iMeter Reader
ENDEARTR

Privacy Policy – iMeter Reader

iMeter Reader (mobile app: iOS, Android, macOS, Windows) · Operator: Ahmad Al Alloush, operator of the iMeter Reader mobile app · Last updated: 7 September 2026 · Version 2.14 · Previous in-place amendments of version 2.13: 15 August 2026 (§§ 6.3, 9, 16.1–16.3, 16.5, Annex A — see § 23); 12 August 2026 (§§ 6.4, 17 — see § 23)

This privacy policy describes which personal data is processed when you use the iMeter Reader mobile app, and on what legal basis. The controller is the app's operator (see § 1). The policy complies with the information obligations under Articles 13 and 14 GDPR, § 5 DDG (German Digital Services Act, formerly TMG) and § 25 TDDDG (German Telecommunications-Telemedia Data Protection Act, formerly TTDSG).

Product name note: The app is published in the App Stores under bundle ID imeterrecorder for historical reasons. The current brand and in-app name is iMeter Reader.


Table of contents

  1. Controller and contact
  2. Data Protection Officer (DPO)
  3. Definitions
  4. Categories of data we process
  5. Purposes of processing and legal bases
  6. Recipients and sub-processors
  7. International data transfers (Chapter V GDPR)
  8. Retention periods and erasure
  9. Your rights as a data subject
  10. Right to withdraw consent
  11. Right to lodge a complaint with a supervisory authority
  12. Obligation to provide data
  13. Automated decision-making / profiling
  14. Data security (Art. 32 GDPR)
  15. Cookies and similar technologies (§ 25 TDDDG)
    • Visiting our website
  16. AI-powered features (OCR, contract analysis, chat)
  17. Tariff comparison (CHECK24 widget)
  18. Service push notifications and reminders
  19. Crash and diagnostic data (Sentry)
  20. Anonymous usage statistics (device telemetry)
  21. Device-keyed record of your privacy choices (pre-login)
  22. Children under 16
  23. Changes to this privacy policy
  24. Annex A — List of sub-processors

1. Controller and contact

The controller within the meaning of Art. 4(7) GDPR is:

Ahmad Al Alloush [NOTE: once the Gewerbeanmeldung for "iMeter Reader" has been completed, prepend "– Geschäftsbezeichnung: iMeter Reader –" and add the Gewerbeschein number below.]

Dietmarstraße 4 · 87463 Dietmannsried · Germany

Email: support@imeterreader.app · Web: https://imeterreader.app

Tax status: small-business (Kleinunternehmer) under § 19 UStG — VAT not charged.

Note: codexo.dev is the operator's technical infrastructure domain (hosting, authentication, API), operated under the iMeter Reader brand; the controller is the operator named above.

For data-protection requests please email: support@imeterreader.app


2. Data Protection Officer (DPO)

The operator of iMeter Reader is not obliged to appoint a DPO under Art. 37 GDPR in conjunction with § 38(1) BDSG:

  • iMeter Reader is operated by a single person — well below the 20-person threshold of § 38(1) sentence 1 BDSG.
  • Core activities do not consist of processing operations that, by virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale (Art. 37(1)(b) GDPR).
  • Core activities do not consist of large-scale processing of special categories of personal data (Art. 37(1)(c) GDPR).

Direct data-protection enquiries to the controller at support@imeterreader.app. We confirm receipt within 72 hours and respond within the statutory 30-day period (Art. 12(3) GDPR).


3. Definitions

We use the GDPR's terminology. "Personal data" is any information relating to an identified or identifiable person (Art. 4(1) GDPR), including:

  • IP addresses (CJEU case C-582/14 Breyer),
  • device identifiers such as a per-installation UUID,
  • energy- or water-consumption data when combined with a customer or contract identifier.

4. Categories of data we process

4.1 Account data

  • mobile phone number — since version 2.12 this is the primary identifier of a new account and the handle you sign in with. It is required to register and is verified by SMS (see § 6.2). Only German (+49) mobile numbers can be registered.
  • email address — optional for accounts created from version 2.12 onwards, and not verified at sign-up. It is stored only so you have a recovery route and can receive service messages, and you may add, change or remove it at any time. Accounts created before version 2.12 keep the email address they registered with.
  • first and last name
  • username (your mobile number for new accounts; your email address for accounts created before version 2.12)
  • pseudonymous user ID (UUID)

4.2 Address and contact (optional)

  • street, house number
  • postal code, city, country

4.3 Energy and water data

  • energy supplier, contract number (customer number), tariff type
  • supply address (when you enter it) — street, house number and any further address detail you record here are stored only on your device and are not transmitted to our servers (Art. 6(1)(b) GDPR)
  • the postal code of the delivery point of an individual meter, where you enter it, and the locality we derive from it — unlike the supply address above, these two fields are part of the meter record: they are stored on your device and, when you are signed in and meter sync is active, they are also transmitted to and stored on our servers in Frankfurt, Germany (Art. 6(1)(b) GDPR). We derive the locality offline, on your device, from a postal-code reference dataset shipped inside the app; no location request, no GPS and no IP-based geolocation is involved (see § 4.9). You can change or clear the postal code at any time; clearing it also clears the derived locality, on your device and on our servers.
  • market-location ID (Marktlokations-ID / MaLo) and metering-location ID (Messlokations-ID / MeLo), and your network and metering operator, where you record them — these are recorded and stored only on your device; they are not transmitted to our servers (Art. 6(1)(b) GDPR)
  • contract start / end / cancellation deadline
  • price structure (per-kWh, base fee, bonuses, price guarantees)
  • energy mix
  • meter tariff configuration you set for each meter: single-register meter, or two-register day/night meter (German HT/NT day-and-night electricity meter)
  • meter readings (value + date + register — day or night, for two-register day/night meters — + optional note)
  • derived consumption series (daily, monthly, yearly)
  • free-text notes attached to contracts and readings
  • water supplier or metering service (e.g. a municipal utility, or a billing service such as Techem / ista) and water contract or customer number
  • cold-water and warm-water meter readings (value + date, in m³)
  • water price structure (€/m³, base fee)

4.4 Device and usage data

  • per-installation device UUID (per-install UUID, platform, OS/app version, country also used once for the install count — Art. 6(1)(f), see § 5)
  • platform (iOS / Android / macCatalyst / Windows)
  • operating-system version
  • app version
  • language and country setting
  • aggregated daily statistics: contracts count, readings count, app opens, session minutes
  • push registration: the Firebase Cloud Messaging registration token of this installation, platform, app language and app version — only while the operating-system notification permission is granted (see § 18)

4.5 Photo / document data (transient)

  • meter photos you capture (cropped, EXIF stripped)
  • contract documents you upload (PDF or JPEG/PNG)

→ These image data are not persistently stored on our servers. They live only in memory for the duration of the AI processing and are discarded afterwards (see § 16).

4.6 Diagnostic and crash data

  • stack traces, breadcrumbs, app state at the time of a crash
  • device info (model, OS version)
  • after the configuration change in § 19: without IP address and without user identifier

4.7 AI chat content

  • the questions you type
  • up to 20 prior turns per session (max 1,000 characters per question)

4.8 Consents

  • per-purpose record of consents (granted/withdrawn, timestamp, policy version)

4.10 Install-count transmission data

On first launch after installation, the app transmits a single, one-time ping containing:

  • a randomly-generated per-installation UUID (created locally at install time, distinct from the sync UUID in § 4.4 once a user account exists, but the same UUID field is reused — see § 5 row on install counting)
  • platform (iOS / Android / macCatalyst / Windows)
  • operating-system version
  • app version
  • 2-letter country code derived from the device locale setting (not from GPS, not from IP geolocation)

This ping fires once per installation, regardless of whether the user has enabled the "Anonymous usage statistics" toggle in § 20. No IP address, no account identifier, and no daily snapshot are included. The UUID is retained on-device in local storage for deduplication purposes; this on-device storage falls under § 25(2) No. 2 TDDDG (technically necessary for the purpose of the transmission, Art. 5(1)(b) GDPR). The legal basis for the transmission itself is Art. 6(1)(f) GDPR (legitimate interest — see § 5).

4.11 Device-keyed privacy-choice record (consent / objection state)

Before and without any account or login, the app transmits the current state of your per-option privacy settings to our backend over the device channel identified by the per-installation device UUID (§ 4.4, HTTP header X-Device-Id):

  • per-installation device UUID
  • per option — AI meter reading (OCR), AI contract analysis, AI chat, tariff comparison (CHECK24), crash diagnostics (Sentry), anonymous usage statistics — the option identifier and its state: consent granted / withdrawn for the consent-based options (Art. 6(1)(a) GDPR); objection state objected / not objected for crash diagnostics and usage statistics (Art. 6(1)(f) / Art. 21 GDPR) — the latter are never recorded as consent
  • the version of the privacy policy shown on the device when the choice was made
  • timestamp of the last change
  • platform (iOS / Android / macCatalyst / Windows)

No name, email address, IP address or account identifier is part of this record. Details, purpose, retention and your rights: § 21.

4.9 Data we do not process

We do not process:

  • advertising identifiers (no IDFA, no Google Advertising ID),
  • tracking pixels or third-party analytics SDKs (no Google Analytics, AppCenter, Mixpanel, Meta SDK, etc.; the Firebase SDK is included only for push delivery — Firebase Analytics is switched off in the app's configuration, see § 18),
  • biometric or health-related special-category data (Art. 9 GDPR),
  • location data (no GPS access; for historical reasons the iOS bundle still declares unused permission strings — these will be removed in the next release),
  • advertising or tracking cookies.

A postal code you type in yourself, and the locality we look up from it offline in a reference data set shipped with the app, are not location data in this sense: they are not measured from your device, and they describe a delivery point you told us about — not your whereabouts.


5. Purposes of processing and legal bases

The following table fulfils Art. 13(1)(c) and (d) GDPR.

Purpose Data categories Legal basis
Creating and maintaining your account, authentication 4.1, 4.2 Art. 6(1)(b) GDPR — performance of contract (iMeter Reader user agreement)
Preventing abuse of the registration, login and password-reset endpoints (rate limiting, brute-force protection) IP address; a one-way hash of the submitted email address; timestamp Art. 6(1)(f) GDPR — legitimate interest in protecting accounts and our infrastructure against credential-stuffing, brute-force and mass-registration abuse (documented balancing test on file). The hash is a pseudonym, not anonymised data. Our own rate-limit counters exist only in memory and are discarded within minutes; they are never written to a database and never logged. Since version 2.12 there is no separate identity service and therefore no external security event log; failed sign-in attempts are counted against the account itself (a counter and a temporary lockout timestamp, no IP address and no log line).
Storing your energy and water contracts and meter readings on-device and (when signed in) syncing to our servers — the supply address, MaLo and MeLo fields (4.3) remain only on the device and are not transmitted; the per-meter postal code you enter and the locality derived from it are part of the meter record and are transmitted and stored with it 4.3 Art. 6(1)(b)
Providing historical consumption charts and analytics 4.3 Art. 6(1)(b)
Reminders for meter readings and contract deadlines (local notifications scheduled on your device) 4.3, 4.8 Art. 6(1)(b) + explicit opt-in (per-meter for meter-reading reminders, per-contract for contract-deadline notifications)
Operator service push notifications to installed apps (service, administrative and security announcements; never advertising) — see § 18 4.4 (push registration: token, platform, app language, app version, per-installation device UUID); for targeting: platform, app version, country and language setting, and whether the installation has been seen within a period we choose (at most 180 days) Art. 6(1)(f) GDPR — legitimate interest in operating and securing the service and in reaching installed apps with service information (documented balancing test on file; see § 18); Art. 6(1)(c) for notices we are legally required to give (e.g. Art. 34 GDPR). Not consent-based and no in-app opt-in: what gates it is the operating-system notification permission (§ 25(1) TDDDG). You may object at any time (Art. 21): switch notifications for iMeter Reader off in your device settings — the app then deletes its registration from our servers on its next start — or email support@imeterreader.app.
AI meter reading (on-device first; cloud fallback to OpenAI in the USA when local OCR fails, § 6.3) 4.5 (transient), 4.3 Art. 6(1)(a) — consent
AI contract analysis 4.5 (transient), 4.3 Art. 6(1)(a) — consent
AI tariff-comparison chat 4.7 Art. 6(1)(a) — consent
Tariff comparison widget (CHECK24) PLZ, kWh, IP, UA, cookies set by third party Art. 6(1)(a) — consent (before widget loads)
Crash and performance diagnostics (Sentry) 4.6 Art. 6(1)(f) GDPR — legitimate interest in app stability and error diagnosis (documented balancing test on file; see § 19). Enabled by default — this is not consent-based processing; you may object at any time (Art. 21) via Settings → Privacy → "Crash & diagnostic reports".
Anonymous usage statistics (device heartbeat + daily snapshot) 4.4 (aggregated) Art. 6(1)(f) GDPR — legitimate interest in quality assurance and product development (documented balancing test on file; see § 20). Enabled by default — this is not consent-based processing; you may object at any time (Art. 21) via Settings → Privacy → "Anonymous usage statistics".
Recording your per-option privacy choices server-side (device-keyed, also before/without any account) 4.11 Art. 6(1)(f) GDPR — legitimate interest in respecting and technically enforcing your privacy choices server-side and in documenting the device's current choice state (Art. 5(2), Art. 24). The recorded choices themselves: AI features and tariff comparison = consent state (Art. 6(1)(a), Art. 7 — granted/withdrawn); crash diagnostics and usage statistics = objection state (Art. 6(1)(f), Art. 21 — objected/not objected, never stored as consent). See § 21.
Counting unique app installations (product/operations metric) Per-installation UUID, platform, OS version, app version, 2-letter country code derived from device locale (not GPS) — see § 4.10 Art. 6(1)(f) GDPR — legitimate interest in measuring adoption of a pre-release product. Balancing test: the UUID is randomly generated with no link to a natural person at creation; no IP, no contact data, minimal device metadata; suppressible/erasable on request. Distinction from § 20: this one-time install count is processed independently of the "Anonymous usage statistics" toggle in § 20: it fires once per installation even when usage statistics are disabled, transmits no daily snapshot and no IP, and is based on Art. 6(1)(f) — not on consent. The § 25 TDDDG analysis: the install-count transmission is non-essential analytics and does NOT rely on the § 25(2) No. 2 exemption; the legal basis is the Art. 6(1)(f) legitimate interest above. The separate on-device storage of the installation UUID for sync remains covered by § 25(2) No. 2 for its own purpose (Art. 5(1)(b)).
Admin/security access log (truncated IP) Operator admin access to backend systems (truncated IP, timestamp, action) Art. 6(1)(f) — legitimate interest in operational security and accountability. Retention: 12 months (GDPR Art. 17(3)(b)/(e) + Art. 32).
Operator-initiated service / administrative / security announcements to registered users 4.1 (email address) Art. 6(1)(f) — legitimate interest in operating and securing the service; you may object at any time (Art. 21) via the unsubscribe link in every message.
Compliance with legal obligations (tax / commercial retention when paid features go live) 4.1 plus payment data Art. 6(1)(c)
Handling your access / rectification / erasure requests 4.1 Art. 6(1)(c) in conjunction with Art. 15–22
Email correspondence via support@imeterreader.app email content Art. 6(1)(b) (pre-contract) or (1)(f) (responding to enquiries)

6. Recipients and sub-processors

We disclose data only to the recipients listed below, and only on the basis of written Data Processing Agreements (DPAs) under Art. 28 GDPR. The current list is in Annex A.

6.1 Hosting infrastructure

Hostinger International Ltd., Jonavos g. 60C, 44192 Kaunas, Lithuania (EU) → Server location: Frankfurt am Main, Germany (we explicitly use the German hosting region) → Data processed: all categories in 4.1–4.4 and 4.7 — and, transiently and in memory only during AI processing, the 4.5 image/PDF data (see § 6.3) — except the supply-address, market-location ID (MaLo) and metering-location ID (MeLo) fields in 4.3, which remain only on your device and are not transmitted to Hostinger (see § 4.3) → International transfer: none — Hostinger is established in Lithuania (an EU member state); physical processing takes place in Germany. → DPA: Hostinger Data Processing Agreement (available in the Hostinger customer portal), signed.

6.2 Identity management and SMS verification

Self-hosted — since version 2.12, accounts, passwords and sessions are managed by our own application on Hostinger servers in Frankfurt am Main, DE. The separate identity service previously used (auth.codexo.dev) has been decommissioned. → Not an external sub-processor; identity data remains within our own infrastructure on the same German server. Passwords are stored only as a bcrypt hash and are never readable by us.

How SMS verification works — and why we never send you a text. To prove that a mobile number belongs to you, our app shows you a short code and our number, and you send us that code by SMS. We do not send SMS to you at any point in this flow. The practical consequences for you: the message is sent from your device at your own operator's rates (a German SMS is included in most tariffs), and we never need your number in order to contact you unprompted.

Verification only succeeds when both the code and the sending number match what was expected, which is what makes it evidence of ownership rather than merely of possessing a code.

6.3 Artificial intelligence

OpenAI, L.L.C., 1960 Bryant Street, San Francisco, CA 94110, USA → Data processed: when AI features are enabled — your meter photo, contract PDF, or chat conversation (up to 20 prior turns) → Models: gpt-4o, gpt-4o-mini → Transfer to: USA. Legal basis: EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914), as incorporated in the OpenAI Data Processing Addendum. OpenAI is not certified under the EU–US Data Privacy Framework, so the adequacy decision (Implementing Decision (EU) 2023/1795) does not apply to this transfer and the Standard Contractual Clauses are the sole safeguard for it. Additional safeguards: no account identifier is transmitted, and the file name of anything you upload is replaced with a neutral one before the request leaves your device; the image or document is held in memory only for the duration of the request and is never stored on our servers. Please note: a contract document is transmitted in full and unredacted, and the analysis deliberately reads identifiers printed on it (such as your customer number and meter number) — this processing is therefore not pseudonymised. → OpenAI retention: API default of 30 days for abuse monitoring. No use of your data to train OpenAI's models (per the OpenAI API data-usage policy). → DPA: OpenAI Data Processing Addendum (https://openai.com/policies/data-processing-addendum), concluded.

6.4 Tariff comparison (joint controllership under Art. 26 GDPR)

CHECK24 Vergleichsportal GmbH, Erika-Mann-Straße 62-66, 80636 Munich, Germany → Data processed: your postal code, estimated annual consumption (kWh), IP address, user agent, plus anything you enter into the widget (specific tariff enquiry, etc.), plus any optional advanced tariff filters that are set (contract term, notice period, auto-renewal, price-guarantee, payment interval, packages, deposit, discounts, guideline match, number of results, green-only) — a pre-set default selection covering ten of the twelve filters is applied the first time the comparison form is shown for a meter; you can change or clear every filter at any time before it is submitted, and a filter you clear stays cleared → Trigger: only when you open the tariff comparison for a meter (from the meter's details or from the comparison shortcut on its chart card) AND have previously given consent — regardless of whether you are signed in. → International transfer: none (EU/EEA). → DPA / affiliate-partner contract: signed (Partner ID 1148136). → For the transmission that occurs when the widget loads, we and CHECK24 are joint controllers (Art. 26 GDPR; for the essence of the arrangement see section 17); for the subsequent delivery of the tariff comparison, CHECK24 processes the data as its own controller. For the immediately related processing, CHECK24's own privacy notice also applies: https://www.check24.de/unternehmen/datenschutz/.

6.5 Crash and performance data

Functional Software, Inc., d/b/a Sentry, 132 Hawthorne St, San Francisco, CA 94107, USA — with European entity Sentry GmbH, Schönhauser Allee 148, 10435 Berlin, Germany → Ingest endpoint: Frankfurt am Main, DE (*.ingest.de.sentry.io) → Data processed: crash stack traces, breadcrumbs, app state, device info. → Important: in the current app version no IP address and no user identifier is transmitted to Sentry (SendDefaultPii = false). → International transfer: primarily EU; intra-group transfers to the US parent cannot be excluded. Legal basis: SCCs and Data Privacy Framework. → DPA: Sentry Data Processing Addendum (https://sentry.io/legal/dpa/), signed.

6.6 Mobile platform provider (on-device OCR model on Android)

For on-device text recognition only: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland — Google ML Kit Text Recognition → Text recognition runs entirely on your device; no image data is transmitted to Google. The model binary is delivered via Google Play Services. For the separate sign-in flow involving this provider, see § 6.11.

6.7 Mobile platform provider (on-device OCR on iOS / macOS)

For on-device text recognition only: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA — Vision framework → Processing is fully on-device; no image data is sent to Apple. For the separate sign-in flow involving this provider, see § 6.11.

6.8 Certificate authority

Internet Security Research Group / Let's Encrypt, USA — issues TLS certificates for *.codexo.dev. No personal data involved.

6.9 SMS and email delivery

Twilio Inc., 101 Spear Street, Suite 500, San Francisco, CA 94105, USA — receiving the verification SMS you send us. Twilio operates the number you text and forwards the message to our server. → Data processed: your mobile number, the message you sent (the verification code), and the time it was received. → Note the direction: since version 2.12 Twilio delivers no messages to you on our behalf, so your number is not used for outbound messaging at all. → International transfer: USA. Legal basis: EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and EU–US Data Privacy Framework (Implementing Decision (EU) 2023/1795). → Retention at Twilio: 30 days by default (delivery proofs + abuse monitoring), then deletion. On our own servers a verification record is deleted after 30 days. → DPA: Twilio Data Processing Addendum (https://www.twilio.com/legal/data-protection-addendum), signed.

Email is no longer sent through an external provider. Since version 2.12 all email — account confirmations, password-reset links, and operator-initiated service/administrative messages — is sent from our own mail server in the EU. Twilio SendGrid, previously named here as a processor for this purpose, no longer receives your email address or any message content, and has been removed as a sub-processor. Each operator-initiated service message continues to carry a one-click unsubscribe link and our Impressum. → Data processed on our own servers: your email address, the content of the message, and the send timestamp. → No open or click tracking of any kind is performed. → International transfer: none — the mail leaves our EU infrastructure directly for your mail provider.

6.10 Public authorities

We disclose data to authorities only when legally required.

6.11 Sign-in providers (independent controllers)

If — and only if — you tap "Sign in with Google" or "Sign in with Apple", the app opens your device's system browser directly at the sign-in page of the provider you chose. Since version 2.12 there is no intermediary identity service between you and the provider. The browser session is opened, and the provider contacted, only after your tap. We receive from the provider only the identity token it issues, which we verify against that provider's published keys; we never receive your provider password.

Note on Apple "Hide My Email": if you sign in with Apple and choose "Hide My Email", Apple gives us a private-relay email address instead of your real one. If you later sign in again with a different method using your real email address, this can result in two separate accounts rather than one. To avoid this, choose "Share My Email" when signing in with Apple, or use the same email address consistently across sign-in methods. If you do end up with duplicate accounts, see § 9 for how to have them merged.

Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland → Data processed by Google: your Google account identity, your device and IP address, our application identifier and the time of sign-in. We receive back from Google: your Google user identifier (sub), your email address and — if present — your name. → Google acts here as an independent controller for its own sign-in processing, not as our processor. Google's privacy notice applies to that processing: https://policies.google.com/privacy → International transfer: Google Ireland is established in the EU; intra-group transfers to Google LLC (USA) cannot be excluded and are covered by Google's EU–US Data Privacy Framework certification and its Standard Contractual Clauses.

Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA → Data processed by Apple: your Apple Account identity, your device and IP address, our application identifier and the time of sign-in. We receive back from Apple: your Apple user identifier (sub), an email address (your own, or an Apple private-relay address if you chose "Hide My Email") and — only on your very first authorisation — your name. → Apple acts here as an independent controller for its own sign-in processing, not as our processor. Apple's privacy notice applies: https://www.apple.com/legal/privacy/ → International transfer: USA, on the basis of Apple's EU–US Data Privacy Framework certification and the EU Standard Contractual Clauses.

Both providers learn that you sign in to iMeter Reader. If you do not want that, register with an email address and password instead — that route involves neither Google nor Apple.

6.12 Push delivery (Firebase Cloud Messaging)

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Firebase Cloud Messaging; Google LLC, USA, as intra-group sub-processor) → Data processed: a Firebase installation identifier created for this app installation, the push registration token of your installation, your platform (iOS / Android), and the content of each service notification we send (title, text, and the in-app screen or link it opens) → Trigger: the Firebase software component is initialised when the app starts and then contacts Google to create the installation identifier — this happens regardless of the notification permission; a registration token is obtained and sent to us only while you have granted the operating-system notification permission for iMeter Reader → International transfer: intra-group transfer to Google LLC (USA) possible; EU Standard Contractual Clauses and the EU–US Data Privacy Framework (Google LLC is certified) → DPA: Google Cloud / Firebase Data Processing and Security Terms. The token is stored on our own servers in Frankfurt am Main (§ 6.1) together with your platform, app language and app version. Firebase Analytics, Crashlytics and every other Firebase product are not used; the analytics collection is switched off in the app's configuration. See § 18.

On iOS, Firebase hands each notification to the Apple Push Notification service operated by Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA: Apple receives the device's APNs token and the content of each notification in order to deliver it. Apple operates this service as the platform provider under the Apple Developer Program License Agreement; international transfer to the USA — Apple Inc. is certified under the EU–US Data Privacy Framework. On Android, delivery runs through Google Play services on your device (Google, above).


7. International data transfers (Chapter V GDPR)

International transfers occur to the recipients in § 6.3, § 6.5, § 6.9 and § 6.12 (Google LLC, USA, and — for the delivery of service push notifications on iOS — Apple Inc., USA), and — only if you choose to sign in with Apple or Google (§ 6.11) — to Apple Inc. (USA) and, through possible intra-group transfer, to Google LLC (USA). Legal basis: EU Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and, for those recipients that are certified under it, the EU–US Data Privacy Framework adequacy decision (Implementing Decision (EU) 2023/1795). AI processing is among these transfers: when you use an AI feature, the image or document is sent to OpenAI, L.L.C. in the USA (§ 6.3). OpenAI is not certified under the Data Privacy Framework, so for that transfer the Standard Contractual Clauses are the sole safeguard.

Additional safeguards:

  • pseudonymisation of requests (no clear name, no user identifier transmitted unless functionally necessary),
  • TLS 1.3 + certificate pinning in the mobile app,
  • storage limits at the recipient (30 days Twilio, 90 days Sentry),
  • prior-notification obligation regarding sub-processors (SCC Clause 9 / Art. 28(2) GDPR): Sentry and Twilio are each contractually required to inform us in advance of any addition or replacement of their own downstream sub-processors. We may object — and where appropriate terminate the contract — before new sub-processors gain access to your data.

A copy of the relevant SCCs is available on request at support@imeterreader.app.


8. Retention periods and erasure

We retain personal data only as long as needed for the purposes in § 5, or until you withdraw consent / object to legitimate-interest processing.

8.1 Offline-first — the default is no data transmission

iMeter Reader is an offline-first app: as long as you do NOT sign in to an account, no contracts, meter readings, notes or other content data are transmitted to our servers. Your content data lives only on your device, in the app's own private storage. (For the narrow technical transmissions that occur even without an account, see the first bullet below and § 4.10 / §§ 19–21.)

Concretely:

  • No account + no AI use: if you neither create an account NOR use any AI feature (cloud OCR, contract analysis, AI chat), your meters, meter readings, contracts, notes and settings never leave your device. Independently of your content data, the app transmits — even without an account — the one-time install ping (§ 4.10), anonymous usage statistics (§ 20, enabled by default, can be switched off), crash diagnostics (§ 19, enabled by default, can be switched off) and the device-keyed record of your privacy choices (§ 21). Uninstalling the app removes all local data immediately; the device-keyed server records are deleted at the latest after the 18-month install-only retention period (§ 8.2).
  • With account (cloud sync): if you create an account and use sync, contracts, meter readings and settings are replicated to our servers (see table below). "Delete account" wipes those server-side copies.
  • With AI use: if you used an AI feature, the corresponding image / PDF / chat message passes through our servers in Frankfurt in memory only and is forwarded to OpenAI in the USA (§ 6.3); we retain no copy after processing. OpenAI holds API content for up to 30 days for abuse monitoring before deleting it. The extracted structured data is saved only on your device.
  • Sentry diagnostics: if crash diagnostics are enabled (they are enabled by default — § 19) and an app crash occurred, the anonymous diagnostic data stays at Sentry for up to 90 days, then is deleted.

8.2 Retention per data category

Data category Retention
Account & master data (4.1, 4.2) Until account deletion + 30-day grace period
Energy contracts and meter readings (4.3) Locally on your device: while the app is installed. On our servers: only when signed-in and cloud sync is on; on account deletion, cascade delete within the 30-day grace period. You can remove individual records from the app at any time.
Meter photos / contract PDFs (4.5) Not persistently stored on our servers. Held in memory on our servers in Frankfurt for the duration of the AI request (seconds to minutes), then discarded. Forwarded to OpenAI in the USA (§ 6.3), which retains API content for up to 30 days for abuse monitoring.
Install-count record (§ 4.10) — device never linked to a user account Maximum 18 months from first install, then deleted — regardless of any telemetry or diagnostics setting.
Device-keyed privacy-choice record (§ 4.11 / § 21) — device never linked to a user account Maximum 18 months from the device's first contact, then deleted together with the install record — regardless of the stored states. On account erasure (Art. 17), the device's privacy-choice records are deleted immediately and the device reverts to install-only status.
Device telemetry — raw daily (4.4 snapshots) 90 days
Push registration (token, platform, app language, app version — § 18) Until you switch notifications for iMeter Reader off in your device settings, delete your account or uninstall the app (the app deletes the registration on its next start after the first two; after an uninstall the token becomes invalid and is removed the next time a delivery fails). A registration on a device from which we have had no contact for 270 days is deleted automatically.
Admin push-broadcast log (operator-initiated service push — acting admin, timestamp, filter descriptor, content class, title and text, target screen or link, recipient / delivered / failed counts, truncated IP; no device identifiers and no tokens) 12 months
Device telemetry — monthly aggregates 24 months
Admin/security access log (truncated IP) 12 months (GDPR Art. 17(3)(b)/(e) + Art. 32 — accountability/security evidence)
Email suppression record (unsubscribe from operator-initiated service email) Retained until account deletion
Admin broadcast log (operator-initiated service email — acting admin, timestamp, filter descriptor, content class, subject, recipient count, truncated IP; no recipient addresses) 12 months
AI chat content (4.7) Local: until you close the app. Server: not persistent.
Sentry diagnostics 90 days
Consent log (4.8) Business relationship + 3 years (to prove consent under Art. 7(1))
Tax / commercial records (when paid features go live) 10 years (§§ 257 HGB, 147 AO)
Rate-limit counters for registration / login / password reset (IP, hashed email) In memory only; discarded automatically within a short window (minutes). Never persisted, never logged.
Identity-service security event log (failed sign-ins: IP address, username, timestamp) Kept only as long as needed for brute-force protection and security review; we are in the process of setting an automatic 30-day expiry. Ask support@imeterreader.app for the current setting.
Account registered but never used: email address never confirmed, no sign-in with Google or Apple, and never signed in to the app 90 days from registration, then automatic deletion (one reminder at day 60). Accounts that have been used are never deleted by this rule.

Local data is held in the app's own private storage on your device until you uninstall the app or use the "Delete account" function. That function removes the energy and water data (§ 4.3) held on the device once our servers have confirmed the deletion request; settings that configure the app on this device — language and display preferences — deliberately remain, and reinstalling the app removes anything left.


9. Your rights as a data subject

Right Scope How to exercise
Access (Art. 15) Receive a full copy of data we hold about you Email support@imeterreader.app; a copy is provided within 30 days.
Rectification (Art. 16) Correct inaccurate or incomplete data Profile screen in the app, or written request.
Erasure / right to be forgotten (Art. 17) We delete your data unless there is a legal retention obligation In-app: open the menu → tap your profile → Profile → Delete Account. Full cascade within the 30-day grace period. See the dedicated account-deletion page for full details.
Restriction (Art. 18) Suspend processing Email support@imeterreader.app.
Portability (Art. 20) Receive your data in a structured, commonly used, machine-readable format On request to support@imeterreader.app, data is provided in a structured, commonly used, machine-readable format.
Objection (Art. 21) Object to processing based on legitimate interest (install count — § 4.10 / § 5; operator-initiated service email — § 5 / § 6.9; operator service push notifications — § 18; crash diagnostics — § 19; anonymous usage statistics — § 20; device-keyed privacy-choice record — § 21). You may object to the install-count processing under Art. 21 GDPR; we will then suppress any further processing of that record and delete it ahead of the 18-month retention period. For crash diagnostics and anonymous usage statistics, the toggles in Settings → Privacy are the easy objection channel: switching an option off is treated as an objection, takes effect immediately and is recorded server-side via the device-keyed privacy-choice record (§ 21). For operator-initiated service email, the one-click unsubscribe link in every message is the easy objection channel; it adds you to our suppression store and stops any further such messages. For service push notifications, switching notifications for iMeter Reader off in your device settings is the easy objection channel: the app then deletes its push registration from our servers on its next start, and no further notification can reach the device. Email support@imeterreader.app, use the toggles in Settings → Privacy, use the unsubscribe link for service email, or switch notifications off in your device settings for push.
No automated decision-making (Art. 22) We do not take automated decisions with legal effect Not applicable.

Handling your request is free of charge. We may require a one-time email confirmation to verify your identity.

Duplicate accounts: if choosing "Hide My Email" with Apple sign-in (§ 6.11) has left you with two separate accounts, email support@imeterreader.app and we can merge them on request. This does not change the 30-day response window above.


10. Right to withdraw consent

Where processing is based on consent (AI meter reading, AI contract analysis, AI chat, CHECK24 tariff-comparison widget), you may withdraw it at any time with effect for the future. Withdrawal is as easy as giving consent:

  • In-app: Settings → Privacy → per-purpose toggles (AI meter reading, AI contract analysis, AI chat, tariff comparison).
  • Email to support@imeterreader.app.

The lawfulness of processing carried out before the withdrawal remains unaffected.

Crash diagnostics (Sentry, § 19) and anonymous usage statistics (§ 20) are not consent-based: they run by default on the basis of legitimate interest (Art. 6(1)(f) GDPR). The corresponding toggles in Settings → Privacy exercise your right to object (Art. 21 GDPR) rather than withdrawing a consent; your objection is recorded via the device-keyed privacy-choice record (§ 21).


11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data-protection supervisory authority. The operator is based in Bavaria, so the competent authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) · Promenade 18 · 91522 Ansbach, Germany · Phone: +49 (0) 981 180093-0 · Email: poststelle@lda.bayern.de · Web: https://www.lda.bayern.de

A list of German DPAs: https://www.bfdi.bund.de/EN/Home/home_node.html


12. Obligation to provide data

To create an account you must provide an email address and set a password — or sign in with Google or Apple, in which case the email address comes from that provider. Your name is optional; if you do not provide one, the app addresses you by your email address instead. Without an account, cloud sync is not available — but all core features (meter reading capture, contract management, reminders) work fully offline; apart from the transmissions described in § 4.10 and §§ 19–21 (install count, crash diagnostics, usage statistics, device-keyed privacy-choice record — each open to objection or switch-off), no data is sent to our servers.

Other data is optional. Not providing it simply means the related feature is unavailable (e.g. no postal code → no tariff comparison).


13. Automated decision-making / profiling

We make no decisions based solely on automated processing that produce legal or similarly significant effects (Art. 22 GDPR). AI features are assistive (OCR and structured-extraction suggestions); you always review and confirm.

No profiling within the meaning of Art. 4(4) GDPR is performed.


14. Data security (Art. 32 GDPR)

We use up-to-date security standards:

  • Transport encryption: TLS 1.3, HSTS, OCSP stapling. The mobile apps additionally enforce Subject Public Key Info pinning (SPKI pinning) for our API host imeterreader.codexo.dev — even a compromised CA cannot man-in-the-middle. When you sign in with Google or Apple, the app opens that provider directly in your device's system browser using the OIDC authorization-code flow with PKCE; our backend receives only the identity token the provider issues and verifies it against the provider's published keys before creating a session of our own. Sessions are held as short-lived access tokens plus a refresh token that we can revoke at any time — signing out, changing your password, or deleting your account ends every session immediately. Our public website is served at imeterreader.app.
  • Secure token storage: auth tokens live exclusively in iOS Keychain / Android Keystore, never in Preferences / NSUserDefaults.
  • RBAC: backend endpoints are protected by JWT validation and resource-owner checks; admin endpoints additionally require the role imeterreader_admin.
  • Input validation & hardening: strict JSON schemas; MIME allow-list + magic-byte check for uploads; 7 MB cap; correlation-ID sanitisation; CORS fail-closed in production.
  • Audit log: operator/admin access to backend systems is logged with the acting admin identity, truncated IP, action and timestamp (12-month retention); see § 5.
  • At-rest encryption: database + backup encryption at Hostinger; local SQLite protected by OS data-protection class (iOS) / File-Based Encryption (Android). SQLCipher on-device is on the roadmap.
  • Backups: daily encrypted, stored on a separate storage box.
  • Patch management: all container images version-pinned; CVE monitoring via Dependabot.
  • Incident response: documented 72-hour breach-notification procedure (Art. 33).

A detailed TOMs catalogue is available to business partners on request (support@imeterreader.app).


15. Cookies and similar technologies (§ 25 TDDDG)

The iMeter Reader mobile app uses no advertising or tracking cookies.

We only use data types that are strictly necessary for the app to function and are exempt under § 25(2) TDDDG:

  • your sign-in session in OS-secure storage (iOS Keychain / Android Keystore): access and refresh token, their expiry times, your user ID, your email address, your display name, and which sign-in method you used,
  • the per-installation device UUID for sync,
  • language and UI preferences,
  • a strictly-necessary session/state cookie set by our identity service (auth.codexo.dev) during Google/Apple sign-in: it binds the OIDC state and PKCE parameters to your browser session and, once you are signed in, carries the identity-service login session. Persistence differs by platform: on iOS, the browser session is ephemeral (ASWebAuthenticationSession) — the cookie is discarded as soon as the sign-in flow completes and nothing persists afterwards. On Android, the flow opens in a Chrome Custom Tab, which shares your device browser's regular cookie jar, so the cookie persists there until the identity-service login session expires; we are in the process of confirming and documenting that session's exact lifetime. Ask support@imeterreader.app for the current setting.

Consent-required items (CHECK24 widget, AI features) are gated by an explicit in-app dialog before activation; see §§ 16, 17. Crash diagnostics (Sentry) and anonymous usage statistics are enabled by default on the basis of legitimate interest; you can object to them / switch them off at any time in Settings → Privacy (Art. 21 GDPR; see §§ 19, 20).

The associated back-office (imeterreader-admin.codexo.dev) is used only by the operator and is not consumer-facing.


Visiting our website

When you open our website (imeterreader.app), your browser transmits technical connection data to our server in Frankfurt (Hostinger): your IP address, browser user-agent and preferred language (Accept-Language). We use these only to deliver the site, to show it in your language, and — when you open our download link /get — to send you to the correct app store for your device (Apple App Store on iOS, Google Play on Android). This routing reads your user-agent in the moment of the request and does not store or log it; the redirect sets Cache-Control: no-store. We make no outbound call — your own browser follows the redirect to Apple or Google, exactly as if you had tapped a store badge.

Legal basis: our legitimate interest in providing and correctly routing our website (Art. 6(1)(f) GDPR). We do not use cookies or similar identifiers for this and do not build any profile from it. You can object under Art. 21 GDPR at support@imeterreader.app.


16. AI-powered features (OCR, contract analysis, chat)

iMeter Reader offers three optional, individually enabled AI features:

16.1 AI meter reading (OCR)

  • Local-first: by default, OCR runs on-device (Apple Vision on iOS; Google ML Kit on Android). No image is sent to our servers.
  • Cloud fallback (optional, consent-required): if local OCR fails, you may switch to cloud OCR. The image (~ 960 × 300 px, JPEG q90, EXIF stripped) is sent to our backend and from there to OpenAI, L.L.C. in the USA (§ 6.3). Response: the extracted numeric reading.
  • You are never required to use it. Entering a reading by hand is always available, needs no consent, and sends nothing anywhere.
  • Limit: maximum 3 cloud OCR calls per week.

16.2 AI contract analysis

  • You may upload a contract PDF or multi-page photo PDF. Where the PDF contains extractable text, the app first checks on your device whether it looks like an energy contract of the type you selected; if it clearly is not, the upload is refused locally and nothing is sent. Otherwise the document passes through our backend in memory only and is then sent in full and unredacted to OpenAI, L.L.C. in the USA (§ 6.3).
  • Response: a structured contract record that you review and optionally correct before saving.
  • Note: contract documents often contain sensitive data (name, address, customer number, IBAN/SEPA). We recommend redacting fields you do not want AI-processed before uploading.
  • Limit: 2 electricity and 2 gas contracts per month.

16.3 AI chat (tariff assistant)

  • Ask questions about energy tariffs, provider differences, cancellation periods, etc.
  • Your input and the last 20 turns of conversation are sent to our backend and from there to OpenAI, L.L.C. in the USA (§ 6.3). There is no self-hosted model — your text leaves the EU.
  • Please do not enter sensitive personal data of third parties in the chat.
  • Per-question input limit: 1,000 characters — deliberately kept low so that no large volume of personal data is inadvertently transmitted to our servers (data minimisation, Art. 5(1)(c) GDPR).
  • Daily limit: 20 requests per day.

16.4 Consent-based

All three AI features ship disabled. They activate only after your explicit, per-feature consent. You can review and revoke at any time in Settings → Privacy.

16.5 No training of AI models

We do not — and will not — use your meter images, contract documents, AI-chat messages or any other content you submit to train, fine-tune or improve any AI model. To be absolutely clear, and we reiterate: we do not train any artificial intelligence on user data. Our AI features are provided by OpenAI, L.L.C. in the USA (§ 6.3), and under the OpenAI API data-usage policy content submitted through the API is not used to train OpenAI's models either. Your uploaded images, PDFs and chat messages are processed in memory only, for the duration of the request, and are discarded immediately afterwards; we do not store them on our servers. OpenAI retains API content for up to 30 days for abuse monitoring before deleting it. Please be aware that this means your content is sent to a third-party AI provider in the United States — if you would rather it were not, do not enable the AI features: every one of them is optional, requires your consent, and has a manual alternative.

There is currently no opt-in that would allow your content to be used for model training. If we ever introduce such an option in a future version, it would require a separate, explicit, freely-given consent under Art. 6(1)(a) GDPR — silence, continued use of the app, or pre-ticked boxes would never count as consent (Art. 4(11), Art. 7 GDPR; EDPB Guidelines 05/2020 on consent).


17. Tariff comparison (CHECK24 widget)

From a meter's details — or from the comparison shortcut on a meter's chart card — you can run a tariff comparison for electricity or gas for that meter. An embedded widget from CHECK24 Vergleichsportal GmbH is loaded (see § 6.4). Loading the widget transmits to CHECK24:

The tariff comparison can also be used without signing in. The first time you compare for a meter, the app shows you — before the widget loads — a comparison form with the postal code, the annual consumption and the twelve optional advanced tariff filters; the postal code and the annual consumption are required for the comparison, and both are transmitted to CHECK24 only to deliver it. Postal code: the form shows the delivery-point postal code of the meter you are comparing (§ 4.3); a postal code you enter or change in the form is saved to that meter and from then on follows the meter's own storage, sync and erasure rules — including transmission to and storage on our servers when you are signed in and meter sync is active, and deletion when you delete the meter or your account. Annual consumption: the figure is kept per meter, so the figure transmitted is the one belonging to the meter you are comparing; it is stored only on your device (on the basis of our legitimate interest, Art. 6(1)(f) GDPR) and never reaches our servers. You can change or clear the consumption figure and the filters at any time via the filter icon of the comparison. If you withdraw consent for the tariff-comparison widget, or uninstall the app, the consumption figures and the filter values are deleted for every meter; the meter's postal code is not deleted by the withdrawal, because it is part of the meter record you created. Up to version 2.13 this policy stated that the postal code entered for the comparison stayed on your device and was deleted on withdrawal; since the comparison is opened per meter, that is no longer the case, and this version retracts that statement (see § 23).

  • your postal code (5 digits),
  • your estimated annual consumption in kWh,
  • your IP address, user agent, language setting,
  • cookies and similar identifiers set by the widget in the in-app browser.
  • where one or more of the optional advanced tariff filters is set (maximum contract term, notice period, auto-renewal, price-guarantee type and length, payment interval, package tariffs, deposit, discounts/bonuses, recommendation-guideline match, number of results, green-electricity-only), the value of each filter that is set — these are search preferences chosen from fixed options. Pre-set default selection: the first time the comparison form is shown for a meter, the app applies a pre-set default selection to ten of the twelve filters (all except "number of results" and "green-electricity-only"). The selection is not a recommendation, is not based on anything about you, and does not narrow the results in your favour; it is visible in the form and can be changed there before you submit it, and it is transmitted only when you submit the form. After the first submission, the values are stored on your device for that meter and are transmitted again with later comparisons for the same meter without the form being shown again. You can change or clear every filter at any time via the filter icon of the comparison; a filter you clear stays cleared with immediate effect, and "Clear all filters" clears all twelve and remembers that. For a filter that is cleared, the comparison portal may still apply a default of its own. A separate control, "Reset to defaults", puts the app's default selection back and deletes the filters saved for that meter; it does not affect the stored annual consumption or the postal code, and after it is used the app's default selection is applied again the next time the form is shown for that meter. The filter values are stored locally on your device only (on the basis of our legitimate interest, Art. 6(1)(f) GDPR) and never reach our servers; withdrawing your consent for the tariff-comparison widget deletes the filter values and the applied-markers for every meter, so a later re-grant starts again from the pre-set selection.

We ask for your consent before the widget loads for the first time. You can disable the widget at any time (Settings → Privacy → "Allow tariff comparison widget"). CHECK24's own privacy notice: https://www.check24.de/unternehmen/datenschutz/.

We participate in the CHECK24.net partner programme: the provider may receive advertising-cost reimbursement when transactions arise through the embedded widget — for example through leads (qualified enquiries) or sales (contracts concluded with a partner provider). This has no effect on tariff selection, as CHECK24 calculates the results list independently. We also display a permanent partner notice on the comparison screen; you can open the full version of this notice there at any time with a tap. Further information on data use by CHECK24.net: https://www.check24.net. Privacy notice of the comparison portal: https://www.check24.de/unternehmen/datenschutz/.

Joint controllership (Art. 26 GDPR). For the transmission of your postal code, your annual consumption, any optional advanced tariff filters that are set, your IP address and your user agent when the widget loads, we and CHECK24 Vergleichsportal GmbH are joint controllers. The essence of the arrangement: we are responsible for obtaining your consent before the widget loads, for informing you under Art. 13 GDPR and for implementing your withdrawal. CHECK24 is responsible, as controller, for calculating and delivering the tariff results, for the cookies set within the widget and for the further processing of the details you enter there, and informs you about this in its own privacy notice. You may exercise your data-subject rights (Art. 15–22 GDPR) against either of us (Art. 26(3) GDPR); contact support@imeterreader.app or CHECK24 at https://www.check24.de/unternehmen/datenschutz/.

The CHECK24.net partner programme is operated by the same entity that provides the comparison widget — CHECK24 Vergleichsportal GmbH, Erika-Mann-Straße 62-66, 80636 Munich (see § 6.4). The privacy notices published at check24.net and check24.de concern the same controller.


18. Service push notifications and reminders

Reminders stay local. All reminders (meter readings, contract end dates, cancellation deadlines) are local notifications scheduled by the app on your device. No reminder content leaves your device.

Service push notifications (from the first app version released after 7 September 2026 / policy version 2.14). In addition, we can send service notifications to installed apps — for example a notice that an app update is required, a security notice, a planned maintenance window, or a notice we are legally required to give. We never send advertising this way: the advertising message class is switched off at server level, and any message declared as advertising is rejected.

  • What is processed. When you have granted the operating-system notification permission for iMeter Reader, the app obtains a registration token from Firebase Cloud Messaging (Google, § 6.12) and sends it to our servers together with your platform, your app language and your app version, keyed to the per-installation device UUID (§ 4.4). The token is a random identifier issued for this installation; it is not linked to your name or email address, and it is not used for analytics or advertising. Firebase Analytics is switched off in the app's configuration. The Firebase software component itself is initialised when the app starts and creates an installation identifier with Google regardless of the permission (§ 6.12); the registration token, however, is obtained and sent to us only with the permission. Each time the app sends or renews this registration — at most about once a month, and whenever the token, your app language or your app version changes — our server also records that the installation was seen and updates the stored app version; this happens independently of the "Anonymous usage statistics" setting (§ 20).
  • How we choose recipients. For a notification we may select installations by platform, app version, country and language setting (so that you receive the message in your app language, with English as fallback), and by whether the installation has been seen within a period we choose (at most the last 180 days), or — for a service message that concerns your account — by account. No behavioural profile is created.
  • Delivery. The notification is handed to Google (Firebase Cloud Messaging), which delivers it via the Apple Push Notification service (Apple Inc., USA) on iOS and via Google Play services on Android. Google — and on iOS also Apple — therefore sees the token and the content of each notification; see § 6.12 and § 7 for the recipients and transfer safeguards.
  • Legal basis. Our legitimate interest in operating and securing the service and in reaching installed apps with service information (Art. 6(1)(f) GDPR; balancing test on file); Art. 6(1)(c) for notices we are legally required to give. Service push notifications are not consent-based and there is no in-app opt-in: the control is the operating-system notification permission (§ 25(1) TDDDG).
  • Your objection (Art. 21). Switch notifications for iMeter Reader off in your device settings. The app then deletes its registration from our servers on its next start, and no further notification can reach the device. You can also object by email to support@imeterreader.app. Deleting your account or uninstalling the app removes the registration as well.
  • Retention. The registration is kept while notifications are enabled; a registration on a device from which we have had no contact for 270 days is deleted automatically (§ 8.2). For each notification we keep an operator log of the acting admin, the time, the selection criteria, the content, and the delivery counts for 12 months — without any device identifiers or tokens.
  • What we do not do. No push token is transmitted for reminders; no marketing push; no per-user tracking of opens or taps.

Android requires POST_NOTIFICATIONS (for both reminders and service notifications), SCHEDULE_EXACT_ALARM and RECEIVE_BOOT_COMPLETED (the last so that reminders survive a device restart).


19. Crash and diagnostic data (Sentry)

Crash diagnostics are enabled by default. While they are enabled, on a crash we send to Sentry (§ 6.5):

  • stack trace and error message,
  • breadcrumbs (in-app navigation in the minutes before the crash),
  • device info (model, OS version),
  • app version.

Not sent to Sentry:

  • your IP address,
  • your email, name or username,
  • contents of meter readings, contracts, chat messages or notes.

No advertising or tracking identifiers. Sentry retains diagnostics 90 days and then deletes them.

Legal basis: our legitimate interest in the stability of the app and in diagnosing errors (Art. 6(1)(f) GDPR; a documented legitimate-interest assessment / balancing test is kept on file with the controller). Crash diagnostics are not consent-based. You have the right to object at any time (Art. 21 GDPR): switch off Settings → Privacy → "Crash & diagnostic reports". The objection takes effect immediately on the device and is additionally recorded server-side via the device-keyed privacy-choice record (§ 21), so it is respected even without an account.

You may disable diagnostic transmission at any time (Settings → Privacy → "Crash & diagnostic reports").


20. Anonymous usage statistics (device telemetry)

To improve quality, detect stability issues and guide product development, we collect aggregated device-level usage statistics (see § 4.4). Each day we transmit:

  • contracts count (cumulative),
  • meter readings count (cumulative),
  • app opens since last snapshot,
  • active session minutes since last snapshot,
  • app version.

These data are not tied to your account, only to an anonymous per-installation UUID. If you sign in later, the UUID is linked to your account — you can sever this link at any time (Settings → Account → "My devices").

Legal basis: our legitimate interest in quality assurance, stability analysis and product development (Art. 6(1)(f) GDPR; a documented legitimate-interest assessment / balancing test is kept on file with the controller). Usage statistics are not consent-based. You have the right to object at any time with effect for the future (Art. 21 GDPR); objecting is as easy as flipping the switch (Settings → Privacy → "Anonymous usage statistics") and is additionally recorded server-side via the device-keyed privacy-choice record (§ 21). The lawfulness of processing carried out before your objection remains unaffected.

Default state: usage statistics are enabled by default. You can switch them off at first launch or at any time later in Settings.

Note: this toggle does not cover the one-time install count described in § 5 / § 4.10; that count runs independently of this setting (you may object under Art. 21).


21. Device-keyed record of your privacy choices (pre-login)

So that your privacy choices are respected on our servers as well — and not only on your device — the app transmits the current state of your per-option privacy settings to our backend before and without any account or login, over the unauthenticated device channel identified by the persistent per-installation device UUID (§ 4.4, HTTP header X-Device-Id).

What is transmitted and stored (server-side, keyed by the device UUID): for each option — AI meter reading (OCR), AI contract analysis, AI chat, tariff comparison (CHECK24), crash diagnostics (Sentry) and anonymous usage statistics — the option identifier and its current state, the version of this privacy policy that was shown on the device when the choice was made, the timestamp of the last change, and the platform (§ 4.11). No name, no email address, no IP address and no account identifier are part of this record.

Purpose: to record the device's privacy choices so that they are respected and technically enforced server-side (for example, our backend refuses cloud AI processing for a device whose record shows no consent) and so that the device's current choice state is demonstrable (Art. 5(2), Art. 24 GDPR).

Lawful bases:

  • Storing and evaluating the device-keyed record itself: Art. 6(1)(f) GDPR — legitimate interest in respecting and enforcing your privacy choices server-side.
  • The recorded choices for AI meter reading, AI contract analysis, AI chat and tariff comparison are your consents (Art. 6(1)(a), Art. 7 GDPR), stored as granted or withdrawn; these features remain off until you consent (§§ 16, 17).
  • For crash diagnostics (Sentry) and anonymous usage statistics, which run by default on the basis of legitimate interest (Art. 6(1)(f); §§ 19, 20), the record stores your objection state (objected / not objected) under Art. 21 GDPR. It is deliberately never stored as a "consent", because a default-on setting is not consent (Art. 4(11), Art. 7 GDPR).

Integrity note: because this channel works without a login, the device-keyed record is operational current-state information reported by the device. It is not used as evidence of consent within the meaning of Art. 7(1) GDPR; that evidence lives exclusively in the account-bound consent log (§ 4.8), which is written only for authenticated users. The operator can view the device-keyed state read-only in the administration back office, where it is marked accordingly.

Retention and erasure: if the device is never linked to a user account, the record is deleted at the latest 18 months after the device was first seen — regardless of which states are stored. If you delete your account (Art. 17 GDPR), the device's privacy-choice records are deleted as well and the device reverts to install-only status (§ 4.10). You can also request deletion at any time via support@imeterreader.app.

Recipients: the record is stored exclusively on our servers at Hostinger in Frankfurt am Main, Germany (§ 6.1). No third-country transfer takes place.


22. Children under 16

iMeter Reader is intended for adult energy customers. It is not intended for children or adolescents under 16. We do not knowingly process data of persons under 16. If we learn that such data has been provided without valid parental consent, we delete it without delay.


23. Changes to this privacy policy

We update this privacy policy whenever our processing or applicable law changes. We give at least 30 days' notice of material changes — via an in-app notice and (if you have an account) by email. The current version is always at:

https://imeterreader.app/en/privacy

Version 2.14 of 7 September 2026 — two changes:

  • Service push notifications (new § 18, new § 6.12). The app can now receive service notifications from us. Up to version 2.13 this policy stated that no push tokens were transmitted; from the first app version released after 7 September 2026 that is no longer true, and this policy was published before that app version was released. A Firebase Cloud Messaging registration token, your platform, app language and app version are transmitted to our servers and the token to Google (Firebase Cloud Messaging, new sub-processor, § 6.12, Annex A) — only while you have granted the operating-system notification permission; on iOS, Apple Inc. (Apple Push Notification service) additionally receives each notification for delivery. The Firebase software component is initialised at app start and creates an installation identifier with Google regardless of the permission (§ 6.12). Legal basis Art. 6(1)(f) GDPR (Art. 6(1)(c) for legally required notices); not consent-based, no in-app opt-in; you object by switching notifications off in your device settings (§ 18). §§ 4.4, 4.9, 5, 7, 8.2 and 9 were amended accordingly. This is a new recipient and a possible third-country transfer (Google LLC, USA — SCCs + Data Privacy Framework). Reminders remain local notifications.
  • Pre-set tariff-filter defaults (Step 2 of the amendment of 12 August 2026 — §§ 6.4 and 17). The app now applies a pre-set default selection to ten of the twelve optional advanced tariff filters the first time the comparison form is shown for a meter, and those defaults are transmitted with the comparison request when you submit the form. § 17 states that every filter can be changed or cleared at any time, that a filter you clear stays cleared, that "Reset to defaults" puts the selection back and deletes what was saved for that meter, that withdrawing consent deletes the filter values for every meter, and that the comparison portal may still apply a default of its own for a cleared filter. § 17 also states that the annual consumption is kept per meter. Retraction: up to version 2.13, § 17 stated that a postal code entered for the comparison was stored only on your device and deleted when you withdrew consent. Because the comparison is now opened per meter, a postal code entered in the comparison form is saved to that meter (§ 4.3) and follows the meter's storage, sync and erasure rules; it is transmitted to our servers with the meter when you are signed in and meter sync is active, and it is not deleted by withdrawing the tariff-comparison consent. The annual consumption and the filter values remain device-only and are deleted on withdrawal. The filter values are stored only on your device on the basis of our legitimate interest (Art. 6(1)(f) GDPR) and never reach our servers; their transmission to CHECK24 continues to rest on your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). No new recipient, no new sub-processor, no third-country transfer, no change to purposes or retention periods for the tariff comparison. No renewed consent is required — the scope of the consent you give for the tariff-comparison widget is unchanged. The tariff comparison is opened from a meter's details; the former "Offers" menu entry no longer exists, and the wording of §§ 6.4 and 17 has been adjusted accordingly.

Neither change affects processing based on Art. 6(1)(a) GDPR, so no renewed consent is required for the AI features or the tariff comparison.

In-place amendment of 15 August 2026 (Version 2.13 unchanged) — correction of the AI sections: the drafts of versions 2.12 and 2.13 described the AI features as running on a self-hosted large-language-model in Frankfurt am Main, and stated that content was never sent to an external AI provider such as OpenAI. That description was incorrect and was never published — the version served to users throughout has been 2.10, which correctly names OpenAI. This amendment restores the accurate description before any of it could reach you:

  • § 6.3 again names OpenAI, L.L.C. (USA) as the recipient of the cloud AI processing, with the EU Standard Contractual Clauses as the sole transfer safeguard. It now also states explicitly that OpenAI is not certified under the EU–US Data Privacy Framework, and that a contract document is transmitted in full and unredacted and is therefore not pseudonymised.
  • §§ 16.2 and 16.3 (contract analysis and AI chat) said the document or conversation was processed by "our own local AI". They now name OpenAI, L.L.C. in the USA, consistent with § 6.3.
  • § 16.2 now also describes the on-device pre-check: where a PDF contains extractable text, the app checks on your device whether it matches the energy type you selected, and refuses the upload locally — without sending anything — when it clearly does not.
  • § 16.5 and § 9 have been corrected accordingly; § 9 now lists the AI transfer among our third-country transfers instead of excluding it, and Annex A again carries an OpenAI row.

What did NOT change, and a correction to an earlier draft of this note: on-device text recognition (Apple Vision on iOS, Google ML Kit on Android) is part of the app, meter reading is local-first with cloud OCR only as a consented fallback, and the published usage limits — 3 cloud OCR calls per week, 2 electricity and 2 gas contracts per month — are enforced. §§ 6.6 and 6.7 and the corresponding Annex A rows therefore remain in place. An earlier version of this amendment, briefly published on 15 August 2026, wrongly removed them; that removal was based on a check of a newer app version that is not yet released, and has been reversed the same day.

No change to purposes, retention periods or legal bases, and no new recipient relative to the published version 2.10. No renewed consent is required — the scope of the consent you give for the AI features is unchanged, and the description you were actually shown (version 2.10) already named OpenAI.

In-place amendment of 12 August 2026 (Version 2.13 unchanged): Version 2.10 — the version published up to now — does not describe the optional advanced tariff filters at all. This amendment closes that gap, and it does so in two steps, because the app you can install today and a future app version behave differently.

  • Step 1 — this amendment. §§ 6.4 and 17 described (until version 2.14) the behaviour of the app version available in the app stores at that time: the twelve optional advanced tariff filters are transmitted to CHECK24 only where you set them; nothing is pre-set for you, and for a filter you leave unset the comparison portal may still apply a default of its own. The value of each filter you set is stored only on your device on the basis of our legitimate interest (Art. 6(1)(f) GDPR) and never reaches our servers; its transmission to CHECK24 rests on your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
  • Step 2 — published with version 2.14 on 7 September 2026. The pre-set default selection of tariff filters described in that version's entry above applies from the first app version released after 7 September 2026; this policy version was published before that app version was released.

No new recipient, no new sub-processor, no third-country transfer, no change to purposes or retention periods. No renewed consent is required — the scope of the consent you give for the tariff-comparison widget is unchanged.

Version 2.13 of 9 August 2026: § 4.3 now distinguishes between the supply address (street / house number), which stays exclusively on your device, and the per-meter postal code of the delivery point together with the locality derived from it: the latter two are part of the meter record and are transmitted to and stored on our servers in Frankfurt am Main when you are signed in and meter sync is active. The corresponding row in § 5 has been corrected accordingly, and § 4.9 clarifies that a postal code you enter yourself, and the locality derived from it offline, are not location data in that sense. Legal basis unchanged — Art. 6(1)(b) GDPR; no new recipient, no new sub-processor, no third-country transfer, no change to retention periods. No renewed consent is required — none of these changes affects processing based on Art. 6(1)(a) GDPR.

In-place correction of 7 August 2026 (Version 2.12 unchanged): §§ 8.1 and 8.2 previously described the data on your device as a local SQLite database and stated that the "Delete account" function wipes it before the server call. We have removed the storage-technology name — an implementation detail that can change from release to release — and corrected the sequence: the copy on your device is removed after our servers have confirmed the deletion request, never before. Both passages now also state that the settings which configure the app on this device deliberately remain. No purpose, legal basis, recipient or retention period changed, and the scope of your consent is unaffected — no new consent is required.


Annex A — List of sub-processors (as of 2026-09-07)

Name Location Role Data location Third-country transfer DPA
Hostinger International Ltd. Kaunas, LT (EU) Hosting (compute, DB) Frankfurt am Main, DE none Hostinger DPA
OpenAI, L.L.C. San Francisco, USA AI model inference (meter reading, contract analysis, chat) USA yes OpenAI DPA + SCCs (not DPF-certified)
Functional Software Inc. / Sentry GmbH San Francisco, USA / Berlin, DE Crash and performance telemetry Frankfurt am Main, DE (ingest); intra-group US possible partly Sentry DPA + SCCs + DPF
CHECK24 Vergleichsportal GmbH Munich, DE Tariff comparison widget Germany none CHECK24 affiliate-partner contract
Twilio Inc. San Francisco, USA Receiving the verification SMS you send us (no outbound SMS) USA yes Twilio DPA + SCCs + DPF
Google Ireland Ltd. (ML Kit + Play Services) Dublin, IE Local OCR model on Android on device intra-group US possible Google Cloud Customer Mobile Services DPA
Apple Inc. (Vision framework) Cupertino, USA Local OCR framework on iOS / macOS (OCR only — sign-in is not a processor relationship, see § 6.11) on device none (no data transfer) Apple Developer Program License Agreement
Google Ireland Ltd. (Firebase Cloud Messaging) Dublin, IE Delivery of service push notifications (installation identifier, registration token, platform, notification content) — § 6.12, § 18 EU; intra-group transfer to Google LLC (USA) possible possible (SCCs + DPF) Google Cloud / Firebase Data Processing and Security Terms
Apple Inc. (Apple Push Notification service) Cupertino, USA Delivery of service push notifications to iOS devices (APNs token, notification content) — § 6.12, § 18 USA yes (DPF) Apple Developer Program License Agreement

Google and Apple additionally act as independent controllers when you choose to sign in with them (§ 6.11). They are not our sub-processors for that flow and are therefore not listed in the table above.

We update this list as our infrastructure evolves. The current version is at https://imeterreader.app/en/subprocessors. We notify users of new sub-processors at least 30 days before introduction.


iMeter Reader privacy policy · Version 2.14 · 7 September 2026 · Privacy questions: support@imeterreader.app

Privacy | Terms | Sub-processors | Imprint | support@imeterreader.app

  • Privacy Policy
  • Terms & Conditions
  • Impressum
  • Cookies & Local Storage
  • Children & Minors
  • Accessibility
  • Open-Source Attributions
  • Sub-processors
  • Delete Your Account

© 2026 iMeter Reader

© 2026 Codexo · iMeter Reader