Roland Malits
Legal noticePrivacyTerms
← Portfolio

Privacy notice · Portfolio & Expiry

Privacy

Clear information about the tracking-free portfolio and Expiry’s local, iCloud, sharing and StoreKit data flows.

CurrentUpdated: 9 August 2026Germany · EU
LEGAL / 26

Contents

01Controller02Scope and principles03Portfolio: hosting and server logs04Portfolio: contact, cookies and links05Expiry: app content processed06Expiry: iCloud and CloudKit sync07Expiry: documents, camera, photos and OCR08Expiry: family and household sharing09Expiry: StoreKit and Expiry Pro10Expiry: system features and backups11Recipients and international processing12Retention and deletion13Your rights and choices14Security and updates
Legal enquiryhello@elvuno.app ↗
01

Controller

Roland Ferenc Malits, trading as Elvuno
Kreutzerstr. 72, 90439 Nuremberg, Germany
Email: hello@elvuno.app
Phone: +49 176 66356580

No data protection officer has been appointed. Privacy enquiries may be sent directly to the email address above.

02

Scope and principles

This notice covers the portfolio websites rolandmalits.com and rolandmalits.de, and the Expiry app including its widgets and Apple Watch extension.

Expiry uses no proprietary user account, developer-operated app backend, advertising, analytics, tracking or profiling SDK. App content is not sold or used for advertising. Where information is processed exclusively on the device, the provider does not receive it.

03

Portfolio: hosting and server logs

The portfolio websites run on a server provided by IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany. To deliver them, Nginx processes technical data including IP address, time and target of the request, transferred data volume, HTTP status, referrer, browser and device information.

This is necessary to provide a secure and reliable website and prevent misuse. The legal basis is Article 6(1)(f) GDPR. Server logs are normally rotated daily and retained for up to 14 days, or longer only where a specific security incident requires investigation.

04

Portfolio: contact, cookies and links

The contact form does not transmit entries to the web server. It opens a prepared message in the visitor’s email application, and information is processed only if that message is sent. Article 6(1)(b) GDPR applies to potential contracts and Article 6(1)(f) GDPR to general correspondence.

The website sets no first-party cookies, stores no theme or language preference, and uses no analytics or marketing service. Fonts and images are served locally. External services are contacted only after a visitor actively follows a link.

05

Expiry: app content processed

Expiry stores the expiry records created by the user locally on the device. These may include title, category, expiry date, an assigned person’s name, notes, tags, a link, reminder and renewal settings, creation and modification times, archive status, and household assignment.

An optional document image, file name, recognised text and suggested expiry date may also be stored. This content is processed only to provide the functions selected by the user. The legal basis is Article 6(1)(b) GDPR.

06

Expiry: iCloud and CloudKit sync

When an available iCloud account is configured on the device, Expiry mirrors its local Core Data database through Apple CloudKit to the private iCloud container iCloud.hu.expiry.app. This synchronises app content across devices using the same iCloud account and provides iCloud-backed storage.

The private CloudKit database belongs to the relevant iCloud user. The provider operates no proprietary Expiry sync server and does not receive private app content. Apple processes account, device, connection and service data required for iCloud under its own terms. If iCloud is unavailable, Expiry continues using the local copy and may synchronise changes when service becomes available again.

07

Expiry: documents, camera, photos and OCR

Documents are scanned with the camera or imported using the system photo picker only after a user action. The photo picker gives Expiry access to the selected image, not automatically to the entire photo library. Camera permission is optional and can be changed in iOS Settings.

Text and date recognition use Apple Vision entirely on the device. Document images and recognised text are not sent to an external AI or OCR service. If saved, the image, file name, recognised text and any suggested date become part of the relevant Expiry record and may be synchronised through iCloud or deliberately shared with a household.

An optional Face ID or device-passcode lock is performed by iOS. Expiry receives no biometric data, only the result of device authentication.

08

Expiry: family and household sharing

Household sharing uses Apple CloudKit Sharing (CKShare). A share is created only after an active invitation and is technically limited to expressly selected recipients with read and write access; no public share is created.

After accepting, invited participants can see and edit the shared household and every record assigned to it. This includes notes, person names, tags, links, reminder data, attached document images and recognised document text. Content not assigned to a shared household remains in the private database.

Apple handles invitations, participant identities and technical permission management. The owner can manage participants or stop sharing through Apple’s system interface, and participants can leave the share.

09

Expiry: StoreKit and Expiry Pro

Expiry Pro is offered as a one-time, non-consumable in-app purchase through Apple StoreKit. The app retrieves the product ID, localised product information and price from Apple, opens Apple’s purchase flow on request, and then checks the Apple-signed transaction and current entitlement. A restore request explicitly starts App Store synchronisation.

Apple processes Apple Account, payment, tax, fraud-prevention and transaction information under its own responsibility. Expiry receives no card or bank details. The app uses only the product identifier, verification and entitlement information, and any revocation status to unlock Pro; no provider-operated purchase database is maintained.

CloudKit household sharing is separate from Apple purchase Family Sharing. Expiry Pro is currently configured as an individual purchase and is not transferred automatically to other Apple Accounts through household sharing.

10

Expiry: system features and backups

Notifications are scheduled locally by iOS. Calendar access occurs only on express request, when Expiry writes the title, expiry date and optional note or link to the selected calendar. Spotlight may place title, category, expiry date, assigned person and tags in the device’s local search index. Widgets receive a reduced local summary through the app group; a paired Apple Watch receives a corresponding snapshot through WatchConnectivity.

When exporting, Expiry creates a JSON backup containing expiry records, households, settings, documents and recognised text. The user chooses the destination or sharing method and is responsible for copies created afterwards. On import, Expiry reads only the backup file selected by the user.

11

Recipients and international processing

IONOS SE may process technically necessary website data as hosting provider. For Expiry, Apple Inc. or the relevant Apple entity receives information necessary for iCloud, CloudKit, StoreKit, the App Store and system services. Invited household participants receive the content deliberately shared with them.

Apple may process information outside the European Union or European Economic Area and describes its safeguards and legal bases in the Apple Privacy Policy. Information is disclosed to other recipients only where permitted or required by law or necessary to establish, exercise or defend legal claims.

12

Retention and deletion

Expiry content remains locally and, when iCloud is active, in the private or shared CloudKit area until the user deletes content, ends a share, or manages the relevant app data through Apple and iCloud settings. Deletions synchronise through CloudKit; technically necessary caches may persist temporarily.

Expiry does not track exported backups, which must be deleted separately at the selected destination. Apple retains App Store purchase records under its legal and contractual obligations. Contact enquiries are deleted when complete unless a legal or contractual reason requires retention. Website logs are normally retained for no more than 14 days.

13

Your rights and choices

Within Expiry, users can delete records, attachments and households, manage sharing, export or import backups, and change optional permissions in iOS Settings. iCloud and App Store information can additionally be managed through Apple Account and iCloud settings.

Subject to the GDPR, individuals have rights including access, rectification, erasure, restriction, data portability and objection. You may also complain to the Bavarian State Office for Data Protection Supervision, Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

14

Security and updates

The websites use encrypted HTTPS connections. Expiry uses the security mechanisms of iOS, App Groups, CloudKit and StoreKit and can optionally be protected by Face ID or the device passcode. No technical method offers absolute security. This notice is updated when app functions, providers or legal requirements change.

Roland Malits

Roland Malits · Nürnberg

hello@elvuno.app ↗