Skip to content
Daniel Gietmann
← Privacy
App · Privacy

Dokio

Privacy policy for the iOS app Dokio.

This is a courtesy translation. The German version is legally binding.


Controller

Daniel Gietmann Kleingewerbe
Siegburger Straße 129 B
53229 Bonn, Germany

Email: hello@danielgtmn.com
Phone: 015679 288876

About Dokio

Native iOS client for Dokploy. Bundle ID: com.danielgtmn.dokio. Platform: iOS.

Summary

Dokio is a native iOS client for self-hosted Dokploy instances. The app has no backend server of its own at Gietmanic, no analytics, no advertising and no tracking. Connection data and API keys are stored on the device. Network requests go exclusively to the Dokploy servers configured by the user and to Apple (App Store / in-app purchases).

What data the app processes

CategoryContentStorage locationPurpose
Dokploy instances (metadata)Display name, base URL and technical identifier of the connected Dokploy servers; active instanceUserDefaults (local)Multi-instance management and restoration after an app restart
API keysDokploy API key per instance (x-api-key header sent to the configured host)iOS Keychain (service com.danielgtmn.dokio, this device only, after first unlock)Authentication with the Dokploy server operated by the user
Dashboard pins & UI statePinned apps, Compose stacks and databases; onboarding progress; optional alert settingsUserDefaults (local)Personalising the interface and the local notifications
Widget snapshotAggregated fleet status and most recently known errors (e.g. Live/Deploying/Error counters), without API keysApp Group (group.com.danielgtmn.dokio)Home Screen widget (fleet status, failed deploys)
Biometrics flagWhether the Face ID / Touch ID app lock is enabled (no biometric template)UserDefaults or the LocalAuthentication systemOptional protection of the app against unauthorised opening
In-app purchases (Supporter / Tips)Purchase status and transaction data via Apple StoreKit (Supporter, optional Tips)Apple App Store / StoreKit on the deviceOptional support for the developer; core features remain free
Operational data on Dokploy serversEverything the app loads or changes via the Dokploy API (projects, deployments, logs, env, backups, etc.) is stored on the user's serverThe user's Dokploy host (self-hosted)Ops function of the app; I do not operate this server

Data not collected

  • Name, email address or contact details by Gietmanic
  • Location, contacts, photos, microphone or camera
  • Health data or advertising ID
  • Usage analytics or crash reports sent automatically to Gietmanic
  • Account registration with Gietmanic

Legal bases

App function (connection to Dokploy, dashboard, deployments, logs, backups, widgets)

Art. 6(1)(b) GDPR (contract or use of the app) or Art. 6(1)(f) GDPR (legitimate interest in a functioning app)

Local deploy/service notifications

Art. 6(1)(a) GDPR (consent in the OS permission dialog)

Optional Face ID / Touch ID app lock

Art. 6(1)(a) GDPR (consent in the OS dialog); biometric characteristics remain in the Secure Enclave and are not read by the app

Optional in-app purchases via the App Store

Art. 6(1)(b) GDPR (purchase contract with Apple) and processing by Apple as an independent controller

Permissions

Notifications

Purpose: Local alerts for failed or successful deployments and for service errors/recovery (no push server of its own).

Revocation: Can be turned off for Dokio in the iOS Settings under “Notifications”; can also be turned off per alert type in the app settings.

Face ID / Touch ID

Purpose: Optional app lock so that API keys and the server overview are not visible without authentication.

Revocation: Can be turned off in the Dokio settings, or Face ID / Touch ID can be denied for this app in the iOS Settings.

Background App Refresh

Purpose: Occasional check of deploy/service status for local alerts, as long as the feature is enabled.

Revocation: In the iOS Settings under General → Background App Refresh, or by disabling the alerts in Dokio.

Technical services

Dokploy API (user's server)

HTTPS calls to {host}/api/{procedure} with the x-api-key header. There is no intermediate server of mine; you set the target address.

Apple StoreKit 2

Optional purchases: Supporter (one-time, non-consumable) and Tips (consumable). Payment processing and receipts are handled by Apple.

Home Screen widget

The widget extension reads a snapshot from the App Group group.com.danielgtmn.dokio. The widgets make no network requests of their own for the core status.

Local notifications & BGAppRefresh

UNUserNotificationCenter and Background App Refresh check the status via the configured Dokploy hosts — without a server of my own.

Recipients and processors

Dokploy server operated by the user

All API calls (including the API key in the header) go to the base URL stored in the app. The operator and controller of this processing is the respective server operator — typically the user themselves or their organisation.

Apple Inc.

App distribution via the App Store, StoreKit / in-app purchases, system notifications and biometric authentication. No third-party analytics or advertising SDKs in the app.

https://www.apple.com/legal/privacy/

No other third-party SDKs (Firebase, Sentry, RevenueCat, Google Analytics, etc.) are used.

No tracking and no advertising

Dokio does not use tracking, does not show advertising and does not transmit usage data to analytics services. The services used and the data they process are described in the sections above.

Retention and deletion

  • Instance metadata and UI settings: until deleted in the app, reset or uninstalled
  • API keys: until you remove the instance or delete the stored credentials; stored in the device keychain
  • Widget snapshot: overwritten when the app is used; removed on uninstall / removal of the App Group data
  • Data on Dokploy servers: retention depends on the configuration and policies of the respective server operator
  • IAP transactions: retained according to Apple account rules

How long data is stored and how you can remove it is described above for each type of data. Data on external servers is not deleted automatically when the app is uninstalled.

Transfers to third countries

I do not operate any server that receives Dokio usage data. If you set up a Dokploy host outside the EU, the data transfer is your responsibility. App Store and IAP processing by Apple may involve servers outside the EU; details are governed by Apple's privacy policy.

Children

Dokio is aimed at developers and operators of self-hosted infrastructure. The App Store age rating is 4+. No personal data of minors is knowingly collected.

Your data protection rights

Using the contact details above, you can exercise the following rights at any time:

  • Access to the data I hold about you and how it is processed (Art. 15 GDPR)
  • Rectification of inaccurate personal data (Art. 16 GDPR)
  • Erasure of the data I hold about you (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Objection to the processing of your data (Art. 21 GDPR)
  • Data portability, where you have consented to the processing (Art. 20 GDPR)

You can lodge a complaint with a supervisory authority at any time, e.g. the competent supervisory authority of the German federal state where you live. A list of the supervisory authorities is available at: www.bfdi.bund.de

Changes

I reserve the right to amend this privacy policy to comply with legal requirements or to reflect changes to the app. The current version is always available at this URL.


Last updated: 29.07.2026