Skip to content

Legal

Privacy Policy

Last updated: August 27, 2026

This policy covers two separate things: the Wonnel app and the website at www.wonnel.app. The app processes no personal data at all. The website counts page views without setting cookies. Both are described in full below.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Maximilian Vogl
Sole proprietor
Maria-Montessori-Straße 24
40789 Monheim am Rhein
Germany
Email: mail@wonnel.app

There is no data protection officer, and none has to be appointed: the conditions of Art. 37 GDPR and Section 38 BDSG (German Federal Data Protection Act) are not met here. I answer data protection questions myself, at the address above.

2. The Wonnel app collects no data

Wonnel processes no personal data. The app has no internet connection, no tracking, no analytics, no advertising, no advertising identifier and no user account. There is no sign-up and no registration.

Everything sections 5 through 9 say about the website therefore does not apply to the app. The reason is how the game is built, and not a setting that could be flipped: Wonnel runs entirely without a network. The app never requests a connection and never opens one. A child can play it in airplane mode, on a train or in a holiday cottage with no reception exactly as they would at home.

No third-party components are built in either. The app contains no analytics SDK, no ad network, no crash reporting and no library that quietly reports identifiers to a server.

The saved game stays on the device

Whatever the game produces stays where it was produced. The saved game lives only in the app’s own storage area on the device. It is never sent to me, never passed on to anyone else and never backed up to a cloud. I have no access to usage data from the app, and there is no way for me to get any.

The downside comes with it: deleting the app deletes the saved game. On a second device the game starts over. That is the price of nothing ever leaving the device.

The parents’ area

The app’s settings sit behind a task that a child aged two to five cannot yet solve. That gate also works entirely on the device. Nothing is checked that could identify a person, and no age is requested.

3. No personal data from children

Wonnel is made for children aged 2 to 5 and processes no personal data from those children. No names, no photos, no voice recordings, no location data, no contacts and no device identifiers are collected. The app has no input field for personal details at all.

That also settles the question of parental consent under Art. 8 GDPR: consent presupposes processing that is based on it. Here there is no processing to begin with.

For the same reason, the app contains none of the following:

  • advertising of any kind, and no advertising identifier from the operating system
  • in-app purchases, subscriptions, or a currency that could be topped up
  • links to social networks or to other apps
  • chat, a forum, or any other way of talking to strangers
  • a browser that could open an arbitrary website from inside the game
  • notifications that nudge a child to keep playing

This policy is available at a fixed address and will stay there. Both stores require that for apps aimed at children, and a link that goes nowhere after six months is as useless to parents as it is to a reviewer.

4. Buying through the App Store and Google Play

Wonnel costs €1.99 once. The purchase itself does not run through me but through the respective store. I never see your name or your payment details.

What data Apple and Google collect during a purchase, and what they do with it, is their own decision. For that processing they are controllers within the meaning of Art. 4(7) GDPR, not me. Their own policies apply:

Both stores send me sales and payout reports. Those reports are aggregated and contain no personal data about individual buyers. I never learn who bought the app.

5. What the web server records

Visiting this website produces no personal log data on the server. The web server is deliberately configured to record neither your IP address nor the page you came from. What is recorded is only:

  • which address was requested, using which method
  • which status code the server returned
  • how many bytes were transferred
  • the browser and operating system string your browser sends along

These entries exist for technical troubleshooting, such as finding out which address stopped working after a change. They allow no conclusion about an individual person, and I combine them with no other source of data. They are deleted after 30 days at the latest.

An IP address is therefore processed at exactly one point on this website, namely in the audience measurement described in section 7. Even there, only in truncated form.

6. Hosting

The website consists of finished pages that the server delivers unchanged. Nothing is computed when you visit, and there is no database anything gets written to. The server sits in a data center in Germany. I administer it myself; it is provided by:

Hetzner Online GmbH
Industriestraße 25, 91710 Gunzenhausen, Deutschland

The provider processes the data named in section 5 solely on my behalf and on my instructions. Should these entries nonetheless relate to an identifiable person in an individual case, the legal basis is Art. 6(1)(f) GDPR; my legitimate interest lies in the secure and uninterrupted operation of this website. For that eventuality, a data processing agreement under Art. 28 GDPR is in place as a precaution.

The provider also keeps its own logs at the infrastructure level, for instance to fend off attacks. I have no influence over those. The periods and conditions of the data processing agreement apply to them.

The audience measurement described in section 7 runs on the same server.

7. Audience measurement with Matomo, without cookies

To see which pages get read, I use the open-source software Matomo. Two things set this apart from ordinary web analytics:

  • Self-hosted. Matomo runs as its own installation on a subdomain of this website (matomo.wonnel.app, site ID 5) and on the same infrastructure as the site, meaning with the provider named in section 6. The data never leaves that infrastructure. Nothing is passed to an analytics vendor and nothing is transferred to a third country. The makers of the software receive nothing either.
  • Without cookies. Matomo is configured here so that it sets no cookies (disableCookies). On top of that, the querying of device properties that could be turned into a fingerprint is switched off (disableBrowserFeatureDetection). Nothing is stored on your device and nothing is read from it.

What is collected:

  • your IP address, truncated by two bytes. 203.0.113.42 becomes 203.0.0.0 before the value is stored.
  • the pages you open, and the time and length of the visit
  • the referring page, if your browser sends one
  • your approximate region, derived from the truncated address
  • device type, browser and operating system
  • whether you followed a link to another website

Because no cookies are set, Matomo cannot reliably recognize returning visitors. What gets evaluated is essentially the single visit, and no cross-device profiles are built.

The legal basis is Art. 6(1)(f) GDPR. My legitimate interest lies in a data-minimizing, statistical evaluation of use in order to improve what is offered here.

Why there is no consent banner: Section 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act) requires consent only where information is stored on your terminal equipment or read from it. Running without cookies and without device fingerprinting, neither happens. The provision therefore does not apply, and there is nothing for you to consent to.

How to object

  • Do Not Track or Global Privacy Control. If your browser sends either signal, Matomo does not count your visit. You will find the setting under your browser’s privacy preferences. Firefox removed “Do Not Track” in version 135 in February 2025; it still offers the Global Privacy Control signal.
  • Objection under Art. 21 GDPR. You can object to the evaluation at any time, informally, by email to the address in section 1. Without a cookie and without an identifier there is nothing for a lasting exclusion to attach to, so for future visits the signal described in the previous point is what takes effect. Once your message reaches me, I delete whatever can be attributed to your visit, and I confirm that to you.

How long the data is kept

The raw data of individual visits is deleted automatically after 14 months. What remains after that is aggregated reporting only, such as the number of views per page and month, which no longer allows any conclusion about a single visit.

8. No content from third-party servers

The Nunito typeface is downloaded while the site is being built and served from the same server as the website. Visiting this site therefore opens no connection to Google Fonts or any other outside server, and no IP address is passed to a third party.

The same goes for everything else. There are no embedded videos, no map services, no social media buttons and no third-party scripts. A Content Security Policy sent by the server further limits where the browser may load anything from at all: only this domain and the site’s own Matomo instance from section 7 are permitted.

The connection is TLS-encrypted throughout. You can tell by the https:// in the address bar.

9. Cookies and local storage

This website sets no cookies. There is no consent banner for you to dismiss.

If you use the switch between the daytime and the night-time forest, your browser remembers that choice in local storage, under the key tageszeit. The value stays on your device and is never sent to the server. It contains nothing but the choice itself, so neither an identifier nor a timestamp. You can remove it by clearing this site’s data in your browser settings.

Local storage is covered by Section 25 TDDDG as well. Here, though, nothing is written until you operate the switch, and what gets stored is your own choice and nothing else. That makes it strictly necessary for a service you have explicitly requested within the meaning of Section 25(2)(2) TDDDG, and it requires no consent. The key is read on every page view, so the page appears right away in the daytime or night-time forest you chose. Reading it is likewise exempt from consent under Section 25(2)(2) TDDDG, because all it does is carry out your own choice.

10. Contact by email

There is no contact form here, and no sign-up either. If you would like to write to me, the address is mail@wonnel.app.

I process your message in order to answer it, and with it your email address and whatever else you choose to tell me. The legal basis is Art. 6(1)(b) GDPR where a contract or its initiation is involved, otherwise Art. 6(1)(f) GDPR, with my legitimate interest in answering inquiries.

I delete these messages once the matter is settled and no statutory retention period stands in the way. Please bear in mind that an unencrypted email can be read on its way through the network.

11. No automated decision-making

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR, neither in the app nor on the website.

12. Your rights

As a data subject you have the following rights in relation to my processing:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate or incomplete data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability in a common, machine-readable format (Art. 20 GDPR)
  • Objection to any processing based on a legitimate interest (Art. 21 GDPR). That covers the server logs in section 5 and the audience measurement in section 7.

An informal message to mail@wonnel.app is enough for all of this. I answer within the statutory period of one month, usually a great deal sooner.

For a plain website visit I can usually give no information, because the stored data cannot be linked to you. Art. 11 GDPR does not require me to collect additional data for the sole purpose of identification. If you give me details that let me identify your visit, I will of course look (Art. 11(2) GDPR).

I obtain no consent, neither in the app nor on the website. There is therefore none for you to withdraw under Art. 7(3) GDPR.

13. Lodging a complaint with a supervisory authority

If you believe that I process your data unlawfully, you may lodge a complaint with a data protection supervisory authority under Art. 77 GDPR. The authority responsible for Monheim am Rhein is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
(State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de (opens in a new window)

You may equally turn to the supervisory authority where you live.

14. Version and changes

This privacy policy is dated August 27, 2026. If something changes about the app, the website or the legal situation, I will update it. The version applicable is always the one you retrieve here.