Privacy Policy

1. Data controller

Matthias Walther
Sentruper Str. 202C, 48149 Münster, Germany
Email: info@elefantapp.io

2. General

ElefantApp is an access-restricted application for managing your own inventory (items, containers, photos, labels). It can only be used with an account created via an invitation; there is no public self-registration. You can visit this website without an account and without providing any personal data.

3. Data processed

Account data: Email address (as login name) and a cryptographically hashed password (bcrypt). The password is never stored in plain text.

Inventory data: The items you create, including names, descriptions, properties, categories, article numbers, photos, comments and activity history. This content belongs to your account and is only visible to others if you actively share it.

Voice recordings & transcripts: Audio recorded in Power Mode and the text transcripts generated from it. The audio file serves only to capture the respective item and is deleted automatically by the server once you have reviewed the created entry or permanently delete it; only the text content generated from it remains in your account.

Photos: Uploaded photos are processed on the server (including automatic cut-out of the depicted object). The original photo is kept for 7 days and then deleted automatically, unless you explicitly choose to keep it; the processed version remains stored.

Session: A technically necessary, signed session cookie (httpOnly) maintains your login status. It is used exclusively for login — no tracking, no analytics.

Local storage in the browser: For offline functionality the application stores data locally on your device (IndexedDB, localStorage, service worker cache), such as recordings not yet transferred and language settings. This data leaves your device only to be transferred to your own account.

Server log files: Technical data is generated on access (including IP address, timestamp, resource accessed), as is standard for web servers.

4. Purposes and legal bases

Account, inventory, photo and audio data is processed to provide the application's features, based on Art. 6(1)(b) GDPR (usage relationship). Log files and the session cookie are processed based on the legitimate interest in secure, functional operation (Art. 6(1)(f) GDPR).

5. AI processing on our own infrastructure

Transcription of voice recordings (Whisper), image analysis and object cut-out, as well as text processing by a language model, take place exclusively on our own infrastructure. No third-party AI or cloud services are used; your photos, recordings and texts are not transmitted to third parties.

The only exception: for article numbers you capture (e.g. ISBN or EAN), the server queries public product databases (Open Library, Open Food Facts) to add title and product information. Only the article number is transmitted — no personal data and no reference to your account.

6. Sharing and QR labels

Content is private by default. You can deliberately share individual items, containers or lists — with other users or via public links. Anyone in possession of such a link, or of a QR label you printed (with the access code encoded on it), can read the shared content even without an account. You can revoke share links at any time.

7. Storage period

Account and inventory data is stored for as long as the account exists, or until you delete it. Deleted entries first go to the bin, where they can be removed permanently. Voice recordings are removed automatically once the entry has been reviewed; original photos after 7 days (see above). Server log files are retained only briefly for security and operational purposes.

8. Encryption

Transmission is exclusively encrypted via HTTPS (TLS).

9. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Please contact the address given above.

10. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular the data protection authority of North Rhine-Westphalia, Germany (LDI NRW).

11. Changes

This policy will be updated accordingly if the application changes.