Privacy Policy

Version v6

In short

This is a private, non-commercial project. We process the minimum personal data needed to run a user account safely. We do not sell personal data, we do not share it for advertising, and we do not profile you or track you across other websites. Most of what we store is deleted automatically on a fixed schedule, and the exact periods are listed below.

Who is responsible

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

IMPRINT_SETUP_REQUIRED — the operator's name, postal address and contact email must be entered here before this service is made publicly available. The same details appear on the Imprint page.

We have not appointed a Data Protection Officer, because this service does not meet the criteria in Art. 37 GDPR. Data protection enquiries go to the contact address in the Imprint.

What kind of service this is

This service is operated privately and free of charge. It is not a commercial offering, there is no fee, no advertising, and no revenue derived from your data. This matters for your rights only in one direction: it does not reduce them. The GDPR applies to this service in full.

What data we process

Account data. Your email address, your username, your chosen language, and — if you set a password — a cryptographic hash of it. We never store your password itself. Hashing uses Argon2id, a current password-hashing algorithm, so the stored value cannot practically be reversed into your password.

Sign-in via Google or GitHub. If you choose to sign in with an external provider, we store the provider name, the account identifier that the provider issues for you, the email address the provider reports, and the time you last used that sign-in method. We never receive your password at the provider.

Session and device data. For every active sign-in we store a session record containing your IP address, your browser's user-agent string, a short human-readable device label derived from it, and the time the session was last seen. This exists so that you can review your active sessions and revoke any you do not recognise.

Security log. We keep an append-only log of security-relevant account events — sign-ins and failed sign-in attempts, password and email changes, two-factor changes, session revocations, and account deletion requests. Each entry records the event, the time, your IP address and your user-agent. This log is what allows you and us to detect a compromised account.

Two-factor authentication. If you enable it, we store your TOTP secret encrypted at rest, along with your recovery codes and the time of last use.

Push notifications. Only if you explicitly allow them in your browser: the push endpoint URL issued by your browser vendor and the two keys needed to encrypt messages to it.

Legal acceptance. Which version of this Privacy Policy, of the Terms of Service and of the Imprint you accepted, and when. We are required to be able to demonstrate consent and acceptance, and this is the minimum record that does it.

Legal bases

We process personal data only where Art. 6(1) GDPR provides a basis:

  • Performance of a contract, Art. 6(1)(b) — creating and operating your account, authenticating you, and delivering the service-related emails that account operation requires.
  • Legitimate interests, Art. 6(1)(f) — keeping the service secure and available: the security log, session records, rate limiting, and abuse prevention. Our interest is protecting the accounts on this service against takeover and abuse; we consider this proportionate because the data involved is limited, is not used for any other purpose, and is deleted on a short schedule.
  • Consent, Art. 6(1)(a) — optional cookies and push notifications. You can withdraw consent at any time, with effect for the future.
  • Legal obligation, Art. 6(1)(c) — where retention or disclosure is required of us by law.

Who receives your data

We do not sell personal data and we do not disclose it to third parties for their own purposes. Data reaches the following recipients only to the extent needed to operate the service:

  • Our hosting provider — a provider operating in Germany or elsewhere in the European Union, acting as a processor under a data processing agreement. All application data and the database are stored there.
  • Cloudflare — the sign-in and registration forms are protected against automated abuse by Cloudflare Turnstile. When you load one of those forms, your IP address and technical browser characteristics are transmitted to Cloudflare. This happens on the sign-in and registration pages regardless of whether you complete them.
  • Google and GitHub — only if you choose to sign in with one of them. In that case your interaction takes place with that provider under their own privacy policy, and we receive back the account data listed above.
  • Our email provider — an external mail delivery service transmits account emails such as confirmation and sign-in links. It receives your email address and the content of those messages.
  • Your browser vendor's push service — if you enabled push notifications, notification delivery runs through the push infrastructure of your browser vendor (for example Google, Mozilla or Apple).
  • OpenStreetMap Foundation — some pages available to signed-in users display a map. The map tiles are loaded by your browser directly from OpenStreetMap servers, which therefore receive your IP address. No map is loaded on pages that do not show one.
  • Amazon Web Services — data exports you request are generated into object storage before being made available to you for a short period.

Public authorities receive data only where we are legally obliged to provide it.

Transfers outside the EU

Our hosting and the database are located within the European Union. Some of the recipients above are US companies or may process data outside the EU. Where that is the case, the transfer is based either on an adequacy decision of the European Commission — including the EU-US Data Privacy Framework where the recipient is certified under it — or on the European Commission's Standard Contractual Clauses together with supplementary measures. You may request further information about the safeguards in place using the contact details in the Imprint.

Cookies and similar technologies

We use a session cookie that is strictly necessary to keep you signed in, and a cookie that records your cookie choice itself. Strictly necessary cookies do not require consent under Section 25(2) TDDDG. Anything beyond that is set only after you consent through the cookie banner, and you can change your choice at any time.

Your cookie choice is stored together with the version of this Privacy Policy that was in force when you made it. If we publish a materially updated policy, your earlier choice is treated as expired and you will be asked again, so that your consent always relates to the policy you actually saw.

How long we keep data

These periods are enforced automatically by scheduled jobs, not by manual review:

  • Security log entries — deleted 30 days after the event.
  • Session records — expire after 14 days; you can revoke any session yourself at any time.
  • Invitation and email-change confirmation links — expire after 7 days.
  • Pending two-factor sign-in state — expires after 60 seconds.
  • Generated data exports — deleted one hour after they are created.
  • Background job records — deleted after one hour.
  • Deleted accounts — when you delete your account it is immediately deactivated and becomes inaccessible. It is then permanently erased 30 days later, together with your sessions, sign-in identities, security log and any other data linked to it. The 30-day window exists so that an accidental or malicious deletion can still be reversed; you can cancel it yourself during that time.

Beyond this, we keep account data for as long as your account exists, and longer only where a statutory retention obligation requires it.

Your rights

Under the GDPR you have the right to access your data (Art. 15), to have inaccurate data corrected (Art. 16), to have your data erased (Art. 17), to have processing restricted (Art. 18), to receive your data in a portable, machine-readable format (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing carried out beforehand.

Two of these you can exercise immediately and without contacting us at all, in your account's privacy settings:

  • Access and portability — request a machine-readable export of your data, which is emailed to you as a download link. This can be done once per hour.
  • Erasure — delete your account yourself, subject to the 30-day reversal window described above.

For everything else, contact us using the details in the Imprint. We answer within the period set by Art. 12(3) GDPR.

Your right to complain

If you believe that our processing of your personal data infringes data protection law, you may lodge a complaint with a supervisory authority. You are free to choose the authority of the EU Member State of your habitual residence, your place of work, or the place where you believe the infringement occurred. Exercising this right costs you nothing and does not require you to contact us first.

How we protect your data

Traffic is encrypted in transit with TLS. Passwords are stored only as Argon2id hashes. Two-factor secrets are encrypted at rest. Sign-in attempts are rate limited to slow down automated attacks, and security-relevant events are logged so that account takeover can be detected. Access to the underlying systems is limited to the operator.

Minimum age

This service is not directed at children. You must be at least 16 years old to create an account. If we learn that an account belongs to a younger person, we will delete it.

Administrative AI and mapping features

The service contains AI and address-lookup features that are available only to administrators, not to ordinary users. Where an administrator uses them, the text and any files they submit are transmitted to Amazon Web Services in the eu-central-1 region (Frankfurt) for processing, and address lookups are sent to Google. No content belonging to an ordinary user account is transmitted to these services, and nothing you enter anywhere else in the service is sent to an AI model.

Automated decision-making

We do not use automated decision-making producing legal effects concerning you, and we do not carry out profiling within the meaning of Art. 22 GDPR.

Changes to this policy

We may update this policy when the service changes or the legal position does. Every version is numbered and archived; the version you are reading is shown at the top of this page. If a change is material, you will be asked to review and accept the new version the next time you sign in, and your cookie choice will be requested again.