Datenschutzerklärung
Stand: 6. September 2026
1. Verantwortlicher
Verantwortlich im Sinne der DSGVO ist:
Aron Krössing
Papingastraße 12, 26386 Wilhelmshaven, Deutschland
E-Mail: [email protected]
2. Welche Daten wir verarbeiten
- Zugangsschutz (Site-Passwort, optionaler Notschalter): Die App
kann bei Bedarf - etwa zur kurzfristigen Missbrauchs- oder Kostenbegrenzung - mit
einem gemeinsamen Zugangspasswort geschützt werden. Ist dieser Notschalter aktiv,
wird nach Eingabe des Passworts ein Cookie (
hilfskoch_site_pw) gesetzt, das nur einen Hash-Wert des Passworts enthält - keinen Personenbezug, keine Kennung deiner Person. Gültigkeit: 30 Tage. Im Normalbetrieb ist dieser Notschalter nicht aktiv, die App ist frei zugänglich. - Benutzerkonto (optionale Registrierung): Wenn du dich mit
E-Mail-Adresse und Passwort registrierst, verarbeiten wir deine E-Mail-Adresse, ein
gehashtes Passwort, Zeitstempel sowie Sitzungs- und Erneuerungstoken bei unserem
Auftragsverarbeiter Supabase (siehe Punkt 4) - zum Zweck der Kontoführung,
Authentifizierung und des Versands der Bestätigungs- und Passwort-Reset-E-Mails.
Dein Browser spricht dabei nie direkt mit Supabase: jede Anfrage läuft ausschließlich
über unseren Server. Deine eingeloggte Sitzung wird über drei Cookies gehalten, alle
technisch notwendig (Art. 6 Abs. 1 lit. f DSGVO / Vertragserfüllung, keine
Einwilligung nötig, keine Tracking-Cookies):
hilfskoch_at(Zugriffstoken,HttpOnly),hilfskoch_rt(Erneuerungstoken,HttpOnly) undhilfskoch_signed_in(reiner Anzeige-Hinweis für die Oberfläche, nichtHttpOnly, enthält keine Zugangsdaten). Gültigkeit jeweils 30 Tage. - Bot-Schutz (Cloudflare Turnstile): Ist der Zugangsschutz (siehe oben) aktiviert, ist das Zugangs-Passwort-Formular durch Cloudflare Turnstile geschützt, das automatisierte Zugriffe von echten Nutzer:innen unterscheidet; dabei werden ein Challenge-Token sowie deine IP-Adresse an Cloudflare übermittelt. Derselbe Bot-Schutz wird unabhängig davon auch für die Registrierungs- und Passwort-Reset-Formulare des Benutzerkontos eingesetzt.
- App-Fortschritt (lokal im Browser): das zuletzt gewählte Rezept, der aktuelle Zubereitungsschritt sowie von dir angepasste Mengenangaben werden ausschließlich lokal in deinem Browser (localStorage) gespeichert, damit die App nach einem Neuladen dort weitermacht, wo du aufgehört hast. Diese Daten verlassen dein Gerät nicht und werden nicht an uns übertragen. Das gilt unverändert auch mit Benutzerkonto: Dein Fortschritt wird nicht mit dem Konto synchronisiert und nicht auf unseren Servern gespeichert.
- Offline-Funktion (Service Worker): App-Grundgerüst (HTML, Skripte, Icons, Rezeptdaten) wird über einen Service Worker im Browser zwischengespeichert, damit die App auch ohne Internetverbindung startet - rein lokal, keine Übertragung an uns.
- Frage-Funktion ("Torsten fragen"): nutzt du die Frage-Funktion, werden deine Frage sowie die Daten des gerade geöffneten Rezepts (Titel, Zutaten, Zubereitungsschritte, aktueller Schritt) zur Beantwortung an unseren KI-Dienstleister (siehe Punkt 4) übermittelt. Zur Missbrauchs- und Kostenbegrenzung zählen wir zusätzlich die Anfragen pro Anschluss in einem Zähler (Cloudflare D1). Deine IP-Adresse wird dafür nicht im Klartext gespeichert: Der Server bildet daraus einen SHA-256-Hashwert, gesalzen mit einem geheimen, ausschließlich serverseitig hinterlegten Wert; IPv6-Adressen werden vorher auf das /64-Präfix gekürzt, also auf den Bereich, den ein Anschluss zugeteilt bekommt, statt auf das einzelne Gerät. In der Datenbank stehen nur dieser Hashwert, das Datum und die Anzahl der Anfragen. Ohne Kenntnis des geheimen Werts lässt sich daraus keine IP-Adresse zurückrechnen; es handelt sich damit um eine Pseudonymisierung, nicht um eine Anonymisierung. Bist du mit einem Benutzerkonto eingeloggt, zählt deine Anfrage zusätzlich in einem eigenen Konto-Zähler statt im IP-Zähler; dafür wird deine Konto-ID mit demselben Verfahren gesalzen gehasht wie die IP-Adresse und ebenso nie im Klartext gespeichert. Nicht eingeloggte Anfragen zählen zusätzlich in einen gemeinsamen Anonym-Topf, unabhängig von deiner IP-Adresse. In der Datenbank stehen für all diese Zähler jeweils nur der Hashwert bzw. die Kennung des Topfes, das Datum und die Anzahl der Anfragen. Einträge, die älter als 2 Tage sind, werden beim nächsten Zugriff automatisch gelöscht - für alle diese Zähler gleichermaßen.
- Sprachausgabe (Vorlesen): Rezepttexte werden auf Wunsch über die im Browser eingebaute Sprachausgabe (Web Speech API) vorgelesen. Das läuft über die Funktion deines Browsers/Betriebssystems - wir übertragen dafür keine Daten an eigene Server oder Dritte.
- Server-Logs: unser Hosting-Anbieter Cloudflare Pages zeichnet wie jeder Webserver bei jedem Aufruf technisch bedingt IP-Adresse, User-Agent und Zeitstempel in kurzfristigen Zugriffslogs auf, zur Erkennung von Angriffen und zur Betriebssicherheit (Art. 6 Abs. 1 lit. f DSGVO, berechtigtes Interesse). Es erfolgt keine Auswertung zu Analyse- oder Marketingzwecken.
3. Zwecke und Rechtsgrundlagen
- Bereitstellung der App-Funktionen (Rezeptführung, Frage-Funktion) - für Inhaber:innen eines Benutzerkontos Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung), für die Nutzung ohne Benutzerkonto Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an einem funktionierenden Betrieb).
- Optionaler Zugangsschutz (Notschalter, siehe Punkt 2) sowie Missbrauchs- und Kostenbegrenzung der Frage-Funktion - Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse).
- Bereitstellung und Verwaltung des optionalen Benutzerkontos (Registrierung, Anmeldung, Passwort-Rücksetzung, Kontolöschung) - Art. 6 Abs. 1 lit. b DSGVO (Vertragserfüllung), hilfsweise Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse), solange kein Vertrag zustande gekommen ist.
- Sicherheit und Betrieb des Dienstes - Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse).
4. Hosting und Dienstleister (Auftragsverarbeiter)
Zur Bereitstellung von Hilfskoch Torsten setzen wir folgende Dienste ein:
- Cloudflare Pages (Cloudflare, Inc., USA) - Hosting der Webseite sowie der serverseitigen Funktionen (Zugangsschutz, Frage-Funktion, Rate-Limit-Zähler).
- Anthropic (Anthropic, PBC, USA) - Beantwortung deiner Fragen über deren API im Rahmen der Frage-Funktion ("Torsten fragen"). Übermittelt werden deine Frage sowie die Rezeptdaten des aktuell geöffneten Rezepts, ausschließlich zum Zweck der Beantwortung dieser einen Anfrage. Laut Anthropics aktuellen Commercial-API-Bedingungen werden über die API gesendete Daten nicht zum Training von Modellen verwendet.
- Supabase (Supabase Pte. Ltd, 65 Chulia Street, Singapur) - Verwaltung von Benutzerkonten und Authentifizierung für das optionale Benutzerkonto, einschließlich der Auslösung der Bestätigungs- und Passwort-Reset-E-Mails, die über den nachstehend genannten Versanddienst zugestellt werden. Gespeicherte Daten: E-Mail-Adresse, gehashtes Passwort, Zeitstempel sowie Sitzungs- und Erneuerungstoken. Dein Browser kommuniziert dabei zu keinem Zeitpunkt direkt mit Supabase - jede Anfrage läuft ausschließlich über unseren Server, der die Zugriffs- und Erneuerungstoken serverseitig verwaltet; es besteht keine unmittelbare Verbindung von deinem Browser zu einem Drittanbieter.
- Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) - Zustellung der Bestätigungs- und Passwort-Reset-E-Mails des Benutzerkontos. Übermittelt werden deine E-Mail-Adresse sowie der Inhalt der jeweiligen E-Mail einschließlich des darin enthaltenen Bestätigungs- bzw. Reset-Links; hinzu kommen Zeitpunkt und Zustellstatus des Versands. Die Versand-Infrastruktur ist auf die EU-Region Irland eingestellt, das Unternehmen selbst sitzt jedoch in den USA - wir gehen daher von einer Drittlandsübermittlung aus (siehe Punkt 5). Ohne Benutzerkonto wird an diesen Dienst nichts übermittelt.
Mit allen vier Dienstleistern besteht ein Vertrag über Auftragsverarbeitung nach Art. 28 DSGVO - bei Supabase als gesondert unterzeichnetes Data Processing Addendum, bei Cloudflare, Anthropic und Resend jeweils als Bestandteil der von uns akzeptierten Nutzungsbedingungen. Alle vier sehen für Übermittlungen in Drittländer Standardvertragsklauseln der EU-Kommission vor (Art. 46 DSGVO, siehe Punkt 5).
Zusätzlich bei der optionalen Vorlese-Funktion: Für die natürliche Vorlesestimme lädt dein Browser die benötigten Programmbausteine und das Sprachmodell (zusammen rund 100 MB) direkt von externen Content-Delivery-Netzwerken; diese Dateien sind zu groß, um von uns selbst ausgeliefert zu werden. Beteiligt sind:
- huggingface.co (Hugging Face, Inc., 20 Jay Street, Suite 620, Brooklyn, NY 11201, USA; EU-Niederlassung: Hugging Face SAS, Paris) - das Sprachmodell der Stimme.
- cdn.jsdelivr.net (Volentio JSD Limited, registriert in England und Wales) - die Laufzeitumgebung der Sprachsynthese (onnxruntime-web und piper-phonemize). Die Auslieferung erfolgt laut Anbieter über wechselnde Netzwerkpartner, unter anderem Cloudflare, Fastly, Bunny und Gcore.
- esm.sh - ein einzelnes Programmmodul der Laufzeitumgebung. Der Dienst wird als quelloffenes Projekt einer Einzelperson betrieben und über Cloudflare ausgeliefert; ein verantwortlicher Rechtsträger und eine eigene Datenschutzerklärung sind für uns nicht auffindbar. Wir weisen hierauf ausdrücklich hin, weil wir insoweit keine belastbaren Angaben zum dortigen Umgang mit Zugriffsdaten machen können.
Beim Abruf dieser Dateien wird - wie bei jedem Abruf einer Datei aus dem Internet - deine IP-Adresse an den jeweiligen Anbieter übertragen, dazu technische Angaben deines Browsers. Inhalte aus der App werden dabei nicht übermittelt: Der vorgelesene Text verlässt dein Gerät nicht, die Sprachausgabe wird vollständig lokal auf deinem Gerät berechnet. Diese Anbieter handeln nicht als Auftragsverarbeiter für uns, sondern sind für den Abruf datenschutzrechtlich eigenständig verantwortlich. Rechtsgrundlage für die Einbindung ist unser berechtigtes Interesse an einer funktionsfähigen, nach dem ersten Laden auch offline nutzbaren Sprachausgabe (Art. 6 Abs. 1 lit. f DSGVO). Der Abruf findet nur statt, wenn du die natürliche Stimme aktivierst, und wegen der lokalen Zwischenspeicherung im Regelfall nur einmal je Gerät. Aktivierst du sie nicht, wird an diese Anbieter nichts übermittelt.
Ein Benutzerkonto ist optional. Ohne Registrierung läuft die App wie bisher, ohne Nutzerkonto und ohne Nutzerprofil. Registrierst du dich, sind die serverseitigen Datenbanken der oben genannte Rate-Limit-Zähler (Cloudflare D1) sowie, bei Supabase, dein Benutzerdatensatz (E-Mail-Adresse, gehashtes Passwort, Zeitstempel, Sitzungen).
5. Übermittlung in Drittländer
Soweit Daten an Dienste mit Sitz bzw. Servern außerhalb der EU bzw. des EWR übermittelt werden (Cloudflare für das Hosting und Anthropic für die Frage-Funktion, beide USA; Resend für den E-Mail-Versand des Benutzerkontos, USA; Supabase für das optionale Benutzerkonto, Sitz in Singapur), erfolgt dies auf Grundlage von Standardvertragsklauseln (Art. 46 DSGVO) und, soweit für den jeweiligen Dienst einschlägig, des EU-US Data Privacy Framework.
Für die optionale Vorlese-Funktion (siehe Punkt 4) gilt gesondert: Das Sprachmodell wird bei einem Anbieter mit Sitz in den USA abgerufen (Hugging Face). Für den Abruf bei jsDelivr (Sitz Vereinigtes Königreich) besteht ein Angemessenheitsbeschluss der EU-Kommission (Art. 45 DSGVO). Bei esm.sh lässt sich mangels auffindbarem Rechtsträger nicht abschließend bestimmen, wo die Daten verarbeitet werden; die Auslieferung erfolgt über Cloudflare. Da es sich jeweils um einen reinen Dateiabruf durch deinen Browser handelt, beschränkt sich die Übermittlung auf deine IP-Adresse und technische Browserangaben. Aktivierst du die natürliche Vorlesestimme nicht, findet keine dieser Übermittlungen statt.
6. Speicherdauer
App-Fortschritt und Zugangs-Cookie bleiben, bis du sie in deinem Browser selbst löschst bzw. bis der Zugangs-Cookie nach 30 Tagen abläuft. Einträge des Rate-Limit-Zählers der Frage-Funktion - gespeichert wird dort nur der gesalzene Hashwert, siehe Punkt 2 - werden automatisch gelöscht, sobald sie älter als 2 Tage sind; das gilt gleichermaßen für Zählerzeilen, die auf deiner gesalzenen Konto-ID beruhen. Die drei Cookies deines Benutzerkontos (siehe Punkt 2) laufen nach 30 Tagen ab bzw. enden mit deiner Abmeldung. Dein Supabase-Benutzerdatensatz bleibt bestehen, bis du dein Konto selbst löschst (siehe Punkt 7).
7. Deine Rechte
Du hast nach der DSGVO das Recht auf:
- Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17),
- Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20),
- Widerspruch gegen die Verarbeitung (Art. 21),
- Beschwerde bei einer Aufsichtsbehörde (Art. 77).
Zur Ausübung deiner Rechte genügt eine E-Mail an die oben genannte Adresse.
Für ein Benutzerkonto steht zusätzlich eine Selbstbedienungs-Löschung im Konto
(/auth/account) zur Verfügung. Dabei werden dein Supabase-Benutzerdatensatz
samt aller aktiven Sitzungen unwiderruflich gelöscht (kein Soft-Delete, also keine
weiterhin vorhandene, nur deaktivierte Zeile) sowie die auf deiner gesalzenen Konto-ID
liegenden Zählerzeilen des Rate-Limit-Zählers entfernt. Fortschrittsdaten sind davon
nicht betroffen, da sie ausschließlich lokal auf deinem Gerät liegen und ohnehin nie bei
uns gespeichert werden (siehe Punkt 2).
8. Änderungen dieser Erklärung
Wir passen diese Datenschutzerklärung an, wenn sich die Rechtslage oder unsere Verarbeitung ändert. Es gilt jeweils die hier veröffentlichte Fassung.
Privacy Policy
Last updated: 6 September 2026
1. Controller
The controller under the GDPR is:
Aron Krössing
Papingastraße 12, 26386 Wilhelmshaven, Germany
Email: [email protected]
2. Data we process
- Access protection (site password, optional kill switch): the app
can, if needed - e.g. for short-term abuse or cost control - be protected by a
shared access password. When this kill switch is active, entering the password sets
a cookie (
hilfskoch_site_pw) that contains only a hash of the password - no personal reference, no identifier tied to you. Valid for 30 days. In normal operation this kill switch is not active and the app is freely accessible. - User account (optional registration): if you register with an
email address and password, we process your email address, a hashed password,
timestamps, and session/refresh tokens at our processor Supabase (see section 4) -
for account management, authentication, and sending the confirmation and
password-reset emails. Your browser never talks to Supabase directly: every request
goes exclusively through our server. Your signed-in session is held via three
cookies, all technically necessary (Art. 6(1)(f) GDPR / contract performance, no
consent required, no tracking cookies):
hilfskoch_at(access token,HttpOnly),hilfskoch_rt(refresh token,HttpOnly), andhilfskoch_signed_in(a plain display hint for the UI, notHttpOnly, contains no credentials). Each valid for 30 days. - Bot protection (Cloudflare Turnstile): when the access protection (see above) is active, the access-password form is protected by Cloudflare Turnstile, which distinguishes automated access from real users; this sends a challenge token and your IP address to Cloudflare. The same bot protection is used for the registration and password-reset forms of the user account, independently of that switch.
- App progress (local in your browser): the last recipe you selected, the current cooking step, and any quantities you've edited are stored exclusively in your browser (localStorage) so the app resumes where you left off after a reload. This data never leaves your device and is not sent to us. This stays true with a user account as well: your progress is not synced to the account and not stored on our servers.
- Offline feature (service worker): the app shell (HTML, scripts, icons, recipe data) is cached in your browser via a service worker so the app also starts without an internet connection - purely local, nothing is sent to us.
- Ask feature ("Ask Torsten"): if you use the Ask feature, your question and the data of the currently open recipe (title, ingredients, steps, current step) are sent to our AI processor (see section 4) to generate an answer. To limit abuse and cost, we additionally count requests per connection in a counter (Cloudflare D1). Your IP address is not stored in the clear for this: the server derives a SHA-256 hash from it, salted with a secret value held only on the server side; IPv6 addresses are first shortened to their /64 prefix, i.e. to the range assigned to a connection rather than to the individual device. The database holds only that hash value, the date and the number of requests. Without the secret value, no IP address can be recovered from it; this is pseudonymisation, not anonymisation. If you are signed in with a user account, your request additionally counts in its own account counter instead of the IP counter; for this your account ID is salted and hashed the same way as the IP address, and is likewise never stored in the clear. Requests that are not signed in additionally count into a shared anonymous-total counter, independent of your IP address. For all of these counters, the database holds only the hash value or bucket identifier, the date and the number of requests. Entries older than 2 days are deleted automatically on the next request - for all of these counters alike.
- Voice output (read-aloud): recipe text can optionally be read aloud using your browser's built-in speech synthesis (Web Speech API). This runs through your browser/operating system's own feature - we do not transmit any data to our own servers or third parties for this.
- Server logs: like any web server, our hosting provider Cloudflare Pages technically records IP address, user agent and timestamp in short-lived access logs on every request, for attack detection and operational security (Art. 6(1)(f) GDPR, legitimate interest). These logs are not evaluated for analytics or marketing purposes.
3. Purposes and legal bases
- Providing the app's features (recipe guidance, Ask feature) - for holders of a user account, Art. 6(1)(b) GDPR (contract performance); for use without a user account, Art. 6(1)(f) GDPR (legitimate interest in a working service).
- Optional access protection (kill switch, see section 2) and abuse/cost limiting of the Ask feature - Art. 6(1)(f) GDPR (legitimate interest).
- Providing and managing the optional user account (registration, sign-in, password reset, account deletion) - Art. 6(1)(b) GDPR (contract performance), or alternatively Art. 6(1)(f) GDPR (legitimate interest) as long as no contract has yet come into being.
- Security and operation of the service - Art. 6(1)(f) GDPR (legitimate interest).
4. Hosting and processors
We use the following services to run Hilfskoch Torsten:
- Cloudflare Pages (Cloudflare, Inc., USA) - website hosting and the server-side functions (access protection, Ask feature, rate-limit counter).
- Anthropic (Anthropic, PBC, USA) - answering your questions via their API as part of the Ask feature ("Ask Torsten"). We send your question and the currently open recipe's data, solely to process that one request. Under Anthropic's current commercial API terms, data sent via the API is not used to train models.
- Supabase (Supabase Pte. Ltd, 65 Chulia Street, Singapore) - managing user accounts and authentication for the optional user account, including triggering the confirmation and password-reset emails, which are delivered by the sending service listed below. Data stored: email address, hashed password, timestamps, and session/refresh tokens. Your browser never communicates directly with Supabase at any point - every request goes exclusively through our server, which manages the access and refresh tokens server-side; there is no direct connection from your browser to this third-party service.
- Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) - delivering the user account's confirmation and password-reset emails. We transmit your email address and the content of the respective email including the confirmation or reset link it contains, along with the time and delivery status of the send. The sending infrastructure is configured for the EU region Ireland, but the company itself is based in the USA - we therefore treat this as an international transfer (see section 5). Without a user account, nothing is transmitted to this service.
A data processing agreement under Art. 28 GDPR is in place with all four providers - with Supabase as a separately signed Data Processing Addendum, with Cloudflare, Anthropic and Resend as part of the terms of service we accepted. All four provide for the European Commission's Standard Contractual Clauses (Art. 46 GDPR, see section 5) for transfers to third countries.
Additionally, for the optional read-aloud feature: to provide the natural reading voice, your browser downloads the required program components and the voice model (around 100 MB in total) directly from external content delivery networks; these files are too large for us to serve ourselves. The services involved are:
- huggingface.co (Hugging Face, Inc., 20 Jay Street, Suite 620, Brooklyn, NY 11201, USA; EU establishment: Hugging Face SAS, Paris) - the voice model itself.
- cdn.jsdelivr.net (Volentio JSD Limited, registered in England and Wales) - the speech synthesis runtime (onnxruntime-web and piper-phonemize). According to the provider, delivery runs via changing network partners, including Cloudflare, Fastly, Bunny and Gcore.
- esm.sh - a single program module of that runtime. The service is run as an open-source project by an individual and delivered via Cloudflare; we were unable to identify a responsible legal entity or a privacy policy of its own. We point this out explicitly because we cannot make any reliable statement about how access data is handled there.
When these files are fetched, your IP address is transmitted to the respective provider, along with technical details about your browser - as with any file retrieved over the internet. No content from the app is transmitted: the text being read aloud never leaves your device, and speech synthesis runs entirely locally on it. These providers do not act as processors on our behalf; they are independently responsible for the retrieval under data protection law. The legal basis for including them is our legitimate interest in a functioning read-aloud feature that works offline after the initial download (Art. 6(1)(f) GDPR). The retrieval only happens if you enable the natural voice, and thanks to local caching, generally only once per device. If you do not enable it, nothing is transmitted to these providers.
A user account is optional. Without registering, the app runs as before, with no user account and no user profile. If you do register, the server-side databases are the rate-limit counter described above (Cloudflare D1) and, at Supabase, your user record (email address, hashed password, timestamps, sessions).
5. International transfers
Where data is transferred to services based or hosted outside the EU/EEA (Cloudflare for hosting and Anthropic for the Ask feature, both USA; Resend for the user account's email delivery, USA; Supabase for the optional user account, based in Singapore), this is based on Standard Contractual Clauses (Art. 46 GDPR) and, where applicable to the service in question, the EU-US Data Privacy Framework.
A separate note for the optional read-aloud feature (see section 4): the voice model is retrieved from a provider based in the USA (Hugging Face). For the retrieval from jsDelivr (based in the United Kingdom), an adequacy decision by the European Commission applies (Art. 45 GDPR). For esm.sh, with no identifiable legal entity, we cannot conclusively determine where the data is processed; delivery runs via Cloudflare. As each case is a plain file retrieval by your browser, the transfer is limited to your IP address and technical browser details. If you do not enable the natural reading voice, none of these transfers take place.
6. Retention
App progress and the access cookie remain until you delete them in your browser yourself, or until the access cookie expires after 30 days. Entries in the rate-limit counter for the Ask feature - which holds only the salted hash value, see section 2 - are deleted automatically once they are older than 2 days; the same applies to counter rows keyed on your salted account ID. The three cookies of your user account (see section 2) expire after 30 days, or end when you sign out. Your Supabase user record remains until you delete your account yourself (see section 7).
7. Your rights
Under the GDPR you have the right to:
- access (Art. 15), rectification (Art. 16), erasure (Art. 17),
- restriction (Art. 18), data portability (Art. 20),
- object to processing (Art. 21),
- lodge a complaint with a supervisory authority (Art. 77).
To exercise your rights, simply email the address listed above.
For a user account, a self-service deletion is also available in the account
(/auth/account). This permanently deletes your Supabase user record along
with all active sessions (no soft delete - no row that merely stays disabled) and
removes the rate-limit counter rows keyed on your salted account ID. Progress data is
unaffected, since it lives exclusively on your device and is never stored with us in
the first place (see section 2).
8. Changes to this policy
We update this policy when the law or our processing changes. The version published here applies.