scrapeaday

Privacy

scrapeaday for iPhone and the website at scrapeaday.app. Last updated 31 August 2026.

This page is in English because the app and the rest of this site are in English. The Impressum is in German, because German law asks for it in German.

The short version

The app collects nothing. Your scraps stay on your iPhone, there is no account and there is no server behind the app.

The website collects one thing, and only if you hand it over: your email address for the waitlist. It is stored in the EU, you confirm it by clicking a link, and you can get out again with one click.

Two things still reach other companies when you read this page: the hosting provider sees the request, and the fonts are loaded from Google. Both are explained below.

1. Who is responsible

The controller under the General Data Protection Regulation is:

Felix Barth
scrapeaday
Alter Oßweiler Weg 23
71638 Ludwigsburg, Germany
support@scrapeaday.app

No data protection officer has been appointed. If you have a question about any of this, the address above is the one to write to.

2. The app on your iPhone

scrapeaday has no account, no login and no server behind it. Every scrap you punch in is stored on your device. Nothing is uploaded, because there is nowhere to upload it to, and nothing is synced between devices.

There is no analytics tool, no advertising code and no tracking of any kind inside the app. Nobody, including me, can see what you photograph, what you write under it or how often you open the app.

Checked on 31 August 2026. The app has no third party packages at all, no crash reporting and no analytics of any kind.

What the app asks your phone for

Camera
Needed, because a scrap can only be taken live in the app. The picture goes straight into the app on your device.
Adding to Photos
Optional. It is used only to place a copy of each scrap into your own Photos album called scrape a day. The app does not read your library and does not see your other photos.
Notifications
Optional. One daily reminder, sent by your own device. No push server is involved.

Because none of this ever reaches me, there is nothing on my side to store, hand over or delete. If you want all of it gone, delete the app. The copies in your Photos album stay in Photos until you delete them there.

3. This website

The site is a handful of static files. It runs on a virtual server I rent myself from Hostinger International Limited, in a data centre in Frankfurt am Main, Germany. The data stays in the EU. A data processing agreement with Hostinger is in place.

Like every web server, it has to process some technical data in order to send you this page: your IP address, the time of the request, the file you asked for, the referring page and the identification your browser sends. The legal basis is Article 6 paragraph 1 letter f of the GDPR, the legitimate interest in delivering a working and reasonably secure website. I do not read these logs, and they are not connected to anything else.

The web server writes its log to the container output. Docker keeps at most three files of ten megabytes each and then overwrites the oldest, so old entries disappear on their own.

4. The waitlist

If you type your address into the waitlist form on the front page, it is sent to MailerLite, the service that runs the list. MailerLite is operated by UAB MailerLite in Lithuania, and it stores subscriber data on servers inside the European Union. Its data processing agreement takes effect with the terms of use, and it applies here.

How the sign up works

Nothing happens until you confirm. MailerLite sends you a mail with a link, and your address only goes on the list once you have clicked it. If you never click, no launch note is ever sent to that address. This is the double opt in that German law expects, and it is switched on.

What is stored

Your email address
The only thing the form asks for. There is no name field and no other question.
Sign up and confirmation time
Together with the IP address used, this is the record that the confirmation was really yours. Without it there is no proof of consent.
Whether a mail was opened
MailerLite can record opens and clicks in the mails it sends. [[ BITTE AUSFUELLEN: Oeffnungs- und Klick-Tracking in MailerLite abschalten und dann diesen Eintrag streichen, oder die Einstellung so lassen und diesen Satz behalten. ]]

What it is used for

One message when the app is on the App Store, and nothing else. The legal basis is your consent, Article 6 paragraph 1 letter a of the GDPR. You can take that consent back at any time, with the unsubscribe link at the bottom of every mail or by writing to the address in section 1. Taking it back does not make anything that happened before it unlawful.

[[ BITTE AUSFUELLEN: entscheiden, was nach der Launch-Nachricht mit der Liste passiert. Die Startseite verspricht genau eine Nachricht. Entweder die Liste danach loeschen, oder das Versprechen auf der Startseite aendern. Die Entscheidung gehoert hier hinein. ]]

5. Fonts loaded from Google

The type on this site is set in Newsreader and Caveat. Both are loaded from Google's servers at fonts.googleapis.com and fonts.gstatic.com while the page is opening. That request carries your IP address to Google, along with the usual request data such as your browser and your operating system.

This is worth saying plainly, because it has been argued about in German courts and a website that hides it is not being honest. There is no consent banner on this site, and the request happens as soon as the page loads.

The fix is simple and it is on the list: the two font files can be served from this site instead, which removes the request to Google completely. That means about 270 kilobytes of font files hosted here rather than fetched from Google.

[[ BITTE AUSFUELLEN: entscheiden, ob die Schriften vor dem Livegang lokal gebundelt werden. Wenn ja, diesen ganzen Abschnitt streichen und die preconnect- und stylesheet-Zeilen aus allen vier HTML-Dateien entfernen. Details und Aufwand in docs/10-livegang.md. ]]

6. Cookies and the visit counter

This site sets no cookies. It stores nothing in your browser, no local storage, no session storage, no tracking pixels, no advertising and no social media buttons.

It does count visits, because I would like to know whether anyone is reading this. The counter is a small program I wrote and run on the same server in Frankfurt. Nothing goes to Google Analytics or any comparable service, and no third party is involved.

For each page view it stores four things: the time, the title of the page, the path you opened without any query parameters, and the origin of the page that linked you here, meaning the scheme and host only and never the full address. It records the same four things when you click one of a small number of marked buttons, for example the waitlist button. Nothing else.

What it deliberately does not store: no cookie, no identifier, no session, no IP address in the counter database, no screen size, no browser identification, no time zone, no language and no canvas fingerprint. Two visits cannot be linked to the same person.

The legal basis for the counter is Article 6 paragraph 1 letter f of the GDPR, the legitimate interest in knowing whether the site works and reaches anyone. Because nothing is stored in or read from your device, no consent banner is required under section 25 of the German TDDDG.

If your browser sends "Do Not Track" or Global Privacy Control, the counter does not run at all. You can also block the file named analytics.js and the rest of the page works exactly the same.

Google Fonts does not set a cookie either. The request to Google still reveals your IP address, which is why it has its own section.

7. The App Store

The app is distributed through Apple's App Store. Whatever happens while you are in the App Store is Apple's business and runs under Apple's own privacy policy, not this one. Apple shows me aggregated numbers, for example how many people downloaded the app in a country. Those numbers are counts, and nothing in them identifies a person.

8. How long things are kept

Scraps in the app
As long as you keep them. They live on your device and nowhere else, so this is entirely in your hands.
Waitlist address
Until you unsubscribe or ask to be removed. [[ BITTE AUSFUELLEN: siehe offene Entscheidung in Abschnitt 4 ]]
Server logs
On the server in Frankfurt, for a short period, then they are rotated away. At most three files of ten megabytes, then the oldest is overwritten.
Counter entries
Kept as a running total. They hold no identifier and cannot be traced back to a person, so there is nothing in them to delete on request.

9. Your rights

Under the GDPR you can ask for a copy of the data held about you (Article 15), have it corrected (Article 16), have it deleted (Article 17), have its use restricted (Article 18), receive it in a portable form (Article 20) and object to processing based on legitimate interest (Article 21). You can withdraw consent at any time (Article 7 paragraph 3).

In practice, for this project, that almost always means the waitlist, because it is the only place where anything of yours is stored. Write to the address in section 1 and it will be handled.

You can also complain to a supervisory authority (Article 77). The one responsible for me is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Königstraße 10a, 70173 Stuttgart, baden-wuerttemberg.datenschutz.de.

10. Changes to this page

If the app or this site starts doing something new, this page is updated before that happens, and the date at the top changes with it. There is no version history to dig through, the current text is the one that applies.