Privacy Policy

Your data stays between you and your providers.

Dashlytics has no account system and no server of its own. This page explains what the app and this website do with data, who else is involved, and what you can do about it.

Effective September 19, 2026

The short version

Who is responsible

The controller for the processing described here is:

Jonas Gehring
Am Blumenstrich 32
69151 Neckargemünd, Germany
Email: apps@jonasgehring.com

We are not required to appoint a data protection officer. Questions about privacy go to the address above.

What the app handles, and where it stays

Dashlytics is a client for other services. You connect an account at a provider (for example Vercel, Namecheap, or Google Search Console), and the app shows you that account's data. We do not receive, store, or see any of it.

API tokens and keysStored in the Keychain on your device, one item per connected account. With iCloud Sync on (the default), these items are synchronized through iCloud Keychain, which is end-to-end encrypted: Apple cannot read them. With iCloud Sync off, they never leave the device. Tokens are never written to logs, caches, or files.
Google sign-insThe OAuth access and refresh tokens, and the email address of the Google account you signed in with, are stored in the Keychain in the same way.
Provider dataProjects, deployments, domains, analytics, and everything else the app displays is fetched directly from the provider when you open it. It is held in memory while the app runs. Summaries for site services are cached in a protected file inside the app's container on your device, excluded from backups, so they appear instantly next time.
Views and hidden itemsThe views you create and the items you hide are stored in the Keychain and follow the iCloud Sync switch, like your accounts.
Settings and recent itemsTab order, appearance, the app lock setting, and the last eight items you opened are stored on the device only.
Namecheap client IPThe public IP address you enter or detect for Namecheap is stored on the device only and never synchronized.
App lockFace ID, Touch ID, Optic ID, and your passcode are handled entirely by Apple's operating system. The app only learns whether unlocking succeeded.

Because none of this reaches us, we cannot view, export, or recover it for you. The legal basis for processing on your device is the performance of our contract with you, Art. 6(1)(b) GDPR.

Services the app contacts

The app only connects to the following. Every connection uses HTTPS without cookies or a shared cache.

The providers you connect

When you connect an account, the app sends requests with your token directly to that provider's API, for example api.vercel.com or api.namecheap.com, or to a self-hosted address you entered yourself. Like any server, the provider sees your IP address and the requests. The provider's own privacy policy applies to that account. Dashlytics is not affiliated with any provider.

Some actions change data at a provider, such as editing a DNS record or purging a cache. The app always asks for confirmation before it sends one.

Your project's own website

To show a project's icon, the app may load the favicon from that project's own HTTPS address. No third-party favicon service is used.

ipify

Namecheap and Name.com only accept requests from allowlisted IP addresses. When you open the connection form for one of these two registrars, the app asks api.ipify.org for your public IPv4 address, so you can copy it into the registrar's allowlist. ipify sees your IP address and nothing else: no token, no account data. This happens only on that form, never in the background.

Apple

The app checks itunes.apple.com for a newer version, sending only the app's bundle identifier. Apple processes App Store purchases, iCloud Keychain, and, if you agreed to share them with developers, crash reports and usage statistics under Apple's privacy policy.

Google user data

Google Search Console, Google Analytics, and Firebase Hosting connect through Google's OAuth sign-in. The app requests only these permissions:

Data from these Google APIs is fetched directly by the app on your device and shown only to you inside the app. It is never sent to us or to anyone else, never used for advertising, never sold, and never used to train AI models. No person at Dashlytics reads it.

Dashlytics' use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke access at any time in your Google Account permissions, or disconnect the account in the app.

Purchases

Dashlytics Pro subscriptions, the lifetime purchase, and tips are sold through the App Store. Apple processes the payment; we never see your name, Apple Account, or payment details.

To know whether Pro is active on your devices, the app uses RevenueCat (RevenueCat, Inc., USA). RevenueCat receives an anonymous app user ID generated on your device, the App Store receipt with your purchase history, the app version, and basic device information such as the operating system and storefront country. RevenueCat never receives your provider credentials or any provider data. We use this data to unlock Pro and to see aggregate purchase figures. The legal basis is Art. 6(1)(b) GDPR. RevenueCat processes this data on our behalf and is bound by a data processing agreement; transfers to the USA rely on the EU Standard Contractual Clauses. See RevenueCat's privacy policy.

In the App Store's privacy label this appears as "Purchase History", not linked to your identity and not used for tracking.

This website

This website is hosted by Vercel (Vercel Inc., USA). When you visit it, Vercel's servers process your IP address, the page requested, the time, your browser's user agent, and the referring page, in order to deliver the site and protect it against abuse. These logs are kept for a short period and are not used by us for analytics. The legal basis is our legitimate interest in running a secure website, Art. 6(1)(f) GDPR. Vercel is bound by a data processing agreement, and transfers to the USA rely on the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. See Vercel's privacy policy.

The website sets no cookies, loads no fonts, scripts, or images from third parties, and uses no analytics. If you use the light/dark toggle, your choice is saved in your browser's local storage and never leaves your device.

Email

If you write to apps@jonasgehring.com, for support or to be told about the launch, we use your address and message only to answer you, or to send that one launch email. We delete launch requests after the launch and support conversations once they are resolved, unless the law requires us to keep them. The legal basis is Art. 6(1)(b) or, for launch requests, your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time by replying.

Children

Dashlytics is a tool for people who run websites and apps. It is not directed at children, and we do not knowingly collect data from them.

Your rights

Under the GDPR you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw consent at any time. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.

Since the app keeps your data on your devices, the data we hold about you is limited to emails you sent us. If you want RevenueCat's purchase record deleted, write to us and we will ask RevenueCat to delete it.

Deleting your data

Changes to this policy

If the app or this website starts processing data differently, we update this page and the date at the top before the change ships. Material changes are also mentioned in the app's release notes.