Wake From Far · iOS + Android
Privacy policy
The German version is authoritative. This notice describes the Wake From Far app (also WakeFromFar) release candidates for version 1.0: iOS bundle com.wakefromfar.iosclient and Android package com.wakefromfar.wolrelay.
1. Controller and contact
Maximilian BlücherAhornring 54
38553 Wasbüttel
Deutschland
[email protected]
The person named above is responsible for app distribution, support, and processing determined by BluecherLab. The general website privacy policy additionally applies to delivery of this web page.
2. Self-hosted operating model and roles
Wake From Far does not provide a central BluecherLab service for device, wake, or activity data. The app connects to an HTTPS address selected by the user or their administrator. That backend is operated independently, for example on a private home network.
The operator of the selected backend determines its user accounts, purposes, access rights, logging, retention, location, and deletion. The operator is independently responsible for that processing under data-protection law. Users should direct access, correction, or deletion requests concerning backend data to their administrator. BluecherLab cannot access that data unless the operator actively sends it.
3. Data on the mobile device
Both apps locally store the selected backend address, authentication token, a randomly generated installation ID, theme and language choices, and onboarding acknowledgement. Depending on the platform, notification identifiers and additional feature markers are also stored. The password is used only for sign-in and is not stored persistently.
On Android, the token, backend address, installation ID, and security markers are protected with Android Keystore and EncryptedSharedPreferences; other settings remain in private app storage. Android backups are disabled for the entire app. Markers for administrator activity already shown, the background-notification setting, and Pro-unlock status may also be stored.
On iPhone, the authentication token, installation ID, and App Attest key identifier and status are stored in the iOS Keychain. The backend address, last username, theme, language, onboarding status, and—after an administrator enables notifications—the APNs device token are stored in UserDefaults inside the private app container. Signing out removes the authentication token; the remaining local settings and security identifiers remain for later use. iOS may handle app data through its user-controlled device and backup features.
4. Transfers to the selected backend
Depending on use, the app sends the selected backend: backend username and password at sign-in, then the authentication token and random installation ID; assigned devices and their status; favourite and sort settings; wake requests; optional shutdown requests with a voluntary note; and administrator activity and its handling status. For App Attest, the iPhone app may also send the app and operating-system versions, an App Attest key identifier, and cryptographic attestation or assertion data. If iPhone administrator notifications are enabled, the APNs device token, app bundle ID, and APNs environment are also sent.
This processing is required for sign-in, device display, the wake and shutdown workflow, role-dependent functions, abuse protection, and error handling. The release app blocks unencrypted HTTP connections; backend connections must use HTTPS. The app cannot be used as intended without a compatible backend and an account created there by its administrator.
5. Notifications and background checks
Android administrators can enable background alerts for new shutdown requests. WorkManager then checks the selected backend periodically and creates a local Android notification when it finds a new event. Wake From Far does not use a push-messaging service such as Firebase Cloud Messaging for this.
iPhone administrators can enable Apple push notifications for new shutdown requests. After iOS permission is granted, the app registers with Apple Push Notification service (APNs) and sends the registration data listed in section 4 to the selected backend. That backend uses APNs to send a generic notice that one or more shutdown requests need review; the voluntary note and device name are not included in the push text. Opening the notice leads to administrator activity in the app.
Whether a notice is visible on the lock screen depends on the device's notification and lock-screen settings. Notification permission can be denied or later withdrawn on Android or iOS; Android background checking can additionally be disabled in the app. The iPhone app deregisters the APNs installation from the selected backend when the associated administrator session ends or changes, provided the backend is reachable.
6. Distribution and payment
The Android app optionally offers the one-time product “Wake From Far Pro” (product ID wakefromfar_pro_unlock) through Google Play. The free version displays up to three assigned devices; Pro displays all assigned devices. It is not a subscription.
Google Play processes the purchasing account, payment data, product ID, purchase status, and purchase token under Google's privacy information. The app receives product, status, and token information from Google, acknowledges the purchase, and stores the unlock status locally. BluecherLab does not receive full payment-instrument details through the app, and purchase tokens are not sent to the self-hosted backend. Google acts independently for its payment and platform purposes.
The iPhone app is offered through the Apple App Store for a one-time purchase price. It contains no in-app purchase, subscription, Pro unlock, restore flow, or entitlement-sync flow. Apple processes the purchasing account, payment data, purchase status, and receipts under Apple's privacy information. During normal use, the iPhone app does not receive or transmit an App Store purchase receipt or purchase token to BluecherLab or the selected backend.
7. Platform-based abuse protection
The app contains technical support for Google Play Integrity as optional protection for backend sign-in. The first Play release has not yet been uploaded. The current release candidate has no Google Cloud project number configured, so the app requests no Integrity token. If this function is activated in a later Play version, Google processes app metadata, licence information, device and integrity signals, and a cryptographic request hash for abuse and fraud prevention. The hash does not contain the password or the content of a wake request.
The iPhone release app uses Apple App Attest when the service is supported on the device. Apple creates or validates an app- and installation-specific cryptographic key. The app sends the proofs listed in section 4 to the selected backend so it can verify a genuine Wake From Far installation and deter abuse. The password and contents of wake or shutdown requests are not included in the cryptographic client hash. If App Attest fails or is unsupported, the app attempts sign-in without App Attest proof; the selected backend decides whether to allow that.
8. No advertising or usage analytics
The app contains no advertising or advertising SDK. It uses no advertising ID and no analytics, crash-reporting, social, attribution, or tracking SDKs. BluecherLab does not sell app data or use it for advertising, profiling, or personalised prices.
9. Permissions
The release app uses internet access, notifications, network state, wake lock, device-boot reception, and Google Play Billing. Network state, wake lock, and device boot are used by Android's periodic work scheduling. The app uses no location, contacts, camera, microphone, storage/media, accessibility, device-administrator, exact-alarm, full-screen-intent, or foreground-service permission.
The iPhone release app requests only notification permission, and only in connection with administrator alerts. It has Push Notifications and App Attest entitlements but declares no background mode. It requests no access to location, contacts, photos, camera, microphone, Bluetooth, calendars, health data, or tracking.
10. Legal bases, recipients, and international transfers
Where BluecherLab processes personal data in connection with app distribution, purchase handling, or support, the legal basis depends on the activity: Article 6(1)(b) GDPR (contract and pre-contract communication), Article 6(1)(c) GDPR (commercial and tax obligations), or Article 6(1)(f) GDPR (security, abuse prevention, and effective support). The legitimate interests are secure and reliable app operation and prevention of fraudulent purchases. The operator determines the legal bases for the self-hosted backend.
Recipients may include the selected backend operator, Google as the Play and payment provider, Apple as the App Store, App Attest, and push-notification provider, and email or hosting providers when support is requested. Apple, Google, and technical providers may process data outside the European Economic Area and state that they use safeguards including adequacy decisions such as the EU-U.S. Data Privacy Framework or EU Standard Contractual Clauses. The selected backend's operator determines its location and transfers.
11. Retention and deletion
Local retention is described in section 3. The app does not create a copy of backend activity data in a BluecherLab cloud. The selected backend's operator determines retention and deletion there. An account cannot be created or deleted in the app; the backend administrator is responsible for this.
Apple and Google retain purchase, platform, and security data under their policies and legal obligations. Support enquiries that do not lead to a contract are generally deleted no later than twelve months after the last substantive contact. Contract and accounting records are retained only for applicable commercial and tax periods.
12. Data-subject rights and complaints
Where the statutory conditions are met, you have rights of access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and objection (Article 21). Requests concerning BluecherLab processing may be sent to [email protected]; contact the relevant operator for backend data.
You may lodge a complaint with a data-protection authority. The authority for the controller's location is in particular the State Commissioner for Data Protection of Lower Saxony. You may also contact the authority for your place of residence or work.
13. Objection
Where BluecherLab processing is based on Article 6(1)(f) GDPR, you may object at any time on grounds arising from your particular situation. Processing will then stop unless compelling legitimate grounds or the establishment, exercise, or defence of legal claims override the objection.
14. Minors, decisions, and changes
Wake From Far is intended for adult operators and users of self-hosted home-network infrastructure and is not designed for children. BluecherLab makes no solely automated decisions with legal or similarly significant effects and creates no user profiles.
This notice will be updated if app functions, recipients, or the legal position change materially. The current version remains available at this address.
Updated: 4 August 2026