Privacy Policy

Last updated: 17 September 2026. This policy covers both the GeoBlockr app and this website.

1. Who is responsible

Felix Kampmann, Picassoring 89, 56626 Andernach, Germany.
Email: support@geoblockr.com

I am the controller for the processing described here, within the meaning of Art. 4(7) GDPR. Full details are in the Impressum. I am not required to appoint a data protection officer, so there is none to contact. Write to the address above for anything on this page.

2. What never leaves your device

GeoBlockr runs on your phone. There is no account, no login, and no server of mine. The following is stored on your device only and is never transmitted, not to me and not to anyone else:

I have no access to any of this and receive none of it, so there is nothing here for me to hand over, lose, or be asked for.

Deleting the app removes all of it from your phone. It does not remove the separate records described in sections 3 and 4, which are held by other companies. Section 10 explains how to have those deleted.

3. Product analytics

I use PostHog to see how people move through the setup questions, so I can find the steps where they get stuck.

What is sent. The answers you give to the setup questions, including the screen time estimate and the daily goal you type in yourself, how far through setup you get, and whether you granted the permissions the app asks for.

None of the things listed in section 2 are sent: not your location, not the zones you create, not which apps you choose to block, and not the Screen Time figures iOS measures.

When it is sent. Only during setup. Once you have finished, the app sends no further analytics. It does still ask PostHog for a small configuration file when it starts, which is part of how the software works and carries no information about you.

How you are identified. By a random identifier created on your device and stored there. It is not Apple's advertising identifier (IDFA), not the vendor identifier, and not derived from you or your hardware. Deleting and reinstalling the app creates a new one, with no way to connect it to the old one. Storing that identifier on your device needs your permission in the EU, and the switch described below covers it. The same identifier is also used for subscription handling, so those two records can be related to each other.

Your IP address is discarded. The PostHog project is configured to drop the client IP address, so it is not stored.

Where. PostHog's EU cloud (eu.i.posthog.com), on servers in Frankfurt. PostHog is a company with a United States parent, so I cannot rule out that staff there see this data while providing support. PostHog is certified under the EU-US Data Privacy Framework, which the European Commission decided on 10 July 2023 offers protection equivalent to the GDPR. If that certification ever lapses, the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914) take over, and you can ask me for a copy of those.

How long. 12 months, after which PostHog deletes it.

Do you have to? No. Analytics is entirely voluntary. The app works exactly the same either way, and nothing is withheld from you if you decline.

Legal basis, and how to stop it. If you are in the EU, the EEA, the United Kingdom, or Switzerland, analytics is off until you switch it on, and nothing is sent before that. The basis is your consent under Art. 6(1)(a) GDPR. You can withdraw it at any time under Settings in the app, and switching it off is as easy as switching it on was. Withdrawing does not make the earlier collection unlawful, but it does end my basis for keeping what was collected, so see section 10 to have it deleted.

Everywhere else, analytics is on by default. The basis is my legitimate interest in improving the app under Art. 6(1)(f) GDPR. You can object at any time under the same setting, and collection stops from that moment. Section 11 explains this right in full.

There is no session recording and no screen recording. PostHog's replay feature is switched off in the project and is not built into the app.

4. Purchases and subscriptions

Purchases are handled by Apple. I never see your payment details, which Apple processes as its own controller under its own privacy policy.

To know whether your subscription is active, I use RevenueCat, Inc., San Francisco, USA. RevenueCat receives the random identifier described above together with the purchase and subscription status belonging to it. The basis is Art. 6(1)(b) GDPR, since the subscription cannot be delivered without it. This part is not optional: if you buy a subscription, this processing is what makes it work, and there is no version of it that skips this step. A data processing agreement under Art. 28 GDPR is in place.

How long. For as long as you have a subscription with me, and afterwards only for as long as it is needed to settle that relationship.

RevenueCat processes data in the United States, on Amazon Web Services and Snowflake infrastructure. That is a transfer to a third country under Art. 44 ff. GDPR, covered by the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914). Write to me for a copy.

5. What these companies may do with your data

PostHog, RevenueCat, Cloudflare and IONOS each handle data only on my instructions, under a written contract that binds them to protect it to a standard equal to or greater than the one described in this policy. They may use it only to provide their service to GeoBlockr. They may not sell it, pass it on, or use it for their own purposes, including advertising or improving their own products.

Apple is the exception, and not because of anything I arranged. For purchases and for the statistics in section 6, Apple decides for itself what it does with the data, under its own privacy policy. I have no say in that and cannot instruct Apple.

6. App Store statistics

Apple gives developers aggregated statistics about downloads, sessions and crashes. Apple collects these as its own controller, and only from people who allowed it in their iOS settings under Privacy & Security, Analytics & Improvements. I receive counts and trends, never data about individual people.

7. This website

The site is hosted by Cloudflare, Inc., San Francisco, USA. Each time a page is requested, Cloudflare's servers record that request: IP address, date and time, the file requested, the referring page, and browser and operating system details. This is necessary to deliver the site at all and to keep it secure and stable, which is my legitimate interest under Art. 6(1)(f) GDPR. A data processing agreement under Art. 28 GDPR is in place.

How long. Cloudflare keeps these logs only for as long as they are needed to deliver and protect the site, which is a short period measured in days, and then deletes them. I do not read them and I keep no copy.

Because Cloudflare is based in the United States, this is a transfer to a third country under Art. 44 ff. GDPR. Cloudflare is certified under the EU-US Data Privacy Framework, which the European Commission decided on 10 July 2023 offers protection equivalent to the GDPR. If that certification ever lapses, the EU Standard Contractual Clauses take over, and you can ask me for a copy of those.

No tracking. This site loads no fonts, scripts, images or anything else from other companies, and runs no analytics. Everything the page loads comes from this domain. It sets no cookies of its own. Cloudflare may set a strictly necessary cookie to tell human visitors from automated ones, which is used for nothing else. That is why you are not asked to consent to anything here.

You can object to the processing described in this section. See section 11.

8. If you email me

If you write to support@geoblockr.com, your email address, your message, and any attachments are processed by IONOS SE, Montabaur, Germany, which operates the mailbox. I use them to answer you, which is my legitimate interest under Art. 6(1)(f) GDPR, or to fulfil a contract where your message concerns one. Writing to me is of course voluntary, but I cannot answer a message you do not send.

How long. I delete correspondence once the matter is settled, unless commercial or tax law requires me to keep it, which for business correspondence can be six or ten years.

You can object to the processing described in this section. See section 11.

9. No automated decisions

There is no automated decision making within the meaning of Art. 22 GDPR and no profiling. Nothing about you is scored, ranked, or sorted into categories, and no decision affecting you is made automatically.

10. Your rights

Under the GDPR you have the right to:

Write to support@geoblockr.com for any of these. I answer within one month, as Art. 12(3) GDPR requires.

Deleting your analytics data. Switching analytics off in the app stops any further collection, but it does not by itself remove what was already sent. To have that deleted as well, email me and say so. I will delete your profile and the events belonging to it. PostHog processes deletions in batches, so allow a few days for it to complete, and in any case no longer than one month.

Deleting your subscription record. Email me and I will have the record held by RevenueCat removed as well. One limit is worth knowing about: Apple keeps its own record of the purchase, as the seller, and I can neither reach nor delete it. For that you would have to go to Apple.

11. Your right to object

Where I rely on legitimate interest as the legal basis, which is the case for analytics outside the EU (section 3), for this website (section 7), and for answering your email (section 8), you have the right under Art. 21 GDPR to object at any time, on grounds relating to your particular situation.

For analytics, you can do this yourself under Settings in the app, and it takes effect immediately. For anything else, write to support@geoblockr.com. If you object, I will stop the processing unless I can show compelling legitimate grounds that override your interests.

12. Complaints

You can complain to a supervisory authority, in particular in the country where you live or work. The authority responsible for me is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.

13. Changes

If the app or the site starts processing data differently, I will update this page and change the date at the top.