Packet Patch

Privacy Policy

Last updated: October 3, 2026

In short

Packet Patch needs no account and never stores children’s names. Whatever the app saves stays in the browser on your device – unless you turn on the optional short code for a class; then its class key (counters only) is also stored on our server. There are no ads, no tracking, no analytics, and we set no cookies. The website loads content from Paddle only after you click “Buy now.” We only receive personal data if you buy a license or email us.

Who is responsible

Michael Andres
Hetkerbruch 21
46286 Dorsten
Germany
Email: kontakt@wunderkammer-apps.de (purchases and license keys: lizenz@wunderkammer-apps.de)

More details in our legal notice. We follow the EU General Data Protection Regulation (GDPR).

For U.S. schools: FERPA and COPPA

Packet Patch is built so that no student information ever reaches us:

  • Students don’t use devices, accounts, or logins. The app runs on one device at the front of the room.
  • The app stores no student names, answers, grades, or scores for individual students. A class is just a short label like “Room 12,” and the table wheel shows table numbers only.
  • Everything the app saves stays in the browser on that device. None of it is sent to us or to anyone else – unless a teacher turns on the optional short code, which sends only the class key (counters, no names; see section 3).

So when teachers use Packet Patch, no education records and no personally identifiable information from education records under the Family Educational Rights and Privacy Act (FERPA) are shared with us. We collect no personal information from children, including children under 13 as covered by the Children’s Online Privacy Protection Act (COPPA). This describes how the app works; it is not legal advice. If your district needs a student data privacy agreement or has questions, please email kontakt@wunderkammer-apps.de.

1. Visiting the website and the app

The website and the app are hosted on our own server with Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in its data center in Helsinki, Finland (EU). When you visit, the server processes the connection data it technically needs – IP address, time, requested file, and browser identifier – only for the duration of the connection. No access logs are kept.

Fonts and all other files come from this server. Nothing is loaded from third parties – the only exception is Paddle’s checkout, and only after you click “Buy now” (see section 4).

Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is delivering the pages.

2. Data in the app

The app stores the following in the browser’s storage (IndexedDB) on the device: class name (a short label like “3b”), grade, tree, album, weekly box progress, letters read, class records, settings, the date of the last change and backup, and, if entered, the license key. None of it is sent to us or anyone else; we have no access to it. The only exception is the optional short code (section 3): then we receive the class key, which contains only counters.

  • Class answers: The table wheel only shows table numbers. Answers and children’s names are not recorded.
  • Microphone (only in the game “Flick Takes a Nap”): only after you allow it in the browser. The app measures only the noise level in the moment; nothing is recorded, saved, or sent. When you leave the game, the microphone is released.
  • Reading aloud: The app uses the browser’s built-in speech. If the device has no voice of its own, the browser may send the text being read to its maker’s speech service (for example, Google in Chrome). That text comes from the app, such as tasks and letters – the app doesn’t know any children’s names. We have no control over what the browser maker does with it. You can turn reading aloud off for each class in the teacher menu.
  • Backups and class keys are created on the device and stay with the teacher. They contain no children’s names.
  • Deleting: You can remove a class in the teacher menu; to delete everything at once, clear the site data in your browser.

Without the short code, the app sends no data to us. With the short code, we receive only the class key – counters with no personal information. In no case do we process data about the class or the children on behalf of the school.

3. Short code for the class (optional)

If a teacher turns on the short code in the teacher menu, Packet Patch sends the class key to our server (address klasse.wunderkammer-apps.de) and again after every change. We store only: the randomly generated short code, the class key (up to ten earlier versions, to protect against accidental overwriting), the time of each change, and the day of last use. The class key contains only the counters of the class world (grade, boxes, fruit, blossoms, rounds played, decorations) – no names, no student data, no information about the teacher or the school. The short code stores no personal information about students.

Your IP address is processed briefly in memory only while handling the request and to limit requests (protection against guessing codes); it is discarded after about one hour and never written to disk. We keep no access logs.

The legal basis is Art. 6(1)(b) GDPR (providing the feature you turned on) and, for the brief processing of the IP address to prevent abuse, Art. 6(1)(f) GDPR (legitimate interest in secure operation).

A short code that has not been used for 400 days is deleted automatically together with all stored versions. We delete it right away on request: send the short code to kontakt@wunderkammer-apps.de. Turning the feature off in the app stops all uploads.

The server is located in a data center of Hetzner Online GmbH in Helsinki (Finland, EU), under a data processing agreement. No data is transferred to third countries.

Anyone who knows the short code can load and overwrite the class. Keep it safe like a password.

4. Buying the full version through Paddle

Our reseller Paddle.com Market Limited (Judd House, 18–29 Mora Street, London EC1V 8BT, United Kingdom) sells the full version as Merchant of Record. Paddle collects the data needed for the purchase, payment, invoice, and taxes – such as name, email address, country, ZIP code, payment details, and tax ID if any – and is responsible for it. See Paddle’s privacy policy.

For each order, Paddle shares with us your name, email address, country, order number, product, and amount. We use this to issue and send your license key, to help with questions and refunds, and for our bookkeeping (Art. 6(1)(b) and (c) GDPR).

The checkout on this website: We load Paddle’s checkout script, Paddle.js, only when you click “Buy now” – until then, the website requests nothing from Paddle. When you click, your browser loads Paddle.js and the checkout window from Paddle’s servers (cdn.paddle.com and other Paddle addresses). The checkout window in turn loads services that Paddle uses for payment and operations, such as the payment provider Stripe. Paddle receives the connection data this requires: IP address, time, browser identifier, and the address of our page. We pass on only the product you chose and the language of the page. Paddle may use cookies or similar browser storage as far as the checkout needs them. The legal basis is Art. 6(1)(b) GDPR: you want to enter into a contract, and the checkout is needed for that. Paddle is based in the United Kingdom, for which the European Commission has issued an adequacy decision (Art. 45 GDPR); for details, including Paddle’s service providers, see Paddle’s privacy policy. If you never click “Buy now,” you never come into contact with Paddle.

5. License keys

A license key contains the license number, license type, date of issue, and, where applicable, the name it was issued to (such as a school). For purchases through Paddle, the name is left blank. We keep a register of issued keys with the same details so that we can resend a key and block it after misuse or a refund. The app checks the key on the device only, without contacting us.

6. Email

If you email us, we use your details only to answer your request (Art. 6(1)(b) or (f) GDPR). We send license keys and replies through our email provider mailbox.org (Heinlein Hosting GmbH, Berlin, Germany).

7. How long we keep data

We keep order and invoice data as long as tax and commercial law requires (usually up to ten years). We keep the license key register as long as the license can be used. Emails not related to an order are deleted once the request is resolved.

8. Your rights

You have the right to access, correct, delete, restrict, and port your data, and to object to processing (Art. 15–21 GDPR). Just email kontakt@wunderkammer-apps.de. You can also file a complaint with a data protection authority, for example the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Germany.