Printatops · com.puredevn.printatops

Privacy Policy & Legal Notice

Published: 7 September 2026

DE · EN · ES · FR · HI · ID · IT · NL · PL · PT · TR

In short: Printatops needs no account and no sign-in. Favourites and settings are stored locally; providing the catalogue, search, favourites and printing also involves sending information to our Supabase service. Optional feedback and abuse-protection values are stored on the server. Google processes device and network data for consent checks and advertising. Adults who consent may receive personalised ads; children and people whose age is unknown do not.

1. Who is responsible

Responsible for data processing and provider of the app:

Michael Spiess
Riedmattstrasse 1
6030 Ebikon
Switzerland

Email: puredevn.io@gmail.com

Printatops is operated as a sole proprietorship under the name “PureDevn Studio”. For any privacy question and to exercise your rights, an email to the address above is enough.

2. Local storage and necessary transmission

The app stores the following information locally. Local storage does not mean that all processing stays on the device: favourite identifiers are sent to Supabase to retrieve their content, language is sent for the catalogue, search, feedback and printing, and the paper format is sent when printing.

Preview images are also cached in memory and on disk. Deleting local app data does not delete feedback messages already sent or data held by the services named in this policy.

3. What is sent to us

Feedback

If you write to us through the feedback form, we process:

What you type into the text field is up to you. We explicitly ask you not to enter names, addresses or email addresses — neither your own nor anyone else’s. A simple arithmetic question sits in front of the form so that children do not send something unintentionally.

Legal basis: your consent, given by submitting the form (Art. 6(1)(a) GDPR). You may withdraw it at any time by email; we will then delete your message as far as we can identify it.

Abuse protection

To protect the form against abuse, we derive a cryptographic hash from the IP address using a secret additional value and store it with a time window and request counter. These application records store the hash rather than the raw IP address. Hosting services may separately process IP addresses and technical request information in their logs. The hash is pseudonymous, not anonymous.

Legal basis: our legitimate interest in a functioning service that resists abuse (Art. 6(1)(f) GDPR).

Colouring pages and printing

The app also sends requests to Supabase when loading the catalogue, searching and filtering, retrieving saved favourites and downloading images. Depending on the function, these include search text, filters, language, page or favourite identifiers and technical network data. These requests provide the requested content.

When you print a colouring page, the app requests the corresponding print file from our server. What is transmitted is the identifier of the requested page, the paper format and the language setting. The server checks whether the page is published and returns a download link that expires after five minutes.

Abuse protection for printing stores a hash derived from the IP address, a time window and a request counter. This is not a dedicated print history containing page identifiers. However, the requested page identifier is sent to the server; technical request and hosting logs and local preview caches are not excluded by that distinction.

Legal basis: providing the function you requested (Art. 6(1)(b) GDPR) and our legitimate interest in a service that resists abuse (Art. 6(1)(f) GDPR).

No usage analytics

The former first-party usage-event feature has been removed. This does not mean that no usage data is processed: there are local preview caches and a print counter for ad frequency, necessary content requests and the Google processing described below.

4. Advertising

Printatops shows ads from Google AdMob, usually after a successful print. You can buy the ad-free version once.

Children, people whose age is unknown and adults without positive consent to personalisation receive non-personalised ads — or no ads if the consent check does not allow them. Adults who consent may receive personalised ads. The app allows this only for an adult age status and a positive Google-provided consent check, including the required purpose and Google-vendor consents. Missing or unreadable consent data does not allow personalisation. For children and unknown age, the app sets the Google SDK child-directed and under-age-of-consent flags; for adults it does not. The maximum ad content rating remains G (suitable for all ages) for everyone.

Non-personalised advertising is not data-free. Google processes device and network data for consent checks, advertising, accounting, diagnostics and security; with the relevant consent, processing may also serve ad personalisation. According to Google, the potentially relevant data types include:

Google is independently responsible for this processing. Details are in Google’s privacy policy.

Consent in the EEA, Switzerland and the United Kingdom

Before loading ads, the app uses Google UMP to check whether ad requests are allowed and shows a consent form depending on age status and the UMP result. The consent choice is stored locally and used by the Google SDKs. The consent check itself sends technical data to Google; content requests to Supabase may also occur after the age screen and before advertising consent. Rejection is not a guarantee that no device or other identifiers are processed. Without permission from the consent check, the app loads no ads. Adults can reopen advertising privacy options in settings when Google UMP requires that entry point; this adult entry point is not offered for children or unknown age.

Legal basis: your consent (Art. 6(1)(a) GDPR) where your device is accessed; otherwise our legitimate interest in funding the free app (Art. 6(1)(f) GDPR).

5. Purchases

The one-time purchase of the ad-free version is handled through Google Play. The app processes product, purchase and transaction information and stores purchase status locally; it does not collect payment details through its own payment form. An arithmetic question before purchase is an additional hurdle, not verified parental consent. Google Play’s terms and privacy policy apply to payment processing.

6. Recipients and international transfers

RecipientPurposeLocation of processing
Supabase Hosting, database, file storage, server functions eu-west-1 (Ireland, EU)
Google (AdMob, Google Play) Consent checks, advertising including possible personalisation for consenting adults, payment processing United States and other countries

Where data is transferred to countries outside Switzerland and the European Economic Area, we rely on the European Commission’s standard contractual clauses and on adequacy decisions where they exist for the country concerned.

7. How long we keep data

DataRetention
Information in local app storageuntil changed or deleted there; this does not guarantee deletion of separate backups or exported files
Feedback messages24 months (intended deletion period)
Abuse-protection hashes30 days (intended deletion period)
Server logs at our hosting providerdepends on the hosting service and configuration; no blanket one-day deletion period is confirmed here

The intended periods of 24 months for feedback and 30 days for abuse-protection values concern application database records, not separate provider logs.

8. Your rights

You have the right to access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing. Where you have given consent, you may withdraw it at any time with effect for the future.

Because Printatops does not create a user account, we cannot automatically match a request to an account. This does not mean that technical identifiers or information you submit cannot allow a match. For feedback, the approximate time and content can help us find the message.

For any request, an email to puredevn.io@gmail.com is enough.

Supervisory authorities

9. Children

Printatops is used by children and adults. On first launch, the app asks for a birth year; you may also choose not to provide one. The device derives and stores a child, adult or unknown status, not the entered year. This is self-declaration, not identity or age verification. Year-based classification is conservative: ages under 18 derived from the stated birth year are treated as child; the year in which someone turns 18 is treated as unknown without a month and day. The status controls advertising and consent treatment, not a different content catalogue.

For users in the United States, the Children’s Online Privacy Protection Act (COPPA) applies. The app does not allow personalised ads for children or people whose age is unknown. This does not exclude technical data processing by Supabase and Google for content, consent checks, non-personalised ads and security. The feedback form is protected by an arithmetic question; this is not verified parental consent.

If you are a parent or guardian and believe that information about your child has nevertheless reached us, write to us — we will delete it.

10. Changes to this policy

We update this policy when the app or the legal situation changes. The version published on this page is the one that applies. The date of the current version is shown at the top.