Privacy Policy — getageless.app website
Last updated: June 2026 · The legally binding version is the German one at /de/datenschutz/.
Scope of this notice
This policy covers the marketing website getageless.app only — what happens when you load the page in your browser. The privacy policy for the Ageless iOS app itself (on-device AI processing, HealthKit data, optional iCloud sync via your private Apple account, App Store subscription handling) will be published as a separate document linked from the App Store listing once the app ships.
1. Service provider
The website getageless.app is offered under the DigitalFreedom brand. The data controller (Art. 4(7) GDPR) is:
Berger & Rosenstock GbR (trading as DigitalFreedom)
Dieselstr. 22e · 61231 Bad Nauheim · Germany
Authorized Representatives: Marcel R. G. Berger, Jasmin Rosenstock
VAT-ID: DE455096022
Data protection inquiries: data-protection@digitalfreedom.co.za
General inquiries: hello@digitalfreedom.co.za
2. GDPR as the global baseline
We adopt the EU General Data Protection Regulation (GDPR) as the strictest baseline and apply it as a global floor — every visitor, in every country, benefits from at least the GDPR-level protections set out here. We additionally respect any applicable local data-protection law (UK GDPR, Swiss FADP, CCPA/CPRA, PIPEDA, Australian Privacy Act, LGPD, APPI, PIPA, DPDP Act, POPIA, etc.); where it is more protective for you, the more protective standard applies.
3. What we collect on this website
3.1 Hosting (server log data)
The site is hosted on GitHub Pages, operated by GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you load a page, GitHub processes:
- IP address of the requesting device
- date and time of the request
- requested resource (path and file name)
- HTTP status code
- volume of data transferred
- browser user-agent string
- referrer URL (where transmitted)
Purpose: deliver the page and protect against abuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure website). Retention: per GitHub's policies. International transfer to the United States is covered by the EU-US Data Privacy Framework. See GitHub's General Privacy Statement.
3.2 Browser local storage
The site sets three keys in your browser's localStorage:
theme— your light/dark preference, only when you actively switch the theme.locale-explicit— set to1when you pick a locale from the language dropdown, so the first-visit redirect never overrides your choice.cookie-consent— your decision on the cookie banner (grantedordenied).
You can clear all three any time in your browser settings. Legal basis: § 25(2) No. 2 TTDSG (strictly necessary for the user-chosen function).
3.3 Waitlist signup
The waitlist form is operated by our email-service processor MailerLite, UAB (Paupio g. 46, LT-11341 Vilnius, Lithuania). When you submit your email address, the form posts it directly to MailerLite (account ID 2106245, form ID 189250313351333767), which stores it in our subscriber list. We never see the address before it reaches MailerLite — the form does not run through a server of ours.
We use the address solely to send you one notification email when Ageless ships on the App Store. No newsletter, no marketing, no profiling. You can unsubscribe at any time via the link in that email or by writing to data-protection@digitalfreedom.co.za.
Legal basis: Art. 6 (1) (a) GDPR (consent given by submitting the form). Retention: until the launch notification has been sent, then deleted from MailerLite within 30 days. MailerLite acts as a processor for us under a Data Processing Agreement pursuant to Art. 28 GDPR; their privacy notice is at mailerlite.com/legal/privacy-policy.
3.4 Google Analytics 4 with Consent Mode v2 (optional)
Provider (if active): Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland.
Google Analytics is only loaded if a measurement ID is configured on the site. Cookies and personalised measurement only run after you accept the cookie banner.
Before consent, only cookieless, aggregated pings are sent to Google — Consent Mode v2 defaults (ad_storage, ad_user_data,
ad_personalization, analytics_storage) are all set to denied before gtag.js loads.
Legal basis:
- Cookies and personalised measurement: Art. 6(1)(a) GDPR (consent) + § 25(1) TTDSG.
- Cookieless aggregated pings before consent: Art. 6(1)(f) GDPR (legitimate interest in aggregated reach measurement).
You can withdraw consent at any time via the "Cookie settings" link in the footer. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3.5 What we do not do on this website
- no marketing tracking pixels (Meta, LinkedIn, X)
- no third-party fonts (Geist is self-hosted from this domain — no connection to Google Fonts)
- no payment or checkout — the app will be sold via Apple's App Store once it ships
- no account creation or login on this website
- no audio, video or session-replay recording
4. Sub-processors used by this website
| Party | Role | Location |
|---|---|---|
| GitHub, Inc. | Static site hosting (GitHub Pages), DNS routing, abuse protection | USA (EU-US DPF) |
| MailerLite, UAB | Waitlist email collection and launch notification email | Lithuania (EU); may use US-based sub-processors under SCCs / EU-US DPF |
| Google Ireland Ltd. (Google Analytics) | Aggregated analytics, only if a measurement ID is configured; cookieless before consent | EEA, with onward transfer to Google LLC (USA) under EU-US DPF / SCCs |
The app-specific sub-processor list (Apple as App Store merchant of record and as iCloud private-database operator when the user enables sync) will be documented in the separate Ageless app privacy policy.
5. International data transfers
Transfers to the United States (GitHub, Google) are covered by the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR) and additionally by EU Standard Contractual Clauses where required. MailerLite is established in Lithuania (EU); for limited operational purposes it may rely on US-based sub-processors, which are likewise covered by SCCs and, where applicable, the EU-US Data Privacy Framework.
6. Your rights
Under GDPR you have the right to:
- access the personal data we hold about you (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing on grounds of legitimate interest (Art. 21 GDPR)
- withdraw consent at any time, with effect for the future (Art. 7(3) GDPR)
- lodge a complaint with a supervisory authority — competent in Hesse: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden
To exercise any of these rights, email data-protection@digitalfreedom.co.za.
7. Children's privacy
This website is not directed at children. We do not knowingly collect personal data from children under 16.
8. Changes to this policy
We may update this policy when the website's data flows change. The current version is always available at this URL with the effective date at the top.
9. Contact
DigitalFreedom — a brand of Berger & Rosenstock GbR
Dieselstr. 22e · 61231 Bad Nauheim · Germany
Data protection: data-protection@digitalfreedom.co.za
© 2025–2026 DigitalFreedom — Berger & Rosenstock GbR. All rights reserved.