Legal
Privacy policy
Version: 27 September 2026
This is a translation provided for convenience. Only the German version is legally binding: read the German version
1. Controller
The controller for the processing of personal data on this website (apksee.io), in the customer account and in the license management of the ApkSee software is:
BuonaLabs UG (haftungsbeschränkt)Maria-Goeppert-Straße 3, 23562 Lübeck, Germany
Managing director: Domingo Buonamassa
Email: [email protected] · Phone: +49 (0) 451 406-07833
For data protection requests please write to [email protected] with the subject “Privacy”. No data protection officer has been appointed because the statutory requirements (§ 38 BDSG) are not met.
2. The essentials
- We use no analytics, tracking or advertising tools, no social media plugins and no embedded third-party content. Fonts are served from our own server.
- The ApkSee software analyses apps locally on your computer. Apps, analysis results, screen contents and network captures are not transmitted to us.
- We only process the data required to operate the website and the customer account and to handle orders, invoicing, license checks and support.
3. Hosting and server log files
The website, the customer account and the license server run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Deutschland, in data centres in Germany. A data processing agreement pursuant to Art. 28 GDPR is in place with this provider.
On every request our server processes technically necessary data: IP address, date and time, the address requested, the HTTP status code, the volume of data transferred, the referrer and the browser identifier (user agent). This data is required to deliver the website, defend against attacks and fix errors. To prevent abuse (e.g. automated sign-in attempts) the IP address is additionally held briefly in memory for rate limiting.
The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in secure and stable operation. Server log files are deleted after 7 days at the latest, unless they are needed for longer to investigate a specific security incident.
4. Cookies, local storage and language selection
On the public pages we set no cookies and store nothing in your browser.
This website is delivered in three language versions: English at /, German at /de/ and Italian at /it/. Which language you see follows solely from the address you request. The language switch consists of plain links between /, /de/ and /it/; it sets no cookie and stores nothing in your browser (in particular no localStorage entry). We use no tracking, no analysis of your behaviour and no profiling to select or suggest a language, and we do not store the Accept-Language header sent by your browser.
When you sign in to the customer account we set a session cookie and a cookie to protect against cross-site request forgery. Both are strictly necessary for signing in, contain only random identifiers and become invalid when you sign out or when the session expires (after 30 days at the most).
On the checkout page the payment form is loaded from Stripe (Stripe.js). In doing so Stripe sets its own strictly necessary cookies or identifiers for fraud prevention and secure payment processing. Stripe.js is loaded only on the checkout page.
The legal basis for these strictly necessary storage operations is § 25(2) no. 2 TDDDG; the subsequent processing takes place under Art. 6(1)(b) and (f) GDPR. No consent is required for this, which is why we do not use a cookie banner.
5. Contacting us
If you write to us through the contact form or by email, we process your name, your email address, your company where given, the topic you selected and the content of your message in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry concerns a contract or its preparation, and otherwise Art. 6(1)(f) GDPR (legitimate interest in replying). The data is deleted once the enquiry has been dealt with conclusively and no statutory retention obligations apply, at the latest after 2 years.
6. macOS waitlist
If you join the waitlist for the macOS version, we store your email address in order to inform you once about its availability. Sign-up uses the double opt-in procedure: your address is only added after you click the confirmation link in our email. As proof of consent we store the time of sign-up and of confirmation. Unconfirmed entries are deleted after 7 days.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time via the link in every email or by writing to [email protected]. After the availability email has been sent, or after withdrawal, your address is deleted; we keep the proof of consent for up to 3 years in order to be able to demonstrate that consent was obtained properly (Art. 6(1)(c) and (f) GDPR in conjunction with Art. 7(1) GDPR).
7. Customer account and sign-in
To purchase a paid plan and manage your licenses you need a customer account. In this context we process: email address, name, optionally company and VAT identification number, your password exclusively as a cryptographic hash (Argon2id), optionally the secret for two-factor sign-in (TOTP), sign-in times and, for security reasons, the IP address and browser identifier of active sessions.
You may alternatively sign in via a third-party provider (“Sign in with Google / GitHub / Apple”). Your browser then takes you to the respective provider; from that provider we receive only your email address, your name and an identifier of your account there. The provider’s own privacy notices apply to its processing: Google Ireland Limited (Ireland), GitHub, Inc. (USA), Apple Distribution International Ltd. (Ireland). These providers are only contacted if you click the relevant button.
The legal basis is Art. 6(1)(b) GDPR (contract and user relationship) and, for security data, Art. 6(1)(f) GDPR. You can have your account deleted at any time in the account settings or by email; invoice data that must be retained by law is not affected (see section 13).
8. Orders, payment and invoices
We handle payments, subscriptions, tax calculation and invoices through Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland (“Stripe”). The following are processed: name, email, billing address, company and VAT ID where given, the plan selected, the number of seats, amounts, means of payment and payment status. Your complete card or account details are entered with and stored by Stripe directly; they do not reach our servers. To determine the applicable VAT rate, Stripe evaluates your country and, where applicable, your VAT ID (Stripe Tax). Stripe carries out an automated risk assessment of the payment for fraud prevention; if a payment has been declined as a result, you can contact us and request a review by a human being.
We also record in the customer account when and in which version you accepted our terms and conditions and whether, in consumer contracts, you consented to immediate provision and confirmed that you acknowledge the loss of the right of withdrawal (proof pursuant to § 356(5) BGB).
The legal bases are Art. 6(1)(b) GDPR (performance of the contract), Art. 6(1)(c) GDPR (obligations under tax and commercial law) and Art. 6(1)(f) GDPR (fraud prevention). Stripe is itself a controller for parts of the processing (among other things fraud prevention and compliance with its own regulatory obligations); details: stripe.com/privacy.
9. License management and license checks
After purchase we generate a license key for every seat booked, display it in your account and send it to you by email. For activation and regular checks the software transmits to our license server: the license key or license ID, a hashed device identifier (a SHA-256 value from which the underlying device attributes cannot be reconstructed), a random number to protect against replay attacks and, technically, the IP address. While the software is running the license is renewed at short intervals; if the connection is lost the software continues to work for a short grace period.
Per license we store: plan, seat identifier, status, term, bound device identifier and time of activation. The purpose is performance of the contract (making the product available only to entitled users, binding a seat to a device) and protection against unauthorised use and passing on of keys. Legal bases: Art. 6(1)(b) and (f) GDPR.
The free plan can be used without a customer account and without a license check. Licenses with offline activation (Enterprise) are not checked on an ongoing basis.
10. Using the software
ApkSee processes the apps you load, device contents, network data and results exclusively locally on your computer or on devices and servers that you connect yourself. We have no access to them. If you set up features such as webhooks, notifications, exports or remote devices, data is transmitted directly from your installation to the destinations you specify, not via us. You are responsible for that processing yourself; please observe in particular our acceptable use policy.
When you download the software and updates, the server log data referred to in section 3 is processed.
11. Emails we send
We send emails that are necessary to perform the contract (e.g. confirmation of your email address, order confirmation, license keys, invoice notices, cancellation confirmation, security notices about your account), as well as replies to your enquiries and the waitlist emails described in section 6. They are sent via our own mail server or an email service provider with which an agreement pursuant to Art. 28 GDPR is in place, always with transport encryption (TLS). We do not send marketing newsletters.
12. Recipients and third countries
We pass on personal data only where this is necessary for the purposes described: to our hosting provider and email service provider (processors), to Stripe (payment, tax, invoice), to the provider of the sign-in method you chose, and to tax advisers and public authorities where we are legally obliged to do so.
Stripe and GitHub may also process data in the USA. The transfer is based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR) where the recipient is certified, and additionally on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
13. Retention periods
We delete personal data as soon as the purpose ceases to apply and no retention obligation exists. Server log files are deleted after 7 days at the latest, sessions end after 30 days at the most, unconfirmed waitlist entries are deleted after 7 days, and records of consent are kept for up to 3 years. Invoices and accounting records are retained for 8 years pursuant to § 147 AO and § 257 HGB, and commercial and business letters for 6 years, in each case from the end of the calendar year. License data is stored for the term of the contract and for up to 12 months thereafter (to prevent abuse and to deal with queries about reactivations), unless a longer obligation applies.
14. Your rights
You have the right of access (Art. 15 GDPR), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and the right to withdraw consent you have given at any time with effect for the future (Art. 7(3)). To do so, please contact [email protected].
Right to object (Art. 21 GDPR): where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to assert, exercise or defend legal claims.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is: Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, www.datenschutzzentrum.de.
Providing your data is required neither by law nor by contract. Without the information marked as mandatory, however, we cannot conclude a contract, provide a license or answer your enquiry. We do not carry out automated decision-making within the meaning of Art. 22 GDPR; regarding Stripe’s risk assessment see section 8.
15. Data security
All connections to our website and our servers are TLS-encrypted. We store passwords only as an Argon2id hash, two-factor sign-in via TOTP is available to you optionally, licenses are cryptographically signed, and credentials for payment and email services exist only on the server side. You can report security vulnerabilities to us in accordance with our security policy.
16. Changes
We adapt this privacy policy when our processing or the legal situation changes. The version published on this page at the time applies.