← Back to zwischen
Privacy Policy
Last updated: August 2026
The short version: zwischen does not require an account, does not sell any data, and uses cookieless, privacy-friendly analytics. The main data processed is your search queries (station names) to fetch train timetables.
Who we are
zwischen is a personal project by Aditya Aserkar. The app helps Deutschland-Ticket holders discover where regional trains take them. Contact: hello@zwischenapp.de. Legal notice: Impressum.
What data we collect
- Search queries — station names you type are sent to our backend (a Supabase Edge Function) to query the Deutsche Bahn API. Responses may be held in a short-lived server-side cache to reduce load; queries are not linked to you personally.
- Server logs & rate limiting — our hosting providers (Vercel for the frontend, Supabase for the backend) automatically log IP addresses and request timestamps as part of standard operation. The backend also holds IP addresses briefly in memory to limit abusive request rates. Logs are retained per the providers' policies (typically up to 30 days) and used solely for debugging and security.
- Usage analytics — we use Umami and Vercel Analytics, both cookieless and anonymised (pageviews, country-level location, anonymous interaction events such as which mode was selected). No cross-site tracking, no advertising identifiers.
- Error reports — Sentry captures technical error reports (stack trace, browser version, approximate location derived from IP) when something breaks, so we can fix it.
We do not collect: your name, email, precise location, or accounts of any kind. We do not use tracking cookies, Google Analytics, or Facebook Pixel.
Third-party services
- Deutsche Bahn Open Data API — station searches and timetable requests are forwarded to DB's API. See DB data terms.
- Supabase — runs our backend and database. Processes request metadata per their privacy policy.
- Vercel — hosts the frontend and provides anonymised analytics. See privacy policy.
- Umami — cookieless analytics. See privacy policy.
- Sentry — error monitoring. See privacy policy.
- Google Gemini — when you open an AI destination guide, the destination name (never your IP or identity — the request is made server-side) is sent to Google's Gemini API to generate the text. See Google privacy policy.
- Photon (Komoot) / OpenStreetMap Nominatim — station names are geocoded to map coordinates server-side. See OSM privacy policy.
- Carto / OpenStreetMap — map tiles are loaded from Carto's servers; your IP address is sent to them when the map loads. See Carto privacy policy.
- YouTube — the homepage background video is embedded from YouTube. YouTube may set cookies or process your IP when the video loads. See Google privacy policy.
- Ko-fi — the "Buy me a chai" button links to Ko-fi; their privacy policy applies only if you visit their site.
Legal basis (GDPR)
For users in the European Economic Area, we process data on the basis of legitimate interests (Article 6(1)(f) GDPR) — specifically, to provide the train search service you request, to understand aggregate usage, and to maintain server security. No personal data is processed for marketing or profiling purposes.
Your rights
Under GDPR you have the right to access, rectify, or erase personal data we hold about you, to object to processing, and to lodge a complaint with a supervisory authority. Since we do not store personal data beyond short-lived server logs, there is typically nothing to access or erase. For any requests, contact hello@zwischenapp.de.
Data retention
Search queries are not stored beyond a short-lived cache (minutes). Server access logs are retained for up to 30 days by our hosting providers, then automatically deleted. Anonymised analytics contain no personal data.
Children
zwischen is not directed at children under 16. We do not knowingly collect data from children.
Changes
If we make material changes to this policy we will update the date at the top of this page.
Contact
For privacy questions: hello@zwischenapp.de