Privacy Policy

Note: The German version of this privacy policy is the legally binding version. This English translation is provided for convenience only.

Last updated: July 14, 2026

Controller

Mario Christ
c/o Impressumservice Dein-Impressum
Stettiner Str. 41, 35410 Hungen, Germany
Email: kontakt@unpii.me
Phone: +49 1551 0601763

What data we process

Account data: Email address, session tokens, hashed API keys, usage counters. No passwords are stored - authentication is via magic links or OAuth (Google, GitHub).

Server logs: IP addresses (pseudonymized/hashed for rate limiting), access timestamps, browser type. Logs are retained for up to 30 days.

Your text: Text submitted for anonymization is processed in memory only and immediately discarded. It is never stored, logged, or used for training.

Service providers

  • Hetzner Online GmbH (Germany) - server hosting. Privacy policy
  • Resend Inc. (USA) - transactional email (magic link delivery). Privacy policy. Transfer basis: Standard Contractual Clauses.
  • Cloudflare Turnstile (USA) - CAPTCHA / bot protection. Privacy policy. Transfer basis: Data Privacy Framework (DPF).
  • Google (Ireland/USA) - optional OAuth login. Privacy policy. Transfer basis: DPF.
  • GitHub (USA) - optional OAuth login. Privacy policy. Transfer basis: DPF.
  • Sentry (EU region, Frankfurt) - application error tracking. Data is stored exclusively in the EU. IP addresses are dropped before storage; request bodies, cookies, and query strings are filtered out before transmission. Privacy policy.
  • Paddle (Paddle.com Market Limited, 30 Old Bailey, London EC4M 7AU, UK; for customers in the EEA, Paddle Payments Limited, 42 Pearse Street, Dublin 2, D02 HV59, Ireland) - payment processing as Merchant of Record for paid plans (checkout, payment, invoicing, refunds). Full payment details (e.g. card numbers) are processed solely by Paddle and are never visible to us. Privacy policy.

Paid plans and payments

For paid plans we handle checkout, payment, invoicing, and refunds through an external payment processor acting as Merchant of Record (seller of record). Full payment details (e.g. card numbers) are processed solely by that provider and are never visible to us - we only receive the information needed to manage your contract and account, in particular subscription and payment status and a pseudonymous customer/subscription identifier. Contract and subscription data we hold is deleted upon account cancellation; invoicing and tax-related retention obligations lie with the Merchant of Record. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Cookies

We use only strictly necessary cookies: session cookies for authentication, plus a short-lived cookie (up to 30 minutes) to remember a successful security check for anonymous users. No consent banner is required for these.

Your rights

Under GDPR you have the right to access, rectify, delete, restrict, or port your data, and to object to processing. You may also lodge a complaint with a supervisory authority.

Supervisory authority:
Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 20459 Hamburg
https://www.datenschutz-hamburg.de

Deletion

Account data is deleted upon account cancellation. Encrypted backups are retained for up to 7 days, after which data from deleted accounts is also permanently removed. No statutory retention obligation applies to user data.