Back to legal

Privacy Policy

Last updated: May 26, 2026

1. Controller

Kristian Hoffmann, Karl-Kraut-Straße 15, 30177 Hannover, Germany. Contact: moin@kristianhoffmann.de.

2. Data we process

We process account metadata, organizations, clients, projects, briefing answers, required-item responses, uploaded file metadata, portal events, billing identifiers and support communication to provide the client portal workflow.

3. Hosting, database and code hosting

cluein.me runs entirely on our own server in Germany. The application, database, authentication and file storage all run on that single server. We use Supabase as software in a self-hosted installation; no data is transmitted to Supabase Inc. The infrastructure provider is Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus, acting as our processor under Art. 28 GDPR. Delivery produces technical server logs (IP address, timestamp, requested resource, user agent) which we retain for operational security (Art. 6(1)(f) GDPR). Source code is managed with GitHub, which receives development metadata only — no customer or portal content.

4. Portal privacy

Client portal access is scoped through hashed, expiring tokens. Raw portal tokens are not stored. IP addresses are hashed before audit logging where application logs are created.

5. AI briefing quality score

When a briefing is submitted, we optionally generate a quality score. For this, the content of the briefing is transmitted to an AI provider that returns a score and per-field feedback. The provider is Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA. Legal basis is Art. 6(1)(f) GDPR (our legitimate interest in assessing briefing completeness); for the transfer to the USA we rely on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR. The provider acts as a processor, does not use the content to train its models and deletes API inputs within 30 days. Organization owners can disable this feature entirely in the organization settings — no briefing content is then transmitted.

6. Reach measurement

We count page views on our own server to see how the site is used. No cookie is set and nothing is stored on your device, so this needs no consent (§ 25(2) TDDDG). We record the page path, the referring website's host name (never the full referring address), any campaign parameters in the link, a coarse device class and the time. Your IP address is not stored: it is combined with your browser identification, a secret server key and the current date and turned into a one-way hash. Because the date is part of it, that value changes every 24 hours and cannot be used to recognise you tomorrow or to link your visits over time. The data stays on our server in Germany, is not passed to anyone, and is deleted after 180 days. Legal basis is Art. 6(1)(f) GDPR (our legitimate interest in knowing whether our website reaches anyone). You can object at any time using the contact details in section 1.

In addition we offer Google Analytics 4 by Google Ireland Limited, but only after you actively consent. The Google Analytics tag is not loaded before consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). If you consent, Google may process page views, referrers, approximate location, device data and pseudonymous identifiers. Google states that GA4 does not log or store individual IP addresses. You can withdraw consent at any time; the measurement described in the paragraph above continues to work without it.

7. Payments and email delivery

For paid plans we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Payment details are entered directly with Stripe and are never stored on our servers; we retain only the Stripe customer and subscription identifiers and the plan status (Art. 6(1)(b) GDPR).

For transactional email (sign-in links, portal invitations, system notifications) we use Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany) as a processor under Art. 28 GDPR. Brevo receives the recipient address and the message content. No other email provider is in use, and no email data leaves the EU.

To limit abuse of client portal links we use Upstash, Inc. (Palo Alto, CA, USA) as a processor under Art. 28 GDPR. Upstash only ever receives a one-way hash of the requesting IP address together with a request counter — never the address itself, and no portal content. Counters expire after 60 seconds. Legal basis is Art. 6(1)(f) GDPR (our legitimate interest in protecting client data from brute-force access); the transfer to the USA is covered by EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.

8. Rights and retention

You may request access, rectification, deletion, restriction, portability and object to processing under the GDPR. Workspace data can be exported by organization owners. Deleted workspaces follow the documented read-only, soft-delete and hard-delete retention schedule.

9. Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

Analytics consent

We use Google Analytics only after consent to understand reach and product usage.