Privacy Policy
Last updated: 25 July 2026
This policy covers the iOS and watchOS app SourTime and this website, sourtime.axeptdesign.com.
The short version: SourTime has no user account and no server of our own. Everything you create in the app — recipes, bakes, starters, photos, settings — stays on your device. We collect no usage statistics, run no tracking and show no ads.
1. Who is responsible
The controller under the EU General Data Protection Regulation (GDPR) is:
axeptdesign, sole proprietor Rupert Maier
Boddinstr. 10, 12053 Berlin, Germany
Phone: +49 30 690 400 70
Email: sourtime@axeptdesign.de
We have not appointed a data protection officer; we are not legally required to.
2. Data the app creates
SourTime stores the following on your iPhone or Apple Watch only. None of it is transmitted to us or to any third party:
- Recipe details: loaf weight, flour mixes, hydration and the quantities calculated from them
- Bakes and phase durations, running and completed timers
- Starter data: feeding rhythm, ripening times, names you have given
- Your baking history, including notes and any photos you add
- App settings such as units, quiet hours and notification options
Technically this data lives in the app's own storage and in a shared app group, which is how widgets, Live Activities and the watch complication read the current timer state. Those areas are part of your device as well.
Legal basis: because this data never leaves your device and is not accessible to us, we do not process personal data in this respect.
Photos
When you add a photo to a bake, you pick it through Apple's system picker or take it with the camera. The app receives only the image you selected and stores it locally. It does not access the rest of your photo library.
Notifications
So that SourTime can remind you when a phase ends, the app schedules local notifications on your device. Nothing is pushed from a server, and no push token is sent to us. You can withdraw the permission at any time in iOS Settings.
Apple Watch
Data moves between iPhone and Apple Watch through Apple's WatchConnectivity framework — directly between your two devices. Only the timer state travels (phase, time remaining, status), so that the watch and its complication show the same thing as the phone.
3. Buying SourTime Pro
SourTime Pro is a one-time in-app purchase. Apple handles the entire transaction through the App Store. We never see payment details such as card numbers or the address on your Apple Account.
The app only asks Apple whether a valid purchase exists for your Apple Account and unlocks the Pro features accordingly. That check runs through Apple's StoreKit interface between your device and Apple; no connection to us is involved.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Apple is the controller for its own processing; see Apple's Privacy Policy.
What we receive from Apple in App Store Connect is aggregated and anonymous sales and usage reporting. It does not let us identify individuals.
4. No analytics, no tracking, no ads
SourTime includes no third-party analytics, advertising or crash-reporting SDKs. No advertising identifier (IDFA) is read, there is no cross-device profiling and no data is shared with third parties for advertising.
If you have agreed in iOS Settings to share diagnostics with developers, Apple may provide us with anonymised crash reports. These contain technical details about the device and the crash, but none of your content.
5. Backups and iCloud
If iCloud Backup is enabled on your device, the system backup may include SourTime's locally stored data. That backup sits in your Apple Account and is governed by Apple's privacy terms — we have no access to it.
6. Deleting your data
Because everything lives on your device, deletion is entirely in your hands:
- Delete individual entries in the app, for example in your baking history.
- Removing SourTime from your device deletes all of the app's locally stored data with it.
- Any existing iCloud backup is managed in iOS Settings.
The one-time SourTime Pro purchase stays tied to your Apple Account and can be brought back after a reinstall via “Restore Purchases”.
7. This website
This site is purely informational. It sets no cookies, embeds no web fonts, maps, videos or third-party analytics, and loads nothing from external servers. That is also why there is no cookie banner — there is simply nothing to consent to.
When you open the site, our hosting provider processes technically necessary server log data (IP address, time of request, file requested, status code, volume of data transferred, referrer and browser identifier). This is required to deliver the site and to operate it securely, and it is not combined with other data.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a technically sound and secure website).
The site is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA (Cloudflare Pages). Cloudflare serves the site from servers in Europe but is a US company. A data processing agreement under Art. 28 GDPR is in place; transfers to the USA rely on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
8. Contacting us by email
If you write to us, we process your message and your email address in order to answer you. We keep the correspondence for as long as that requires and delete it afterwards, unless statutory retention periods apply.
Legal basis: Art. 6(1)(b) or 6(1)(f) GDPR.
9. Children
SourTime is not directed at children and does not knowingly collect data from them. Since the app works without an account and transmits nothing, no data about younger users reaches us either.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
In practice we usually hold no data about you at all — unless you have written to us. For any request, just get in touch at sourtime@axeptdesign.de.
You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), either where you live or where we are established.
11. Changes to this policy
We update this policy when the app or the legal situation changes. The version published here is the one that applies; the date at the top shows how current it is.