Legal & Privacy
Impressum
Catalysys Switzerland GmbH
Mühlackerstrasse 19
4402 Frenkendorf
Switzerland
Contact: contact@catalysys.ch
UID: CHE-318.570.876
We reserve the right not to be responsible for the topicality, correctness, completeness, or quality of the information provided. Liability claims regarding damage caused by the use of any information provided, including any kind of information which is incomplete or incorrect, will be rejected.
Privacy Policy
Last updated: February 2026
1. Data Protection
Based on Article 13 of the Swiss Federal Constitution and the data protection provisions of the Swiss Confederation (Federal Act on Data Protection, FADP), every person has the right to protection of their privacy as well as protection against misuse of their personal data.
We comply with these provisions and treat your personal data confidentially. We do not pass on personal data to third parties. We cooperate closely with our hosting providers to protect the databases as well as possible against unauthorized access, loss, misuse, or falsification.
2. End-to-End Encryption
Zettelcrypt is designed with privacy as a core principle. All note content is encrypted on your device before being transmitted to our servers. This means:
- Your notes are encrypted using keys derived from your password
- Only you can decrypt and read your note content
- Our servers only store encrypted data that cannot be read by anyone, including us
- Even in the event of a data breach, your note content remains protected
3. Data We Collect
We collect and process the following data:
- Account information: Username and a securely hashed password
- Encrypted content: Your notes in encrypted form (unreadable to us)
- Technical data: IP address and access times for security and server logs
4. Contact Communications
When contacting us, your data (e.g., name, email address) and your request will be stored and processed by us in order to process and respond to your inquiry, as well as for any follow-up questions.
5. Cookies
Zettelcrypt uses minimal cookies that are essential for the service to function:
- Session data: Used to maintain your logged-in state
- Preferences: Stores your language and display preferences
We do not use tracking cookies or third-party advertising cookies.
6. Website Analytics
We use a self-hosted, privacy-centric analytics system to understand how our website is used. Our analytics:
- Uses no cookies or tracking pixels
- Does not collect personal information
- Generates anonymous visitor IDs using a daily-rotating hash (IP + User Agent + daily salt)
- Cannot track individual users across days or sessions
- Raw IP addresses are never stored
- A small script (~300 bytes) confirms real browser visits and collects screen resolution
- Fully respects your browser's Do Not Track (DNT) setting
This data helps us understand which pages are visited and improve the website experience. No data is shared with third parties.
7. In-App Analytics (Opt-In)
Zettelcrypt offers optional, anonymous analytics within the application. This is entirely opt-in — no data is collected unless you explicitly enable it in Settings > Privacy. You can choose to share:
- Feature usage: Which features you use (e.g., search, graph view, export)
- Preference insights: Anonymous preference data (theme, language choice)
This data helps us identify popular features, prioritize development, and improve the user experience. All data is anonymous and processed by our self-hosted analytics system. You can disable analytics at any time.
8. Data Storage Location
All data is stored on servers located in Switzerland, which provides strong data protection under Swiss law and is recognized by the EU as providing an adequate level of data protection under GDPR.
9. Your Rights
Under the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR), you have the right to:
- Access: Request information about your stored personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data
- Restriction: Request restriction of processing
- Portability: Export your data (available via the app's export feature)
To exercise these rights, please contact us at contact@catalysys.ch.
10. Data Retention
Your account and encrypted notes are retained as long as your account is active. Server logs are retained for security purposes and automatically deleted after 90 days. You may delete your account and all associated data at any time through the application settings.
11. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date.