Privacy policy
What this site knows about you
Almost nothing, and that is not a slogan. We set no cookies, run no analytics, load no tracking pixels and embed no third-party content. Reading these pages leaves nothing behind but the web server's own log, which we cannot see. The one exception is deliberate on your part: a feedback form you may choose to submit.
Controller
The controller for data processing on this site within the meaning of the GDPR is:
Kai JaekelAm Bisberg 8
78250 Tengen
Email: kai.jaekel@outlook.com
Full contact details are in the Impressum.
What happens when you open a page
The site is hosted on Cloudflare Pages, a service of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare delivers it from a global network, so the request is answered by whichever data centre is nearest to you — which may be inside or outside the European Union. Each time a page is requested, technical data is recorded in a log file: typically the requesting IP address, the date and time, the page requested, the referring page, and the browser and operating system identifiers your browser sends.
This happens on the host's infrastructure, not ours. We have no access to these logs, cannot read them, and cannot delete individual entries. Cloudflare processes this data on our behalf as a processor within the meaning of Art. 28 GDPR, under a data processing agreement. How long the data is kept is governed by Cloudflare's privacy policy.
The legal basis is Art. 6 (1) (f) GDPR. The legitimate interest is the technically necessary delivery of the site and its protection against attack; a web server cannot answer a request without processing the requesting address.
Transfer to the United States
Because the host is a US company, personal data may be processed in the United States. Cloudflare self-certifies under the EU–U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision under Art. 45 GDPR; transfers on that basis do not require additional safeguards. Note that US authorities may have access rights that go beyond what EU law would permit, and that this residual risk cannot be ruled out entirely.
What this site deliberately does not do
- We set no cookies — not for analytics, not for preferences, not at all. Nothing on this site writes one. The only cookie you may encounter is a security cookie from the host, described under “Why there is no cookie banner” below.
- No analytics or statistics service is used. There is no Google Analytics, no Plausible, no Matomo, no counting pixel.
- No content is loaded from third parties. No web fonts, no embedded videos, no maps, no social media buttons. Every file the page needs comes from this domain, so opening a page tells no company anything beyond the host that serves it.
- Nothing runs in your browser. There is no program code on this site at all — not a
single
scriptelement on any page, inline or external. - Nothing is stored on your device — no local storage, no session storage, no fingerprinting.
You can verify all of this rather than take our word for it: open your browser's network tab and reload. Every request goes to this domain, and there are no others. The cookie list will show either nothing at all or the host's security cookie.
Why there is no cookie banner
Under § 25 TDDDG, consent is needed before anything is stored on your device or read from it — and that covers far more than cookies: local storage, session storage, device fingerprinting, all of it. The obligation is triggered by the storing or reading, not by the technology, which is why so many sites that call themselves cookie-free still ask.
This site stores nothing and reads nothing. It sets no cookie, local and session storage stay empty, there is no service worker, and nothing on the page can write to your device because nothing on the page runs.
One thing is not ours to promise: Cloudflare, which delivers the site, may set a cookie
of its own for attack detection — typically named __cf_bm, and
cf_clearance if you are ever shown a security check. Whether it appears at
all depends on the protection settings on the account. Such a cookie serves only to
keep the site reachable and to tell human visitors from automated traffic; it measures
nothing, follows you nowhere, and is not used to build a profile. Storage that is
strictly necessary to deliver the service you asked for is exempt from the consent
requirement under § 25 (2) TDDDG, which is why it does not change the answer here.
So there is nothing to consent to. A consent banner would have nothing to ask about, and there is none.
The light or dark appearance is the one thing that might have needed remembering. It does not: the stylesheet simply follows the setting your operating system already reports, and never records what it saw.
The server log described above is a separate matter. It is unavoidable — no web server can answer a request without the requesting address — and it falls under the GDPR, which requires that we tell you about it, not that we ask permission for it.
If you use the feedback form
Two pages carry a form asking whether an app we are considering would be worth building. Submitting it is entirely voluntary and nothing happens unless you press one of its buttons.
What is stored when you do: which of the two buttons you pressed, the star rating if you chose one, the text you typed if you typed any, the language of the page, which of the two pages you submitted from, and the date and time. That is the whole record. No IP address, no browser identifier, no cookie, no identifier of any kind is attached to it, and the entries are not linked to each other or to anything else.
The data is stored by Cloudflare — the same processor that hosts the site, under the same agreement — in a key-value store. The legal basis is Art. 6 (1) (f) GDPR: the legitimate interest is finding out whether a piece of software is worth building before building it. We keep the answers until that question is decided, and delete them afterwards.
Because nothing in an entry identifies you, we cannot find yours again either. Under Art. 11 GDPR the rights of access, rectification and erasure do not apply to data a controller cannot link to a person — so please do not put your name, address or any other personal detail into the free-text box. If you want a reply, write to us by email instead; that we can answer.
If you write to us
The site has no contact form. If you send email to the address above, your message and the address it came from are processed for the sole purpose of answering you. The legal basis is Art. 6 (1) (f) GDPR, and Art. 6 (1) (b) GDPR where your message concerns a prospective agreement. We keep such correspondence only as long as the matter requires, and delete it once it is settled and no retention obligation applies.
Your rights
Under the GDPR you have the right to obtain confirmation of whether data concerning you is processed and to access it (Art. 15), to have inaccurate data corrected (Art. 16), to have data erased (Art. 17), to have processing restricted (Art. 18), to receive your data in a portable format (Art. 20), and to object at any time to processing based on legitimate interests (Art. 21).
In practice, the only data reachable through such a request is email you have sent us — we hold nothing else about visitors. You also have the right to lodge a complaint with a supervisory authority (Art. 77), normally the data protection authority of the German state in which the controller is established.
No automated decision-making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place on this site.
Changes
The feedback form described above was added under exactly this rule: the policy was written before the form went live. If the site gains another feature that processes data — a newsletter, an App Store link that measures clicks — the same applies.