Skip to content
No!
How it worksPrivacyFeaturesWeekly reviewFAQJoin the waitlist
ENDE

Legal

Privacy policy

Last updated: August 2026

1. Controller

Waldemar Enns
Ebersteinstraße 10
76437 Rastatt
Germany
Email: kontakt@waldemarenns.de

2. Overview

This policy explains the processing of personal data in connection with the website (landing page) and the mobile app No! (project name: say-no).

In short: The app stores your reflections and profile settings locally on your device. It needs no account and does not sync content to a cloud. The app is sold as a one-time purchase via the App Store (later via Google Play for the Android version). This website is primarily a static information page without user accounts; if you join the waitlist, we process your email and related status data as described in section 3.5.

3. Website (landing page)

3.1 Hosting and server logs (Hetzner)

This website is hosted on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (“Hetzner”), and operated by us via our own application stack (Coolify) in a German data center. When you visit, technically necessary connection data (e.g. IP address, time, requested resource, user agent) may be processed and stored in server or access logs. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure and stable operation of the website).

Hosting and log processing take place in Germany / the EU. Retention of technical logs is limited to what is needed for operation, security, and troubleshooting, and logs are then deleted or anonymized. Object storage used for selected website assets (for example roadmap illustrations) is provided as self-hosted MinIO on the same Hetzner server and is not a public CDN.

3.2 Analytics and session replays (Umami)

This website uses Umami (privacy-focused analytics) to understand page views and usage. We self-host the Umami instance on a server of Hetzner Online GmbH in Germany; it is reachable at umami.alphabyte-solutions.com. Website analytics therefore run on our self-hosted infrastructure in Germany, not on a US cloud analytics provider. We do not use Google Analytics and do not build advertising profiles.

For pageviews, Umami processes technical usage data such as page path, referrer, browser/device type, approximate location (from IP, anonymized), and language. Page views may be forwarded to the Umami instance via a proxy on this website. Legal basis for pageview analytics is Art. 6(1)(f) GDPR (legitimate interest in understanding and improving the website). You can object and opt out at any time via the Analytics control in the website footer; opting out sets Umami’s disabled flag (localStorage key umami.disabled) so further pageviews are not recorded.

Session replays are collected only with your prior consent under Art. 6(1)(a) GDPR. You can grant or withdraw that consent via the same Analytics control in the footer. When enabled, replays may record interactions with this website (e.g. clicks and scrolling) so we can improve layout and content. Recording uses sampling (only a portion of sessions, sample rate about 15%) and masking so sensitive input is not shown in full. Replays are not used for advertising or ad profiling. Replay requires pageviews to be enabled; turning pageviews off also disables replay.

Your analytics preferences (pageviews on/off and replay consent) are stored only in your browser’s localStorage on this device; they are not stored as a user account on our servers. Analytics and replays run only on the production domain (say-no.app), not on localhost during development. No marketing cookies are set for this purpose. Language preference may use a functional cookie or local storage for locale selection.

3.3 Fonts

Fonts (Fraunces, Sora) are served locally with the website and are not loaded from third parties (such as Google Fonts).

3.4 Contact by email

If you contact us by email, we process the data you provide (email address, message content, name if any) to respond to your request. Legal basis is Art. 6(1)(b) GDPR (pre-contractual/contractual communication) or Art. 6(1)(f) GDPR (general inquiries).

3.5 Waitlist

If you join the waitlist via the form on this website, we process the email address you provide, your selected language (locale), the subscription status (for example pending, confirmed, or unsubscribed), and related timestamps (for example creation, confirmation, and last update). We use this data solely to inform you about the launch, beta availability, or store release (App Store, later Google Play) of the No! app. We do not use waitlist data to build advertising profiles and do not sell it to third parties.

Signup uses double opt-in: after you submit the form, we send a confirmation email with a link. Only after you confirm via that link do we treat your address as confirmed for waitlist messaging. Until then the entry remains pending. Invalid or expired confirmation links cannot complete signup; you may request a new confirmation via the form.

Waitlist data is stored in a PostgreSQL database on our Hetzner server in Germany. The database runs in our self-hosted application stack and is not provided via Vercel Prisma Storage. Access is server-side only for operating the waitlist (subscription, confirmation, and status updates).

Confirmation and related transactional emails are sent via Postmark (ActiveCampaign, LLC / Postmark) on a transactional message stream. Launch, beta, and other list-style updates are sent on a Postmark Broadcast stream. We send from our domain say-no.app (for example waitlist@say-no.app). Broadcast messages include Postmark’s unsubscribe link (and related list-unsubscribe headers). If you unsubscribe, Postmark notifies this website via a server-side webhook so we can remove your waitlist entry from our database. Postmark processes the recipient address and message content as needed to deliver the mail and manage suppressions. Where Postmark processes data outside the EU/EEA, transfers rely on appropriate safeguards where required (for example standard contractual clauses or an adequacy decision). See Postmark’s privacy information for further detail.

Legal basis for processing confirmed waitlist entries and for sending launch or beta information is your consent under Art. 6(1)(a) GDPR, given by completing the double opt-in. You may withdraw consent at any time with effect for the future via the unsubscribe link in Broadcast emails or by email to the controller. After unsubscribe (or a hard bounce / spam complaint that Postmark suppresses), we delete your waitlist row from our database. We otherwise retain waitlist data until the purpose ends (for example after relevant launch or beta messaging is complete) or you request deletion; we then erase or anonymize the data unless statutory retention duties apply. For access, erasure, or other rights regarding your waitlist entry, contact kontakt@waldemarenns.de as described in section 7.

3.6 Error monitoring and performance (Sentry)

To detect and fix technical errors and performance problems on this website, we use Sentry (Functional Software, Inc. / Sentry). The Sentry organization for this project is configured in the EU (data hosted in the EU region, ingest endpoint under de.sentry.io). When an error or performance issue occurs, technical diagnostic data may be sent to Sentry — for example error message and stack trace, page URL, browser/device information, and approximate timing of the request. We do not intentionally send reflection content from the mobile app (that data stays local on the device). Legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, secure operation and quality of the website).

Sentry processes this data as a processor for error and performance diagnostics. Where Sentry or its sub-processors process data outside the EU/EEA, transfers rely on appropriate safeguards where required (for example standard contractual clauses or an adequacy decision). See Sentry’s privacy documentation (sentry.io/privacy) for further detail. Events are retained according to our Sentry project settings and only as long as needed to diagnose and fix issues.

4. Mobile app “No!”

4.1 No account

The app requires no registration and no login. No user account is created on a server. The app is sold as a one-time purchase processed by Apple through the App Store (for the Android version, later by Google through Google Play).

4.2 Local storage

On the device (e.g. via AsyncStorage) the app stores, among other things:

  • Reflection entries (situation, feelings, reaction, notes)
  • optional display name
  • language setting
  • onboarding status
  • settings for local reminders, if any

These data do not leave the device via a backend service we operate. There is no cloud sync and no server-side analysis of your reflections. Weekly review counts are computed on the device from your local entries.

Legal basis for local processing on your device is your use of the app (Art. 6(1)(b) GDPR) or your legitimate interest in the app’s functionality (Art. 6(1)(f) GDPR). You can delete the data in the app at any time or uninstall the app.

4.3 Local notifications

If you enable reminders, the app schedules local notifications on the device. No push content is sent via an external messaging service by us. You control the system permission for notifications in your device settings (iOS, and Android once that version is available).

4.4 App stores and device manufacturers

When downloading and using the app, Apple (App Store) — and, once the Android version is available, Google (Google Play) — as well as the device manufacturer may process their own data (e.g. purchase handling, device identifiers, crash reports if you allow them). These processings are subject to the privacy policies of the respective providers. We have only limited influence on them.

4.5 No health-data cloud, no therapy offering

No! is a practice room for self-reflection and deliberately distances itself from therapy and medical advice. The app is not a medical device. The weekly review shows counts from your entries, not clinical advice. In mental health crises, please seek professional help locally.

5. Recipients and third-country transfers

Beyond the parties named in this policy (Hetzner for website hosting and self-hosted infrastructure in Germany, self-hosted Umami on Hetzner in Germany, Sentry for error/performance diagnostics with EU-region hosting, email, app store providers), we do not share personal data from app use with third parties. Where service providers process data in third countries, this is done, where applicable, on the basis of appropriate safeguards (e.g. adequacy decision / EU–US Data Privacy Framework or standard contractual clauses). We process website hosting, waitlist database, object storage, and Umami analytics data on self-hosted infrastructure in Germany. Sentry error events for this website use the EU data region.

6. Retention

  • Website logs, analytics, and error diagnostics: technical access data on our Hetzner server only as short as required for security and operation, then deletion or anonymization; Umami analytics and replay data on our Hetzner server only as long as needed to evaluate and improve the website, then deletion or anonymization; Sentry error and performance events according to our Sentry project retention settings and only as long as needed to diagnose and fix issues.
  • Email inquiries: as long as handling and any documentation require; then deletion unless statutory retention duties apply.
  • App data: until you delete them in the app or uninstall the app.

7. Your rights

Under the GDPR you have in particular the right to:

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)

To exercise your rights, a message to kontakt@waldemarenns.deis enough.

You also have the right to lodge a complaint with a data protection supervisory authority. Among others, the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg is competent.

8. Obligation to provide data

You can use the website without providing personal data. Core app features do not require your name; the display name is optional. The app is sold as a one-time purchase in the respective app store.

9. Changes

We may update this privacy policy if the app, website, or legal situation changes. You will find the current version on this page.

Back to home · Legal notice

No!

A quiet app for practicing boundaries at work, at home, and with friends.

Product

How it worksPrivacyFeaturesWeekly reviewFounderFAQRoadmap

Legal

Legal noticePrivacy
Contact

© 2026 Waldemar Enns

iOS first, Android to follow. Your data stays on the phone.