1 · Who is responsible
Sirius Pelikan, trading as Pelikan Studios, Winkelackerweg 10, 5522 Tägerig, Switzerland. Contact: adflow@pelikan-studios.com. Full details in the imprint.
The service is operated from Switzerland and directed at Switzerland. It is available elsewhere, and where the GDPR applies to a user we observe it; the legal bases named below are given for that reason.
2 · Visiting the website
This site loads nothing from third-party servers. Fonts and scripts are served from this domain. There is no analytics, no tracking pixel, no social plugin and no advertising network on the website itself.
Our hosting provider writes standard web server logs: IP address, time, requested page, browser identification. We use them to keep the service running and to investigate attacks. They are kept for about one month and then deleted. Legal basis: legitimate interest in secure operation (Art. 6 (1) (f) GDPR).
Security log
Separately from the server logs we record security-relevant events: a rejected password, a failed signature, an unusual number of requests. These entries contain a shortened checksum of the IP address instead of the address itself, so they show that the same source came back without revealing who it was. They are deleted after 90 days.
Cookies
One single cookie, dia_session. It is set only on pages that carry a
form (the download page, the booking form and the account page), and it does two
things: it protects those forms against cross-site request forgery, and while you are
signed in to your account page it remembers that it is you. It contains no advertising
identifier, is not readable by JavaScript, is not sent to anyone else and is deleted
when you close the browser. It is technically necessary for the functions you asked
for, which is why there is no consent banner.
3 · Creating an account
An account is needed to be paid for displayed ads. Creating one asks for no name, no email address and no bank details. This is what is stored when you sign up:
| Data | Form | Why |
|---|---|---|
| ID | plain text, randomly generated | identifies your account |
| Passkey | Argon2id checksum only; the passkey itself is never stored | proves the account is yours |
| IP address | never stored, only a shortened HMAC | limits abuse and duplicate accounts |
| Device token | SHA-256 of a random value | lets the app fetch ads without sending the passkey again |
Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). Under Swiss law the processing follows from the agreement itself.
Bank details, once you add them
Only when you want to be paid do you enter the name on your bank account and your IBAN, on your account page. From then on, this is stored as well:
| Data | Form | Why |
|---|---|---|
| Name on your bank account | encrypted with AES-256-GCM, like the IBAN | a bank transfer carries a name as well as an account number, and one without a name is returned |
| IBAN | encrypted with AES-256-GCM; the key is stored outside the web directory | to pay out your share of the ad revenue |
| Country and last four digits of the IBAN | plain text | so you can recognise your own account |
| Checksum of the IBAN | HMAC-SHA256 | detects the same bank account on a second adflow account without reading the IBAN |
Legal basis: performance of a contract (Art. 6 (1) (b) GDPR). Without the IBAN we cannot pay you. Once saved, the bank details cannot be changed on the account page; you write to us instead. That way nobody who obtains your passkey can redirect a payout.
If you choose Stripe instead
You can be paid through Stripe instead of by bank transfer. Then we store no name and no IBAN. Stripe collects what it needs to pay you, such as your name, date of birth, address and bank details, on its own pages. For that it is a controller in its own right, and its privacy policy applies. We store only this:
| Data | Form | Why |
|---|---|---|
| Stripe account ID (acct_…) | plain text | to send your payouts to the right account |
| The country you chose | plain text | Stripe opens the account for that country |
| Whether Stripe can pay you yet | plain text, yes or no | so your account page shows whether Stripe still needs something from you |
When the account is opened we tell Stripe your adflow ID, so that a payout can be matched to it on both sides, and with each payout the amount and a reference. Legal basis as above.
Invitations
If you open an invite link, its code is kept in your session (not in a separate cookie) until you create an account. Your account then records which account invited you. The inviting account sees only how many of its invitations have qualified, never who you are. Each account gets its own invite code once it opens the account page. To check an invitation we compare checksums of the IP addresses used at sign-up, never the addresses themselves. Bonuses are recorded with amount, reason and date.
Legal basis: performance of a contract (Art. 6 (1) (b) GDPR), and our legitimate interest in preventing abuse of the bonus (Art. 6 (1) (f) GDPR).
Waiting list
adflow is starting with a limited number of accounts. If all places are taken when you try to sign up, no account is created and nothing is stored.
You may instead leave your email address so we can tell you when a place opens up. We then store the address (encrypted, plus a checksum so the same address is not listed twice without reading it), which edition you wanted, a checksum of your IP address, and the date. The address is used for that one message and for nothing else: no newsletter, no forwarding, no advertising. There is no automatic mailing — the message is written by hand.
The entry is deleted after 180 days at the latest, whether or not a place became free, and immediately if you ask us to. One line to adflow@pelikan-studios.com is enough.
Legal basis: your consent (Art. 6 (1) (a) GDPR), given by ticking the box on the form. You may withdraw it at any time with effect for the future.
4 · Displayed ads
Each ad the app displays is recorded: which spot, when it was delivered, when the app reported it, how long it stayed on screen, whether the button was clicked, and the amount credited. This record is the basis of your balance. Without it we could not prove what we owe you, and you could not check it.
These records contain no information about what you do on your computer. The app reads no documents, no browsing history and no other applications. On macOS it may ask for accessibility permission; that is used solely to measure how far the menu bar of the active app extends, so the overlay can move out of the way.
Clicking the button in an ad opens the advertiser's website in your browser. From that moment you are on their site and their privacy policy applies. We pass them nothing: no identifier, no referrer of yours, nothing that would let them recognise you. We only count that a click happened.
The figures on our home page (screens online, displays served, money paid to users, campaigns running) are totals across everyone. They contain nothing about any single person or device.
5 · Booking an advertisement
If you book a campaign, we store your email address (encrypted, plus a checksum so a repeat booking can be recognised without reading the address), a shortened checksum of your IP address, the wording, colour, image mark and target link of the ad, how many displays you bought, the price, and the state of the campaign. Your email address is used to send you the campaign code and to reach you about that campaign, not for newsletters.
Before a campaign goes live its text and link are checked automatically against a word list, and the result is recorded. Nothing about a booking is published except the ad itself; your email address is never shown to anyone.
Legal basis: performance of a contract (Art. 6 (1) (b) GDPR), and our legitimate interest in preventing fraud and abusive content (Art. 6 (1) (f) GDPR).
If you tick the optional case study box, we publish the results of the finished campaign on our case study page: brand and ad text, displays delivered, runtime, the price paid and the share that went to users. Your email address and campaign code are never shown. Legal basis: your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time by email; we then take it down within 7 days.
6 · Payment
Payments run through Stripe Payments Europe, Limited, The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland, together with its group companies including Stripe, Inc. in the United States.
Card details never reach our server. The payment form is Stripe's own page. We receive from Stripe only the payment reference, the amount, whether it succeeded, and later whether it was disputed or refunded. Stripe decides for itself what it collects to run and secure the payment, and is a controller in its own right for that; its privacy policy applies alongside this one.
7 · Getting paid out
To pay you, we send our bank a payment instruction containing your name, your IBAN, the amount and a reference. The bank needs this to make the transfer, and both banks involved keep the record under their own legal duties. This is the only situation in which your IBAN leaves our server, and it leaves it only for the bank.
If you chose Stripe, no IBAN is involved. We instruct Stripe to transfer the amount to your Stripe account, with a reference and your adflow ID, and Stripe pays it out to the bank account you gave Stripe.
8 · Bookkeeping
Payments received and paid out are business records. Swiss law requires us to keep them for ten years (Art. 958f Code of Obligations). That duty is stronger than a request to delete: a paid booking and a completed payout stay on file for ten years even after the account itself is gone.
9 · How long data is kept
- Abandoned sign-ups: accounts that never displayed a single ad and hold no balance are deleted automatically after 365 days.
- Active accounts are kept as long as the account exists. An account holding an unpaid balance is never deleted automatically.
- Unpaid bookings are removed automatically 24 hours after they were started.
- Waiting list: an email address left because all places were taken is deleted after 180 days, and at once on request.
- Paid bookings and payout records: ten years, see section 8.
- Server logs: about one month. Security log: 90 days. Abuse counters: 24 hours.
10 · Who else sees the data
Nobody, apart from the three parties each function needs:
| Who | What they get | Why |
|---|---|---|
| Metanet AG Zurich, Switzerland |
runs the server, so technically holds everything stored on it | hosting; bound by contract to process it only on our instructions |
| Stripe Ireland / United States |
advertisers' payment data and email address | to take card payments; see section 6 |
| Our bank Switzerland |
IBAN, amount and reference of a payout | to make the transfer; see section 7 |
| Stripe, if you are paid through it Ireland / United States |
your adflow ID, and amount and reference of each payout | to pay you; see sections 3 and 7 |
No data is passed to advertisers, and none is sold, rented or given to any advertising network. Beyond the three above, data is disclosed only where the law obliges us, for example to a court or a criminal authority acting within its powers.
11 · Data outside Switzerland
The server and the database are in Switzerland. Payment data reaches Ireland and the United States through Stripe, as described in section 6. Those transfers rest on the standard contractual clauses recognised by the Federal Data Protection and Information Commissioner and, for the United States, on the Swiss-U.S. Data Privacy Framework.
12 · Your rights
You may request information about your data, have it corrected or deleted, and receive it in a machine-readable form. For accounts in the EU/EEA the GDPR additionally grants the right to object and to restrict processing, and the right to lodge a complaint with a supervisory authority. In Switzerland the competent authority is the Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB).
One request by email to adflow@pelikan-studios.com is enough; we answer within 30 days. Two limits are worth knowing in advance: your passkey cannot be recovered, because we only hold a checksum of it, so we may have to ask you to prove in another way that the account is yours; and records covered by section 8 cannot be deleted before the ten years are up.
13 · Security
The connection is encrypted (HTTPS). The IBAN and every stored email address are encrypted at rest, the passkey is stored only as a checksum, and your IP address never reaches the database in readable form. The database and the encryption key are outside the publicly reachable directory. No system is beyond attack; if one ever reaches your data, we will tell you and the EDÖB as the law requires.
14 · Changes
Last updated: 14 September 2026. Changes are announced in the app itself: a notice appears in the bar the next time it checks in with our server, at the latest an hour after a change.