# Privacy Policy **Current Spot - Wear OS, watchOS, iOS & macOS App** Last updated: 26 July 2026 A German version of this policy is available at , along with Dutch, Swedish and Norwegian translations. ## 1. Data Controller The controller within the meaning of the GDPR is: Ivan Kablar Carl-Sonnenschein-Straße 31 65936 Frankfurt am Main Germany Email: ivankablar25@gmail.com ## 2. Data Collection and Storage This app collects and stores the following data locally on your devices: - **Tibber Access Token**: Your personal Tibber API access token is stored locally on your phone and synchronized to your Wear OS watch - **Home ID**: Your Tibber Home identifier for retrieving electricity prices - **Electricity Price Data**: Current and forecasted prices — from the Tibber API when a Tibber account is connected, otherwise from public exchange prices - **App Preferences**: Your selected settings (e.g., price interval: hourly/15-minute) - **CarPlay Home Location (iOS, optional, opt-in)**: If you enable CarPlay home detection, the GPS coordinates and radius of your home are stored locally in iOS system settings. This feature is off by default. See section 3 ("CarPlay & Location") for details. **All data is stored exclusively on your devices.** No data is transmitted to third-party servers except as described below. No analytics or tracking services are used. ## 3. Third-Party Services ### Tibber API - The app connects to the official Tibber API (api.tibber.com) to retrieve electricity prices - Your access token is used to authenticate with Tibber's servers - Data transmitted: Access token, Home ID - Data received: Electricity prices, price levels, home information - Purpose: Display current and forecasted electricity prices on your smartwatch - Legal basis: Art. 6 (1) (b) GDPR (performance of the service you requested) - Privacy Policy: https://tibber.com/de/privacy-policy ### Google Play Services - Wear OS Data Layer: Used to synchronize your access token and settings between phone and watch - No user data is shared with Google beyond what's required for app functionality ### CarPlay & Location (iOS, optional) The optional CarPlay features process additional data **exclusively locally on your iPhone**. No location or address data is transmitted to the developer, to Tibber, or to third parties. - **CarPlay in-car display**: When the iPhone is connected to CarPlay, the app shows electricity prices and cheapest charging blocks from the local cache. No additional network requests are made. - **Home geofence (opt-in, off by default)**: If you enable the "cheap charging window at home arrival" notification, the app processes the GPS coordinates and radius of your home (manually entered or derived from your Tibber address via reverse geocoding). These are stored exclusively locally in iOS system settings and never leave your device. iOS monitors the home region and the app only receives a "region entered" event — it does not know your location outside the home region. - **"Always" location permission**: iOS requires this permission level for region monitoring to work in the background. The app uses it exclusively for this purpose — no continuous tracking. - **Reverse geocoding**: If you enter your address as text, the app passes it to Apple's geocoding service. Apple processes the request per [Apple's Privacy Policy](https://www.apple.com/legal/privacy/). Coordinates are stored only locally. - **Notifications for this feature**: The arrival alert is generated by your iPhone itself; no push token is transmitted to a server for it. The separately enabled server notifications are described in the next section. - **Deleting data**: App Settings → CarPlay → "Delete home" removes all stored location data and stops region monitoring. Uninstalling permanently deletes everything. - **Legal basis**: Art. 6 (1) (a) GDPR (consent) or Art. 6 (1) (b) GDPR (performance of activated function). ### Server push: Live Activity auto-start & tomorrow-prices notification (iOS) This optional feature (**off by default**) lets the "cheap electricity block" banner (Live Activity / Dynamic Island) start **automatically** at the right time and disappear again when the block ends, even when the app is not open. It requires minimal server-side processing. In addition, the **"tomorrow's prices" notification** (settings switch, can be turned off at any time) can be delivered via the same server — faster and more reliable than the local background fetch. - **Transmitted & stored:** **anonymous push tokens issued by Apple**, a scheduled time, the **public** electricity-block data (block start/end, average price), your **electricity price zone** (e.g. DE-LU or SE3 — a coarse region, not an address), **calculation values** derived from your tariff (to estimate the block price server-side) and your chosen **lead time**. **No** Tibber token, **no** Home ID, **no** identity, **no** consumption data. - **Public price data:** to compute the block, the server fetches **public spot prices** from electricity market data sources. **No user data** is transmitted in the process. - **Where:** stored with **Cloudflare, Inc.**; the start signal is delivered via the **Apple Push Notification service (APNs)**. - **Anonymity:** neither the developer nor Cloudflare can link the token to your identity — only Apple can resolve it to a device (Apple issued it). No email, name or account is involved. - **Retention:** block entries are kept for **up to 36 hours after the block ends** (technical diagnostics), then deleted automatically. The zone registration (price zone, calculation values, lead time) is stored until you **turn the feature off** — at which point it is deleted server-side together with all entries. Uninstalling without turning it off: entries expire as soon as the tokens become invalid. The same applies to the notification registration: switch off → deleted server-side. - **Legal basis:** Live Activity auto-start: Art. 6 (1) (a) GDPR (consent — opt-in). Tomorrow-prices notification via server: Art. 6 (1) (b) GDPR (delivery of the notification requested via the switch; switch off = server-side deletion). Cloudflare: https://www.cloudflare.com/privacypolicy/ · Apple/APNs: https://www.apple.com/legal/privacy/ ### In-app purchases Optional purchases (donations on Wear OS via Google Play Billing, the optional Premium subscription on Apple platforms) are handled entirely by Google or Apple. The developer receives **no payment or identity data** — only the technical confirmation of the purchase or subscription status. Legal basis: Art. 6 (1) (b) GDPR. See [Google](https://policies.google.com/privacy) and [Apple](https://www.apple.com/legal/privacy/). ## 4. Data Usage The collected data is used solely for: - Authenticating with the Tibber API - Displaying electricity prices on your watch, phone, tablet or desktop - Synchronizing settings between your devices - Providing app functionality **We do not:** - Sell or share your data with third parties - Use your data for analytics or advertising - Store your personal data on external servers (the optional server-push feature stores only the anonymous tokens and public data described above) - Track your usage behavior ## 5. Data Security - All data is stored in app-private storage protected by the operating system's application sandbox - Communication with the Tibber API uses HTTPS encryption - Your access token is never logged or exposed in debug output ## 6. Your Rights (GDPR) You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, contact ivankablar25@gmail.com. Because the app stores all data locally, you can exercise most of them yourself: - Uninstalling the app from your devices deletes all local data - Revoking the Tibber access token in your Tibber account settings - Exporting your token from the app settings - Updating your token or home selection at any time ## 7. Right to Lodge a Complaint You have the right to lodge a complaint with a data protection supervisory authority. ## 8. Data Retention - Local data is retained only while the app is installed - Uninstalling permanently deletes all data from your device - Apart from the anonymous server-push registrations described in section 3, the developer stores no user data on own servers ## 9. Children's Privacy This app is not intended for children under 16. We do not knowingly collect personal data from children. ## 10. Changes to This Policy We may update this privacy policy from time to time. The date at the top of this page indicates the last update. Significant changes will be announced in the app. ## 11. Contact For questions or concerns about data privacy, please contact: - Email: ivankablar25@gmail.com - GitHub: https://github.com/IvanKablar/current_spot_support/issues - Developer: Ivan Kablar