Privacy Policy
Updated : 13 September 2026
This Privacy Policy explains how SELFCUT ACADEMY LLC (“Max Counter”, “we”, “us”) collects, uses, and protects your personal data when you use the Max Counter mobile application (the “App”) and the Max Counter cloud service. The App is the companion for the Max Counter IoT device — a network-connected LED matrix display that shows live data through configurable “widgets”.
1. Who we are (Data Controller)
The data controller responsible for your personal data is:
- SELFCUT ACADEMY LLC
- 6300 Riverside Plaza Ln Nw Ste 100, Pm b 1107, Los Alamos, NM 87544, USA
- Email: support@themaxcounter.com
2. What data we collect
2.1 Account & identity
- Email address and password (the password is transmitted over an encrypted connection and stored only in hashed form on our servers).
- Name, entered at sign-up or provided by Google if you sign in with Google (along with your profile picture).
- Email verification status and authentication provider.
2.2 Linked accounts (optional)
- Some widgets show data from your third-party accounts (e.g. Instagram, TikTok). If you link such an account, we keep its identifier, name, picture, and the required access tokens, stored encrypted on our servers. You can unlink an account at any time from your profile.
2.3 Devices & widgets
- Devices you associate: serial numbers, names, configuration (brightness, volume, screen cycle), and the users you share them with.
- Technical operating data reported by the device: firmware version, uptime, Wi-Fi signal quality, last connection time.
- Installed and custom widgets: their configuration is saved on your phone and on your device.
- Widget parameters (e.g. city, YouTube channel, GitHub repository): saved on your device. When the device fetches the data to display, these parameters pass through our servers to query the relevant service (see §4). We do not retain them.
2.4 Commissioning (Wi-Fi & time zone)
- During device setup, the Wi-Fi network name and password you enter, and your phone’s time zone, are sent directly to your device over Bluetooth. They are not transmitted to or stored on our servers.
2.5 Location
- The App requests location permission. On older Android versions the operating system requires it to scan for nearby Bluetooth devices during commissioning.
- It is also used, only when you tap “use my location”, to fill in the city of a location-based widget (e.g. weather). Your approximate position is then sent to OpenStreetMap (Nominatim) to look up the matching city. When you search for a city, the text you type is sent to Open-Meteo. Only the city name is kept, on your device, as a widget parameter. We do not store your location on our servers.
2.6 Camera
- The App uses the camera only to scan QR codes during device setup. Camera images are processed on-device and are not stored or transmitted.
2.7 Notification forwarding (optional, off by default)
- Android: if you enable notification forwarding, the App uses Android’s notification-listener permission to read new notifications from the categories you select (calls, messages, email…) and send their title or text, along with the category, to your Max Counter device over Bluetooth. We show a disclosure and ask for your consent before enabling this.
- iOS: once paired over Bluetooth, your device reads the iPhone’s notifications (title and message) through Apple’s standard Bluetooth notification service (ANCS).
- In both cases notifications are shown on the device and then discarded. They are not stored, not sent to our servers, and not shared with any third party. You can turn this off at any time in your phone’s settings or in the App.
2.8 Messages to support
- If you contact us from the App (Profile → Send feedback), your message, your email address, and the App version are sent to us by email so we can reply.
2.9 Crash diagnostics (optional, off by default)
- If — and only if — you turn on Profile → Share crash diagnostics, the App sends crash reports to our provider Sentry (EU data region). These reports contain technical details (device model, OS and app version, stack trace, a screenshot with text and images masked) and a pseudonymous account identifier — never your email or name. If you do not turn this on, the App sends no crash data.
2.10 Technical logs
- Like any online service, our servers keep technical logs (including your IP address and the requests received) to operate and secure the service.
3. How we use your data and our legal bases
Under the GDPR we rely on the following legal bases (Art. 6(1)):
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account; authenticate you | Account/identity | Contract (Art. 6(1)(b)) |
| Provision and manage your devices and widgets | Device, widgets, parameters, Wi-Fi credentials | Contract (Art. 6(1)(b)) |
| Show data from your linked accounts | Linked accounts | Contract (Art. 6(1)(b)) — at your request |
| Bluetooth scanning during setup | Location | Consent (Art. 6(1)(a)) — granted via the OS permission prompt |
| Fill in a widget’s city | Approximate position | Consent (Art. 6(1)(a)) |
| Forward notifications to your device | Notification content | Consent (Art. 6(1)(a)) — via the in-app disclosure |
| Reply to your messages | Message, email | Legitimate interests (Art. 6(1)(f)) |
| Diagnose crashes and improve reliability | Crash diagnostics | Consent (Art. 6(1)(a)) — opt-in toggle |
| Secure the service, prevent abuse | Technical logs | Legitimate interests (Art. 6(1)(f)) |
Where we rely on consent, you may withdraw it at any time (see §7); this does not affect processing carried out before withdrawal.
4. Who we share data with
We do not sell your personal data. We share it only with:
- Hetzner Online GmbH — hosts the Max Counter cloud backend. Region: Germany (EU/EEA).
- Brevo — sends the service’s emails (verification, password reset, messages to support).
- Sentry (Functional Software, Inc.) — error monitoring, EU data region.
- Google — Google sign-in, if you choose it; downloading the App’s fonts (Google Fonts), which shares your IP address.
- Meta (Instagram) and TikTok — when you link those accounts.
- Widget data providers (e.g. Open-Meteo, YouTube, GitHub) — receive the widget’s parameters (city, channel, repository), without your identity.
- OpenStreetMap (Nominatim) — your approximate position, when you use “use my location”.
- LaMetric — icon catalog browsed while creating a custom widget, which receives your IP address.
- Authorities — where required by law.
5. International data transfers
Where personal data is transferred outside the EU/EEA, we ensure an adequate level of protection through appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or an adequacy decision. We host our servers and diagnostics in the EU to minimise such transfers. Some third-party services you choose to use (Google, Meta, TikTok, GitHub) may process data outside the EU under their own privacy terms.
6. Data retention
- Account: kept while your account is active. On deletion it is erased immediately together with linked accounts (whose access is revoked), and disappears from our backups within 35 days at most.
- Devices: on account deletion they are unlinked and reset.
- Widgets and their parameters: kept on your phone and device until you remove them or reset the device.
- Messages to support: kept as long as needed to handle your request.
- Crash diagnostics: retained by Sentry for 90 days, then deleted.
- Technical logs: kept for a limited period, for security purposes.
- Wi-Fi credentials / notification content / location: not retained on our servers.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data (you can edit your profile in-app).
- Erase your data — you can delete your account directly in the App (Profile → Delete my account), which removes your account and associated data; or contact us. You can also delete some data without deleting your account (linked accounts, devices, shares, widgets…). All options are described on the Delete your account page.
- Restrict or object to certain processing.
- Data portability — receive your data in a structured, machine-readable format.
- Withdraw consent at any time — disable notification forwarding, crash diagnostics, or location permission in the App or your device settings.
To exercise these rights, use the in-app controls or contact support@themaxcounter.com. We will respond within the time limits set by applicable law (one month under the GDPR).
8. EU/EEA users — additional information
- Supervisory authority: You have the right to lodge a complaint with your national data protection authority — for example the CNIL (France), AEPD (Spain), CNPD (Portugal), or the authority in your country of residence — if you believe we have infringed data protection law.
- Automated decision-making: We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
- Consent-first design: Location, notification forwarding, and crash diagnostics are all off by default and enabled only with your explicit consent.
9. Security
We protect your data with industry-standard measures, including encryption in transit (HTTPS with certificate pinning), encrypted on-device storage of authentication tokens, encryption of linked-account tokens on our servers, and least-privilege access controls.
10. Children
The App is not directed to children under 13 years old, or under the minimum age required in your country to consent to data processing on their own (for example 15 in France). We do not knowingly collect personal data from such children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date; material changes will be notified in-app or by email where appropriate.
12. Contact us
Questions or requests about this policy or your data:
- SELFCUT ACADEMY LLC
- Email: support@themaxcounter.com
- Address: 6300 Riverside Plaza Ln Nw Ste 100, Pm b 1107, Los Alamos, NM 87544, USA