konsumchen
  • English
  • Deutsch
Access
Install app
Install konsumchen for quick home-screen access.

Privacy & data transparency

konsumchen is built so that even the operator can't surveil what you log. Here is exactly what the server can and cannot see.

What the server never sees or logs

  • Your IP address. It is stripped at the network boundary before the app runs, so no code, log, or error report can record where you connect from.
  • Access logs. No request lines, URLs, methods, or timing are written — and the token in your link is never recorded.
  • When you create or delete a tracker. These actions are deliberately not logged.
  • Your access token via the Referer header. A strict no-referrer policy stops it leaking to any site you open next.
  • Third parties. No CDNs, no Google Fonts, no analytics, no ad or tracking scripts — every asset is served from this server.
  • Tracking cookies. There are none.

What is stored

To do its job, the app keeps only:

  • Your entries — substance, amount, time, and any optional mood or note. These are stored in plaintext because the app must read them to compute your stats.
  • Your access token — the credential in your private link.
  • Optional details you choose to add: a display name, a recovery email, your language, and your standard-drink setting.

Cookies

One strictly-necessary cookie: a signed, HttpOnly session cookie (SameSite=Lax). It keeps you signed in on this device, remembers your language, and holds your "recently opened" list. It carries no tracking identifiers and is never shared. Because it is essential to the service, no consent banner is required.

Only on your device

The "recently opened on this device" list lives inside that session cookie in your browser. The server never builds a cross-device profile of you.

Your data, your control

  • Export everything as CSV or JSON at any time.
  • Delete your tracker and every entry in one click — it is irreversible and no server-side copy is kept.
  • If you added a recovery email, it is the only personal detail on file; remove it anytime in Settings.

Data at rest

Entries are stored unencrypted at the application level so your stats can be computed. Protecting the database at rest (disk or managed-database encryption) is the responsibility of whoever operates this instance.

Email

This instance can email your access link to a recovery address if you add one. The address is used only for that, and the message is sent through the operator's mail server.

Questions?

No public contact channel is configured on this instance.

konsumchen is a private, harm-reduction self-tracking tool. It is not medical advice and does not encourage use. Reference doses are approximate.

Privacy

© 2026 konsumchen · privacy-first, no account required