← Back to the home pageDeutsch

Privacy Policy

This is a courtesy translation. The German version at /datenschutz is the binding one; in case of any discrepancy, the German text prevails.

1. Controller

The controller responsible for processing personal data on this website and in this service is:

Jens Bösche
Am Piepenbrink 16A
29379 Wittingen
Deutschland

kappaxbeta@gmail.com

We have not appointed a data protection officer, as the statutory thresholds for doing so are not met. For any privacy matter, please contact us at the address above.

2. The principle this service is built on

This service is built so that as little personal data as possible comes into existence in the first place. That is not a statement of intent — each of the following can be checked:

  • There are no advertising, tracking or marketing cookies, and no third-party analytics are embedded (no Google Analytics, no Meta pixel, no consent-management service).
  • There is no content delivery network in front of the site. Every page is served directly from our own server.
  • Fonts are served locally from our own server. No connection is made to Google Fonts or any comparable service.
  • Your IP address is not stored for analytics purposes (see section 6).
  • No account is needed to enter a room (see section 8).

3. Hosting

The application and the database run on servers we rent in Germany. No transfer to a third country takes place for hosting.

  • Application server: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. This runs the website itself and the TLS proxy that encrypts your connection.
  • Database, authentication and file server: STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. This runs our self-hosted Supabase installation, which holds accounts, content and files.

We have a data processing agreement under Art. 28 GDPR with both providers. Neither has access to the content of the data; they process it solely in order to operate the servers.

TLS certificates for encrypted transport are obtained automatically from Let’s Encrypt (Internet Security Research Group, USA). Only domain names are transmitted in that process — no visitor data.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the technically secure and reliable operation of this service.

4. Server log files

When a page is requested, the web server automatically records log data transmitted by your browser:

  • IP address
  • date and time of the request
  • the address requested and the HTTP status code
  • volume of data transferred
  • referrer URL, where one is sent
  • browser type, browser version and operating system

This data is technically necessary to deliver the page and additionally serves to detect and defend against abuse and attacks. It is not combined with other data sources and is not evaluated for analytics. The legal basis is Art. 6(1)(f) GDPR. Logs are deleted, or their IP addresses anonymised, after 14 days at the latest.

5. Cookies

We use strictly necessary cookies only. There is therefore no consent banner: under § 25(2) no. 2 TDDDG, no consent is required for cookies that are strictly necessary to provide a service the user has expressly requested. No cookies are set for analytics or advertising.

  • sb-…-auth-token— keeps you signed in. Set only when you sign in. Lifetime depends on your “keep me signed in” choice: until the browser is closed, or up to 30 days.
  • kxb.keep — remembers that choice, so the session gets the right lifetime each time it is renewed.
  • unkown_last_space — remembers which space you opened last, so that signing in takes you there rather than to a picker. Lifetime: several weeks.
  • unkown_invite — holds an open invitation while you create the account that accepts it. Not needed afterwards.

You can delete or block cookies in your browser at any time. If you do, you will not be able to sign in or use the protected areas of the service.

6. Analytics

We measure how often which pages are opened, in order to understand what is being found and what is not. We use no third-party analytics tool and no cookie for this. One record is stored per page view, containing:

  • the path requested, without the query string — identifiers, invitation tokens and search terms are discarded before the path is stored, so they never reach the database at all;
  • the host of the referring site, e.g. “discord.com”, not the full address. Referrals from our own pages are not stored;
  • the country, as a two-letter code;
  • the preferred language, as a language tag from the Accept-Language header;
  • the device class, only ever as one of four buckets — “desktop”, “mobile”, “tablet” or “bot”. The user agent string itself is not stored;
  • a pseudonymous daily value (see below);
  • your user id, if you are signed in at the time.

The daily value

To group repeat views within a single day, we compute a cryptographic hash from your IP address, your user agent, the current date and a secret key known only to us. Only that hash is stored.

Your IP address is not stored.Because the date is part of the calculation, the hash changes completely at midnight UTC. The same person receives a different value the next day, and the two cannot be linked. Recognition across days, and therefore the building of any usage profile, is technically impossible; “unique visitors” here is a daily figure and cannot be anything else.

Country lookup without transmission

The country code is determined offline, from an address-registry allocation table built into our application. Your IP address is not transmitted to anyone for this purpose and is not passed to any geolocation service. The result is a country and never anything more precise.

Views of our administrative area are not counted. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is in designing this service to meet actual demand. Given the design described above, the impact on your rights is low.

7. Account and profile

If you create an account, we process your email address and your password. The password is stored only as a hash; we do not know it in plain text. In addition, we process the details you enter in your profile, such as a display name and your choice of character, along with the spaces you are a member of and your role in them.

If you invite others to a space by email, we process the address you provide in order to deliver the invitation. Please only invite people who are happy to receive one.

The legal basis is Art. 6(1)(b) GDPR, as this processing is necessary to perform the user agreement.

8. Taking part without an account (guests)

Rooms can be entered via a guest link without creating an account. In that case we process the name you give yourself, the character you choose, and a technical identifier that identifies your session for its duration. We do not ask for an email address.

Guest access is time-limited and is deleted automatically once it expires. The legal basis is Art. 6(1)(b) GDPR.

9. Content in spaces and rooms

What you create in the service is stored: pages and their content, rooms you build, chat messages, game state and comparable input. This content is visible to the members of the space in question and to guests who have been granted access. Please note that chat messages and things you build are visible to everyone present.

How our storage works — and what that means for deletion

The service stores changes as an append-only log (“event sourcing”). An entry is never overwritten; a further entry is appended instead. That is the reason content survives a lapsed subscription.

This does not affect your right to erasure. If you request deletion, we delete your account and overwrite the personal details in the affected log entries so that they can no longer be attributed to you. The entry itself remains in anonymised form, because removing it would destroy the state of rooms shared with other people. Please contact us at the address in section 1.

10. Contact form and event enquiries

If you write to us via the contact form or the event enquiry form, we process the details you provide there — in particular your name, email address and the content of your message — in order to deal with your enquiry.

The legal basis is Art. 6(1)(b) GDPR where the enquiry is aimed at entering into a contract, and otherwise Art. 6(1)(f) GDPR based on our legitimate interest in answering enquiries. We delete enquiries once they have been dealt with, unless statutory retention obligations apply.

11. Payments

For paid subscriptions we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. You enter payment details — card details in particular — directly with Stripe. We neither receive nor store them.

In our own database we store only the Stripe customer id, the subscription id and its status, so that we know which features are unlocked. Stripe may also transfer personal data to the USA; that transfer is based on standard contractual clauses and certification under the EU-US Data Privacy Framework.

The legal basis is Art. 6(1)(b) GDPR. Invoice-related data is retained under Art. 6(1)(c) GDPR for the statutory periods of up to ten years.

12. Email

System messages such as sign-up confirmations, password resets and invitations are sent via a mail server we run ourselves on our own infrastructure. No external mail delivery provider is involved. There is no open or click tracking, and we do not send a newsletter.

13. Recipients

Beyond the parties named in sections 3 and 11, we do not pass your data to third parties. Disclosure occurs only where we are legally obliged to make it. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR, and your data is not sold.

14. Retention

  • Server logs: 14 days at most.
  • Analytics: the daily value ceases to be attributable at the turn of the day; the remaining fields are anonymous and are evaluated in aggregate on an ongoing basis.
  • Account and content: until the account is deleted.
  • Guest access: until the guest access expires.
  • Form enquiries: until dealt with, unless a retention obligation applies.
  • Invoice records: up to ten years, under commercial and tax law obligations.

15. Your rights

You have the following rights in relation to us:

  • access to the data we hold about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdrawal of any consent given, with effect for the future (Art. 7(3) GDPR).

Right to object

Where we process data on the basis of a legitimate interest under Art. 6(1)(f) GDPR — which covers the server logs and the analytics — you have the right to object at any time on grounds relating to your particular situation (Art. 21 GDPR). An informal message to kappaxbeta@gmail.com is sufficient.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority competent for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover
https://www.lfd.niedersachsen.de

16. Changes to this policy

We update this policy when the service or the legal position changes. The version available here is the one that applies.

Last updated: August 2026