Schorsch
Get the app

Privacy policy

Last updated: 8 October 2026 Schorsch («we», «us») is an app that gives dog owners in Switzerland a hazard radar for their walks: shooting noise, poison bait, blue-green algae and other hazards. Protecting your data matters to us. This privacy policy explains which data we collect, what we use it for and what rights you have. The German version of this policy is the authoritative one. 1. Controller Sebastian Waldburger Pfändwiesenstrasse 23a, 8152 Opfikon, Switzerland Email: hallo@schorsch-app.ch Website: https://schorsch-app.ch 2. Which data we collect With an account: Email address (for login and communication), username (freely chosen), password (stored encrypted, not visible to us), profile picture (optional), favourite shooting ranges (max. 10), notification settings, the language you chose (we also write notifications and emails to you in it), your last known location (see below), the notifications and daily check summaries sent to you, your device token for push notifications (if enabled), the app version installed on your device together with the operating system (Android or iOS), the time of your last sign-in and the time you last opened the app, as well as feedback messages including optional pictures (if you send any) and a note of which operating system and app version they were sent from. We need the app version to know which versions are still in use: only then can we judge whether a change is safe for everyone or whether we have to ask people to update first. The time of last opening belongs to the same question: an account nobody has used for weeks does not hold back a change. Of these two times we store only the latest value, so no history and no usage log, and it is updated at most once an hour. It allows no conclusions about your device model or your location. Community reports (if you create any): Location of the report (coordinates and a place description that we determine automatically and that you can adjust yourself before sending), type of report (poison bait, blue-green algae, other hazard, fireworks, livestock guardian dogs, active shooting), optional description (max. 500 characters), optional photo (for every type of report except «active shooting» and «dead animal», which take no photo at all). Community reports are publicly visible and linked to your username, including for people without an account, because reports can be shared. The same applies to your confirmations and rejections of other people's reports and to your feedback «hazard still there» and «hazard resolved»; for the latter we only store that your account replied, and we show no list of names. Dog waste bins (if you add any): Location of the bin (coordinates and a place description that you can adjust yourself), the type (dog waste bin, poo bag dispenser or both), an optional note (max. 200 characters) and an optional photo. If there is already a bin very close by and you confirm that it really is a second one, we store that confirmation with the entry. As with reports, the entry is publicly visible and linked to your username. Two things are different here, and both deliberately so: the entry does not expire, because a bin stands there permanently, and you can only withdraw it yourself during the first 24 hours. After that it belongs to the shared collection and only disappears once several people report that the bin no longer exists. Of these replies we only store that your account replied, and we show no list of names. You can complete dog waste bins from OpenStreetMap: correct the type, move the point up to 100 metres to the right spot, add a photo as long as there is none, write a note and adjust the place description. By doing so you take over the entry. It is then treated like one you added yourself, so it is shown publicly with your username, and it gets a place description determined from its coordinates if it has none or if you move it. An entry you added or took over can be edited in the same way for 24 hours, and during that time you can also replace or remove its photo; we then delete the previous photo. Internally we keep a log of every change (which account, what, previous and new value). This log is not public, serves to prevent abuse and is deleted after 90 days. Missing dog reports (if you create any): Dog's name, description, last known location, optional photo, contact details (phone and/or email). The dog, the description, the location and the photo are publicly visible. Your contact details are only visible to people signed in to Schorsch, which keeps your phone number and email address safe from address collectors. Location: We record your location only with your explicit consent and only while you are using the app, never in the background and never as a continuous movement profile. The canton and locality the app shows you are determined by our server (Supabase, Zurich) from your position using the official canton and locality boundaries from swisstopo, and so is the locality in the place description of a report. Your position is not stored for this. When you open the map, we store your last known position on our server (Supabase, Zurich), overwriting the previous one. We need it to be able to tell you at all that something is happening near you: hazard reports within 5 km (missing dogs 10 km), the warning about livestock guardian dogs as soon as you come within 3 km of a guarded pasture, the advance warning about shooting times nearby, the weather in the daily check and storm warnings. Without this stored position we could not warn you, because the server has to know who a new report concerns. We always store only the last known point, no history. You can have it deleted (see point 7); it is created anew the next time you open the map. You can prevent it being stored for good by revoking the app's location permission in your device settings. The map still works; you then only receive location-based warnings if you set a fixed home location (see next paragraph). Fixed home location (optional): under Profile → Notifications you can set a fixed place as your home location, by address, from your current location or with a tap on the map. We then store this point and its address, that is street and house number as far as one can be determined for the point, plus postcode and locality. All location-based warnings and the daily check follow the home location as long as we have no current position from you: if you open the map with location turned on, the position sent then applies for 12 hours, after which the home location applies again automatically. For that to work, we additionally store the time your position was last sent whenever a home location is set, again only the latest value. Without location the map also opens at the home location. You can remove it at any time (Profile → Notifications → «Back to automatic»), which also deletes that time; deleting your account deletes both as well. The location of a report you create is independent of this and publicly visible (see above). When signing in with Google: Email address and name from your Google profile. We get no access to your Google password, your contacts or any other Google data. When signing in with Apple (iPhone only): Email address from your Apple account. If you choose «Hide My Email», we receive an anonymous forwarding address from Apple instead of your real one (ending in @privaterelay.appleid.com), so we never see your real address and Apple forwards our emails to you. Apple does not send us a name; your username is therefore assigned automatically (something like «schorsch_a1b2c3d4») and can be changed in your profile at any time. We get no access to your Apple password or any other Apple data. Newsletter (with an account): If you turn on «News & offers» at the bottom of your profile in the app, we store your email address together with your account ID in a separate list, in order to occasionally send you news about the app and offers around dogs. If you signed in with Apple and «Hide My Email», we ask you at that point for an address you actually read and store that one instead of the forwarding address, only for the newsletter, your account stays unchanged. This is optional and separate from all other emails: without this consent you get no advertising. If you turn the switch off again, the entry is deleted immediately; the same happens if you delete your account. Every one of these emails also contains a note on how to unsubscribe. Support (optional, on schorsch-app.ch): If you support the further development of Schorsch, you pay on a Stripe payment page (see point 4). You enter your payment details there directly with Stripe; we do not see them and we store no amounts. From Stripe we receive your email address and the language of the payment page, in order to send you a thank-you email. During the payment you can answer two questions, both optional and independent of each other: whether we may name you in the app one day with a name of your choosing, and whether we may contact you again later. Only if you answer at least one of them with yes do we store your email address, the name you gave, your two answers and when and how often you supported us; otherwise we store none of it. You can withdraw both at any time, using the unsubscribe link in our emails to this list or with a message to hallo@schorsch-app.ch. Supporting us unlocks nothing in the app. Waiting list for Germany and Austria (no account, only on schorsch-app.ch): If you join the waiting list on that page, we store your email address, the country you chose (Germany or Austria), the language of the page, so that our emails reach you in it, and the time you signed up. We send you a confirmation email immediately; your sign-up only counts once you click the link in it. Without that confirmation we never write to you. The sole purpose is to notify you once, as soon as Schorsch is available in your country: the two countries launch one after the other, hence the question. We use this address for nothing else, in particular not for advertising, and we do not pass it on. Every email contains a link that deletes your address immediately and completely; you can also contact us at any time at hallo@schorsch-app.ch. At the latest six months after the launch in your country we delete the list completely. The legal basis is your consent (Art. 6(1)(a) GDPR for users from the EU); you can withdraw it at any time with effect for the future. 3. What we use your data for We use your data solely to run the app: login and identification, showing your favourites and your own reports, sending push and in-app notifications (only if you turned them on), working out from your last known location which warnings are relevant to you, translating texts written in another language into the language you chose, and improving the app based on feedback. We also check uploaded pictures and entered texts automatically for breaches of our community guidelines (violence, sexual content, insults); this includes the username you choose when registering, because it appears publicly on every report of yours. This protects everyone using the app and is a requirement of the App Store and Google Play. After saving, our server checks every new contribution a second time in the same way; a picture that is flagged is removed automatically, a text that is flagged is put to us for review. If you report someone else's content, we store who reported what, so that we can deal with the case. We do not use your data for advertising, tracking or profiling. We do not sell your data to third parties. 4. Where your data is stored Your data is stored with Supabase (server location: Zurich, Switzerland). The app and the website are delivered through Vercel (USA). Account, report and location data is not stored there; for the website's visitor statistics, aggregated access figures arise at Vercel (see point 6). For individual purposes we pass data to service providers that may process it outside Switzerland: Firebase Cloud Messaging (Google) for push notifications. What is transferred is a device token and the text of the notification. Google Cloud (Vision and Natural Language) for the automatic check of uploaded pictures and entered texts for inappropriate content. The picture or text in question is sent for the check and is not stored there permanently. Google Cloud Translation (Google) translates texts written in a language other than the one someone chose in the app: descriptions of reports and dog waste bins, breed, colour and distinguishing features of missing dogs, titles and texts of shooting dates, and the notes on pastures with livestock guardian dogs. The request is made by our server, not by your device, and only the text itself is sent, without username, location or photo. We store the translation with Supabase in Zurich so that the same text does not have to be translated over and over. It is deleted as soon as the original text is deleted or changed, and at the latest once nobody has read it for 30 days. For these texts we also store which language they are written in. On the website schorsch-app.ch we use the same service to translate the App Store reviews shown there into the language of the page; only the public review text is sent, without the author's name and without any information about visitors. Cloudflare (Cloudflare, Inc., USA) delivers the map image. As soon as you open the map, your app loads the map data directly from there. Your device sends its IP address and which section of the map it is requesting, which shows the area in which you are looking at the map. Your exact position is NOT sent: the blue dot is drawn on your device, and your stored position sits with Supabase in Zurich. Up to and including version 1.6.15 the map image came from CARTO (CARTO DB Inc., USA) instead of Cloudflare. As long as you use an older version of the app, that provider still applies to you. Nominatim, the address service of the OpenStreetMap Foundation (United Kingdom), determines addresses. Your app queries it directly, in two cases: for the address search in a report form or for the fixed home location, with the text you typed; and for «My location» or a tap on the map, with the chosen point, in order to show the address for it. Your device also sends its IP address. The Foundation stores such data in the United Kingdom and in the Netherlands. In older versions of the app, location detection also queries Nominatim, with your exact position, in order to determine canton and locality. As long as you use such a version, that still applies to you. Open-Meteo (OpenMeteo GmbH, Bürglen UR, Switzerland) provides the weather data. The weather on the home screen is requested by your app directly from there, sending your exact position and your device's IP address. According to its own statement, Open-Meteo keeps its server logs for at most 90 days. The weather in the daily check and the storm warnings, by contrast, are requested by our server, for a point rounded to about one kilometre or coarser and without your IP address. Apple («Sign in with Apple»), if you sign in that way on an iPhone. Apple confirms your sign-in to us and sends your email address or, with «Hide My Email», an anonymous forwarding address. Resend for sending emails: registration confirmation, password reset, confirmation of an email change, the acknowledgement of your feedback, the newsletter if you turned it on, the thank-you email after a support payment, and internal notifications to us when feedback arrives or content is reported. What is transferred is your email address and the content of the message in question. So that nobody receives the same bulk email twice, we record which of these emails we sent to which address. When signing in with Google, data is processed by Google Ireland Limited, when signing in with Apple by Apple Distribution International Ltd. (Ireland). Stripe (Stripe Payments Europe Ltd., Ireland) handles voluntary support payments on schorsch-app.ch. What you enter on the payment page, that is your email address and payment details, is processed by Stripe under its own privacy policy. The payment receipt, and with a monthly contribution the later receipts too, are sent to you by Stripe itself, in the language in which you paid. How long we keep things: your account and the data connected to it (profile, favourites, settings) stay as long as you have the account. Everything else is cleaned up automatically, every day. Hazard reports are deleted for good 14 days after they expire, together with their photos; by that time they have long since disappeared from the map. Your notification history and your daily checks are also deleted after 14 days. Operating logs of our automatic data retrievals are kept for 90 days; they contain no data about individual people. We keep the list of supporters until you unsubscribe; it is not tied to an account and therefore remains even if you delete your account. Dog waste bins that have been added are an exception: they describe no incident but a bin that stands there permanently, and they therefore remain. A photo of a dog waste bin stays as long as the entry exists and is deleted as soon as the entry is removed. If you delete your account, such an entry is not deleted but anonymised: your username and the photos you added, both to your own entries and to existing ones, are removed, while the location itself stays on the map anonymously, because other people rely on it. One exception to all of this is moderation: if content was reported and reviewed by us, the note about it remains, even when the content itself has long been deleted. Without it we could not spot repeated breaches of the rules. 5. Photos in reports Photos you upload with reports are stored in Supabase Storage (Zurich) and are publicly retrievable as long as the report is active. Deleting your report also removes the photo irrevocably. The same applies to your profile picture. Pictures you attach to feedback are the only ones that are not public: they are retrievable only by us. That is deliberate, because a feedback screenshot often shows things you did not want to publish. Before uploading, we check every picture and every text automatically for inappropriate content (see point 4). If something is flagged, it is not stored in the first place. 6. Cookies, local storage and visitor statistics In the app we use no tracking cookies and no advertising tracking, on the website with a single exception (the campaign page, see below). We use your device's local storage (localStorage/sessionStorage) for: your login session, personal settings (language, map filters, noise radius per shooting range), the detected canton, and markers for what you have already seen (introduction tour, «What's new?», last opened notifications). This data stays on your device and is not transferred to us. On the website schorsch-app.ch we measure with Vercel Web Analytics how often which page is called up. Recorded are the page called up, the referring page, country, operating system, browser and device type. This happens without cookies and without access to your device's storage. To be able to tell returning visits from new ones, an irreversible check value that changes daily is formed from the connection data, which makes permanent or cross-site recognition impossible; your IP address is not stored. So we see how many people visit the site, but not who. If you pick a language yourself from the language menu on schorsch-app.ch, the website remembers that choice for a year in a cookie called SCHORSCH_LANG. It contains nothing but the code of the language, for example «en», and is not evaluated. Without a choice of your own, the website follows your browser's language setting and sets no cookie. One single page is excepted from this: the campaign page schorsch-app.ch/start, to which our ads on Facebook and Instagram lead. Only there the Meta Pixel is embedded, a measuring tool by Meta (Meta Platforms Ireland Ltd., Ireland, and Meta Platforms, Inc., USA). When you open this page, your browser loads a script from Meta. In doing so Meta learns your IP address, details about browser and device, the address of the page including the identifier of the ad that brought you there, that you opened the page, and whether you tapped the button to the App Store or to Google Play. For this Meta sets cookies in your browser (_fbp and _fbc, each valid for 90 days) and can connect these details with your Facebook or Instagram account, if you have one. We use the measurement to see which ads lead to someone getting Schorsch, and so that Meta shows our ads rather to people who are interested in them. We ourselves only see added-up numbers, no individual persons, and we pass neither your name nor your email address on to Meta. Meta also processes the data in the USA and additionally uses it under its own rules for its own purposes; details are in Meta's privacy policy (facebook.com/privacy/policy). You can prevent this: in the settings of your Facebook or Instagram account you decide under ad preferences whether Meta may use information from partners for advertising, and you can block or delete cookies in your browser. On all other pages of schorsch-app.ch and in the app the Meta Pixel is not embedded. In the app itself no such measurement takes place. If you share a report from the app, the link carries a note that it comes from the app, which type of report was shared and in which language the preview should appear. It contains nothing about you and is only counted if the recipient opens the website. 7. Your rights You have the right to information, correction, deletion and data export at any time. You can do much of it yourself: you delete your account in the app under Profile → Edit profile → Danger zone → Delete account. You withdraw individual reports with «Withdraw report» (the photo belonging to it is deleted too), you remove favourites with the star and your profile picture under Profile → Edit profile. If you want individual data deleted without giving up your account, for example your stored location, your notification history or feedback you sent, write to us at support@schorsch-app.ch. Please write from the address your account is registered with; otherwise we will ask, to be on the safe side. You will find step-by-step instructions and a complete list of what is deleted and what is kept at schorsch-app.ch/konto-loeschen. For all other data protection matters you can reach us at hallo@schorsch-app.ch. We answer within 30 days. 8. Data security Passwords are stored encrypted. The connection to the app is encrypted (HTTPS/TLS). Access to the database is protected by row level security, so everyone sees and edits only their own data. 9. Note on community content Community reports (poison bait, blue-green algae, other hazards, fireworks, livestock guardian dogs, active shooting, missing dog reports) are unverified tips from users. Schorsch accepts no liability for their accuracy or completeness. Which contributions are allowed is set out in our community guidelines at schorsch-app.ch/richtlinien. If content breaches them, we remove it; in the case of repeated breaches we can restrict the ability to create contributions or block the account. 10. Official data from third parties The shooting data shown comes from publicly accessible sources (sat.admin.ch, schützenportal.ch, OpenStreetMap and individual public club calendars). The grazing zones with livestock guardian dogs come from herdenschutzschweiz.ch (AGRIDEA). The basic stock of dog waste bins comes from OpenStreetMap and is available under the Open Database License (© OpenStreetMap contributors, ODbL). The canton and locality boundaries with which we determine canton and locality come from swisstopo (© swisstopo). This is public information, not personal data; the contact details of the farmers that this source supplies with it we deliberately do not take over. 11. Changes We can adapt this privacy policy at any time. You will always find the current version at schorsch-app.ch/datenschutz. This policy also exists in German, French and Italian; the German version is the authoritative one. 12. Contact If you have questions about data protection: hallo@schorsch-app.ch