Gestari

Privacy Policy

Last updated: 21 September 2026 · Applies to the Gestari iPhone app and to this website.

The German version at gestari.app/privacy is the binding one; this is a translation for convenience.

1. Controller

Name
Cédric Kurek
Address
Gölsdorfgasse 2/2, Tür 29, 1010 Wien, Austria
Email
[email protected]

No data protection officer has been appointed; the conditions requiring one are not met.

2. The principle first

Gestari is built so that almost nothing leaves your device. There is no account, no sign-in and no synchronisation. If you use the app without AI suggestions, no content is sent to any server at all.

3. What stays on your device only

This data sits in a database on your iPhone. It is not uploaded, not backed up by me, and I cannot see it:

Delete the app and this data goes with it. A backup of your iPhone via iCloud or a computer may however contain the database — that depends on your iOS settings, not on the app.

Data about other people

In Gestari you enter details about third parties: your mother, friends, colleagues. As long as you do this for private purposes, the GDPR household exemption applies (Art. 2(2)(c)) and the regulation does not apply to you. Regardless: do not enter anything the person would not want to see written down by you — especially no health data, religious or political details. If you use AI suggestions, these notes go to a service (section 4).

4. When you ask for AI suggestions

The app asks you explicitly first. Without your consent nothing is transmitted, and you can decline without losing the app: it then keeps suggesting ideas without AI.

What is sent

FieldExample
Relationship to youmother
Country of the personAT
Interface languagede
Occasion and days until itmothers_day, 12
Budget and currency5000, EUR
Interestsgardening, coffee
Hints and notesyour free text
Gift history with feedback2024, Christmas, secateurs, went down well

What is not sent

Who processes the data

The request goes to a server function of mine at Supabase. That function assembles a request to Anthropic and returns the three suggestions. The content of your request is not stored on my server — only the counters described in section 5 live there.

Both companies act as processors: they process the data solely on my behalf and on my instructions, not for their own purposes. Each is covered by a data processing agreement.

On Supabase's side my contracting party is Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. The data is stored in region eu-west-1 in Ireland and, under clause 6.1 of the data processing addendum, primarily processed there as well. The subprocessors Supabase uses are listed publicly.

On Anthropic's side my contracting party is Anthropic Ireland, Limited, which serves customers in the EU. The Commercial Terms of Service apply, together with the Data Processing Addendum, which forms part of the contract through those terms. Those contracts govern what may happen to the transmitted data. Anthropic's privacy policy for consumers explicitly does not cover use through the programming interface and is irrelevant here.

No training on what you enter

What Gestari sends is not used to train AI models. The Commercial Terms commit Anthropic to exactly that: "Anthropic may not train models on Customer Content from Services." Customer Content covers both directions — what the app sends and what comes back.

Legal basis

The legal basis for the processing is your consent (Art. 6(1)(a) GDPR), given in the app. You can withdraw it at any time in the app settings. Withdrawal applies going forward; it does not affect what was transmitted before.

Transfer to the USA

Both processors are based outside the EU, and in both cases the European Commission's Standard Contractual Clauses safeguard the transfer (Art. 46(2)(c) GDPR):

The transfer deliberately does not rely on the derogation in Art. 49(1)(a) GDPR: according to the European Data Protection Board's guidelines, that derogation is meant for occasional, non-repetitive transfers — whereas here data is transferred for every suggestion.

For neither country has the European Commission found the level of data protection to be equivalent. Even with Standard Contractual Clauses a residual risk therefore remains: authorities may access data under certain conditions without you having a judicial remedy to the same extent as in the EU. That is precisely why the app asks first, why the person's name never goes along, and why the app keeps working without AI suggestions.

5. Anonymous identifier and abuse protection

So that nobody can drain the server function at my expense, each installation receives an anonymous identifier from Supabase on its first AI request. This is not an account: there is no email address, no password and no name.

The server holds only:

No interests, no hints, no names. The legal basis is my legitimate interest in protection against abuse and unbounded cost (Art. 6(1)(f) GDPR).

6. Amazon affiliate links

Every idea comes with a search link to Amazon containing an affiliate tag. Only when you tap it does your system browser or the Amazon app open the page — the app itself does not call Amazon and loads no content from there. From that moment Amazon's privacy policy applies: Amazon learns of your visit including the affiliate tag and may set cookies to attribute a later purchase.

As an Amazon Associate I earn from qualifying purchases.

7. Calendar

At your explicit request the app reads birthdays from your birthday calendar to suggest people you might want to add. Only that calendar is read, only at that moment, and only on the device. None of it is transmitted. Without your iOS permission nothing happens at all.

8. Notifications

Reminders before an occasion are scheduled locally on your device only. There is no push service, no device token and no server that knows when anyone has a birthday.

9. No tracking

Gestari contains no analytics, advertising or tracking components, no crash reporting and no advertising identifier. There is no user profile and no automated decision-making with legal effect.

10. This website

gestari.app is hosted on Cloudflare Pages (Cloudflare, Inc.). The pages are static, contain no JavaScript and set no cookies. When you visit, Cloudflare processes technically necessary connection data such as your IP address in order to deliver the page and fend off attacks (Art. 6(1)(f) GDPR). Cloudflare governs the details under its own responsibility.

11. Retention

12. Your rights

You have the rights of access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR), as well as withdrawal of consent.

For the data on your device you exercise these rights directly yourself: you see it in the app, can change it, and remove it entirely by deleting the app. For the anonymous identifier I cannot help you without further detail, because I cannot link it to a person (Art. 11 GDPR); in that case tell me the identifier from the app settings.

You may also lodge a complaint with a supervisory authority, in Austria the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.

13. Changes

If what the app processes changes, this policy changes with it. The date at the top tells you which version you are reading.