Amelus Logoamelus
  • WorkflowBuddy
  • Deutsch
  • Français
  • Español

Privacy Policy

WorkflowBuddy – n8n Companion App for iOS
Last updated: March 26, 2026

1. Overview

WorkflowBuddy is an iOS companion app for n8n workflow automation. It lets you monitor your n8n workflows, receive push notifications when workflows fail, and manage your automations on the go.

Responsible party:
Amelus UG (haftungsbeschränkt)
Email: apple@amelus.de
Website: amelus.de

2. What Data We Process

2.1 Data Stored Locally on Your Device

The following data is stored exclusively on your iPhone and never leaves your device unless explicitly described in Section 2.2:

  • n8n API keys – stored in the iOS Keychain (hardware-encrypted, accessible only when your device is unlocked)
  • HMAC authentication secret – stored in the iOS Keychain, used to sign requests to our backend
  • Chat endpoint credentials – stored in the iOS Keychain
  • Instance URL and instance ID – stored in UserDefaults to remember your active n8n connection
  • App preferences – onboarding status, biometric lock setting, notification preferences
  • Monitoring rule cache – a local copy of your monitoring rules for background sync
  • Usage counter – a simple counter for when to show the App Store review prompt (no behavioral tracking)
  • Error log – recent API errors for debugging, stored locally, limited to 100 entries

2.2 Data Sent to Our Companion Backend

To provide push notifications when your n8n workflows fail, we operate a backend server at companion.amelus.de. When you enable monitoring, the following data is transmitted to and stored on this server:

DataPurposeStorage
APNs Device TokenIdentifies your device for push notification deliveryStored until you deregister
n8n Instance URLSo our server can poll your n8n instance for workflow failuresStored until you deregister
n8n API KeyTo authenticate with your n8n instance on your behalfAES-256-GCM envelope-encrypted at rest
HMAC SecretTo verify that requests come from your deviceStored per device
Workflow IDs and NamesTo identify which workflows to monitor and to display names in notificationsStored as part of monitoring rules
Monitoring ConfigurationCheck interval, quiet hours, error notification preferenceStored as part of monitoring rules
Subscription TierTo enforce free/premium rule limits on the serverStored per device (“free” or “premium”)

Important: Our backend does not store your n8n workflow data, execution results, or any content processed by your workflows. It only checks whether executions succeeded or failed.

2.3 Data Shared with Apple

  • APNs Device Token – Apple Push Notification service requires a device token to deliver push notifications. This token is generated by Apple and does not contain personal information.
  • StoreKit Subscription Data – When you subscribe to WorkflowBuddy Premium, the transaction is processed entirely by Apple. We receive only the subscription status (active/expired) and product ID. We do not receive your name, Apple ID, or payment details.

2.4 Data Sent to Your n8n Instance

WorkflowBuddy communicates directly with the n8n instance URL you provide, using the API key you supply. This communication includes:

  • Fetching workflow lists and execution history
  • Activating or deactivating workflows
  • Triggering webhooks
  • Sending chat messages to n8n chat endpoints

This communication happens directly between your device and your n8n server. We have no access to this data. You are responsible for securing your n8n instance.

3. Why We Process This Data (Legal Basis)

Under the EU General Data Protection Regulation (GDPR), we process your data based on:

  • Contract performance (Art. 6(1)(b) GDPR): Processing the data listed in Section 2.2 is necessary to provide the monitoring and push notification service you requested.
  • Legitimate interest (Art. 6(1)(f) GDPR): Storing an error log and usage counter on your device to maintain app quality and decide when to show a review prompt.

We do not process data based on consent for any purpose not directly tied to app functionality. We do not profile you.

4. How We Protect Your Data

  • Encryption in transit: All communication between the app, our backend, and your n8n instance uses HTTPS/TLS.
  • Encryption at rest: Your n8n API key is stored on our backend using AES-256-GCM envelope encryption with a server-side master key. On your device, credentials are stored in the iOS Keychain with hardware-backed encryption.
  • Request authentication: Every request from the app to our backend is signed with HMAC-SHA256 to prevent tampering and replay attacks. Timestamps are validated with a 5-minute window.
  • SSRF protection: Our backend validates all instance URLs against SSRF attacks before making any requests.
  • Minimal data: We store only what is strictly necessary for the monitoring service to function.

5. Data Deletion

You can delete all your data from our backend at any time:

  • Per instance: Remove an n8n instance from the app. This sends a deregistration request that deletes all monitoring rules and encrypted credentials for that instance from our server.
  • All data: Delete the app. Without a valid device token, our backend can no longer reach your device. Orphaned data is cleaned up during routine maintenance.
  • Manual request: Email apple@amelus.de to request complete deletion of all data associated with your device.

Data stored locally on your device (Keychain, UserDefaults) is deleted when you uninstall the app.

6. No Sharing with Third Parties

We do not sell, rent, or share your data with any third party. The only external services involved are:

  • Apple Push Notification service (APNs): For delivering push notifications.
  • Apple StoreKit: For processing in-app subscriptions.

Both are operated by Apple Inc. and subject to Apple’s privacy policy.

7. No Tracking or Analytics

WorkflowBuddy does not include any analytics SDKs, tracking pixels, advertising frameworks, or crash reporting services. We do not track your behavior, create user profiles, or collect usage analytics. The “Analytics” feature in the app displays statistics fetched directly from your own n8n instance – this data never passes through our servers.

8. Children

WorkflowBuddy is not intended for children under the age of 16. We do not knowingly collect data from children.

9. Contact

For questions about this privacy policy or to exercise your rights under GDPR (access, rectification, deletion, data portability, restriction, objection):

Amelus UG (haftungsbeschränkt)
Email: apple@amelus.de

You also have the right to lodge a complaint with a data protection supervisory authority.

10. Changes to This Policy

We may update this privacy policy when the app’s data processing changes. The date at the top of this page indicates when the policy was last updated. Continued use of the app after changes constitutes acceptance.

© 2026 Amelus UG. All rights reserved. · Imprint · Privacy Policy