Privacy

Privacy Policy

Last updated: 31.01.2026

Protecting your personal data is very important to us. This privacy policy informs you in accordance with Articles 13 and 14 of the GDPR about what personal data we collect, for what purposes we process it, the legal basis for processing, and what rights you have.

1. Data Controller and Data Collection

The data controller is Manuel Beutel, Bergerstraße 12, 82024 Taufkirchen, Germany ([email protected]). We collect the following personal data: • Account data: Email address and encrypted password upon registration (Art. 6(1)(b) GDPR – contract performance) • Usage data: Information about how you use our service, IP address, timestamps (Art. 6(1)(f) GDPR – legitimate interest in service improvement) • Payment data: Processed exclusively by our payment service provider Stripe (Art. 6(1)(b) GDPR) • Feedback data: Content submitted by your users, screenshots, and technical information such as browser, operating system, and viewport size (Art. 6(1)(b) GDPR)

2. Purpose of Data Processing

We process your data exclusively for the following purposes: • Provision, operation, and improvement of our SaaS service • Communication regarding your account and support requests • Billing and payment processing through our payment service provider • Compliance with legal retention and documentation requirements • Protection against misuse and ensuring system integrity Your data will only be shared with third parties where necessary for contract performance or where you have given explicit consent.

3. Data Storage and Retention Periods

All data is stored exclusively on servers in the European Union. We use Supabase as our database provider with server location in Frankfurt am Main, Germany. Retention periods: • Account data: For the duration of the active contractual relationship, then deletion within 30 days • Billing data: 10 years in accordance with commercial and tax law retention requirements • Feedback data: According to your selected plan (3 months to unlimited depending on plan) • Server logs: Maximum 7 days for security purposes

4. Cookies and Local Storage

We use exclusively technically necessary cookies and local storage for: • Authentication and session management (essential for service operation) • Language preferences for user interface personalization These cookies are essential for service operation and therefore do not require consent. We do not use tracking cookies, advertising cookies, or third-party analytics tools.

5. Data Processors and Third Parties

We work with the following carefully selected data processors: • Hostinger International Ltd. (Server hosting) – EU company based in Lithuania, GDPR compliant • Supabase Inc. (Database and authentication) – EU servers in Frankfurt, data processing agreement pursuant to Art. 28 GDPR in place • Stripe Inc. (Payment processing) – GDPR compliant, certified under EU-US Data Privacy Framework All third parties meet the requirements of the GDPR. We have concluded appropriate data processing agreements (DPA) with each processor.

6. Your Rights Under GDPR

You have the following rights: • Right of access (Art. 15 GDPR): Learn what data we store about you • Right to rectification (Art. 16 GDPR): Have incorrect data corrected • Right to erasure (Art. 17 GDPR): Request deletion of your data • Right to restriction (Art. 18 GDPR): Request restriction of processing • Right to data portability (Art. 20 GDPR): Receive your data in a machine-readable format • Right to object (Art. 21 GDPR): Object to the processing of your data • Right to complain (Art. 77 GDPR): File a complaint with the relevant supervisory authority (Bavarian Data Protection Authority)

7. Contact and Data Protection Inquiries

If you have questions about data protection, wish to exercise your data subject rights, or have complaints, you can contact us at any time. We will process your request promptly, but no later than within one month.