Privacy Policy

Last updated: August 2026

This Privacy Policy informs you about the nature, scope and purpose of the collection and use of personal data by the app “Klip” and by this website.

1. Data Controller

Florian Murnig
Kreuzstraße 11
6067 Absam, Austria
Email: office@dynamo.at
Phone: +43 650 9292200

2. Core Principle: Local-First Storage

Klip operates on a strict local-first architecture. Your clients, projects, tasks, hourly rates, notes, time entries, receipts and invoice data are stored locally on your device in a protected SwiftData database. We do not operate any database servers and have no access to your logged data at any time. Optionally, you can create backup files (Klip Backup) that are stored exclusively where you decide.

Legal basis: performance of a contract / provision of app functionality (Art. 6(1)(b) GDPR).

3. No Processors, No Third-Country Transfers

We do not engage any processors to operate Klip and we do not transfer data to third countries. There is no Klip server, no analytics, tracking or advertising services, and no crash reporting to third parties.

Data reaches other companies only where you actively use a feature: iCloud sync through your own Apple account (section 4), an automatic backup into a cloud folder you choose (section 5), and the invoice export to an accounting tool that you trigger yourself (section 7). In those cases you are the controller responsible for the disclosure.

4. Apple iCloud Synchronization (CloudKit)

If iCloud sync is enabled, your data is synchronized across your devices through your personal Apple ID via Apple CloudKit. Transmission and storage are encrypted and handled directly between your devices and the servers of Apple Inc. We have no access to your iCloud container or your encryption keys.

Legal basis: your consent / performance of a contract (Art. 6(1)(a) and (b) GDPR). Withdrawal: you can turn sync off at any time in Klip’s settings under “iCloud sync”; your data then remains local to each device.

5. Automatic Backup (Klip Pro)

If you use automatic backup, the app writes backup files into a folder of your choice – in iCloud Drive, Google Drive or Dropbox, for instance. The file leaves your device only through the service you selected; its further processing is governed by that provider’s privacy policy. No data is transmitted to us.

Legal basis: your consent (Art. 6(1)(a) GDPR). Withdrawal: at any time by disabling the feature in settings.

6. Device Permissions

Klip requests device permissions only when you actively use the corresponding feature. All processing described here happens exclusively on your device:

  • Contacts: when importing client details, Klip accesses your address book after your permission and imports only the entries you select.
  • Calendar (EventKit): when importing events as tasks, Klip reads your calendar entries after your permission. Only the events you select are imported locally – Klip never writes to your calendar and never transmits data to third-party systems.
  • PDF receipts (on-device text extraction): when you attach a receipt PDF, its text is extracted purely on device to prefill amount, date and vendor. The PDF remains exclusively in the app’s local support directory; no external service receives the document.
  • Siri, Shortcuts, widgets & Live Activities: system-level interactions are processed natively by iOS and macOS.

Legal basis: your explicit consent, given at first access (Art. 6(1)(a) GDPR). Withdrawal: at any time through your device’s system settings (Privacy & Security).

7. Optional Invoice Export to Third Parties (Klip Pro)

Klip optionally lets you transfer selected billable time entries as a draft invoice into an external invoicing tool (GrandTotal, sevdesk, Lexware Office, Billomat, FreshBooks). This feature is disabled by default and only runs when you actively trigger it.

  • Local providers (GrandTotal): data is provided purely locally via the clipboard or a file; no transmission to external servers takes place.
  • Cloud providers: on export, Klip transmits the required data – client name, line-item descriptions, hours and amounts – directly and encrypted (HTTPS) from your device to the API of the provider you selected. There is no Klip intermediary server. Your credentials (API tokens and keys) are stored exclusively in your device’s Apple Keychain. Further processing by these providers is governed by their respective privacy policies; you as the user are the controller responsible for this disclosure.

Legal basis: your consent, given explicitly before the first cloud export (Art. 6(1)(a) GDPR). Withdrawal: at any time by deleting the stored credentials in Klip’s settings; invoices already transferred must be removed at the provider yourself.

8. In-App Purchases (Apple StoreKit)

Purchases of “Klip Pro” are processed entirely through Apple’s App Store (StoreKit). We never receive or store your credit card or billing details. Apple only provides an anonymized transaction token to unlock the Pro features.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

9. Retention & Deletion

Because your data lives on your device, you determine how long it is kept. There is no server-side retention on our side and therefore no retention periods we could enforce.

  • Individual records are deleted directly in the app.
  • “Reset / Delete All Data” removes every record permanently from your device and from your CloudKit container.
  • Removing the app deletes the locally stored data, receipts and backups inside the app directory. Backups you placed in a cloud folder yourself remain there until you delete them.
  • Credentials stored in the keychain for invoice export are deleted in Klip’s settings.

10. Security

The local database resides in the protected app directory and is covered by the device encryption of iOS and macOS. Credentials for the optional invoice export are stored in the Apple Keychain, not in the Klip database. Every outbound transfer – iCloud sync as well as invoice export – uses transport encryption over HTTPS/TLS. This website is served over HTTPS only.

11. Your Rights

Under the GDPR you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent with effect for the future (Art. 7(3) GDPR)
  • Right not to be subject to a decision based solely on automated processing (Art. 22 GDPR) – no such processing takes place in Klip

You can exercise access and portability directly yourself: the app exports your complete dataset at any time as a JSON backup or as CSV.

You also have the right to lodge a complaint with the competent supervisory authority: Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria.

12. This Website: Cookies & Local Storage

This website uses no tracking, marketing or analytics cookies and embeds no third-party services for audience measurement. For your language choice (DE/EN) we store a single technical value in your browser’s localStorage. It is functionally necessary, contains no personal data and is never transmitted to us. You can reset it at any time via your browser settings or the notice at the bottom of the page.

13. Contact

For privacy inquiries: office@dynamo.at

This text is for information only and does not constitute individual legal advice.