Privacy policy
For the andon.app website, the configurator, the Andon app and the relay. As of October 2026.
At a glance
Andon has four parts: this website, the configurator in your browser, the app on iPhone and iPad, and the relay, which passes sealed envelopes between your data source and your devices. The content of your views is end-to-end encrypted. You generate the key for it yourself, and it never reaches us. We therefore cannot read your data.
We process only what operation requires. The website sets no cookies and uses no tracking, analytics or advertising.
Controller
The controller is SMARTR.solutions GmbH, Technologiezentrum Jülich, Karl-Heinz-Beckurts-Straße 13, 52428 Jülich, Germany. Phone: +49 2464 584868-0. Email: support@andon.app.
The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
Hosting
The website and the relay run at IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, on servers in Germany. IONOS processes the data on our behalf and on our instructions, under a data processing agreement.
This serves the performance of our contracts (Art. 6 (1) (b) GDPR) and our interest in secure, fast and reliable operation (Art. 6 (1) (f) GDPR).
Visiting the website
When you open the website, the host stores technically necessary information in server log files: IP address, date and time, the page requested, browser and operating system, and the page visited before. This serves secure operation and troubleshooting (Art. 6 (1) (f) GDPR). The log files are not combined with other data and are deleted after 8 weeks at the latest.
The website sets no cookies and loads nothing from third parties: fonts and scripts come from our own server.
Configurator
The configurator runs in your browser. The draft and the secrets live only in the memory of the open tab, not in browser storage, and are gone when you close it. You download the file with the secrets yourself; it goes to no one.
The configurator talks to the relay only when you trigger it: when you create a view, send a test or manage a view. Your browser transmits your IP address in the process. The configurator never transmits the content key.
Relay
For each view the relay stores the envelope sent last. Its content is encrypted and unreadable to us. All we can see is the view ID, the key version, whether devices should be woken, the size and the time. Of the write and invite secrets the relay stores only check values (hashes), not the secrets themselves.
For paired devices the relay stores the device ID, the time of pairing and the device name, encrypted with your content key and unreadable to us.
To prevent abuse, the relay limits the creation of new views and devices per IP address. Operational logs contain the IP address only in shortened form. We log security-relevant events (creating, pairing, revoking, renewing, deleting) with view and device IDs, without content and without secrets. For capacity planning and billing we keep usage statistics per view and subscription (number and volume of uploads, wake-ups and fetches).
The legal basis is the performance of the contract (Art. 6 (1) (b) GDPR) and our legitimate interest in secure operation (Art. 6 (1) (f) GDPR).
Retention at the relay
We delete a view with its envelope and pairings 30 days after its last upload, and a view with no upload and no paired device after just 10 days. You can delete a view yourself in the configurator at any time.
Devices that have not been in touch for 90 days are deleted with their pairings. Subscription data is deleted 13 months after the subscription expired, once no device uses it any more. The security log is deleted after 12 months. Usage statistics are condensed into monthly figures after 13 months.
App
On first pairing the app registers with the relay and receives a device ID and a device secret. The secret lives in your device's keychain; the relay stores only a check value. With it the app fetches the envelopes of its views and opens them on the device. It keeps the last state on the device, encrypted, so that it stays visible without a network.
So that widgets update on a status change, the app sends a push token to the relay. The relay uses it to send wake-ups through the Apple Push Notification service. A wake-up carries only the signal that there is something new, never content. Apple also processes data outside the EU, see Apple's privacy policy.
When you remove a view in the app, the relay deletes the pairing. When you delete the app, the device ID and device secret lapse; the relay deletes the device after 90 days without contact.
Subscription through the App Store
You buy and manage the subscription in the App Store. Payment data is processed by Apple alone; we do not receive it. To check whether a subscription is valid, the relay stores a one-way identifier of the transaction (a hash), the product and the expiry date (Art. 6 (1) (b) GDPR).
Contact by email or contact form
If you write to us by email or through the contact form, we store your details to handle your request and any follow-up questions. We do not pass these data on without your consent. The contact form sends first name, last name, email address and message to us through the Zapier service (Zapier Inc., 548 Market St. #62411, San Francisco, CA 94104-5401, USA). Data may be transferred to the USA in the process; Zapier is certified under the EU-US Data Privacy Framework.
The legal basis is Art. 6 (1) (b) GDPR where your request relates to a contract, otherwise our legitimate interest in handling requests (Art. 6 (1) (f) GDPR). The data stay with us until the purpose no longer applies or you ask for deletion, unless statutory retention periods apply.
Your rights
You have the right at any time to information about your stored personal data, its origin, recipients and the purpose of processing, as well as to rectification, erasure, restriction of processing and data portability. You can withdraw any consent you have given at any time with effect for the future.
Right to object (Art. 21 GDPR): where processing is based on Art. 6 (1) (e) or (f) GDPR, you can object at any time on grounds relating to your particular situation.
You also have the right to lodge a complaint with a data protection supervisory authority. For any questions, reach us at support@andon.app.
Encrypted connection
The website, configurator, app and relay communicate exclusively over encrypted HTTPS (TLS). The content of your views is additionally end-to-end encrypted.