Privacy Policy

InkMe – eInk display app · Last updated: August 2026

This is the English version of our privacy policy. The German version at ink-me.de/datenschutz is authoritative; in case of discrepancies, the German text prevails.

1. Controller

The controller responsible for data processing within the meaning of the EU General Data Protection Regulation (GDPR) is the provider of InkMe. For any privacy matter you can reach us at:

Email: info@ink-me.de

The controller's name and full postal address are given in Section 19 at the end of this policy and in the imprint.

2. Overview of processing

InkMe lets you create content (images and widgets such as calendar, weather, habits, QR codes and more) and send it to your eInk displays. To provide these features we process personal data. Below we explain which data this is, for what purpose and on which legal basis we process it.

3. Account and sign-in

An account is required to use InkMe. When you register or sign in, we process:

Purpose: providing and securing your account, associating your content and devices.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

4. Content and device data

When you use InkMe, we process and store the content you create on our server:

If you have configured an address that content should come from – such as a calendar, a news feed or a shared photo album – our server retrieves that address regularly and prepares the content for your display. Control commands to your display run over an MQTT broker with device-specific credentials.

Purpose: rendering and delivering content to your displays.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Wi-Fi credentials: When setting up a display, the Wi-Fi name and password are transmitted directly via Bluetooth from your smartphone to the display – encrypted using a key negotiated beforehand between phone and display. These credentials are not sent to or stored on our server.

Sharing displays with others

You can share a display with other InkMe users – either by entering their e-mail address or via an invitation code that the other person redeems in their app. To do so we process the e-mail address you enter in order to find the matching account, and we store the share as a link between device and account. Invitation codes are single-use and expire after seven days at the latest.

While a share exists, everyone involved sees the same display, its name, its state and the widgets set up on it, and can send content to it. As the owner you see the name and e-mail address of the accounts you have shared with. You can revoke a share at any time; anyone who was given access can also give it up themselves.

Purpose: shared use of a display within a household or team.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

Widget requests and contacting us

If you send us a widget request from within the app, we store your text together with your e-mail address so that we can review the suggestion and reach you with any questions. The same applies to messages you send us by e-mail. Please do not include data there that does not belong in the suggestion.

Purpose: handling your request, further development of the service.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving the service), or (b) for enquiries relating to the contract.

5. Location data (weather widget and setup)

For the weather widget, the app can access your location. The app deliberately requests only coarse (city-level) location – that is enough for the weather display, so your precise whereabouts are never collected. Access happens only after you explicitly grant it in iOS and can be revoked there at any time. Alternatively, you can search for and select a location manually, in which case no location access is needed.

With these coordinates the following happens:

The app uses the same permission in one further place: when setting up a display it suggests the name of your current Wi-Fi network so you do not have to type it. iOS only reveals that network name to apps that hold location permission – the location itself is neither evaluated nor stored nor transmitted for this. Without the permission you can simply type the Wi-Fi name yourself.

Legal basis: Art. 6(1)(a) GDPR (consent).

6. Connected calendar accounts (Google and Apple)

For the calendar widget you can connect your Google account or your Apple account directly, instead of entering an ICS address. This is optional and only happens if you establish the connection yourself in the app.

What we store: the Google token or the Apple app-specific password – both encrypted in our database only – along with the names and identifiers of your calendars, so you can choose which ones appear on the display. These credentials never leave our server and are not returned to the app either.

What we do not store: your events themselves. They are fetched fresh while the display image is being generated, placed into that image and then discarded. Only the finished image for your display is retained. We use your calendar data solely to render your display – not for advertising, not for training AI models, and we do not pass it on to third parties.

Disconnecting: you can end the connection at any time in the app under calendar widget → Disconnect. We delete the credentials and, for Google, also revoke the access that was granted. Independently of that, you can revoke InkMe at any time at myaccount.google.com/permissions.

InkMe's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Legal basis: Art. 6(1)(a) GDPR (consent).

7. AI features

InkMe can generate images with AI and edit existing images with AI. Both are optional and run only when you actively invoke the feature.

Depending on the feature and availability we use OpenAI or Google; both process the data in the USA. The transfer is based on the EU Standard Contractual Clauses. The request is made by our server – the AI providers do not learn your IP address. We store the result on our server like your other content.

Please note: Whatever you put into the AI features leaves our server. Do not upload images or text that are especially sensitive – such as ID documents, health or financial records.

Legal basis: Art. 6(1)(b) GDPR (performance of the feature you requested).

8. Push notifications

If you allow notifications, iOS generates a device token that the app transmits to our server. We use it solely to inform you about the state of your displays – currently, when a display's battery is running low. Delivery runs via the Apple Push Notification service (APNs); the message contains the name of the affected display.

Legal basis: Art. 6(1)(a) GDPR (consent via the iOS prompt). You can turn off notifications at any time in iOS Settings.

9. InkMe Plus (in-app purchase)

The InkMe Plus subscription is handled through the App Store. Payment data is processed exclusively by Apple – we neither receive nor store it.

To unlock the subscription, our server verifies the Apple-signed receipt with Apple and stores: product identifier, status, expiry date and the transaction identifier assigned by Apple. So that a purchase remains permanently associated with exactly one account and cannot be reused, the app additionally transmits your InkMe user identifier to Apple at the time of purchase.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

10. Bluetooth and photo access

Legal basis: Art. 6(1)(a) and (b) GDPR.

11. Server log data and operational log

When accessing our server, data transmitted by your device (including IP address, time of the request, the feature invoked) is automatically processed for technical reasons. This data serves the provision, stability and security of the service and is retained only for a limited period.

In addition, we keep an operational log: for errors, rejected requests (e.g. when a limit is exceeded) and security-relevant events (e.g. claiming a display or actions in the administration area) we store a structured entry with the time, the affected feature and your user identifier. These entries are automatically deleted after 30 days at the latest and are accessible only to the administration.

Purpose: attributing and fixing faults, detecting abuse.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure and functioning service).

12. Services used (processors & third parties)

To provide our service we use carefully selected providers. Where required, data processing agreements (Art. 28 GDPR) are in place with them. For providers outside the EU/EEA, transfers are based on the EU Standard Contractual Clauses.

ServicePurposeData processed
Supabase (authentication)Account management, login, password resetEmail, name, password hash, Apple user ID
Resend (email delivery)Sending confirmation and password-reset emailsEmail address
Server hosting (Hostinger)Operating the server infrastructure; your content and device data are stored hereAll data processed server-side
Apple – Sign in with AppleOptional login with Apple IDPseudonymous Apple user ID, optionally name/email
Apple – Push (APNs)Delivery of notifications about your displaysDevice token, message text
Apple – App StoreProcessing and verifying the InkMe Plus subscriptionTransaction data, InkMe user identifier
Apple – iCloud calendars (CalDAV)Reading your iCloud calendars if an account is connected (Section 6) – only when usedApple ID, app-specific password, your calendar names and events
Apple – geocodingPlace names for your coordinates, for display in the appApproximate coordinates
OpenAI (USA)Generating and editing AI images – only when usedYour prompt; when editing, additionally the selected image
Google (USA)Generating and editing AI images; import from shared Google Photos albums; reading your Google calendars if an account is connected (Section 6) – only when usedYour prompt; when editing, additionally the selected image; the album link you provide; with a connected calendar account, your calendar names and events
Yahoo Finance (USA), Frankfurter (ECB reference rates), CoinGeckoPrices and price history for the markets widget – only when usedThe symbol you select (e.g. "GC=F", "AAPL"); the request is made by our server, so your IP address and identity are not transmitted
Open-MeteoWeather data for the app and the weather widgetApproximate coordinates
Sources you provideRetrieving the content you want on your display (calendar, news feed, shared album)The address you configure and the content stored there

Content without any personal reference – such as artworks from the Metropolitan Museum, wallpapers or the default news feed – is retrieved by our server itself. Your device does not connect to those providers, so your IP address is not disclosed to them.

13. Retention

We store your personal data as long as your account exists or as long as it is necessary to fulfil the purposes stated above. If you delete your account, the associated data is deleted (see Section 15). Operational log entries are deleted after 30 days at the latest, regardless. Statutory retention obligations remain unaffected.

To guard against data loss we create regular backups of the database. Deleted data may still be contained in them for a short period until the backup in question is overwritten in the normal rotation; backups are restored only in the event of a fault.

14. Your rights

Under the GDPR you have the following rights:

To exercise these, a message to info@ink-me.de is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI Baden-Württemberg).

15. Account and data deletion

You can delete your account at any time directly in the app under Profile → Delete account. This permanently deletes your account and the associated content and device data. Alternatively, you can request deletion by email to info@ink-me.de.

16. Data security

Transmission between the app and the server, and between the server and the services used, is encrypted via HTTPS/TLS. Passwords are stored only as a hash, and each display receives its own credentials for connecting to our server. We take appropriate technical and organisational measures to protect your data.

One exception concerns the last step to the display: the displays' firmware does not support TLS encryption, so the display downloads the finished, prepared image file from our server without encryption. Only that image file is transmitted – no account or credential data.

17. Children

InkMe is not directed at children under 16. We do not knowingly collect data from children without the consent of their parents or guardians.

18. Changes to this Privacy Policy

We will adapt this Privacy Policy if our data processing changes or legal requirements make it necessary. The current version is always available at this address.

19. Provider and contact

The controller within the meaning of Art. 4(7) GDPR and the provider of InkMe is:

Rafael Banzhaf
John-F.-Kennedy-Allee 55/5
71686 Remseck am Neckar, Germany
Email: info@ink-me.de

Further mandatory details can be found in the imprint.