurt region). Depending on the task, it forwards the input to Google Gemini or Anthropic (Claude) — the server, not you, selects the provider — and returns the response to the app. The server only stores usage counters tied to your anonymous user ID (actions per month, tokens per day), not the content of your input. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Anonymous account & quotas (Firebase): For managed AI and purchases, the app signs in anonymously with Firebase Authentication (Google) and receives a random, stable user ID — no name, no email address. Under this ID I store plan and quota data in Firebase Firestore: the active plan (free/trial/subscription/lifetime), used sample actions, monthly action and daily token counters, and, where applicable, the start and expiry of a tester access and the redemption of a tester code. No idea content is stored there. Legal basis: performance of a contract and legitimate interest in preventing abuse (Art. 6(1)(b)/(f) GDPR).
- Purchase processing (RevenueCat): Purchases, subscriptions and trials are managed by RevenueCat (RevenueCat, Inc., USA). The app registers the anonymous user ID with RevenueCat; RevenueCat processes the purchase and subscription information from the respective app store and reports the purchase status to my server, which stores it under the user ID. RevenueCat’s privacy notice also applies. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- App integrity check (Firebase App Check): For requests to the server function, the app proves via Firebase App Check that it is an unmodified original app — on iOS via Apple’s “App Attest”, on Android via Google’s “Play Integrity”. Device and app attestation data are transmitted to Apple or Google in the process. Legal basis: legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
- Speech recognition: There are two ways to turn speech into text. With offline recognition (Whisper), transcription happens entirely locally on the device; no audio data is transmitted. With the operating system’s speech recognition, processing may take place on the device or on Apple’s or Google’s servers, depending on device, language and system settings; their privacy notices apply.
- Feedback feature (optional): If you send feedback through the app, the category, your description, an optional contact detail plus app version, platform and language are stored in Firebase Firestore and delivered to me by email (sent via Brevo) so I can handle your report. Legal basis: legitimate interest in fixing and improving the app (Art. 6(1)(f) GDPR).
- Third countries: Using Firebase, RevenueCat or an AI provider may involve processing in third countries (incl. the USA); providers rely on the EU Standard Contractual Clauses (Art. 46 GDPR) for such transfers.
9. Web analytics (Google Analytics 4)
This website uses Google Analytics 4 — only after your consent via the cookie banner — a web analytics service provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Data may also be transferred to Google LLC in the USA; Google is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR). Without consent, Google Analytics is not loaded and no data is transferred to Google.
- Purpose: audience measurement (e.g. page views, referrers, device type) and conversion measurement (e.g. newsletter sign-ups).
- Legal basis: your consent (Art. 6(1)(a) GDPR), given via the cookie banner.
- Cookies: Google Analytics sets the cookies _ga and _ga_* with a storage period of up to 14 months.
- IP addresses: are truncated by Google Analytics 4 at collection and are not stored.
- Withdrawal: at any time via the “Cookie settings” link in the footer of the homepage — it clears your choice and reopens the banner so you can decide again. The lawfulness of processing carried out up to the point of withdrawal remains unaffected.
10. Your rights
You have the following rights vis-à-vis the controller:
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18),
- data portability (Art. 20), objection (Art. 21) and withdrawal of consent given (Art. 7(3)).
You also have the right to lodge a complaint with a supervisory authority, e.g. the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.