Privacy Policy

Effective date: 20 June 2026 Β· Updated: 12 July 2026 (payment processing via Merchant of Record)

1. Controller

Nedim Agic, sole proprietor (Einzelunternehmen, trading as United DigiArt Vision), Krossensee 2a, 91361 Pinzberg, Germany. Contact: [email protected]. A Data Protection Officer is not named β€” not legally required for an operation of this size.

2. What we process, why, and on what legal basis

We keep data minimal. The Service deliberately uses no CAPTCHAs and no behavioral/ad tracking.

DataWhenPurposeLegal basis (GDPR Art. 6(1))
Email addressEmail signupCreate/verify the account, send the verification link, account recovery, service notices(b) performance of contract
GitHub identity (numeric id + username)GitHub signup (OAuth)Create/link the account(b) performance of contract. We request only the read:user scope and store only your GitHub id and username β€” we do not read or store your GitHub email
API keysAccount useAuthenticate your requests(b). Stored only as a sha256 hash of a high-entropy random secret β€” we cannot recover the raw key
IP addressEvery requestRate limiting, abuse prevention, security(f) legitimate interest (protecting the Service and third parties)
Usage metadata (deploy timestamps, counts, tier)DeployingEnforce quotas, operate the Service(b) and (f)
Submitted content / code ("Your Content")DeployingBuild, run, and serve your app(b). Ephemeral β€” see Β§5
Server logsOperationSecurity, debugging, abuse handling(f)
Abuse-report contact (optional email + reason)If you submit an abuse reportInvestigate and act on the report(f) legitimate interest (protecting the Service and third parties)
Billing metadata (Paddle customer id, subscription id, plan, subscription status, renewal date)Paid subscriptionProvision the paid tier, apply billing status (renewal, dunning, cancellation)(b) performance of contract. We never receive or store card or bank details

We do not sell personal data and do not use it for advertising.

3. Email delivery

Verification and service emails are sent through Resend (Resend, Inc.) acting as our processor, under a data-processing agreement (GDPR Art. 28). We use Resend's EU sending region (Ireland, eu-west-1); the provider processes your email address and the message to deliver it. Resend, Inc. is US-incorporated β€” we rely on the EU Standard Contractual Clauses for any transfer.

4. Hosting

The Service runs on servers operated by Hetzner Online GmbH (Germany, EU), our hosting processor under a data-processing agreement. Data is processed in the EU.

5. Retention

6. Recipients / processors

A current list of processors is available on request. We do not otherwise share personal data, except where legally required or to respond to lawful requests.

Payment processing

Paid plans are processed by Paddle as Merchant of Record (seller of record). When you buy a plan, Paddle collects and processes your payment and billing data (including payment method, billing address, tax information) as its own responsibility as seller of record; see Paddle's privacy policy. Paddle shares with us only the billing metadata listed in Β§2 (never card details). We send Paddle a pseudonymous account reference so the purchase can be linked to your account.

If your account-owned deployments approach inactivity expiry, we send a one-time service notice to your account email (legal basis: performance of contract). This is not marketing.

7. International transfers

Our processors Resend, Inc. and Cloudflare, Inc. are US-incorporated; we rely on the EU Standard Contractual Clauses (with supplementary measures as appropriate) under their respective data-processing agreements. Resend email sending is configured to the EU (Ireland) region, and Hetzner hosting is in the EU.

8. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (16), erasure (17), restriction (18), data portability (20), and to object to processing based on legitimate interest (21). To exercise them, contact [email protected]. You also have the right to lodge a complaint with a supervisory authority β€” for Bavaria (the controller's state) this is the Bayerisches Landesamt fΓΌr Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Where we rely on consent, you may withdraw it at any time with future effect.

9. Automated decision-making

We do not carry out automated decision-making producing legal or similarly significant effects (GDPR Art. 22). Quota enforcement is a simple technical limit, not a profiling decision.

10. Cookies / tracking

openpouch's own application sets no cookies β€” the GitHub-login CSRF check uses a short-lived value handled server-side and passed in the redirect URL, not a cookie. The openpouch.dev landing page sets no cookies and runs no analytics/tracking (static page). Our CDN/proxy (Cloudflare) may set strictly necessary cookies for security and load balancing; we use no advertising or cross-site tracking cookies. A cookie banner is therefore not required; we will add one only if non-essential cookies are later introduced.

11. Changes

We may update this Policy; the effective date marks the current version, and material changes will be announced.

12. Contact

Nedim Agic, Krossensee 2a, 91361 Pinzberg, Germany Β· [email protected].

← Back to openpouch.dev