Privacy Policy
treichel-labs.app
Last updated: July 28, 2026
The protection of your personal data is important to us. This privacy policy informs you about what data is collected when using treichel-labs.app, for what purpose and on what legal basis.
Table of contents
1. Controller
Controller within the meaning of the GDPR:
Ulf Treichel · treichel-labsDeepener Str. 17
27386 Hemslingen
kontakt@treichel-labs.app
2. Hosting & server logs
treichel-labs.app is operated on a private Virtual Private Server (VPS) physically located in Germany. No hosting data is transferred to third countries.
When the website is accessed, the web server (Apache 2.4) automatically records the following data in server log files:
- IP address of the requesting device
- Date and time of the request
- Page accessed (URL)
- HTTP status code and amount of data transferred
- Browser type, version and operating system
- Referrer URL (previously visited page, if transmitted)
This data is technically necessary to deliver the website and ensure server security (e.g. detecting attack attempts). It is not merged with other data sources and is not used to identify individuals.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable provision of the website). Logs are automatically deleted after a maximum of 7 days.
3. SSL/TLS encryption
This website uses SSL/TLS encryption for security reasons. This means that transmitted data cannot be read or manipulated by third parties. You can recognise an encrypted connection by the "https://" in the address bar of your browser.
4. Cookies
treichel-labs.app uses only one technically necessary session cookie, which does not require consent (§ 25(2) TTDSG). No marketing, tracking or analytics cookies are used.
| Name | Purpose | Lifetime | Provider |
|---|---|---|---|
PHPSESSID |
CSRF protection for the contact form; only set when the form is accessed | Session cookie – ends when browser closes | treichel-labs.app |
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the contact form).
5. Contact form
When you use the contact form, the following data is collected and processed to handle your enquiry:
- Name
- Email address
- Message content
- Selected subject (optional)
- Time of submission
This data is used exclusively to process your enquiry and is not passed on to third parties without your consent. After final processing, the enquiry is deleted unless statutory retention obligations apply.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in processing your enquiry) or Art. 6(1)(b) GDPR if your enquiry is directed at concluding a contract.
The form is secured against unauthorised external calls using a CSRF token. Additionally, Google reCAPTCHA v3 is integrated (see section 6).
6. Bug report form
Via the bug report form at /bugreport, users can report errors, display issues or improvement suggestions for our apps and website. The following data is collected:
- Affected app and report type (required)
- Short description and detailed description of the issue (required)
- Device and Android version (optional)
- Screenshot as JPG, PNG or WebP, max. 5 MB (optional)
- Email address for follow-up questions (optional)
- Time of submission
Reports are stored in an encrypted SQLite database on our server in Germany and forwarded to us by email. Screenshots are stored outside the publicly accessible area of the server. IP addresses are stored exclusively as a day-based SHA256 hash – tracing back to an individual is therefore not possible.
The data is used exclusively to analyse and resolve the reported issue. Received reports are deleted after a maximum of 12 months, unless they need to be retained longer for the traceability of corrections.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in quality assurance and error correction of our services).
7. Google reCAPTCHA v3
To protect the contact form from automated requests (spam, bots), we use Google reCAPTCHA v3, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
reCAPTCHA v3 analyses user behaviour in the background using various characteristics (including IP address, mouse movements, dwell time, browser information) and assigns a score without the user having to take any action. This data is transmitted to Google servers, which may be located within the EU or in the USA. For transfers to the USA, Standard Contractual Clauses (SCC) pursuant to Art. 46 GDPR apply.
reCAPTCHA v3 is only loaded on pages where the contact form is present (home page and /kontakt). On all other pages, no reCAPTCHA script is loaded from Google.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the contact form from abuse).
8. Google Fonts
This website loads fonts (Syne, DM Mono, DM Sans) via Google Fonts, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When the page is accessed, a connection to Google servers is established, during which your IP address is transmitted.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent and technically reliable presentation of the website). If you wish to object to the transfer, you can block Google Fonts in your browser – the website will remain fully functional.
9. No tracking or analytics tools
We deliberately refrain from using web analytics services (e.g. Google Analytics, Matomo) as well as marketing and tracking tools (e.g. Facebook Pixel). No user-based tracking, profiling or analysis of usage behaviour for advertising or analytics purposes takes place.
10. Your rights
You have the following rights at any time:
- Access (Art. 15 DSGVO) – What data we hold about you.
- Rectification (Art. 16 DSGVO) – Correction of inaccurate data.
- Erasure (Art. 17 DSGVO) – Deletion of your data, provided no retention obligation applies.
- Restriction (Art. 18 DSGVO)
- Data portability (Art. 20 DSGVO)
- Objection (Art. 21 DSGVO) – against processing based on legitimate interests.
To exercise your rights, please contact: kontakt@treichel-labs.app
11. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
The State Commissioner for Data Protection of Lower SaxonyPrinzenstraße 5 · 30159 Hannover
www.lfd.niedersachsen.de ↗
12. Changes to this privacy policy
We reserve the right to update this privacy policy if technical or legal conditions change. The current version is always available at /datenschutz.