Kelter

Datenschutz

Für die App Kelter und für Kelters Relay, notify.kelter.app. Ein Satz pro Tatsache; nichts, was die App nicht tut.

Fassung vom 25. September 2026 · English version below

1. Wer verantwortlich ist

Ahmad Bakour Alzayat
Südbahnweg 69/36, 9201 Krumpendorf am Wörthersee, Österreich
office@abz.studio

Kelter ist eine App von einem Entwickler. Es gibt kein Konto, keine Nutzerdatenbank und keinen Dritten, der für Kelter Daten auswertet.

2. Was die App auf deinem Gerät speichert

Kelter liest deine Dateien und dein Terminal zu keinem anderen Zweck, als sie dir zu zeigen.

3. Was das Gerät verlässt — und wann

Das Terminal

Zwischen deinem Gerät und deinem Server, über SSH, direkt. Kelter betreibt keinen Server auf diesem Weg.

Dein eigener Gesprächsserver

Die App kann mit deinem eigenen Gesprächsserver auf deiner eigenen Maschine verbunden werden. Du verbindest ihn, indem du ein Türtoken einfügst, das der Betreiber dieses Servers einmal ausstellt und dir übergibt; ein Token pro Gerät, im Schlüsselbund des Geräts. Die Nachrichten, Bilder und Berichte, die du dort mit deinen Agenten austauschst, liegen auf diesem Server — dem, den du betreibst — und nie auf einem Server von Kelter. Kelters Entwickler betreibt einen solchen Server für sich selbst; die öffentliche Adresse conv.kelter.app ist sein eigener Server, erreichbar über TLS.

Walk Mode und Sprache

Sprache wird auf dem Gerät zu Text — das macht Apples Spracherkennung; auf manchen älteren Geräten erledigt Apple das auf Apples Servern, also auf Apples Weg, nicht auf unserem. Durch Kelter verlässt kein Ton das Telefon. Der Schalter Send logs to Suri ist aus, bis du ihn einschaltest; eingeschaltet schickt er das Protokoll des Spaziergangs selbst — was gehört wurde als Textlängen und Zustände, nie Ton, nie Schlüssel — an deinen eigenen Gesprächsserver.

Agent pings — nur, wenn du sie einschaltest

Pings sind aus, bis du sie für einen Server einschaltest. Beim ersten Mal auf einem Gerät fragt die App vorher, auf einer Karte mit drei Tatsachen:

Was gesendet wird
Der Push-Token dieses Geräts, der Name des Servers und der Sitzung, und was der Agent zuletzt gesagt hat oder ausführen will — bis zu 600 Zeichen.
Wohin es geht
Dein Server → notify.kelter.app, Kelters Relay (betrieben vom Entwickler) → Apples Push-Dienst → dieses Gerät.
Was behalten wird
Nichts. Das Relay speichert keine Nachricht; es zählt Pings pro Token für einen Tag und protokolliert Zeitpunkte, Längen und sechs Zeichen des Tokens — nie die Worte. Apple hält einen Push, bis das Gerät erreichbar ist.

Nicht jetzt lässt den Schalter aus; Erlauben wird auf dem Gerät gemerkt. Schaltest du Pings für einen Server ein, richtet Kelter dort einen kleinen Hook ein. Den Push-Token schickt Kelter an keinen anderen Ort als an diesen Server, über https://, in eine Datei, die nur dein Konto auf dem Server lesen kann. Wenn der Agent fertig ist oder dich braucht, geht seine letzte Nachricht von deinem Server über Kelters Relay an Apple, um dieses Gerät zu erreichen; auf dem Relay wird nichts gespeichert.

Nur Titel

Mit Titles only für einen Server geht nur der Name der Sitzung von deinem Server über Kelters Relay an Apple; die Nachricht des Agenten bleibt auf dem Server, bis du die App öffnest. Für einen neu hinzugefügten Server ist dieser Schalter von Anfang an an — die Worte des Agenten gehen erst den Weg über das Relay, wenn du ihn ausschaltest. Denselben Schalter gibt es einmal für das ganze Gerät (Settings › Privacy & Security): Ist er an, gilt er auf jedem verbundenen Server und auf jedem Server, sobald er sich verbindet. Eine stummgeschaltete Sitzung oder ein Server im Schlummer schickt gar nichts.

Eine Glocke für einen langen Befehl

Mit Long commands ring für einen Server (aus, bis du es einschaltest) oder Tell me when this finishes auf einem Tab gehen die erste Zeile des Befehls und der Name der Sitzung denselben Weg wie ein Ping — wenn ein Shell-Befehl, der eine Minute oder länger lief, zurückkommt. Es kommt als schlichter Hinweis ohne Absender an. Unter Titles only bleibt der Befehl auf dem Server, und die Glocke sagt nur, dass ein langer Befehl fertig ist. Beobachter ist tmux' eigener Rename-Hook und ein kleines Skript in ~/.kelter; deine Shell-Startdateien werden nicht verändert.

Deine Antworten berühren das Relay nie

Eine Antwort aus einer Mitteilung, von Siri oder aus der App wird über deine eigene SSH-Verbindung in die Sitzung des Agenten getippt, Gerät → Server. Das Relay sieht sie nicht.

Der Absender auf dem Banner

Ist die Sitzung auf deinem Server, gezeigt wie ein Kontakt (Name, ein Maschinenbild). Es ist dein Agent, keine Person, und das Bild sagt das.

Sitzungsnamen und Siri

Der Name, den ein Tab zeigt, ist der Name der tmux-Sitzung auf deinem Server. Die Namen gesperrter Sitzungen bekommt Siri auf diesem Gerät als Vokabular, damit sie sie aussprechen kann; für nichts anderes verlassen sie das Gerät.

Sonst nichts

Keine Analyse. Kein Absturzbericht an einen Dritten. Kein Tracking. Kein Konto. Keine KI eines Dritten: Der Agent läuft auf deinem eigenen Server, und Kelter gibt nichts an einen KI-Dienst weiter.

4. Was das Relay behält — und wie lange

Apple hält einen Push, bis das Gerät erreichbar ist. Deine Antworten, deine Zugangsdaten und dein Terminal erreichen das Relay nie.

5. Empfänger

Dein eigener Gesprächsserver steht nicht in dieser Liste: Er ist deine Maschine, nicht die eines Dritten.

Ein Push kann dabei die EU verlassen: Apple speichert personenbezogene Daten in der Regel bei Apple Inc. in den USA und stützt Übermittlungen aus dem EWR nach seiner eigenen Datenschutzerklärung auf die Standardvertragsklauseln der EU-Kommission (Art. 46 Abs. 2 lit. c DSGVO), nicht auf einen Angemessenheitsbeschluss. Der Rechner des Relays steht in Deutschland; auf diesem Weg verlässt nichts die EU.

6. Zweck und Rechtsgrundlage

Die Daten eines Pings werden nur verarbeitet, um die Mitteilung zuzustellen, die du für deinen Server eingerichtet hast — sonst für nichts. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO: die Erbringung des Dienstes, den du selbst eingeschaltet hast.

7. Deine Rechte

Du hast das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO). Schreib an office@abz.studio. Weil das Relay keine Nachrichten speichert und Kelter kein Konto führt, gibt es dort meist nichts, was sich einer Person zuordnen lässt — wir antworten trotzdem, innerhalb von zwei Werktagen.

Beschwerden nimmt die Österreichische Datenschutzbehörde entgegen: Barichgasse 40–42, 1030 Wien, dsb@dsb.gv.at, dsb.gv.at.

8. Abschalten und löschen

9. Änderungen

Diese Fassung gilt seit dem 25. September 2026. Ändert sich, was die App oder das Relay tut, ändert sich diese Seite — mit neuem Datum.


Privacy

For the Kelter app and for Kelter's relay, notify.kelter.app. One sentence per fact; nothing the app does not do.

Version of 25 September 2026 · Deutsche Fassung oben

1. Who is responsible

Ahmad Bakour Alzayat
Südbahnweg 69/36, 9201 Krumpendorf am Wörthersee, Austria
office@abz.studio

Kelter is made by one developer. There is no account, no user database and no third party that analyses data for Kelter.

2. What the app stores on your device

Kelter never reads your files or your terminal for any purpose but showing them to you.

3. What leaves the device, and when

Your terminal

Between this device and your server, over SSH, directly. Kelter runs no server in that path.

Your own conversation server

The app can be connected to your own conversation server, on your own machine. You connect it by pasting a door token, which the person who runs that server mints once and hands over; one token per device, kept in the device keychain. The messages, pictures and reports you exchange with your agents there are stored on that server — the one you run — and never on a server of Kelter's. Kelter's developer runs one such server for himself; the public address conv.kelter.app is his own server, reached over TLS.

Walk Mode and voice

Speech is turned into text on the device by Apple's recognition; on some older devices Apple does that on Apple's servers — Apple's path, not ours. No audio leaves the phone through Kelter. The switch Send logs to Suri is off until you switch it on; on, it streams the walk's own log — what it heard as text lengths and states, never audio, never keys — to your own conversation server.

Agent pings — only if you switch them on

Pings are off until you switch them on for a server. The first time on a device the app asks first, on one card with three facts:

What is sent
This device's push token, the server's and session's names, and what the agent last said or asks to run, up to 600 characters.
Where it goes
Your server → notify.kelter.app, Kelter's relay (run by its developer) → Apple's push service → this device.
What is kept
Nothing. The relay stores no message; it counts pings per token for a day and logs times, lengths and six characters of the token, never the words. Apple holds a push until the device is reachable.

Not now leaves the switch off; Allow is remembered on the device. When you switch pings on for a server, Kelter installs a small hook there. Kelter never sends the push token anywhere but to that server, over https://, into a file only your account on that server can read. When the agent finishes or needs you, its last message travels from your server through Kelter's relay to Apple to reach this device; nothing is stored on the relay.

Titles only

With Titles only on for a server, only the session's name travels from your server through Kelter's relay to Apple; the agent's message stays on the server until you open the app. For a newly added server this switch is on from the start — the agent's words travel through the relay only once you switch it off. The same switch exists once for the whole device (Settings › Privacy & Security): on, it is set on every connected server and on each server as it connects. A muted session, or a server on snooze, sends nothing at all.

A bell for a long command

With Long commands ring on for a server (off unless you switch it on), or Tell me when this finishes on a tab, the command's first line and the session's name travel the same way a ping does, when a shell command that ran a minute or more returns. It arrives as a plain alert with no sender. Under Titles only the command stays on the server and the bell says only that a long command finished. The observer is tmux's own rename hook and a small script in ~/.kelter; nothing is added to your shell's startup files.

Your replies never touch the relay

A reply from a notification, from Siri or from the app is typed into the agent's session over your own SSH connection, device → server. The relay does not see it.

The sender on the banner

Is the session on your server, shown as a contact would be (name, a machine picture). It is your agent, not a person, and the picture says so.

Session names and Siri

The name a tab shows is the tmux session's name on your server. Locked sessions' names are given to Siri on this device as vocabulary so it can say them; they leave the device for nothing else.

Nothing else

No analytics. No crash reporting to a third party. No tracking. No account. No third-party AI: the agent runs on your own server, and Kelter hands nothing to any AI service.

4. What the relay keeps, and for how long

Apple holds a push until the device is reachable. Your replies, your credentials and your terminal never reach the relay.

5. Recipients

Your own conversation server is not on this list: it is your machine, not a third party's.

A push can leave the EU on that path: Apple generally stores personal data with Apple Inc. in the United States and, by its own privacy policy, bases transfers out of the EEA on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), not on an adequacy decision. The relay's machine stands in Germany; nothing leaves the EU on that leg.

6. Purpose and legal basis

A ping's data is processed only to deliver the notification you set up for your server — for nothing else. The legal basis is Art. 6(1)(b) GDPR: performing the service you switched on yourself.

7. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). Write to office@abz.studio. Because the relay stores no messages and Kelter keeps no account, there is usually nothing there that can be tied to a person — we answer anyway, within two working days.

Complaints go to the Austrian data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at.

8. Switching off and deleting

9. Changes

This version applies from 25 September 2026. If what the app or the relay does changes, this page changes — with a new date.