Privacy policy
Last updated: 15 August 2026
Legal basis: revised Federal Act on Data Protection (revFADP, Switzerland).
In short
ELMOF works offline. Everything you enter is stored in a database on your device. There is no ELMOF server holding your accounts, and the provider has no access to them. The app requires no user account and no sign-in. There is no advertising, no analytics tool, no third-party crash service and no advertising identifier. Whatever leaves the device is always something you trigger yourself.
What data is stored in the app
Your company details including IBAN and QR-IBAN. Customers and suppliers with name, address, e-mail, telephone and contact person. Bookings, invoices, quotes, VAT and liquidity figures. Projects, working hours and work reports. Employees with name, address, e-mail, salary and hourly and billing rates. Receipt photos, company logo, report photos and signatures. Appointments you enter in the app (not your device calendar). If you use private mode: your private accounts, transactions and savings goals.
Particularly sensitive personal data
For payroll and the salary certificate, ELMOF stores your employees' AHV number (Swiss social security number) and date of birth, along with personnel number, start and end date of employment, withholding tax rate and occupational pension (BVG) details. This is particularly sensitive personal data. It stays on your device and only travels where you send it – for example on a payslip or a salary certificate that you pass on. Before sending, check who will receive the document.
Receipt photos and scanning
Receipts and invoices often carry names and details of third parties. Text recognition when scanning a receipt runs entirely on your device, as does scanning the QR connection code. No image is uploaded.
Bank statement import (camt.053)
You download the file yourself from your e-banking and import it into the app. No data flows to the provider or to third parties.
Permissions
ELMOF only asks for what a function genuinely needs: the camera for receipt photos and the QR connection code, the photo library for the company logo and receipts, Face ID or a fingerprint as an alternative to the PIN, and on Android additionally permission for reminders on the device. ELMOF does not request your location and does not access your contacts, your device calendar or the microphone.
When data leaves the device
Never on its own. There are eight ways out, and every single one needs you to press a button. As long as you use none of them, everything stays on the device.
1. Backup
You create a backup file and store it wherever you like. The file is encrypted; the key is derived from your backup code. If the code is lost, not even the provider can open the file.
2. Sending, sharing or saving a PDF
Invoices, quotes, work reports, payslips, salary certificates and reports for your accountant are produced as PDF files. Where they go is your choice in your device's share menu. Bear in mind that these documents contain personal data.
3. Team sync
Only if you work with employees and switch the sync on yourself – it is off by default. It runs only when you press “Sync now”; there is no background sync and none when the app starts. ELMOF encrypts the data and the attachments on your device before they leave, and then places them in a folder in your own cloud storage – iCloud, OneDrive, Google Drive or another folder that your cloud app synchronises anyway. That storage belongs to you, not to the provider. Anyone looking at the folder sees the folder name ELMOF-Team and file names made of letters and digits from which nothing can be read off, but no readable contents and no readable receipt photos. The terms of your cloud provider apply in addition.
4. Signing in to Google Drive
If you choose “Sign in with Google”, Google's sign-in page opens. Sign-in data goes to accounts.google.com and googleapis.com, and ELMOF receives the e-mail address of your Google account together with an access permission. That permission covers only files ELMOF creates itself – the app cannot see the rest of your Google Drive. The access credentials stay on your device.
5. Signing in to OneDrive
The same applies to “Sign in with OneDrive”: sign-in runs via login.microsoftonline.com. ELMOF then retrieves the e-mail address of your Microsoft account from graph.microsoft.com and shows it to you, so you can see which account is connected. The permission covers only ELMOF's own folder. The access credentials stay on your device.
6. Feedback and crash report
Both create a prepared e-mail in your device's mail app. You see the whole text before you send it; nothing goes out without your action. A feedback message contains your own text, the app version, the platform, the language setting and whether a company has been created and whether private mode is active – no company names, no amounts, no customer data, no database extract. You enter the screen number yourself; it is deliberately not captured automatically. You attach a screenshot yourself in your mail program. A crash report contains the time, the error message, the technical error trace, the app version and the platform version. Until you send it, it stays on the device.
7. Subscription purchase
The purchase runs through Apple or Google and is tied to your app store account. Product identifier and purchase status are transmitted. The privacy terms of Apple or Google apply in addition.
8. Printing
You can print directly from the PDF preview. The PDF then goes to the printer on your network.
Access to the app
You can lock the app with a PIN, optionally with Face ID or a fingerprint. The PIN and the recovery code are not stored in plain text, only as a check value. After several failed attempts the app locks for increasingly long periods. If you lose both the PIN and the recovery code, nobody can get into the app any more – not even the provider. The only remaining option is to reinstall, and the existing data is lost unless you have a backup.
What the PIN does not do
The PIN protects access to the app, not the file on the device. The database is not encrypted on the device, and ELMOF's folder is visible through your device's Files app – this is needed so that ELMOF can place your project folders there. Anyone holding your unlocked phone can reach those files without knowing the PIN. So protect the device with your operating system's passcode, with Face ID or with a fingerprint, and do not hand it over unlocked.
Responsibility
As the owner of the business, you are as a rule the party responsible under data protection law for the business, customer and employee data in your company – not the app provider. The provider is responsible for the app as a tool and for the data flows it triggers itself. This is not a matter of interpretation but follows from how the app is built: there is no ELMOF server, and the provider never gets to see your business, customer or employee data. If a customer or an employee asks what data is held about them, the company is the right address, not the provider of the app.
Deleting
All data is on your device. Delete the app and it is gone. There is no account with the provider that would have to be deleted. Backup files, PDF files and the team folder in your cloud remain where you put them – you delete those yourself.
Your rights
You may ask at any time what data is stored about you and request that it be corrected or deleted. With the provider of ELMOF this is quickly answered: there is no user account and no server holding anything about you. The only thing stored is what you sent the provider yourself – a piece of feedback or a crash report by e-mail.
If it concerns data that a company has recorded about you in ELMOF – as a customer, a supplier or an employee – please contact that company. It recorded the data, the data is on its device, and it is responsible for it (see “Responsibility”). The provider of the app can neither view nor hand it over.
If you are not satisfied with the answer, you may contact the Swiss Federal Data Protection and Information Commissioner.
Retention period
The provider keeps only the e-mails you write to it – feedback, crash reports, support enquiries. These are deleted one year after the last reply.
Your business data cannot be kept by the provider: it is on your device. How long it stays there is up to you – until you delete it or remove the app. The same applies to your backup files and to the team folder in your cloud.
Applicable law and place of jurisdiction
Swiss law applies. The place of jurisdiction is Stans, canton of Nidwalden.
Contact for data protection enquiries
stropps.pappeln-18@icloud.com
Write to the same address as for support. It is a mailbox, not a form – you will get an answer from a person.
This website
The site runs without cookies, without analytics tools and without embedded fonts or scripts from third parties. The domain is registered with GoDaddy; the pages are hosted by Netlify, Inc. (San Francisco, USA). Like any web server, Netlify records access data for technical reasons — IP address, time and page requested; this data arises in the USA. We do not evaluate it and do not access it. How long Netlify keeps it is set out in Netlify’s own privacy policy.