Privacy
It's all about your privacy.
Sockpuppet exists, because many Agentic AI applications make extensive use of cloud hosted AI models. But sending your daily routine, everyday automations and the most personal things of your life to a distant data centre rightfully leaves a bad tase in your mouth, and comes with an unpleasant gut feel. Sockpuppet was build to eliminate that, it doesn't have servers, and it collects nothing.
The privacy policy of Sockpuppet shouldn't be a formal requirement, and Sockpuppet doesn't want to only have formal privacy. It's mission is to have real, honest and accountable privacy, security and safety guardrails. That's why the privacy policy isn't a lengthy legal document, but real questions and answers.
Privacy in the app
The following questions are around the privacy, security and safety of the app.
Where is my personal data stored?
Sockpuppet uses SwiftData, and hence Apple CloudKit, to store your entered data. All the data that you enter is stored in your personal iCloud account. Neither the developer, nor any other party, has access to that data. It is as protected as your photos, your notes and anything else you store in iCloud.
Is my usage of the app analysed?
No. There is no tracking or usage analyses in the Sockpuppet app.
The developer has no control over whether Apple itself performs any analytics within its operating systems iOS or macOS. You have the option to transmit anonymised crash details when the app terminates unexpectedly. Such crash reports cannot and will not contain personally identifyable information.
Who builds and controls the app?
Sockpuppet is build, and hence controlled, by Kammerath Technology UG, Im Johdorf 10, 53227 Bonn, Germany in the European Union. The business is run by me, Jan Kammerath, and I am also the sole owner, and the sole developer of Sockpuppet.
The company registration is HRB 25914 at the District Court of Bonn. The European tax identification number (VAT-ID) is DE342554917. Further legal information can be found in the Imprint on kammerath.com.
What data does Apple share about me?
Apple does not share any data about you with me.
The granularity of download and sales reports provided in the App Store Connect, the platform for developers to manage apps on, is limited to countries. I am not able to see if you buy, refund, install or uninstall Sockpuppet. I am not able to see any details of your usage, or link any reported data to your personal account.
How is the security of the builtin browser ensured?
The underlying component for the browser is WebKit for SwiftUI, which is the same technology that Safari uses. Security patches and updates are done by Apple through iOS and macOS updates, in the same way they are done for Safari.
Does t he app have access to my files, contacts, or messages?
No. The app only has access to the Internet through the builtin browser, to an isolated storage in iCloud that is dedicated to the app, and those files you open with it. Sockpuppet cannot access any other data than that which you have entered.
Where can the app be safely downloaded?
Sockpuppet is exclusively available on the Apple App Store for iPhone, iPad and macOS. It is not offered outside the App Store, and it is not possible to install it from any other source than the official Apple App Store. This ensures that the app will only operate in a Sandbox, which means iOS and macOS isolate the app from the rest of your system, and your personal data.
Where are my credentials stored?
Passwords, and any other confidential credentials that you mark on text input, are encrypted with a master key that is stored within your Apple Keychain. The encrypted data is securely stored within the automation inside your iCloud storage. The encryption algorithms are provided by Apple, and the implementation follows the latest Elliptic Curve Cryptography (ECC).
Privacy on this website
The following questions are around the privacy, security and safety of this website, and in communication through various means.
How do you use my data in communication?
You may contact me for support, inquiries, feature requests or anything related to Sockpuppet. This can be through any form of digital communication, such as email, social media, phone or text messages. The data that you share with me through communication may be subject to the privacy policy of the platform you are using. If you send me a direct message on Reddit for example, their privacy policy applies.
I will not maintain a customer record, or any file with customers, their contact details or other personally identifyable information. Further, I will not use such records for marketing purposes, unless you explicitly ask to be included in any form of communication on app updates.
All users of Sockpuppet are treated under the regulations of the EU GDPR (European Union General Data Protection Regulation), with the specific implementation of the DS-GVO (Datenschutzgrundverordnung) of the Federal Republic of Germany. Kammerath Technology UG, as the legal entity that publishes Sockpuppet, is legally bound to the German DS-GVO, which is the concrete German implementation of the EU GDPR.
This data is processed on the basis of Article 6 (1) (b) GDPR if your request is related to the fulfillment of a contract or is necessary to carry out pre-contractual measures. In all other cases, the processing is based on the legitimate interest in the effective processing of inquiries addressed (Art. 6 Para. 1 lit. f GDPR) or on your consent (Art. 6 Para. 1 lit. a GDPR) if this was queried; the consent can be revoked at any time.
Does this website use encryption?
For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this site uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the address line of the browser changes from "http://" to "https://" and by the lock symbol in your browser line. If SSL or TLS encryption is activated, the data that you transmit to us cannot be read by third parties.
Where is this website hosted?
This website is hosted externally. The personal data collected on this website is stored on the hoster's servers. This can primarily be IP addresses, contact requests, meta and communication data, contract data, contact data, names, website access and other data generated via a website. The external hosting takes place for the purpose of fulfilling the contract with our potential and existing customers (Art. 6 Para. 1 lit. b DSGVO) and in the interest of a secure, fast and efficient provision of our online offer by a professional provider (Art. 6 Para. 1 lit. f GDPR). If a corresponding consent was requested, the processing takes place exclusively on the basis of Art. 6 Para. 1 lit. a DSGVO and § 25 Para B. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time. Our host(s) will only process your data to the extent necessary to fulfill their performance obligations and follow our instructions in relation to this data.
We use the following host(s):
Duda Inc. DPO, Duda Legal Department, 577 College Avenue, Palo Alto, CA 94306
Do you use YouTube plugins?
This website includes videos from the YouTube website. The website operator is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland.
We use YouTube in the extended data protection mode. According to YouTube, this mode means that YouTube does not store any information about visitors to this website before they watch the video. However, the extended data protection mode does not necessarily exclude the transfer of data to YouTube partners. This is how YouTube establishes a connection to the Google DoubleClick network, regardless of whether you are watching a video.
As soon as you start a YouTube video on this website, a connection to the YouTube servers is established. The YouTube server is informed which of our pages you have visited. If you are logged into your YouTube account, you enable YouTube to assign your surfing behavior directly to your personal profile. You can prevent this by logging out of your YouTube account.
Furthermore, YouTube can save various cookies on your end device after starting a video or use comparable recognition technologies (e.g. device fingerprinting). In this way, YouTube can receive information about visitors to this website. This information is used, among other things, to collect video statistics, to improve user-friendliness and to prevent attempts at fraud.
If necessary, after the start of a YouTube video, further data processing operations can be triggered over which we have no influence.
YouTube is used in the interest of an attractive presentation of our online offers. This represents a legitimate interest within the meaning of Article 6 Paragraph 1 Letter f GDPR. If a corresponding consent has been requested, the processing takes place exclusively on the basis of Article 6 Paragraph 1 Letter a GDPR and Article 25 Paragraph 1 TTDSG, insofar as the consent includes the storage of cookies or access to information in the user's device (e.g. device fingerprinting) within the meaning of the TTDSG. The consent can be revoked at any time.
Still have a question?
Please get in touch if you still have a question around privacy, security and the safety guardrails. Privacy information on Sockpuppet should be extensive and exhaustive. There are no wrong questions, only unanswered ones.