Privacy
Last updated: 1 October 2026
1. Controller
The controller within the meaning of Art. 4(7) GDPR for the app Unloop and this website is:
- Provider
- Marvin Kicha
- Address
- Hueskenboerde 34
45136 Essen
Germany - hello@deckle.io
No data protection officer has been appointed, and none is required: fewer than twenty people are permanently engaged in automated processing (§ 38(1) German Federal Data Protection Act), and there is neither large-scale regular monitoring nor large-scale processing of special categories of data (Art. 37(1) GDPR). The German version of this policy is authoritative.
2. The app in short
Unloop has no account and no tracking. Everything the app knows about your use lives on your iPhone. It is never sent to us or anyone else, and we cannot see it. The only thing that ever leaves the app is feedback you choose to send us (see section 8).
3. What stays on your device
The app stores the following only locally on your iPhone (in storage shared by the app and its extensions):
- your shields: the apps and categories you chose (as anonymous tokens issued by Apple, see section 4), schedules and unlock rules
- your daily budget, focus sessions, active unlocks and your streak
- what you enter during a mindful unlock: the reason you pick and, if you type one, your intention
- settings such as reminders and widgets
In legal terms this is storing information on your device under § 25 of the German Telecommunications Digital Services Data Protection Act. No consent is needed because the storage is strictly necessary to provide the function you asked for (§ 25(2) no. 2). No processing by us takes place, because this data never reaches us. Deleting the app removes all of it.
4. Screen Time
Shields, focus and insights are built on Apple's Screen Time frameworks (Family Controls, Managed Settings, Device Activity). You grant the permission in iOS and can withdraw it there at any time (Settings → Screen Time).
Unloop cannot see which apps you use. Instead of app names, Apple gives the app anonymous tokens it can put shields around. Your usage numbers are drawn by iOS inside a sealed-off extension that cannot send data anywhere. This processing happens in iOS, on your device.
5. Notifications, widgets and Live Activities
Reminders and the end of an unlock or focus session are delivered as local notifications that iOS schedules on your device. Widgets and Live Activities are also updated on the device. There are no push notifications from a server.
6. Purchases and subscriptions
Unloop+ is handled entirely through the App Store. Purchase, payment, renewal and cancellation run through Apple. We receive no payment details, no address and no Apple Account; the app only learns whether a valid entitlement exists on this device. Apple is independently responsible for processing within the App Store: apple.com/legal/privacy.
7. Crash reports via Apple
If you have turned on “Share with App Developers” in iOS, Apple provides us with aggregated usage statistics and crash reports through App Store Connect. They contain nothing that would let us identify you. The setting is under Settings → Privacy & Security → Analytics & Improvements.
8. Feedback from the app and contacting us by email
Under Settings → Feedback you can send us a message from the app. It is transmitted over an encrypted connection to our server (gentle.deckle.io, shared with our app Gentle) and forwarded to us by email. It contains your message, the category and areas you picked, the email address you entered (optional), the app version and build, and your device language. No Screen Time data, no app names and no device identifiers are included. To prevent abuse, the server briefly uses your IP address to limit how many messages can be sent in a short time; it is not stored with the message.
If you email us, we process your address and your message in order to reply. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is answering enquiries. We delete the correspondence once the matter is settled, at the latest after 12 months, unless a statutory retention duty applies.
9. This website
The website is hosted by Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Deutschland. When you visit, the server processes the usual access data (IP address, time, page requested, amount of data, referrer, user agent) in server logs. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest is secure and reliable operation. The logs are kept only as long as needed for that and are then deleted automatically.
Hetzner Online GmbH acts as our processor under Art. 28 GDPR; a data processing agreement is in place. The servers are in Germany; no data is transferred to a third country.
- This website sets no cookies and uses no local storage. The server picks the language once from your browser's language setting; nothing is stored.
- There is no analytics or audience measurement.
- Fonts are served from our own server. There is no connection to Google Fonts or any other third party.
- No maps, videos, social media widgets or other third-party content are embedded.
10. What doesn't happen
- no advertising and no advertising identifiers
- no tracking, no analytics tools, no third-party SDKs
- no automated decision-making or profiling (Art. 22 GDPR)
- no selling or sharing of data
- no access to contacts, photos, location, microphone or camera
11. How long data is kept
Data in the app stays on your device until you change it in the app or delete the app. Website logs are deleted automatically once they are no longer needed for secure operation (section 9). Emails follow the period in section 8.
12. Your rights
You have the following rights towards us:
- access to the data processed about you (Art. 15 GDPR)
- rectification of inaccurate data (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
Because we keep no accounts and cannot identify you, we are usually unable to attribute any particular processing to you (Art. 11 GDPR). You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
- Authority
- Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
- Address
- Kavalleriestraße 2–4
40213 Düsseldorf, Germany - Website
- ldi.nrw.de
You can also contact the supervisory authority where you live or work.
13. Changes
We update this policy when the app, the website or the law changes. The version published here applies; the date at the top shows when it was last changed.