Privacy Policy

This privacy policy describes the processing of personal data at nexcogen, a non-commercial hobby project in active development.

1. Controller

Leif Söffge
Triftweg 52
59555 Lippstadt
Germany

Email: info@nexcogen.com
Contact form: https://nexcogen.com/contact

No data protection officer has been appointed, because on current assessment there is no statutory obligation to appoint one.

2. Principles and legal bases

Personal data is processed only to the extent necessary for operating the website, providing a user account, securing the application, handling enquiries, or complying with legal obligations. The legal bases are in particular Art. 6(1)(b) GDPR (user account and requested features), Art. 6(1)(f) GDPR (secure and stable operation, abuse prevention, answering enquiries), and Art. 6(1)(c) GDPR (legal obligations).

No processing takes place for advertising, tracking, profiling, newsletter distribution, or the sale of personal data.

3. Hosting and server log files

The website is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. For production operation, Hetzner is engaged on the basis of a data processing agreement (Art. 28 GDPR).

When the website is accessed, technically necessary access data is processed: IP address, date and time, requested URL, referrer, browser type, operating system, volume of data transferred, and HTTP status. This data serves secure operation, error analysis, and abuse prevention. The legal basis is Art. 6(1)(f) GDPR. Server log files are generally deleted after 14 days at the latest, unless a security incident or legal reason requires longer retention.

4. User account and authentication

The following data is processed on registration:

On sign-in, when accessing protected features, and on every further request of a signed-in session, the following data is additionally stored in a session table (database table sessions): unique session ID, user ID, IP address, user agent (identifier of the browser/operating system), session content, and the time of last activity. This data is removed automatically as soon as the session expires (by default after 120 minutes of inactivity). The legal basis is Art. 6(1)(b) GDPR, supplemented by Art. 6(1)(f) GDPR for security measures.

For failed sign-in or registration attempts, hash values derived from the IP address and email address are stored briefly in the application cache in order to limit brute-force attacks (max. 5 attempts per minute per IP/email combination). The cache entries are removed automatically once the throttling period has elapsed. The legal basis is Art. 6(1)(f) GDPR.

For password resets and email verification, technically necessary emails are sent. Delivery runs over the SMTP mailbox infrastructure of Hetzner Online GmbH (Hetzner Mail), for which a data processing agreement likewise exists. Emails sent contain signed links valid for 60 minutes (password reset) or for the configured verification window. No transmission to external mail service providers outside Hetzner takes place.

5. Content creation with Ollama-based AI infrastructure

Registered users can enter topics, optional parameters, and format specifications in order to generate a blog draft. These inputs, the selected template, the generated draft, status messages, and technical metadata are stored in the user account.

Generation runs on Ollama-based AI infrastructure controlled by the operator. Prompts are not transmitted to an external AI provider such as OpenAI, Anthropic, Google, or similar services, and are not processed by such a provider for training purposes. Users should nevertheless not enter sensitive personal data, health data, payment data, or confidential data belonging to third parties into prompts.

6. Contact form

When the contact form is used, the email address entered, optionally a name, and the content of the message are transmitted to the operator by email. The IP address is additionally processed for short-term throttling of excessive requests. The sender IP may also be included as technical metadata in the contact email delivered to the operator, in order to make abuse traceable. The message is not stored permanently in a database; it remains in the operator's email mailbox until it is handled and deleted there. The legal basis is Art. 6(1)(f) GDPR (answering the enquiry, protection against abuse).

7. Cookies and local storage

This website uses only technically necessary cookies and comparable storage. They provide the selected interface language, sign-in, sessions, CSRF protection, the contact form, and the “Remember me” option. The locale preference cookie is also set on public read-only pages so the selected or browser-negotiated language remains consistent. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR; access to the end device is necessary pursuant to § 25(2) no. 2 TDDDG and therefore does not require consent.

No analytics, advertising, affiliate tracking, or social media cookies are used. For this reason, no cookie banner is displayed.

8. External content and fonts

The application embeds no external fonts, analytics scripts, advertising networks, maps, videos, captchas, or social media plugins. Fonts are rendered using the system fonts of the end device. All CSS and JavaScript files are served from our own server.

9. Retention period and deletion

Account data, stored inputs, and generated drafts remain stored for as long as the user account exists or as long as further storage is legally required. If the account is deleted via the profile settings, the content and drafts belonging to the account are deleted. System templates are retained because they are not assigned to any individual user account.

10. Recipients and third-country transfers

Recipients of personal data are infrastructure and telemetry service providers. Within the EU/EEA, Hetzner Online GmbH in particular processes data (hosting, database, mailbox SMTP). Sentry is additionally used for error monitoring; under the Sentry DPA, the contracting party and processor is Functional Software, Inc. d/b/a Sentry, based in the United States, although application data is stored in the EU data region operated by Sentry. The processing and any transfer of error event data by Functional Software, Inc. is safeguarded by the European Commission's Standard Contractual Clauses; where applicable, the provider additionally relies on the EU-US Data Privacy Framework. Details of error monitoring with Sentry are set out in section 13.

11. Data subject rights

Data subjects have rights under the GDPR to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21) to processing based on legitimate interests. Where processing is based on consent, that consent can be withdrawn at any time with effect for the future.

There is also a right to lodge a complaint with a data protection supervisory authority, in particular with the competent supervisory authority in North Rhine-Westphalia: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf.

12. Security

The application uses in particular the following technical and organisational measures (Art. 32 GDPR): authentication with hashed passwords (bcrypt, 12 rounds), CSRF protection, HTTP-only and secure session cookies, encrypted session storage, throttling of failed sign-ins, HTTPS enforcement via HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy. Traffic between browser and server is encrypted end-to-end via TLS in public production operation.

13. Error monitoring with Sentry

In order to detect and remedy technical faults in application operation, the error monitoring service Sentry is used in the production environment. Under the underlying Data Processing Addendum, the contracting party and processor within the meaning of Art. 28 GDPR is Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. Application data is stored in the EU data region operated by Sentry (Frankfurt). The processing and any transfer of error event data by Functional Software, Inc. relies on the European Commission's Standard Contractual Clauses; where applicable, the provider additionally relies on the EU-US Data Privacy Framework.

In the event of an error, primarily technical event data is processed: time, error message and stack trace, application and runtime context (e.g. Laravel and PHP version, route name, affected component), HTTP method and the requested path, as well as a technical trace identifier (trace ID).

The application is configured for data minimisation, so that personal identifiers are, as far as possible, not transmitted to Sentry. Before transmission, the following data in particular is removed server-side or replaced with the placeholder [Filtered]:

Cache-related diagnostic traces (“breadcrumbs”) are disabled. Keys for sign-in and registration throttling are additionally hashed server-side, so that neither email addresses nor IP addresses can appear in plaintext.

The following Sentry features are not active: performance monitoring, profiling, session replay, and the Sentry user feedback widget. No data is transmitted to Sentry in the development and test environments; the SDK is disabled there by configuration (no DSN set).

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in ensuring stable, secure operation, prompt remediation of faults, and maintaining the confidentiality, integrity, and availability of the application within the meaning of Art. 32 GDPR. No personality assessment or profiling in the data protection sense takes place. Data subjects may object to this processing pursuant to Art. 21 GDPR; guidance on asserting rights can be found in section 11.

Error events are deleted automatically in accordance with the 30-day retention period applicable to the Sentry plan in use (Developer / Free). Individual events may be deleted earlier where this is necessary to safeguard data subject rights or for data protection reasons.

14. Logging of administrative actions (backoffice audit log)

In the internal backoffice area of the application, security- and administration-relevant operations are recorded in an audit log, in order to make changes to user accounts traceable and to allow abuse and operator error to be investigated.

The following details are stored per operation:

The content of generations created by users (input fields and model responses) is not stored in the audit log.

If an admin suspends an account, the stated reason for suspension is stored directly on the affected account in addition to the audit log trace, for as long as the suspension is in place. If the account is unsuspended, this detail is removed from the account; the corresponding audit entry is nevertheless retained.

The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the security and traceability of administrative interventions and in the investigation of abuse and errors. No blanket retention period is currently defined; individual entries can be reviewed on request and — provided no legitimate investigative or security interests preclude it — deleted.

Last updated: 1 August 2026 · Version: 2026-08-01