Privacy Policy

Updated : 9 June 2026

This Privacy Policy explains how SELFCUT ACADEMY LLC (“Max Counter”, “we”, “us”) collects, uses, and protects your personal data when you use the Max Counter mobile application (the “App”) and the Max Counter cloud service. The App is the companion for the Max Counter IoT device — a network-connected LED matrix display that shows live data through configurable “widgets”.

1. Who we are (Data Controller)

The data controller responsible for your personal data is:

  • SELFCUT ACADEMY LLC
  • 6300 Riverside Plaza Ln Nw Ste 100, Pm b 1107, Los Alamos, NM 87544, USA
  • Email: support@themaxcounter.com

2. What data we collect

2.1 Account & identity

  • Email address and password (the password is transmitted over an encrypted connection and stored only in hashed form on our servers).
  • If you sign in with Google: your name, email address, and profile picture as provided by Google.
  • Email verification status and authentication provider.

2.2 Device & usage data

  • Devices you associate: device serial numbers, names, and configuration (brightness, volume, screen cycle, installed widgets, custom widgets).
  • Custom widget configurations you create.

2.3 Wi-Fi credentials (commissioning)

  • During device setup, the Wi-Fi network name and password you enter are sent directly to your device over Bluetooth so it can join your network. These credentials are not transmitted to or stored on our servers.

2.4 Location

  • The App requests precise location permission. On Android this is required by the operating system to scan for nearby Bluetooth devices during commissioning. Location is also used by certain location-based widgets (e.g. local weather) that you choose to install. We do not store your location on our servers — it is saved locally on your device as a widget parameter.

2.5 Camera

  • The App uses the camera only to scan QR codes during device setup. Camera images are processed on-device and are not stored or transmitted.

2.6 Notification access (Android — optional, off by default)

  • If you enable notification forwarding, the App uses Android’s notification-listener permission to read notifications from the apps you select and forward their app name, title, and text to your Max Counter device over your local network. We show a disclosure and ask for your consent before enabling this. This notification content is not stored on our servers and is not shared with any third party — it travels from your phone to your own device. You can disable it at any time in your phone’s settings or in the App.

2.7 Crash diagnostics (optional, off by default)

  • If — and only if — you opt in under Profile → Privacy → Share crash diagnostics, the App sends crash reports to our error-monitoring provider Sentry. These reports may include a screenshot of the screen at the time of the error, technical details (device model, OS version, app version, stack trace), and your account identifier, email, and name so we can correlate and resolve the issue. If you do not opt in, no crash data is sent. We use Sentry’s EU data region so this data is processed within the EU/EEA.

Under the GDPR we rely on the following legal bases (Art. 6(1)):

PurposeDataLegal basis
Create and manage your account; authenticate youAccount/identityContract (Art. 6(1)(b))
Provision and manage your devices and widgetsDevice, custom widgets, Wi-Fi credentialsContract (Art. 6(1)(b))
Bluetooth scanning during setupPrecise locationConsent (Art. 6(1)(a)) — granted via the OS permission prompt
Location-based widgets you installPrecise locationConsent (Art. 6(1)(a))
Forward notifications to your deviceNotification contentConsent (Art. 6(1)(a)) — via the in-app disclosure
Diagnose crashes and improve reliabilityCrash diagnostics (incl. screenshots, account email)Consent (Art. 6(1)(a)) — opt-in toggle
Secure the service, prevent abuseTechnical/usage dataLegitimate interests (Art. 6(1)(f))

Where we rely on consent, you may withdraw it at any time (see §7); this does not affect processing carried out before withdrawal.

4. Who we share data with

We do not sell your personal data. We share it only with:

  • Hetzner Online GmbH — operates the Max Counter cloud backend that stores your account and device data. Region: Germany (EU/EEA).
  • Sentry (Functional Software, Inc.) — crash diagnostics, only if you opt in, processed in Sentry’s EU data region.
  • Google — when you choose Google sign-in, to authenticate you.
  • Authorities — where required by law.

5. International data transfers

Where personal data is transferred outside the EU/EEA, we ensure an adequate level of protection through appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) or an adequacy decision. We have configured crash diagnostics (Sentry) to use the EU data region to minimise such transfers. When you use Google sign-in, your authentication data is processed by Google LLC (USA) under their own privacy terms and Standard Contractual Clauses.

6. Data retention

  • Account data: kept while your account is active and deleted (or anonymised) within 30 days of account deletion.
  • Device & custom widget data: kept while associated with your account.
  • Crash diagnostics: retained by Sentry for 90 days, then deleted.
  • Wi-Fi credentials / notification content / location: not retained on our servers.

7. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data (you can edit your profile in-app).
  • Erase your data — you can delete your account directly in the App (Profile → Delete account), which removes your account and associated data; or contact us.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time — disable notification forwarding, crash diagnostics, or location permission in the App or your device settings.

To exercise these rights, use the in-app controls or contact support@themaxcounter.com. We will respond within the time limits set by applicable law (one month under the GDPR).

8. EU/EEA users — additional information

  • Supervisory authority: You have the right to lodge a complaint with your national data protection authority — for example the CNIL (France), AEPD (Spain), CNPD (Portugal), or the authority in your country of residence — if you believe we have infringed data protection law.
  • Automated decision-making: We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
  • Consent-first design: Location-based features, notification forwarding, and crash diagnostics are all off by default and enabled only with your explicit consent.

9. Security

We protect your data with industry-standard measures, including encryption in transit (HTTPS with certificate pinning), encrypted on-device storage of authentication tokens, and least-privilege access controls.

10. Children

The App is not directed to children under 13 years old, and we do not knowingly collect their personal data.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date; material changes will be notified in-app or by email where appropriate.

12. Contact us

Questions or requests about this policy or your data:

  • SELFCUT ACADEMY LLC
  • Email: support@themaxcounter.com
  • Address: 6300 Riverside Plaza Ln Nw Ste 100, Pm b 1107, Los Alamos, NM 87544, USA