Back to Legal

Privacy Policy

Datenschutzerklärung / Privacy Policy · Effective 17 September 2026 · Version 1.2

This Privacy Policy describes how Sebastian Pichler ("we", "us", or "our") processes personal data in connection with the Callisto app ("App") on Android devices and the website at callistoapp.eu ("Website"). It applies from the date of first use of the App, and to every visit to the Website.

Controller

Sebastian Pichler
Lindengasse 4
4040 Linz
Austria
E-mail: dev@callistoapp.eu

What data we collect and why

1. Crash reports (Firebase Crashlytics)

We use Firebase Crashlytics, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to collect crash reports automatically whenever the App experiences an unexpected error.

Data collected: device model and manufacturer, operating system version, App version and build number, timestamp of the crash, stack trace and exception type. We do not collect names, e-mail addresses, IP addresses, location data, file contents, or any other personally identifiable information through crash reports. We do not link crash reports to individual users.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in maintaining App stability and fixing defects. This processing is necessary to keep the App functional for all users and does not override your interests, rights, or freedoms.

Crash reporting is always on. If you do not wish crash data to be collected, you may uninstall the App.

2. Usage analytics (Firebase Analytics)

If you enable "Anonymous usage data" in Settings → Privacy, we additionally collect basic usage events via Firebase Analytics, also provided by Google Ireland Limited.

Data collected when opted in: screen_view events (which screens you open), session start and session end events, and general engagement metrics. We do not collect user IDs, advertising IDs (AAID is set to zeros by Firebase when analytics are disabled; we do not enable AAID collection), names, e-mail addresses, notebook or script file contents, or any code you write in the App.

Legal basis: Article 6(1)(a) GDPR — your freely given consent. You can withdraw consent at any time by disabling the toggle in Settings → Privacy. Withdrawing consent does not affect the lawfulness of any processing based on consent before its withdrawal. Firebase Analytics stops collecting new events immediately upon opt-out; previously collected aggregate data cannot be retroactively deleted from Google's aggregation infrastructure.

When you have not enabled analytics, no usage events are sent.

Your files and data

Your notebooks, scripts, and workspace files are stored on your device in app-private storage. We have no access to the content of your files, nor do we transmit them anywhere. No internet connection is required to use the App.

Jupyter servers you connect yourself. The App can optionally connect to a Jupyter server that you choose and configure — for example Termux on the same phone, a machine on your own network, or a server you rent. While such a connection is active, the code you run, the output it produces, and any files you upload or download travel between your device and that server. That connection is between you and the operator of that server; we are not a party to it, we receive nothing from it, and we operate no such server. Server addresses and access tokens you enter are stored on your device only. This feature is off until you set a server up.

This website

Hosting. The Website is hosted on GitHub Pages, a service of GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you open a page, your browser necessarily sends GitHub your IP address, the date and time, the page requested, the referring page, and your browser's user agent. GitHub may log this information, including your IP address, to keep the service secure and working. We have no access to these logs; how long they are kept is set by GitHub — see the GitHub General Privacy Statement.

Legal basis: Article 6(1)(f) GDPR — our legitimate interest in delivering the Website securely and reliably.

No cookies, no tracking. The Website sets no cookies, stores nothing on your device, and uses no analytics or tracking. Fonts, images, and styles are served from the Website itself; no third-party content is loaded. Links to Google Play only contact Google once you follow them.

E-mail. If you write to us, we use your e-mail address and message only to reply, under Article 6(1)(f) GDPR (our legitimate interest in answering enquiries), or Article 6(1)(b) GDPR where your message concerns a purchase. We delete the correspondence once it is no longer needed, unless statutory retention obligations apply.

Data retention

Crash report data is retained by Google on Firebase Crashlytics for up to 90 days. Analytics event data is retained for 60 days (Firebase default retention setting). These retention periods are set by Google and may change; please refer to Google's Firebase Data Processing and Security Terms for the current settings.

Data processors and third-country transfers

We share data only with the following providers:

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Firebase Crashlytics and Firebase Analytics), for the App.

GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (GitHub Pages), for the Website.

Google may transfer data to servers in the United States and other countries outside the EEA. Google provides appropriate safeguards for such transfers under Standard Contractual Clauses adopted pursuant to Article 46(2)(c) GDPR. For details, see Google's Privacy Policy and the Firebase Data Processing and Security Terms.

Website requests are processed by GitHub in the United States. GitHub, Inc. is certified under the EU-U.S. Data Privacy Framework, which the European Commission has found to provide an adequate level of protection (Article 45 GDPR).

No other third parties receive your data. A Jupyter server you connect yourself is not a processor acting for us — see Your files and data above.

Your rights under the GDPR

You have the following rights regarding your personal data, subject to statutory conditions:

To exercise your rights, contact us at dev@callistoapp.eu. Please note that crash report data is associated only with an anonymous Firebase installation identifier, not with your personal identity. If you cannot provide such an identifier, we may be unable to locate the specific data.

You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria, e-mail: dsb@dsb.gv.at, or with any other EU supervisory authority in your country of residence or place of work.

Children

The App is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, please contact us at dev@callistoapp.eu and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. The current version is always available within the App under Settings → About → Privacy Policy and on the Website. We will notify you of material changes by updating the effective date below. Continued use of the App after a revised policy is made available constitutes acceptance of the changes.

Contact

For any questions or requests relating to this Privacy Policy: dev@callistoapp.eu

Effective date: 17 September 2026 · Version 1.2