This policy covers the website manqr.me and the MANQR mobile app for iOS and Android.
1. Controller
Frederick Hörner
c/o Online-Impressum #10122
Europaring 90
53757 Sankt Augustin
GermanyEmail: support@manqr.app
We have not appointed a data protection officer. As a one-person business we are below the threshold in § 38 (1) BDSG, which requires one only where at least 20 people are constantly engaged in automated processing. You can raise any data protection matter with us at the address above.
2. Legal bases
We process personal data only where one of these applies:
- Article 6(1)(b) GDPR — performance of our contract with you, or steps taken at your request before entering into it.
- Article 6(1)(f) GDPR — our legitimate interests, where these are not overridden by your interests or fundamental rights.
- Article 6(1)(c) GDPR — compliance with a legal obligation.
- Article 6(1)(a) GDPR — your consent, where we ask for it. You can withdraw consent at any time with effect for the future.
3. Visiting the website
Server log files
When you load a page, our hosting provider processes technically necessary access data: IP address, date and time, the file requested, volume transferred and HTTP status, browser and operating system, and where applicable the referring page. This is necessary to deliver and secure the site (Article 6(1)(f) GDPR). Logs are deleted after a short period and are not combined with other sources.
Storage on your device
The site stores two values in your browser’s local storage: your theme preference and your language preference. Both exist only because you chose them, and both are strictly necessary to provide the display you asked for, so no consent is required under § 25 (2) TDDDG. They stay on your device and are never sent to us.
On this website we set no advertising cookies, run no third-party trackers and embed no advertising. Clause 9 covers the advertising shown in the free version of the app.
Product analytics
We use no product analytics on this website. Which events the app reports is set out in clause 8.
4. Account and sign-in
Guest mode
You can use the core of the app — the nail and hand editors, your local design library, export, the AR try-on and the onboarding tour — without an account. In guest mode you choose a name and an avatar; both, together with the designs you make, are stored only on your device (the app’s local database and its preferences) and are never sent to us. If you delete the app, they are lost with it. If you sign in later, the designs you made as a guest are moved into your account and are backed up from then on.
An account is required only for: the AI designer, cloud backup and synchronisation of your designs, purchases, subscriptions and AI credits, the referral programme, and your profile. Sign-in is exclusively via Sign in with Apple or Sign in with Google (single sign-on / OAuth). We do not offer email-and-password registration and store no passwords.
We process as part of your account:
- email address and name, as provided by Apple or Google;
- your username and, optionally, a display name;
- your date of birth — required to complete profile setup, because we derive from it whether the age threshold in Article 8 GDPR applies to you (clause 9);
- profile and avatar data, and your theme setting;
- the authentication token from the sign-in service, to keep your session;
- technical session data: IP address and user agent of the active session.
With Sign in with Apple you can use Apple’s Hide My Email feature to give us only an anonymised forwarding address.
Legal basis: Article 6(1)(b) GDPR for providing the account, and Article 6(1)(f) GDPR for operating it securely. The sign-in providers are Apple Inc. and Google Ireland Limited; see Apple’s privacy policy and Google’s privacy policy.
5. Email
We send system and service messages to your email address — for example to confirm your address, or about your account or content moderation. Delivery runs over a mail server in the European Union (smtp.ionos.de). Legal basis: Article 6(1)(b) and (f) GDPR.
6. Your designs
Designs you create are stored on your device and, for backup and synchronisation between your own devices, on our servers. We store the design name, the design data, a preview image and any tags you assign.
Your designs are private. There is no public gallery and no community feed; they are not shown to other users. We do not use them for advertising. We use them to train our own models only if you have explicitly switched that on — see below. You can export a design and share it yourself.
Legal basis: Article 6(1)(b) GDPR.
AI designer
The AI designer is text-only: you describe the design in words, and we send that text and our own fixed design-catalogue prompt to OpenRouter, Inc., an AI-model broker that forwards the request to a model of the GLM family (built by Z.ai). It does not accept photos — the app no longer offers a way to attach one, and if an older version of the app still sends one, our backend discards it unread before it reaches OpenRouter, Inc. or any other provider. As you refine a design, the model is also shown renders of the design it has already produced, so it can see what it built — those are images of the design itself, not of you. We do not send anything about your account: no account id, name or email travels with the request, and the model is not told who is asking.
OpenRouter, Inc. is instructed to route the request only to hosting providers based in the United States that are contractually barred from storing the content or from training on it; the request is never routed to, and never processed in, China. Because processing takes place in the United States, this relies on standard contractual clauses in accordance with Article 46 GDPR. The broker’s own privacy policy is at https://openrouter.ai/privacy.
Neither OpenRouter, Inc. nor the hosting providers it routes the request to keep what you typed or the design renders, or use them to train models. We keep the text you typed ourselves, with your account — see clause 13 for how long.
The result is machine-generated. We mark it as an AI design in the app and store that marking with the design so it does not get lost. No automated decision about you is involved — what you get is a proposal you can accept, change or discard.
Legal basis: Art. 6 (1)(b) GDPR — generating the design is the service you asked for.
Training our own models
We would like to train our own model on the designs created in the app. This happens only with your explicit consent: the setting is off by default and lives in the app’s settings.
If you switch it on, we use the design document and nothing else — nail shape, colours, materials, which patterns and charms are used, and how they are arranged. We do not use the design’s name, your tags, the preview image or your account identifier. Nothing that links back to you is kept.
You can withdraw your consent at any time in the settings; withdrawal takes effect for the future. Data that has already been anonymised and folded into the corpus can no longer be attributed to any person, and therefore can no longer be picked out and removed. The lawfulness of processing carried out before withdrawal is unaffected.
Legal basis: Art. 6 (1)(a) GDPR.
7. Subscriptions
Purchases are processed by Apple and Google, who act as the seller. We receive a purchase and entitlement status so that we can unlock paid features for your account — not your payment details. We never see your card number or billing address.
We use RevenueCat, Inc. to keep that entitlement status consistent across your devices. The app configures RevenueCat with your account id, so that a purchase you make is recognised as yours; RevenueCat in turn provides us with your purchase and entitlement status, the app store transaction data needed to verify it, and technical device and app information. RevenueCat’s own privacy policy is at revenuecat.com/privacy.
Legal basis: Article 6(1)(b) GDPR.
8. App usage statistics
Named events
We count a small number of named events at the moment they happen. Two of them are reported by the app itself: the app being opened — at most once every six hours — and a design being exported. The rest arise on our server when the operation completes there: a saved design, a completed sign-up, the start, renewal or end of a subscription, the purchase of an AI credit pack, a redeemed referral, a request the AI designer refused, and an error on our side.
Each event carries only the few coarse details that operation needs — the platform (iOS or Android), the app version, the kind of editor, the subscription plan, the credit pack bought, the number of reward days granted, or the reason a subscription ended or a request was refused. Neither your account id nor your name, your email address, a device identifier or an advertising identifier is transmitted. The app’s report travels through our own interface and, while the request is in flight, technically belongs to your signed-in session; what is taken into the statistics is the event alone, without any identifier. Those statistics sit on our own server in the European Union; no outside provider is involved. Nothing is stored on your device for this.
Purpose: to see how many people actively use the app and which features are used. Legal basis: Article 6(1)(f) GDPR.
You can switch off the events reported by the app at any time under Settings → Anonymous statistics; the change takes effect immediately. The counts that arise on our server are not covered by that setting — they carry no identifier and cannot be attributed to you. You may object to them under Article 21 GDPR.
Aggregate business figures
Once a day we count, from our own database, how many accounts exist, how many of them are on the free or the paid tier, how long subscriptions run, how many people joined through a referral link, and how many designs accounts hold. These are totals and averages about all users together — they contain no name, no account id and nothing else that relates to you individually, and they are not passed to anyone. Legal basis: Article 6(1)(f) GDPR (understanding and running the service).
9. Advertising in the app
The free version of the app displays advertising delivered through Google AdMob. Every request we make is non-personalised: we do not read your device’s advertising identifier (IDFA on iOS, the advertising ID on Android), we do not build an advertising profile, and no ad is selected based on your behaviour or your interests — for every user, regardless of age. Apple’s App Tracking Transparency prompt is not shown, because the app does not track you across other companies’ apps or websites.
A consent message may still be shown before the advertising SDK starts, where one is required for your region under § 25 (1) TDDDG; it covers the technical access to your device described below, not ad personalisation — we do not offer personalised advertising to anyone. Whatever you answer, you continue to see only non-personalised advertising: declining does not remove ads, and agreeing does not unlock personalised ones. You can change your answer at any time under Settings → Ad privacy settings.
Even a non-personalised ad still requires Google Ireland Limited to process some technical data from your device — in particular your IP address, the approximate region derived from it, device and app information, and which ads were shown or interacted with — solely to deliver the ad, to avoid showing you the same one repeatedly, to account for delivery, and to detect fraud; not to recognise you or build a profile. Legal basis: our legitimate interest in a free version of the app that can pay for itself, Article 6(1)(f) GDPR, and § 25 (2) no. 2 TDDDG for the access to your device itself, because without capping, accounting and fraud detection the ad-financed free version you asked for cannot be delivered. You may object to the processing under Article 21 GDPR. The app is entirely free of advertising with MANQR Pro.
Google Ireland Limited is a controller in its own right for the advertising it delivers; its own privacy information is at https://policies.google.com/privacy. Processing in the United States is possible, based on the European Commission’s adequacy decision on the EU-US Data Privacy Framework and on standard contractual clauses.
Rewarded ads
You may choose to watch a rewarded ad to earn AI credits; the app shows you how many credits before you start. Once you have watched it to the end, the ad network confirms this directly to our server — a server-side verification carrying a transaction id and the reference that identifies your account — so that we can credit the right account. Because that confirmation depends on the ad network, we do not guarantee that a rewarded ad is always available. Legal basis: Article 6(1)(b) GDPR — crediting your account is the service you asked for by choosing to watch the ad.
MANQR Pro removes advertising entirely. For a subscriber no ad is requested and no data reaches the ad network.
10. Camera
If you use the try-on feature, the camera image is processed on your device in order to place the design on your hand. The camera feed is not transmitted to us and not stored. Access requires the operating system permission you grant, which you can withdraw at any time in your device settings.
The AI designer described in clause 6 does not use your camera or photo library — it works from the text you type. No photo of you is sent to us or to OpenRouter, Inc. for this purpose.
The app writes to your photo library only what you export yourself. That access, too, requires a permission from the operating system, which you can withdraw at any time.
11. Recipients
We do not sell personal data. Apart from the advertising described in section 9, where Google Ireland Limited is the recipient, we do not pass it on for advertising. Otherwise data is disclosed only to:
- our hosting provider in the European Union, under a data processing agreement (Article 28 GDPR);
- IONOS SE, as our email service provider (section 5);
- Apple and Google, as sign-in providers and as sellers of subscriptions;
- RevenueCat, Inc., to keep your subscription and purchase status consistent across your devices (section 7);
- public authorities, where we are legally obliged to disclose.
- OpenRouter, Inc. as the broker for the AI model, together with the US-based inference providers it may route your request to (DeepInfra, Together AI, Fireworks, Baseten, Parasail, CoreWeave, Crusoe and DigitalOcean) — each contractually barred from storing the content or training on it — solely for generating a design as described in section 6.
12. Transfers outside the EU/EEA
Our own infrastructure — hosting, email and analytics — is located in the European Union.
Sign-in and payments necessarily involve Apple and Google, which may process data in the United States. Both rely on the European Commission’s adequacy decision for the EU–US Data Privacy Framework and on standard contractual clauses. If you sign in with Apple’s Hide My Email, less data reaches us in the first place.
RevenueCat, Inc. is based in the United States, and the subscription and purchase status described in section 7 may be processed there. This relies on standard contractual clauses in accordance with Article 46 GDPR.
If you use the AI designer, the text you typed and our design-catalogue prompt are transmitted to OpenRouter, Inc., which routes them only to hosting providers based in the United States that are contractually barred from storing or training on the content, and never to hosts in China. This transfer relies on standard contractual clauses in accordance with Article 46 GDPR. If you do not use the feature, no such transfer takes place.
13. Retention
- Account data: until you delete your account.
- Designs: until you delete them, or until you delete your account.
- Session data: until the session expires or you sign out.
- Server logs: a short period, then deleted.
- Abuse and rate-limit counters: one counter per IP hash or account for the length of a short window; it is overwritten afterwards.
- Security records: where something has to be noted to prevent abuse — a referral redemption we want to look at, or the fact that an account was deleted — that entry is kept for 90 days and then erased. It holds an irreversible hash of the IP address and the account reference of the event, nothing you wrote or made.
Where statutory retention periods apply — for example under tax or commercial law — we retain the data concerned for as long as those periods require and restrict its processing in the meantime.
- AI session and credit records: for as long as your account exists, since they evidence what was charged.
- Training corpus: indefinitely, but only in anonymised form with no link to you.
- What you typed into the AI designer: the text you entered is stored with the session for as long as your account exists — it is the record of what a credit was spent on.
- AI call logs: at most 30 days. They contain the text entered and the model’s answer, but are grouped only by a peppered hash of the session and are not linked to any account.
14. Deleting your account
You can delete your account at any time in the app, or ask us to delete it by emailing support@manqr.app. Deletion removes your account and profile data, sessions, linked sign-in accounts, notifications, tags, your designs together with their files, and your AI designer sessions with what you typed into them, your credit balance and its ledger.
What deletion does not reach. Not every record is linked to your account, and what is kept without that link cannot be reached by deleting the account either:
The AI call logs named in clause 13 carry no account identifier. They are not deleted with your account but automatically, after 30 days at the latest.
When a referral link is redeemed we store an irreversible hash of your Apple or Google sign-in identifier. It contains neither your email address nor your name, cannot be reversed, and serves only to ensure that one person can redeem a referral link exactly once. That is precisely why it outlives deletion of the account — otherwise the reward could be triggered again and again by deleting and signing up afresh. We use it for no other purpose.
We also note the fact that the account was deleted, together with its account id, so that deleting an account cannot be used to shake off an abuse investigation or to claim a referral reward a second time. That note is erased after 90 days (clause 13).
Beyond that we retain what we are legally required to retain (clause 13).
15. Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Article 15);
- rectification of inaccurate data (Article 16);
- erasure (Article 17);
- restriction of processing (Article 18);
- data portability — to receive your data in a structured, commonly used, machine-readable format (Article 20);
- object to processing based on legitimate interests, on grounds relating to your particular situation (Article 21);
- withdraw consent at any time, with effect for the future (Article 7(3)).
An email to support@manqr.app is enough to exercise any of these. We respond within one month.
16. Complaints
You can lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work, or the place of the alleged infringement (Article 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 27
91522 AnsbachPhone: +49 981 180093-0
Email: poststelle@lda.bayern.de
Web: https://www.lda.bayern.de
17. Automated decision-making
There is no automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not carry out profiling. The AI designer described in section 6 produces a design proposal; it does not make a decision about you.
18. Changes
We update this policy when the service or the law changes. The current version is always available at this address; the date at the end of this page tells you when it last changed.