Legal
Privacy Policy
Cropy.it is designed for data minimisation: the app works entirely locally on your device. We only process personal data when you visit the website, purchase the full version (via Stripe) and when you get in touch.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws as well as other data protection provisions is:
appoxi · Owner: Aleyna Sönmez
Kantorgärten 6
21354 Bleckede
Germany
Email: info@appoxi.com
Further details can be found in the Legal Notice.
2. Principle: local processing, no tracking
Cropy.it is a native screenshot and clipboard app for macOS and Windows. The central characteristic of the App is that it works 100 % locally on your device. There is no server, no user account, no tracking, no analytics and no cloud.
All content that you create or manage with Cropy.it is stored and processed exclusively locally on your device. No personal data is transmitted to the Provider or to third parties. You can find out more about this on the home page under "100 % local".
Processing of personal data by the Provider therefore essentially only takes place during the operation of this website (see Section 4), when you purchase the paid full version (see Section 5) and when you get in touch with us (see Section 7).
3. Data in the App (local, not transmitted)
When using Cropy.it, the following data may be created depending on the feature, which remains exclusively local on your device:
- Screenshots and screen captures including your edits (arrows, rectangles, ellipses, freehand, text, number badges, blur/pixelate).
- Clipboard history with copied texts and images, favourites and associated metadata (e.g. timestamp).
- Text from OCR / Live Text that you recognise and copy from images.
- App settings, e.g. global hotkeys and configuration.
This data is stored locally on the device. There is no transmission to the Provider, to a server or to a cloud. OCR / text recognition takes place on the device; no images are sent to external services for this purpose.
For the scrolling capture, Cropy.it uses the macOS Accessibility features to scroll the selected window — entirely locally, with no data transmission.
Since this processing takes place solely on your device and under your control, the Provider has no access to it and gains no knowledge of it. You retain full control at all times: you can delete entries in the history as well as remove stored screenshots and App data yourself, by deleting them or uninstalling the App.
Special protection of sensitive content
Cropy.it is designed to protect your privacy: content originating from password apps is automatically ignored and not added to the history. In addition, you can secure access to the history via Touch ID.
4. Website Hosting / Server Log Files
This website is operated by a hosting provider. When the website is accessed, information is automatically collected by the provider or its server and stored in what are known as server log files, which your browser transmits automatically. These are usually:
- the page / file accessed,
- date and time of access,
- volume of data transferred,
- notification of successful retrieval (HTTP status code),
- the browser type and its version used,
- the operating system used,
- referrer URL (the previously visited page),
- IP address.
This data is not merged with other data sources. The legal basis is Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and security of its website; for this purpose, the server log files must be collected. The log files are deleted after 14 days, unless they are exceptionally required for longer to investigate or avert security incidents.
This website is also delivered via an encrypted connection (SSL/TLS) to ensure the security of data transmission.
Hosting provider:
Hostinger International Ltd
Jonavos g. 60C
44192 Kaunas
Lithuania
A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with the hosting provider. The server log files are deleted after 14 days.
5. Purchase of the Full Version & Payment Processing
The App can be downloaded free of charge and trialled for 30 days. Personal data is only processed for the purchase of the paid full version.
a) Payment processing via Stripe
Payment is processed via Stripe. The seller and Merchant of Record is Link, LLC (a company of the Stripe group, 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA), which also handles invoicing and VAT processing (EU-OSS). During the payment process, the data you enter is processed, in particular your email address and payment data (e.g. credit card or other payment method data) as well as transaction- and device-related data for fraud prevention. The payment data is entered directly with Stripe/Link; the Provider does not receive any complete payment data (such as no credit card number). The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (fraud prevention). Since Link, LLC is based in the USA, this involves a transfer of data to a third country (USA); this is based on appropriate safeguards (including EU Standard Contractual Clauses). Details: stripe.com/de/privacy.
b) Licence management (Provider's server)
To provide and manage the licence, the Provider operates a licence server (lizenz.cropy.it). The following is processed there:
- your email address (for sending the licence key as well as for support and refunds),
- a pseudonymised device identifier (cryptographic hash), which serves exclusively to activate the licence and manage the trial period and does not allow any inference back to your device or identity,
- the licence key, the purchase or refund status, timestamps and the App version.
The legal basis is Art. 6(1)(b) GDPR (performance of the licence contract, including the prevention of multiple/abusive activations). The licence server is operated in Germany (Hetzner Online GmbH, Gunzenhausen); a data processing agreement pursuant to Art. 28 GDPR is in place with the operator. The data is stored for as long as this is necessary for licence management and is subsequently, or on request, deleted (Art. 17 GDPR). The licence email is sent via the service provider Resend; a data processing agreement is also in place for this.
c) Future sale via app stores
Should the App additionally be offered via an app store in future, the purchase and payment processing will in that respect be handled by the respective store operator as the processor; its privacy provisions then apply (Apple: apple.com/de/legal/privacy; Microsoft for the Windows version: privacy.microsoft.com).
Further information about the contract can be found in the Terms and Conditions.
6. Web analytics, cookies & local storage
In the app, Cropy.it deliberately refrains entirely from tracking and analytics:
- No analytics or tracking tools are used in the App.
- No usage profiles are created.
- No telemetry or usage data from the App is transmitted to the Provider.
- No user account is required, and there is no cloud synchronisation by the Provider.
Functional local storage: For settings such as your language and platform choice and your cookie decision, we store small values locally in your browser (localStorage). This is technically necessary, contains no personal data and is not transmitted to any server. The website sets no cookies for this.
Google Analytics 4 – only with your consent: On this website we use Google Analytics 4 (a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for anonymous audience measurement — only with your prior consent (Art. 6(1)(a) GDPR). On your first visit we ask you via a banner. Without your consent, Google Analytics is not loaded, no analytics cookies are set and no data is sent to Google.
If you consent, Google processes pseudonymised usage data (e.g. pages visited, approximate region, device/browser, time on page) to provide us with aggregated, anonymous statistics. Data may also be processed on Google servers in the USA. We use Google Consent Mode for consent and loading behaviour.
You can withdraw your consent at any time with effect for the future: Change cookie settings. Alternatively, delete the locally stored decision via your browser settings. Further information in Google's Privacy Policy.
7. Getting in Touch
If you contact the Provider by email or via the channels stated in the Legal Notice, the information you provide (e.g. your email address, your name and the content of your message) is processed for the purpose of handling your enquiry and in the event of follow-up questions. The legal basis is Art. 6(1)(b) GDPR insofar as your enquiry relates to the performance of a contract, and otherwise our legitimate interest in answering the enquiry pursuant to Art. 6(1)(f) GDPR.
Your information will be deleted as soon as the enquiry has been conclusively processed and no statutory retention obligations conflict with this.
8. Your Rights as a Data Subject
Within the scope of the statutory provisions, you have the following rights vis-à-vis the controller, insofar as personal data is processed:
- Access (Art. 15 GDPR) — whether and which data concerning you is processed;
- Rectification (Art. 16 GDPR) — correction of inaccurate data or completion of your data;
- Erasure (Art. 17 GDPR) — "right to be forgotten";
- Restriction of processing (Art. 18 GDPR);
- Objection to processing (Art. 21 GDPR);
- Data portability (Art. 20 GDPR) — receipt of your data in a structured, commonly used and machine-readable format.
Insofar as processing is based on your consent, you can withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected. To exercise your rights, an informal message to the details stated under "Contact" is sufficient.
9. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the member state of your residence, place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
A list of the supervisory authorities in Germany and their contact details can be found at: bfdi.bund.de.
10. Contact
If you have any questions about data protection or the exercise of your rights, you can reach the controller at:
appoxi · Owner: Aleyna Sönmez
Kantorgärten 6
21354 Bleckede
Email: info@appoxi.com
General questions about the App are also answered by our Help page.
11. Status and Amendments to this Privacy Policy
We reserve the right to adjust this Privacy Policy so that it always complies with current legal requirements or to implement changes to our services, e.g. upon the introduction of new features. The version in force at the time then applies to your next visit.
Last updated: July 2026
