Privacy Policy

Version: 29 July 2025

Data Controller
Raphael Nußbaumer BSc (Sole Proprietor)
Sohlstraße 3, 6845 Hohenems, Austria
Email: raphaeln@outlook.com


1. Collection and Use of Personal Data

We collect and process the following personal data:

Data Category Purpose Legal Basis
Email Address Registration, sending login codes (passwordless login) Art. 6(1)(b) GDPR (Contract)
Timestamps (Creation, Synchronization) Device synchronization and version management of notes, files, images, and videos Art. 6(1)(b) GDPR (Contract)
IP Address (temporary, non-persistent) Rate limiting and protection against overload Art. 6(1)(f) GDPR (Legitimate Interest)
Session Cookie (only during login) Maintaining the session Art. 6(1)(b) GDPR (Contract)
hCaptcha Data Prevention of automated registration and login attempts; collection of IP address, interaction data (e.g., mouse movements, click patterns), and HTTP headers Art. 6(1)(f) GDPR (Legitimate Interest)
Notes, Files, Images, Videos (encrypted) Storage, synchronization, and display in the PWA (notes: max. 1 MB, Render/AWS, Frankfurt; files/images/videos: max. 100 MB, Wasabi Hot Cloud, Frankfurt) Art. 6(1)(b) GDPR (Contract)

Note: No tracking, user-agent logging, error reporting, or performance monitoring takes place.


2. Data Retention Period


3. Data Sharing & Data Processors

We use the following data processors, with whom contracts pursuant to Art. 28 GDPR have been concluded:

  1. Hosting & Infrastructure
    • Render.com (AWS, Frankfurt) for storing notes (max. 1 MB).
    • Wasabi Hot Cloud (Frankfurt) for storing files, images, and videos (max. 100 MB).
  2. Email Delivery
    • Mailjet
  3. Bot Protection
    • hCaptcha Inc. (collection of IP address, interaction data such as mouse movements and click patterns, and browser header information for bot prevention)
  4. No additional data processors are used in the free basic service.

4. Cookies & Local Storage


5. Security & Encryption


6. Data Subject Rights

You may exercise the following rights at any time by emailing raphaeln@outlook.com:

We will process requests within the statutory period (generally 1 month).


7. Export & Deletion


8. Notification of Data Breaches

In the event of a data breach (e.g., unauthorized access to personal data), we will promptly inform affected users via email about the incident, its impact, and the measures taken, in accordance with Art. 34 GDPR.


9. Austrian Data Protection Authority

You have the right to lodge a complaint with a supervisory authority. The competent authority is:
Austrian Data Protection Authority
Wickenburggasse 8, 1080 Vienna, Austria
Email: dsb@dsb.gv.at


10. Accessibility

If you have any questions or issues regarding the accessibility of this Privacy Policy or the PWA “ciphernotes,” please contact us at raphaeln@outlook.com.


11. Amendments to this Privacy Policy

We reserve the right to update this Privacy Policy as needed (e.g., due to new features or legal changes). Users will be informed of significant changes via email or a notice in the PWA. The current version is available at any time in the PWA under “Privacy.”