← WELTEN home

Privacy notice

Last updated: 17 September 2026

This notice covers the WELTEN website, Mac app downloads and updates, beta and support correspondence, and checkout/licence processing when you use those services. WELTEN is currently in a free private beta; optional CommerceDev testing uses the Stripe sandbox. Live sales and monthly subscriptions have not started.

Who is responsible?

Anastasia Miller
Trading as WELTEN · Sole proprietor
Rümpeler Weg 29
23843 Bad Oldesloe
Germany

For privacy questions and requests, email hello@welten.app.

Website hosting

The public website is hosted using Cloudflare Workers Static Assets, provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Serving and protecting the website involves processing IP addresses and technical request data, such as the requested URL, time, browser information and referring page where transmitted.

The purpose is reliable delivery and protection against abuse. The legal basis is our legitimate interest in a secure, functioning website (Article 6(1)(f) GDPR). Technical data is retained only as necessary for delivery, security and incident investigation; applicable provider retention practices are described in Cloudflare’s privacy policy.

Cloudflare operates internationally, including in the USA. Its data processing terms describe safeguards for international transfers, including EU Standard Contractual Clauses where applicable. You can request information about these safeguards using our contact address.

Mac app downloads and updates

Download and update files are delivered through Cloudflare R2 at downloads.welten.app and the download routes on welten.app. Cloudflare receives the connection IP address and ordinary request information, including the requested file or update list, request time and browser or updater user agent. The purpose is to deliver the requested software, check update availability and protect the service against abuse. The legal basis is our legitimate interest in reliable, secure software delivery (Article 6(1)(f) GDPR). The Cloudflare provider, retention criteria and international-transfer safeguards described above also apply here.

In updater-enabled WELTEN releases, automatic update checks are off by default. You can independently choose “Notify me when an update is available” during setup, in the update invitation, or in Settings → Updates. This choice does not enable usage statistics. You can also check manually. Installation requires confirmation. Update requests do not include your focus history, projects, intentions, folder links, licence identifiers or a system profile. Download delivery does not give us access to your locally stored focus data.

Personal beta download links

When we send you a personal beta download link, we assign a random invitation code to your beta email address and the offered build. The address is not included in the URL or the app. Opening the invitation page alone is not counted. When the archive is served through its personal download button, we record daily counts of started full-file deliveries, partial requests and delivery errors for that invitation. We do not store IP addresses, browser identifiers, cookies or a request-by-request browsing history in this database. Repeated requests, forwarded links and automated scanners may count; these records do not prove a completed download, installation or use by a particular person.

We use this limited delivery record to manage beta invitations and help with download problems, based on our legitimate interest in operating and supporting the private beta (Article 6(1)(f) GDPR). The invitation page also offers the same approved app through a standard download without personal counting. You can object to personal delivery counting or ask us to revoke your link by contacting hello@welten.app. This does not affect your beta access.

Invitation records are stored in a separate Cloudflare D1 database restricted to the European Union, apart from anonymous app statistics. Links expire after at most 90 days; the daily cleanup deletes expired invitation records and their counts. Private operational exports are reviewed and deleted when no longer needed for delivery or support. Cloudflare’s connection processing and transfer safeguards described above also apply. Neither these links nor their records are joined to app usage events, focus history, projects or purchase data.

For delivery support, we receive internal Telegram summaries of new personal-link download counts. These include the beta email assigned to the link, its build, UTC day and a short invitation reference, so we can identify which invitation may need help. They contain no download URL or token, IP address or app usage data. Telegram therefore receives the assigned beta email and these delivery details; the Telegram processing information below also applies. This is a link assignment, not proof of who used it. You can use the standard download without personal counting instead.

Beta request form

When you request beta access, we store your email address, your confirmation that you have a compatible Mac, your optional broad use category, the submission time and the version of this notice. We use this information to handle your request and contact you about a beta place. Submitting a request does not subscribe you to a newsletter, create an account or provide an immediate download. We do not check your Mac automatically.

The form is processed by Cloudflare Workers and stored in a Cloudflare D1 database configured with the European Union jurisdiction restriction. This limits where the database runs and stores data; website request processing may still occur internationally as described above. Your connection IP address is used for a short request limit to prevent abuse; it is not stored in the beta-request database. The form does not collect your app sessions, projects or forest.

To help us handle your request, the Worker sends us an internal alert through the Telegram Bot API. The alert contains only a short reference to your entry: not your email address, not your use category, not the time you submitted. We read the request itself from our own database. We store the alert time, its reference and retry status alongside your request. Telegram operates outside the European Union; see Telegram's privacy policy for its processing and international operations. This alert goes to us. Invitations are sent separately after review.

The legal basis is Article 6(1)(b) GDPR for handling your request for beta access, and Article 6(1)(f) GDPR for protecting the form against abuse. An email address and compatibility confirmation are required to process the form; the use category is optional. You can also contact us by email.

We delete form entries automatically after 180 days, with a daily cleanup, or earlier when you withdraw your request or the entry is no longer needed. To withdraw or ask for deletion, email hello@welten.app. Deleted data may remain temporarily in the provider’s recovery backups until those expire. Correspondence is handled separately as described below.

Email, beta and purchase enquiries

Email links open your own email application. No message is sent simply by clicking a link. If you send an enquiry, we process your email address, message, any name or attachments you provide, and correspondence metadata to respond and handle your beta, purchase, cancellation or withdrawal enquiry.

Our mailbox uses Titan Email, purchased through Name.com. Titan processes email for delivery and storage. See Titan’s privacy policy for its processing and international operations.

The legal basis is Article 6(1)(b) GDPR for requests relating to a potential contract, or Article 6(1)(f) GDPR for our legitimate interest in answering other enquiries. Providing this information is voluntary, but we need a reply address to answer. A beta enquiry does not subscribe you to a marketing newsletter.

We retain correspondence while the enquiry or beta request is active, then delete it when no longer needed. Ordinary resolved support enquiries are reviewed for deletion within six months of closure. Contract-related business correspondence and evidence needed for a specific claim or legal obligation are retained separately as described below.

Checkout and transaction information

When you choose a purchase or sandbox test, the app opens Stripe-hosted Checkout using Stripe Managed Payments, identified as “Sold through Link”. Stripe/Link receives the information you enter, such as email, billing and payment details, as well as transaction and technical connection information. In the sandbox, use test payment details. We can access relevant order, contact, billing, payment-status and support information through Stripe to fulfil and support the request. The WELTEN app and licence database do not store your full card number or security code.

Stripe/Link also processes information for its own consumer services and legal obligations. It is not solely our processor for all these activities. Its responsible entities, processing, retention and international transfers are explained in Stripe’s privacy policy and Link’s privacy centre. A Link billing account is separate from WELTEN. Stripe-hosted pages may use cookies and similar technologies under their own notices.

We process necessary transaction and licence information to fulfil the contract or handle steps you request before it (Article 6(1)(b) GDPR). Specific legal record-keeping duties use Article 6(1)(c). Necessary abuse prevention and enforcement of the agreed personal activation limit use Article 6(1)(f), based on our interest in protecting the service. Payment and ownership information is necessary to verify paid access; optional installation names are voluntary. The free session does not require payment details.

Licence activation, recovery and checks

The licence service processes a random installation credential, a licence identifier, recovery-code verifier, purchase reference and status, activation identifiers, activation/deactivation dates and any installation name you choose. These support licence verification, restoration and management of two personal installations. The database stores hashed credential/recovery verifiers; they are pseudonymous data, not anonymous data. Credentials are transmitted over HTTPS when needed to authenticate a request. The Mac app keeps credentials and its verified offline proof in the macOS Keychain.

WELTEN does not automatically send your computer name or use a hardware fingerprint. It sends a licence reference to Stripe to associate the payment with the correct licence. It does not send focus sessions, projects, intentions, folder links or forest contents to the licence service. A recovery code is not required in ordinary support email and should not be included.

After activation, automatic online checks run on launch or foreground entry at most once per hour, and hourly during runtime. Pending purchases are checked more frequently; manual refresh is also available. A connection failure does not expire an activated one-time licence. A successful check can record a verified revocation or deactivation. Contact hello@welten.app for human review of an incorrect access result.

The service uses Cloudflare Workers and D1. The current sandbox database uses the EU jurisdiction restriction, while edge request processing may occur internationally. The Cloudflare provider and transfer safeguards above apply. Request processing exposes the connection IP address and ordinary HTTP information to the host. Short-lived IP-derived request-limit identifiers are separate from licence records and are removed when older than one hour by a ten-minute scheduled job; unsuccessful runs can delay cleanup.

Licence and financial record retention

We keep the minimal purchase, licence and recovery records while the licence remains valid and recoverable. A perpetual licence is not deleted solely because of inactivity. Deactivated-installation identifiers and state remain recognisable for as long as an old credential or signed proof can still be presented; a perpetual proof can require a long-lived minimal record.

The current sandbox retains licence, activation and event records for testing, recovery and reconciliation; it does not yet run the commercial cleanup schedule. For the sales launch, that schedule provides deletion of optional deactivated-device names and confirmed abandoned checkouts after 30 days, processed operational event details after 90 days, and necessary ended-subscription contract evidence normally three years after the end of the relevant calendar year. These are purpose-based WELTEN limits, not universal GDPR deadlines. The commercial schedule will be verified before paid processing starts.

Where German retention duties apply, accounting vouchers and invoices are normally kept for eight years, required business correspondence and other tax records for six years, and required books and financial statements for ten years, from the relevant calendar-year end. Longer retention is limited to a specific legal duty, proceeding or documented claim. These duties do not require us to retain all technical licence metadata for the same period. See Section 147 AO and Section 14b UStG.

Deletion requests are assessed individually. We explain any minimum data that must remain and why. A privacy request does not automatically forfeit a valid licence. Link account/order deletion is separate from WELTEN licence records and does not delete your locally stored forest. Deleted data can remain temporarily in provider recovery backups until they expire; provider-operated logs and backups follow the applicable settings and notices.

Cookies, media and analytics

The website code does not set cookies, use browser storage, or include advertising or visitor analytics scripts. Fonts, images and the demo video are served with the website. There is no embedded YouTube player. Ordinary hosting request processing still occurs as described above.

Your rights

Subject to the conditions in the GDPR, you can request access, correction, deletion, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. Where processing relies on consent, you may withdraw it for the future.

You may also complain to a supervisory authority, including the Independent Centre for Data Protection Schleswig-Holstein (ULD). We do not use your enquiry for automated decision-making or profiling.

Optional app usage statistics

In versions that offer this option, sharing usage statistics is off by default. You can choose it in the initial display setup, in a one-time invitation after an update, or in Settings → Privacy. Closing or declining the invitation leaves statistics off. Participation is optional and does not affect app features or beta benefits. The purpose is to understand whether people successfully begin using WELTEN and return to focus. We rely on your consent for this optional processing (Article 6(1)(a) GDPR).

After you opt in, the app can report three milestones once per local installation: joining the measurement, completing the first focus session that began after consent, and starting another focus session 24 hours to seven days after that completion. Reports contain the event type, app build, schema version, new/existing setup classification, UTC day and completion-cohort day. Each report has a random event identifier to prevent retry duplicates. There is no persistent installation identifier and reports are not linked to your email, licence or purchases. No project names, notes, session durations, focus history or world content are sent. Existing history is not reported retrospectively.

Reports are handled by Cloudflare Workers and a separate D1 database. Our measurement database and application logs do not store IP addresses or browser identifiers. Cloudflare still processes ordinary connection information as described under hosting above; the service is not an anonymous network transport. Event deduplication records are deleted after 14 days and daily aggregate counts after 12 months, subject to the provider’s backup expiry. Reports awaiting delivery on your Mac expire after seven days.

You can withdraw consent at any time in Settings → Privacy. This stops future reports, cancels pending delivery and removes unsent reports. A report already received may have contributed to an aggregate count that we cannot attribute to you and therefore cannot individually remove. Withdrawal does not affect processing before withdrawal.

We receive internal Telegram summaries of new anonymous milestone counts by build and UTC day. These contain no event identifiers, installation identifiers, invitation references or contact details, and are not joined to personal download records. Telegram’s processing and international operations are described in Telegram’s privacy policy. Delivery and retry bookkeeping in D1 is removed by a daily job once its event day is more than 14 days old; personal-link bookkeeping is also removed when its invitation is deleted. Telegram messages are separate operational copies, reviewed and removed when no longer needed.

Download counters

Measurement-enabled download routes distinguish public downloads from our internal tests. We keep aggregate daily counts of started full-file deliveries, partial requests and errors by build and route for up to 12 months. These aggregate counters use no cookies, per-person invitation identifier or app identifier. Personal beta links have the separate, limited delivery record explained above; it is never joined to app usage statistics. A delivery count does not prove completed installation or identify a unique person. Existing direct archive links and update requests remain separate technical delivery statistics. Cloudflare’s ordinary connection processing still applies.

New counts through the standard public download route can also appear in our internal Telegram summaries, with the event type, build and UTC day. Internal test downloads are excluded. Personal-link deliveries use their separate reference-based alert and do not create a second public-download alert.

The Mac app

Your focus sessions, projects and world are stored locally on your Mac. Visiting this website, testing Checkout or restoring a licence does not give us access to them. Licence operations are separate from local focus data and are not used for product analytics. Monthly billing is not yet offered; subscription-specific processing will be described here when its implementation is complete, before subscriptions become available.