Privacy Policy — Tin Can Smartphone

Binding language: German. In the event of any conflict between language versions, only the German version is legally binding.

This Privacy Policy explains how Albrecht Apps GmbH (“we”, “us”) processes personal data when you use Tin Can Smartphone (www.tincansmartphone.com, the REST API, MCP endpoint, and the Android and iOS companion apps — together the “Service”).

Version 2026-08-18 · Effective: 18 August 2026

B2B offering. The Service is directed exclusively at entrepreneurs (Section 14 BGB), not at consumers. The German version is legally controlling; this English text is a convenience translation.

Controller / Verantwortlicher
Albrecht Apps GmbH
Falkenstraße 9
49610 Quakenbrück
Germany
E-Mail: hello@tincansmartphone.com
Company details: Imprint

We have not appointed a data protection officer. For privacy requests, contact us at the address above or via our contact form.

1. Categories of data

  • Account and profile data (e.g. name, email, login credentials, organisation).
  • Billing and contract data if you purchase a paid plan.
  • Device and SIM metadata (e.g. device identifiers, app version, connection status, phone numbers you register).
  • Message and signalling data needed to operate the gateway (destination/sender numbers, timestamps, delivery status, and message content you send or receive through the Service).
  • API / MCP usage data (tokens, tool calls, approval decisions, audit logs).
  • Technical logs (IP address, user agent, request paths, error logs) and, where used, analytics/cookie data.
  • Communication you send us (support emails, contact form).

2. Purposes and legal bases (GDPR)

  • Providing the Service, accounts, API, webhooks, MCP tools, and Android sync — Art. 6(1)(b) GDPR (contract).
  • Security, abuse prevention, billing, bookkeeping, and legal compliance — Art. 6(1)(c) and/or (f) GDPR.
  • Product improvement and aggregated statistics — Art. 6(1)(f) GDPR (legitimate interests).
  • Optional analytics or marketing cookies/tools only with your consent — Art. 6(1)(a) GDPR; you may withdraw consent at any time.

3. SMS content

Message content is processed to deliver the Service you requested. You are the controller of SMS content you initiate for your own customers or end users; you must have a lawful basis to send those messages. We process that content as needed to relay, store temporarily for delivery/retry, and show it in your account. Do not use the Service for unlawful content.

4. Android app

The Android companion app needs permissions to send and receive SMS (and related connectivity) on your device. Data leaves the device only as required to authenticate, sync queue state, and exchange messages with our servers under your account.

4a. Optional crash reporting in the apps

In the Android and iOS apps you may optionally enable “Share crash reports” under Settings (off by default in production/release builds; development builds may enable it by default for testing). If you turn this on, technical crash and error diagnostics (for example stack traces, device model, OS version, and app version) may be sent to our error-monitoring provider (Sentry, which we may operate ourselves or via a hosted service) so we can fix bugs. When sharing is off, the app still keeps a local technical note of a crash on the device and may ask on the next launch whether you want to send that report (and optionally always share thereafter). We configure the SDK not to send SMS message content or default personally identifying contact data. Legal basis: your consent — Art. 6(1)(a) GDPR (and, for development builds where reporting is on by default, our legitimate interest in diagnosing defects during development — Art. 6(1)(f), limited to non-production builds). You can withdraw or change this at any time in Settings; when off, no further reports are sent from that device unless you approve a one-time prompt.

5. Cookies and similar technologies

We use essential cookies for login, security, language, and cookie-consent state (Section 25(2) TDDDG). On production sites we may use Google Analytics and self-hosted PostHog (ingest at ingest.analytics.albrecht-apps.com; first-party cookies such as ph_*) to understand traffic and product usage; where required we load such tools only after consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG; Google Consent Mode / cookie banner). You can withdraw or change your choice at any time via Cookies in the website footer. You can also change browser settings to limit cookies; essential cookies may be required for the Service to work.

6. Recipients and processors

We host the website and core application data with Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany (predominantly Nuremberg). Payments run through Stripe (Stripe Payments Europe, Limited / Stripe, Inc.). Further infrastructure and service providers (email, error monitoring) are bound by data-processing agreements where required. Data is primarily processed in the EU/EEA. If a transfer to a third country occurs, we use an adequacy decision, the EU-US Data Privacy Framework or appropriate safeguards (e.g. EU Standard Contractual Clauses).

6a. Email address checks (anti-abuse)

When you submit an email address on signup, contact, password reset, or newsletter forms, we may check that address with an email validation service (currently Mailboxlayer / apilayer, or Mailgun Validate as an alternate) to reject disposable, malformed, or undeliverable addresses and protect our mail infrastructure. The address (and technical result metadata) may be processed by that provider for the check. We cache the result for a limited period. Outbound product or marketing email is only sent after you confirm ownership of the inbox (double opt-in / account email verification), except for the confirmation message itself and messages to our company inboxes.

6b. Email opens and link clicks

When we are allowed to send you product or marketing email, we measure opens and link clicks with our own tracking links and a one-pixel image (Art. 6(1)(f) GDPR) to improve delivery and content. Measurement runs on our servers; aggregated events may appear in our self-hosted PostHog project with surface mail, without your email address as an event property. Unsubscribing stops marketing sends and thus this measurement.

7. Retention

We keep account and contract data for the life of the account and as required by commercial/tax law. Message and technical logs are kept only as long as needed for delivery, support, security, and statutory duties, then deleted or anonymised. Signed-in users can start deletion from Account → Delete account (also in the Android app under Settings). We ask what we can improve first so we can try to help; you can still continue and close access. Email and plan records may be kept until the current billing period ends, and as required by commercial/tax law.

8. Your rights

Under the GDPR you may have the right to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent. You may lodge a complaint with a supervisory authority (for Lower Saxony, Germany: Landesbeauftragte für den Datenschutz Niedersachsen).

9. Security

We apply technical and organisational measures appropriate to the risk (access control, encryption in transit, least-privilege access). No method of transmission or storage is completely secure.

10. Children and audience

The Service is directed exclusively at businesses and adult professional users, not at consumers and not at children. We do not knowingly collect data from children under 16.

11. Changes

We may update this Privacy Policy when our processing changes. The current version is always published on this page. Material changes that require your action will be communicated appropriately.

12. Related documents

Terms of Service · Imprint · © 2026 Albrecht Apps GmbH