Skip to content
Seigut
BlogContactDeutschDEGet the app

Deutsche Fassung

Privacy policy for seigut.ch and the Seigut app

Version: 4 October 2026

Note: If you are under the age of 16, we require the consent of your parents or legal guardians. Please show this privacy policy to your parents so that they can read it and decide whether they wish to consent on your behalf. Parents may give such consent under both European data protection law (Art. 8(1) GDPR) and Swiss law (Art. 19(1) in conjunction with Art. 304(1) of the Swiss Civil Code). We rely on the assumption that all persons who consent to this privacy policy are at least 16 years old and thus capable of giving valid consent under the applicable data protection laws. We accept no responsibility in the event of a deliberate misrepresentation of age. Detailed information on this matter can be found in Section 11 of this privacy policy.

1. Introduction

Protecting your personal data is a matter of great importance to us, the operators of seigut. This Privacy Policy explains which personal data we collect via our website seigut.ch and our mobile application seigut, for what purposes we process it, to whom we may disclose it and how long we store it. We also inform you about your rights in relation to the processing of your data.

Controller for the data processing activities described in this Privacy Policy:

Daniele Catarci
Hohlstrasse 480
8048 Zurich
Switzerland
E-mail: daniele@seigut.ch

If you have any questions about data protection, you can contact us at any time via the e-mail address given above.

2. Legal Bases

We process your personal data in accordance with the Swiss Federal Act on Data Protection (FADP) [Bundesgesetz über den Datenschutz, DSG]. Where applicable, we also take into account the EU General Data Protection Regulation (GDPR) [Datenschutz Grundverordnung, DSGVO]. The grounds for our processing activities are, in particular, our legitimate interests (e.g. operation and security of the website and app, anonymised analysis to improve app content), legal obligations, or the performance of a contract with you (e.g. when using core functions of the app that require user data storage). Where specific functions are used (e.g. contact by e-mail, feedback form, chat), processing is carried out to handle your request or on the basis of your consent (mailing list, YouTube videos).

3. Definitions

To make this Privacy Policy more user friendly, we first explain the essential terms used below.

  • Website: seigut.ch
  • seigut.app: Address for shared challenges (see 7.4)
  • App: The mobile application “seigut”
  • FADP (DSG): Federal Act on Data Protection of 25 September 2020 (SR 235.1)

4. Territorial Scope

This Privacy Policy applies to all users of our services (website and app), regardless of their place of domicile or habitual residence (worldwide). By accepting the Privacy Policy, you agree to all provisions contained herein.

The FADP applies to all matters, because under Art. 3(1) FADP the decisive factor is solely the effect of the data processing and we always carry out the processing for purposes within Switzerland.

The EU GDPR applies only in the cases provided for by law. According to Art. 3(2) GDPR, this concerns the situation where you yourself have your domicile or habitual residence in the European Union. For persons resident in Switzerland, the GDPR does not apply.

5. Principles

We do not collect or process any particularly sensitive personal data within the meaning of Art. 5(c) FADP. All data collection and processing is carried out in good faith and fair dealing, and in accordance with the principle of proportionality. All data is destroyed or anonymised as soon as it is no longer required for our purposes.

6. Data Processing on the Website (seigut.ch)

6.1 Hosting and Log Files

Our website is a static website without user accounts. It is delivered via Cloudflare (Cloudflare Pages and the Cloudflare network). Every time a page is accessed, Cloudflare automatically processes technical data transmitted by your browser in order to deliver the page and to protect against attacks:

  • IP address of the requesting device
  • Date and time of access
  • Address of the page or file requested
  • Website from which the access was made (referrer URL)
  • Browser and operating system used (user agent)
  • Status code and amount of data transferred

We do not store any log files containing IP addresses ourselves and do not analyse such data. This processing is based on our legitimate interest in operating the website securely and reliably.

The provider is Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare operates a global network, so data may also be processed in the USA and other countries. Cloudflare is certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. In addition, Cloudflare's Data Processing Addendum applies, including the EU Commission's Standard Contractual Clauses, which are also used for data covered by the FADP. Further information: https://www.cloudflare.com/privacypolicy/

6.2 Audience Measurement (Cloudflare Web Analytics)

To understand which pages are read, we use Cloudflare Web Analytics. When a page is opened, a small Cloudflare script records the address visited, the referring page, loading times as well as browser, operating system, device type and country. According to Cloudflare, the service uses no cookies and no local storage in the browser and does not recognise individuals, whether by IP address, user agent or any other data. We only see aggregated figures, such as how often a page was viewed. This processing is based on our legitimate interest in improving the website. The provider is Cloudflare (see 6.1).

6.3 Contact by E-mail

You can contact us via the e-mail address provided. In this case, the personal data transmitted with the e-mail (e-mail address, information in the e-mail itself) will be stored. This data is processed solely for the purpose of handling your enquiry and communicating with you. The data will be deleted once your enquiry has been finally processed, provided there are no statutory retention obligations. Please note that e-mails may be transmitted unencrypted and could therefore be viewed by third parties.

6.4 Feedback Form (Google Forms)

For feedback on the app, we link to a Google Forms form (the address seigut.ch/feedback redirects there). If you fill in the form, your answers are stored on Google's servers. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; data may also be transferred to Google LLC in the USA, which is certified under the EU-U.S. and Swiss-U.S. Data Privacy Frameworks. Please only enter what is needed for your feedback. We use the answers solely to improve the app and delete them as soon as they are no longer needed for this purpose. Google's privacy policy: https://policies.google.com/privacy

6.5 Embedded Videos (YouTube)

Some blog articles show videos from YouTube. A video is only loaded once you click «Load video»; before that, no data is transferred to YouTube. After the click, it is loaded via youtube-nocookie.com in privacy-enhanced mode. YouTube (Google Ireland Limited, see 6.4) then receives, among other things, your IP address and the address of the page, and may use cookies or similar technologies during playback. This processing is based on your consent given by the click.

6.6 Mailing List (Release Notification)

Until October 2026, you could sign up on our former website with your e-mail address to be notified about the release of the Android app. The form was provided by our hosting provider at the time, Webflow, Inc. (USA); your e-mail address, the time of sign-up and your IP address were stored. New sign-ups are currently not possible. We use the e-mail addresses solely to inform you about the release; this processing is based on your consent. You can withdraw it at any time by replying to one of our e-mails or writing to daniele@seigut.ch. Your address will then be deleted immediately.

6.7 Cookies

Our website does not set any cookies itself. Cloudflare may set technically necessary cookies to protect against attacks and automated access. Only when you load a video (see 6.5) or open the feedback form (see 6.4) may the respective providers set their own cookies. You can configure your browser to inform you about cookies, to allow cookies only in individual cases or to block them in general, and to delete stored cookies.

7. Data Processing in the App (seigut)

7.1 Download of the App

The app is distributed via third-party app stores (e.g. Apple App Store, Google Play Store). Downloading may require prior registration with the respective app store and installation of the app store software. We have no influence on the collection, processing and use of personal data in connection with your registration and the provision of downloads in the app store concerned. The responsible entity in this regard is solely the operator of the respective app store.

7.2 AI Chat Function (ChatGPT API)

The app offers a chat function with an AI assistant. This function uses the application programming interface (API) of ChatGPT, a service of OpenAI (depending on location, OpenAI Ireland Ltd or OpenAI, L.L.C., USA). When you use the chat function, the texts you enter (your questions/prompts) are transmitted to OpenAI’s servers for processing. OpenAI processes this data to generate the AI assistant’s response.

Important: We store the contents of your chats (questions and answers) only locally on your device and only during the active chat session. After the session ends (e.g. by closing the chat window or the app), these chat contents are deleted from your device. We do not store chat logs on our own servers. Please note that OpenAI processes the data received via the API in accordance with its own privacy policies (e.g. to monitor misuse, possibly to improve its services, but not to train its models with API data unless explicitly agreed). We have concluded a Data Processing Addendum with OpenAI. As data are transferred to OpenAI (possibly to the USA), the transfer is based on appropriate safeguards (e.g. Standard Contractual Clauses). For deletion of data collected by OpenAI, please contact OpenAI directly. Further information can be found in OpenAI’s Privacy Policy: https://openai.com/policies/privacy-policy and API Data Usage Policies: https://openai.com/policies/api-data-usage-policies.

Do not enter sensitive, confidential or personal information that you do not wish to share with third parties.

7.3 User Account, Functional Data and Device Data

When you use the app, an anonymous user account is created during initial setup.

This account is assigned an automatically generated user ID. The access key (token) required to access this account is stored exclusively locally on your device. The following data are linked to your user ID and account and stored on our servers (hosted by Google Cloud Firestore). This storage is necessary to provide the core functions of the app (e.g. saving your progress, participation in challenges):

  • Data on challenges you have joined: information on which challenges you have accepted, their status (e.g. started, completed) and the time of relevant changes. Linking these data to your user ID and account is essential for the app’s functionality.

In addition, the following data may be collected:

  • Technical device data (e.g. device type, operating system version), insofar as necessary for functionality and troubleshooting.
  • Crash reports: In the event of app crashes, anonymised crash information (possibly via services such as Firebase Crashlytics by Google) may be sent to us to help us fix errors. These reports do not contain any of the above data linked to your account.

7.4 Sharing Challenges (seigut.app)

When you share a challenge in the app, we create an entry in Cloud Firestore containing the challenge, your user ID and the time, and generate a link of the form seigut.app/shared/…. The app of the person opening the link only uses the challenge; your user ID is not shown to them. The address seigut.app is provided via Firebase Hosting by Google; opening it involves technical data such as IP address, time and browser (comparable to 6.1). So that shared links keep working, these entries remain after you delete your account; they are then not linked to any other data about you. We will delete them on request.

8. Disclosure of Data to Third Parties and Processors

We disclose your personal data (such as your e-mail address from contact enquiries) to third parties only if this is necessary to fulfil your request, required by law, or necessary to enforce our rights. By means of this Privacy Policy, you also consent to our disclosing the data described under 7.3 and 7.4 that are linked to your user account, as well as technical data, as follows and/or to our using the following service providers as processors:

  • Cloudflare, Inc. (USA): Hosting and provision of the seigut.ch website and audience measurement (see 6.1 and 6.2).
  • Google (Google Ireland Limited, Ireland / Google LLC, USA): Hosting of the app backend database (Google Cloud Firestore) for the user data described under 7.3 and 7.4 (challenge data, preferences, etc., linked to your user ID); crash reports (Firebase Crashlytics, see 7.3); provision of the share links on seigut.app (Firebase Hosting, see 7.4); feedback form (Google Forms, see 6.4); embedded videos after your click (YouTube, see 6.5). The Cloud Firestore database is located in the Google Cloud region europe-west1 (Belgium).
  • OpenAI (OpenAI Ireland Ltd, Ireland / OpenAI, L.L.C., USA): Provision of the AI chat functionality via the ChatGPT API (processing of your chat inputs, see 7.2).
  • Apple / Google (App Stores): Distribution of the app (see 7.1).

We have concluded data processing agreements (DPAs) with these service providers insofar as they act as processors. For data transfers to countries without an adequate level of data protection (such as the USA), we rely on appropriate safeguards, in particular the EU Commission’s Standard Contractual Clauses (SCCs) (where applicable and offered by the service providers) or other mechanisms permitted under the new FADP / GDPR.

9. Data Security

We take appropriate technical and organisational security measures (TOMs) to protect your personal data (especially from contact enquiries) and the app data linked to your user account against loss, unauthorised access, misuse or alteration. These measures include, among others:

  • Encrypted data transmission (HTTPS/TLS).
  • Access restrictions and controls for access to our cloud infrastructure (Google Cloud Firestore).
  • Regular creation of backups.

Despite our efforts, absolute security in data transmission on the internet or electronic storage cannot be guaranteed.

10. Storage Periods

We store your personal data only for as long as is necessary to achieve the purposes for which it was collected or for as long as statutory retention obligations exist.

  • Website log files: We do not store any ourselves. Cloudflare retains technical data in accordance with its privacy policy (see 6.1).
  • Contact enquiries (e-mail): Until your enquiry has been finally processed, then deletion or archiving in accordance with statutory retention obligations (e.g. for business correspondence).
  • Mailing list: Until you withdraw your consent.
  • Feedback answers: Until they are no longer needed to improve the app.
  • Share entries (seigut.app): As long as the shared link is meant to work; we delete them on request (see 7.4).
  • App user account data (challenge data, preferences, user ID): Stored on our servers (Cloud Firestore) as long as your user account in the app is active. If you use the deletion function in the app to delete your account, all data linked to your account and user ID on our servers will also be deleted, unless statutory retention obligations prevent this. The access key stored locally on your device is removed when the app or its data are deleted.
  • AI chat data (local): Stored only temporarily on the device during the session and then deleted (see 7.2).
  • Anonymised crash reports: Stored as long as necessary for error analysis and improvement of the app.

11. Your Rights

Under the applicable data protection law, you have various rights regarding your personal data:

  • Right of access: You can request information about which personal data we process about you. This also includes the data linked to your user ID on our servers. The primary way to view and manage these app-specific data is the app itself. For additional access requests concerning server-side app data, we may need your user ID for identification.
  • Right to rectification: You can request the correction of inaccurate personal data.
  • Right to erasure: You can request the deletion of your personal data. For the data stored in the app and linked to your account (challenges, preferences, user ID) you can initiate deletion directly via the function provided in the app. This will delete the data on our servers. For other personal data (e.g. from e-mail contact) please contact us. We will delete your data unless legal reasons (e.g. retention obligations) prevent this. Instructions are available at seigut.ch/en/delete-data.
  • Right to restriction of processing: You can request that we restrict the processing of your data.
  • Right to object: You can object to the processing of your data if it is based on our legitimate interests.
  • Right to data portability: You have the right to receive certain personal data in a commonly used, machine-readable format.
  • Right to withdraw consent: If processing is based on your consent (mailing list, YouTube videos), you may withdraw this consent at any time with effect for the future.

Regarding app usage, you control the data linked to your account via the app settings and the deletion function.

To exercise your rights concerning your personal data (e.g. from e-mail contact or for extended access to app data), please contact the address stated in Section 1 (daniele@seigut.ch). Please note that we may require proof of your identity to verify your request and to identify you.

You also have the right to lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch

12. Data Protection for Minors

Our website and app are intended for persons aged 16 and over. We do not knowingly collect or process personal data from children under 16 years of age (an exception may be e-mail addresses if minors contact us themselves by e-mail or via the feedback form). If we nevertheless become aware that personal data of children under 16 years of age have been stored without the consent of their guardians, we will delete such data immediately. If you have any indications of such a case, please contact us immediately (see contact details above).

Our website and app are generally intended for individuals aged 16 and above. Consent to this privacy policy may only be given independently by persons who are at least 16 years old. This ensures that individuals providing consent understand the scope of their declaration and that we comply with Article 8(1) (GDPR).

If you are under the age of 16, we require the consent of your parents or legal guardians. Please show this privacy policy to your parents so that they can review it and decide whether they wish to consent on your behalf. Such consent may be given under both European data protection law (Art. 8(1) GDPR) and Swiss law (Art. 19(1) in conjunction with Art. 304(1) of the Swiss Civil Code).

We rely on the assumption that all persons who consent to this privacy policy are at least 16 years old and, therefore, legally capable of providing valid consent under the applicable data protection laws. We do not accept liability in the event of a deliberate misrepresentation of age.

We do not knowingly or intentionally collect or process personal data from individuals under the age of 16 without the required consent of their parents or legal guardians (an exception may apply in cases where minors contact us directly by e-mail or via the feedback form and, in doing so, provide personal data such as their e-mail address. In such cases, the data will be used solely for responding to the inquiry.) If we become aware that personal data of individuals under the age of 16 has been stored without the necessary parental consent, we will delete such data without delay. If you become aware of such a case, please contact us immediately (see contact details above).

13. Amendments to this Privacy Policy

We may amend this Privacy Policy at any time without prior notice. The current version published on our website and in the app shall apply. We will announce changes on the website or in the app.

Seigut

The sustainability app with short challenges and Robo as your coach. Made in Zurich.

App

  • Download on the App Store
  • Blog
  • Contact
  • Feedback

Legal

  • Legal notice
  • Privacy
  • Delete data

© 2026 Seigut

Deutsch