Privacy policy

Last updated: September 25, 2026

Data Controller

Christopher Brock
Vennhauser Allee 196 C
40627 Düsseldorf
Deutschland
Email: [email protected]

Data Processing

Zero Duplicates processes all files locally on your device. No files, file names or scan results are transmitted to external servers. Data leaves your device only in the cases described below: usage analytics and crash reporting, both off unless you consent, and feedback reports you choose to send.

Website Analytics

This website uses PostHog for cookieless audience measurement, operated by PostHog Inc. Website data is stored on PostHog Cloud EU, with servers located within the European Union. PostHog Inc. is a U.S.-incorporated company; any access to data from outside the EU is governed by the EU Standard Contractual Clauses (Art. 46 GDPR) and, where applicable, the EU–U.S. Data Privacy Framework adequacy decision (Art. 45 GDPR). Privacy policy: https://posthog.com/privacy

It records page views and clicks on links and buttons together with referrer, campaign parameters, browser, device type and language; PostHog uses your IP address to derive an approximate country. No cookies or local storage are used. Processing is based on my legitimate interest in privacy-friendly audience measurement (GDPR Art. 6(1)(f)). You can object at any time by enabling Do Not Track, which the script honors, or by contacting me. Data is deleted in line with the retention period of the PostHog plan in use.

Usage Analytics

The app includes optional usage analytics to help me understand how the app is used and improve it over time. This feature is disabled by default and requires your explicit consent during first launch or via Settings. Processing is based on your explicit consent under GDPR Art. 6(1)(a).

Events describe how the app is used, such as screens and features used, aggregate scan statistics, purchase flow steps, subscription tier, language, device class, app version and error types. They contain no files, file paths or contact details and are grouped only by an identifier that is created fresh at each app launch and never stored. Events are sent to PostHog (PostHog Inc., stored on PostHog Cloud EU; any access from outside the EU is covered by the EU Standard Contractual Clauses and, where applicable, the EU–U.S. Data Privacy Framework) and to a self-hosted Aptabase instance on a server in Germany operated by me. You can withdraw your consent at any time in Settings.

Crash Reporting

The app includes optional crash reporting to improve stability. This feature is disabled by default and requires your explicit consent during first launch or via Settings. Processing is based on your explicit consent under GDPR Art. 6(1)(a).

Crash reports contain technical information such as error type, stack trace, device model, OS version, app version and available memory. They are sent to a server hosted in Germany and used only to find and fix crashes. You can withdraw your consent at any time in Settings.

Feedback from the App

If you send a report through the feedback form in the app, it contains your message, a screenshot if you leave that option on, your email address if you enter one, and technical information such as app and system version, device model, language, anonymous scan counts and a random install identifier. A screenshot shows whatever was on screen, which can include file names. Nothing is sent until you submit the form.

I use reports only to answer you, fix the problems you describe and prevent abuse of the form, based on my legitimate interest (GDPR Art. 6(1)(f)). Reports are received through Cloudflare and stored in Linear, the issue tracker I use; Cloudflare, Inc. and Linear Orbit, Inc. process them on my behalf. Both are U.S. companies; transfers are covered by the EU Standard Contractual Clauses (Art. 46 GDPR) and, where applicable, the EU–U.S. Data Privacy Framework (Art. 45 GDPR).

Reports are kept until the matter is resolved. To have a report deleted earlier, write to [email protected].

In-App Purchases

Payment processing and subscription management is handled exclusively by Apple. I do not have access to your payment details. See Terms and Conditions for details.

Your Rights

Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability and objection, the right to withdraw consent at any time with effect for the future, and the right to lodge a complaint with a data protection supervisory authority. Analytics events and crash reports carry no direct identifiers, so I cannot attribute them to a specific person or answer requests about them; you can stop them at any time in Settings. For feedback reports, contact me as described under "Feedback from the App".

Changes to This Policy

This privacy policy may be updated to reflect changes in the app or legal requirements.

Contact

For questions: [email protected]