Privacy
Kaze collects no data about you. There is no account, no sign-in, no analysis and nothing passed on. This page says what that means precisely — and what the three exceptions are: the emergency code, the contact form and the feedback route inside the app.
What stays on your iPhone
Your app selection, the times of your blocks and your settings live on your device and do not leave it.
The selection itself is not readable by Kaze: iOS hands over unreadable tokens, not names. Names and icons are drawn by iOS. So Kaze does not know which apps you blocked — and cannot tell anyone.
The emergency code is not stored on the device in plain text. Only a checksum with a random addition is kept, which is what your entry is matched against.
Exception one: the emergency code to your email address
When you want to end a block early, Kaze sends a code to the address you entered. That is one of three paths on which anything leaves your device — the other two are below.
What happens along it:
- The address is used for sending and is not stored anywhere in what we run — no log, no list.
- As with any connection on the internet, our interface sees your IP address in the process. It is not stored: the abuse protection remembers only counters, tied to a shortened fingerprint derived from it — no email addresses, no content. The counter deletes itself after a minute; the plain hourly totals behind it after a little over a day.
- The mailbox the mail is sent from is emptied unread every hour. Nothing there is counted or recorded.
- If you reply to the mail, your reply goes to a mailbox a person reads.
Exception two: the contact form
On the support page you can write to us. What you put into the form then goes to us: your name, your message, up to three attached files — and your email address if you want a reply. Nothing more: the form sends no device data, no identifier, no app version.
Your message arrives as an email in a mailbox a person reads (info@neckarshore.ai). A reply goes to the address you gave for it. We keep your message for as long as we need it to answer and follow up — and delete it at the latest six months after it arrived.
Attachments arrive exactly as you choose them — nothing is resized or altered. Keep in mind: a camera photo can carry the place and time it was taken in its metadata, and a screenshot shows whatever is on it. Send us only what you want us to see.
The spam protection: so that the form is not flooded by machines, a service by Cloudflare (Cloudflare, Inc., USA) checks that a human is at the screen. For this, your browser loads a script from Cloudflare when you open the support page; it processes technical characteristics of your browser and your IP address — by Cloudflare's own commitment without cookies and without cross-site tracking. The content of your message and your attachments never reaches Cloudflare.
Exception three: the feedback route inside the app
In the settings you can write to us from inside Kaze. Unlike the contact form, three technical details come along — deliberately: without them a reported bug often cannot be reproduced.
What comes along:
- Your text — what you write yourself, and only that. If you type your name, you send your name.
- The version of Kaze — so we know which build you have in front of you.
- The version of iOS — because the same bug behaves differently across iOS versions.
- Your iPhone's model designation, in the form "iPhone16,1" — the model, not your device. No device name, no identifier; two reports do not add up to the same person.
What is sent includes no account, no identifier and no number by which we could recognise you.
Your report leaves your device and goes to our own interface (relay.neckarshore.ai) — the same one the emergency code uses, and to nobody else. As with any connection on the internet, it sees your IP address in the process; it is not stored, and as with the emergency code the abuse protection remembers only a counter tied to a shortened fingerprint derived from it — it deletes itself after a minute. What happens to your report there is being rebuilt: until that is finished, it is not accepted.
This website
This site sets no cookies, loads no counting or analytics script into your browser. With one exception it also fetches nothing from third-party servers: on the support page your browser loads the contact form's spam protection from Cloudflare — what it does is explained with the form above. Beyond that there is nothing here to recognise you by — and you do not have to take our word for it: it is verifiable in the page as delivered.
Like any web server, the operator of this site processes technically necessary connection data in order to deliver it at all.
Who helps us
Four service providers work on our behalf and under our instructions — they may not do anything of their own with the data:
- Vercel (Vercel Inc., USA) serves this website, runs the service that sends the emergency code on its way, and receives the messages from the contact form and the reports from inside the app.
- Upstash (Upstash, Inc., USA) holds the counters of the abuse protection — the numbers described above, no addresses.
- Hostinger (HOSTINGER, UAB, Lithuania) carries the emergency-code mail and the messages from the contact form, and provides both mailboxes — the emergency-code sending mailbox, which is emptied hourly, and the mailbox your message arrives in.
- Cloudflare (Cloudflare, Inc., USA) checks, for the contact form's spam protection, that a human is writing — technical browser characteristics and your IP address, no content.
Vercel, Upstash and Cloudflare are based in the USA. For these transfers, the safeguards the EU provides are in place: Vercel and Cloudflare are certified under the EU-US Data Privacy Framework; for Upstash, the contractual safeguards provided by the EU Commission apply. You can obtain a copy of the safeguards via the address below.
Why we are allowed to do this
The law requires a reason for every processing. Ours are:
- The emergency code is sent, and your reply answered, because you ask for it (Art. 6(1)(b) GDPR).
- Your message through the contact form is received and answered because you ask us to (Art. 6(1)(b) GDPR).
- The abuse protection, the contact form's spam protection and the technically necessary connection data of this website keep the service working and safe — our legitimate interest (Art. 6(1)(f) GDPR).
The checkbox in the contact form is not a consent the processing depends on — we may process your message because you write to us. It makes sure you have seen this page before anything is on its way.
Your rights
You can find out at any time whether and which data about you exists (access, Art. 15 GDPR), have it corrected (Art. 16), deleted (Art. 17) or its processing restricted (Art. 18), and receive it in a portable format (Art. 20). Write to info@neckarshore.ai.
With Kaze, the answer will usually be: nothing is stored that could be linked to you. If so, we will tell you exactly that (Art. 11 GDPR).
Objection: You may object at any time, on grounds relating to your particular situation, to the processing based on our legitimate interest — the abuse protection, the spam protection and the connection data (Art. 21 GDPR).
If you believe we are handling your data wrongly, you can complain to a data protection supervisory authority (Art. 77 GDPR) — the one responsible for us is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.
Who is responsible
Responsible is German Rauhut, Rotebühlstraße 176, 70197 Stuttgart — full details in the Imprint.
Changes
If what is described here changes, this page changes with it. It describes the state, not a plan.