Crowdergy
Privacy Policy
This Privacy Policy applies to the Crowdergy iOS app, the Crowdergy Home Assistant connector and the Crowdergy backend API. The controller within the meaning of the GDPR is:
Colin Wilke Consulting
Pfarrer-Holl-Weg 43
40489 Düsseldorf, Germany
Email: info@crowdergy.de
1. What data we process
1.1 Account data
When you register we store your email address and a hashed password (bcrypt – we cannot see your plain-text password). The email address is used for signing in and for account recovery. If you use Sign in with Apple, we receive the email address (or Apple’s private relay address) provided by Apple.
1.2 Device and energy data
When you set up the Crowdergy connector in your Home Assistant, the connector transmits the following data to our backend:
- Device name and type (e.g. “home battery”, “battery”)
- Location metadata (district, city, region): the place names you entered. From the district we derive approximate coordinates via geocoding (OpenStreetMap Nominatim, see 3.3) and store them with the device so the aggregation map can be drawn. The coordinates mark the centre of the district, not your home address – typical resolution a few hundred metres. We do not collect a live location of the device or your phone.
- Current power in kW and state-of-charge values of your devices (energy time series)
- Configuration status (which Home Assistant entities you have mapped)
Energy time series can allow inferences about presence, sleeping times and charging sessions. They are the basis for the app display, the anonymised neighbourhood aggregation and the future Crowdergize token accounting. During the beta phase we retain this raw telemetry indefinitely; automatic consolidation of older data (hourly averages after 90 days, full deletion after 1 year) is in preparation. Until then you can remove your entire energy history at any time by deleting your account.
1.3 Session and log data
When the API is called we log on our server:
- IP address (for rate limiting and security logs, max. 30 days)
- Time and endpoint of the call
- Error messages (anonymised via Sentry – see section 3)
1.4 Data we do not collect
We do not track a live location of your phone, no phone identifiers (IDFA, IDFV), no advertising IDs, no contacts and no photos. The Crowdergy iOS app uses the Apple Keychain to store your tokens securely. Push notifications use an Apple device token that is tied to your account and deleted when you sign out.
2. Where we store the data
- Backend: dedicated server at Hetzner Online GmbH (located in Germany). Encrypted transmission via TLS 1.2/1.3.
- Database: PostgreSQL on the same server, no cloud service.
- No disclosure to third parties for advertising or analytics purposes.
3. Third parties
3.1 Sentry (crash and error reports)
We use Sentry (Functional Software, Inc., USA) to collect app crashes
and backend errors anonymously. Data transmitted: stack trace, app
version, anonymised device info (model class, iOS version).
No personal data is sent deliberately
(send_default_pii=False). The Sentry servers receiving our
events are located in Germany (EU ingest). You can turn crash
reporting off in the app under Settings → Feedback & Legal →
“Send crash reports”.
3.2 Apple TestFlight
During the beta phase we use Apple’s TestFlight to distribute the app. Apple receives your TestFlight sign-in data and crash reports under Apple’s own privacy policy.
3.3 Apple MapKit & OpenStreetMap Nominatim
The aggregation map uses Apple MapKit (Apple Inc.) and OpenStreetMap Nominatim (OSMF UK) to geocode your location entries. During geocoding the district/city name you entered is transmitted to Nominatim.
4. Your rights (GDPR Art. 15–21)
You have the right at any time to:
- Access (Art. 15) the data stored about you
- Rectification (Art. 16) of inaccurate data
- Erasure (Art. 17) – directly in the Crowdergy iOS app via Settings → Account → Delete account or by email to info@crowdergy.de. This irrevocably removes the account, all linked devices and the complete energy history from our system.
- Restriction of processing (Art. 18)
- Objection (Art. 21) to processing
- Data portability (Art. 20) – export of your data in a common format
To exercise your rights, simply contact info@crowdergy.de.
5. Data security
- HTTPS enforced with HSTS (1 year including subdomains)
- Rate limiting on auth endpoints to protect against brute force
- Strict Content Security Policy and X-Frame-Options
- Minimum password length 8 characters, bcrypt hashing
- JWT refresh-token rotation with revocation blacklist (Redis)
6. Changes to this Privacy Policy
Changes are documented here. Materially updated versions are announced to users in the app.