Privacy
Last updated 24 August 2026
Who is responsible
Andreas Oberdammer, Beerengasse 4, 4616 Weißkirchen an der Traun, Austria. Questions about your data: [email protected].
What we store on your device
Everything below is strictly necessary — it exists to deliver something you asked for, such as staying signed in. Under §165(3) TKG 2021 that does not require your consent, but you are entitled to know about it. We run no analytics, no advertising and no tracking pixels, so there is currently nothing optional to accept or refuse.
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
| __session, __client_uat, __clerk_db_jwt, clerk_active_context | Cookie | Clerk | Keeps you signed in and identifies your session. | Session to 1 year |
| ao-theme | localStorage | Telagate | Remembers whether you chose light or dark. | Until cleared |
| ao-consent | localStorage | Telagate | Would remember your cookie choice. Not created at present — there is nothing optional to decide about, so no banner is shown. | Until cleared |
Public pages — the link pages people share — set no cookies at all. If you only ever visit someone's page, nothing is stored on your device by us. Your IP address is still briefly handled on our server — see “Keeping the service usable” below.
Keeping the service usable
Every request to our API — including the one your browser makes to load someone's public page — is counted against a short-term limit, so that no single source can flood the service. Counting needs your IP address, which Cloudflare passes to us with the request. We use it for nothing else: it is held in memory on the server, never written to the database, never linked to an account, and discarded after two hours at the very latest. It is not used to identify you, to profile you, or to measure visitors. Legal basis: our legitimate interest in keeping the service available and resisting abuse (Art. 6(1)(f) GDPR).
What we hold in the database
If you create an account: your email address, an account identifier from Clerk, and whatever you put on your page — links, headings, your handle. If you subscribe: a subscription identifier, its status, and the brand and last four digits of your card. We never see or store your full card number. If you report a page: the report itself — which page, the reason, anything you wrote, and your email address if you chose to leave one for a confirmation. Reports are kept as long as moderation and legal obligations require (Art. 6(1)(c) and (f) GDPR, DSA Art. 16).
Who processes it
| Processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Clerk, Inc. | Authentication and session management | United States | EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA |
| Stripe, Inc. | Payment processing and invoicing. Where Stripe’s Managed Payments programme applies to a purchase, Stripe’s Link entity acts as merchant of record on the receipt and handles VAT. | United States | EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA |
| Hetzner Online GmbH | Application server and database | Germany | Processing within the EEA |
| Cloudflare, Inc. | Network routing (tunnel), DNS and image delivery (R2) | United States / EU edge | EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA |
| Functional Software, Inc. (Sentry) | Error monitoring — receives a report when something breaks: the page, browser type and the technical error trace. Configured to exclude IP addresses and identifiers. | United States (reports stored in the EU — Frankfurt) | EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA |
| Resend, Inc. | Transactional email — abuse-report confirmations and failed-payment notices. Nothing promotional; every mail is one you asked for or your subscription needs. | United States | EU–US Data Privacy Framework (self-certified), plus SCCs in its DPA |
When something breaks
If a page errors in your browser or on our server, a technical report goes to our error-monitoring service (Sentry, stored in Frankfurt): which page, which browser type, and the error trace. We have configured it not to record IP addresses or identifiers, it stores nothing on your device, and reports are deleted after 90 days. This is fault diagnostics, not analytics — nothing at all is sent while pages are working. Legal basis: our legitimate interest in keeping the service running (Art. 6(1)(f) GDPR).
Transfers to the United States
Clerk, Inc., Stripe, Inc., Cloudflare, Inc., Functional Software, Inc. (Sentry) and Resend, Inc. are US companies, so signing in, paying, loading pages, error reporting and receiving our emails involve transferring personal data outside the EEA. All are self-certified under the EU–US Data Privacy Framework, which the European Commission recognised as providing adequate protection in July 2023 (Decision (EU) 2023/1795).
You should know that this framework is under legal challenge: the EU General Court upheld it in September 2025, and an appeal is pending before the Court of Justice. Its predecessors, Safe Harbour and Privacy Shield, were both struck down. If the decision is annulled we will move to standard contractual clauses or to an EU-based provider, and say so here.
Your rights
You can ask for a copy of your data, correct it, delete it, restrict or object to its processing, and take it elsewhere. Deleting your account removes your page and its contents. Write to [email protected].
You can also complain to the Austrian Data Protection Authority (dsb.gv.at), or the authority where you live.
How long we keep it
Your account and page for as long as the account exists, then deleted. Payment records for as long as tax law requires — in Austria, seven years. Webhook logs for 90 days.