konfora apps
Your data

Privacy policy

Information about this website and the services available across Konfora apps.

Last updated: September 5, 2026

Which information applies to you? This website is a simple information page hosted on Vercel. The app service directory below applies only to features and providers used by the particular app you choose. It does not mean that every app sends data to every provider. The Dock Out and Yokai Road sections below provide information for those games and platforms. Other apps need their own specific processing details; the shared directory does not replace those details.

1. Who is responsible?

Fabio Blankenhorn · Konfora Apps
Heppstr. 17
72760 Reutlingen, Germany
Email: hallo@konfora.de

This notice covers this website and supplies general information for apps that refer to it. Products with a separate controller or their own privacy notice remain subject to that product-specific information. When contacting us about an app, please include its name and, if possible, its version.

ROWPOP — iPhone and iPad

ROWPOP has app-specific privacy information covering local gameplay, Apple purchases and Game Center, Google AdMob, Firebase Analytics, Crashlytics and Remote Config, your choices and your rights. Read the full notice in English or Deutsch. Contact ROWPOP Support for help.

Habinity — iPhone and Apple Watch privacy information

Habinity helps you build routines, record check-ins and reflect on your progress. This section describes Habinity 1.0 and the services actually used by this release. Read it together with the controller, website, international-transfer and rights information on this page. The other providers in the shared service directory are not automatically used by Habinity.

Your device, habits and journal

You can start without creating a Habinity account. Your identity statement, chosen areas, habit names and schedules, reminders, check-ins, streaks, achievements, preferences and onboarding draft are stored on your device. Optional mood records, journal entries, tags and voice memos are also stored locally. These records provide the features you select and let you resume your routines. Habinity does not operate a separate server that receives your private habit or journal database.

Saved journal edits and new voice recordings are encrypted by the app using AES-GCM, with keys stored in the Apple Keychain. Older local recordings are migrated to encrypted storage when they are synchronised or exported. Microphone access is requested when you choose to record a voice memo. Recordings are not sent to a transcription or cloud AI service. If a required encryption key is unavailable, an encrypted entry cannot be opened until the key becomes available; the app does not replace it with a plaintext cloud copy.

Apple Health and sensitive information

Apple Health is optional. With your permission, Habinity reads supported step count, sleep, mindful-session, water-intake and active-energy information on the device to recognise relevant habit check-ins. You can choose the permitted data types in Apple's permission interface and change access in the device's Health privacy settings. With a separate Apple Health write permission, Habinity can save the measured active intervals of a mindful focus-timer session as mindful minutes. An ordinary check-in without a measured session does not invent a health measurement.

The app separately asks for explicit consent before processing health-related mood and journal information or using its health features. You can withdraw this consent in the app's privacy settings and manage or delete existing records separately. Where health information is processed, the applicable consent condition is Article 9(2)(a) GDPR, alongside Article 6(1)(a). Giving permission to read Apple Health is separate from choosing any other sharing feature. Health information is not used for advertising, tracking or data brokerage.

Apple Health values, mood records and health-related habits are excluded from Habinity's personal iCloud projection and Family sharing. The exclusion covers habits linked to Apple Health and habits in fitness, mindfulness, sleep or nutrition areas, together with their check-ins. Mood associations and check-in notes are not uploaded through personal sync. Device backups and Apple's own Health or iCloud settings are separate platform features. See Apple's Health App privacy information.

Optional personal iCloud sync

Personal iCloud sync is off until you explicitly enable it. When enabled with an available Apple account, Habinity uses Apple's private CloudKit database to synchronise eligible general habits, including their names, schedules, icons, check-in dates and streak information. Your local identity profile, mood records and the health-related records described above are not included.

Journal entries remain local by default, including existing entries. You must additionally select the per-entry option to sync a general note. Notes with mood tags or links to health-related or unknown habits are excluded. This option is intended for general notes: do not include medical or other health information in notes you choose to sync. An eligible note's associated voice memo can be included.

Selected personal record contents and voice files are encrypted by Habinity with AES-GCM before upload. When you enable sync, the necessary keys can synchronise through Apple's iCloud Keychain so that your other devices can decrypt them. The same Apple account, available keys and platform configuration are needed for recovery. Apple still processes the technical account, connection and storage information needed to run iCloud. This personal encryption arrangement does not describe Family sharing.

Turning sync off stops new uploads and keeps your local data. It does not by itself erase copies already in iCloud. A change of Apple account pauses sync and requires a new choice for that account. Requested cloud deletions may need the original Apple account to be connected again before they can finish.

Apple Watch, widgets and reminders

The companion Apple Watch app exchanges habit information and check-ins with your paired iPhone using Apple's WatchConnectivity framework. This paired-device exchange is distinct from personal iCloud sync. Widgets and supported system actions use the app's shared on-device storage to show or update your routines. They do not send your journal or voice recordings to a Habinity server.

If you allow notifications, habit and trial reminders are scheduled on the device and can display relevant habit or subscription information. You control notification permission and previews in device settings. Apple's CloudKit notification service can also signal changes to enabled cloud records; Habinity does not use a separate marketing-push provider.

Family and shared routines

Family sharing is optional and asks participants to confirm that they are at least 16 and agree to the sharing disclosure. You can create or join one group with up to six participants through an Apple CloudKit share invitation. You explicitly select eligible general habits to share. Other participants can see your chosen display name, the selected habit's name and icon, streak and current-day check-in, and predefined emoji reactions. Do not include health or other sensitive information in shared names. Journals, voice memos, mood records and health-related habits are not shared with the group.

Family records are stored in Apple's CloudKit sharing service and are accessible to invited participants. They do not use Habinity's additional private-journal encryption. You can change the selected habits, leave the group or, as owner, delete it. Changes and removal requests are queued if the service is unavailable and are retried; already shared information can remain visible until Apple confirms the change. Copies independently made by another participant are outside the app's deletion controls.

Coaching, diagnostics and purchases

Coaching uses local templates or, on supported devices when available, Apple's on-device Foundation Models framework. The identity context and streak information used for a suggestion are processed on the device. Habinity does not send your journal, health records or coaching context to an external AI provider.

Habinity has no advertising, cross-app tracking or third-party behavioural analytics SDK. Optional MetricKit diagnostics, such as launch, memory and crash information, are handled locally by the app; this release has no telemetry upload endpoint. Apple's own platform diagnostics and sharing settings are separate. Contacting support or opening this website involves the correspondence and website processing described below.

Apple handles purchases, payment details and subscription billing. Habinity uses StoreKit to verify product and transaction identifiers, purchase dates, expiry, refunds and entitlement status so that it can unlock or restore Pro. Habinity does not receive your payment-card details and does not use RevenueCat or a separate purchase backend. You can manage or cancel subscriptions through your Apple account. Deleting local or cloud app data does not cancel a subscription. Apple's standard licensed application agreement applies to the app.

Retention, deletion and your rights

Local records remain until you delete them or remove app data, subject to your device's storage and backup controls. The app offers data export and deletion controls in its privacy settings. Deleting a journal entry also removes its local voice file and queues removal of any synchronised copy. Removing all Habinity data records cloud and sharing deletion requests before clearing local content. If offline, keep the app installed and reconnect the relevant Apple account so queued requests can finish. The app reports pending cloud deletion; encryption keys required for cleanup are retained until those deletions are acknowledged.

Removing the app alone does not necessarily erase iCloud records, device backups, Apple purchase records or copies you exported or shared. A file exported through the system share sheet goes to the destination you select, which has its own storage and privacy arrangements.

Providing the local app and requested purchase benefits is based on Article 6(1)(b) GDPR. Optional personal sync and Family sharing are based on your choices and consent under Article 6(1)(a); you can withdraw consent for future processing through their controls. Health-related consent is explained above. Necessary security processing can rely on Article 6(1)(f), and legally required records on Article 6(1)(c). This policy is information, not a consent request. Apple processes platform information under its own Privacy Policy; its services can involve processing outside the EU/EEA as explained in the general transfer section.

For support or privacy requests, contact Fabio Blankenhorn, Konfora Apps, at hallo@konfora.de and identify Habinity. Please send only information needed for your request. We may not hold a copy of information that exists only on your device or in your private Apple storage. The rights and supervisory-authority information below apply.

Larply — iOS privacy information

Larply creates AI images and videos from text, selected photos and templates. This section describes Larply 1.0 and identifies the services actually used by the app. The other services in this directory are not automatically part of Larply.

Accounts and authentication

Supabase provides Larply’s account service, database and file storage in Frankfurt, Germany. We process your account identifier, email address, optional display name, login records, credit balance and subscription status to provide your account and purchases. You can sign in with Apple, an email code, or an email address and password. Apple may provide a private relay email address if you choose Hide My Email. Credentials and session tokens are handled by Apple or Supabase; the app stores its session in the iOS Keychain.

Login and confirmation emails are sent using Resend in its EU region, from login@go.konfora.de. Resend processes the recipient address, message and delivery information. Open and click tracking are disabled for this sending domain. Login codes expire after ten minutes. Contact and support remain available at hallo@konfora.de.

Your prompts, photos and generated media

When you request a generation, Larply sends your prompt, chosen reference photos, selected settings and the required file links through its backend to fal, which runs the configured ByteDance Seedance and Seedream models. Larply shows a disclosure before your first generation. Only submit content you are entitled to use, including permission from people shown in reference photos. Cloud generation is optional; selecting a photo in the iOS photo picker does not give Larply access to your whole photo library.

Prompts, generation settings, job identifiers, status and credit usage are associated with your account so that jobs can resume and completed work can appear in your library. Uploads in Larply’s storage are scheduled for deletion after seven days. Generated result files are scheduled for deletion after thirty days; save anything you want to keep to Photos or Files before it expires. The cleanup job runs periodically, so deletion is not guaranteed at an exact minute. Account records and job metadata can remain until account deletion. Provider copies and technical logs follow the providers’ own retention rules.

Purchases

Apple handles the payment. Larply does not receive your payment-card details. Its backend verifies App Store transactions and processes product and transaction identifiers, dates, subscription expiry, refunds and an app-account identifier to deliver credits, restore purchases and prevent duplicate fulfilment. Subscription benefits and unused credit balances are separate: an expired subscription does not by itself erase unused paid credits.

A backend endpoint hosted by Vercel in Frankfurt verifies the digital signatures on Apple’s purchase notifications before Larply processes them. These signed notifications can contain the purchase identifiers, app-account identifier and subscription information described above. This endpoint does not receive your prompts, photos or generated media.

Storage on your device and sharing

Larply keeps app settings, your session, generation history and cached media on your device. Exporting to Photos or Files creates a copy under your device’s storage controls. Content you share through the system share sheet goes to the destination you select. Those exported or shared copies are not deleted by removing the Larply account.

Deletion and your choices

Use Profile → Delete account to delete your Larply account, stored uploads and results, generation records and credit records from the active service. For an Apple-linked account, the app may ask you to authenticate with Apple again so that the backend can revoke Apple’s authorization. Removing the app alone does not delete your cloud account. Account deletion does not cancel an Apple subscription: manage or cancel it in your Apple account’s subscription settings. Provider backups, operational logs and any records required by law follow their applicable retention periods.

Purposes, recipients and rights

Providing your account, requested generations and purchased benefits is based on Article 6(1)(b) GDPR. Necessary security and abuse prevention are based on Article 6(1)(f), and legally required recordkeeping on Article 6(1)(c). Where a separate consent is required for a particular operation, that consent is collected in context; this notice is not itself consent. Larply does not embed advertising, behavioral analytics or cross-app tracking SDKs.

See Supabase’s Privacy Policy, Resend’s Privacy Policy and Apple’s Privacy Policy. International processing may occur, including when media is generated by fal and its model infrastructure. EU hosting of the account database does not mean every operation stays within the EU. The sections on international transfers and your rights below also apply. Contact Fabio Blankenhorn, Konfora Apps, at hallo@konfora.de for requests concerning Larply.

Dock Out — iOS and Android privacy information

This section describes Dock Out version 1.0, currently being prepared for release. It supplements the shared information below about support, international transfers and your rights. Other providers listed on this page are not automatically used by Dock Out.

Progress, preferences and game features

Dock Out requires no game account. Level progress, earned coins, onboarding completion and music, sound, haptic and reduced-effect preferences are stored on your device. Local records support continued play and your chosen settings. This version has no game-operated cloud save, player chat, purchases or subscriptions. Game coins have no cash value.

Audio, graphics and the tutorial are included in the app. Playing does not send your inputs to an AI service. Haptic effects use the device's feedback capabilities. Dock Out does not request access to contacts, microphone, camera or precise location.

Advertising and your choices

Dock Out uses Google AdMob for optional rewarded videos and interstitial advertisements between levels. A rewarded offer identifies its benefit before you choose to watch it. Declining a rewarded offer does not stop ordinary play.

The advertising SDK may process IP addresses, approximate location derived from connection information, device identifiers, advertising views and interactions, and diagnostic or performance data. Purposes include ad delivery and measurement, advertising personalisation where permitted, and fraud prevention. Non-personalised ads can still involve personal data.

Google's User Messaging Platform (UMP) updates the advertising consent status at startup. The app requests advertisements only when the SDK permits it. Where required, a consent form presents the available purposes, providers and choices. You can reopen required advertising privacy options from Settings; changing them discards previously loaded advertisements before new requests. Choosing to watch an ad is separate from consenting to data processing.

Consent can be withdrawn for the future through the applicable privacy controls. Where consent is required, the relevant legal basis is Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. The consent message, not this policy, records your choices. Device and platform privacy settings may provide additional controls. See Google's Privacy Policy and Google's advertising information.

Analytics, support and retention

This release configuration does not initialise GameAnalytics or AppLovin MAX. Google advertising diagnostics remain part of the processing described above. Apple's and Google's platform diagnostics and store records are separate from the game's local save.

Local data remains subject to your device's storage and backup controls. Removing local app data does not erase records already held by advertising or platform providers; backups may retain separate copies. Provider retention depends on the relevant service and purpose. Contact us for information relevant to your request.

Opening support or privacy links involves the website processing described below. If you email hallo@konfora.de, include Dock Out and enough information to explain your request. Support does not automatically receive your saved progress. The controller, transfer information and rights described on this page apply to Dock Out; contact Fabio Blankenhorn, Konfora Apps, at the address above for privacy requests.

Yokai Road — privacy information

This section explains the data processing for version 1.0 of Yokai Road on iOS, which is currently being prepared for release. Read it together with the sections on website visits, contact, international transfers and your rights in the Konfora Apps privacy policy. The other providers in that website's service directory are not automatically used by Yokai Road.

Who is responsible

Fabio Blankenhorn, Konfora Apps, Heppstr. 17, 72760 Reutlingen, Germany. For privacy requests and support, contact hallo@konfora.de and identify Yokai Road. Do not send passwords or payment-card details.

Intended audience

Yokai Road is intended for players aged 13 and over. The content age rating displayed by your app store is separate and may differ by region and operating system. The game does not ask for an age or date of birth and has no separate age-selection screen. Advertising uses age-restricted treatment. Optional gameplay analytics is controlled through the shared Google privacy message.

Online progress, accounts and community features

Players receive a guest account through Google Firebase Authentication. The authoritative game progress is stored in Cloud Firestore and processed by Cloud Functions in Frankfurt, Germany. This includes equipment, heroes, currencies, progression, battles, rewards, pending decisions and the times required for daily or return rewards. The game retains a local cache and a journal of pending decisions so that an interrupted connection does not duplicate a reward or lose a confirmed decision. Music, sound and vibration preferences remain on the device.

You can optionally link an email address and password in Settings to recover the same account on another installation. Firebase Authentication processes the email and authentication credentials; passwords are not stored in the game's Firestore documents or sent to RevenueCat. A guest account that has not been linked may become inaccessible after local account data is removed. Signing into another account switches progress; it does not merge two accounts.

Clans, rivals, rankings and chat connect real players. Other players can see your generated game name, clan membership, contributions, ranking and the game statistics needed for those features. Chat sends only the game's predefined replies. You can block or unblock players and report messages. Reports include the reported message and the involved account identifiers and are available to authorised moderators, who can remove a message or restrict community features.

Google Firebase App Check and Apple's App Attest help verify that requests come from the game. Service requests and operational logs can include account or request identifiers, IP addresses and technical request information. These checks and the server's booking records help prevent unauthorised access, duplicate rewards and abuse. Providing accounts, progress and requested community features is based on Article 6(1)(b) GDPR; necessary service security and abuse prevention on Article 6(1)(f). See Firebase's privacy information. The general policy's international-transfer information also applies to provider processing outside Germany.

Test builds use a separate test economy and separate game accounts. Test purchases do not credit production progress.

Purchases and subscriptions

Apple handles App Store purchases and the payment details you supply to the store. Yokai Road uses RevenueCat to check purchases and subscriptions, restore access and determine which benefits are available. This processing can occur when the game checks your entitlements, including at startup, as well as when you purchase or restore.

Relevant data includes your Firebase game account identifier, product and transaction identifiers, purchase history, entitlement status and technical device information. The game uses the same account identifier with RevenueCat to assign and restore purchases. An optional account email is not sent to RevenueCat by the game. A generated account identifier can still distinguish a customer and is not a promise of anonymity.

The game keeps server-side booking records so that a transaction does not grant the same consumable twice. Providing the game and requested purchase benefits is based on Article 6(1)(b) GDPR; necessary fraud prevention on Article 6(1)(f), and legally required recordkeeping on Article 6(1)(c). RevenueCat also uses purchase information for purchase and subscription reporting in its dashboard. See RevenueCat's Privacy Policy and Apple's Privacy Policy.

You can manage or cancel an App Store subscription through your Apple account. Deleting the game or game account does not cancel a subscription. Game progress and store entitlements are different records; restoring a purchase does not by itself restore a deleted game account.

Optional rewarded advertising and privacy choices

Yokai Road uses Google AdMob directly for optional rewarded advertisements. The game tells you the offered benefit before you choose to watch a video. For server-side reward verification, the game sends its account identifier and a single-use reward request identifier to AdMob; Google sends a signed callback to the game server, which confirms and books the reward.

Google AdMob is configured with age-restricted treatment for teens and a maximum ad content rating of G. Google UMP presents the applicable privacy message before advertising is requested and provides access to privacy choices from Settings. The same message also covers Google Analytics storage. Advertising delivery can involve connection IP addresses, ad views and interactions, diagnostics, performance measurement and fraud prevention. Non-personalised advertising does not mean that no personal data is processed.

The game does not request Apple App Tracking Transparency permission or use advertising identifiers for cross-app tracking.

Where consent is required, the relevant processing is based on that consent and can be withdrawn for the future through the applicable privacy controls. The applicable consent message identifies the advertising purposes and participating providers before you make your choices. This page does not itself grant consent. See Google's advertising information and Google's Privacy Policy.

Notifications and reviews

If you allow notifications, Yokai Road schedules local reminders using the device's notification service. The game does not upload a server-push token for those reminders. You can manage notification permission through the device settings.

The game may offer Apple's native review interface. Apple handles submitted reviews through its platform. Opening that interface does not give the game your App Store account or a copy of your review.

Gameplay analytics

The new version uses Google Analytics for Firebase to understand game usage and improve gameplay. The Google privacy message provides the applicable choice for analytics storage together with advertising privacy choices; there is no separate analytics prompt or switch. Analytics collection starts disabled and is enabled only after Google reports an allowed analytics-storage choice or that consent mode does not apply. Missing, denied or unconfigured signals keep collection off. You can review or withdraw your choice through Settings → Privacy choices. In the EEA, the legal basis for optional analytics is consent under Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG.

Firebase Analytics can process app-instance identifiers, app and device information, sessions, approximate geographic information, automatically detected in-app purchase events and usage events, such as completed battles, equipment choices and claimed rewards. These identifiers are pseudonymous, not a guarantee of anonymity. The game does not supply Firebase account IDs, emails, chat text, passwords, receipts or command payloads to Analytics. It disables Analytics advertising storage, advertising user data and personalised-ad signals; the iOS Analytics integration omits IDFA support and disables IDFV collection. See Firebase privacy information and how Google uses information from partner apps. Analytics processing is separate from the Frankfurt game database and may involve international transfers described in this policy. PostHog is no longer an active integration.

Diagnostics, support and websites

Opening the privacy or support website involves the website processing explained in the general Konfora privacy policy. If you contact support, the information you choose to send is used to address your request. Support requests are handled separately from the game database; authorised operational access may be used when needed to investigate your account or request.

Retention, requests and your rights

Game profiles remain while the account is active. Chat history is removed after 30 days, reports and moderation audit records after 180 days, temporary rival caches after one day, and unneeded reward requests after two days. These periods are enforced by the next successful scheduled cleanup. Full command responses are removed or reduced after 30 days; a small replay marker can remain while needed to protect the current game revision. Minimal pseudonymous purchase-booking keys and account-deletion markers are retained to prevent old transactions or deleted accounts from being restored as new rewards. These records do not contain an email, raw account identifier or full receipt.

You can request account deletion in the game’s Settings. Linked accounts require the password again. The server immediately prevents further use of the account and then removes the profile, community records and other direct account references, requests deletion of the RevenueCat customer, and deletes the Firebase Authentication account. Failed cleanup attempts are retried. The app also stops Analytics and resets its local analytics data and app-instance identifier. This local reset does not itself erase data already transmitted to Google. References within other players’ historical command responses and operational logs can remain within their applicable retention periods. Purchase and subscription records that Apple must retain, and records independently processed by advertising providers, are subject to those providers’ arrangements and applicable legal requirements.

Turning Analytics off stops future collection on this device and resets local Analytics data. Google Analytics is configured to retain event and user data for two months, without resetting the retention period when a user returns. This setting does not apply to most aggregated standard reports. Earlier transmitted records remain subject to these settings and applicable erasure rights. The game does not set a Firebase account ID as an Analytics User-ID. Separate privacy requests can be sent to our contact address. Any records from earlier PostHog test builds remain covered by their original consent and can be addressed through support; removal of an integration is not evidence that historical provider records were erased.

Firestore point-in-time recovery retains versions for seven days; daily backups expire after 14 days. Deleted data can remain in those protected backups until expiry. Recovery procedures must reapply deletion records before a restored database is used. Local records and device backups remain subject to the device's storage controls. Deleting one record does not delete every provider's copy.

For a request about data processed for Yokai Road, contact hallo@konfora.de. Include enough information to identify the app and request. Additional information may be needed to locate a purchase-related record; do not send passwords or full payment details. If information exists only on your device, we may not hold a copy of it.

The general Konfora privacy policy explains the applicable rights of access, correction, erasure, restriction, portability, objection and withdrawal, and how to complain to the competent supervisory authority. For information about a particular provider record or retention arrangement, contact us and identify the app and request. The shared sections on this page explain international transfers and provider information.

2. This website and your enquiries

The landing page and its legal pages have no account registration, advertising, analytics, contact form or embedded third-party content. The website code sets no cookies and uses no browser storage. Fonts and visual assets are served with the website. Visiting this page does not load the app services listed below.

Vercel hosting

Vercel Inc. hosts this website. To deliver pages and protect the service, Vercel may process your IP address, requested URL, access time, browser information and response status. Our legal basis is Article 6(1)(f) GDPR: our legitimate interest in secure, reliable operation. Technical data is subject to the hosting service’s retention settings and security requirements; we do not use it to create visitor profiles.

Processing outside the EU/EEA is possible. See Vercel’s Privacy Notice and its Data Processing Addendum for processing and transfer arrangements.

Email enquiries

If you email us, we process your address, message, attachments and related correspondence to answer you. Contractual enquiries are handled under Article 6(1)(b) GDPR; other enquiries under Article 6(1)(f), based on our interest in responding to you. Correspondence is kept as needed to resolve the matter, subject to applicable retention duties. A mail link opens your own email application; no message is sent merely by viewing this website.

3. App hosting, storage and accounts

The following providers are relevant where an app offers the corresponding online features. Account services may process identifiers, email addresses, authentication information and sessions. Storage services may process the records and files you choose to save. Hosting providers also handle technical requests and security logs.

Vercel, Supabase, Hetzner and Cloudflare

Clerk

Products using Clerk use it to manage sign-in, accounts and sessions. Relevant data can include your email address, profile, user identifier, authentication factors and technical access data. See Clerk’s Data Processing Addendum. A third-party sign-in option additionally involves the identity provider you choose.

IONOS: domain registration

IONOS is used for domain registration in parts of our product portfolio. In this role, it handles domain-holder and administrative contact information. Domain registration alone does not make IONOS the host of an app or a recipient of its users’ app content. This landing page is hosted on Vercel. See IONOS’s Privacy Notice.

Required account and online functionality generally relates to contract performance under Article 6(1)(b) GDPR. Technical security and abuse prevention relate to Article 6(1)(f). The relevant app must identify its actual providers and purposes.

4. Apple services and local device features

You can manage the available permissions and Apple account features in your device settings. App purchase processing and requested online features generally concern Article 6(1)(b) GDPR; consent applies where required. Health data needs a separate applicable condition under Article 9 GDPR. See Apple’s Privacy Policy.

5. Google services

Google services have different functions. Using one of them does not automatically activate the others.

Firebase and Cloud Messaging

Firebase Cloud Messaging supports push notifications in compatible Android apps. Relevant information includes installation identifiers, registration tokens and message delivery data; a message payload may also contain information supplied by the app. Notification controls are available through the app or operating system.

Firebase Authentication, Firestore, Realtime Database, Crashlytics and Google Analytics for Firebase are separate products. Authentication concerns account and sign-in data; databases concern stored app records; Crashlytics concerns crash traces and technical identifiers; Analytics concerns usage events. These additional products are not declared active in every app by this notice. Their actual use, configuration and retention need to be stated for the relevant app. See Privacy and Security in Firebase.

AdMob and the User Messaging Platform (UMP)

Games with Google AdMob can display rewarded or interstitial advertising. Advertising services may process IP addresses, device and advertising identifiers, approximate location derived from connection data, ad interactions and diagnostics. UMP manages applicable advertising privacy choices. Non-personalised advertising can still involve personal data. See Google’s advertising information and UMP privacy controls.

Connected Google accounts and website analysis

Some web products offer an optional connection to your Google Analytics 4 or Search Console account. This can involve authorisation tokens, selected property/site identifiers and the reporting data you authorise us to read. It is distinct from embedding Google Analytics to track visitors to this landing page. Website analysis may also send a website URL to Google PageSpeed Insights. Disconnecting an integration or revoking access in your Google account stops its authorised access, subject to the product’s handling of previously saved results. See Google’s Privacy Policy.

Google Play may handle store distribution, purchases and review features on Android. Google Gemini is described under AI services below.

6. Payments and subscriptions

RevenueCat

Where used, RevenueCat verifies purchases and manages subscription entitlements. Data can include an app user identifier, transaction and product identifiers, purchase history, entitlement state and relevant device information. It may associate purchases across sessions or platforms according to the app’s account setup. See RevenueCat’s Privacy Policy.

Stripe

Products with Stripe checkout can process customer identifiers, billing details, transaction status, subscription information and invoices. Payment details entered into Stripe’s payment interface are processed by Stripe; our product can receive the results needed to manage your purchase. Stripe also processes data for its own payment, fraud-prevention and legal obligations. See Stripe’s Privacy Policy.

The relevant purposes are fulfilling a purchase or subscription under Article 6(1)(b) GDPR, required recordkeeping under Article 6(1)(c), and necessary fraud prevention under Article 6(1)(f). Store transactions may instead be handled by Apple or Google.

7. Advertising, game platforms and analytics

AppLovin MAX

Games with AppLovin MAX use it to request and display advertisements and manage mediation. Relevant data can include device/advertising identifiers, IP addresses, approximate location, ad interactions and technical diagnostics. Additional advertising partners depend on the game’s actual mediation configuration and privacy choices. See AppLovin’s Privacy Policy.

GameAnalytics and Vercel Web Analytics

GameAnalytics integrations can report sessions, game progression, gameplay events and advertising events alongside device and technical identifiers. See GameAnalytics’s data processing information. Products using Vercel Web Analytics can measure page views and configured events; see Vercel’s analytics privacy information. Neither service is embedded in this landing page.

CrazyGames

Games played through CrazyGames may interact with its platform for game-session events, advertisements, player accounts and saved progress. The available integration depends on the game and its launch mode. CrazyGames has its own responsibilities for the platform and its account, advertising and storage features. See CrazyGames’s Privacy Policy.

Your choices: where advertising, analytics or device access requires consent, the legal basis is Article 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG. This policy is not itself consent. Use the relevant app’s privacy controls and your device’s tracking settings to manage your choices. Apple’s tracking permission and an advertising consent choice serve different requirements. Refusing personalised advertising does not necessarily prevent all technical processing.

8. Email, calls and service monitoring

Requested communications generally concern Article 6(1)(b) GDPR; service availability and security concern Article 6(1)(f). Marketing requires its own applicable basis and is not authorised merely by using an app or reading this notice.

9. AI, connected platforms and mapping

AI providers

Where an app offers a cloud AI feature, it can transmit the text, image, document or other context selected for that feature, together with instructions and technical request information, to its configured provider. A desktop assistant’s selected context can include text from another application. Local templates and on-device features do not by themselves send data to a cloud AI provider.

Provider options found across our products include OpenAI, Anthropic, Google Gemini, xAI, Amazon Bedrock and fal for image generation. Only the provider used for a request receives that request through the relevant integration. Some apps allow a user-selected provider or custom gateway.

Requested AI processing generally concerns Article 6(1)(b) GDPR; separate consent may be required depending on the data and feature. Retention, model-training rules, regions and transfer safeguards depend on the provider, service tier and account configuration. We do not make a universal zero-retention or no-training promise for all integrations. Avoid including unrelated personal information in your request.

Connected platforms

Optional integrations can involve GitHub repositories and proposed changes, WordPress content and media, or X profile and publishing data. The connected service receives the authorised content and identifiers needed for the requested action. Public research features can retrieve Reddit posts and other publicly available website content, which may include usernames or author information. Your own WordPress host or a custom gateway is a provider you select, rather than a single provider shared by all users.

Geoapify

Products offering address geocoding can submit an address to Geoapify to obtain map coordinates. This is distinct from continuously tracking a device’s location. See Geoapify’s Privacy Policy.

10. Retention, transfers and security

Retention depends on the purpose and the app: local records remain under the device’s storage and deletion controls; cloud records and account information depend on the active account, deletion request and applicable backup lifecycle; authorisation tokens are relevant while a connection is maintained; transaction records may be subject to statutory retention. Technical logs and diagnostic records have provider- and configuration-specific retention periods. Deleting an app does not automatically delete cloud accounts, store purchases or copies shared with another person.

Some listed providers operate internationally, including outside the EU/EEA. EU hosting does not by itself exclude overseas support access or other transfers. Where required, transfers need an applicable adequacy decision or safeguards such as EU standard contractual clauses. The mechanism must match the actual recipient and service. The provider links above explain their published arrangements; they do not establish that every optional integration has already been activated or that every possible agreement has been concluded. Contact us for the arrangements relevant to your app.

This website uses HTTPS and serves its own assets. Security controls for an app depend on that app’s implementation. Provider names alone do not establish encryption, data residency or end-to-end encryption for every feature.

11. Your rights and choices

Subject to the legal conditions, you may request access, correction, erasure, restriction or portability of your personal data. You can withdraw consent with effect for the future. You can object to processing based on legitimate interests for reasons relating to your situation, and to direct marketing at any time.

Contact hallo@konfora.de and identify the app and request. Do not send passwords or payment-card details. If data is stored only on your device, we may have no copy to retrieve; the app’s local controls remain relevant. Removing access to a connected account and requesting deletion of previously stored data are separate actions.

You may complain to a supervisory authority, including the State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg. The GDPR and Section 25 TDDDG explain the applicable statutory rules.

12. Updates and app-specific information

We update this page when relevant information changes. A complete notice for an individual app must identify its actual data flows, enabled providers, purposes, legal bases, retention and deletion rules, international transfers and any special requirements for children or sensitive data. This directory provides shared information; it does not state that those app-specific checks are complete.