Privacy Policy
Last updated: 25 July 2026
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
DigitalZen GmbH
St.-Cajetan-Str. 12
81669 München
Germany
For anything related to data protection, you can reach us at dataprivacy@digitalzen.digital.
Privacy at a Glance
This website is deliberately built to collect as little data as possible:
- We do not use tracking or analytics cookies.
- We do not show advertising and do not embed ad networks.
- We do not use third-party analytics services.
- Fonts are served from our own server; no data is transmitted to Google when fonts load.
- You see no cookie banner because nothing on this site would require one.
If we embedded third-party advertising, tracking or analytics services, data such as your IP address would be transmitted to third parties. We prefer not to. We also do not use automated decision-making, including profiling.
Individual features of this website process additional data — each one is described separately below.
Hosting and Server Log Files
This website is statically generated and externally hosted.
Our hosting provider is Cloudflare, Inc., USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR); in addition, EU standard contractual clauses (Art. 46 (2) (c) GDPR) are in place.
When you visit the website, the hosting provider automatically processes server log files: your device's IP address, the user agent (browser and operating system), the date and time of the request, and the page requested. The hosting provider processes this data on our behalf as our processor (Art. 28 GDPR). We have concluded a data processing agreement with the provider that ensures our visitors' personal data is processed only on our instructions and in compliance with the GDPR.
The purpose of this processing is the secure, fast and efficient delivery of our website and the defence against attacks and abuse (Art. 6 (1) (f) GDPR). The log files are stored only for as long as these purposes require and are then deleted. The data is not evaluated for marketing purposes in this context. All data is transmitted TLS-encrypted (HTTPS).
No Cookies
This website sets no cookies of its own. No third-party cookies are used either. That is why you see no cookie banner here.
Theme Preference (Dark Mode)
If you use the dark-mode toggle, your browser creates one localStorage entry that stores a single piece of information: whether the site should be displayed in light or dark mode. The entry is written only when you actively use the toggle, serves that one purpose only, and is never transmitted to us. You can view and delete it at any time in your browser settings. Storing this information and accessing information already stored are strictly necessary for the feature you explicitly request (§ 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG)); no further processing of personal data by us takes place.
Contacting Us by Email
If you contact us by email, we store your inquiry, including any personal data it contains, in order to handle your request. The legal basis is Art. 6 (1) (b) GDPR where your inquiry relates to a contract or to pre-contractual steps, and otherwise our legitimate interest in handling inquiries effectively (Art. 6 (1) (f) GDPR). We delete the data once the matter has been conclusively resolved; statutory retention obligations remain unaffected.
Privacy in the DreamJournal zzZ App
This section describes data processing in our DreamJournal zzZ app. Using the app does not change how this website processes data (described above).
Processing Happens on Your Device
The app's core features run entirely locally: your entries — voice recordings, transcripts and AI analyses — are processed and stored exclusively on your device. They never reach our servers, and we have no access to them. There is no account and no login — we do not know who you are. The app contains no analytics, tracking or telemetry services and shows no advertising.
Your entries can reveal special categories of personal data within the meaning of Art. 9 GDPR, for example information about your health, sex life or religious beliefs. That is precisely why this content never leaves your device: the on-device architecture is the safeguard. Because we never receive your entries, no processing by us as controller takes place — we neither claim nor need a legal basis for it.
iCloud Sync
You can optionally sync and back up your entries across your own Apple devices via iCloud. Sync runs entirely through your own iCloud account: the data is stored in the private, encrypted database of your Apple ID (CloudKit). Apple acts as your provider on your behalf, not as our processor. We have no access to this data and cannot read your entries; no transfer by us takes place. You can switch sync off at any time in the settings.
Distribution via the App Stores
You obtain the app through the Apple App Store. Apple processes your App Store account, purchase and payment data as an independent controller under Apple's own privacy policy.
We receive neither your name nor your payment details from the respective store.
Purchase and Subscription Management (RevenueCat)
To manage purchases and subscriptions, the app uses RevenueCat (RevenueCat, Inc., USA) as our processor. The data processed is a pseudonymous, randomly generated app-user ID and receipt data for the purchase — no names, no email addresses and no content from the app. The legal basis is Art. 6 (1) (b) GDPR (performance of the user agreement). We store the data for as long as it is required to manage your purchases, and beyond that only where statutory verification or retention obligations require it. Transfers to the USA are based on the EU standard contractual clauses (Art. 46 (2) (c) GDPR).
International Data Transfers
Where we transfer personal data to countries outside the EU or the European Economic Area, we do so only if the European Commission has issued an adequacy decision for that country (Art. 45 GDPR) or appropriate safeguards are in place, in particular the standard contractual clauses approved by the European Commission (Art. 46 (2) (c) GDPR). You can request a copy of the standard contractual clauses from us. Which mechanism applies to a specific service is stated in the relevant section of this Privacy Policy.
Storage Periods
Unless a more specific storage period is stated in this Privacy Policy, we store personal data only for as long as is necessary to achieve the purpose of the processing. If you make a justified request for erasure or withdraw your consent, we delete the data unless other legally permissible grounds for continued storage exist. Statutory retention obligations — in particular under the German Commercial Code (HGB) and the Fiscal Code (AO), generally six, eight or ten years — remain unaffected.
Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — receiving your data in a structured, commonly used and machine-readable format
- Withdrawal of consent (Art. 7 (3) GDPR) — at any time with effect for the future; the lawfulness of the processing carried out before withdrawal remains unaffected
A simple email to dataprivacy@digitalzen.digital is enough to exercise any of these rights.
Right to object (Art. 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data carried out on the basis of Art. 6 (1) (f) GDPR. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Where personal data is processed for direct marketing, you can object at any time without giving reasons.
We do not conduct direct marketing without your consent.
Under Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedy.
Changes to this Privacy Policy
We update this Privacy Policy when our services evolve or when legal or regulatory requirements change. The current version is always available on this page; the date at the top indicates the latest revision. On your next visit, the updated Privacy Policy applies.