Help & Documentation
Offline-first guidance for safe gear lists.
Privacy & Data
Where data lives, what's encrypted, which third parties touch it, and how to delete an account
Cine Power Planner is local-first. By default, all data lives in IndexedDB and OPFS on your device. Cloud sync is opt-in and uses a self-hosted Supabase instance in Nuremberg, Germany. Sensitive data (contacts, profile, billing) is encrypted at rest with AES-256-GCM. This article covers the exact behavior, the third parties involved, GDPR rights, and account deletion.
Local Storage by Default
All data starts on your device. Nothing is transmitted unless you opt into cloud sync or use a feature that requires it (payments, route planning).
- IndexedDB — primary store for projects, devices, contacts, gear, settings.
- OPFS (Origin Private File System) — secondary backup tier; auto-backups land here.
- LocalStorage — obfuscated preferences (theme, language, UI state).
- No account is required to use the app.
- The app works fully offline.
Tips
- Clearing site data in the browser wipes everything except items that were synced to the cloud.
- Export a JSON backup periodically (Settings → Backup & Data) — local-only data has no other safety net.
Optional Cloud Sync
Cloud sync is opt-in and disabled by default. Since v0.223, an explicit Cloud Sync consent decision is recorded before any project data is uploaded — see 'Cloud Sync consent' in the Cloud Sync help article for the full grant/withdraw flow.
- Self-hosted Supabase instance on Hetzner Cloud, Nuremberg, Germany.
- Data encrypted in transit via TLS.
- Sensitive entities encrypted at rest (see the Data Encryption section).
- Explicit consent gate (v0.223 / UL-11): the upload-to-cloud step only runs after you've granted Cloud Sync consent. Until you do, sync stays paused even though you're signed in.
- Sync runs in the background while online; the app stays fully usable offline.
- Anonymous tool-usage counts: with Cloud Sync consent, opening a PDF tool or a calculator adds one to a daily counter for that tool (at most once per tool, account and day). Only the tool and the date are stored in the counter — not your account, device or IP address. To avoid counting a tool twice on one day, the server keeps a one-way hash of account ID, tool and date and deletes it the next day; nothing is saved on your device for this. To leave your account out of tool counting and of the aggregate usage statistics, turn on “Leave my account out of usage statistics” in Settings → Security & Privacy → Privacy & Legal. Admins use the totals to decide which tools to improve.
- Help-search terms: only if you turn on Help search analytics under Settings → Security & Privacy → Privacy & Legal (off by default, and you also need Cloud Sync consent), a search in the Help panel sends the search term (lowercased, at most 200 characters) and whether it found anything to a counter for that term. The term is stored without your account or IP address, so avoid typing personal details. Admins use the totals to find missing help articles. Switched off, help searches stay on your device.
- Settings → Account.
- Click 'Create Account' or 'Sign In'.
- If a Cloudflare bot-check (Turnstile) appears, complete it.
- Verify your email address and sign in.
- In the one-time Cloud Sync consent dialog, choose 'Consent and continue' to sync, or 'Sign out instead' to upload nothing.
- Sync becomes active; existing local data uploads in the background.
Tips
- Cloud sync can be turned off in two ways. Sign out — sync stops on this device, cloud copy untouched, other signed-in devices keep syncing. Withdraw consent (Settings → Security & Privacy → Privacy & Legal → Cloud Sync → 'Withdraw cloud sync consent') — the server purges your cloud data globally; local copy on every device stays intact.
- Enabling sync does not change offline behavior; the app still works without a connection.
Data Ownership
You own your data. The app neither claims rights nor sells information.
- Projects, gear, contacts, templates — all yours.
- No data mining; no advertising profile.
- Export anytime via Settings → Backup & Data.
- Account deletion removes cloud-stored data permanently and then clears the local data on the device you delete from.
Third-Party Services Used
A short list of services involved, exactly what they process, and what they don't.
- Supabase (self-hosted, Germany)
- Authentication and cloud sync. Runs on your Hetzner instance — Supabase Inc. has no access to the data.
- Stripe (Stripe Payments Europe, Ireland)
- Stripe Checkout for upgrades and Stripe Customer Portal for managing subscriptions. Processes email, card details, and IP. Sends transactional billing emails. Privacy: stripe.com/privacy.
- Transactional email (self-hosted mail server)
- Account confirmations, password resets, subscription notifications, and other transactional emails are sent from the app's own self-hosted mail server over SMTP — not via a third-party email provider. Only your email address and the message content are processed, and they stay on the self-hosted infrastructure.
- Marketing email (opt-in only)
- Occasional emails about the app and its plans are sent only if you tick “Marketing & product emails” at sign-up or later in Settings → General → Email Notifications. They go through the same self-hosted mail server, every one carries an unsubscribe link, and switching the setting off withdraws your consent. Legal basis: your consent (Art. 6(1)(a) GDPR).
- Cloudflare Turnstile
- Bot protection on sign-in / sign-up. May process IP and browser metadata. No cookies are set. Privacy: cloudflare.com/privacypolicy.
- OpenRouteService (HeiGIT, Germany)
- Optional route planning and travel-time estimates. Coordinates and IP are transmitted only when this feature is actively used. Privacy: openrouteservice.org/privacy-policy.
- Open-Meteo (run on our own server)
- Weather forecasts for shoot locations are calculated on our own server, with the open-source Open-Meteo software and Open-Meteo's open weather data (CC BY 4.0). The GPS coordinates and your IP address stay on our server; nothing is sent to Open-Meteo or another weather service.
- Support auto-reply (self-hosted)
- Emails to support@cine-power-planner.com get an automated acknowledgment. Rate-limited. Processes sender email and subject only; no data shared with third parties.
- No tracking pixels, no Google Analytics, no Facebook Pixel.
- No advertising cookies.
Data Encryption at Rest
Sensitive records (contacts, your profile, invoices, expenses, billing details and more) are encrypted on your device before they are written to storage or synced.
- Cipher: AES-256-GCM.
- Key derivation: PBKDF2-SHA256 with 600,000 iterations (OWASP 2023 guidance). The key is derived from your user ID plus a server-issued seed, mixed with a per-device salt. (Older data uses a legacy 100,000-iteration path and stays readable for backward compatibility.)
- A per-device salt is stored redundantly in both localStorage and IndexedDB.
- Cloud sync transmits already-encrypted payloads over TLS — TLS is the second layer, not the only one.
- Non-sensitive preferences use XOR obfuscation only — enough to prevent casual DevTools inspection, not a security boundary.
Tips
- Encryption is automatic — no setup, no key to memorize.
- Clearing all browser data on a device removes the data stored on that device and creates a new local key. Nothing becomes unreadable through the new key: everything that was synced comes back from cloud sync. What was never synced is gone.
- These records are encrypted on your device before upload, and no part of the server decrypts them — sync and the assistant (Agent access) only ever handle encrypted data. It is still not end-to-end encryption in the strict, zero-knowledge sense: the key is derived from your user ID and a seed that the server stores, so someone with full access to the server database could derive it.
GDPR / DSGVO Rights
Six rights, each mapped to an action in the app.
- Access
- Settings → Security & Privacy → Privacy & Legal → 'Download my personal data' gives you everything the server holds about your account, as one file. 'Download full backup' under Settings → Backup & Data exports what is on this device.
- Rectification
- Edit any record directly inside the app.
- Erasure
- Delete the account from Settings → Security & Privacy → Danger Zone → Delete Account.
- Portability
- JSON backup is portable and human-readable when decompressed.
- Restriction
- Sign out or disable cloud sync to stop server-side processing.
- Objection
- To object to usage statistics alone, turn on 'Leave my account out of usage statistics' under Settings → Security & Privacy → Privacy & Legal. Delete the account to opt out of all processing.
Tips
- Data Processing Agreements (AVV) are in place with each processor named in the third-party list.
- GDPR rights apply regardless of whether you're paying — Free users have the same protections as Pro.
Deleting the Account
Account deletion removes cloud data permanently, then clears the local data on the device you delete from and reloads the app.
- Settings → Security & Privacy → Danger Zone → Delete Account.
- All cloud-stored projects, devices, contacts, and account metadata are permanently removed.
- An active subscription bought on the website is cancelled automatically via Stripe. An App Store subscription is not — cancel it in your Apple Account subscription settings first.
- Local data on the device you delete from is cleared too (a factory reset of this app's storage), and the app reloads — download what you want to keep first.
- Settings → Security & Privacy → Danger Zone, then click 'Delete Account' to open the confirmation gate.
- Download your tax records (GoBD) AND a full backup using the two download buttons — deletion is irreversible and erases the cloud copy of these records. The tax records are built on this device from your synced invoices; if some have not reached this device yet, the download stops and says how many are missing.
- Type DELETE in the confirmation field.
- Tick the acknowledgment checkbox that your data will be permanently deleted.
- Enter your current password. The confirm button stays disabled until all of the above are satisfied.
- Confirm. Server-side erasure of your cloud copy follows; the cloud data and account record are removed.
Tips
- Re-registering with the same email later is permitted but creates a fresh account — old data does not return.
- Contact support if you need help (e.g. recovery of a backup before deletion).
Privacy Consent Banner
On first use (or after clearing site data) a banner asks for consent to the privacy policy.
- Accepting unlocks full functionality.
- Declining restricts project creation and Power Calculator use; a notice explains exactly which features are blocked.
- Cloud sync and subscription features remain usable even if you decline.
- The consent decision is stored locally; clearing site data resets it.
- Local data is never deleted just because consent was declined.
Tips
- Accepting consent is not the same as enabling cloud sync — that's a separate opt-in.
- If you're not sure, read this Privacy & Data article (and the privacy policy linked from the banner) before deciding.
Privacy Mode: Hide Amounts
The eye icon in the sidebar footer, next to Privacy and Terms, hides every amount on screen, the way banking apps do. Use it on set, in a shared office or while sharing your screen.
- Click the eye to hide amounts. Every price, total, balance and budget then shows ••••, including dashboards, charts, invoice and quote lists, banking and project budgets.
- Bank account numbers (IBANs) in read-only views keep only their last four characters (•••• 1234).
- Click the crossed-out eye to show the amounts again. The change applies instantly, without a reload, and open forms keep their edits.
- Input fields always show their real value, so you can still edit an amount while amounts are hidden.
- PDFs, e-invoices, exports, emails and share links always contain the real amounts. Privacy mode changes only what the screen shows. The public page where a customer accepts a quote always shows the amounts too.
- The setting belongs to this device and browser. It survives a reload and is not synced to your other devices.
Tips
- Privacy mode hides figures from onlookers; it is not access protection. Anyone who can use the device can switch it off.
- On the collapsed sidebar the eye has its own row directly under the privacy and terms icons; in the expanded sidebar it follows "Privacy • Terms".
Local by default, encrypted in transit AND at rest when sync is on, built around the GDPR requirements. Cloud infrastructure runs on your team's self-hosted Hetzner Cloud instance in Nuremberg, Germany — not on shared SaaS.
Related Topics
See also
