Legal

Privacy
Policy

Last updated: 2026-07-08 · architect-dna.ch and all subdomains

Privacy-first by default. Where an app genuinely needs server-side data to work — like showing you who's nearby — we disclose exactly what's stored and for how long, instead of pretending otherwise.

Most apps: no cookies, no accounts, everything stays in your browser No advertising networks, no fingerprinting, no data resale — anywhere Audio synthesis (VOID FREQ, Noise) runs entirely in your browser Encryption (LIA) is client-side — only ciphertext stored GPS coordinates (VELO NOIR) never transmitted Zugcafé is the exception — it stores nickname, activity type, and location server-side to show you what's nearby. Details below. Einspruch uses Vercel Analytics (cookieless) and Stripe for premium payments. Details below.

Scope

This policy applies to all services under architect-dna.ch and its subdomains, as well as native mobile apps published by Architect-DNA: VOID FREQ (iOS), VOID CELL (Nexus Breach, Grid Fall, Sector Zero), Rida, Konnekt, Noise, Prompt Vault, LIA, CV Card, VELO NOIR, Podcast DNA, TACZ, Zugcafé, Einspruch, and any future services.

Data We Collect — Most Apps

Most services collect no personal data. Specifically:

  • User settings, API keys, ride logs, and mission progress are stored in your browser's localStorage on your own device — never on our servers.
  • GPS coordinates (VELO NOIR) are used locally to render the map and are never transmitted to any server.
  • Passkey credentials are managed entirely by your device's authenticator via WebAuthn. We do not receive or store biometric data.
  • Rider cards and crew codes (VELO NOIR) are text strings you share manually — we do not relay or store them.
  • Konnekt profiles are encoded in the share URL itself — no profile data is stored on any server.
  • Noise and VOID FREQ audio is synthesized locally via the Web Audio API — no audio data is transmitted.

Zugcafé — Server-Side Data (Exception)

Zugcafé is the one app that genuinely needs a server, because it shows you real people near you right now. We store, on a Supabase server:

  • The nickname you choose (not tied to any account — just a name you type in).
  • A random device identifier stored in your browser, used only to recognize "your" posts — not linked to your identity.
  • The activity type, note, and precise GPS coordinates you post when sharing that you're open for coffee, a card game, or company.
  • Chat messages sent inside a Room, and any Room's approximate location (used only to keep the Rooms list local and recent).

"Activities" (the nearby feed posts) expire and stop being shown after 5 minutes. Rooms disappear from the public browse list after 24 hours or once you're more than 5km away, but a room's direct link — and its message history — is not automatically deleted, so anyone who already has the link can still open it later. Anyone with a room's URL can read that room's messages; there is no per-user access control. Do not share anything in a Zugcafé chat you wouldn't want a stranger with the link to read.

Einspruch — Payments and Analytics (Exception)

  • Einspruch uses Vercel Analytics, a cookieless, non-fingerprinting page-view analytics tool, to see aggregate usage. It does not set cookies or track you across sites.
  • Premium letter credits are purchased via Stripe — we never see or store your card details. Stripe's own privacy policy applies to payment processing: stripe.com/privacy.
  • Your drafted letter text is sent to an AI provider (Anthropic Claude for premium, Groq/Llama for the free tier) to generate the letter. See the Third-Party Services section below. We do not store your letter content on our servers after the response is returned.

Authentication (Passkeys)

Passkey-enabled applications use the WebAuthn / FIDO2 standard with the PRF extension for key derivation. Your private key never leaves your device. We store only a credential ID in localStorage. No biometric data is accessible to us at any point.

LIA — Legal Vault

LIA stores encrypted evidence documents. All encryption is performed client-side before any data is persisted. Only ciphertext is stored — the decryption key never leaves your device and is never accessible to us.

Cookies and Tracking

  • We do not use cookies anywhere, on any app.
  • The only analytics used anywhere in the portfolio is Vercel Analytics on Einspruch — cookieless, no cross-site tracking. No other app has any analytics or tracking script.
  • We do not use advertising networks, on any app.
  • We do not fingerprint your device or browser, on any app.

Third-Party Services

Some applications use Anthropic Claude and/or Groq (Llama models) APIs for AI features — including the PulseBot chat widget on this site, and Einspruch's letter generation. When you use one of these features, your input is transmitted to that provider's servers. See anthropic.com/privacy and groq.com/privacy-policy. We do not store AI conversation history on our end.

Zugcafé's data (see above) is hosted on Supabase. See supabase.com/privacy.

Einspruch's payments are processed by Stripe. See stripe.com/privacy.

Map tiles are loaded from OpenStreetMap servers. Your IP address may be visible to OSM when fetching map tiles.

The site is hosted on Vercel. Vercel may log request metadata (IP, user agent) per their infrastructure policy. See vercel.com/legal/privacy-policy.

Data Retention and Deletion

For apps that store data only in your browser, clearing your browser's site data (or using an in-app reset) deletes it completely — there is no server-side copy to remove.

For Zugcafé, activity posts expire automatically after 5 minutes. Room and message data is not on an automatic deletion schedule; contact us to request deletion of a specific room or message.

Your Rights (GDPR / nDSG)

As a user in Switzerland or the EU, you have the right to access, correct, and delete any personal data we hold. For most apps, all data is already stored locally on your device and you're already in full control. For Zugcafé data or Einspruch payment records, contact us and we will act on your request.

Contact

Architect-DNA · Bern, Switzerland
systems@architect-dna.ch

Privacy policy changelog 4 versions
v4.0 2026-07-08 — Current
ADDZugcafé added to scope. Unlike every other app, it stores nickname, activity/note, and precise GPS location server-side (Supabase) so it can show nearby posts — disclosed explicitly rather than folded into the "no server-side data" claim.
ADDEinspruch added to scope, including Stripe payment processing and Vercel Analytics (cookieless) — corrects the prior blanket "no analytics" statement, which was no longer accurate once Einspruch shipped.
ADDGroq (Llama models) disclosed as an AI provider, used by the PulseBot widget on this site and Einspruch's free tier.
ADDSupabase disclosed as Zugcafé's hosting provider for server-side data.
UPDPage restyled to match the current architect-dna.ch light theme (was a legacy dark purple/teal palette).
v3.0 2026-05-21
ADDVOID FREQ now available as native iOS app on the App Store — no additional data collection beyond web version
ADDRida added to scope: fasting tracker, all data in localStorage, no server-side storage
UPDScope clarified to include native mobile apps alongside web services
v2.0 2026-05-17
ADDAdded Noise app coverage: Web Audio synthesis, no audio data transmitted
ADDKonnekt: clarified that profiles are URL-encoded, no server storage
ADDVercel infrastructure disclosure added to third-party services
ADDnDSG (Swiss new Data Protection Act) reference added alongside GDPR
UPDExpanded scope to include VOID FREQ, VOID CELL game titles, and Noise
UPDStandalone page at architect-dna.ch/privacy (was inline section only)
v1.0 2025-09-01 — Initial
ADDInitial privacy policy covering VELO NOIR, Podcast DNA, TACZ, Prompt Vault, LIA, Konnekt, CV Card
ADDWebAuthn / FIDO2 passkey section
ADDLIA client-side encryption disclosure
ADDCookies and tracking: confirmed none used
ADDGDPR rights section for Swiss/EU users
ARCHHosted as inline collapsible section within architect-dna.ch main page