Skip to content
NorthProfit Studio
  • Products (German)
  • Contact (German)
  • Deutsch
Contact support Menu

Navigation

  • Products (German)
  • Contact (German)
  • Deutsch
Contact support

Email: support@northprofitstudio.de

Zählerstand
  • Help
  • Privacy
  • Terms
  • Delete account
  • Legal notice (German)

Legal

Privacy policy for Zählerstand

Last updated: 10 October 2026

This translation is provided for convenience; the German version is legally binding. Read the German version

On this page

  1. Controller
  2. Data on your device
  3. Permissions
  4. Optional account (from version 2.0)
  5. Sending emails
  6. End-to-end encrypted backup and sync
  7. Purchases and RevenueCat
  8. Operational counters and optional product analytics
  9. Server, backup copies and protection against abuse
  10. Support, website and deletion page
  11. Storage period and deletion
  12. Your rights
  13. Changes

In short: Zählerstand works without an account; your meters and readings then stay only on your device. From version 2.0 you can create an optional account, with Apple, Google or a code by email. The app then backs up your meters end-to-end encrypted on our server in Germany and syncs them between your devices. Only your devices can read them, not us. More detailed product analytics starts only after your consent. No advertising, no tracking.

1. Controller

NorthProfit UG (haftungsbeschränkt)
Waldnieler Straße 28
40549 Düsseldorf
Germany

Email: kontakt@northprofitstudio.de

2. Data on your device

The app stores this content in a database in your device’s protected app storage:

  • meters (type, name, meter number, property, room, note)
  • readings with date and value, heating oil tank levels
  • tariffs, monthly payments and prices
  • reminders and meter changes
  • your settings

Without an account we don’t receive this content.

The app creates backup files, CSV exports and PDF reports on your device. You decide yourself where you share or store them. A device backup set up by the operating system may back up app data according to the settings of your Apple or Google account.

Whether you set up Zählerstand before or from version 2.1.2 is stored by the app on your device, so that existing users keep their free features. As the version of the paywall, this information also goes to RevenueCat, but only with your consent (section 7).

3. Permissions

  • Camera – only after you allow it:
    Reading a meter: the app photographs the register and recognises the digits on your device (Apple Vision or Google ML Kit, without internet). It deletes the photo right after recognition. It is neither stored nor transferred. You confirm the recognised value yourself.
    Scanning a meter code: the QR code contains only a meter identifier, no readings.
  • Notifications: the operating system on your device schedules reminders. For this, the app asks for permission. While a free trial of Zählerstand Pro is running, the app uses this permission to remind you two days before the trial ends; from version 2.1.2 this is the last day on which you can still cancel free of charge, and the reminder arrives at 7 pm on that day. It then states how many meters and readings you have recorded so far, never your values; the app counts this on your device. It reads the end of the trial from your purchase status with Apple or Google (via RevenueCat, section 7); nothing is sent to us for this. If you cancel or the trial ends, the app removes the reminder.

Without these permissions, manual entry remains fully usable.

4. Optional account (from version 2.0)

The account is optional. It is used for the encrypted backup of your meters and for syncing between your devices, for example iPhone and Android. You sign in without a password. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

  • With Apple (Apple Distribution International Ltd., Ireland):
    We receive a signed confirmation from Apple with an identifier that applies only to Zählerstand, and your email address. If you wish, this is a relay address (“Hide My Email”).
    We also exchange a one-time code for a token and store it encrypted. We use it to revoke the sign-in with Apple at Apple when you delete your account.
    On Android, “Continue with Apple” opens Apple’s sign-in page in the browser. Apple sends the result directly to our server.
  • With Google (Google Ireland Limited, Ireland): we receive a signed confirmation with your Google identifier for Zählerstand and your verified email address.
  • With an email code:
    We send you a six-digit code (section 5).
    It is valid for 15 minutes and allows at most five attempts.
    We store it only as a checksum.

We don’t request names, profile pictures or contacts. The respective provider learns that you are signing in to Zählerstand; its privacy notices also apply.

For the account we store:

  • a random account ID and your email address
  • the sign-in methods with their identifier
  • the times of creation and last sign-in
  • the version of the accepted terms of use
  • your sessions: device type (iPhone or Android) and times, sign-in tokens only as a checksum

You link further sign-in methods under “More” → “Account”. Methods are linked only if you have confirmed both yourself, never just because the email address is the same.

Purchases aren’t tied to the account: Zählerstand Pro stays bound to your Apple or Google account (section 7).

5. Sending emails

  • We send codes for signing in and deleting the account via Amazon Simple Email Service (SES) of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, from a data centre in Frankfurt am Main. Amazon acts as our processor.
  • Amazon receives your email address and the content of the email with the code.
  • Where data reaches Amazon Web Services, Inc. in the USA, this is based on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, under which Amazon Web Services is certified. In addition, the EU standard contractual clauses in the AWS data processing agreement apply (Art. 45 and 46 GDPR).
  • The legal basis is Art. 6(1)(b) GDPR.

Proof of delivery. Since 9 October 2026, Amazon SES reports to our own administration system via the notification service Amazon SNS (also Amazon Web Services EMEA SARL, AWS region Frankfurt) whether an email was sent, delivered or delayed, whether it could not be delivered or whether someone complained about it. There we store the recipient address, sender, subject, delivery status, time and the technical ID of the email. We make sequences of three or more digits and long character strings unrecognisable in the subject, so codes don’t appear there; we don’t store the content of the email. The administration system runs on our own server at STRATO GmbH in Germany; we delete the entries after 30 days. The purpose is to prove delivery and to be able to help you with support requests. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is demonstrably reliable delivery.

6. End-to-end encrypted backup and sync

With an account, the app backs up your meters, readings, tariffs, reminders, meter changes and the default currency. This way they are kept when you change devices, lose a device or reinstall, and are the same on your devices. Theme, language, analytics setting and notifications stay on the respective device.

  • Encryption: the app encrypts every entry on your device before it is transferred (AES-256-GCM). Only your devices have the key. On our server it is stored only in a form encrypted so that we can’t open it. We therefore can’t read or analyse your content.
  • What our server sees: your account ID, the type of an entry (for example meter or reading), a pseudonymous identifier, a version number, a check value, the time of the change and whether the entry was deleted.
  • Recovery key: when you set up the backup, the app shows a key with 24 characters. You use it to open the backup on a new device. We don’t know it and can’t restore it. If you lose the key and all devices, the backup is lost; the data on your devices is not affected.
  • Another device: instead of using the key, you confirm a new device on a device on which Zählerstand is already running. Both show the same six-digit security code. For this we store the public key and the device type of the new device, the code and, after confirmation, the key encrypted for this device, each until 15 minutes after the request.
  • Merging: if a device already has its own meters, the app asks whether they should be added. Beforehand it saves the previous state as a file on this device.
  • Deleting: if you delete an entry, a deletion marker without content remains so that your other devices apply the deletion.

The legal basis is the performance of the contract (Art. 6(1)(b) GDPR).

7. Purchases and RevenueCat

In-app purchases (monthly and annual subscription, permanent unlock) are processed via the Apple App Store or Google Play.

  • For the offer, purchase verification, unlocking Pro and restoring, we use RevenueCat, Inc.
  • RevenueCat processes a random app-specific identifier, platform, product ID, store environment, purchase and subscription status and technically necessary diagnostic data.
  • We don’t link this identifier to your Zählerstand account and don’t send readings, tariffs, usage values, names, email addresses or advertising IDs to RevenueCat.

The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). With your consent (section 8), from version 2.1.2 we also send RevenueCat which version of the paywall applies (new installation or previous use), to see which version leads to subscriptions (Art. 6(1)(a) GDPR, Section 25(1) TDDDG). In addition, the privacy policies of Apple, Google and RevenueCat apply. Where a service provider processes data outside the EEA, the statutory transfer mechanisms provided for are used.

8. Operational counters and optional product analytics

Operational counters without an identifier. Release versions explicitly built for production send limited counting events to our own server, for example:

  • app and session start, full active minutes, moving to the background
  • start and completion of onboarding, plus which setup steps were shown, completed, skipped or interrupted by moving to the background, with a rough duration (such as “under 5 seconds”). If you tap an answer under “Later” during onboarding, we send this answer from a fixed list (such as “I’m not at the meter right now”) and whether you set up a reminder for your first reading. There is no free text.
  • start and local completion of a reading; from version 2.1.5 also where it came from (from the app, from a reminder, via the widget or with the camera)
  • from version 2.1.5, your answer to the question whether the app may send notifications (allowed, declined or later)
  • from version 2.1.5, when the app points out a new version (a quiet notice or the full-screen “Please update”) and whether you open the App Store or Google Play from it
  • whether the app asked for a rating in the App Store or on Google Play (this doesn’t tell us whether the store shows the request or how you rate)
  • the summarised decision on product analytics

Up to and including version 2.1.0, the app also counts without an identifier when the Pro screen is opened and a store purchase is started and completed. From version 2.1.3, the app again counts opening the Pro screen and the steps of a purchase (started, completed, cancelled, failed or restored) without consent as anonymous operational counters: only the name of the step, without an identifier, time of day, price or origin. With your consent, the steps also arrive with details in product analytics (see “Optional product analytics”). In versions 2.1.1 and 2.1.2, the app recorded them only with consent.

Each report contains only:

  • the contract version and a one-time retry ID
  • the official app ID and channel: store version, review device (App Review, TestFlight, Google’s review devices), test or development installation; whether the app was installed from the App Store or Google Play is checked only on your device. Only such installations on real devices go into our statistics
  • platform, app version, build and event type

It contains no user, account, installation, session, advertising or device identifier and no meter ID, reading, tariff or usage. The server stores daily aggregates. The retry ID only prevents double counting; the server stores it as a hash and deletes it after eight days. The purpose is checking function and stability (Art. 6(1)(f) GDPR). From version 2.1.1, nothing is stored on the device for this without consent: the reports go out immediately, at most with an immediate second attempt, and until then stay only in memory.

Error and crash reports. If an error occurs in the app, it immediately sends our server, without an identifier, the error name (such as “TypeError”), the affected place (such as “Read meter”), app version and platform. Error messages, content, readings and device or user identifiers are not transferred. The server summarises the reports daily. The purpose is checking function and stability (Art. 6(1)(f) GDPR). Without consent, nothing is stored on the device for this. Only with consent can a crash be stored until the next launch.

Optional product analytics. Only after your explicit consent do we measure app-specific active installations, sessions, screen changes and strictly limited function steps, for example whether a sign-in or a camera scan worked, the steps of a purchase (Pro screen opened, purchase started, completed, cancelled or restored), which version of the paywall you saw, and your answer to the onboarding question “What should Zählerstand help you with?” (such as “No back payment”). From version 2.1.5, for the update notices, which of the two notices appeared is added. Without consent, the answer stays only on the device and arranges the Pro screen there; “Delete all data” removes it. It is not part of backup and sync. Whether and what you buy we learn without this measurement only through the billing of the App Store or Google Play and our billing service.

  • The app generates a random installation identifier that applies only to Zählerstand, and changing session identifiers.
  • The server stores the installation identifier only as a project-specific pseudonym. It is not linked to your account.
  • Readings, usage, tariffs, costs, names, notes, email addresses, advertising or device IDs or free texts are never transferred.
  • The local queue is limited to 100 events and 48 hours.
  • You can withdraw your consent under “More” → “Privacy”. The transfer then stops, the local identifier is removed and the app requests the deletion of the associated event history. “Delete all data” does this too.
  • Regular retention: at most 180 days.
  • The legal basis is Art. 6(1)(a) GDPR.

Zählerstand contains no advertising, no cross-app tracking and no advertising, attribution or analytics SDK from other providers. We don’t create profiles from your readings.

9. Server, backup copies and protection against abuse

  • The account and backup run on our own server at STRATO GmbH in Germany.
  • The database is backed up daily in encrypted form and kept for 30 days. An additionally encrypted copy is stored at Hetzner Online GmbH in Germany. Your meter data is contained in it only in end-to-end encrypted form anyway.
  • Data processing agreements exist or apply with both providers (Art. 28 GDPR).
  • The service doesn’t log individual requests. To ward off abuse, it counts requests per IP address only briefly in memory, for a few minutes (Art. 6(1)(f) GDPR).

Notice of new versions. From version 2.1.5, on launch and when you return to the app, the app asks our server apps.northprofit.eu for the current and the minimum required version number in order to point out updates: after a successful request at most once a day; if the request fails, for example without a connection, it tries again when you open the app later; if the installed version is no longer supported, it asks at most hourly until you update. No identifiers, no cookies and no meter data are transferred; the server processes the IP address only for delivery (section 10, Art. 6(1)(f) GDPR). On the device the app stores only the retrieved version numbers, the time of the last request and for which version it has already shown the notice (Section 25(2) No. 2 TDDDG).

10. Support, website and deletion page

Support. If you contact us, we process your message and contact details to handle it (Art. 6(1)(b) or (f) GDPR). Please don’t send readings or other sensitive content.

Website. When you visit the website, the server processes technically necessary connection data for secure delivery and to limit abuse. We don’t set marketing cookies.

Measuring the reach of this website. We measure how this website is used ourselves, without Google Analytics or other third parties. Without your consent we measure without measurement cookies and without storing anything on your device for measurement: pages viewed, the name of the referring website, campaign parameters from the address and clicks on our download buttons and on links to the App Store, Google Play and other websites, each without content. From the information your browser sends anyway, we derive device type, browser, operating system and language in broad categories, and from the IP address on receipt the country, region and city. From the IP address and browser identifier we form, with a key that is newly generated each day and held only in memory, an identifier that stays the same only for that day; only its hash value is stored, never the IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the pages based on aggregated usage figures.

With your consent we also set our own cookies: “__Host-np_vid” with a random visitor ID for 12 months and “__Host-np_sid” for the session for 30 minutes. This lets us recognise returning visits. We then also record scroll depth, active time, page load times and a broad screen size class. The legal basis is your consent under Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

We store your choice in “Privacy settings”, including a refusal, for 12 months in the cookie “__Host-np_consent”; this is necessary so that we respect it (Section 25(2) No. 2 TDDDG). As long as you don’t make a choice, we store nothing. Via “Privacy settings” at the end of every page you can withdraw your consent at any time or switch measurement off completely; we then delete the measurement cookies and the measurement data stored with your visitor ID. If your browser sends the “Global Privacy Control” signal, we don’t measure at all. We store the measurement data in our access-protected NorthProfit Cockpit on servers of STRATO GmbH in Germany and delete it after 180 days. We determine the location on our own server with the database IP Geolocation by DB-IP (opens in a new tab) (licence CC BY 4.0).

Deletion page. On the page for deleting the account, we process the email address you enter in order to send you the confirmation code (section 5). The page sets no cookies. It belongs to our account service and contains no reach measurement.

Feature board: On apps.northprofit.eu/zaehlerstand/wuensche/ you can suggest features for Zählerstand and vote for other people’s suggestions. We store the suggestions you submit (title, optional details, language) in our NorthProfit Cockpit on servers of STRATO in Germany. So that each device can vote only once, the page stores a random device key in your browser’s local storage; the Cockpit receives it only as an irreversible check value (hash), together with your votes. We don’t store names, email or IP addresses for this; the IP address is used only briefly in memory to limit abuse. Suggestions appear only after our review and without reference to you (Art. 6(1)(f) GDPR). You can delete the device key via your browser’s website data.

11. Storage period and deletion

  • On the device: until you delete the data or the app. Under “More” → “Delete all data” you delete the data on this device; with an account you choose “Only on this device” or “On all devices”.
  • Account:
    until you delete it
    Sessions end after 180 days without use. We remove ended or expired sessions 30 days later.
    We delete email codes and device requests one day after they expire.
    We automatically delete accounts, including their backup, without a sign-in and without a used session for 24 months.
  • Backup: until you delete the entry or the account. Deletion markers remain until the account is deleted.
  • Server backup copies: 30 days.
  • Deleting the account:
    in the app under “More” → “Account” → “Delete account” or without the app at apps.northprofit.eu/zaehlerstand/en/delete-account/
    We immediately delete the account, sign-in methods, sessions, device requests and the backup.
    We revoke a sign-in with Apple at Apple.
    A deletion marker without reference to you remains (time, method of deletion, Apple revocation yes or no).
    The meters on your devices are kept. You cancel a subscription in your store.
  • Product analytics: at most 180 days, earlier if you withdraw consent (section 8).
  • Purchases: store transactions are subject to the rules of Apple or Google and RevenueCat.
  • Support messages: until they are no longer needed for the request, as evidence or for statutory retention.

12. Your rights

Subject to the legal requirements, you have the right to access, rectification, erasure, restriction, data portability and objection. You can withdraw consent at any time with effect for the future. You can take your meters with you at any time as a backup file, CSV or PDF. Contact: kontakt@northprofitstudio.de. Competent supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

13. Changes

We update this policy when features, service providers or legal requirements change. The current version is always available at this address.

NorthProfit Studio

Apps, websites and AI automation from Düsseldorf, Germany – and nine products of our own.

Zählerstand

  • Help
  • Privacy
  • Terms
  • Delete account
  • Legal notice (German)

NorthProfit Studio

  • About the studio (German)
  • All products (German)
  • Contact (German)

Legal

  • Studio legal notice (German)
  • Studio privacy (German)
© 2026 NorthProfit UG (haftungsbeschränkt)kontakt@northprofitstudio.de

Privacy

Measurement with your consent

With a first-party cookie we see which pages help and how visitors find the app. The data stays with us, without Google or other third parties. Without your consent we only measure without cookies.

About measurement