Skip to content
NorthProfit Studio
  • Products (German)
  • Contact (German)
  • Deutsch
Contact support Menu

Navigation

  • Products (German)
  • Contact (German)
  • Deutsch
Contact support

Email: support@northprofitstudio.de

Kassensturz
  • Help
  • Privacy
  • Terms
  • Legal notice (German)
  • Delete account (German)

Legal

Privacy policy for Kassensturz

Last updated: 10 October 2026

This translation is provided for convenience; the German version is legally binding. Read the German version

On this page

  1. Controller
  2. Register data on your device
  3. Kassensturz account (optional, from version 2.0)
  4. Account backup
  5. Purchases, subscriptions and RevenueCat
  6. Identifier-free operational counters
  7. Optional product analytics
  8. No advertising and no cross-app tracking
  9. Permissions and external links
  10. Support and website
  11. Storage period and deletion
  12. Your rights
  13. Changes

In short: Kassensturz works without an account. Registers, quantities, target balances and notes stay on your device. From version 2.0 you can create an optional Kassensturz account (with Apple, Google or a code by email), back up your registers encrypted and move them to a new device. Without your consent, release versions only send identifier-free operational counters without register data; optional product analytics starts only after your explicit consent and can be switched off again in the app at any time.

1. Controller

NorthProfit UG (haftungsbeschränkt)
Waldnieler Straße 28
40549 Düsseldorf
Germany

Email: kontakt@northprofitstudio.de

2. Register data on your device

Registers (name, currency, target balance, float target, roll and bundle sizes), quantities, saved counts with target and actual, difference, float and deposit, and notes are stored in the app’s local storage. We don’t receive this content unless you turn on account backup (section 4). From version 2.2.3, the app asks on first launch what you count the register for (shop or hospitality, club, market or event). Answering is optional; the answer stays on the device and is part of neither the backup file nor the account backup; the app uses it for the heading of the Pro screen.

When you create a backup file, a CSV file, a PDF register receipt or a deposit slip, you decide where it is stored and who receives it. In the Android app, operating-system backup of app data is disabled. On Apple devices, operating-system or device backups may apply according to your Apple settings.

Reminders. If you turn on the count reminder, Kassensturz schedules notifications locally on your device. No data is transferred to us or third parties for this; time and weekdays stay on the device. The notification contains no amounts. You can turn the reminder off at any time in the app under “More” or in the system settings. From version 2.2.2, during a free trial of Kassensturz Pro, the app also offers to remind you two days before the trial ends; only after you tap “Continue” does your device ask for permission to send notifications. If you have already allowed notifications, from version 2.2.3 the app schedules the reminder as soon as the trial starts; the Pro screen tells you the date beforehand. The app also schedules this reminder only locally on your device, it contains no amounts, and your choice stays on the device; we transfer no data for it. The app reads the end of the trial from the purchase data that runs through Apple or Google and RevenueCat anyway (section 5). If you cancel during the trial, the app removes the reminder the next time it checks your purchase status.

3. Kassensturz account (optional, from version 2.0)

You don’t need an account: counting, saving and exporting work without one. After your first saved count, the app offers an account once. With the account you can back up your registers if you wish (section 4), move them to a new device, even between iPhone and Android, and use Pro on your other devices. You sign in without a password: with Apple, with Google or with a six-digit code by email.

For this we process your email address, the sign-in method, the times of creation and last sign-in, the version of the accepted terms of use and your sessions (device type iOS, Android or web, times). We store sign-in codes and session keys only as cryptographic check values. A code is valid for 15 minutes and is locked after five failed attempts. A session ends when you sign out, at the latest 180 days after it was last used. The legal basis is Art. 6(1)(b) GDPR.

We send sign-in and deletion codes via Amazon Simple Email Service (SES) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, from a data centre in Frankfurt am Main. Amazon acts as our processor and receives your email address and the content of the email with the code. Where data reaches Amazon Web Services, Inc. in the USA, this is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, under which Amazon Web Services is certified. In addition, the EU standard contractual clauses in the AWS data processing agreement apply (Art. 45 and 46 GDPR). The legal basis is Art. 6(1)(b) GDPR.

Proof of delivery. Since 9 October 2026, Amazon SES reports to our own administration system via the notification service Amazon SNS (also Amazon Web Services EMEA SARL, AWS region Frankfurt) whether an email was sent, delivered or delayed, whether it could not be delivered or whether someone complained about it. There we store the recipient address, sender, subject, delivery status, time and the technical ID of the email. We make sequences of three or more digits and long character strings unrecognisable in the subject, so codes don’t appear there; we don’t store the content of the email. The administration system runs on our own server at STRATO GmbH in Germany; we delete the entries after 30 days. The purpose is to prove delivery and to be able to help you with support requests. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is demonstrably reliable delivery.

With Apple or Google. If you choose “Continue with Apple” (Apple Distribution International Ltd., Ireland) or “Continue with Google” (Google Ireland Limited, Ireland), you sign in with the respective provider. We receive a signed confirmation from it with an identifier that applies only to Kassensturz, and your email address; with Apple, this can be a relay address if you wish (“Hide My Email”). We don’t request names, profile pictures or contacts. The provider learns that you are signing in to Kassensturz; its privacy notices also apply. On Android, “Continue with Apple” opens Apple’s sign-in page in the browser; Apple sends the result directly to our server.

With Apple, we also exchange a one-time code for a token that we store encrypted. We use it to revoke the sign-in with Apple at Apple when you delete your account. If you sign in another way with the same email address, the app asks you to use your previous method; accounts are never merged just because the address is the same.

When you are signed in, the app logs in to RevenueCat with your account ID. This is a random identifier, not an email address. This way Pro applies on all devices on which you are signed in with this account.

Under “More” → “Account” you can sign out and delete the account; without the app, you can also delete it in the browser or by email (Delete account). Deleting removes the account, sign-in methods, sessions, open codes and the account backup immediately and revokes a sign-in with Apple at Apple; we delete the token stored for this after the revocation, at the latest after 30 days. Signing out and deleting don’t change the data on your device.

4. Account backup

Only if you turn it on does the app back up your registers in your account, so that they are kept when you change devices, lose a device or reinstall, and are the same on your devices. Backed up are registers (name, currency, target balance, float target, roll and bundle sizes), saved counts (time, quantities, rolls and bundles, actual, target, difference, float and deposit, note), deletion markers for deleted registers and counts, and language and appearance. A current count that hasn’t been saved yet is not backed up.

The backup is stored encrypted (AES-256-GCM) on our server at STRATO in Germany; we keep the keys separate from the data. We keep the last three versions as restore points. The legal basis is your consent (Art. 6(1)(a) GDPR).

You can turn off account backup at any time under “More” → “Account”. We then delete all backed-up versions immediately; the data on your device is kept.

5. Purchases, subscriptions and RevenueCat

Pro purchases and subscriptions are processed by the Apple App Store or Google Play. To unlock and restore Pro and to check whether a subscription is active, has renewed or has ended, we use RevenueCat, Inc. RevenueCat processes a randomly generated anonymous app user ID or, if you are signed in, your account ID (section 3), as well as the product ID, platform, store environment and the purchase or subscription status with term and, where applicable, trial period. We don’t send register data, names, email addresses or advertising IDs to RevenueCat.

The processing is necessary for purchase verification, fraud prevention, unlocking, renewal and restoration (Art. 6(1)(b) GDPR). With your consent to product analytics (section 7), from version 2.2.3 we also send RevenueCat which version of the paywall applies (new installation or existing user), to see which version leads to subscriptions (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). If you withdraw your consent, the app deletes this information at RevenueCat. Purchase and subscription history is also used in aggregated RevenueCat reports to assess the purchase function technically and commercially. No advertising or attribution integrations are set up.

In addition, the privacy policies of Apple (opens in a new tab), Google (opens in a new tab) and RevenueCat (opens in a new tab) apply. Where data is processed outside the EEA, the statutory transfer mechanisms provided for apply.

6. Identifier-free operational counters

Release versions explicitly built for production send strictly limited event counters to our NorthProfit Cockpit at cockpit.northprofit.eu (STRATO, Germany) even without your analytics consent: app launch and return from the background, session start, each full active minute, moving to the background, first launch and first saved count after a new installation, start and successful completion of a register count, and your consent to product analytics. From version 2.2.1 we also count a refusal of product analytics, the steps of the initial setup (counting and first count; each shown, completed or skipped) and technical errors and crashes of the app. From version 2.2.2 we also count when the app asks for a rating in the App Store or on Google Play; this doesn’t tell us whether the request appears or whether or how you rate. Steps of the purchase flow (viewing the Pro screen, choosing a plan, start, completion, cancellation, errors and restoring a purchase) were counted in versions 2.2.1 to 2.2.3 only with your consent as part of product analytics (section 7). From version 2.2.4 we again count viewing the Pro screen as well as the start, completion, cancellation and errors of a purchase and restoring as anonymous daily counters, like the other counters without an identifier and without a time of day. Details such as the chosen plan and term, the version of the Pro screen and where you opened it from, and the plan choice itself, we still record only with your consent (section 7). From version 2.2.6 we also count when the app points out a new version (a quiet notice or the full-screen “Please update”) and whether you open the App Store or Google Play from it. After five minutes in the background, a return counts as a new session start. These are separate counting events, not a user path.

Each request contains only the contract version, a one-time request ID, the official app ID, the channel, iOS or Android, app version, build and event type. From version 2.2.2 the channel distinguishes store versions, review devices (App Review, TestFlight, Google’s review devices) and simulator or emulator; only store versions on real devices go into our statistics. To recognise review and test installations, the app only checks on the device whether it is running in a simulator or emulator and reads, on Android, a system setting and, from version 2.2.3, the installation source (only installations from Google Play count as a store version), or, on iOS, the file name of the purchase receipt; only the channel is transferred. Reports on the initial setup also contain a fixed step name (for example “01_zaehlen”) and, for a completed step, a rough duration class (under 5, 5 to 15, 15 to 60 or over 60 seconds). From version 2.2.4 the app also reports when you leave it during a step (also with a duration class) and whether you chose “I already use Kassensturz”. Also from version 2.2.4, it asks once at the next launch after an unfinished first count what was missing. If you tap one of the fixed answers (for example “I couldn’t find my currency” or “Prefer not to say”), it sends this answer with the step name; there is no free text, and closing sends nothing. On the device the app only stores that it has asked, never your answer. Error reports additionally contain only the technical error name (for example “TypeError” or “http_503”) and the place in the app (for example the screen “counter” or “api”); error texts and technical logs (stack traces) are never transferred. The requests contain no user, installation, session, advertising or device identifier and no registers, denominations, amounts, currencies, register names, notes or freely fillable additional data. Therefore neither individual persons nor unique active users, sessions or retention can be determined from them.

The server immediately combines each report into a daily counter per version. The one-time request ID is only hashed and deleted after eight days. If a transfer fails, the app retries a request at most once and doesn’t store operational counters on the device without analytics consent. Only with your consent can a crash be stored on the device until the next launch from version 2.2.1, so that the report arrives after the restart (Art. 6(1)(a) GDPR, Section 25(1) TDDDG); after a withdrawal it is deleted unsent. An IP address is processed only briefly to limit abuse and is not stored in the operational counter database. The purpose is to check whether published versions start and run stably and whether the initial setup and core function work, for versions before 2.2.1 also the purchase path, from version 2.2.2 also how often the app asks for a rating, and from version 2.2.6 also whether notices about new versions arrive (Art. 6(1)(f) GDPR).

7. Optional product analytics

From version 2.2, Kassensturz asks once on first launch whether you want to consent to optional product analytics (“Agree” or “Continue without statistics”). If you used the app before or closed the question, you are asked once after a later count; in earlier versions the question came after the second saved register count, and if you had used the app since a version before 2.0, after the first count in 2.0. Refusing doesn’t limit the app. From version 2.2.1 we count a refusal, like a consent, only as an anonymous daily counter without an identifier (section 6); before that it was not reported. Without consent no analytics events are transferred; only the identifier-free operational counters from section 6 remain. Your choice is stored only locally and can be changed at any time under “More” → “Optional product analytics”.

Only after consent can production versions send to our NorthProfit Cockpit at cockpit.northprofit.eu: app and session start, return to the app, viewed areas and function steps, start and result of the core function, steps of the purchase and restore flow, and technically limited result, duration or error codes. From version 2.2.3, your answer to the opening question as a fixed value (shop or hospitality, club, market or event, or skipped) and the version of the Pro screen are added. From version 2.2.6, for the update notices, which of the two notices appeared is added. The purpose is to identify usability problems, drop-off points and technical function paths and to improve Kassensturz.

Each event contains only the app ID, platform, channel (as in section 6), app version, build, event type and time, consent version, random event, installation and session identifiers, and strictly permitted technical attributes. NorthProfit stores the random installation identifier only as a project-bound one-way value. Not transferred are registers, denominations, amounts, currencies, target balances, differences, notes, names, email addresses, account ID, store accounts, RevenueCat ID, advertising ID, Apple IDFV, Android ID, device fingerprint, freely entered texts or cross-app identifiers.

The processing is based on your consent (Art. 6(1)(a) GDPR and, where applicable, Section 25(1) TDDDG). Transfers are encrypted via HTTPS. Failed transfers can be cached locally for at most 48 hours and at most 100 events. The IP address is processed only briefly to limit abuse and is not stored in the analytics database.

If you turn analytics off, the app stops transferring, empties the local queue, removes the local analytics identifier and requests the deletion of the associated detailed event history. If the device is offline, this deletion request is kept locally until it is transferred successfully. Processing that was lawful until then remains unaffected. Turning it off is just as easy as turning it on.

8. No advertising and no cross-app tracking

Kassensturz contains no advertising, no third-party usage analytics SDK and no separate crash reporting SDK. The optional analytics is exclusively our own, app-bound product analytics. It is not combined with data from other apps or third parties for advertising, attribution or profiling purposes. We don’t create profiles from your register data.

9. Permissions and external links

The app needs no camera, microphone, location or contacts. It asks for permission to send notifications only if you turn on the count reminder or, from version 2.2.2, accept the reminder before the trial ends; without this permission Kassensturz works fully, only the reminders stay off. When you open the support page, the privacy policy, the terms of use or, from version 2.2.3, the explanation of the cash report on the Pro screen, you leave the app and your browser calls up this website (reach measurement in section 10). For signing in with Apple or Google, the app shows the respective provider’s sign-in (section 3).

Notice of new versions. From version 2.2.6, on launch and when you return to the app, the app asks our server apps.northprofit.eu for the current and the minimum required version number in order to point out updates: after a successful request at most once a day; if the request fails, for example without a connection, it tries again when you open the app later; if the installed version is no longer supported, it asks at most hourly until you update. No identifiers, no cookies and no register data are transferred; the server processes the IP address only for delivery (section 10, Art. 6(1)(f) GDPR). On the device the app stores only the retrieved version numbers, the time of the last request and for which version it has already shown the notice (Section 25(2) No. 2 TDDDG).

10. Support and website

If you contact us, we process your message and contact details to handle the request (Art. 6(1)(b) or (f) GDPR). Please don’t send register contents.

When you visit this website, the web server processes technically necessary connection data such as IP address, time, requested address and browser identifier for secure delivery and to ward off errors (Art. 6(1)(f) GDPR). We don’t set marketing cookies.

Measuring the reach of this website. We measure how this website is used ourselves, without Google Analytics or other third parties. Without your consent we measure without measurement cookies and without storing anything on your device for measurement: pages viewed, the name of the referring website, campaign parameters from the address and clicks on our download buttons and on links to the App Store, Google Play and other websites, each without content. From the information your browser sends anyway, we derive device type, browser, operating system and language in broad categories, and from the IP address on receipt the country, region and city. From the IP address and browser identifier we form, with a key that is newly generated each day and held only in memory, an identifier that stays the same only for that day; only its hash value is stored, never the IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the pages based on aggregated usage figures. The deletion form at apps.northprofit.eu/kassensturz/api/konto-loeschen/ is delivered by our account service; we don’t measure reach there.

With your consent we also set our own cookies: “__Host-np_vid” with a random visitor ID for 12 months and “__Host-np_sid” for the session for 30 minutes. This lets us recognise returning visits. We then also record scroll depth, active time, page load times and a broad screen size class. The legal basis is your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

We store your choice in “Privacy settings”, including a refusal, for 12 months in the cookie “__Host-np_consent”; this is necessary so that we respect it (Section 25(2) No. 2 TDDDG). As long as you don’t make a choice, we store nothing. Via “Privacy settings” at the end of every page you can withdraw your consent at any time or switch measurement off completely; we then delete the measurement cookies and the measurement data stored with your visitor ID. If your browser sends the “Global Privacy Control” signal, we don’t measure at all. We store the measurement data in our access-protected NorthProfit Cockpit on servers of STRATO GmbH in Germany and delete it after 180 days. We determine the location on our own server with the database IP Geolocation by DB-IP (opens in a new tab) (licence CC BY 4.0).

Feature board: On apps.northprofit.eu/kassensturz/wuensche/ you can suggest features for Kassensturz and vote for other people’s suggestions. We store the suggestions you submit (title, optional details, language) in our NorthProfit Cockpit on servers of STRATO in Germany. So that each device can vote only once, the page stores a random device key in your browser’s local storage; the Cockpit receives it only as an irreversible check value (hash), together with your votes. We don’t store names, email or IP addresses for this; the IP address is used only briefly in memory to limit abuse. Suggestions appear only after our review and without reference to you (Art. 6(1)(f) GDPR). You can delete the device key via your browser’s website data.

11. Storage period and deletion

Local app data stays on the device until you delete it. Under “More” → “Delete all data” you remove all local data; an account backup is not affected. We store account data until you delete the account, and the account backup until you turn it off or delete the account. We delete sign-in codes and unfinished sign-ins one day after they expire, and ended sessions 30 days after they end. Deleted data disappears from the encrypted backup copies of our server after about 30 days, at the latest after 35 days. You delete backup files and exports yourself wherever you stored them.

Detailed, consent-based analytics events and the project-bound pseudonymous installation mapping are deleted at the latest 180 days after the last associated receipt. If you withdraw consent, the detailed event history is removed early after a successful deletion request; a blocked record of the withdrawn random identifier can remain until the end of the same 180-day window. Identifier-free daily counters can then remain as product statistics that can no longer be assigned to an installation. One-time technical retry hashes are deleted after eight days.

For a request about your RevenueCat purchase record, choose “More” → “Share privacy ID” in the app and send this ID to support@northprofitstudio.de. Store purchases and legally required transaction records are subject to Apple’s or Google’s retention rules. Deletion at RevenueCat doesn’t delete a purchase in the store; a later restore can create the necessary purchase record again.

12. Your rights

Insofar as we process personal data, you have, subject to the legal requirements, the right to access, rectification, erasure, restriction, data portability and objection. You can withdraw an analytics consent you have given at any time in the app without affecting the lawfulness of the processing until the withdrawal. Please send requests to kontakt@northprofitstudio.de.

You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

13. Changes

We update this policy when features, service providers or legal requirements change. The current version remains available at this address.

NorthProfit Studio

Apps, websites and AI automation from Düsseldorf, Germany – and nine products of our own.

Kassensturz

  • Help
  • Privacy
  • Terms
  • Legal notice (German)
  • Delete account (German)

NorthProfit Studio

  • About the studio (German)
  • All products (German)
  • Contact (German)

Legal

  • Studio legal notice (German)
  • Studio privacy (German)
© 2026 NorthProfit UG (haftungsbeschränkt)kontakt@northprofitstudio.de

Privacy

Measurement with your consent

With a first-party cookie we see which pages help and how visitors find the app. The data stays with us, without Google or other third parties. Without your consent we only measure without cookies.

About measurement