Privacy Policy

Last updated: July 2026

⚠ Before publishing, fill in the controller and every sync-provider detail. The website currently uses no cookies or tracking, but the app contains optional account sync. Do not enable it commercially until provider, legal basis, processing agreement, storage location, deletion and data-subject rights are fully documented here. Billing and analytics are not built. This English version is a courtesy translation; the German version is legally controlling.

1. Data controller

[First and last name]
[Street and house number]
[Postal code and city], Germany
Email: [contact@fennig.app]

2. The short version

This website is a static information page. It uses no cookies, no tracking, no analytics services, and embeds no third-party content (fonts are self-hosted; no Google Fonts or CDNs are loaded). There are no contact forms and no registration.

3. Hosting and server log files

This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit the site, Vercel processes technically necessary data (in particular IP address, date and time of access, requested URL, user agent) to deliver the page and ensure operational security. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation of the website).

Vercel may process data in the USA. This transfer relies on the EU Standard Contractual Clauses (Art. 46 GDPR) and the EU-US Data Privacy Framework, of which Vercel is a participant. A data processing agreement (DPA) under Art. 28 GDPR is in place with Vercel.

4. The Fennig app itself

Fennig is local-first. In local mode, business data (invoices, clients, expenses and tax data) is stored in IndexedDB in your browser, on your own device; no account is required. If you explicitly enable optional account sync and it is configured for production, synced business records are sent to the configured Dexie Cloud service. API keys and local backup-folder permissions are excluded from sync.

If you use the optional AI receipt recognition with your own API key, the receipts you select are sent directly from your device to the provider you configured (e.g. Google Gemini, Anthropic, OpenAI, or a local Ollama model). This processing happens at your initiative and under your responsibility; the respective provider's privacy terms apply. If you use a local model, receipts never leave your device.

5. Your rights

Under GDPR, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6(1)(f) (Art. 21) against the data controller. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77), e.g. the authority responsible for the controller's state (Bundesland) in Germany.

6. Changes

Before public account sync is enabled, this policy must name Dexie Cloud and every other processor and state the applicable processing details. Before billing, hosted AI or analytics launch, it must also cover the Merchant of Record/payment provider, AI providers, data transfers and retention.