Questa pagina è disponibile solo in inglese. Contiene disposizioni legali e in materia di protezione dei dati, e una traduzione non verificata potrebbe alterarne il significato — preferiamo quindi mostrarLe l’originale anziché una versione che nessuno ha controllato.
Controller / Imprint
Zügle is a private, self-hosted app used by exactly two people. It is not operated by a company. The person responsible for this app (the "controller" under GDPR) is:
- Name: Danilo Nunes Melo
- Contact: nmelodan@gmail.com
Guest mode (not logged in)
Zügle is also usable without logging in. An anonymous visitor gets an empty app, types their own income, address, and rent, and gets an evaluation; none of it touches any stored account. Those figures live only in the browser's sessionStorage and are gone the moment the tab closes; nothing is written to this server's data files for a guest.
To compute a result, the figures are sent to the Zügle server transiently, and onward to the same third parties any evaluation uses (ESTV, Flatfox/Homegate, transport.opendata.ch), listed in "Who receives your data" below. The one trace that survives after the tab closes: the ESTV request (income, municipality, relationship, confession, children) lands in the same tax cache every evaluation writes to. Stated plainly, that is a real, if indirect, retention of the numbers a guest typed.
What is stored
Everything below belongs to your own account (your profiles and your evaluation history) and is stored in a database on the server, readable only by your account. There is no analytics service and no third-party tracking. Fields marked special category get an explicit note underneath.
Experiences & needs posts
| Display name, title, text, chosen municipality | An experience or need you choose to post. Reviewed before publication — once approved it is public, shown under the display name you chose (or "Anonymous"), never your account email |
Identity
| Name | First name only, as entered in Settings |
| Relationship status | Single / married, affects Swiss tax calculation |
| Number of children | Affects Swiss tax calculation |
Financial
| Gross annual income | Used only to compute the tax comparison |
| Rent, charges, parking, electricity, other bills | Current home and any evaluated candidate |
| One-off application costs | E.g. Betreibungsregisterauszug, entered under Settings |
Location
| Current home address (ZIP / city / municipality) | Used for the tax and commute comparison |
| Candidate listing addresses | Street, ZIP, city, coordinates, from pasted Flatfox/Homegate links or manual entry |
| Commute target and time | E.g. "Zürich HB", commute minutes/cost |
Special category (Art. 9 GDPR)
| Religious denomination ("confession") | None / Roman Catholic / Protestant, see below |
Religious denomination: special category data
Your confession (religious denomination) is stored because Swiss church tax depends on it: it directly changes the tax comparison this app exists to make. Under Art. 9 GDPR this is "special category" data, and it is processed only on the basis of your explicit consent (Art. 9(2)(a)). You can set it to "None" at any time in Settings, which stops it being used or stored as anything but the value "none".
Lawful basis
Confession: explicit consent (Art. 9(2)(a) GDPR), withdrawable at any time in Settings. Everything else: consent, and/or the legitimate interest of this two-person household in running a tool that compares housing costs for its own members (Art. 6(1)(a)/(f) GDPR).
Who receives your data
All of the calls below are made by the server, not your browser; third parties see the server's IP, never yours. The one exception is the background photo: your browser loads it directly from images.unsplash.com, for every visitor, logged in or not: an anonymous visitor's IP reaches Unsplash (US) the moment the photo loads.
| Recipient | Receives | Why |
|---|---|---|
| ESTV (Swiss Federal Tax Administration) | Municipality, income, relationship, confession, number of children | Compute the cantonal/communal/federal tax comparison |
| Flatfox, Homegate | The listing ID from a pasted URL | Fetch the apartment listing details |
| Flatfox | A map bounding box around a municipality you clicked, no personal data | Find apartments currently for rent there |
| transport.opendata.ch | Home address and candidate address | Compute commute time |
| Unsplash (search + download-ping) | A landscape search query; a ping when a photo is shown | Source the background photo |
| Resend (EU region, Ireland) | Your email address, when you sign up or ask to reset your password | Deliver the welcome mail and the password-reset link |
| Zügle's own self-hosted language model | The text of a pasted listing, only when required figures are still missing after parsing | Read the listing's own figures (rent, rooms, size, address) so you don't have to type them. Not a third party: it runs on the operator's own server over an encrypted private network, and the text is not stored, logged or shared |
Retention
- Login sessions: 30 days, then they expire automatically.
- Profile and evaluation history: kept until you delete it.
- Experiences & needs posts: kept until you delete the individual post, or the whole account.
- Tax cache: purged for a profile the moment that profile's data is erased.
- Operational event log: the most recent 2000 events, oldest discarded automatically.
Advertising
Some advertisements shown here are first-party: the image and text are stored on this server and served from this domain, and clicking one goes through a redirect on this server. Nothing about you is sent to an advertiser for these, and no profile is built for targeting; the only figures recorded are anonymous totals per advertisement (how often it was shown and clicked), held in memory and lost on every restart.
This site may also show ads served by Google AdSense. Consent for those is collected by Google's certified Consent Management Platform, which asks you before any personalized ad is served. If you do not consent, you get no personalized ad and no advertising cookie.
One thing has changed, and this page used to say otherwise: Google's script now loads before you answer. It used to wait until you accepted a prompt this app drew itself. That prompt is gone, because Google requires consent from visitors in the EEA, the UK and Switzerland to come from a platform it has certified, and that platform is delivered by the very script that used to be held back, so it can't ask a question it was never loaded to ask. In practice, Google can see the request that loads it, including your IP address, before you decide anything. What you decide still governs whether you're profiled or shown a personalized ad.
If you consent, Google and its partners may use cookies and similar identifiers to serve ads based on your prior visits to this or other websites; you can opt out of personalized advertising generally by visiting adssettings.google.com. See Google's own policies.google.com/technologies/partner-sites for how Google uses data from sites that use its services.
Operational logging
The server keeps a short technical log so faults and abuse can be diagnosed: which API path was called, the response status and duration, rate-limit hits, and login successes and failures. It does not record IP addresses, and query strings are stripped before anything is written: a guest's income travels in the query string on two routes, so the path is stored without it. It also records no account id and no email address: an entry says that a login succeeded, not who logged in. That is why "Delete my data" does not need to touch the log; there is nothing in it that identifies you.
Log entries do carry a visit id, so that a handful of requests can be recognised as one visit and we can see where the app fails. It is a random value generated in your browser, it is erased when you close the tab, it is never stored next to your account or email, and it is never sent to anyone else. There is no analytics service involved. It records which screens were reached, never what you typed.
AI assistants (MCP)
Zügle can be connected to an AI assistant, so that it can look up Swiss tax figures, municipalities, commute times and advertised apartments for you. That connection reaches nothing about any account: it is anonymous and read-only, limited to exactly the same public lookups an anonymous visitor can make with a web browser. It cannot see profiles, saved evaluations or settings, and it cannot create, change or delete anything.
The connector runs on your own machine and holds no password or key. Each lookup writes one log entry recording which capability was used and how long it took, never the figures you asked about, so, like everything above, it adds nothing that identifies you.
Your rights
You have the right to access, rectify, erase, and receive a copy of your data (portability), and to withdraw consent at any time. In practice:
- Access / portability: the "Download my data" button in Settings gives you a JSON file with everything held about you.
- Erasure: the "Delete my data" button in Settings hard-deletes your evaluation history, every experience/need post you made, purges your entries from the tax cache, removes your entries from the operational log, and resets your profile.
- Rectification: edit any field directly in Settings.
- Withdraw consent: set Confession to "None" in Settings, or use Delete my data for everything.
These rights apply to your account's stored profiles and history. A visitor who is not logged in has nothing stored server-side to access, export, or erase; their figures never left the browser to begin with.
Cookies
This app itself sets exactly one cookie: zugle_session, HttpOnly, SameSite=Strict, valid 30 days. It is strictly necessary to keep you logged in, and no consent banner is needed for it. Your ad-consent choice (see "Advertising" above) is recorded by Google's consent platform, in your own browser. It is never sent to this server and never seen by us, but unlike the choice this app used to store itself, it is a record Google keeps rather than one we keep. If you consent to AdSense ads, Google may then set its own cookies for ad delivery and measurement; those are covered by the consent choice described above, not by this app's own cookie.
Hosting
This app is self-hosted on a personal VPS and reached over an encrypted (HTTPS) connection. Server logs (systemd journal) do not record visitor IP addresses.