Privacy Policy
Last updated: August 19, 2026
Overview
This policy explains how Kurcz Software GmbH processes personal data when you use kurczsoftware.com, a Kurcz account, or a Kurcz app. It also explains which app data stays only on your device.
Controller
Kurcz Software GmbH Widmaierstraße 60, 70567 Stuttgart, Germany Email:
What is collected
• Website and waitlist: email address, language, contact submissions, referral-link visits and inviter/invitee relationships, referral qualification history, UTM context, and product interactions such as pages viewed or buttons clicked. • Kurcz account: email address, profile choices, active app/device sessions, product entitlements and subscription status, and small app data you choose to sync. Payment providers process payment details; Kurcz stores provider identifiers and access status, not full card details. Daily Widget sync includes subscriptions and progress, notification preferences, interests, and theme choices. • Coauthr: published document HTML and optional Markdown source, versions, comments, proposed edits, attachments, project access and invitations, agent tokens and terminal labels, and short-lived live-session and presence records. Reviewer email addresses are visible to project owners for access management; other reviewers see display names. • Coauthr operational measurement: minimized first-party service events and server-confirmed publishing, review, subscription, and error events. These can include an ephemeral in-memory identifier, an authenticated account ID, opaque document/project IDs, interaction type, release, sanitized route, and allowlisted acquisition source. Coauthr never sends document text, comments, proposed edit text, email addresses, share keys, invite tokens, or session recordings to analytics. • Optional app analytics: after you allow it, a random first-party browser or installation ID connects product interactions across visits and may be linked to your account after sign-in. • Daily Widget community safety: pack content, creator identity, reports, moderation decisions, and report reasons. Hiding a creator is stored only on your device. • Timezones: your ordered city list and time-zone identifiers are included only in account sync when you sign in; selected cities and search queries are never included in analytics. • llypa: selected apps, Screen Time reports, opening budgets, pickups, challenges, and usage history stay on your device and are never included in analytics. • Steppya: step counts, Health and Motion data, step history, and your exact daily goal stay on your device and are never included in analytics.
Why it's processed (legal basis)
• Waitlist, marketing email, and optional cross-visit app analytics: your consent (Art. 6(1)(a) GDPR). Withdraw it by unsubscribing or turning optional analytics off in the app. • Account, sync, purchases, entitlements, and referral rewards: providing the service or promotion you request (Art. 6(1)(b) GDPR). • Site security, payment and referral fraud prevention, service diagnostics, and minimized first-party/server product measurement: Kurcz Software's legitimate interests in operating and improving the service (Art. 6(1)(f) GDPR). You may object as described below.
Processors
Kurcz Software uses Convex (database and first-party service measurement), Vercel (hosting and web performance), Resend (email), PostHog EU Cloud (operational diagnostics and optional product analytics), Paddle (web and Mac payments), and Apple (iOS payments). EU regions are selected where offered. Data processing agreements and appropriate transfer safeguards apply.
Cookies
Essential first-party storage keeps sessions, security state, language, and preferences, including your analytics choice. The site does not use advertising cookies. Coauthr creates a random first-party analytics ID only after you allow cross-visit analytics; PostHog uses memory persistence and session recording is disabled.
Retention
Account data is kept while your account exists; use the direct Delete account section at /account#delete-account to permanently delete the account and associated personal data. Coauthr immediately closes public links and access, then deletes documents, versions, comments, edits, attachments, tokens, invitations, and presence records in bounded background batches. Active Paddle subscriptions are canceled before deletion begins. Referral lineage is removed when either linked account is deleted. Payment providers may retain transaction records under their legal obligations; Kurcz removes its account-linked billing and entitlement data on account deletion except records it must retain by law. Waitlist email-delivery records are deleted within 30 days. After you unsubscribe, we retain your account and the minimum opt-out record needed to honor that choice until account deletion or a deletion request. Coauthr raw first-party journey events are kept for up to 365 days and first-party exception rows for 90 days; PostHog EU event history follows its active one-year retention window. Turning optional analytics off immediately clears the local analytics ID and stops cross-visit collection; minimized operational and server-confirmed service measurement continues.
Your rights
You may access, correct, erase, restrict, or port your data, withdraw consent, and object to processing based on legitimate interests. Delete a Kurcz account directly at /account#delete-account, turn optional analytics off in Settings, or email to exercise a right or object to account-linked measurement. You may also complain to a data protection authority.