Privacy policy
As of October 2026 ·
Deutsche Fassung
This is a translation of our German privacy policy
(Datenschutzerklärung).
The German version is authoritative (Maßgeblich
ist die deutsche Fassung).
This policy describes which personal data we process when you use the
website landstimme.de, the Landstimme app
and the pages behind our QR codes (at
api.landstimme.de). We want to collect as little data as
possible. At its core the app works without an account and without you
revealing who you are, and you need neither the app nor an account for a
story behind a QR code.
1. Controller
Expert Sieve UG (haftungsbeschränkt)
Wilhelm-Raabe-Str. 6
04416 Markkleeberg
Germany
Privacy contact: hallo@landstimme.de
Further details in the imprint.
2. Website landstimme.de
Visiting the site (server logs)
When you visit the website, your browser transmits technically necessary
data (IP address, time, requested page, browser identifier). This data is
needed to deliver the site and to keep it secure. The legal basis is our
legitimate interest in a secure, working website (Art. 6(1)(f) GDPR). Server
logs are deleted after 30 days at the latest and are not
combined with other data.
Audience measurement (Pirsch Analytics)
To see how often our pages are visited and which of them people look for,
we use Pirsch Analytics by Emvi Software GmbH
(Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Germany). The service works on
our behalf (Art. 28 GDPR) and processes the data on servers in Germany and
the EU.
Pirsch sets no cookies and stores no IP
addresses. From your IP address, your browser identifier, the date
and a random value valid only for this website, a number is formed that
cannot be reversed. Because the date is part of it, this number changes
after 24 hours at the latest; because the random value belongs only to
landstimme.de, your visit cannot be tracked across other websites. What is
recorded is the page view, the referring source and, roughly, country,
device type and browser. No profile of you is created from this.
In addition we count three events on the home page: a
click on a store link (App Store or Google Play, with whether it was in the
header or the footer), paging through the audio samples (with the
direction) and playing an audio sample (with the name of the sample). We
want to know whether the page leads to the app and whether, and which,
audio samples are looked at and listened to. All that is stored is that such
an event happened — the same non-reversible number as for the page view, no
additional attribute about you.
The legal basis is our legitimate interest in knowing whether and how our
service is used (Art. 6(1)(f) GDPR). You can object to this processing at
any time — informally by email to
hallo@landstimme.de.
The website uses no tracking cookies and no
advertising networks.
3. The Landstimme app
Location
Landstimme plays audio stories that match your position — on the road by
car as well as on foot, for example on a walk through a town. To do this the
app processes your location on the device to find out which
place is nearby. Your route — driven or walked — is only recorded
continuously if you expressly agree (see “Your route”). Without that
consent your exact route does not leave the device.
Anonymous usage data
To understand whether stories are triggered at the right place and at the
right time, we record to a limited extent which story was played
when, as well as some technical details for
troubleshooting (app version, operating system and its version, and
the rough type of surroundings at the moment of triggering — motorway,
built-up area or country road —, the search radius derived from it, what
triggered the story — a sign, the place itself, entering an area or the
motorway you are driving on — and how far away this trigger point was, and
— if a story did not come about — the technical reason, such as “being
created”, “no text available” or “no connection”, together with the
player's error message verbatim, so that such cases can be
fixed at all; this message comes from your device and the player, not from
you, and contains nothing you entered). This data is linked to a random
installation number, not to you as a person, and contains
no continuous location trail. The legal basis is our
legitimate interest in a working app (Art. 6(1)(f) GDPR). This data is
deleted after twelve months.
For every story that was played or failed we also record
in which language it was played or requested. This shows us
how often stories are heard in a language other than German and whether
they arrive late or not at all more often there — in other languages they
are only created when needed. The same link to the installation number, the
same legal basis and the same period of twelve months
apply.
App language
The app is available in several languages. After a new installation it
follows the language of your phone; you can change it in the settings. So
that stories, announcements and texts come in your language, the app sends
the language it is running in when it fetches content. This information is
only processed for that purpose and not stored: our
application removes it from its access logs, and in normal operation
requests to the app's interface are not logged at the entrance to our
servers. Only if a request is refused there (for example because of too many
requests in a short time) or fails with an error is an entry with the IP
address and the full request, including the language, created — solely to
fix the fault. These entries are kept in our operational logs and deleted
after 30 days at the latest. The language
is stored only where this policy says so: with the anonymous usage data
(above) and with support requests (below). The legal basis is our legitimate
interest in delivering content in your language (Art. 6(1)(f) GDPR).
Your route (only with consent)
To improve how accurately stories are triggered, the app can send the route
you have travelled (GPS points) to our server — whether driven or
walked makes no difference: walks are covered by the same consent,
the same purpose and the same retention period as drives. This happens
only if you agree in the app (“Save route”, Art. 6(1)(a)
GDPR). If you do not agree, no such data is transmitted or stored. The
transmitted route, too, is linked only to a random, replaceable
installation number, not to you as a person; you can reset this
number by reinstalling the app. You can withdraw your consent in the
settings at any time; from then on no further route data is transmitted.
Stored route data is deleted after twelve months.
From this route data, already transmitted, the app derives on request the
start and end places of a trip (the name of the town or of
a nearby place), so that your past drives and walks are shown in the history
with a place name such as “Berlin → Leipzig” instead of only a date. No new
data is collected for this; only the position data already available with
your consent is used, and the query is limited to your own installation
number. These derived place names are stored for display on your
device and are excluded from device backups — see
“Device backup (iCloud and Google)” below.
Map in walking mode
When you set off on foot in a town, the app shows you a map. The map
sections (“tiles”) come from our own service on our
servers — deliberately not from a third-party map provider: it would
see your IP address and the requested section and would thus know roughly
where you are. So no further service provider is involved
for the map.
Your map requests are not logged: neither at the entrance
to our servers nor in the map service itself is it recorded which section
someone requested. In normal operation no record of where you have been is
created. Only if a request fails with a server error is an
entry with the IP address and the requested path created — solely to fix
the fault. These entries are kept in our operational logs and deleted after
30 days at the latest. The legal basis is our legitimate
interest in a working service (Art. 6(1)(f) GDPR).
The map data comes from OpenStreetMap; the attribution is
shown in the map.
Support requests (Feedback & Support)
When you write to us via “Feedback & Support” in the app, we process
the text you voluntarily enter, some technical details (app
version, operating system and version, the language you use the app in — so
that we can reply in that language) and your IP address, in
order to handle your request and reply to you. The text may contain personal
data if you write it in (such as your name or contact details) — only give
what your request needs. The IP address is used to protect against misuse
(limiting the number of requests). The legal basis is the handling of your
request (Art. 6(1)(b) and (f) GDPR). Requests are matched through a random
identifier of the request stored on your device, not through a user
account. Support requests are deleted after 90 days.
Requested city tours
If you are in a place for which there is no city tour yet, the app offers
to let you wish for one. If you tap it, we store: the place
name, the district, a location rounded to
about one kilometre, the anonymous device identifier mentioned
above and the time. This shows us for which places tours are wanted, and we
decide on that basis which ones to create next. The legal basis is our
legitimate interest in developing the app further (Art. 6(1)(f) GDPR).
This information remains stored and is not deleted after a
fixed period. The reason is the purpose itself: we want to see over years
for which places tours are wanted and decide which ones to build. A number
that disappears again after a year does not measure that.
The anonymous device identifier is not in the record to recognise you, but
to prevent double counting: a second wish from the same
device for the same place does not count again. Without it the number would
be worthless, because a single person could wish for a town any number of
times. Neither a name nor an exact location is in the record — the location
is rounded to about one kilometre.
You can have this information deleted: informally to
hallo@landstimme.de, stating your
installation number from the app settings. You can also object to the
processing at any time (Art. 21 GDPR).
To recognise which place you are in at all, your location is sent to our
server and compared with the place boundaries there. This exact
location is not stored and not logged — it is only processed for
the duration of the request. Only the rounded value is stored, and only once
you actually wish for a tour.
If you correct the recognised place, we store the name you entered. In that
case we store no location. Please only enter the place
there, no names or addresses.
Notice about a new version of the app
When it starts, the app checks whether a newer version is available in the
store it came from. If there is one, a dismissible notice appears with a
button to the store. The check happens at most once every 24
hours and only after you have completed the introduction.
On the iPhone this sends a request from your device
directly to Apple. Transmitted are your IP
address and the fact that exactly this app is being looked up in
the German store. No identifier of your installation and not your
location are included. The request does not go through our
servers; we store nothing about it. Apple processes it
as an independent controller — according to Apple's own
privacy policy, Apple Distribution International Ltd. (Ireland) is
responsible for users in the European Economic Area. Processing outside the
EU cannot be ruled out; there is therefore a third-country
link. The legal basis is our legitimate interest in you using a
current version with bugs fixed (Art. 6(1)(f) GDPR).
On Android devices the app asks the Play
Store installed on the device whether an update is available. This
adds no recipient: Google already knows which apps are
installed on the device and which version they are on. Here, too, no
identifier and no location are included, and we store nothing.
Device backup (iCloud and Google)
If you have device backup switched on — iCloud Backup on the iPhone, Google
backup on Android — your phone copies the data of installed apps to your own
cloud account and restores it on a new device. The same data moves along
when you switch from one phone to a new one.
Excluded from this backup are: your consent
decision, your installation number, the
route recorded on the device, usage events not yet sent,
your past trips including place names, the exact
location the app briefly holds for a city tour wish, and the access
credentials of your support requests.
The reason is the same as for the identifier itself: consent you gave on
one device should not apply to a second one without asking, and a movement
trail should not leave your phone at all — not even into your own cloud
account. The price for this is intended: after switching devices the app
asks for consent again, and the list of your past trips starts afresh.
Your settings are backed up — chosen voice, short or long
version, minimum pause, categories — together with the lists of places
heard, saved and visited in walking mode, so that your history survives the
switch. This data is then in your own Apple or Google account; we have no
access to it.
4. QR codes and short links (api.landstimme.de)
In magazines, on notices, on flyers or in emails we hand out QR codes. They
lead either to exactly one recorded story or — as a short
link — to another page, such as a campaign page or an app store
listing. Both are at api.landstimme.de. You need
neither the app nor an account, and we set no
cookie.
Visiting the page (server logs)
As with every page visit, technically necessary logs are created (IP
address, time, requested page, browser identifier). They are needed to
deliver the page and keep the service secure; the legal basis is our
legitimate interest in a secure, working service (Art. 6(1)(f) GDPR). The
code's short key is removed from the log — it only shows
that a code page or a short link was called, not which one. So the log
cannot reveal who listened to which story or scanned which flyer. The logs
are collected centrally and remain retrievable beyond updates of the
service; they are deleted after 30 days at the latest.
We do not combine them with other data.
Counters per code
For each code we hand out, we count how often its page was opened
and how often Play was tapped, plus the first and the last call.
Calls after a code has expired are counted separately. This shows us
whether a cooperation is used at all — the legal basis is our legitimate
interest in this evaluation (Art. 6(1)(f) GDPR).
Only these numbers are stored: no IP address, no device
identifier, no cookie and no record per individual call. Two calls therefore
cannot be attributed to the same person, not even afterwards. The numbers
remain stored as long as the code exists.
Short links (flyers, notices, campaign pages)
A short link has no page of its own: when you open it, we
forward you directly to the stored target address — without an intermediate
page, without a click, without a cookie and without a consent prompt. The
same applies to the call as above: the logs are created, the short key is
not in them.
For each short link we count how often it was opened per
day, plus the total and the first and last call. This shows us
whether a flyer achieves anything — the legal basis is our legitimate
interest in this evaluation (Art. 6(1)(f) GDPR). Only these
numbers are stored: no IP address, no device identifier, no
referring source and no record per individual call. Two calls therefore
cannot be attributed to the same person, not even afterwards. The stored
time of the last call is overwritten each time; for a short
link opened only once on a day it is in effect the time of that call.
When forwarding, we usually append an identifier of the printed
code to the target address (utm_source,
utm_medium, utm_campaign). It is visible in your
browser's address bar. The operator of the target page sees it together
with your IP address and the time and processes this information
as an independent controller; with a small print run they
could derive a recognition value from it. We can switch off the appendix
per short link and do so where it serves no purpose. You can remove it from
the address bar before the page loads.
Playing the story
When you tap Play, our server forwards you to the audio file in the storage
service Cloudflare R2. In doing so your IP address
is transmitted to Cloudflare so that the file reaches you. The
operator is Cloudflare, Inc., based in the USA; there is
therefore a third-country link. More below under “Hosting
and processing on our behalf”.
A partner's logo on the page is fetched by our server
itself and delivered with the page. Scanning therefore sends
no request to the partner — they learn neither your IP
address nor when you scanned.
5. Hosting and processing on our behalf
The website and server service are operated by netcup
GmbH (Karlsruhe, Germany) on servers within the EU. The audio files
delivered are kept in the storage and delivery service Cloudflare
R2 (Cloudflare, Inc.). These providers process data on our behalf
(Art. 28 GDPR) and are contractually bound. Cloudflare, Inc. is based in the
USA: when an audio file is fetched — in the app as well as
via a QR code — your IP address is transmitted there, so there is a
third-country link.
The map service for walking mode runs on the same servers
and is operated by us; no third-party map provider is involved.
Audience measurement for the website runs via Pirsch
Analytics (Emvi Software GmbH, Rheda-Wiedenbrück) on servers in
Germany and the EU; more above under “Audience measurement”.
Support requests from the app are processed via our own support service
thredbox, which is operated with the same netcup GmbH in
Germany.
To create the audio texts and voices — including the
translations into other languages — we use service providers for speech
synthesis and text generation. They process place content
(names and facts about sights), not your personal data.
6. Your rights
You have the right of access, rectification, erasure, restriction of
processing and data portability, and the right to object to processing. You
can withdraw consent you have given at any time with effect for the future.
To do so, contact
hallo@landstimme.de.
You also have the right to lodge a complaint with a data protection
supervisory authority.
7. Changes
We adapt this policy when the app or legal requirements change. The version
published here applies in each case; if the English and the German version
differ, the German version prevails.