Last updated: 21 September 2026 · Applies to the Gestari iPhone app and to this website.
The German version at gestari.app/privacy is the binding one; this is a translation for convenience.
No data protection officer has been appointed; the conditions requiring one are not met.
Gestari is built so that almost nothing leaves your device. There is no account, no sign-in and no synchronisation. If you use the app without AI suggestions, no content is sent to any server at all.
This data sits in a database on your iPhone. It is not uploaded, not backed up by me, and I cannot see it:
Delete the app and this data goes with it. A backup of your iPhone via iCloud or a computer may however contain the database — that depends on your iOS settings, not on the app.
In Gestari you enter details about third parties: your mother, friends, colleagues. As long as you do this for private purposes, the GDPR household exemption applies (Art. 2(2)(c)) and the regulation does not apply to you. Regardless: do not enter anything the person would not want to see written down by you — especially no health data, religious or political details. If you use AI suggestions, these notes go to a service (section 4).
The app asks you explicitly first. Without your consent nothing is transmitted, and you can decline without losing the app: it then keeps suggesting ideas without AI.
| Field | Example |
|---|---|
| Relationship to you | mother |
| Country of the person | AT |
| Interface language | de |
| Occasion and days until it | mothers_day, 12 |
| Budget and currency | 5000, EUR |
| Interests | gardening, coffee |
| Hints and notes | your free text |
| Gift history with feedback | 2024, Christmas, secateurs, went down well |
The request goes to a server function of mine at Supabase. That function assembles a request to Anthropic and returns the three suggestions. The content of your request is not stored on my server — only the counters described in section 5 live there.
Both companies act as processors: they process the data solely on my behalf and on my instructions, not for their own purposes. Each is covered by a data processing agreement.
On Supabase's side my contracting party is Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. The data is stored in region eu-west-1 in Ireland and, under clause 6.1 of the data processing addendum, primarily processed there as well. The subprocessors Supabase uses are listed publicly.
On Anthropic's side my contracting party is Anthropic Ireland, Limited, which serves customers in the EU. The Commercial Terms of Service apply, together with the Data Processing Addendum, which forms part of the contract through those terms. Those contracts govern what may happen to the transmitted data. Anthropic's privacy policy for consumers explicitly does not cover use through the programming interface and is irrelevant here.
What Gestari sends is not used to train AI models. The Commercial Terms commit Anthropic to exactly that: "Anthropic may not train models on Customer Content from Services." Customer Content covers both directions — what the app sends and what comes back.
The legal basis for the processing is your consent (Art. 6(1)(a) GDPR), given in the app. You can withdraw it at any time in the app settings. Withdrawal applies going forward; it does not affect what was transmitted before.
Both processors are based outside the EU, and in both cases the European Commission's Standard Contractual Clauses safeguard the transfer (Art. 46(2)(c) GDPR):
The transfer deliberately does not rely on the derogation in Art. 49(1)(a) GDPR: according to the European Data Protection Board's guidelines, that derogation is meant for occasional, non-repetitive transfers — whereas here data is transferred for every suggestion.
For neither country has the European Commission found the level of data protection to be equivalent. Even with Standard Contractual Clauses a residual risk therefore remains: authorities may access data under certain conditions without you having a judicial remedy to the same extent as in the EU. That is precisely why the app asks first, why the person's name never goes along, and why the app keeps working without AI suggestions.
So that nobody can drain the server function at my expense, each installation receives an anonymous identifier from Supabase on its first AI request. This is not an account: there is no email address, no password and no name.
The server holds only:
No interests, no hints, no names. The legal basis is my legitimate interest in protection against abuse and unbounded cost (Art. 6(1)(f) GDPR).
Every idea comes with a search link to Amazon containing an affiliate tag. Only when you tap it does your system browser or the Amazon app open the page — the app itself does not call Amazon and loads no content from there. From that moment Amazon's privacy policy applies: Amazon learns of your visit including the affiliate tag and may set cookies to attribute a later purchase.
As an Amazon Associate I earn from qualifying purchases.
At your explicit request the app reads birthdays from your birthday calendar to suggest people you might want to add. Only that calendar is read, only at that moment, and only on the device. None of it is transmitted. Without your iOS permission nothing happens at all.
Reminders before an occasion are scheduled locally on your device only. There is no push service, no device token and no server that knows when anyone has a birthday.
Gestari contains no analytics, advertising or tracking components, no crash reporting and no advertising identifier. There is no user profile and no automated decision-making with legal effect.
gestari.app is hosted on Cloudflare Pages (Cloudflare, Inc.). The pages are static, contain no JavaScript and set no cookies. When you visit, Cloudflare processes technically necessary connection data such as your IP address in order to deliver the page and fend off attacks (Art. 6(1)(f) GDPR). Cloudflare governs the details under its own responsibility.
You have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR), as well as withdrawal of consent.
For the data on your device you exercise these rights directly yourself: you see it in the app, can change it, and remove it entirely by deleting the app. For the anonymous identifier I cannot help you without further detail, because I cannot link it to a person (Art. 11 GDPR); in that case tell me the identifier from the app settings.
You may also lodge a complaint with a supervisory authority, in Austria the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
If what the app processes changes, this policy changes with it. The date at the top tells you which version you are reading.