Privacy Policy
This privacy policy describes the processing of personal data at nexcogen, a non-commercial hobby project in active development.
This English text is a convenience translation. The legally binding version is the German version.
On this page
- 1. Controller
- 2. Principles and legal bases
- 3. Hosting and server log files
- 4. User account and authentication
- 5. Content creation with Ollama-based AI infrastructure
- 6. Contact form
- 7. Cookies and local storage
- 8. External content and fonts
- 9. Retention period and deletion
- 10. Recipients and third-country transfers
- 11. Data subject rights
- 12. Security
- 13. Error monitoring with Sentry
- 14. Logging of administrative actions (backoffice audit log)
1. Controller
Leif SöffgeTriftweg 52
59555 Lippstadt
Germany
Email: info@nexcogen.com
Contact form: https://nexcogen.com/contact
No data protection officer has been appointed, because on current assessment there is no statutory obligation to appoint one.
2. Principles and legal bases
Personal data is processed only to the extent necessary for operating the website, providing a user account, securing the application, handling enquiries, or complying with legal obligations. The legal bases are in particular Art. 6(1)(b) GDPR (user account and requested features), Art. 6(1)(f) GDPR (secure and stable operation, abuse prevention, answering enquiries), and Art. 6(1)(c) GDPR (legal obligations).
No processing takes place for advertising, tracking, profiling, newsletter distribution, or the sale of personal data.
3. Hosting and server log files
The website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. For production operation, Hetzner is engaged on the basis of a data processing agreement (Art. 28 GDPR).
When the website is accessed, technically necessary access data is processed: IP address, date and time, requested URL, referrer, browser type, operating system, volume of data transferred, and HTTP status. This data serves secure operation, error analysis, and abuse prevention. The legal basis is Art. 6(1)(f) GDPR. Server log files are generally deleted after 14 days at the latest, unless a security incident or legal reason requires longer retention.
4. User account and authentication
The following data is processed on registration:
- name and email address,
- an encrypted password hash (bcrypt with 12 rounds; the plaintext password is not stored),
- timestamps of registration and of acceptance of the terms of use and privacy policy, including the respective version number,
- the email verification status,
- usage counters (generations consumed and remaining).
On sign-in, when accessing protected features, and on every further request of a signed-in session, the following data is additionally stored in a session table (database table sessions): unique session ID, user ID, IP address, user agent (identifier of the browser/operating system), session content, and the time of last activity. This data is removed automatically as soon as the session expires (by default after 120 minutes of inactivity). The legal basis is Art. 6(1)(b) GDPR, supplemented by Art. 6(1)(f) GDPR for security measures.
For failed sign-in or registration attempts, hash values derived from the IP address and email address are stored briefly in the application cache in order to limit brute-force attacks (max. 5 attempts per minute per IP/email combination). The cache entries are removed automatically once the throttling period has elapsed. The legal basis is Art. 6(1)(f) GDPR.
For password resets and email verification, technically necessary emails are sent. Delivery runs over the SMTP mailbox infrastructure of Hetzner Online GmbH (Hetzner Mail), for which a data processing agreement likewise exists. Emails sent contain signed links valid for 60 minutes (password reset) or for the configured verification window. No transmission to external mail service providers outside Hetzner takes place.
5. Content creation with Ollama-based AI infrastructure
Registered users can enter topics, optional parameters, and format specifications in order to generate a blog draft. These inputs, the selected template, the generated draft, status messages, and technical metadata are stored in the user account.
Generation runs on Ollama-based AI infrastructure controlled by the operator. Prompts are not transmitted to an external AI provider such as OpenAI, Anthropic, Google, or similar services, and are not processed by such a provider for training purposes. Users should nevertheless not enter sensitive personal data, health data, payment data, or confidential data belonging to third parties into prompts.
6. Contact form
When the contact form is used, the email address entered, optionally a name, and the content of the message are transmitted to the operator by email. The IP address is additionally processed for short-term throttling of excessive requests. The sender IP may also be included as technical metadata in the contact email delivered to the operator, in order to make abuse traceable. The message is not stored permanently in a database; it remains in the operator's email mailbox until it is handled and deleted there. The legal basis is Art. 6(1)(f) GDPR (answering the enquiry, protection against abuse).
7. Cookies and local storage
This website uses only technically necessary cookies and comparable storage. They provide the selected interface language, sign-in, sessions, CSRF protection, the contact form, and the “Remember me” option. The locale preference cookie is also set on public read-only pages so the selected or browser-negotiated language remains consistent. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR; access to the end device is necessary pursuant to § 25(2) no. 2 TDDDG and therefore does not require consent.
- locale: stores the selected or browser-negotiated interface language; set on public and authenticated pages; lifetime one year.
- nexcogen-session: maintains a technically necessary session for authentication, protected pages, and forms such as the contact form; lifetime up to 120 minutes of inactivity, then deleted automatically.
- XSRF-TOKEN: protects forms and Livewire requests against cross-site request forgery; lifetime of the respective session.
- remember_web_*: set only if the “Remember me” option is actively selected; persists until sign-out or until the browser data is cleared.
No analytics, advertising, affiliate tracking, or social media cookies are used. For this reason, no cookie banner is displayed.
8. External content and fonts
The application embeds no external fonts, analytics scripts, advertising networks, maps, videos, captchas, or social media plugins. Fonts are rendered using the system fonts of the end device. All CSS and JavaScript files are served from our own server.
9. Retention period and deletion
Account data, stored inputs, and generated drafts remain stored for as long as the user account exists or as long as further storage is legally required. If the account is deleted via the profile settings, the content and drafts belonging to the account are deleted. System templates are retained because they are not assigned to any individual user account.
- Session records (table
sessions): deleted automatically once the session lifetime expires (120 minutes). - Password reset tokens: expire after 60 minutes and are invalidated thereafter.
- Server log files: after 14 days at the latest.
- Sign-in throttling in the cache: once the throttling period has elapsed (typically a few minutes).
- Incoming contact form messages: remain in the operator's email mailbox until deleted there.
- Error events at Sentry: in accordance with the configured retention period (see section 13).
10. Recipients and third-country transfers
Recipients of personal data are infrastructure and telemetry service providers. Within the EU/EEA, Hetzner Online GmbH in particular processes data (hosting, database, mailbox SMTP). Sentry is additionally used for error monitoring; under the Sentry DPA, the contracting party and processor is Functional Software, Inc. d/b/a Sentry, based in the United States, although application data is stored in the EU data region operated by Sentry. The processing and any transfer of error event data by Functional Software, Inc. is safeguarded by the European Commission's Standard Contractual Clauses; where applicable, the provider additionally relies on the EU-US Data Privacy Framework. Details of error monitoring with Sentry are set out in section 13.
11. Data subject rights
Data subjects have rights under the GDPR to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interests. Where processing is based on consent, that consent can be withdrawn at any time with effect for the future.
There is also a right to lodge a complaint with a data protection supervisory authority, in particular with the competent supervisory authority in North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf.
12. Security
The application uses in particular the following technical and organisational measures (Art. 32 GDPR): authentication with hashed passwords (bcrypt, 12 rounds), CSRF protection, HTTP-only and secure session cookies, encrypted session storage, throttling of failed sign-ins, HTTPS enforcement via HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Traffic between browser and server is encrypted end-to-end via TLS in public production operation.
13. Error monitoring with Sentry
In order to detect and remedy technical faults in application operation, the error monitoring service Sentry is used in the production environment. Under the underlying Data Processing Addendum, the contracting party and processor within the meaning of Art. 28 GDPR is Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Application data is stored in the EU data region operated by Sentry (Frankfurt). The processing and any transfer of error event data by Functional Software, Inc. relies on the European Commission's Standard Contractual Clauses; where applicable, the provider additionally relies on the EU-US Data Privacy Framework.
In the event of an error, primarily technical event data is processed: time, error message and stack trace, application and runtime context (e.g. Laravel and PHP version, route name, affected component), HTTP method and the requested path, as well as a technical trace identifier (trace ID).
The application is configured for data minimisation, so that personal identifiers are, as far as possible, not transmitted to Sentry. Before transmission, the following data in particular is removed server-side or replaced with the placeholder [Filtered]:
- user IDs, names, email addresses, and IP addresses,
- cookies as well as
Authorization,Cookie,CSRF, andXSRFheaders, - query strings; URLs are reduced to the bare path,
- sensitive fields in request data such as passwords, tokens, API keys, contact form input, and the content of created drafts.
Cache-related diagnostic traces (“breadcrumbs”) are disabled. Keys for sign-in and registration throttling are additionally hashed server-side, so that neither email addresses nor IP addresses can appear in plaintext.
The following Sentry features are not active: performance monitoring, profiling, session replay, and the Sentry user feedback widget. No data is transmitted to Sentry in the development and test environments; the SDK is disabled there by configuration (no DSN set).
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in ensuring stable, secure operation, prompt remediation of faults, and maintaining the confidentiality, integrity, and availability of the application within the meaning of Art. 32 GDPR. No personality assessment or profiling in the data protection sense takes place. Data subjects may object to this processing pursuant to Art. 21 GDPR; guidance on asserting rights can be found in section 11.
Error events are deleted automatically in accordance with the 30-day retention period applicable to the Sentry plan in use (Developer / Free). Individual events may be deleted earlier where this is necessary to safeguard data subject rights or for data protection reasons.
14. Logging of administrative actions (backoffice audit log)
In the internal backoffice area of the application, security- and administration-relevant operations are recorded in an audit log, in order to make changes to user accounts traceable and to allow abuse and operator error to be investigated.
The following details are stored per operation:
- the acting admin account (or, for actions from the server console, a note to that effect);
- the action performed (technical identifier);
- a technical reference to the affected record (e.g. model class and record ID);
- the time of the action;
- the IP address and user agent of the admin browser, provided the action was triggered via the web application;
- optionally, a short justification for the action given by the admin.
The content of generations created by users (input fields and model responses) is not stored in the audit log.
If an admin suspends an account, the stated reason for suspension is stored directly on the affected account in addition to the audit log trace, for as long as the suspension is in place. If the account is unsuspended, this detail is removed from the account; the corresponding audit entry is nevertheless retained.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the security and traceability of administrative interventions and in the investigation of abuse and errors. No blanket retention period is currently defined; individual entries can be reviewed on request and — provided no legitimate investigative or security interests preclude it — deleted.
Last updated: 1 August 2026 · Version: 2026-08-01