"Velmun" is a brand name, not a company. The apps are published by Daniel Pommranz as an individual.
This is a draft, not yet reviewed by a lawyer. It covers this website, the info@velmun.com mailbox, and the sync relay used by Velmun apps (including naido). The naido Android app and naido.app carry their own, additional privacy policy at naido.app/privacy/en/.
Daniel Pommranz, Untere Haldestraße 7, 72810 Gomaringen, Germany. E-mail: info@velmun.com. “Velmun” is a brand name, not a company; the provider and controller within the meaning of Art. 4 no. 7 GDPR is Daniel Pommranz as an individual. No data protection officer has been appointed; the conditions of § 38 BDSG are not met.
This website sets no cookies, loads no third-party scripts, fonts or content, embeds no analytics or reach measurement, and contains no forms. There is nothing here you would need to consent to, and therefore no consent banner. We keep no access logs ourselves. What is processed is limited to what arises technically (section 3), what you send us yourself (section 4), and the sync service, if you use it (section 5).
This site is static and hosted on Cloudflare (Cloudflare Pages). When you open a page, the host processes technically necessary connection data: the requesting device’s IP address; date and time of access; the resource requested, HTTP status code and volume transferred; the user agent (browser and OS identifier); and, where present, the referrer.
We don’t yet have a confirmed figure for how long the host retains these logs; we will add it here once we do, rather than guess at a retention period.
Purpose: delivering the site, operational security, defending against attacks and abuse. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in technically sound and secure operation of the site. For technically necessary access to your device, § 25(2) no. 2 TDDDG applies; nothing beyond that is stored on or read from your device.
We do not combine this data with other sources, and we do not derive an identity from it.
If you write to info@velmun.com, we process your e-mail address, the subject, the content of your message and the message’s technical header data.
The mailbox runs through Cloudflare Email Routing: Cloudflare receives the incoming message and forwards it to our destination mailbox, processing it in transit. We haven’t yet documented the destination mailbox provider and its processing location in this text; we will add that here.
Purpose: handling your enquiry. Legal basis: Art. 6(1)(b) GDPR where your enquiry concerns a contract with us; otherwise Art. 6(1)(f) GDPR (our interest in answering enquiries). Retention: we delete the correspondence once it is no longer needed to answer you and no statutory retention duty stands in the way; commercial and tax retention duties (§ 257 HGB, § 147 AO) are unaffected.
Note: unencrypted e-mail is not a secure channel. Don’t send us anything you wouldn’t write on a postcard.
Velmun apps can sync data between your own devices. If the devices are on the same Wi-Fi, they talk to each other directly and nothing touches our infrastructure. Where that isn’t possible, sync runs through the mailbox — a temporary store that we operate.
What is processed there: the sealed envelope, an end-to-end encrypted data package of at most 2 MB; the mailbox address, a SHA-256 hash computed from your sync code; a SHA-256 hash of your write token (not the token itself), used to check write permission; version number, time of the last drop, and expiry date; and whether sync is active for this mailbox and until when.
We don’t point the mailbox at a person: there is no account, no e-mail address, no login, no device identifier, and no record of how many devices access a given mailbox. Only your paired devices hold the key to the envelope. We cannot read the content, neither on our own initiative nor on request from an authority.
This data still counts as personal data, because the mailbox address is a pseudonym that can be linked to your devices, and because even transporting encrypted data is processing within the meaning of Art. 4 no. 2 GDPR. We are the controller for it; Cloudflare is our processor.
IP addresses: we do not log the IP addresses of connecting devices ourselves. Cloudflare’s infrastructure sees the connecting IP address, as with any request on the internet. We don’t yet have a confirmed figure for the scope and retention of these connection logs at Cloudflare; we will add it here once we do.
Purpose: providing the sync service you switched on in the app. Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract for the sync service); additionally Art. 6(1)(f) GDPR for abuse prevention and operational security of the relay. Retention: a mailbox, contents included, deletes itself automatically if no new envelope has been dropped for 30 days. You can empty it yourself at any time. An envelope is overwritten as soon as a new one is dropped for the same address.
Location: the mailbox runs on Cloudflare infrastructure that places mailboxes exclusively in European Union data centres. Mailboxes created before the zone was bound to the EU (3 September 2026) were discarded.
The sync code carries the security. The security of the sync depends on the code. Exchanged by QR code between your devices, it is randomly generated and strong. If you choose it yourself, it is only as strong as what you typed — a short or guessable code weakens the protection. For the content of an envelope, we derive the key using PBKDF2-HMAC-SHA256 with 150,000 iterations from the code. The mailbox address and your write token, however, are formed as a plain SHA-256 hash of the code without additional stretching — so a short or guessable self-chosen code is easier to work backwards from at that level than the envelope content itself, which stays protected by the 150,000 iterations. Use the randomly generated, QR-code sync code wherever you can. If you lose every device and the code, the mailbox stays shut; we cannot open it and cannot restore the data.
Paid features (for example naido’s partner sync, EUR 39.99 per year or EUR 5.99 per month) do not currently run through Google Play’s purchase flow. You buy or renew through a process we operate ourselves; the app then exchanges a code for a digitally signed entitlement token, which each of your devices verifies itself. The token carries only a mailbox identifier, an expiry date and the plan — no name, account or payment data reaches us through it. Where and how a purchase itself is paid for, and which payment processor is involved, isn’t yet finalised and documented here; we will complete this section once it is. A purchase flow through Google Play (Play Billing) is planned for a later version of the naido app; once introduced, payment data for that flow will run exclusively through Google, without us seeing it (Google’s privacy policy), and we will update this section accordingly.
Cloudflare processes data for us as a processor under Art. 28 GDPR — hosting this website, e-mail forwarding, and operating the mailbox — in EU data centres, within a corporate group headquartered in the US. We haven’t yet recorded the exact contracting Cloudflare entity here; we will add it. Google, as an independent controller, is involved wherever Play Billing handles a purchase or app distribution, under Google’s own privacy policy. Our destination-mailbox provider processes stored correspondence as a further processor; its identity and location aren’t yet documented here.
Beyond that, we pass on data only where we are legally required to. For mailbox content: we couldn’t hand it over even if we had to — we don’t hold the key.
We have a data processing agreement with Cloudflare, including the European Commission’s standard contractual clauses for the case that data reaches a third country; we haven’t yet recorded the date it was accepted in our account. Where a transfer to the US occurs, it relies on Art. 46(2)(c) GDPR together with the standard contractual clauses and, where the contracting party is certified, the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR); we haven’t yet verified and recorded that certification status here.
Website server logs: retention period at the host not yet confirmed. E-mail correspondence: kept until your enquiry is resolved, then deleted, subject to statutory retention duties. An envelope in the mailbox: kept until overwritten, at the latest until automatic deletion. The mailbox as a whole: deleted automatically after 30 days without a new drop. Relay connection data at Cloudflare: retention period not yet confirmed.
You have the right of access to data processed about you (Art. 15 GDPR), rectification of inaccurate data (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing we base on Art. 6(1)(f) GDPR for reasons arising from your particular situation (Art. 21), and withdrawal of any consent given, with effect for the future (Art. 7(3)). Contact info@velmun.com.
A limit in substance, not in law: for the mailbox we process no data by which we could identify you. If we cannot link your enquiry to a specific processing operation, Art. 11(2) GDPR means we are not obliged to obtain additional information; you may, however, provide details that make a link possible — for example your mailbox address. You can empty your mailbox yourself in the app at any time, which amounts to erasure.
You can complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany, www.baden-wuerttemberg.datenschutz.de. You can also contact the authority where you live or work.
You are not obliged to provide us with data. Without the data described in section 5, the sync service cannot technically be provided; the apps themselves work without it. No automated decision-making, including profiling within the meaning of Art. 22 GDPR, takes place.
We update this policy when the processing it describes changes. The version published here applies. Last updated: 6 September 2026.