Last updated: 3 August 2026
AloxBook is designed so your financial data stays under your control. The desktop app works offline, stores your books in files you choose, and avoids the usual tracking patterns found in many online products. This page explains what is processed when you use the app or visit the website.
No AloxBook account or built-in cloud synchronization is required. The app does not transmit book contents, financial records, or passwords; enabled or manual update checks contact aloxbook.com with the app version, platform, and standard web-request data.
When update checks are enabled, or when you start a manual update check, AloxBook contacts
www.aloxbook.com/releases/ to check for and download updates. These requests include the
application version and platform together with standard web-request information such as the IP address,
timestamp, requested resource, and user agent. They do not include the contents of your books, financial
records, or passwords. Setting the update frequency to "Never" disables automatic checks; a manual check
still contacts the update server when you request it.
Password protection is optional. When a password is set, SQLCipher encrypts the book with AES-256; without a password, the book is an unencrypted SQLite database. Forgotten passwords cannot be recovered.
You choose where to store your book files. AloxBook provides no built-in cloud backup or remote storage. If you place a book in a cloud-synced folder, synchronization is handled by your chosen provider and settings.
The website, update service, and support and security mailboxes are hosted by Hetzner Online GmbH on servers in Germany. Backups are stored in Germany and Austria.
Like most web servers, aloxbook.com records requests, including:
These records are used for security, operation of the website and update service, and aggregated statistics about website visits, downloads, package managers, and application updates. No tracking cookies are used.
To prepare country statistics and help distinguish ordinary visits from automated or data-centre traffic, public IP addresses are looked up in locally stored DB-IP Lite City and ASN databases. No visitor IP address is sent to DB-IP or another geolocation service. The lookup can add an approximate country, region, city, and network operator to the server record. The databases are checked daily and replaced when DB-IP publishes its monthly update. IP Geolocation by DB-IP. Database licence: CC BY 4.0.
Ordinary identifiable website and update-service request records are kept for 35 days. Records marked as security-relevant are kept for 90 days; evidence required for a specific unresolved incident or legal obligation may be kept longer. Before raw records are deleted, anonymous daily totals for requests by country and download requests by platform and type are stored; monthly totals are derived from these rows, and both may be kept indefinitely. Nginx log rotations are kept for 35 days and statistics-database backups for 30 days. Support and security messages are kept for up to three years after the last correspondence or resolution. Messages may be kept longer only for an unresolved issue or legal obligation. Anonymized quality-assurance notes may be kept indefinitely.
The website stores your chosen language in your browser's localStorage under aloxbook_lang. This preference is used only to show the website in your selected language and is not a tracking identifier.
When you email support@aloxbook.com, security@aloxbook.com, or the legacy forwarding address aloxbook@alox.at, the sender address, message, and any technical details you provide are processed to answer the request, investigate the issue, and protect AloxBook and its users. They are not sold or used for marketing.
Support and security messages are received and stored on servers in Germany, with backups in Germany and Austria. Email is transmitted through the mail systems used by the sender and recipient. If a sender or recipient uses an email provider outside the EEA, message and addressing data may be processed in that provider’s country. Please do not send passwords, AloxBook files, bank statements, or unredacted financial screenshots.
To protect the mailboxes from spam and abuse, technical indicators associated with a message—including the sending server’s IP address and relevant sender or link domains—may be checked against third-party DNS reputation lists. These services receive the resulting DNS query, not the message body. Some providers may process that query data outside the EEA. The checks are used only to assess message reputation and protect the mail service.
The controller is Alois Hartl. Privacy questions can be sent to support@aloxbook.com; the postal address and full contact details are in the Imprint. Website and update-service request data, and support and security messages, are processed under Article 6(1)(f) GDPR where necessary for our legitimate interests in secure and reliable operation, preventing abuse, maintaining and improving AloxBook, and answering messages. If a message requests steps before entering into a contract, the necessary processing is based on Article 6(1)(b) GDPR. Where processing or retention is necessary to comply with a legal obligation, Article 6(1)(c) GDPR applies. Subject to the legal requirements, you may request access, rectification, erasure, restriction of processing and, where applicable, data portability. You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. You may lodge a complaint with the Austrian Data Protection Authority (dsb.gv.at) or another competent supervisory authority. This data is not used for automated decision-making, including profiling, within the meaning of Article 22 GDPR.
The application can be used without creating an account or entering personal profile information. The request data described above is processed in the same way for all users.
We may update this privacy policy from time to time. Changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
Privacy questions can be sent through the Support route. Full legal contact information is in the Imprint.