← Back to WaveLoka

Legal

WaveLoka Privacy Policy

Last updated: 25 August 2026

This Privacy Policy applies to the WaveLoka Android app, including Android Auto, and to the waveloka.app website. It describes the active release state.

1. Controller

Igor Maderic – Softwareentwicklung
Belßstraße 48
12249 Berlin
Germany

Email: contact@waveloka.app

2. Principles

WaveLoka does not require a user account. The operator does not maintain its own server for user profiles, listening histories, or location histories. Much of the app data remains solely in the device's private storage. Website delivery, catalog retrieval, location features, radio playback, station artwork, privacy-choice management, advertising, and email communication nevertheless contact the providers and recipients described below.

Where processing is necessary to provide an app or website function you request, the legal basis is Article 6(1)(b) GDPR. For operational security, abuse prevention, and reliable delivery, we rely where applicable on Article 6(1)(f) GDPR; our legitimate interest is the secure and functional operation of WaveLoka. Processing required by law is based on Article 6(1)(c) GDPR. Consent-dependent processing is based on Article 6(1)(a) GDPR and, for storing or accessing information on your device, section 25(1) TDDDG. Strictly necessary local storage may be used without consent under section 25(2) TDDDG.

3. Website and static app catalog

The website and the app's https://waveloka.app/source/stations.json file are delivered as static GitHub Pages content. For every request, at least the IP address, date and time, requested address, transferred data volume, status, and browser or app/device information are technically transmitted to the delivery infrastructure. The app also sends a WaveLoka user agent and, where available, an If-None-Match value to update the catalog efficiently. GitHub expressly documents that a visitor's IP address is logged and stored for security purposes when a GitHub Pages site is visited.

Recipients are GitHub B.V., the Netherlands, and/or GitHub, Inc., United States, including infrastructure used by GitHub. The processing supports delivery, stability, and security under Article 6(1)(b) and (f) GDPR. GitHub determines retention according to purpose and legal obligations. See the GitHub Pages documentation and GitHub Privacy Statement.

We do not use our own web analytics, advertising technology, or marketing cookies on the website. Fonts are provided by the operating system; no remote font provider is contacted. Technically necessary processing by GitHub remains unaffected.

4. App data stored locally

The app stores locally in particular:

These data enable requested app functions and are processed under Article 6(1)(b) GDPR. They are not uploaded as a user profile to a WaveLoka server.

You can change favorites, delete user-created stations, and delete or replace the parking place in the app. Recent history is limited to the ten newest entries. All local app data can be removed using Android's “Clear storage/data” control or by uninstalling the app. Cached catalog data is replaced on update; station artwork is evicted under the image cache's storage limits and can be removed with the app cache.

Android cloud backup is disabled for WaveLoka. The backup rules also exclude app data from cloud backup and device-to-device transfer. Android notes that some manufacturers may treat device-to-device migration differently on Android 12 or later; WaveLoka applies the strongest available app-level exclusions but cannot absolutely guarantee manufacturer-specific behavior. See Android Auto Backup.

5. Location, Nearby, and parking place

Location access is optional. Without permission, a region can be selected manually and radio playback remains available. With approximate or precise Android location permission, WaveLoka uses the Google Play services Fused Location Provider to obtain a current or last available location. For Nearby, the position is converted into a country and state. Android's Geocoder is supplied by the device; its specific implementation may operate locally or use a network service run by the device or platform provider. In the latter case, coordinates and technical connection data may be sent to that provider. WaveLoka does not send GPS location to its own server and does not explicitly pass it to Google Mobile Ads.

“Find my car” requests a precise location where possible. Manual save stores one location locally. During an active Android Auto projection, the app updates a local position fix approximately every 30 seconds so that a recent parking place remains available after disconnect; a worse fix does not automatically replace a better one. The previous place is removed when a new projection starts. A stored place remains local until it is deleted, replaced, or app data is removed. If you choose “Navigate to car,” Android passes the coordinates to the map/navigation app you select; that provider's privacy policy governs its further processing.

The sole purpose is the requested regional or parking function, based on Article 6(1)(b) GDPR. Android permission can be withdrawn at any time in system settings. The Android Geocoder documentation explains that the implementation is device-dependent; the Fused Location documentation describes approximate and precise location handling.

6. Radio streams, station pages, and artwork

When you select a station, your device connects directly to the stream address operated by the station or its technical provider. Loading station artwork directly contacts the image server specified in the catalog or user data. Opening a station website loads it in the selected browser. Those recipients obtain technically necessary connection data such as IP address, time, requested URL, header/device information, and data volume. This will usually permit an approximate location to be inferred. Station artwork may be retained in memory and app caches.

WaveLoka does not determine the logging, content, advertising, or retention of these independent providers. Their terms and privacy notices also apply. The connection performs the playback or display you selected under Article 6(1)(b) GDPR. Providers retain information according to their own published criteria and legal duties.

HTTPS is preferred for curated streams where technically possible. Third-party streams and user-added streams or images may, however, remain available only over unencrypted HTTP. With HTTP, network operators or other intermediaries may see or alter the connection and transmitted content. Use only trusted stream and image addresses. Advertising embedded in a radio stream is supplied by the broadcaster and is not controlled by WaveLoka.

7. Google UMP, banner, and rewarded advertising

WaveLoka uses Google User Messaging Platform (UMP) to manage legally required privacy choices and Google Mobile Ads (AdMob) for:

These ads are not displayed on the Android Auto screen. Release audio pre-roll is disabled. Advertising inserted by a broadcaster into its own stream is unaffected.

At app launch, UMP requests current consent information and displays a privacy message where required. Until UMP reports canRequestAds(), WaveLoka does not initialize Google Mobile Ads and does not request banner or rewarded ads. If requests are not permitted, or if the update fails without a still-valid stored status, the core service remains usable without WaveLoka ads.

Depending on region, choices, and ad delivery, Google and the advertising technology providers identified in the UMP form may process in particular:

Purposes include consent management, ad delivery, selection and personalization, reach and performance measurement, reporting, and fraud, security, and abuse prevention. Google lists advertising, analytics, and fraud prevention as default Mobile Ads SDK purposes. WaveLoka does not include its own Analytics or Firebase integration and does not pass GPS coordinates in ad requests.

Recipients include Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google LLC, United States; their processors; and the ad partners named in the current UMP form. Google and some partners may act as independent controllers for their purposes. The exact partner list, purposes, and controls appear in the UMP form and may change with the AdMob configuration.

Where consent is legally required, device access and personal-data processing for advertising are based on section 25(1) TDDDG and Article 6(1)(a) GDPR. Strictly necessary consent management is covered by section 25(2) TDDDG; the related processing is based on Article 6(1)(c) and (f) GDPR. For non-personalized or restricted ads you select, Google and partners may use additional legal bases disclosed in the UMP form, including legitimate interests. You can object there where that option is offered.

Where UMP requires a privacy entry point for your region or previous choice, you can change or withdraw consent at any time for the future through “Ad privacy choices” in the app. This route must remain available for processing that requires consent. Withdrawal does not affect the lawfulness of earlier processing. You can also reset or delete the Android advertising ID in Android privacy settings.

Google processes data globally. For transfers to the United States and other third countries, Google identifies in particular adequacy decisions including the EU-U.S. Data Privacy Framework and Standard Contractual Clauses where required. Google and its partners determine retention according to data type, purpose, settings, security, and legal requirements; we do not set a separate fixed period for them. Details:

8. Email contact

When you email contact@waveloka.app or optout@waveloka.app, we process your sender and recipient address, header and delivery information, time, subject, message, attachments, and communication data created while handling the request.

The actual mailboxes are stored by IONOS SE. Incoming messages are additionally forwarded to a Gmail mailbox, and replies are sent using the WaveLoka addresses. Messages and metadata are therefore processed by both IONOS and Google and copies may exist in both systems. Recipients/processors are IONOS SE and, for Gmail, Google Ireland Limited and where applicable Google LLC and their subprocessors. The IONOS Privacy Policy and Google Privacy Policy also apply.

The legal basis is Article 6(1)(b) GDPR for pre-contractual, contractual, or requested matters, and otherwise Article 6(1)(f) GDPR for handling and documenting legitimate enquiries. Legally required retention is based on Article 6(1)(c) GDPR. We keep communications while needed to handle the matter, meet legal evidence duties, or establish, exercise, or defend legal claims, then delete them through regular mailbox maintenance. Provider backups and recipient copies may be removed later under their deletion and retention processes.

9. Recipients and international transfers at a glance

Apart from providers expressly identified above, only people and service providers receive data where needed for operation, communication, legal advice, or compliance with law. GitHub and Google may process data in the United States and other countries. For relevant transfers they identify, in particular, the EU-U.S. Data Privacy Framework and/or EU Standard Contractual Clauses. Independent stream, image, map, and navigation providers may be located anywhere; selecting such a service creates a direct connection to its location. Review the chosen provider's privacy notice.

10. Your rights

Subject to the GDPR, you have in particular rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), and complaint (Article 77). Where processing is based on Article 6(1)(e) or (f) GDPR, you may object under Article 21 for reasons arising from your particular situation. Consent may be withdrawn at any time for the future.

Send requests to contact@waveloka.app. We technically cannot remotely inspect or erase data held solely on your device; use the app and Android controls described above. For data processed by an independently responsible third party, you may also contact that provider directly.

You may complain to a data protection supervisory authority, in particular:

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61
10555 Berlin
Germany
Email: mailbox@datenschutz-berlin.de
Online complaint

11. Children

WaveLoka is intended for a general audience and is not specifically designed for children. There is no age-verification process, and we do not knowingly invite children to submit personal data. Minors should use the app, especially ad-supported functions and email contact, only in accordance with applicable age rules and, where required, with a parent or guardian's consent or supervision. If you believe a child has sent us personal data, please contact us so that we can review the matter and take any required action.

12. Security

We limit our own data holdings, separate local app data from public services, disable Android backup, and use encrypted connections for the WaveLoka catalog and Google advertising services. No transmission or storage system is risk-free. In particular, independent or user-added HTTP streams and HTTP images are not encrypted in transit. Do not put confidential information in stream addresses or station metadata.

13. Changes to this policy

We update this policy when functions, recipients, law, or processing change. The current date appears at the top. For material changes, we will provide an appropriate notice in the app or on the website and seek fresh consent where legally required. Continued use alone is not treated as consent to changed processing that requires consent.

The principal legal framework and disclosure duties are set out in the GDPR and section 25 TDDDG.