Privacy Policy

Effective date: 2026-05-17 Last updated: 2026-08-29

1. Introduction and Scope

This Privacy Policy explains how Halora ("the App", "we", "us", "our") handles information when you use the Halora iOS application and when you visit our website. The controller within the meaning of Art. 4(7) GDPR is:

Lennox Kornmann
Am Pachtersgrund 14
98617 Meiningen
Germany
Email: halorasupport@gmail.com

We respect your privacy and have designed Halora to collect as little information as possible. The core of the App runs entirely on your device. The only personal data we ever process is what you choose to provide by optionally signing in, and what is needed to validate your one-time Halora Pro purchase.

This Privacy Policy covers two things: (a) your use of the Halora iOS App distributed via the Apple App Store, and (b) your visit to our website at https://halora-app.pages.dev. Sections 2 to 5 concern the App. Section 5a concerns the website and section 5b concerns our advertising. It does not apply to any other third-party service or website that may be linked from the App or the website.

We have not appointed a Data Protection Officer, as we are not required to do so under Art. 37 GDPR or § 38 BDSG.

2. Data We Collect (and Do Not Collect)

Data we do NOT collect

Halora has been built around the principle of data minimisation. We do not:

Data processed on your device only

The App processes the following information locally on your iPhone, without transmitting it anywhere:

Account data (only if you choose to sign in)

Signing in is completely optional and exists solely to sync your Halora Pro unlock and your settings across your devices. You can use the entire App as a guest without providing any of the data below. If you choose Sign in with Apple or Sign in with Google, we collect:

This account data is stored on our behalf by Supabase (our authentication and database provider; see section 5), which acts as our data processor and hosts the data in the European Union. You can delete your account and all associated data at any time from Settings → Account → Delete Account.

Data processed by Apple and our purchase processor

When you buy the optional one-time Halora Pro purchase, the following limited information is processed:

This information is processed by RevenueCat, Inc. as our data processor (see section 5).

For App Store privacy-label purposes, Halora declares "Purchases" as collected because RevenueCat processes purchase transaction data on our behalf to verify your Halora Pro entitlement. For guest users this is not linked to your real identity; for signed-in users it is associated with your account ID.

Apple itself processes payment information when you make a purchase. Halora never sees or stores your payment details. Please refer to Apple's Privacy Policy for details: https://www.apple.com/legal/privacy/

3. Data We Share

We share data only as strictly necessary to operate the App:

RecipientPurposeData SharedTheir Policy
Apple Inc.App distribution and In-App Purchase processingManaged by Apple under its own policyhttps://www.apple.com/legal/privacy/
RevenueCat, Inc.One-time purchase entitlement validationApp user ID, purchase transaction eventshttps://www.revenuecat.com/privacy
Supabase, Inc.Optional account sign-in and cross-device sync (EU-hosted)Name, email, account user ID, only if you sign inhttps://supabase.com/privacy
Cloudflare, Inc.Website only, hosting of halora-app.pages.devServer log data (IP address, time, page requested, browser)https://www.cloudflare.com/privacypolicy/
Meta Platforms Ireland Ltd.Website only, and only with your consent, advertising measurement (section 5b)IP address, browser/device data, page visitedhttps://www.facebook.com/privacy/policy/

No data from the App is shared with advertisers or data brokers, and we never sell personal information. The two website-only recipients above are listed for completeness: Cloudflare because it hosts the pages you are reading, and Meta only if you have actively consented to advertising measurement on the website (section 5b).

If you have explicitly enabled crash and analytics sharing in iOS Settings (Settings > Privacy & Security > Analytics & Improvements > Share With App Developers), Apple may share aggregated, anonymised crash reports with us. This is a setting you control entirely through iOS; Halora does not contain its own crash-reporting SDK.

4. Permissions We Request

Halora requests the minimum iOS permissions needed to function:

You may revoke either permission at any time in iOS Settings > Privacy & Security. Revoking camera access will disable the App's core functionality; revoking Photos access will prevent saving captured media.

5. Third-Party Services

Supabase (optional account sign-in)

If you choose to sign in, we use Supabase to authenticate you (Sign in with Apple / Google) and to store your account record so your Halora Pro unlock and settings sync across devices. Under the GDPR, Supabase acts as our data processor (Auftragsverarbeiter). Supabase stores your name, email address and account user ID, and hosts this data in the European Union. See https://supabase.com/privacy. You can delete this data at any time via Settings → Account → Delete Account.

RevenueCat (purchase validation)

We use RevenueCat to validate Apple In-App Purchase receipts and manage your Halora Pro entitlement. Under the GDPR, RevenueCat acts as our data processor (Auftragsverarbeiter) on the basis of a written data processing agreement.

RevenueCat receives only:

RevenueCat does not receive your name, email address, payment details, photos, or videos.

RevenueCat is based in the United States. See its privacy policy at https://www.revenuecat.com/privacy and its security and compliance information at https://www.revenuecat.com/security.

Apple In-App Purchase

All payments are processed by Apple. Halora never receives or stores your payment card or Apple ID credentials. See https://www.apple.com/legal/privacy/.

5a. Our Website (halora-app.pages.dev)

This section applies only when you visit our website. It does not describe the App.

Hosting and server logs

The website is a set of static pages hosted by Cloudflare, Inc. on Cloudflare Pages. When you open a page, your browser necessarily transmits technical information to Cloudflare's servers, which is processed to deliver the page and to keep the service secure and available:

We do not run our own web analytics on this data, we do not build visitor profiles from it, and we do not combine it with any App data. Cloudflare processes it as our data processor (Auftragsverarbeiter) under a data processing agreement and under the EU Standard Contractual Clauses. See https://www.cloudflare.com/privacypolicy/. The legal basis is our legitimate interest in operating a secure and functioning website (Art. 6(1)(f) GDPR).

Cookies and local storage

The website sets no cookies at all unless you have given consent for advertising measurement as described in section 5b. If you make a choice in the consent banner, that choice alone is stored in your browser's local storage (key halora-consent-v1) so that we do not ask you again. That entry stays in your browser, is never transmitted to us, and can be removed at any time by clearing your browser's site data.

No contact form, no newsletter

The website has no contact form, no comment function, no newsletter sign-up and no user accounts. If you email us at the address above, we process your message and your email address solely to answer you (Art. 6(1)(b) and (f) GDPR) and delete the correspondence once it is no longer needed and no retention obligation applies.

External links

Links to the App Store lead to Apple's servers. Once you follow such a link, Apple's own privacy policy applies; we receive no information about what you do there. See https://www.apple.com/legal/privacy/.

5b. Advertising and Measurement

We advertise Halora. This section explains exactly what that does and does not mean for your data.

The App itself contains no advertising or tracking technology

Advertising happens outside the App. The Halora App contains no advertising SDK, no attribution SDK and no analytics SDK (see section 2), shows no ads, and does not track you across other apps or websites. This remains true regardless of which advertising channels we use.

Advertising platforms (Meta, Apple)

We may run ads for Halora on platforms including Meta Platforms Ireland Ltd. (Facebook, Instagram) and Apple Search Ads. When we do, the platform itself decides which of its users are shown our ad and reports back only aggregated, statistical results, for example, how many people saw or clicked an ad. We do not receive, and do not ask for, any information that identifies you personally as a viewer of an ad.

The platform's own processing of your data as its user is governed by its own privacy policy and is outside our control: Meta at https://www.facebook.com/privacy/policy/ and Apple at https://www.apple.com/legal/privacy/. Apple Search Ads attribution operates through Apple's privacy-preserving framework and does not identify individual users to us.

Meta pixel on this website, only with your consent

To measure whether our ads actually work, we may use the Meta pixel on this website. If it is active, it is loaded only after you have explicitly agreed in the consent banner. Until you agree, and if you decline, or simply ignore the banner, no Meta script is loaded, no cookie is set and no data is transmitted to Meta.

If you do consent, the pixel transmits to Meta: your IP address, information about your browser and device, the page you are on, and the fact that you clicked through to the App Store. Meta uses this to report campaign performance to us and may link it to your Facebook or Instagram account if you have one. In this respect we and Meta act as joint controllers within the meaning of Art. 26 GDPR for the collection and transmission of the data; the joint-controller arrangement is available at https://www.facebook.com/legal/controller_addendum. Meta's onward processing is carried out by Meta on its own responsibility.

If no consent banner appears on this website, the pixel is not configured and nothing described in this subsection is taking place.

6. Children's Privacy

Halora is rated 4+ in the App Store. The App is suitable for general audiences and does not contain content directed at children.

We do not knowingly collect personal information from children under the age of 16 (or the applicable age in your jurisdiction). Because Halora can be used fully without an account, most users provide no personal data at all.

In-app purchases require either the user's Apple ID password or a parent's approval through Apple's Family Sharing and Ask to Buy features. Parents are encouraged to use Apple's parental control and Screen Time settings to manage in-app purchases on a child's device.

If you believe that a child has provided personal data to us, please contact halorasupport@gmail.com and we will take reasonable steps to delete it.

7. Your Rights

Under the EU General Data Protection Regulation (GDPR) and similar laws (including the UK GDPR, the Swiss FADP, Brazil's LGPD, and the California Consumer Privacy Act/CPRA), you have the following rights regarding your personal data:

If you signed in, you can exercise your right to erasure directly in the App via Settings → Account → Delete Account, which deletes your account and associated data from Supabase. You can also email halorasupport@gmail.com for any request, including resetting or deleting the purchase app user ID held by RevenueCat.

California residents (CCPA/CPRA)

If you are a California resident, you also have the right to:

To exercise any of these rights, contact halorasupport@gmail.com. We will respond within the timeframes required by applicable law.

Supervisory authority

EU/EEA residents have the right to lodge a complaint with their local data protection supervisory authority. The competent authority for the operator is:

Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI)
Häßlerstraße 8
99096 Erfurt, Germany
Telephone: +49 361 57 3112900
Email: poststelle@datenschutz.thueringen.de
Web: https://www.tlfdi.de

You may also lodge a complaint with the supervisory authority of your own place of residence or workplace.

8. International Data Transfers

Your optional account data is stored with Supabase in the European Union, so account sign-in does not, by itself, involve a transfer outside the EU/EEA.

RevenueCat, Inc. is established in the United States. When we transmit app user IDs and purchase transaction information to RevenueCat, this constitutes a transfer of data to a third country in the meaning of GDPR Articles 44 et seq. We rely on the following safeguards for this transfer:

For details, see RevenueCat's processing terms at https://www.revenuecat.com/dpa and its privacy notice at https://www.revenuecat.com/privacy.

Apple processes data globally under its own legal framework; see https://www.apple.com/legal/privacy/.

Website-side transfers

Cloudflare, Inc. (website hosting, section 5a) operates a global network, so server log data may be processed outside the EU/EEA. The transfer is covered by the European Commission's Standard Contractual Clauses in Cloudflare's data processing addendum, and Cloudflare is certified under the EU-U.S. Data Privacy Framework.

Meta (advertising measurement, section 5b), only if you have consented. Meta Platforms Ireland Ltd. is the EU-facing controller, but data may reach Meta Platforms, Inc. in the United States under the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses. If you do not consent, no such transfer takes place.

9. Retention

Website data

10. Security

We apply reasonable technical and organisational measures to protect any data we process:

No security measure can be guaranteed to be perfect; however, given how little personal data we process, the practical risk from a Halora-side breach is limited.

11. Legal Bases for Processing (GDPR)

Where the GDPR applies, our legal bases for processing are:

You may withdraw consent at any time with effect for the future: delete your account, revoke the relevant permission in iOS Settings, or, for the website, clear this site's data in your browser so the consent banner reappears and you can decline. Withdrawal does not affect the lawfulness of processing carried out beforehand.

12. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this document indicates when the policy was last revised. Material changes will be communicated within the App or by updating the policy at https://halora-app.pages.dev/privacy.

Continued use of the App or the website after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. Where we rely on your consent, we will ask for it again rather than relying on a policy update.

13. Contact

If you have any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please contact:

Lennox Kornmann
Email: halorasupport@gmail.com
Web: https://halora-app.pages.dev

We will respond to verifiable requests within the timeframes required by applicable law (typically within one month under GDPR).