Mr. Grummel Early access
← Back to class
LEGAL GDPR + revFADP

Privacy policy

This is a marketing site for an app. It collects almost nothing, and what little it does collect is listed here.

Last updated: 17 August 2026

1. Who is responsible

The controller for the data described here, within the meaning of Art. 4(7) GDPR, is:

Kevin Salzmann
Jasminweg 1
3930 Visp, Switzerland
Email: salkev@gmx.net

Full contact details are in the imprint.

We are based in Switzerland, so the Swiss Federal Act on Data Protection (revFADP) governs everything described here. We apply the GDPR's standards to everybody, wherever you happen to live, rather than sorting visitors by country and giving some of them fewer rights than others. Where the two regimes differ, we apply whichever gives you more.

If the GDPR does apply to you, note that Switzerland is recognised by the European Commission as providing an adequate level of data protection, so your data moving from the EU to us needs no additional transfer safeguard.

2. Visiting the site

The site is hosted by Vercel Inc. (USA). Like any web server, it writes a log entry for each request containing your IP address, the page requested, the time, the referring page and your browser's user agent string.

The legal basis is Art. 6(1)(f) GDPR: we have a legitimate interest in serving the site reliably and in noticing when someone is attacking it. These logs are written and held by Vercel as part of running the platform, and on our plan they are discarded automatically after a short period rather than archived. We do not export them, copy them anywhere, or use them to build a profile of you. If you want the exact retention window that applies on the day you ask, write to us and we will tell you what Vercel currently states.

3. Fonts, and what we deliberately don't do

The typefaces on this site are served from our own server. They are not loaded from Google Fonts, so visiting this site does not send your IP address to Google.

There is no CDN, no embedded video, no social widget, no advertising and no tracking pixel on any page. The single request your browser makes to anyone other than us is the analytics request described in section 8 — and that one carries no cookie and no identifier for you.

4. Cookies

This site sets no cookies and stores nothing in your browser's local storage. There is no cookie banner because there is nothing to consent to.

5. The waiting list

If you enter your email address to be told when the app ships, we store that address, the time you submitted it, and which form you used.

We use double opt-in: after you submit, we send one email containing a confirmation link. Until you click that link, your address sits in a pending state and receives nothing further. When you do click it, we additionally record the time of the click and the IP address it came from. That record exists for one reason — Art. 7(1) GDPR puts the burden on us to demonstrate that you actually consented — and it is not used for anything else.

The legal basis is your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time, with effect for the future, using the unsubscribe link in any email we send or by writing to the address in section 1. Withdrawing does not affect the lawfulness of anything sent beforehand.

If you never confirm, the pending entry is deleted after 90 days. Confirmed addresses are kept until you unsubscribe.

6. Topic requests

The request slip on the landing page asks for a subject you'd like to be quizzed on, and optionally an email address. The subject is stored so we can decide what to write next. The email address, if you leave one, is used only to reply about that request — it does not put you on the waiting list, and we won't mail you anything else without asking separately.

Legal basis: Art. 6(1)(f) GDPR for the suggestion itself, and Art. 6(1)(a) GDPR for the optional address.

7. Spam protection

Both forms carry a hidden field that a human never sees and never fills in. Submissions that fill it are discarded. We also limit how often the same source can submit, which requires counting recent submissions per visitor — for that we store a salted hash of the IP address, not the address itself, and delete those counters after 24 hours. Legal basis: Art. 6(1)(f) GDPR, our interest in not having our forms abused.

8. Analytics

We use Umami Cloud to count visits, so we can see which pages are worth writing more of. It is deliberately the least invasive analytics we could find:

  • It sets no cookies and writes nothing to your browser's storage.
  • It does not track you across other websites, and it builds no profile.
  • It does not store your IP address. Your IP is used in transit to derive a country and a non-reversible daily hash that lets Umami tell one visit from another, and is then discarded.
  • What we see is aggregate: page views, referrers, rough country, browser and screen size.

The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in knowing whether anything we publish is being read. Because no cookie or comparable device access is involved, no consent banner is required, and we do not show one. You can object to this processing at any time under Art. 21 GDPR by writing to the address in section 1; setting your browser's Do Not Track or using any ad blocker also stops it, and nothing on the site breaks if you do.

9. Who else sees your data

We use a small number of service providers, each acting as a processor under Art. 28 GDPR and permitted to use your data only to provide the service we engaged them for:

  • Hosting — Vercel Inc. (USA), serving the site and writing the server logs in section 2.
  • Database — Supabase, storing waiting-list entries and topic requests. Region: European Union.
  • Email delivery — Resend, sending the confirmation email and any later announcement.
  • Analytics — Umami Cloud, counting page views as described in section 8.

Your waiting-list entry sits in the European Union. Where a provider nonetheless processes data outside the EU/EEA — Vercel, in particular, is a US company — that transfer rests on the EU standard contractual clauses or on the EU–US Data Privacy Framework where the provider is certified under it. Each provider is engaged under a data processing agreement before any of your data reaches it.

We do not sell your data, and we do not share it with anyone outside this list. Nobody here is permitted to use it for their own purposes.

10. Your rights

Under the GDPR you have the right to:

  • access the data we hold about you (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • have your data erased (Art. 17)
  • restrict how we process it (Art. 18)
  • receive it in a portable format (Art. 20)
  • object to processing based on legitimate interest (Art. 21)
  • withdraw consent at any time (Art. 7(3))

Under the revFADP you additionally have the Swiss-law rights of access and of correction, which overlap with the above. Write to the address in section 1 and we will deal with it — free of charge, and normally within a month.

You also have the right to complain to a supervisory authority. Because we are established in Switzerland, ours is the Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, 3003 Bern. If you are in the EU, you may instead complain to the data protection authority of the country where you live, where you work, or where you think something went wrong — you do not have to come to the Swiss one.

11. Children

This site is meant for adults deciding how they use their own phone. It is not directed at children, we do not knowingly collect anything from a child under 13, and nothing here is designed to appeal to one. If you believe a child has given us an email address, write to us at the address in section 1 and we will delete it.

Our page for parents is about a parent managing their own habits — this app is not a covert monitoring tool for someone else's device, and we do not build one.

12. Changes

If what the site does changes, this page changes with it. The date at the top tells you when it was last touched.

Questions? salkev@gmx.net
Back to the app