Privacy policy
Last updated: 6 October 2026
This policy covers the website getsolista.app and the Solista app.
1. Controller
Oliver Drewing
Carrer Vicenza 21
03738 Xabia (Alicante)
Spain
Email: hello@drewing.dev
2. In short
- The website sets no cookies, stores nothing in your browser and loads nothing from third-party servers. Fonts and images come from my own server.
- There is no tracking, no analytics and no advertising.
- On the website, I only process personal data in server log files and when you join the waitlist.
- The app stores your lists on your device. Shared lists are optional and end-to-end encrypted.
3. Hosting
The website and all related server services (waitlist, sync for shared lists) run on my own virtual server at netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. The server is located in a data centre in Germany.
A data processing agreement under Art. 28 GDPR is in place with netcup.
4. Server log files
When you visit the website, the web server (nginx) writes the following to a log file:
- IP address
- date and time
- requested address (URL) and request method
- HTTP status code and amount of data transferred
- the page you came from (referrer), if your browser sends it
- browser and operating system (user agent)
- requested host name and technical details such as response time
Requests for images, fonts, stylesheets and scripts, and for favicon.ico and robots.txt are not logged. For waitlist requests (signup, confirmation, unsubscribe), the address is logged without parameters, i.e. without the identifiers from confirmation and unsubscribe links. Requests to the sync service for shared lists are not logged at all (see section 7).
Web server errors are written to a separate error log, which may also contain the IP address.
Log files are rotated daily; after 14 rotations the oldest one is deleted. Entries are therefore deleted after about 15 days at most.
The purpose is secure and stable operation, troubleshooting and defending against attacks. The legal basis is Art. 6(1)(f) of the General Data Protection Regulation (EU) 2016/679, GDPR for short (legitimate interest).
5. Waitlist (email updates)
What is stored: name, email address, IP address at the time of signup, chosen language, status (unconfirmed or confirmed), times of signup, last change and confirmation, and random identifiers for the confirmation and unsubscribe links. The data is kept in a database on my own server (see Hosting) that only the waitlist service can access.
Double opt-in: After you submit the form, you receive an email with a confirmation link. You are only added to the waitlist once you open it. You then receive a confirmation email with an unsubscribe link, and I receive a notification with your name, email address, IP address, language and the times of signup and confirmation.
What you get: occasional updates about progress, tests or a possible launch of Solista. I send these updates by hand from my mailbox, always as blind copy (BCC), so recipients cannot see each other.
Abuse protection: The form contains an invisible field and checks how long it took to fill in. To limit repeated requests from the same address, the service keeps the IP address in memory for one hour and then deletes it automatically. No captcha service is used for the waitlist.
Automatic emails: The email with the confirmation link, the confirmation email and the notification to me are sent by the server via the Resend service (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). Your email address, name and the email content are transmitted to Resend; for the notification to me, the IP address as well. Sending runs via servers in the EU (Ireland), but Resend may also process data in the USA. According to Resend's data processing agreement, the basis for this is the EU-US Data Privacy Framework, in which Resend participates, and the European Commission's standard contractual clauses.
My mailbox: My email mailbox (hello@drewing.dev) is hosted by Proton AG, Switzerland. Notifications about new signups and your messages to me arrive there, and I send the updates from there. The European Commission has found that Switzerland provides an adequate level of data protection (adequacy decision).
Legal basis: your consent, Art. 6(1)(a) GDPR. I store the IP address and timestamps to be able to demonstrate consent (Art. 7(1) GDPR); the legal basis for this is Art. 6(1)(f) GDPR.
Retention and withdrawal:
- Confirmed signups are kept until you unsubscribe.
- Unconfirmed signups are deleted automatically after 30 days.
- You can unsubscribe via the link in the confirmation email, by replying to an update or by email to hello@drewing.dev. Your entry is then deleted from the database completely, and I delete the related notification from my mailbox.
6. Cookies, browser storage and third-party content
The website sets no cookies and uses neither localStorage nor sessionStorage. It loads no content from third-party servers; fonts and images are hosted on my own server. Links to other websites (e.g. drewing.dev or Google Play) are only loaded when you click them.
7. The Solista app
Locally on your device: Your lists, stores and routes are stored on your device. The Android app excludes its data from the automatic Google backup.
Sharing a list as a copy (link or QR code): No server is needed. The content is in the part of the link after "#". Browsers never send this part to a server; the page getsolista.app/l decodes nothing and sends nothing.
Shared lists are optional and off by default. As long as they are off, the app does not send a single byte to the server. There are no accounts: no registration, no email, no names, no phone numbers.
When you use shared lists, content is encrypted on the device and only decrypted again on a device (end-to-end encryption). The relay server only stores blocks it cannot read.
The server stores:
- an identifier for the list, derived from the list key, that looks random
- a SHA-256 check value of the access token; the token itself is not stored
- the creation time and the time of last activity, used for automatic deletion after 180 days of inactivity
- encrypted blocks, one per change, together with their size, order and time
The server does not know: contents, list and item names, quantities, stores, names, email addresses, devices, or the number of members.
IP addresses are not logged: For sync, the web server keeps neither an access log nor an error log; the IP address is only used briefly in memory for rate limiting. The relay writes no request logs and also removes request data from error logs.
Visible metadata: The server can see how often and when a list is changed and how large the blocks are. This allows rough conclusions about activity, not about content.
Member profile: To assign items, each device has a profile without an account: a random ID, a freely chosen name, initials and a colour. It is only transmitted encrypted within shared lists. Copies via link or QR code contain neither names nor assignments.
Deletion: "Delete for everyone" removes the list from the server. If you only turn shared lists off, nothing is deleted on the server; the encrypted blocks expire after 180 days without access.
No analytics: The app contains no analytics, tracking or crash-reporting services.
Legal basis: For shared lists, Art. 6(1)(b) GDPR – the processing is necessary to provide the feature you switched on yourself.
Download: If you download the app from Google Play, Google processes data under its own responsibility; Google's privacy policy applies to that.
8. Recipients
- netcup GmbH (hosting, see section 3)
- Resend (automatic waitlist emails, see section 5)
- Proton AG (my email mailbox, see section 5)
I do not pass on data beyond this unless I am legally required to.
9. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21).
You can withdraw your consent to the waitlist at any time with effect for the future (Art. 7(3) GDPR), via the unsubscribe link or by email to hello@drewing.dev.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state where you live or work. As I am based in Spain, the competent authority for me is the Agencia Española de Protección de Datos (AEPD): www.aepd.es.
10. Encryption
The website and all server services are delivered encrypted via HTTPS (TLS); requests over HTTP are redirected to HTTPS.
11. Changes
I will update this policy when the website, the app or the legal situation changes.