SaQuraCertWatch

Privacy in SaQura CertWatch

iOS and Android app · Version 1.1 · Last updated 23 September 2026

In short: the app needs no account and no server of ours to do its work. Your addresses stay on the device; only on the iPhone can you switch on iCloud sync, which also places them in your own iCloud. What does leave it, leaves because you have an address checked — once, or regularly through the watch — because you have set up a webhook on the iPhone, or because you explicitly send an error report. This page covers the app on the iPhone and on the Android device; where the two differ, it says so.

What stays on the device

Checked and watched addresses, notes, tags, the grade history, the event log, your settings and the purchase state live in the app’s own storage on your device. We have no access to it. The app has no user account, so there is nothing you would need to have deleted at our end: delete the app from the device and all of this data is gone.

On the iPhone, like any app’s data, it is part of a device backup you have set up yourself (for example iCloud Backup). On the Android deviceyour watch list and your log are not included in Android’s automatic backup. They live on this device only, and even a move to a new phone does not carry them over.

Remove an address from the watch and it is no longer checked; the entry about the earlier check remains in the event log, because the log is deliberately gap-free (each entry is chained to the previous one by a checksum). The app is not directed at children; we knowingly collect no data from children.

iCloud sync (iPhone only) — only if you switch it on

iCloud sync is off out of the box. If you switch it on under “More → Settings”, the app stores your watch list — addresses, notes, tags and grade history — in the private iCloud database of your Apple Account (CloudKit container iCloud.jp.co.kyototech.certwatch) and syncs it with your devices that use the same Apple Account. That database belongs to your Apple Account and is operated by Apple under the terms of that account; we have no access to it and run no server for this data. The webhook address and the event log are not synced; they stay on the device. Switch it off and everything stays on the device only. Legal basis: your consent (Art. 6(1)(a) GDPR), withdrawn by switching it off. On the Android device there is no such sync; the watch list stays on that device only.

What goes out during a check

Checking a certificate means opening a connection. Your device connects to exactly the address you typed, the way a browser would. That server sees the connection as it sees any visit, including your IP address.

The app additionally asks about the certificate’s revocation status by calling the places the certificate itself names (the issuer’s OCSP responder or its revocation list). What travels there is the certificate’s serial number and identifiers of the issuer — nothing about you. Like any server you contact, that service sees your IP address as well as the name and version of the app and of the operating system, and it can infer that someone is interested in this certificate. As the standard foresees, these lookups are usually unencrypted.

The watch checks again by itself.Addresses in the watch are re-checked when you open the app (at most every 15 minutes) and — as long as you leave background checking switched on — in the background when the operating system gives the app time for it, no more often than every six hours. Each of these checks is a connection to that address and to the issuer’s revocation service, exactly like a check by hand. You can switch background checking off in Settings.

We are not part of any of this. No server of ours is in the path, and the addresses are never stored with us.

Sharing and export

Via “Share” and “Export” you pass a check result or the entire event log — including the addresses in it — to an app of your choice. What happens with it then is governed by that app.

What we do not do

No usage statistics, no analytics services, no advertising identifier, no advertising or analytics library. Nothing in the app can recognise you across sessions or across apps.

On the iPhone the app uses no third-party libraries. On the Android deviceit uses Android’s own building blocks (AndroidX, Jetpack Compose) and Google Play’s billing — none of which collects data about you for us.

Error reports — only when you say so

The switch “Send the error log to KyotoTech” is off out of the box. Even turned on, the app sends nothing by itself: you tap “Send the error log now”, you see the complete content in a preview, and only then does it go.

It contains the error lines from the event log, the device model, the operating system version (iOS or Android), the app version and a note whether addresses were redacted. Addresses are redacted by default (shop.example-company.com becomes shop.***.com); you can turn the redaction off on the same screen. If you do, the checked addresses appear in clear text — if you check addresses that are not your own, it is your decision whether to share them with us. Redaction covers the address field; free text of an error message is shown unchanged in the preview. Not included are your watch list, your other settings and any payment or transaction data; an error message from the purchase flow may appear as an error line.

The recipient is KyotoTech LLC. The report is used for debugging only, is not linked to your identity, and is deleted after 30 days at the latest; on request we delete it earlier — tell us when you sent it. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time for the future by turning the switch off.

The report is received on a server in Germany (Nuremberg) at Hetzner Online GmbH and stored there encrypted (AES-256-GCM); Hetzner acts as our processor and does not read the reports. We evaluate them from Japan; an adequacy decision of the European Commission exists for Japan (Decision (EU) 2019/419 of 23 January 2019), so no further safeguards are required. On receipt the usual technical access data arise (IP address, time, app and operating system version). We use them only to prevent abuse (at most 20 submissions per hour per installation) and to debug the service itself (Art. 6(1)(f) GDPR) and delete them after 14 days as a rule.

The transfer is TLS-encrypted, and the report is stored encrypted on our side. On the iPhoneone more step is added: so that nobody can push fake reports at us, the app identifies itself as a genuine installation using Apple’s App Attest when sending. For that, your iPhone creates a key once in its Secure Enclave, which Apple certifies for us; we store the public part together with the time of the last submission, so later reports from the same installation can be accepted without a new certification. This key is not an identifier of your person and is not linked to the content of the reports; we delete it after 90 days without use, or earlier on request. The legal basis is our legitimate interest in not accepting forged reports (Art. 6(1)(f) GDPR). Apple is involved in that step under Apple’s own privacy terms.

On the Android devicethe app sends the report together with the app’s identifier and version. Nobody is involved in that transfer but your device and our intake service.

Notifications

The reminders 30, 14, 7 and 1 day before expiry are local notifications. They are scheduled and fired on the device; there is no push service and no server that learns about them. The notification names the address concerned, so it is visible on the lock screen like any other notification. On Android 13 and later the app asks once for notification permission, as soon as the first address goes into the watch.

Widgets, Live Activities and Siri (iPhone only)

Widgets, the lock-screen countdown and the Siri shortcuts run on the device and read the same local data as the app. When you speak an address to Siri, Apple processes your voice under the terms of your Siri settings; the check itself runs in the app on your device.

Webhook alerts (CertWatch Pro, iPhone only) — only if you set one up

You can enter an https address of your own. When an alert fires, the app calls that address from your device with the address concerned and its grade. The recipient is the server you named, not us; the webhook address is not synced and is not transmitted to us.

Purchase and subscription

On the iPhone“Extend the watch” and the CertWatch Pro subscription (monthly or yearly, with a free trial where offered) are handled by Apple through the App Store (Apple Distribution International Ltd. or Apple Inc., depending on your region). We receive no payment data and no account data from Apple; Apple provides us with financial reports that contain no personal data. The app only remembers that a purchase or subscription is active, and restores it via the App Store when you reinstall.

On the Android device“Extend the watch” and CertWatch Pro are handled by Google Play. We receive no payment data. The app only remembers that a purchase was made.

Deleting your data

The addresses you check, your watch list, the event log and your settings are kept on your device alone, in the app’s private area. We hold no account and no copy of them; we can neither see them nor delete them for you.

You remove single addresses in the watch with “Remove”. You remove everything at once like this: on the iPhone by deleting the app from the iPhone — if you switched on iCloud sync, your watch list is also in the private iCloud database of your Apple Account, and switching the sync off leaves everything on the device only; on the Android deviceby uninstalling the app, or in the Android settings under Apps → SaQura CertWatch → Storage by clearing the app’s data, and there is no automatic backup into your Google account. Nothing of the app is left on the device afterwards.

We never send error reports on our own. The switch for error reports in the settings is off out of the box, you see the full content before every send, and you can turn the switch off again at any time. A report that was sent contains error lines from the log, the device model, the operating system version (iOS or Android) and the app version — no watch list, no purchase data — is not linked to your identity, and is deleted after 30 days at the latest. If you want a report you already sent deleted sooner, write to support@kyototech.co.jp; we need no identifier from you, only the approximate date.

Your rights

You have the rights of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), the right to withdraw consent at any time with effect for the future (Art. 7(3)), and the right to lodge a complaint with a data-protection supervisory authority (Art. 77), for example the authority where you live. Since we store nothing about you other than voluntary error reports, and those are not linked to your person, we can attribute an individual report only if you tell us the time of sending and the device model. You are under no obligation to provide anything; without error reports the app works exactly the same. No automated decision-making takes place.

Controller and representative in the EU

The controller is KyotoTech LLC (合同会社KyotoTech), Kyō-machi 2-237-202, Fushimi-ku, Kyoto 612-8083, Japan, represented by its managing director Christopher Batsch, e-mail support@kyototech.co.jp.

Our representative in the EU/EEA under Art. 27 GDPR, and in Switzerland under the Swiss FADP, is DataRep. You may contact DataRep in any EU/EEA member state, in the United Kingdom or in Switzerland at datarequest@datarep.com(please reference “KyotoTech; SaQura”) or via www.datarep.com/data-request. Postal requests must be addressed to “DataRep”.

Information under the Japanese Act on the Protection of Personal Information

As a Japanese company we are additionally subject to the Act on the Protection of Personal Information (個人情報保護法). Business operator: KyotoTech LLC, Kyō-machi 2-237-202, Fushimi-ku, Kyoto 612-8083, represented by Christopher Batsch. Purpose of use of error reports: investigating and fixing defects of the app. We do not provide the reports to third parties. Storage takes place with a service provider in Germany (Hetzner Online GmbH), i.e. in the EU, whose level of data protection the Personal Information Protection Commission has recognised as equivalent. Requests for disclosure, correction or deletion, and complaints, go to support@kyototech.co.jp; we respond without undue delay.

Reporting security vulnerabilities

If you suspect a security vulnerability in the app or in our error-report service, write to security@kyototech.co.jp. We confirm receipt and come back with an assessment; please do not publish details before a fix is available.

Contact: support@kyototech.co.jp · KyotoTech LLC, Kyō-machi 2-237-202, Fushimi-ku, Kyoto 612-8083, Japan.