BookStax

Privacy Policy

1. Controller

Sven Hanold Falkenweg 27 89129 Langenau Germany Email: info@hanold.info

2. General information on data processing

This website is predominantly a static information page. No cookies are set and no data is transmitted to advertising networks. All content, including fonts, is served from my own server; no content is loaded from third-party servers. To anonymously count page views, a self-operated, non-personal counting mechanism is used — see section 4 for details. No analysis of user behaviour, no cross-page tracking and no profiling takes place.

3. Hosting

This website is hosted on a virtual server that we rent from STRATO GmbH (Berlin) and operate ourselves; the data centres are located in Germany. STRATO processes data as a processor solely on our behalf; a data processing agreement pursuant to Art. 28 GDPR is in place with STRATO. The data processing agreement is available at strato.de/agb/avv.

When you visit the site, the web server processes the technical information required to deliver it, in particular your IP address. Access is not recorded in log files; this data is only processed for the duration of the connection. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure and stable operation).

4. Anonymous page-view counter

To see how often individual pages are viewed, this website counts page views. Only the site name, the requested page path, the language version and the date are processed — aggregated into a daily counter per page. In the same way, the site counts how often the App Store link is clicked (with its placement on the page) and how often the support form is submitted successfully — again only as a daily counter, with no link to a person or to the content of a message.

No IP addresses, cookies, device or browser identifiers, or any other personal data are stored. Individual visits cannot be traced back to a person or device afterwards. The counting runs on infrastructure we operate ourselves; no third parties are involved. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in measuring the reach of our own offering).

5. Support form

You can contact us directly through the form on our support page. The data you enter (name, email address, topic, message and, optionally, an attached file — image or text file) is sent from your browser directly to an automation we operate ourselves (n8n). This creates a support ticket in our internal ticketing system and triggers a notification to us.

For short-term abuse detection (rate limiting), your IP address is stored for a maximum of 5 minutes and then automatically overwritten. In addition, the IP address is contained, together with the form data, in the technical logs of the automation, which are used solely for troubleshooting and are automatically deleted after 7 days; it is not analysed.

To protect against automated abuse (spam bots), the form contains an invisible control field and a self-hosted verification mechanism (ALTCHA). While you fill in the form, your browser solves a small computational task that it has previously fetched from our automation; in addition, the time between loading the page and submitting the form is transmitted. For this check, no cookies are set, no third parties are involved and no characteristics of your device or browser are collected; the required script is served from our own server. When the task is fetched, your IP address is processed only for the duration of the connection for technical reasons and is not stored. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse).

After submitting, you will receive an automatic confirmation with a reference number at the email address you entered; in addition, your request is forwarded by email to our support mailbox. To send and store these emails, we use an email service provider that processes the data as a processor solely on our behalf.

An attached file is stored together with your request in our ticketing system and forwarded by email to our support mailbox. It is not transmitted to the AI service named below. Please do not upload files containing passwords, access credentials or other confidential information.

To answer more quickly, we have a draft reply for support requests prepared by the AI service Claude from Anthropic PBC (USA), which we review and edit ourselves before sending. Transmitted for this purpose are the app, the topic and the message text, but not your name, your email address or an attached file. Email addresses within the message text are removed automatically before transmission. Anthropic processes the data as a processor on the basis of a data processing agreement. The transfer to the USA is safeguarded by the EU standard contractual clauses. The data is not used to train AI models. If the service is unavailable, the draft is created on our own infrastructure. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the prompt handling of support requests).

The submitted form data is used exclusively to process your request. It is not passed on to any recipients other than those named here. After the request has been dealt with, the data is deleted unless statutory retention obligations apply. The legal basis is Art. 6 (1) (b) GDPR (processing your request) or Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse).

6. The BookStax app

BookStax is a client for self-hosted BookStack servers. The app connects exclusively to the servers you configure yourself. Your library, book and page contents remain between the app and your own server – except for the names of pages and books in push notifications, if you turn them on (see below). No third-party analytics, tracking, or advertising services are embedded, and no crash reports are transmitted to third parties. Credentials are stored exclusively locally on your device in the iOS Keychain. Data transmissions to systems operated by the developer take place only in the cases fully described below: the anonymous usage statistics, which you can switch off at any time, the retrieval of public content (news about the app version) and – only if you turn them on – push notifications.

Anonymous usage statistics (from version 2.2)

To understand how well setup and purchase work in the app — and to base improvements and pricing decisions on that — BookStax records a small number of predefined events from version 2.2 onwards and transmits them, TLS-encrypted, to a server we operate ourselves in Germany (telemetry.hanold.online). These are exclusively the following four events, and there are no others:

  1. First launch of the app after installation
  2. First successful connection to a BookStack server
  3. Display of the purchase screen
  4. Completed purchase (unlock of BookStax Pro or a tip)

Each event contains exactly this technical information: a randomly generated installation ID (a UUID created on first launch — it contains no device, account or personal reference and is deleted when the app is uninstalled), a timestamp, the app version, the coarse operating-system version (e.g. “iOS 26”), the platform (iPhone or iPad), and occasionally a short context hint (e.g. where in the app the purchase screen was shown, or the product ID of the purchased product).

What is explicitly not collected and not stored: IP addresses (the receiving endpoint deliberately writes no access log), device or advertising identifiers (no IDFA, no IDFV), the name or address of your BookStack server, your credentials or tokens, the contents or scope of your books, shelves and pages, your reading activity, and any other personal data. The events can neither be linked across devices nor traced back to a person afterwards.

Processing runs entirely on our own infrastructure in Germany (reception via a self-operated automation, storage in a self-operated database); no third parties are involved at any point. Evaluation is exclusively aggregated — for example: “How many of a month’s installations connected a server, and how many of those later purchased?”

You can switch off the usage statistics at any time in the app: Settings → “Security & Privacy” → the “Privacy” section → the “Anonymous usage statistics” toggle. Transmission then stops immediately. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving our own offering). As the data is anonymous, there is no personal reference — we still offer the opt-out because we would expect it ourselves.

Content retrieval (from version 2.3)

After an update – and when you open “What’s new in version …” in Settings – the app downloads a public file listing the changes in the installed version from our server content.bookstax.app. No data from the app is sent along; this is an ordinary request for a public file. The file is served by the server we operate at STRATO in Germany, described in section 3. For technical reasons, your IP address is processed only for the duration of the connection; access is not logged. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in informing users about new features).

Push notifications (from version 2.3, only if you turn them on)

With BookStax Pro you can get notified about events in your BookStack wiki. The feature is off until you turn it on for a server in Settings under “Notifications”. Because BookStack itself cannot send notifications to iPhones and iPads, it runs through a push service we operate (push.bookstax.app) on the server at STRATO in Germany described in section 3, and through the Apple Push Notification service.

When you turn it on, the app sends the following to the push service: a randomly generated channel ID and a random channel secret for this server, the push token Apple assigned to your device, the app identifier and delivery environment, the events you selected and – only if you use “Hide my own changes” – the BookStack user ID whose changes should not be reported. Your BookStack server address and your credentials are not transmitted. The push service stores this information as long as notifications are turned on.

Webhooks from BookStack: Notifications are triggered by your BookStack server. It sends events by webhook to an address that contains the channel ID and channel secret. You or the administrators of your BookStack server set up the webhook; with the recommended setting “All system events”, BookStack sends every event. A webhook contains, among other things, the type of event, a description text from BookStack, the address and name of the page or book concerned, and the name and user ID of the person who triggered it; for administration events (e.g. a new user account) also details of that account. The push service processes webhooks in memory only. Events you haven’t selected, or that come from the hidden user ID, are discarded immediately. The content of a webhook is neither stored nor logged; the technical log only contains the channel ID, the event type and the number of devices notified (size-limited; older entries are overwritten automatically). IP addresses are kept in memory for at most one minute to prevent abuse and are not stored.

Delivery via Apple: For the events you selected, the push service hands a notification to the Apple Push Notification service of Apple Inc. (USA), which delivers it to your device. It contains the name of the page or book, BookStack’s description text (with the name of the person who triggered it), the page address and the related IDs. Comment texts and page contents are never transmitted. Apple processes this data to deliver the notification; Apple’s privacy policy applies in addition. The transfer to the USA is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, under which Apple is certified.

Deletion: When you turn notifications off or generate a new webhook address, the app unregisters your device from the push service; once no device is left on the channel, it is deleted together with its secret and settings. The same happens automatically when Apple reports the push token as invalid (e.g. after deleting the app). Please also remove the webhook in BookStack afterwards; events sent to a deleted address are rejected.

The legal basis is Art. 6(1)(b) GDPR (providing the feature you turned on). Where webhooks contain names or user IDs of other people in your wiki, the legal basis is Art. 6(1)(f) GDPR (legitimate interest in being notified about changes in a shared wiki); this data is only processed transiently and is passed on to Apple only for the events you selected.

Purchases via the App Store

The app is distributed via the Apple App Store. Any purchases or unlocks within the app are processed exclusively through the App Store; the developer does not receive any payment data, only anonymized, aggregated statistics from Apple. Apple’s privacy policy applies in addition.

7. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection (Art. 21 GDPR). You also have the right to lodge a complaint with a data protection supervisory authority; the competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg, Germany.

Note on the usage statistics: as the events processed there are anonymous and we cannot attribute them to any person, we cannot relate access, rectification or erasure requests to individual events (Art. 11 GDPR). The most effective means is the opt-out switch in the app.

8. Last updated

27 September 2026. This policy will be updated as necessary.