Privacy & operations
How we implement privacy
No seal, no marketing formula: here's where your data lives, what we don't do – and what we deliberately don't promise.
Where your data lives
On servers in Germany (Hetzner). We run the database self-hosted – there is no US cloud in your community's data path.
What we don't do
No ad tracking, no ads, no selling or sharing your data for advertising, no cross-site profiling. Your members are our users – not our product.
Sessions instead of trackers
For sign-in we use a strictly necessary first-party cookie (httpOnly, secure, sameSite) – no ad IDs, no third-party scripts in standard operation. Analytics is a switch, and ours is off by default.
Your data is yours
Export and deletion are built-in flows, not support tickets: full data export on request, full deletion including a prior snapshot so nothing disappears by accident.
Transport and access
Encrypted transport (TLS), separate keys for operations and migrations, server secrets never in the browser. Who sees what in your community is governed by roles – not by chance.
Data processing agreement
If you run a community with us, you are the controller and we process on your behalf. That requires a data processing agreement with us – talk to us and we'll sort it out before your community goes live.
What we deliberately don't promise
Others put seals here. We'd rather write down why there aren't any:
- “GDPR-compliant” as a blanket seal
- Compliance depends on your configuration, your legal texts and your processes – not on our software alone. We provide the technology for it; nobody can sell you the seal.
- “No cookie banner needed”
- Whether you need one depends on which services you enable on your site. In standard operation we set no advertising cookies – but that assessment belongs to your site, not to our marketing.
- “Daily backups, guaranteed recovery”
- We back up regularly. We'll publish a commitment on recovery time and maximum data loss only once a documented restore test stands behind it.