Last updated: 19 July 2026 · App version: v1.0 and later
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the processing described in sections 2 and 3 is:
Stefan Venekamp
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach, Germany
Email: classtiles@icloud.com
No data protection officer has been appointed (no obligation to do so under Art. 37 GDPR, § 38 BDSG).
Note on roles: If a school uses ClassTiles in an official capacity, the school (or its governing body) is generally the controller for the processing of student data; if a teacher uses the app on their own responsibility and on their own devices, they are the controller themselves. The provider has no access to the data processed in the app (no provider server, no user account, no analytics, no access to your private iCloud) — there is therefore no processing on behalf of a controller, and no data processing agreement (DPA) is required. Should a school procurement process nevertheless formally require a DPA, the provider makes a precautionary template available.
2. Processing by the provider (support contact & public pages)
Contrary to the other sections of this policy, the provider (Stefan Venekamp) is the controller in two narrowly defined contexts: when you contact him by email via the “Send feedback” function, and for the operation of the public legal pages. In all other contexts the provider does not process any of your app data and has no access to it (see sections 1 and 7).
2.1 Support / feedback contact
- Purpose: handling and answering your support/feedback enquiries.
- Data processed: your sender email address, your message text, and a technical footer without personal reference (app version and build number, operating system version, device model identifier such as “iPad13,4” — no serial number, no device name).
- Legal basis: Art. 6(1)(b) GDPR (communication at your request within the user relationship) and Art. 6(1)(f) GDPR (legitimate interest in product improvement and user support).
- Recipients: the provider only; no disclosure to third parties. The support mailbox
classtiles@icloud.comis hosted with Apple (iCloud Mail); Apple processes the email communication as a service provider and may also process data in the USA (Apple bases third-country transfers on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses). - Retention: support emails are deleted once your enquiry has been conclusively dealt with, unless statutory retention periods apply (see section 9).
- Optional diagnostic report: to support an enquiry, you can generate a diagnostic report as a text file in the settings (Help → Diagnostics) and attach it to your message yourself. It contains technical information without clear names — in particular anonymous counts (e.g. the number of classes, students and grades), a history of such counts covering up to 90 days, app, system and device information, and — only if you actively enable this option — a log excerpt from the current app session. This log excerpt may contain technical identifiers (e.g. internal ID numbers); you can omit it using the toggle. You create the report yourself, can review it in full before sending, and it is transmitted only if you actively send it — there is no automatic upload.
2.2 Public legal pages (GitHub Pages)
- Purpose: public provision of the legal texts (privacy policy, legal notice, terms of use) and a support page at
https://classtiles.de/. - Data processed: technically necessary connection data collected when the pages are retrieved (in particular IP address, date/time, page requested, browser/operating system identifier), as recorded by the host when delivering the pages.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, functional operation). The pages set no cookies and embed no analytics, tracking or advertising services.
- Hosting: the pages are provided via GitHub Pages of GitHub, Inc. (88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA), a company of the Microsoft group. GitHub processes the connection data arising when the pages are retrieved as an independent controller in its capacity as host; the provider receives no server log files and has no access to the server-side logging. Details are governed by the GitHub Privacy Statement.
- Third-country transfer (USA): as GitHub is based in the USA, personal data (in particular the IP address) may be transferred to the USA. GitHub/Microsoft is certified under the EU-US Data Privacy Framework; the EU Standard Contractual Clauses apply in addition.
- Domain & DNS: The domain classtiles.de and its DNS resolution (name servers) are provided by netcup GmbH (Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany). When the site is accessed, technical DNS query data arises at netcup; the actual delivery of the page content continues to be handled by GitHub Pages (see above). netcup is based in Germany; no third-country transfer takes place in this respect.
The provider is not the controller for the student, grade and documentation data you record in the app (see section 1).
3. Scope
This policy applies to the iOS/iPadOS/macOS app ClassTiles (grade management) and to the associated legal pages published via GitHub Pages. It does not apply to linked third-party services (e.g. Apple iCloud, the Apple App Store, or a WebDAV server you configure yourself), for which their respective privacy provisions apply.
4. What data is processed?
ClassTiles stores data primarily locally on your device; there is no user account and no provider server. Depending on how you use it, the following are processed:
- Student data: first/last name, date of birth (optional), gender (selection), free-text notes, class membership, student number.
- Performance data: grades, assessments, grade trees.
- Educational documentation: observations, documentation entries, support/accommodation profiles, each including optional photo/file attachments.
- Organisational data: classes, subjects, school years, calendar and lesson planning (including image attachments and handwritten notes/drawings), seating and group plans, calendars you subscribe to (ICS).
- The teacher's own details: name, initials, email address (for timetable/PDF headers).
- Collaboration data (the “Class Tasks” feature): task title, description, priority, due date, status, and the display names of board members.
Deleted entries are temporarily held in the trash (a complete copy including grades) until you restore them or remove them permanently.
Special categories (Art. 9 GDPR): information on accommodations/special educational needs may constitute health data; photo attachments may also reveal special categories. For the legal basis, see section 5.
Obligation to provide data (Art. 13(2)(e) GDPR): there is neither a statutory nor a contractual obligation to provide personal data to the provider. Which student data is recorded in the app is decided solely by the responsible teacher or school within the scope of their duties.
ClassTiles contains no analytics, tracking or advertising tools and creates no user profiles.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Local management of grades/documentation by the teacher | For official use: Art. 6(1)(e) GDPR in conjunction with the applicable state school act / school data protection law; for use on one's own responsibility on one's own devices: Art. 6(1)(f) GDPR (legitimate interest in efficient lesson organisation). |
| Processing of support/accommodation data (Art. 9) | For official use: Art. 9(2)(g) GDPR in conjunction with the permissive provision of state school law (which varies by federal state). An explicit consent (Art. 9(2)(a) GDPR) may also be considered; within the school relationship it is only of limited viability as the sole basis, given the relationship of dependence. Whether and which Art. 9 data is recorded is decided solely by the responsible teacher/school; the app neither prescribes this nor actively requests such data. |
| Optional iCloud synchronisation/backup | Art. 6(1)(f) GDPR (legitimate interest: cross-device availability of your own data); synchronisation runs only after you actively enable it and can be switched off at any time. |
| Optional WebDAV backup to a server you choose | Art. 6(1)(f) GDPR (legitimate interest: self-determined backup of your own data); only if you actively set it up. |
| Retrieval of calendars you subscribe to (ICS) | Art. 6(1)(f) GDPR (legitimate interest: integration of your own calendar sources); only if you actively set it up. |
| The “Class Tasks” feature (sharing via a share link) | Art. 6(1)(f) GDPR (legitimate interest: collaboration among colleagues); only if you actively share. |
| Handling voluntary feedback/support enquiries by email | Art. 6(1)(b) or (f) GDPR (see section 2.1). |
6. Permissions (camera, photos, Face ID)
The app only requests system permissions when you use the respective function:
- Camera / photo library: only when you take or select a photo as an attachment (e.g. for a documentation entry or in lesson planning) — or when you scan a printed class list with the camera while setting up a class. Scanned pages are processed by on-device text recognition. The images become part of your app data (locally, and via iCloud/backups where applicable) and are not transmitted to the provider.
- Face ID / Touch ID / Optic ID (app lock): the biometric check is performed exclusively locally by the operating system; the app only receives the result (successful/unsuccessful). No biometric data is transmitted to the app or the provider.
7. Storage location, recipients and processors
With one exception, ClassTiles transmits no personal data to the provider and integrates no advertising/tracking services. The exception is the voluntary feedback/support contact: if you tap “Send feedback”, a pre-filled email opens in your own mail program. If you send it, the provider receives the data listed in section 2.1; nothing is transmitted without you actively sending it.
Depending on the functions you enable, your data may also be transmitted to the following recipients:
- Apple iCloud / CloudKit (in the EU/EEA: Apple Distribution International Ltd., Ireland) — if you enable iCloud synchronisation or iCloud backup. The data resides in your own iCloud account (private CloudKit database or your iCloud Drive); the provider has no access to it. Apple processes this data in the relationship between you and Apple in accordance with the iCloud Terms and Conditions and the Apple Privacy Policy; transport and server-side encryption are performed by Apple. Note for official use: whether student data may be stored in a private iCloud depends on the requirements of your federal state or school authority — clarify this before enabling synchronisation.
- A WebDAV server configured by you — if you enable WebDAV backup. ClassTiles does not prescribe a server; you choose the server, provider and credentials yourself (only
https://addresses are accepted; the password is stored in the device keychain). You are responsible for the data protection assessment of that server (location, provider, DPA where applicable). - Calendar sources you subscribe to (ICS) — on retrieval, the server you choose receives the usual technical connection data (IP address, time of retrieval); app data is not transmitted in the process.
- Persons holding the share link — if you use “Class Tasks”, you create a share link on the “anyone with the link” principle (as with Apple Notes/Reminders). Anyone in possession of this link can read and edit the shared task boards — including board/task titles and the display names of members. There is no person-specific access restriction; confidentiality depends solely on whom you pass the link to. You should therefore not enter any real names or sensitive data of students in shared boards. You can revoke a share at any time (the link then becomes invalid); content already synchronised may remain as a local copy on other participants' devices until it is removed there.
8. Transfer of data to third countries
If you use iCloud, Apple may also process personal data on servers outside the EU/EEA (in particular in the USA). Apple bases this transfer on the EU-US Data Privacy Framework (for correspondingly certified recipients) as well as on the EU Standard Contractual Clauses and supplementary measures (see the Apple Privacy Policy). If you use a WebDAV server or a calendar subscription, any third-country transfer depends on the location of the server you choose; you are responsible for this. The provider itself does not transfer any data to third countries, with the exception of the hosting of the public legal pages described in section 2.2 (GitHub, USA).
9. Retention period
Data remains stored until you delete it:
- You delete individual entries or complete student records in the app (Settings → Manage student data, or the trash).
- When the app is uninstalled, the local data is removed; data already synchronised to iCloud remains in your iCloud account until you delete it there.
- Backups on iCloud Drive or WebDAV persist until you delete them or the automatic retention limit takes effect (older automatic backups are removed periodically).
- Support emails are deleted once your enquiry has been conclusively dealt with, unless statutory retention periods apply.
- Connection data arising at GitHub as the host when the public legal pages are delivered is processed and deleted in accordance with GitHub's privacy provisions. The provider receives no server log files in this respect (see section 2.2).
For student data processed in an official capacity, the retention and deletion periods under the school law of your federal state additionally apply.
10. Your rights
Vis-à-vis the provider, you have the rights under Art. 15–21 GDPR for the processing described in section 2 (support correspondence, page logs): access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21, in particular against processing based on Art. 6(1)(f)). Please contact classtiles@icloud.com.
For the student, grade and documentation data recorded in the app, the addressee of data subject rights is the responsible teacher or school (section 1) — not the provider, who has no access to this data. So that the controllers can fulfil these rights, the app provides the corresponding functions:
- Access/data portability: complete export of individual or all student records as PDF (human-readable) and JSON (structured, commonly used, machine-readable within the meaning of Art. 20 GDPR); grade tables additionally as XLSX.
- Rectification: all entries are editable in the app.
- Erasure: individual entries, complete student records, or all data (including the trash).
You may withdraw any consent given at any time with effect for the future (Art. 7(3) GDPR), e.g. by switching off iCloud synchronisation.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority responsible for your place of residence or work or (for processing by the provider) the authority responsible for the provider (Art. 77 GDPR).
11. No automated decision-making
ClassTiles makes no automated individual decisions and carries out no profiling within the meaning of Art. 22 GDPR.
12. Changes to this policy
This privacy policy will be adapted when the app's functionality changes. The authoritative version is the current German version published at https://classtiles.de/datenschutz.
This English text is a convenience translation. The German version is the legally binding one.