Who is responsible
inndevs GmbH, Dammstrasse 19, 6300 Zug, Switzerland, is responsible for the personal data described here. For a privacy request, use the contact form or write to that postal address.
Website operation and hosting
inndevs.com does not use analytics or advertising trackers. The site and its server-side mail service are hosted in Switzerland by hosttech GmbH. hosttech and authorised inndevs personnel can access data where needed to operate, secure, and support the service.
The server records ordinary request logs containing the IP address, timestamp, requested URL, referrer, browser user agent, response status, and transferred size. We use these logs to keep the site reliable, diagnose errors, and investigate abuse. Logs rotate when they reach approximately 200 MB; one compressed rotated file is retained and older rotations are deleted.
Emoji Picker keeps first-party aggregate acquisition and commerce counts for download starts, checkout starts, verified paid checkouts, and successful license-email delivery. A counted download records only the day, an allowlisted source and campaign, the release version, and a coarse browser family. Obvious automated requests and a repeat for the same release within 30 minutes in the existing anonymous browser session are not counted.
The metrics store does not keep IP addresses, raw user agents, referrers, URL or app-search queries, session IDs, payment identifiers, names, email addresses, license values, or inserted content. Unknown attribution values are grouped as “other.” Daily breakdowns and one-way idempotency digests are deleted after 400 days. All-time totals are aggregate-only and are retained for product planning. Allowlisted attribution in the session expires after 12 hours; the session cookie itself expires when the browser session ends.
A strictly necessary inndevs_contact session cookie supports one-time form tokens, submission feedback, and optional Emoji Picker admin sessions. The cookie expires when the browser session ends. Public form tokens are valid for up to two hours; admin sign-in uses a password and Cloudflare Turnstile, and admin sessions expire after 12 hours.
Public Emoji Picker support
The Emoji Picker support board lets you publish a support question, issue report, feature request, or comment without an account. The public page displays the name, content, attached images and files, optional app and macOS versions, timestamps, topic status, and any official Admin badge. The email address you provide is stored privately outside the public website and is used to identify and follow up on the submission; it is never displayed on the board.
“Email me about replies” is selected by default and can be cleared before publishing. We send a confirmation email and start notifications only after you confirm. Each notification is sent separately and includes a link to stop emails for that discussion. Confirmation links expire after 24 hours.
Public discussions remain available so other users can find answers and add context. Do not include license keys, receipts, email addresses, or other private information in public text or attachments. You can ask us through the private contact form to correct or remove a post. Imported historical discussions retain their original public author, content, date, status, and source attribution.
To prevent abuse, support forms use one-time session tokens, a honeypot, timing checks, link and length limits, Cloudflare Turnstile, and IP-derived pseudonymous rate limits. New public posts and comments also generate a private email notification to the inndevs support mailbox.
Contact form
When you submit the form, we receive the name, email address, optional subject, and message you provide so we can reply and, where requested, discuss a product, project, or possible contract. The message is delivered through the hosting server's mail service to the inndevs company mailbox and is accessible only to people handling the request.
Messages are kept for as long as needed to answer and follow up on the request. They may be kept longer where the conversation becomes part of a customer or contractual record, or where legal documentation and retention duties apply.
To prevent abuse, the form keeps an IP-derived pseudonymous rate-limit key and submission timestamps. Only timestamps within the preceding one-hour window are used; stale entries are discarded when that rate-limit key is evaluated again.
Cloudflare Turnstile
The contact and public support forms use Cloudflare Turnstile to distinguish legitimate visitors from automated abuse. Turnstile loads when a protected form approaches the viewport or you interact with it. Cloudflare then processes technical signals such as the IP address, TLS fingerprint, browser user agent, site key, and page origin. Cloudflare processes these signals as our service provider for site protection and as an independent controller when improving its bot-detection service.
Cloudflare, Inc. is based in the United States and operates global infrastructure, so Turnstile data may be processed outside Switzerland. Details are in Cloudflare's Turnstile privacy addendum. If Turnstile is blocked, the website remains readable but protected forms cannot be submitted.
Why we process this data
We process server logs, rate-limit data, session data, and Turnstile signals because they are necessary for our legitimate interest in operating and protecting a reliable website. We process contact messages and public support submissions to respond, maintain a useful product-support history, and take steps you request, including before a possible contract. We retain records where required by contractual or legal duties. Processing is governed primarily by the Swiss Federal Act on Data Protection; the GDPR also applies where its territorial scope is met.
Your choices and rights
You can ask whether we process personal data about you and request access, correction, deletion, restriction, objection, or portability where the applicable law provides those rights. You may also withdraw consent where processing relies on consent. We may need information confirming your identity before fulfilling a request, and legal retention duties can limit deletion.
Send a request through the contact form or to the postal address above. You may also contact the Swiss Federal Data Protection and Information Commissioner.
Product privacy
Products can handle different information and permissions. Read the available product-specific privacy, support, and legal information:
External links
Links to product sites, GitHub, payment providers, and other external services take you to their systems. Their own privacy terms apply once you leave inndevs.com.