Privacy policy

This policy covers the website travstats.de, the TravStats Companion app and the two helper services this project runs, stats.travstats.de and push.travstats.de. The data on a self-hosted TravStats server is the responsibility of whoever runs that server, not of this project (see section 6). The German version of this policy is authoritative.

1. Controller

The controller within the meaning of the GDPR is:

Dennis Wittke
Gögging 18a
83083 Riedering
Germany
Email: [email protected]

2. Hosting and Cloudflare

The website and the statistics and push services run on the operator's own hardware in Germany (Linux containers in a private Proxmox environment). They are reached through a Cloudflare Tunnel; no external hosting provider is involved.

Cloudflare (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA) terminates the encrypted connection and in doing so processes your IP address and the request data, to forward the request and protect against attacks. A data processing agreement under Art. 28 GDPR is in place with Cloudflare.

Transfers to third countries: Cloudflare is a US company; a transfer to the USA cannot be ruled out. Cloudflare is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023). Transfers to the USA rely on that decision; where a processing operation is not covered by it, on the Standard Contractual Clauses in the data processing agreement (Art. 46(2)(c) GDPR).

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable provision).

3. Website server log files

The web server logs every request with date and time, requested address, HTTP status code, amount of data transferred, referrer (the page visited before), user agent (browser and operating system) and — only in the password-protected handbook (section 4) — the signed-in user name.

Your IP address is not stored. Because every request arrives through the Cloudflare Tunnel, the log only holds the tunnel's internal address. Only Cloudflare sees your IP address (section 2). The statistics and push services write no address to their logs at all.

The logs serve operation and troubleshooting only, are not combined with any other data, and are deleted automatically after at most 15 days.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).

4. Cookies, local storage and password protection

The website sets no cookies and embeds no analytics, tracking or advertising services. Fonts, scripts and the search (Pagefind) are served by this website itself; the search runs entirely in your browser.

Only when you explicitly choose a language with the language switch does the website store that choice in your browser's local storage (localStorage, entry travstats-lang), so you are not redirected to the other language on your next visit. The entry never leaves your device. It is necessary to provide the language you explicitly chose (Section 25(2) no. 2 TDDDG); you can delete it at any time in your browser's settings. Without your choice the website stores nothing.

The Companion app handbook (/docs/companion) is password-protected during the test phase (HTTP Basic Authentication). User name and password are sent encrypted (TLS) with every request; your browser remembers them for the current session, and the website stores nothing in your browser for this. The user name appears in the log files (section 3), the password does not. Legal basis: Art. 6(1)(f) GDPR (access protection during the test phase).

5. External links

The website links to external services, in particular GitHub and the project's Discord server. Only when you click such a link is the other site opened; from then on its privacy policy applies. The website makes no connections to third parties in the background.

6. Companion app

The TravStats Companion app is the mobile app for a self-hosted TravStats server. It connects to the server you pair it with and stores its data on your phone. What you record (trips, flights, places, photos, notes) goes only to that server. This project receives none of it; whoever runs the server is responsible for the data on it. When pairing, the app sends the server the device name, a random device identifier and the platform (iOS/Android), so you can recognise and sign out the device there.

The app contains no analytics, tracking or crash-reporting services and no advertising.

Retention: what the app keeps on the phone (cached travel data, offline maps, entries not yet sent, recorded flight paths) stays there until you unpair the app from the server or delete it. Unpairing deletes the account's data from the app; the offline maps (plain map areas without travel data) stay until you delete the app. You manage the data on your server yourself. Questions about the app go to the controller in section 1.

Maps (CARTO)

To show maps, the app loads the map style and map tiles directly from the map service CARTO (CartoDB Inc., 307 Fifth Avenue, Floor 9, New York, NY 10016, USA). CARTO receives your IP address, the map module's user agent, the time and the map areas requested. So that maps also work offline, the app additionally downloads map areas around your planned and past destinations automatically over Wi-Fi. Tile requests can reveal places and destinations; CARTO receives no names, travel dates or account data.

Under the CARTO terms, CARTO processes this request data as a processor, truncates the IP address on receipt and keeps the truncated logs for 30 days in the USA; transfers to the USA rely on Standard Contractual Clauses and, where CARTO is certified, on the EU-U.S. Data Privacy Framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working map that also works offline).

Permissions and device features

Camera (scanning boarding passes and documents), location (cockpit, "place now", optional flight recording), photos and — on iOS — Apple Health (importing selected workouts) are used only when you grant the permission. Processing happens on the phone; only what you save or explicitly transfer goes to your server. On Android, Google's barcode and document scanner module (ML Kit, part of Google Play services) recognises the images on the device; Google may receive technical usage data of the module, not the images.

App stores

For installation and updates through the App Store or TestFlight (Apple), Apple's privacy terms apply. This project only receives aggregated, non-personal statistics from there.

7. Push notifications (push.travstats.de)

A self-hosted TravStats server can send notifications (flight changes, departure reminders) to the Companion app. For this, the project runs the relay push.travstats.de, which passes the messages to Apple (Apple Push Notification service) or Google (Firebase Cloud Messaging) — the only way a message reaches a phone while the app is closed.

Only when both are switched on: technically, the relay is used only once the TravStats server's administrator switches the feature on in the server's settings (it is off by default). Your own data is processed only once you allow notifications in the app and switch on "Push from the server" — that is your consent; the administrator's switch does not replace it. Both can be switched off again at any time.

End-to-end encrypted: the content of every message is encrypted on the TravStats server for your phone alone. Only your phone holds the key to read it. push.travstats.de, Cloudflare, Apple and Google cannot read the content; all they see is a generic placeholder text ("News about your flight").

Processed:

  • per message, your phone's push token (issued by Apple or Google) and the encrypted content — forwarded, never stored;
  • when a TravStats server registers once, its IP address — kept as a hash in memory for at most 24 hours to limit abuse, never written to disk or logs.

Stored per TravStats server is only a random instance identifier, a hash of its access key, an optional label and a daily counter. No data about people, flights or devices is stored.

Recipients: Cloudflare (section 2) for transport; Apple Inc. (USA) or Google LLC (USA, Firebase Cloud Messaging) for delivery to your phone. Transfers to the USA rely on the safeguards Apple and Google provide (EU-U.S. Data Privacy Framework where certified, or Standard Contractual Clauses).

Legal basis: your consent by allowing notifications and switching them on in the app, Art. 6(1)(a) GDPR; for the brief abuse limiting, Art. 6(1)(f) GDPR. You can withdraw consent at any time in the app or in your phone's system settings.

8. Anonymous usage statistics from self-hosted installations (opt-in)

Anyone running TravStats themselves can voluntarily enrol their installation in anonymous usage statistics operated by this project at stats.travstats.de. The feature is off by default and must be switched on by an administrator of the installation. The exact content transmitted is documented verbatim in the usage statistics documentation.

Legal bases:

  • For the transmitted figures (version, enabled domains, coarse buckets, rounded distance totals, achievement summary, feature use, configured flight data providers, language): consent, Art. 6(1)(a) GDPR. Consent is obtained by the installation itself (not by this website) and can be withdrawn there at any time in the admin area. Withdrawal requests deletion of the stored record of that installation; if the statistics service is unreachable at that moment, the record is removed at the latest by the 180-day retention limit. From the withdrawal on, no further data is sent in any case.
  • For the requesting IP address, which is held only as a hash in memory for the duration of the single request for rate limiting (abuse protection) and then discarded, never stored: legitimate interest, Art. 6(1)(f) GDPR (protecting the service against overload and abuse).

Recipients: like this website, the service runs behind the Cloudflare Tunnel; section 2 applies.

Retention: an installation's record (identified by a random install_id, never derived from IP address, host name or paths) is deleted once that installation has not reported for 180 days. Withdrawal requests immediate deletion; if that request could not be carried out at once, the 180-day limit applies at the latest. The daily total of active installations used for the public growth chart is kept indefinitely but holds no installation identifier.

Your rights: since the figures can, in individual cases — especially single-user installations — describe a person, the rights in section 9 apply accordingly. For an access or deletion request please give the install_id (shown under Admin → Instance → Anonymous usage statistics); without it no record can be matched.

9. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw consent at any time with effect for the future (Art. 7(3)). An informal email to the address in section 1 is enough.

Right to object (Art. 21 GDPR): where data is processed on the basis of legitimate interests (Art. 6(1)(f) GDPR), you may object to this processing at any time. We then stop processing the data unless there are compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.

You also have the right to lodge a complaint with a supervisory authority. The authority competent for this controller is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

10. Encryption

The website and the services can only be reached over an encrypted connection (TLS, recognisable by https:// and the padlock icon).

11. Changes to this policy

This policy is updated when the processing changes or new legal requirements call for it. The current version is always available here.

Last updated: 1 October 2026.