Halmist — App Privacy Policy
This policy describes how the Halmist app handles data. It is separate from the privacy policy for this website (German).
Halmist has not been released yet. This version describes the processing as it is being built. Before the app goes into the app stores we verify every statement here against the running system. Anything we cannot demonstrate there will be corrected or removed — not left standing. Open points are marked as such in the text.
1. Controller
A&D Media und Data GbR
Anastasiia Pylypenko, Denys Drobotov
Bornholmer Straße 68, 10439 Berlin, Germany
E-mail: info@admediadata.com
Phone: +49 160 90326363
The company is the controller within the meaning of the GDPR. The servers, the domains and the Apple and Google developer accounts are held by it.
2. What Halmist does not store
Halmist is built on a no-logs principle. The following are not stored:
- your browsing history or the sites and services you visit;
- your DNS queries;
- the contents of your traffic;
- connection IP addresses with timestamps that could be traced to a person.
What we don't store, we can neither hand over nor sell. That isn't a promise of good intentions but a consequence of the architecture: connection logging is switched off in the server configuration.
To be technically honest: when a connection is established your device necessarily transmits its IP address to the server — no internet connection is possible without it. The distinction is not whether the server sees the address but whether it writes it down. It is not written to a log file and not linked to your activity.
Open point before release: the management system that handles accounts and the device limit may retain the IP address of your most recent connection. We are checking whether it does before publication. If that retention cannot be switched off, this section will state how long the address is kept and for what purpose. Until it has been checked, we claim nothing to the contrary here.
3. Data we do process
An account and a billing relationship inevitably produce data, so "no logs" does not mean "nothing at all". The following list is complete:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| The account's e-mail address | Access to the service, account recovery, service messages | Art. 6(1)(b) GDPR (contract) | up to 30 days after the account is deleted |
| Subscription status, supplied by Apple or Google | Checking whether your access is active | Art. 6(1)(b) GDPR | for the term of the subscription, then as required by commercial and tax law |
| Device identifiers | Enforcing the device limit of your plan | Art. 6(1)(b) GDPR | until the device is removed, at the latest 90 days after last use |
| Total data volume transferred | Billing and abuse detection | Art. 6(1)(b) GDPR | the current billing period and the twelve months that follow |
| Messages to support | Answering your enquiry | Art. 6(1)(b) and (f) GDPR | twelve months after the matter is closed |
Data volume is kept as a total, not as a record of individual connections. It does not reveal what you were connected to.
4. What we do not use
Halmist contains no analytics or advertising components: no tracking, no advertising identifiers, no third-party analytics SDKs, no crash reporting sent to third parties. Should this change during development, this section will be changed accordingly before release — the change will not be left unsaid.
5. Payments
At launch, billing runs exclusively as an in-app subscription through Apple (App Store) and Google (Google Play), each under their own privacy policies. We never see your payment details; the store only tells us whether your subscription is active. Purchasing on our website is not possible at launch.
For cancellation and refunds, see our Terms and the Right of Withdrawal (both in German).
6. Servers, locations and transfers outside the EU
The servers are rented — VPS and dedicated machines at data-centre providers, not hardware of our own. We say so explicitly, because the phrase "our own infrastructure" is common in this industry without being true.
At launch there will be three to five locations across the European Union and the United States. If you choose a location outside the EU, that is where your traffic leaves the network — which is the point of choosing a location. The personal data listed in section 3 is not stored on the VPN nodes; it resides in the management system. Data processing agreements are in place with the server providers; transfers to third countries are based on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies to the provider in question.
To be added before release: the specific locations and the names of the providers used. These are only settled once the servers are set up.
7. Recipients and processors
We do not sell data. It is shared only where operation requires it:
- Apple and Google — handling subscriptions and distributing the app;
- the providers of the rented servers — running the nodes and the management system;
- an e-mail service provider — delivering account and support messages.
8. Security
The connection runs over TLS 1.3 with X25519 key exchange and the ChaCha20-Poly1305 and AES-128-GCM ciphers. Server disks are encrypted with LUKS, connection logging is switched off in the configuration, and nodes are deployed automatically from a template.
No independent security audit has taken place so far. It is on our roadmap, without a date. Until then we do not claim to have been audited.
9. Requests from authorities
We are bound by legally binding orders from German authorities and courts like any other company. But we can only hand over what actually exists: the data in section 3. Browsing history, DNS queries and traffic contents do not exist on our side and cannot be produced after the fact.
10. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). To exercise any of them, write to info@admediadata.com.
You also have the right to lodge a complaint with a supervisory authority. Ours is: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany.
11. Children
Halmist is not directed at children under 16, and we do not knowingly collect their data.
12. Changes
We update this policy when the app or the legal situation changes. The version in force is always at this address, dated at the top. For material changes we will notify you in the app or by e-mail to your account.