Last updated: June 2026
Protecting your personal data is very important to us. We process data solely on the basis of the applicable legal provisions (the GDPR, the Austrian Telecommunications Act, and — where relevant — international standards such as CCPA/COPPA and the policies of Google Play, the Apple App Store, Steam, and Epic Games). This policy applies to all of the websites listed below that are operated by Ostrong Studios (Mathias Oysmüller), as well as to all games and applications („apps“) published under the Ostrong Studios name or its brands.
ostrongstudios.de · ostrong.net · ostronggames.net · thyrathar.de · thyratharlegends.de · thyratharlegends.eu · limbustales.de · limbustales.eu · elyravalen.de · evlnk.de
Note on structure: Exactly which data is processed depends on the service you use. Parts 1–3 apply generally, Part 4sets out the framework for apps/games with online features, and Part 5 covers the current Spieglein family (purely local, with no data transfer to us).
- ostrongstudios.de
- ostrongstudios.at
- ostrongstudios.com
- ostrong.net
- ostronggames.net
- ostronggames.com
- thyrathar.de
- thyratharlegends.de
- limbustales.de
- elyravalen.de
- wuff.chat
- wichtelrunde.xyz
1. Controller
Oysmüller Mathias (Ostrong Studios)
Altwaldhäusl 55
3662 Münichreith-Laimbach
Austria
Email: office@ostrongstudios.de
Website: www.ostrongstudios.de
2. Your rights
You have the right at any time to:
- Access the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16)
- Erasure — the „right to be forgotten“ (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
- Withdraw consent you have given (Art. 7(3))
To exercise your rights, simply contact office@ostrongstudios.de — no particular form is required.
Right to lodge a complaint: You have the right to complain to the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna; phone +43 1 52 152-0; email dsb@dsb.gv.at; web https://www.dsb.gv.at).
No automated decision-making: We do not carry out automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
3. Processing on the website
Server/access data: When you visit the website, the hosting provider processes technically necessary data (e.g. IP address, date/time, page accessed, browser type). This serves the technical operation, stability, and security of the site (Art. 6(1)(f) GDPR).
Contacting us: If you contact us by email or a form, we process your details in order to handle your request (Art. 6(1)(a)/(b) GDPR). We keep the request only as long as necessary, and at most 3 years.
Cookies & third-party content: Where the website uses cookies or embedded third-party content (e.g. videos), we obtain your consent via a consent banner where required. Technically necessary cookies are set without consent.
4. Apps & games — general framework
This part applies insofar as an app or game uses online features (e.g. leaderboards, cloud save states, advertising). For the current Spieglein family, Part 5 applies instead, since those apps work purely locally.
4.1 Automatically collected data: When you access a service, technical information such as your IP address, device type, OS version, and store ID (e.g. Google Play ID, Apple IDFA/IDFV) may be processed for the technical operation, stability, and security of the service.
4.2 Identifiers:
- Device IDs: to identify the device for cloud saves and to sync game progress.
- Advertising IDs: only if you explicitly agree (e.g. via Apple’s ATT dialog or the Google Advertising ID), in order to show ads.
4.3 Distribution platforms (data sharing with third parties): To provide the games and social features (leaderboards, achievements), third-party services may be used:
- Google Play Services — features for Android users
- Apple Game Center — features for iOS/macOS users
- Steamworks (Valve) — authentication, cloud saves, and multiplayer on Steam
- Epic Online Services (Epic Games) — authentication and social features in the Epic Games Store
In doing so, data (such as your account ID on the relevant platform) is transferred to these providers. Details can be found in the respective privacy policies of Google, Apple, Valve, or Epic.
4.4 International data transfers: Since some distribution partners are based in the USA, data may be processed outside the EU. We ensure an adequate level of data protection through Standard Contractual Clauses and the EU–U.S. Data Privacy Framework.
4.5 California notice (CCPA): We do not sell your personal information.
4.6 Children’s policy (COPPA / GDPR-Kids): Our apps are not specifically directed at children and do not knowingly collect children’s personal data without parental consent. In Austria, consent under data protection law for information-society services is valid from the completed age of 14 (§ 4(4) DSG); in other countries this threshold ranges between 13 and 16 depending on national rules. If we become aware of data from children below the applicable age limit that was provided without parental consent, we delete it immediately.
4.7 Security: We use SSL/TLS encryption for our web communication and modern security standards within our apps.
4.8 Data erasure & retention: We store data only as long as needed to provide our services. You can request deletion of your data (e.g. high scores, linked platform IDs, or app data) at any time by emailing office@ostrongstudios.de. We delete within the statutory period unless retention obligations prevent it. This process meets Apple’s and Google’s account-deletion requirements.
4.9 Platform-specific compliance:
- Google Play Data Safety: All data is encrypted in transit (HTTPS/TLS); users can request deletion directly through us.
- Apple App Store (App Privacy): We declare in the App Store which data is collected; tracking only occurs after explicit consent (App Tracking Transparency).
- Steam (Valve): Where a game uses Steamworks, we process Steam data such as your SteamID, your public persona name, and your avatar solely to provide core features (e.g. save states, leaderboards, achievements, multiplayer). Persona name and avatar are publicly available via the Steam API in any case. Within each game we tell you which Steam data is stored and in which countries (per Valve’s Steamworks requirements).
- Epic Games: Epic Online Services are used only to provide core features (authentication, social features).
4.10 Distribution via app stores (Microsoft Store, Google Play, Steam): Our apps and games are distributed through app stores — currently the Microsoft Store and Google Play, and possibly Steam in future. This applies regardless of whether an app uses online features; even purely local apps (e.g. the Spieglein family) are distributed and updated through these stores.
When you buy, download, or update, the respective store processes your account and transaction data as an independent controller under its own privacy policy (Microsoft Store: privacy.microsoft.com; Google Play: policies.google.com/privacy; Steam/Valve: store.steampowered.com/privacy_agreement). From the stores we essentially receive aggregated or statistical data (e.g. download numbers, regions) and publicly visible reviews. Ostrong Studios does not carry out any further independent processing of personal buyer data — unless you contact us yourself.
5. Our apps in detail
5.1 Spieglein (Windows/PC — receiver for Apple/AirPlay):
The Spieglein apps mirror screen content between devices on the same local network. All data transfer happens exclusively locally, within the same Wi-Fi/LAN. No content or metadata is transmitted to external servers — or to Ostrong Studios, Apple, Microsoft, Google, or any third party. No cookies, no tracking, no analytics/telemetry tools, and no advertising are used. The general framework in Part 4 therefore does not apply to these apps.
„Spieglein“ is a Windows application that receives AirPlay streams (screen, audio, video) from Apple devices (iPhone, iPad, Mac) and displays them on the PC. Processed exclusively locally on your device:
| Type of data | Storage location | Purpose |
|---|---|---|
| Configuration (device name, optional PIN, language, audio mode) | LocalCache (settings.json) | Restoring your settings |
| Diagnostic log (technical messages) | LocalCache (uxplay.log) | Troubleshooting; only visible locally |
| Audio/video stream from the Apple device | Transient, in memory | Playback of the AirPlay stream |
| Hostnames / device identifiers of connected devices | Transient, in memory | Displaying the connection name |
Network (local only): mDNS/Bonjour (UDP 5353), AirPlay control (TCP 7000, 7001, 7100), RTP audio/video (UDP 6000, 6001, 7011). No internet connection is actively established; updates run via the Microsoft Store mechanism. Open-source components (run locally): UxPlay (GPL v3), mDNSResponder (Apache 2.0), GStreamer (LGPL), Microsoft .NET 8 / Windows App SDK (MIT). Source code: https://github.com/OstrongStudios/spieglein
5.2 Spieglein (Android sender) & Spieglein (Android) (PC receiver): The Android app „Spieglein“ captures your Android device’s screen and internal audio and sends them over Wi-Fi to the Windows receiver app „Spieglein (Android)“. Processed exclusively locally on your device:
| Type of data | Storage location | Purpose |
|---|---|---|
| Settings (resolution, language) | App’s own storage (SharedPreferences) | Restoring your settings |
| Screen content (video) and internal playback audio | Transient, in memory | Live transmission to the connected PC |
Permissions: screen capture (MediaProjection, started by you); microphone (RECORD_AUDIO — technically required to capture the internal playback audio via AudioPlaybackCapture, not the microphone itself); foreground service (keeps the transmission running); WAKE_LOCK (keeps the screen on); INTERNET (only for the local connection to the PC, no access to external servers). Network (local only): mDNS (UDP 5353) for discovery, TCP (local port) for the stream connection. No recordings are stored. Open-source components: AndroidX and Material Components (Apache 2.0); no code under copyleft licenses.
5.3 Spieglein TV (Android): „Spieglein TV“ belongs to the Spieglein family and follows the same principle: screen mirroring exclusively on the local network, with no transmission of content or metadata to external servers, no tracking, and no advertising. The details in section 5.2 apply accordingly.
5.4 Legal basis for the Spieglein family: Because the Spieglein apps do not transmit any personal data to Ostrong Studios or process any such data there, no data-protection-relevant processing takes place on our side. If you actively contact us (e.g. for support), we process your request on the basis of Art. 6(1)(a)/(b) GDPR and only for as long as necessary, at most 3 years.
5.5 ShellDiver (iOS, iPadOS, macOS, Windows)
ShellDiver is an SSH client. We collect no data. There is no analytics, no crash reporting to us, no advertising, no tracking and no advertising identifier. Section 4 does not apply to ShellDiver.
Connections. SSH, SFTP and port-forwarding connections go directly from your device to the server you name. There is no intermediate server of ours. We learn neither which servers you connect to nor what you do there. A local port forward listens on 127.0.0.1 only, that is, on the device itself.
On the device. Your server list, folders, snippets, confirmed host keys and settings live in the app on your device. Passwords and private keys are never stored or transmitted in the clear by the app: on Apple devices they live in the device keychain, on Windows under the protection of the Windows Data Protection API (DPAPI). Keys generated inside the Secure Enclave cannot technically leave the device at all; no such hardware-bound key exists in the Windows version.
Crash reporting on Windows. ShellDiver switches off Windows Error Reporting for its own process. No memory dumps are created that could contain passphrases or key material, and nothing goes to us either.
iCloud (optional, off by default; Apple devices only). If you turn on iCloud sync, ShellDiver stores your server list, snippets and confirmed host keys in your own private iCloud database, under your Apple Account. We have no access to it — not as a promise, but because Apple’s private database cannot be read by the developer. Passwords and private keys are not transferred there; they follow your own iCloud Keychain setting and nothing else. For that data Apple is the party responsible towards you, and Apple’s privacy policy applies.
Vault sync (optional, off by default; all platforms). This keeps your server list, snippets, keys and confirmed host keys in step across your devices — including between Windows and Apple devices. The sync runs through a storage location you choose: a folder, a removable drive, or a WebDAV server of your choosing.
Encryption happens on the device before anything is written: the key is derived from your passphrase with Argon2id, the data is encrypted with AES-GCM. Whoever runs the storage sees nothing but files they cannot open. We run nothing in this and have no access at any point.
If you use a WebDAV server, its credentials go to that server and nowhere else, and they live on the device in the keychain or under DPAPI respectively. The operator of that server is responsible for it and for the data held there; if you run it yourself, that is you.
Only you know the passphrase and the recovery code. If both are lost, not even Ostrong Studios can bring the data back — that is not a promise, it is a property of the method.
Adding a second device. Pairing moves a QR code from one screen to the other. It is displayed locally and read locally; there is no brokering service and no transfer through any server of ours.
Backup and restore. You can write your data to a file. Where it goes is up to you. On request it also contains passwords and private keys; that part is then encrypted under a password you choose yourself. Without that request it contains no credentials.
Tip jar. Voluntary, and it unlocks nothing. On Apple devices it is an in-app purchase handled entirely by Apple. In the Windows version it is a link to a page of ours: if you follow it, your browser opens and you leave the app; the page you reach and any payment service involved are governed by their own privacy terms. The link is only followed when you press it.
The purchase. Buying the app is handled entirely by Apple or Microsoft respectively; we receive no payment details and nothing that identifies you — only the aggregated sales reports.
Retention and erasure. Since we collect nothing, we retain nothing. All data lives on your device, in your iCloud, or at the storage location you chose for vault sync. Deleting the app removes the local data along with its keychain or DPAPI entries. iCloud sync can be turned off in the app at any time, and the data stored there can be deleted in the iCloud settings of your Apple Account. Vault sync you end in the app with „Forget the vault on this device“; the files at the storage location you delete where they live — with you.
Legal basis. No processing of personal data by Ostrong Studios takes place in ShellDiver; accordingly there is no legal basis to state and no consent that could be withdrawn. Your rights under section 2 remain unaffected.
5.6 Hirnschmaus
5.6.1 Hirnschmaus: Denkspiele
Hirnschmaus: Denkspiele is a collection of six puzzle and brain games. We do not collect any
data. There is no analytics, no crash reports to us, no advertising, no tracking
and no advertising ID. Of the general framework in Section 4, only the part
concerning Game Center applies to Hirnschmaus (see below); there is no
advertising, no cloud save games and no other online services.
On the device. Saved games, statistics, your streak counter and the settings are
stored solely within the app on your device. They are not transmitted to us or to
any third party.
Game Center (optional). If you are signed in to Apple’s Game Center on your
device, Hirnschmaus reports your achievements and leaderboard scores to Game
Center. Leaderboard scores may be shown to other players under your Game Center
name. This data is processed by Apple under your Apple account; we have no access
to it and do not receive it. Apple is responsible to you for this data, and
Apple’s privacy policy applies. If you are not signed in, the app remains fully
playable — achievements and leaderboards are simply omitted.
No purchases, no advertising. Hirnschmaus contains no in-app purchases, no
subscriptions and no advertising.
Retention and deletion. Since we do not collect anything ourselves, we do not
retain anything. Local data is removed when you delete the app. Your achievements
and scores stored in Game Center are managed through your Apple account and can be
reset in its Game Center settings.
Legal basis. No processing of personal data by Ostrong Studios takes place in
Hirnschmaus; therefore no legal basis and no consent that could be withdrawn are
required. Any data processed within Game Center is Apple’s responsibility. Your
rights under Section 2 remain unaffected.
5.6.2 Hirnschmaus: Brettspiele
Hirnschmaus: Brettspiele is a collection of six board games played against the computer. We collect no data. There is no analysis, no crash reports to us, no advertising, no tracking and no advertising ID. Section 4 does not apply to Hirnschmaus.
On the device. Statistics, your daily streak, unlocked achievements and settings reside in the app on your device (in the „Application Support“ folder). We neither read nor transmit them.
Game Center (voluntary). Game Center is Apple’s service; the app has no account of its own. Only when you are signed in to Game Center on your device does the app report three leaderboard values to Apple — total wins, longest daily streak, wins on hard — along with, for each of the 16 achievements, whether it has been earned. Nothing more leaves the device. Sign-in is handled by iOS; the app never sees your credentials. For this data Apple is responsible to you, and Apple’s privacy policy applies. Without signing in, the app works in full — it simply reports nothing outward.
No other connections. Apart from the reports to Game Center, the app makes no network connection. There is no server of ours, and there are no purchases.
Retention and deletion. Since we collect nothing, we retain nothing. All data resides on your device or in Game Center: „Reset progress“ in the app’s settings clears the local state, and deleting the app removes the local data as well. Whatever has already been reported to Game Center is managed in your Apple account’s Game Center settings — the app cannot take anything back there.
Legal basis. No processing of personal data by Ostrong Studios takes place in Hirnschmaus; accordingly, no legal basis and no consent requiring revocation is needed. Your rights under section 2 remain unaffected.
5.7 Lichtblick (Apple, Microsoft, Android)
Lichtblick is a photo editor that runs entirely on your iPhone or iPad. We collect no data. There is no analytics, no crash reports to us, no advertising, no tracking and no advertising ID.
Your edits, looks and custom presets are stored solely on your device; editing is non-destructive and your original photo stays unchanged. Access to the photo library is used only to save new images, and the camera only to capture – both stay on the device. All image analysis (such as subject and face detection via Apple’s Vision framework) runs on-device; there is no server connection, and your photos are not transmitted.
Voluntary support (in-app purchases): Through the „Tip Jar“ you can give us a voluntary tip. Payment is handled exclusively by Apple via the App Store; we receive no personal payment data. The purchase unlocks no feature and is purely support.
Feedback (optional): If you send us feedback from within the app, your email program opens with a prepared message to feedback@ostrongstudios.de. Only once you send this email yourself do we receive your email address and the content you wrote, in order to handle your request; technical details such as the app version and device model are attached solely for troubleshooting. Sending is voluntary.
Legal basis: Because Lichtblick does not, of its own accord, transmit any personal data to Ostrong Studios, no data-protection-relevant processing takes place on our part in this respect. If you voluntarily contact us via the feedback email, we process your details solely to handle your request (Art. 6(1)(b) and (f) GDPR).
5.8 wuff.chat (Windows)
wuff.chat is a voice and text chat for self-hosted servers. We collect no data. There is no analytics, no crash reports to us, no advertising, no tracking, no advertising ID and no update check. The app never contacts a server operated by Ostrong Studios – we run no central service for wuff.chat.
Unlike our other apps, data does leave your device with wuff.chat, because that is precisely its purpose: the app connects solely to the server whose address you enter yourself. It transmits your display name and your account password when signing in, your voice while you are speaking, your text messages and – technically unavoidable – your IP address. Who runs that server is your decision. As a rule it is you yourself or the person who invited you; that person is then responsible for the data stored there, not Ostrong Studios.
Encryption: voice and text are encrypted between your device and the server (ChaCha20-Poly1305 with per-session keys). This is not end-to-end encryption: the server decrypts your voice and passes it on to the other participants in the channel, because it could not distribute it otherwise. Whoever runs the server could technically listen in. That is the usual design for self-hosted voice chat; we point it out explicitly rather than leaving it unsaid.
On your device the app stores, in %APPDATA%\wuff.chat\config.json, the server address, your display name, your choice of microphone and playback device, your key bindings, the overlay settings, saved bookmarks as well as language and sound scheme. Passwords are not kept in that file; they are stored in the Windows Credential Manager. You can remove everything by deleting the folder %APPDATA%\wuff.chat and the *.wuff.chat entries in Credential Manager.
Microphone: the app needs access to your microphone in order to transmit speech. It records only while you are speaking or holding the push-to-talk key. Nothing is recorded and nothing is stored – the audio goes straight into the transmission.
If you run a wuff.chat server yourself, the server software we provide stores account names, passwords exclusively as Argon2id hashes, roles, channels, chat history and temporary IP bans. Voice is not recorded. You are then the controller for that data within the meaning of the GDPR.
Voluntary support: via „Buy me a coffee“ in the settings the app opens our page in your browser, which redirects to the service Buy Me a Coffee. From the moment you leave the app, that provider’s privacy policy applies; we receive no personal payment data. The contribution unlocks no feature and is purely support. Likewise the „Privacy policy“ item merely opens this page in your browser.
Legal basis: because wuff.chat does not, of its own accord, transmit any personal data to Ostrong Studios, no data-protection-relevant processing takes place on our part in this respect. Transmission to the server you choose serves the performance of your relationship with its operator (Art. 6(1)(b) GDPR); the operator is the controller in that respect. If you contact us voluntarily, we process your details solely to handle your request (Art. 6(1)(b) and (f) GDPR).
6. Newsletter
6.1 Sign-up and double opt-in: On our website you can subscribe to our free newsletter, through which we keep you informed about our apps, games, and books. Sign-up uses the double opt-in procedure: after you register, we send an email to the address you provided asking you to confirm via a link. Only after this confirmation do we add you to the mailing list. If you don’t confirm, we send you nothing; unconfirmed sign-ups are deleted once no longer needed. This prevents someone from signing up with an email address that isn’t theirs.
6.2 Data processed: For sending the newsletter we process your email address. As proof of sign-up, we also log the times of registration and confirmation and the IP address used during registration. No further details are required.
6.3 Purpose and legal basis: The legal basis for processing is your consent under Art. 6(1)(a) GDPR. Logging the sign-up serves as proof of consent (Art. 7(1) GDPR) and is based on our legitimate interest in legally compliant mailing (Art. 6(1)(f) GDPR).
6.4 Withdrawal and unsubscribing: You can withdraw your consent at any time with future effect and unsubscribe. Just click the unsubscribe link in any newsletter email, or write to us informally at office@ostrongstudios.de. The lawfulness of processing carried out before withdrawal is unaffected.
6.5 Retention period: We store your data for as long as you are subscribed. After you unsubscribe, we remove your email address from the active mailing list. To prove the consent given and to prevent unwanted re-sending, we may retain the details in a limited form beyond that until you object to further storage.
6.6 Sending and disclosure: Our newsletter is sent via the email server of our provider STRATO AG (Pascalstraße 10, 10587 Berlin, Germany; smtp.strato.de). STRATO processes the transmitted data solely for the purpose of sending, on our behalf as a processor, on the basis of a data processing agreement under Art. 28 GDPR. Processing takes place within the European Union. We do not use any external newsletter or tracking service, and we do not share your data with third parties for advertising purposes.
7. Status and changes
This privacy policy is dated June 2026. We reserve the right to adapt it if our services change or legal requirements change. The current version is always available at https://ostrongstudios.de/privacy-policy.
© 2026 Ostrong Studios