Controller
This notice covers wobinich.lol, its location API and the Android app “Wo bin ich?” (de.shroomlife.wobinich). The controller is:
Robin LehmannBahnhofstr. 98
71679 Asperg
Deutschland / Germany
robin@shroomlife.de
Website & hosting
The website and API run on a server at Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. IP addresses and connection information are processed to deliver and secure the service. The basis is Article 6(1)(f) GDPR: our legitimate interest in a reliable, secure service. Hetzner privacy notice.
This website uses no cookies, analytics, advertising trackers or external fonts. Icons, flags, images and scripts are served locally. It does not request your location; displayed places are examples. Language and motion settings last only for the current page visit.
Location in the app
Only pressing “Where am I?” requests a location through the operating system. System settings let you choose whether to allow access and with what precision. The app processes coordinates and reported accuracy. It has no location history, analytics SDKs, account or background location tracking.
Berlin districts and localities are resolved on your device using bundled official boundaries. The app then automatically requests online enrichment for streets and other place names: coordinates and your selected language are sent over HTTPS to wobinich.lol. The API rounds coordinates to five decimal places before querying Nominatim. Accuracy, your name, advertising IDs and device identifiers are not sent. Article 6(1)(b) GDPR is the basis for providing the location lookup you request.
Location permission is necessary for a fix. Without internet, coordinates and Berlin boundary matching remain available after a fix, but additional addresses do not. There is currently no separate offline-only switch. You can cancel a search and revoke permission in system settings. Cancellation cannot undo a request already transmitted. Depending on your system settings, operating-system location services may use their own providers, whose processing is described by the operating-system provider.
Nominatim address service
The OpenStreetMap Foundation’s public Nominatim service receives rounded coordinates and language. Requests originate from our server: we do not forward your device IP. The provider sees the server IP and a general Wobinich application identifier.
OSMF keeps its own service logs. Its policy identifies the UK and the Netherlands as storage locations for such data. Our cache lifetime does not apply there; the policy gives no specific deletion period for Nominatim requests. UK transfers are covered by an EU adequacy decision under Article 45 GDPR. See the OSMF privacy policy for details and contact information.
Storage & server logs
The app holds location results only in memory. Your app language is stored locally until changed or app data is cleared. Our API caches rounded coordinates, language and address responses in shared memory for 15 minutes plus at most 30 seconds for cleanup. The cache is limited to 2,048 entries, is not linked to accounts or device identifiers, and is erased on restart.
The Nginx Proxy Manager in front of the API keeps access logs containing IP address, time, HTTP method, hostname, requested path including any URL parameters, status, response size, user agent and, where supplied, referring page. Error logs support troubleshooting. The purposes are operation, troubleshooting and abuse prevention under Article 6(1)(f) GDPR. App coordinates are sent in the POST body, which is not included in the configured access log. The API itself disables access logging.
Proxy logs are configured for weekly rotation, retaining four access-log archives and ten error-log archives alongside the current files. With regular rotation this is approximately five and eleven weeks respectively. Empty files are not rotated, so older archives can remain longer. This configuration therefore does not guarantee deletion after a fixed number of calendar days.
Contact & external links
If you email us, we process your sender information and message to handle your enquiry: Article 6(1)(b) GDPR for service-related matters, otherwise Article 6(1)(f), our interest in responding to enquiries. Messages are retained for the necessary handling and documentation period, then deleted unless statutory retention duties apply.
Downloads and source code are hosted on GitHub. Opening these links sends connection information to GitHub, whose privacy statement applies there. This website does not embed GitHub trackers or widgets.
Your rights
Subject to applicable conditions, you may request access, correction, erasure, restriction and portability. You may object to processing based on legitimate interests on grounds relating to your situation (Article 21 GDPR). Any consent may be withdrawn for the future. There are no automated decisions with legal effects or profiling.
Contact robin@shroomlife.de. You may also complain to a supervisory authority, such as LfDI Baden-Württemberg. These rights arise under the GDPR.