Privacy Policy for the App
The PhotoNote iOS and Android apps do not track, collect, or transmit any personal data, usage data, or telemetry. All data you create in the app stays on your device. There are no analytics, no crash reporters, and no third-party SDKs that phone home.
The analytics and logging described below apply only to this website, not to the app.
Privacy Policy for this Website
1. Protection of Your Privacy
The protection of your privacy when processing personal data, as well as the security of all business data, is an important concern for us, which we take into account in our business processes. We process personal data collected during your visit to our online offerings confidentially and only in accordance with legal regulations.
When you use this website, various personal data are collected. Personal data are data with which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.
2. Responsible Party
The party responsible for processing your data is Mug of Coffee Software GmbH. Exceptions are explained in these privacy notices.
Our contact details are as follows:
Mug of Coffee Software GmbH
Corrensstraße 25
72076 Tübingen
Germany
Phone: +49-7071-9196966
3. Collection, Processing, and Use of Personal Data
Principles
Personal data are all information relating to an identified or identifiable natural person, such as names, addresses, phone numbers, or email addresses, which are an expression of a person's identity.
We collect, process, and use personal data (including IP addresses) only if there is a legal basis for doing so or if you have given us your consent, e.g., as part of a registration.
Legal Basis
We and the service providers we commission process your personal data to provide the website with our legitimate interest in providing information about our company, fulfilling our legal obligations in the area of data security, our legitimate interest in eliminating disruptions and ensuring the security of our offerings, and generally our legitimate interest in asserting and defending our rights.
Storage Duration
We store your data as long as it is necessary to provide our online offering and the associated services or as long as we have a legitimate interest in further storage. We then delete your data, except for data that we must continue to store to fulfill legal obligations.
Recipients of Personal Data
In the course of our business activities, we work with various external entities. In some cases, it is also necessary to transfer personal data to these external entities. We only pass on personal data to external entities if this is necessary for contract fulfillment, if we are legally obliged to do so (e.g., transfer of data to tax authorities), if we have a legitimate interest under Art. 6 para. 1 lit. f GDPR in the transfer, or if another legal basis permits the data transfer. When using processors, we only transfer personal data of our customers based on a valid processing contract. In the case of joint processing, a joint processing agreement is concluded.
Transfer to Recipients Outside the EEA
We may also transfer personal data to recipients located outside the European Economic Area (EEA) in so-called third countries. In this case, we ensure before the transfer that the recipient either has an adequate level of data protection or that your consent to the transfer is present.
Hosting and Data Collection through Server Log Files
Our hosting provider collects the following data in so-called log files, which your browser transmits: IP address, the address of the previously visited website (referrer request header), date and time of the request, time zone difference to Greenwich Mean Time, content of the request, HTTP status code, transferred data volume, website from which the request originates, and information about the browser and operating system.
This is necessary to display our website and ensure its stability and security. This corresponds to our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR.
We do not have direct access to GitHub's raw server log files.
We use the following hosting provider to provide our website:
GitHub Inc.
88 Colin P Kelly Jr St, San Francisco, CA 94107, United States
This provider is the recipient of your personal data. This corresponds to our legitimate interest in accordance with Art. 6 para. 1 sentence 1 lit. f GDPR, as we do not need to maintain our own server on our premises. The server location is the USA.
Further information on objection and removal options regarding GitHub can be found at: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
You have the right to object to the processing. Whether the objection is successful will be determined as part of a balancing of interests.
The data will be deleted as soon as the purpose of the processing ceases to apply.
The processing of the data specified in this section is neither legally nor contractually required. The functionality of the website cannot be guaranteed without the processing.
GitHub has implemented compliance measures for international data transfers. These apply to all global activities where GitHub processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs). Further information can be found at: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
Web Analytics (Umami)
We use Umami, a privacy-focused, open-source web analytics tool, to understand how this website is used in aggregate. We operate our own Umami instance — no analytics data is shared with Umami's authors or any third-party analytics vendor.
Umami is cookieless. It does not set cookies, does not use any other client-side storage, and does not assign you a persistent identifier. There is no cross-site or cross-device tracking. The visitor identifier used internally is a hash computed from your IP address, your user agent, and a daily-rotated salt; it cannot be reversed back to your IP, and it changes every day, so we cannot recognize a returning visitor across days.
For each page view we record: the page URL, the referring URL (if any), the country derived from your IP address (the IP itself is discarded immediately and never stored), the browser, the operating system, the device type, and the screen size. We do not record your IP address, and we do not record any personal identifiers.
In addition to page views, we record a small number of anonymous interaction events — for example, clicks on the download buttons that link to the App Store and Google Play. These events consist only of an event name (e.g. download-ios) and the same anonymized context recorded for page views. They contain no personal identifiers and no content you have entered.
The legal basis for this processing is our legitimate interest under Art. 6 para. 1 sentence 1 lit. f GDPR in understanding aggregate usage of our website in order to improve it. We consider the impact on your privacy to be minimal because the processing is cookieless, anonymized, and does not enable cross-site tracking.
You have the right to object to this processing at any time using the contact details below. You can also block analytics requests at the network level (e.g. via a browser extension) — the website remains fully functional.
Analytics Endpoint Hosting
Our Umami instance is reached through a reverse proxy operated by us on a server located in Germany. The reverse proxy writes standard access log entries which contain your IP address, the requested path, and the request date and time. These logs are accessible to us as the controller.
This processing is necessary to operate the endpoint, detect abuse, and debug operational issues. The legal basis is our legitimate interest under Art. 6 para. 1 sentence 1 lit. f GDPR. Access log entries rotate out on a 7-day rolling window. As the server is located in Germany, no third-country transfer takes place for this step. You have the right to object as described above.
Children
This online offering is not directed at children under the age of 16.
4. User Rights
Please use the contact details provided in the "Contact" section (see No. 4) to exercise your rights. Please ensure that we can clearly identify you.
Contact
If you wish to contact us, please reach out to:
Mug of Coffee Software GmbH
Corrensstraße 25
72076 Tübingen
Germany
or via email at: info@mugofcoffee.de
Last updated: June 13, 2026