VoidSignal

Privacy Policy

Last updated: July 10, 2026

This Privacy Policy explains how VoidSignal processes personal data when you use the VoidSignal iOS app, web app, and related account services.

Controller / Responsible Party

Jens Rosenfeld
Lahnstr. 18
64347 Griesheim
Germany
Email: voidsignal@deckhead.de

Scope of This Privacy Policy

This policy covers VoidSignal’s account service, the iOS app, the web app, and the servers that provide the service. It does not govern RSS publishers, websites, Apple, or other services you access outside VoidSignal.

Data We Collect

VoidSignal processes data needed to provide a personal RSS reader. The following categories are associated with your account and therefore with your identity:

  • contact information: first name, last name, display name, email address, and login name;
  • identifiers: internal user ID, authentication-token records, and, when used, an Apple-provided user identifier;
  • product interaction and other usage data: subscriptions, categories, article states, filters, and app preferences described below.

VoidSignal does not request location, payment, health, contacts, photos, videos, audio, sensitive information, advertising data, or browsing/search history outside the app. The reviewed source code and declared app dependencies do not include analytics, advertising, tracking, or crash-reporting services.

Account Information

Registration and profile management process your name, email address, login name, password hash, internal user ID, language, and selected interface font. Passwords are stored as password hashes, not as plaintext passwords. Authentication records contain hashed tokens, their creation, expiry, and last-use times. Failed authentication attempts are rate-limited using hashed IP-address and identity values for security.

Usage and Product Interaction Data

To make the reader work across your devices, VoidSignal stores your feed subscriptions, categories, feed settings, read/unread state, Read Later state, muted state, global and feed-specific mute keywords, and interface preferences. This is product-interaction and other usage data linked to your account; it is not treated as anonymous data.

Feed and Article Data

VoidSignal stores feed URLs and feed metadata such as titles, site URLs, descriptions, and fetch status. It fetches RSS and Atom content and stores article data supplied by those sources, including titles, links, authors, summaries, content, images, and publication dates. Article content may be shared between subscribers to the same source, while your subscription and article-state records remain associated with your account.

Sign in with Apple

If you choose Sign in with Apple, VoidSignal receives and verifies the Apple identity token and authorization code. It processes Apple’s user identifier and the email address provided by Apple, which may be a private relay address. Apple may provide your name during sign-in. This information is used to create or link your VoidSignal account and sign you in. Apple’s own privacy policy applies to Apple’s processing.

Local Storage and Offline Use

The iOS app stores a local SQLite cache in the app’s support storage. It can contain your profile, feeds, categories, articles, article states, and queued changes that have not yet synchronized. The iOS app also stores local display preferences, including the Day/Night theme. This local storage supports offline reading and later synchronization; it is separate from the server-side account data.

Cookies and Web Sessions

The web app uses a same-origin session cookie named voidsignal_session. It is HttpOnly, Secure when served over HTTPS, and SameSite=Strict, so browser JavaScript cannot read it. A separate voidsignal_csrf cookie is readable by the web app only to send its value in the X-CSRF-Token header for state-changing requests; it is also Secure when served over HTTPS and SameSite=Strict. These are necessary security and login cookies, not advertising or analytics cookies. The current default session lifetime is 90 days; logout revokes the active web session.

Purpose of Processing

We process data to create and secure accounts, authenticate users, provide and synchronize the reader, import and export subscriptions, fetch feeds, show content and preferences, handle account deletion, prevent abuse, and maintain the service’s security and reliability.

Legal Basis

Where the GDPR applies, processing is generally based on performance of a contract or steps requested by you to provide VoidSignal (Art. 6(1)(b) GDPR). Where required, processing is based on consent (Art. 6(1)(a)). Security, abuse prevention, operation, and troubleshooting may be based on legitimate interests (Art. 6(1)(f)). Processing may also occur where necessary to comply with a legal obligation (Art. 6(1)(c)).

Data Sharing

VoidSignal does not sell personal data, use it for cross-app or cross-website tracking, create advertising profiles, or serve personalized advertising. Personal data is not shared for those purposes. Data may be processed by infrastructure providers that operate the deployed service where necessary to host, secure, and maintain it.

Third-Party Services

The reviewed code uses Apple for Sign in with Apple when you choose that sign-in method. RSS and Atom sources are external services selected by you or available through the feed catalog. The reviewed source code and declared iOS dependencies contain no third-party analytics, advertising, tracking, or crash-reporting SDK.

External Websites and RSS Sources

VoidSignal’s server requests the RSS or Atom URLs that are subscribed to so it can retrieve feed content. When you open an original article, VoidSignal can open the publisher’s external website. The external site then operates under its own privacy policy. iOS sharing and opening links are initiated by you through the system’s sharing or browser facilities.

Data Retention

Account-related data is retained while the account exists unless it is deleted sooner. By default, the cleanup job removes eligible read or muted articles after 30 days. Read Later articles are retained while they remain saved. Authentication tokens expire under the configured token lifetime and can be revoked on logout; expired tokens and stale rate-limit counters are cleaned up. Operational fetch logs may record feed-fetch status, HTTP status, counts, messages, and timestamps; optional file logging can be enabled by the operator. Retention can vary where security, technical, or legal needs require it.

Account and Data Deletion

You can delete your account from the account/profile area of both the iOS app and web app after confirming your current password. The service deletes the user record; related account data is configured with database deletion relationships, including tokens, provider links, categories, subscriptions, filters, and article-state records. The iOS app’s local cache is cleared as part of its sign-out/account-deletion flow. Shared feed and article records may remain where they are used by other subscribers or are not account-specific. Limited information may persist temporarily in technical backups or logs where necessary for security, integrity, or legal reasons. For deletion requests or help, use the contact details below.

Security

VoidSignal uses account authentication, hashed passwords and tokens, HTTPS-capable secure cookies, SameSite cookie restrictions, CSRF checks for cookie-session changes, authorization checks, rate limiting, and input validation. No method of transmission or storage is completely secure, but we take reasonable technical and organizational measures appropriate to the service.

International Data Transfers

VoidSignal may retrieve feeds from sources located in different countries, and Apple processes Sign in with Apple according to its own service arrangements.

Children’s Privacy

VoidSignal is not directed to children. Do not use the service if you are not permitted to enter into the relevant agreement in your jurisdiction. If you believe a child has provided personal data, contact us so the request can be reviewed.

User Rights

Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data, and to withdraw consent where processing relies on consent. You may also have the right to complain to a competent data protection authority. To exercise rights, contact the responsible party below. We may need to verify your identity before acting on a request.

Changes to This Privacy Policy

We may update this policy when the service or applicable requirements change. The date at the top shows when it was last updated.

Contact

For privacy questions, account deletion assistance, or data-rights requests, contact:

Jens Rosenfeld
Lahnstr. 18
64347 Griesheim
Germany
Email: voidsignal@deckhead.de