Effective: May 2026 Provider: Qorvano° — Dustin Dondrup, Pastor-Hoffmann-Straße 20, 48301 Nottuln, Germany Email: info@qorvano.com Phone: +49 174 976 1123 VAT ID: DE422040107
1. Data Controller
The party responsible for data processing within the meaning of Article 4 (7) GDPR in connection with the app “Lineon” is:
Dustin Dondrup Qorvano° Pastor-Hoffmann-Straße 20 48301 Nottuln · Germany Email: info@qorvano.com Phone: +49 174 976 1123
A separate Data Protection Officer is not required under § 38 BDSG given the scope of processing.
2. Scope
Lineon is available as a native app (iOS, Android) and as a web app (https://lineon.qorvano.com/). Data processing differs between the two — please refer to the section that applies to you.
3. Native App (iOS, Android) — no data collection
The native Lineon app itself does not collect, store or transmit any personal data. Distribution of the app and processing of in-app purchases run solely through the Apple App Store or Google Play and are subject to those providers’ privacy policies.
Specifically:
- No registration or account creation required
- No analytics or tracking tools (no Google Analytics, no Firebase Analytics, no Crashlytics)
- No advertising and no ad tracking
- No location data
- No contacts or other device data
- Photo library access only when you actively pick an image — the app processes the selected image strictly locally
- No sharing of data with third parties
All image processing, all calculations and all generated PDFs are produced and stay strictly on your device.
4. Web App (lineon.qorvano.com) — privacy by design
The web variant runs in your browser, served by a host in Germany (IONOS, Frankfurt). Image processing itself happens client-side in your browser — your photo never leaves your device. The server only handles the anonymous payment flow.
4.1 What we store
When you pay for an image, our backend records:
- an anonymous image fingerprint as
HMAC_SHA256(server_secret, sha256(image))— this fingerprint cannot be reversed to the image and is unique to that exact image content, - a timestamp of the payment (
created_at), - an expiry (72 hours after payment,
expires_at), - an export counter (max. 5 re-exports,
export_count), - separately, a replay-protection hash of the PayPal order identifier as
HMAC_SHA256(server_secret, paypal_order_id).
4.2 What we do not store
- No original images — never uploaded to the server
- No generated PDFs — produced in the browser, downloaded directly
- No PayPal order or capture IDs in clear text — only the HMAC hash for replay defence
- No names, email addresses, phone numbers or postal addresses
- No cookies — only the payment status for the active session
4.2a No third-party CDNs, no Google services
The web variant deliberately avoids any third-party CDN that would expose your IP address to a foreign provider:
- Fonts (Inter, Space Grotesk) and Material Icons are served from our own origin (
lineon.qorvano.com). No connection to Google Fonts (fonts.gstatic.com) is opened — the runtime fallback URL has been pinned to our own origin. - CanvasKit (the rendering engine for Flutter Web) is bundled with the app; nothing is fetched from
www.gstatic.com/flutter-canvaskit/.... - HEIC → JPEG conversion for iPhone Photos uploads runs through a self-hosted copy of
heic2any.min.js, not via a public CDN. - No Google Analytics, no Google Tag Manager, no Crashlytics, no Sentry, no Hotjar, no Mixpanel, no Plausible, no Matomo.
The only third-party origin contacted at runtime is PayPal (and only when you actively start a payment) — see § 4.3.
4.3 PayPal as payment processor
Payment runs through PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg). PayPal processes your payment data under its own privacy policy (https://www.paypal.com/en/webapps/mpp/ua/privacy-full). We only receive a confirmation that a payment succeeded — no card data, no account data, no personal master data.
4.4 Server logs
Caddy (our web server) keeps minimal access logs (timestamp, abbreviated IP address, requested URL, HTTP status, user-agent) for 14 days for security, abuse-prevention and error diagnostics. After that period the logs — including the IP address — are deleted automatically.
Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in operating a secure, debuggable web service. You may object to this processing under Art. 21 GDPR; in that case we will examine whether your legitimate interests outweigh ours.
5. In-App Purchases (Native)
Lineon native offers two pricing options:
- Single PDF export — as a consumable via Apple IAP or Google Play Billing
- Lifetime unlock — as a non-consumable, restorable via “Restore purchases” on reinstall
Qorvano° never has access to your payment information (card details, bank information, etc.). Processing is handled solely by Apple or Google:
6. Local Data Storage (Native)
The native app stores the following on your device:
- Currently edited image (during a session, not persistent)
- Generated PDFs (in the app sandbox, until you delete them)
- Purchase status (whether a lifetime unlock is present; single-export credits are consumed at export time)
This data is not synced, not uploaded to any cloud, and not shared with third parties. When you uninstall the app, all local data is automatically deleted.
7. Permissions
Lineon native requires one permission: read-only access to the photo library, requested only when you actively pick an image. The app prompts via the standard iOS / Android system dialogs.
No other permissions are requested — no camera, no microphone, no location, no contacts.
8. Web variant: cookies and local storage
The web variant sets no cookies that require consent. During an active payment flow a short-lived functional cookie may hold the payment status — this is strictly necessary within the meaning of § 25 (2) No. 2 TDDDG (formerly TTDSG) / Art. 5 (3) ePrivacy Directive and therefore exempt from the consent requirement.
Local storage is used only for UI state (e.g. last-used configuration) — without any personal content. PayPal’s own SDK may set its own cookies/iframes during the checkout flow; these are governed by PayPal’s privacy policy.
9. Children and Minors
Lineon collects no personal data and is therefore suitable for users of all ages. The app contains no content that would be inappropriate for children.
10. Your Rights as a Data Subject
To the extent we process personal data relating to you (e.g. the abbreviated IP address in our 14-day server logs, or — at PayPal — your payment data), the following GDPR rights apply:
- Right of access (Art. 15 GDPR) — you can ask us what data about you we are processing.
- Right to rectification (Art. 16 GDPR) — you can ask us to correct inaccurate data.
- Right to erasure (Art. 17 GDPR) — you can ask us to delete data, where one of the listed conditions applies.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR), where applicable.
- Right to object (Art. 21 GDPR) — in particular to processing on the legitimate-interest basis (server logs).
- Right to withdraw consent (Art. 7 (3) GDPR), where processing is based on consent.
To exercise these rights, write to: info@qorvano.com.
Because we deliberately store no names, emails, postal addresses, original images or PDFs, and because the HMAC fingerprint is non-reversible, we are usually unable to identify a specific user from a request alone. To trace a specific transaction please include the PayPal order ID.
Right to lodge a complaint with a supervisory authority (Art. 77 GDPR): you may complain to any data protection authority, in particular the one in your habitual residence or the one of the controller. The competent authority for the Provider is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany — https://www.ldi.nrw.de/.
11. Changes to This Privacy Policy
We reserve the right to update this policy as needed — particularly when introducing new features or pricing. The current version is always available at www.qorvano.com/en/lineon/privacy.
12. Contact
For privacy-related questions:
Dustin Dondrup Qorvano° Email: info@qorvano.com Website: www.qorvano.com