Data & Privacy
This page explains how the GatusPocket website, support channels, and iOS app handle data.
Controller
Manuel Faderny e.U.
Anastasius-Gruen-Gasse 12
1180 Wien
Austria
Email: support@manueldigital.at
Website Data
When you visit this website, technical access data may be processed to operate and secure the service, such as IP address, requested path, timestamp, referrer, and user-agent information.
The website uses functional browser storage for site controls, including the announcement-close cookie, the manuel_consent cookie, theme preferences, and the language preference key gatuspocket.preferredLanguage where available.
The consent banner can send same-origin POST requests under /__manuel-consent/v1/... for aggregate consent-flow measurement. These requests contain no request body, no query string, no cookies, and no referrer.
Matomo analytics is optional. No Matomo tracking request is sent before you accept analytics in the privacy settings. If you reject analytics or revoke consent later, Matomo remains blocked and Matomo consent or tracking cookies are cleared where possible.
No advertising tracking is enabled.
App Data
GatusPocket stores multiple Gatus connection profiles, with one connection active at a time. Its network requests go only to the HTTPS Gatus server configured by you. The app can use Basic auth or a bearer token to request the Gatus status API.
Credentials remain local-only in the iOS Keychain and are stored separately for each connection profile. Saved connection definitions, cached statuses, pins, runbooks, and the newest 20 observed status transitions per connection are also stored locally. Credentials and operational data are isolated by the profile’s UUID.
The iOS app has no provider backend, analytics, tracking, advertising, or telemetry. GatusPocket does not require a GatusPocket account, and the app provider does not receive app data.
The Home Screen widget uses the newest shared snapshot written by the app. Small widgets are count-only. By default, medium widgets may display the active connection name and up to three endpoint names. The privacy option in Settings switches widgets to count-only and removes name-bearing summaries and endpoint keys from newly written shared snapshots.
Shared status summaries exclude credentials, URLs, hostnames, endpoint and profile names, runbooks, Gatus keys, and raw failure-condition text. When widget names are enabled, the separate name-bearing part of a widget snapshot contains only the active connection display name and up to three endpoint display names and keys needed for that widget.
Sign Out clears the active profile’s credentials, cache, pins, runbooks, history, and owned widget snapshot while retaining its saved connection definition. Delete Connection removes the selected connection definition and all credentials and local data belonging to its profile UUID.
Clean Start removes all profiles, profile and legacy credentials, profile-scoped data, the global widget preference, widget snapshots, UserDefaults, legacy artifacts, and app caches.
Upgrading from GatusPocket 1.0 preserves the configured server, credentials, cache, pins, and runbooks. Status-change history starts empty because version 1.0 did not record it.
Legal Bases
- Operation and security of the website (Art. 6(1)(f) GDPR).
- Optional website analytics after consent (Art. 6(1)(a) GDPR).
- Aggregate consent-flow measurement from same-origin access logs (Art. 6(1)(f) GDPR).
- Handling support requests (Art. 6(1)(b) and Art. 6(1)(f) GDPR).
- Processing app data based on your app configuration and choices in iOS (Art. 6(1)(a) GDPR where applicable).
Recipients
Personal data may be disclosed only to service providers required for operation.
- Website operation: Manuel Faderny e.U.
- Website analytics after consent: Matomo operated by Manuel Faderny e.U.
- App distribution and billing for iOS: Apple, as an independent controller for App Store services.
Personal data is not sold.
Retention
- Technical server logs and consent-flow access-log entries are retained only as long as needed for operation, security, troubleshooting, and aggregate consent statistics; they are normally kept for up to 30 daily rotations.
- Matomo analytics records are created only after analytics consent and retained only as long as needed for aggregate website improvement.
- Support requests are retained only as long as needed to handle the request and any necessary follow-up.
- App data remains on your device until you remove it through Sign Out, Delete Connection, Clean Start, or iOS. Recent status-change history is limited to the newest 20 observed transitions per saved connection.
Your Rights
Under GDPR, you have rights of access, rectification, erasure, restriction, objection, and data portability.
You can withdraw website analytics consent at any time by reopening the privacy settings in the footer. To ensure Keychain credentials are removed before deleting the app through iOS, use Sign Out, Delete Connection, or Clean Start first.
Complaint Authority
Austrian Data Protection Authority (Datenschutzbehoerde)
Barichgasse 40-42
1030 Wien
Austria
www.dsb.gv.at
Privacy Contact
Email: support@manueldigital.at
Last updated: August 31, 2026.