thadwi studio
Spurando

Privacy Policy

1. Controller

Thomas Wittek
Buchenweg 38, 66424 Homburg, Germany
Email: hello@thadwi.studio

2. Hosting of this website

This website is hosted by Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA; delivered through Cloudflare data centres in the EU). When you visit it, server log files are processed automatically (IP address, timestamp, pages requested, volume of data transferred, browser and operating system identifiers). The legal basis is our legitimate interest in the secure and uninterrupted operation of the site, Art. 6(1)(f) GDPR.

Retention: We do not store these log files and have no access to the raw data. Cloudflare processes them, according to its own statements, to operate and protect the site and deletes them according to its own retention policy, generally within a few days. No further analysis is carried out by us.

Transfer to the USA: Cloudflare, Inc. is based in the United States. Cloudflare is certified under the EU-U.S. Data Privacy Framework; in addition, we have a data processing agreement with Cloudflare that incorporates the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Cloudflare's privacy policy is available at cloudflare.com/privacypolicy.

3. Spurando — data processing in the app

Spurando was deliberately built without any server infrastructure of our own. There is no user account, no sign-in with us and no transfer of your trip data to us. Your record is kept on your device. Data leaves your device only in the following cases, each described individually below: through your operating system's location services during a recording (with full automation switched on, additionally for a coarse wake-up location fix and — on Android — through the activity recognition of Google Play services), through the address suggestion, which you can switch off (start and destination coordinate of a GPS trip sent to your system's map service), through the time anchoring, which you can switch off (a hash value — and, for technical reasons, your IP address — sent to a timestamp service), through the optional cloud synchronisation into your own Apple or Google account, and through the device backups that your operating system creates according to your system settings. Everything else — backup files and exports — is passed on only by you, through your device's share dialog. Spurando contains no analytics, tracking or advertising services.

Where Apple or Google are named below, this means your contracting partner for iOS or Android respectively: Apple Distribution International Ltd. (Cork, Ireland) or Google Ireland Ltd. (Dublin, Ireland). Both process this data under their own responsibility in accordance with their privacy policies (apple.com/legal/privacy, policies.google.com/privacy) and may also process it in the USA (Apple Inc. or Google LLC); the safeguards they use for this are disclosed there.

What the app processes: the trips you record — date, odometer reading at the start and at the end, trip type (business, private, commute) and, for business trips, destination, purpose and business partner. For GPS trips, the start and destination coordinates and the route are added; the app also notes for each trip how it was recorded (manually, via GPS or automatically). The record is kept as a continuously chained list: corrections and cancellations are appended as new entries together with your reason and do not replace the old entry. If you record a trip eight or more days after the trip date, you can give a "reason for late entry"; from the 31st day on, you must. The reason is noted with the trip. In addition, there are your vehicles (label, licence plate, activation history with reasons), receipts (see "Receipts") and — only if you enter them — the tax details for the header of the export: holder name, company and tax number. These tax details are not synchronised and are not part of the app's backup file; they are, however, part of your operating system's device backup (see "Storage location and device backups").

To protect professional secrecy, you can specify that destination, purpose or business partner are replaced by a placeholder in the export; for this the app stores your reason (e.g. "medical confidentiality") and the affected trips. The plain-text details remain in the record. This reason appears in the export at every redacted spot and in the record description — choose it so that it does not itself reveal any client. Note on business partners: names of customers or contacts that you enter into trips are personal data of third parties; you are yourself responsible for recording them and for passing them on in the export. Legal basis: Art. 6(1)(b) GDPR (use of the app function).

Storage location and device backups: Your trips, vehicles, receipts and settings are held in the app's private storage on your device. On iOS only the app itself accesses it; the Live Activity on the lock screen receives from the app merely the licence plate and label of the vehicle, the current odometer reading of the ongoing recording and whether the first GPS fix has been obtained — there is no shared storage (app group). On Android everything is held in the private application storage, which only Spurando accesses; the system notification of an ongoing recording shows the licence plate and label of the vehicle as well as the kilometres, also on the lock screen. Both displays are — like any lock-screen display — visible to anyone holding the device. Retention: the data stays on your device until you delete it in the app or remove the app. The trip record itself is not shortened in the process — trips are cancelled, not deleted (see "Your rights").

If you back up your device using the operating system's backup function, the record and the associated timestamp tokens are part of that backup: the chained trip record (including addresses, business partners and start/destination coordinates), the timestamp tokens, the vehicles with their history, professional-secrecy settings, reasons for late entry, recording methods, the tax details, the app's toggle settings and — if chosen — the car Bluetooth device for automation (its name; on Android also its Bluetooth address), and on Android the note of which late-entry reminders have already been shown. This is intentional — otherwise, if you changed devices without synchronisation switched on, you would lose your entire logbook. Deliberately excluded on both platforms are the complete GPS routes (your location history), the receipt photos and the receipt details; they stay on this device unless you take them along via the app's backup file. On iOS the device backup is the iCloud backup or a backup via Finder/iTunes (Apple); on Android it is the auto-backup into your Google account (Google Drive) and the direct device-to-device transfer when setting up a new device. These backups are held in your own account with the respective provider — a Finder/iTunes backup on your computer; we have no access to them, and the privacy policies of Apple or Google apply. You control whether your device creates backups in the system settings (iOS: Settings → [your name] → iCloud → iCloud Backup; Android: Settings → Google → Backup). Legal basis for local storage: Art. 6(1)(b) GDPR.

Location data (optional, for route recording): When you start a GPS recording, the app continuously determines your location in order to establish the route, the start point and the destination. The complete route stays on the device as an attachment to the trip — it is neither synchronised nor included in the device backup nor exported; only the app's backup file contains it. The start and destination coordinates, by contrast, become part of the trip entry and thus of the device backup, the backup file and — if switched on — the cloud synchronisation. Positioning runs during a recording; with full automation switched on, additionally as a coarse wake-up location fix (see "Automatic trip detection"). Positioning is carried out by your operating system's location service, which can use Wi-Fi and mobile network data in addition to GPS — on iOS Apple's Location Services, on Android the location service of Google Play services. What these services transmit to Apple or Google in the process is governed by their privacy policies; the app itself does not send positions to any server of its own. The app requests the permission only when the first recording starts, via the system dialog (iOS: location "While Using the App"; Android: "Location" and, from Android 13, additionally "Notifications" so that the ongoing recording is visible as a notification). You can recognise an ongoing background recording on iOS by the blue status bar and the Live Activity on the lock screen, on Android by the persistent system notification with a "Stop recording" button (a foreground service that the system keeps visible) — provided you have allowed the app to send notifications. If you decline, the recording still runs, then without this notification; it remains visible through the "Recording in progress" banner in the app. Legal basis: Art. 6(1)(b) GDPR (use of the recording function). The app accesses your location only after you have allowed it in the system dialog; if you revoke that permission, positioning ends. Revoke at any time: iOS under Settings → Privacy & Security → Location Services → Spurando; Android under Settings → Apps → Spurando → Permissions → Location.

Automatic trip detection (optional): If you switch on automation, Spurando starts and ends recordings by itself. For this there are two stages on both platforms, which you switch on separately. The app immediately saves automatically detected trips as a trip draft in the record; completing the mandatory details remains up to you.

Stage 1 — connection to the car: On iOS the app reads the name of the currently active audio output (CarPlay or the Bluetooth device you have chosen) and stores locally only the name of this one device. No audio data and no microphone are used, and no separate Bluetooth permission is needed; detection works only while the app is in memory. On Android you choose your car from the list of your paired Bluetooth devices; for this the app requests the "Nearby devices" permission from Android 12, while on Android 8 to 11 it uses the earlier Bluetooth permission, which the system grants without a dialog. The app stores locally the name and Bluetooth address of this one device and reacts to system events announcing that this specific device has connected or disconnected — even when the app is not currently open; the system then starts the recording, with the system notification (see "Location data"). In addition, via a separate toggle that is off by default, you can use an Android Auto connection as a trigger; for this the app only queries the connection state of the Android Auto app and needs no separate permission.

Stage 2 — full automation (motion): On iOS the app asks for the location permission "Always" and for "Motion & Fitness". With "Always", the system can wake the app on a significant change of location (coarse, in the range of a few hundred metres) — even if you have quit it. This wake-up positioning therefore runs outside a recording for as long as full automation is switched on. After waking, the app checks via the device's motion data whether you are in a car and only then starts the actual recording; if the driving motion stops for a few minutes, it ends the recording. Motion data is evaluated, not stored. On Android the app asks for "Physical activity" and for the location permission "Allow all the time". The activity recognition of Google Play services notifies the app when your device enters or leaves the "in vehicle" state; "Allow all the time" is needed so that the app may start the recording from the background. The recording itself remains visible through the system notification (see "Location data"). Whether a trip is taking place is decided by the app on the device; it does not send motion or connection data to any server of its own. Legal basis: Art. 6(1)(b) GDPR (function switched on by you). The respective stage works only after you have granted location "Always" and Motion & Fitness or Physical activity — on Android, for the Bluetooth stage, "Nearby devices" — in the system dialog; if you revoke one of these permissions, that stage stops working. You can switch off automation in the app at any time (More → Automation & default car). You revoke the permissions on iOS under Settings → Privacy & Security → Location Services or Motion & Fitness → Spurando, on Android under Settings → Apps → Spurando → Permissions (Location, Physical activity, Nearby devices).

Address suggestion (reverse geocoding, can be switched off): When you record a trip via GPS or have it detected automatically, the app translates two coordinates into a readable address: the start point (only for display during the recording; it is not stored) and the destination (for the trip's destination field). For this it transmits the respective coordinate to your operating system's geocoding service — on iOS to Apple's map service, on Android to the system geocoder, which on devices with Google Play services is answered by Google. The respective provider processes the request under its own responsibility in accordance with its privacy policy; nothing is transmitted to us, and the app does not itself store the request permanently. For a recording you started yourself, the destination address appears as a suggestion in the record-trip form (only as long as the field is empty), and you decide whether to accept it. For an automatically detected trip, the app enters the detected destination address into the trip draft as a correction entry marked as detected from GPS (on iOS labelled "Destination detected from GPS"), provided the destination is still empty; you can correct it afterwards. If you record trips manually, no reverse geocoding takes place. The address suggestion is switched on after installation; you can switch it off at any time on both platforms in the More tab via the toggle "Address suggestion via map service" — then you enter the address yourself, and the coordinates do not leave the device. Legal basis: Art. 6(1)(b) GDPR; withdraw at any time via the toggle in the app.

Time anchoring (RFC 3161 timestamp token, can be switched off): Spurando keeps your trips as a continuously chained record whose current head hash summarises the state of all entries so far. So that you can later show that this state already existed at a certain point in time, the app occasionally obtains a timestamp token under RFC 3161 for the head hash. This is a cryptographically secured attestation of the point in time — proof of the timeliness of the recording, not an examination, assessment or recognition of your trips by any authority. Not every entry is timestamped: when the app is opened (on iOS also when it returns to the foreground), it checks whether the last token is older than 30 days or whether entries have been added to the record since, and only then requests a new one; when the export is opened, it additionally obtains a fresh token on both platforms. In terms of content, only the SHA-256 hash value of the chain head together with a random number is transmitted — no trip content, no licence plate, no address; the content cannot, in practice, be reconstructed from this hash value. As with any internet connection, the recipient technically receives your IP address and the usual connection data of an HTTPS request (in the request header, on Android for instance the device model and Android version, on iOS the app name and build as well as the system version in technical form). The recipient is the free timestamp service freeTSA.org. Apart from a contact email address, this service names neither its operator nor its registered office on its website and publishes no privacy policy; whether and for how long it stores connection data such as your IP address, and whether processing takes place outside the EU, we do not know and cannot influence. There is no agreement between us and the service. The app stores the returned token locally in a separate, likewise chained timestamp file and attaches the most recent token to the export as a .tsr file; it can be verified with OpenSSL-compatible tools, and instructions are included in the export's record description. Time anchoring is switched on after installation. If you do not want this transmission, switch it off on both platforms in the More tab via the toggle "External time anchoring" — the app then works fully offline in this respect; tokens already stored are retained. Legal basis: Art. 6(1)(b) GDPR — time anchoring is part of the logbook function you use. You can object at any time; the only effective way to do so is this toggle: we have no server and no access to your device, so an email to us cannot technically stop the requests.

Cloud synchronisation (optional): Synchronisation is off after installation. If you switch it on, the app syncs your record with your own cloud account so that you can continue it on another or a new device. The data is then held in your account; we have no access to it, and there is no server of ours. The following is synchronised: the complete trip record (date, odometer readings, trip type, destination, purpose, business partner, correction and cancellation reasons and, for GPS trips, the start and destination coordinates), your vehicles (label, licence plate, activation history with reasons) and your professional-secrecy settings including the reason you have given. Deliberate limits: Not synchronised, and kept only on the device, are the complete GPS route, the receipts including photos, the timestamp tokens, the tax details (holder name, company, tax number), the reasons for late entry and the recording method. The app's backup file, by contrast, does include routes and receipts (not the timestamp tokens and tax details) and can be transferred to another device manually as a file.

On iOS, Spurando uses the private iCloud database of your Apple account (CloudKit) for this; Apple's privacy policy applies. Syncing runs when you switch it on, when the app is opened and when it returns to the foreground, after every new entry and on request ("Sync now"). On Android, Spurando places a single file in the app-specific area of your Google Drive that is invisible to other apps and to you in the file explorer (the "app data" area; the app receives from Google only the permission for this area, technically drive.appdata). For this you sign in via the Google dialog; the app requests no further rights to your account and does not store the access token permanently. Syncing runs when the app is opened, when it returns to the foreground, when it moves to the background, after every saved entry and on request ("Sync now"); Google's privacy policy applies. If you switch synchronisation off, syncing ends; the copy already placed remains in your account until you remove it yourself — on iOS under Settings → [your name] → iCloud → Manage Storage → Spurando, on Android under drive.google.com → Settings → Manage apps → Spurando → "Delete hidden app data". Legal basis: Art. 6(1)(b) GDPR (function switched on by you). On Android, this is complemented by the access you grant in the Google sign-in dialog; you can revoke it under myaccount.google.com (Security → Third-party apps & services). Switch off at any time via the toggle in the app.

Reminders (local notifications): A trip that is still missing mandatory details — such as an automatically detected trip draft — is marked "Complete" in the app and should be completed within the 7-day deadline after it was recorded. Spurando reminds you with a notification when this deadline approaches. The notifications are generated entirely on the device; no data is transmitted for them. On iOS the app schedules the notification two days before the deadline expires (or in about an hour if the deadline is closer) and asks for notification permission only when a reminder is actually due; the notification contains the date of the affected trip. On Android the app checks once a day in the background (as a scheduled background task of the system, without a network connection) whether deadlines are pending and shows one notification per trip that is due, with the trip date and the days remaining. The app requests the "Notifications" permission (from Android 13) when the first recording starts — or, if you had switched the toggle off in the meantime, when you switch it back on. As long as you have not granted it, the daily check still runs but shows no reminder; you can grant it at any time under Settings → Apps → Spurando → Notifications. Tapping the notification opens the affected trip directly in the app — this too is purely local. The reminders are switched on after installation on both platforms and can be switched off at any time in the More tab via the toggle "Late-entry reminders" or via the system settings for notifications (iOS: Settings → Notifications → Spurando; Android: Settings → Apps → Spurando → Notifications). Legal basis: Art. 6(1)(b) GDPR.

Receipts (camera and photos, optional): You can file receipts with each vehicle — fuel, garage, service, car wash, insurance, toll, parking or other receipts. A receipt consists of a photo and optional details for date, category, amount and note. You take the photo with the camera or choose an existing picture. The app processes the picture only on the device: it scales it down to at most 2048 pixels on the longer edge, stores it as a JPEG in the app's private storage and does not keep the original. For Live Photos (iOS) or Motion Photos (Android) it takes only the still image; the video and audio part is neither loaded nor stored. Videos cannot be selected at all. On iOS the app asks for access to the camera via the system dialog when you first take a photo. You choose an existing picture via the system's photo picker, which runs outside the app: for this the app needs no permission for your photo library and does not request one — it receives only the one picture you tap, does not read your library and writes nothing into it. On Android the app opens the system camera or the system photo picker; for this it needs no camera or storage permission of its own — it receives only the picture you hand over yourself (a camera shot is first placed in a temporary file in the app's cache). Receipts are not included in cloud synchronisation and are excluded from the operating system's device backup; they are part of the app's backup file and are attached to the PDF export as an appendix unless you deselect this when exporting. If you delete a receipt in the app, the photo and details are removed; the photo of a saved receipt cannot be replaced, only the details — a new photo is a new receipt. Legal basis: Art. 6(1)(b) GDPR (app function used by you). On iOS the app uses the camera only after you have allowed it in the system dialog; you can revoke this permission at any time under Settings → Privacy & Security → Camera → Spurando. For the photo picker the app holds no permanent permission on either platform, and on Android none for the camera either — there is nothing to revoke there.

Backup and export/sharing: Backup: You can save your entire record as a single file. It contains all trips including addresses, business partners and coordinates, the complete GPS routes, vehicles with their history, professional-secrecy settings, recording methods, reasons for late entry and all receipts including photos. Not included are the timestamp tokens and the tax details. When restoring, the app reads only the file you select in the file dialog. Export: For passing on — for instance to your tax adviser or, on request, to the tax authorities — the app generates a CSV file, a record description, a PDF and the most recent timestamp token (.tsr). For each trip, the export contains the date, licence plate, odometer readings, trip type, destination, purpose, business partner, status, checksums and the date of recording, plus the reasons for late entry, the vehicle history and — if entered — the tax details. Coordinates and routes are not included. Receipt photos are attached to the PDF unless you deselect this in the export; professional-secrecy redactions apply in the export, together with the reason you have given at every redacted spot. Whether, when and to whom you pass on a backup or export is decided solely by you, through your device's share dialog. The files are created in the app's temporary storage on your device and remain there until the system clears it or you remove the app; nothing is transmitted to us in the process. Note that exports and backups may contain third-party data (business partners). The record is thereby documented and exportable; whether it is recognised for tax or official purposes in an individual case is decided by the competent authority — no such recognition is guaranteed. Legal basis: Art. 6(1)(b) GDPR.

Legal basis (all other functions): Art. 6(1)(b) GDPR (performance of a contract / use of the app's functionality).

4. Obtaining the app through the App Store / Google Play Store

Spurando is distributed through the Apple App Store and the Google Play Store. When you download or update it, the respective store provider processes personal data under its own responsibility — such as your Apple ID or Google account, the time of download and device information. We have no influence over this and do not receive that data. The privacy policies of Apple and Google respectively apply.

5. Your rights

You have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Because we ourselves store no data about you, you exercise them for the most part directly on your device.

Viewing and taking your data with you: All data is held on your device. Backup and export give you the record, vehicles, receipts and reasons as files; the tax details (they appear only in the header of the PDF export) and your settings can be viewed in the app. Of the timestamp tokens, the app shows only the most recent (More tab and export); older ones are held in the app's timestamp file on your device and are part of the device backup, but cannot be viewed individually either in the app or via the export or the backup file.

Rectification: You correct trips in the app. Because the record is kept as a continuously chained list, a correction does not replace the old entry but appends a correction entry with your reason. That way it remains traceable what was changed and when. You change vehicles and settings directly; for receipts, the details — the photo stays, a new photo is a new receipt.

Erasure: You do not delete an individual trip in the literal sense but cancel it — a cancellation entry with a reason marks it as invalid, while the original entry remains in the chained record, for GPS trips including the route on the device. You can delete a vehicle as long as no trip and no receipt refers to it; after that you can only end it as "no longer driven", with a reason, so that the record remains traceable. You delete receipts individually in the app (photo and details are removed). You delete the entire record by uninstalling the app. If you had cloud synchronisation switched on, the copy remains in your own account and must be removed there separately (see "Cloud synchronisation"); the same applies to device backups with Apple or Google and to backup files you have stored yourself.

Withdrawal: You revoke the permissions for location, Motion & Fitness or Physical activity, Nearby devices (Android), camera (iOS) and notifications in your device's system settings, and the Google access for Android synchronisation under myaccount.google.com. Cloud synchronisation, automation, time anchoring ("External time anchoring"), address suggestion and late-entry reminders can be switched off at any time in the app (More tab).

For any questions, contact hello@thadwi.studio. You also have the right to lodge a complaint with a data protection supervisory authority; the authority competent for us is the Independent Data Protection Centre of Saarland (Unabhängiges Datenschutzzentrum Saarland).

6. Cookies

This website does not use cookies.

Last updated: September 2026