Skip to content
Buzzbelt
  • Home
  • How it works
  • What it does
  • Setup
  • Honest limits
  • Questions

Privacy

Privacy policy

This is Buzzbelt's privacy notice under the EU General Data Protection Regulation (GDPR). The central fact behind everything below: Buzzbelt has no server. Aralel GmbH does not operate any back end for this app, receives none of your data, and cannot see, store or act on anything the app does. What follows explains, precisely, what that means in practice.

Deutsche Fassung (in Deutschland rechtlich maßgeblich): Datenschutzerklärung. Where the two differ, the German text governs for users in Germany; this English version is provided for convenience.

The short version

  • There is no server. Nothing you do in the app ever reaches Aralel.
  • Your data lives on your phone, and on the phones of people you message.
  • No accounts, no analytics, no advertising, no third-party SDKs, no location access.
  • If you're 13–15, an adult responsible for your trip needs to have said yes on your behalf before you use it — ask your group leader if you're not sure they have.
  • This website sets no cookies and loads nothing from anyone else's server.

Who is responsible

The controller for the processing described in this policy, within the meaning of Article 4(7) GDPR, is:

Aralel GmbH
Josefstr 66
52080 Aachen, Germany
Registered at the Amtsgericht Aachen, HRB 29506
Represented by: S Torabi
Email: buzzbelt@aralel.com

Full company details are in the Impressum.

Aralel GmbH has not appointed a data protection officer. Under § 38 BDSG a German company must appoint one only once at least twenty people are constantly engaged in the automated processing of personal data — a threshold that presumes there is processing on the company's own systems to be engaged in. Aralel operates none: there is no server, no database and no pipeline that any employee works on. If that changes, this notice changes with it.

What Buzzbelt stores on your device

Installing and opening the app writes the following to your phone's own storage, and nowhere else:

  • Your display name — whatever you type when you set it, or change it later.
  • A profile picture, only if you choose to add one.
  • A member ID — a 128-bit value your phone generates at random the first time the app runs. It identifies your phone to the group; it is not derived from your name, your device's hardware identifiers, or anything else that could be reversed to learn who you are.
  • The cryptographic keys the app uses to encrypt your group's messages and, if you are a group's leader, to sign your announcements.
  • Your message history — everything sent and received, in the group conversation and in direct messages.
  • Other members' names, pictures and reachability, as broadcast by their own phones once you're in the same group.

Legal basis: Article 6(1)(b) GDPR — this processing is necessary to provide the functionality you install the app to get, under Buzzbelt's Terms of use. Generating a member ID before you have typed anything, and holding cryptographic keys, do not fit "contract" quite as neatly; where they don't, Article 6(1)(f) — Aralel's and your shared legitimate interest in the app working at all — applies instead.

Whether you have to provide it: you choose your own display name and are free to leave the picture blank. Without a name, though, there is nothing for anyone else's roster to show as the sender of your messages, so in practice a name is required for the app to do anything.

How long it's kept: for as long as you keep the app and the conversation. Aralel enforces no retention period, because Aralel has nothing to enforce one on — the data never reaches us. See your rights for how to delete it yourself.

What leaves your device, and why

When you send a message or a buzz, it leaves your phone over Bluetooth and travels to any Buzzbelt phones within range — not necessarily every member of your group directly, since (as the main page explains) other phones pass messages along so your reach isn't limited to who's standing next to you. Content is encrypted with a key established when you joined the group, by scanning the leader's QR code at departure, so that only phones holding that key can decrypt it. A leader's announcement additionally carries a cryptographic signature, so a recipient's phone can confirm it genuinely came from the leader's key rather than from an ordinary member's.

What leaves your device this way: message content, your display name and picture (attached so a recipient's roster can show who sent it), your buzz signal, and — for a leader — an announcement's signature.

Buzzbelt is under active development. The paragraph above describes how the app is designed to work, matching what the main page promises. If you are holding an early or field-test build rather than a public release, check its release notes or ask your organiser whether group encryption and leader signing are already active in your specific copy before relying on either.

Who can actually read it

A phone that is only relaying your message on its way to someone else does not hold your group's key and cannot read it — it moves the encrypted bytes along without knowing what's inside them, the way a courier can carry a sealed envelope without reading the letter. That is true whether or not the relaying phone happens to be running Buzzbelt for a group of its own: the part of the app that passes messages along treats every message as an opaque block of bytes and never looks inside it, for anyone's messages, ever.

Inside your own group the position is the opposite. Every member who holds your group's key can read every group message, because that shared key is what makes it one conversation rather than many private ones. There is no message that is readable by you and not by every other current member. If that matters for what you're about to send, see the honest limits on the main page.

What Aralel receives

Nothing. Stated as plainly as the structural fact deserves: Buzzbelt has no server, so there is no address for your phone to send anything to even if the app tried. There is no logging pipeline, no crash reporting, no analytics collector and no support inbox that this data could land in. We cannot produce a list of who is in your group, cannot read a single message, and cannot tell that your group exists — not as a promise we're asking you to trust, but as a consequence of what the software is and is not built to do.

What Buzzbelt does not do

  • No analytics. Nothing measures how you use the app.
  • No advertising. Nothing is shown to you and nothing about you is sold or shared for it.
  • No third-party SDKs. No crash reporter, no ad network, no analytics library — none of the usual channels through which an app quietly hands data to somebody else are present here.
  • No international data transfer. A transfer needs data on Aralel's side to move; there is none, so there is nothing to transfer, to the US or anywhere else.
  • No location access. The app has no location permission and cannot be granted one through a setting it doesn't ask for. On Android, the Bluetooth scanning permission is declared with neverForLocation, so the operating system itself is told this app does not use it to infer where you are.
  • No account system. No email address, no phone number, no password, and nothing to reset if you forget one, because there is nothing to log into.
  • No automated decisions or profiling. Nothing about you is scored, ranked or decided upon by an algorithm — the app's whole job is to show you what your own phone directly observed.

Your rights, and what Aralel can actually do about them

Where data protection law gives you a right, we say so — and then we say, honestly, what exercising it against Aralel specifically can and cannot do, because "write to us and we'll delete it" would be a promise Aralel has no way to keep.

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21, for processing under Art. 6(1)(f) only) all exist as rights against Aralel. You are welcome to write to the address above and ask.
  • What we can actually do about it: nothing, directly — Aralel holds none of this data, so there is nothing on our systems to access, correct, restrict, export or delete. There is no database row with your name on it here to act on.

What you can do yourself, which is where these rights actually live for an app like this one:

  • Delete your own copy. Clearing the app's data, or uninstalling it, removes your display name, your keys, your member ID and your message history from that device immediately and completely.
  • You cannot delete a message from someone else's phone once they've received it, for the same reason no messaging app can reach into a recipient's device and unsend something they already have — Signal and WhatsApp can't either, for what it's worth, and Aralel has less reach into your phone than either of those, not more.
  • Stopping someone from reaching you, or stopping yourself reaching a group: group administration controls — a leader excluding a member, or ending a group outright — are part of Buzzbelt's design, and not every one of them is built yet in every version. The reliable option that works today, in any version: stop using the app for that group. Because there is no account, there is nothing to close and no subscription to cancel — uninstalling, or simply not opening it again, is the whole mechanism.

Where processing relies on someone's consent — see the next section, on participants under 16 — that consent can be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7(3)).

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — see below.

If you're under 16: parental consent

Buzzbelt is meant to be used inside an organised group — a school trip, a youth group, a scout troop, something with an adult already running it — by participants aged 13 and up. The app itself has no age gate: it never asks how old you are, and has no way to check.

Article 8 GDPR sets the age at which a child can validly consent to an information-society service themselves at 16, unless a country has lowered it by law, to no lower than 13. Germany has not lowered it. So for anyone aged 13 to 15, the legal basis for Buzzbelt's processing of their data is not their own consent — it is consent given or authorised by whoever holds parental responsibility for them (Art. 8(1), second sentence).

Aralel does not, and cannot, collect that consent itself: there is no sign-up screen, no age question and no server to record a "yes" on. It has to be obtained, and kept, by the organisation running the trip or group — as part of whatever consent process it already runs for the trip itself, such as a permission form parents sign before departure. That consent is never sent to Aralel, never visible to Aralel, and not something Aralel has any way to verify happened.

What this means in practice for an organiser: before a 13–15-year-old participant uses Buzzbelt, get the same kind of go-ahead from whoever holds parental responsibility for them that you'd get for anything else on the trip — informed, at minimum, by what this page says the app stores and who can read it. Keep that record with your own trip paperwork; Aralel has nowhere to keep it and no way to know it exists. For participants 16 or older, Article 8 imposes no such requirement on this processing — though your organisation's own rules, or the general rule that a minor's capacity to enter into a contract like Buzzbelt's Terms of use is limited under German civil law until 18, may independently call for a guardian's involvement. That question sits between you, your participants and their guardians; it is not one Aralel is in a position to answer for you.

This website

Everything above is about the app. buzzbelt.com, the website you're reading this on, is a separate, much simpler thing: four static pages and a stylesheet, with no back end of its own either.

Cookies

None. No cookies, no local storage, no fingerprinting and no consent banner, because there is nothing on this site to consent to.

Fonts

The typefaces are served from this server. This site does not embed fonts from Google Fonts or any other third party, so loading a page here never sends your IP address to a font provider — see how, if you're curious.

Server log files

The web server records a log entry for each request, which is standard practice and necessary to run one securely. An entry contains the requesting IP address, the date and time, the page requested, the referring page if your browser sent one, and your browser's user-agent string.

Legal basis: Article 6(1)(f) GDPR — the legitimate interest is delivering the site reliably and detecting attacks against it. These logs are not combined with any other data, are not used to analyse visitor behaviour, and are deleted after 7 days.

The site is hosted by github, acting as a processor under a data processing agreement pursuant to Article 28 GDPR.

Contacting us

If you write to us, we keep your message and your address in order to answer it, on the basis of Article 6(1)(f) GDPR — or Article 6(1)(b) where your enquiry concerns a contract. We delete it once it is no longer needed and no retention obligation applies.

Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in particular in the state you live or work in, or where the thing you're complaining about happened. Because Aralel GmbH is established in North Rhine-Westphalia, its lead authority is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
ldi.nrw.de · poststelle@ldi.nrw.de

Changes to this policy

If this notice changes, the date below changes with it. There is no mailing list to notify, because there is no mailing list — check back here, or in the app, before a trip if it matters to you.

Last updated: 2 September 2026 · Draft

Buzzbelt — group messaging for trips with no signal.

This site has no cookies, no analytics and no third-party content. The fonts are served from this server, not from Google. Nothing is stored on your device and nothing is sent anywhere, which is why there is no banner here asking your permission for it.

Privacy Datenschutz Terms Impressum