Legal
Privacy policy
This policy covers the iOS app Celeris and this website. They are treated separately because they work differently: the app needs no server, the website by its nature sits on one.
In short: Celeris has no accounts, no trackers, no ads and no analytics. All astronomical calculations run on your device. There is no server for the app to send anything to.
Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
Stefan Engel
Talstr. 25
66994 Dahn
Germany
Email: info@stefan-engel.biz
No data protection officer has been appointed; the statutory conditions for one are not met.
The Celeris app
What the app does not do
- No user accounts, no registration, no login
- No tracking across apps or websites
- No third-party analytics, statistics or crash reporting
- No advertising and no advertising identifiers
- No server of its own for data to be sent to
This is what the app's privacy manifest declares as well: no collected data types and no tracking.
What is stored on the device
The app remembers a few settings locally so that it carries on where you left off:
- The map section last planned for (longitude and latitude)
- The object last chosen from the catalogue
- Whether the introduction has already been shown
- Focal length and place for the widget
These values live in the app's own settings and in a shared container the widgets can read. They do not leave the device and are removed when the app is deleted. Whether they end up in a device backup is decided by your iCloud or iTunes settings, over which the app has no influence.
Location
The app asks for the device location only when you tap the location button in the top row, and it uses it for nothing but moving the map to your position. The location is neither transmitted nor logged; what is stored is the map section last planned for, as described above.
Granting access is voluntary. Decline it, or withdraw it later in the iOS settings, and the app remains fully usable — the map can be dragged by hand or reached through the place search. The legal basis is your consent given through the iOS system dialogue, Art. 6(1)(a) GDPR, together with the performance of the function you asked for, Art. 6(1)(b) GDPR.
Maps, place search and time zones (Apple)
For three things the app relies on Apple system services, which in turn talk to Apple servers:
- Map display — the map imagery comes from Apple Maps (MapKit)
- Place search — your search input is resolved into suggestions by Apple
- Time zone determination — the time zone for the coordinates under the crosshair is looked up through Apple's geocoding
The coordinates and search inputs concerned are transmitted to Apple and processed there on Apple's terms. I do not receive this data and have no access to it. The legal basis is Art. 6(1)(b) GDPR, as these functions are an essential part of the app.
Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA, and Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Details in Apple's privacy policy.
Obtaining the app through the App Store
Purchase, download and updates are handled by Apple. Data arising there — your Apple account identifier and purchase information, for instance — is processed by Apple under its own responsibility. What I see of it is aggregated, non-personal sales and crash statistics in App Store Connect.
This website
Hosting and server log files
This website is hosted by 1blu AG, Riemannstraße 1, 10961 Berlin, Germany. There is a data processing agreement with the provider under Art. 28 GDPR: 1blu processes the access data named below solely to perform the hosting contract and is bound by my instructions in doing so. The servers are in Germany; no transfer to a third country takes place.
When a page is requested, the server automatically records the usual access data:
- IP address of the requesting device
- Date and time of the request
- Name and address of the file requested
- Amount of data transferred and whether the request succeeded
- The page visited before (referrer), where it is sent
- Browser type, browser version and operating system
This data is technically necessary to deliver the site, keep it stable and fend off attacks. The legal basis is Art. 6(1)(f) GDPR; the legitimate interest lies in the secure and undisturbed operation of the site. It is not combined with other data, and no profiles are built from the log files.
For the retention period 1blu names no fixed term but criteria (Annex 3 to the data processing agreement): full IP addresses are recorded only as far as the proper operation of the servers requires it — to fend off attacks, to establish misuse of services, or for disclosure to law enforcement authorities. Log files holding unmasked IP addresses are rotated automatically. Where IP addresses are kept for longer, as the basis for access statistics for instance, one octet (IPv4) or one hextet (IPv6) is masked, so that they can no longer be attributed to a particular person.
No cookies, nothing embedded from third parties
The site sets no cookies and uses no analytics, reach measurement or tracking tools. There is no cookie banner because there is nothing to consent to. Fonts, images, stylesheets and scripts are all on this server; nothing is loaded from foreign servers — no web fonts, no CDNs, no embedded videos or maps.
A few external sites are linked, such as GitHub and Creative Commons. Only when you click such a link does your browser connect to that provider. Its own data processing is its own responsibility.
Contact by email
There is no contact form. If you write to me, I process your address and the content of your message in order to answer it. The legal basis is Art. 6(1)(b) GDPR for enquiries about the app and Art. 6(1)(f) GDPR otherwise. Messages are kept for as long as handling them requires and are deleted afterwards, unless statutory retention periods say otherwise.
Your rights
You have the following rights against the controller:
- Access to whether and which data about you is processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on a legitimate interest (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR) — location access can be withdrawn at any time in the iOS settings
An informal mail to info@stefan-engel.biz is enough for any of these.
Independently of that, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for instance the authority responsible for my place of residence or the one where you habitually reside.
This policy is current as of July 2026. It is a translation for convenience; in case of doubt the German version applies.