Privacy policy
Last updated: August 31, 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation is:
Tom Schönefeld
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach
Germany
Email: contact@priviot.com
Phone: 0156 79814609
Priviot is the project and product name used by the controller.
2. Scope and local processing
This policy applies to priviot.com and priviot.de, communications with Priviot, the Priviot account, and online functions of Priviot applications that refer to it.
Purely local application processing is not processing by Priviot unless content or usage data is sent to Priviot or a service used by Priviot. Opening an application does not automatically upload local documents, text, snippets, or notes.
Network access may be required for website requests, downloads, update checks, sign-in, sync, sharing, collaboration, support, voluntary telemetry, or a deliberately selected external AI API.
3. Website, essential storage, and no advertising tracking
The website does not use analytics, marketing pixels, advertising profiles, or download click counters. Fonts, scripts, and design resources are served locally.
Essential cookies or comparable browser storage are used to remember dismissal of the information notice, support sign-in and session renewal, save language or appearance, and provide expressly requested account features.
Section 25(2) no. 2 TDDDG applies to strictly necessary device access. Related personal-data processing relies on Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the function; the legitimate interest is secure and functional operation.
4. Hosting and server logs
The website and downloads are hosted by ALL-INKL.COM – Neue Medien Münnich. Requests may process IP address, date and time, requested resource, HTTP status, data volume, referrer, browser, and operating-system details.
The purposes are delivery, stability, error analysis, and abuse prevention. The legal basis is Art. 6(1)(f) GDPR. According to ALL-INKL, regular server logs are deleted after no more than seven days. Security incidents, attacks, or abuse may require longer retention.
Where ALL-INKL acts as a processor, an agreement under Art. 28 GDPR is required.
5. Account, authentication, profile, and avatar
A Priviot account processes email address, account ID, confirmation state, authentication and session data, and first and last name used for the account display. Language, appearance and application preferences, organisation membership, and an uploaded avatar with storage path and revision may also be stored.
The purposes are account creation, sign-in, security, administration, and expressly used online services. Art. 6(1)(b) GDPR generally applies; security records may rely on Art. 6(1)(f).
An avatar is held in private storage unless it is expressly used as a public author image for a published blog post.
6. Browsers, devices, and application preferences
Connected browsers and physical devices may process random device or session ID, display name, platform, browser or Priviot application, app version, creation time, last contact, last successful sync, and revocation or sign-out time.
Several Priviot applications on one physical device may be combined into one device display. The purposes are account security, session display, revocation, and sync control.
Supported preferences such as language, accent colour, appearance, or reduced motion may be stored with the account and synced between applications.
7. Organisations, members, and invitations
Organisation use processes organisation name, description, logo, creator, roles, permissions, membership, join time, and related account and email identifiers.
A member's name, email address, avatar, role, and join time may be visible to authorised members of the same organisation. Administrators can manage roles and membership.
Invitations process recipient email, a token stored only as a hash, inviter, intended role, expiry, and acceptance or rejection. Pending invitations are generally valid for seven days. The inviter may receive a transactional notice about acceptance or rejection.
Art. 6(1)(b) GDPR applies to expressly used organisation functions. Security, evidence, and abuse-prevention data may rely on Art. 6(1)(f).
8. Optional sync
Supported sync in Priviot PDF, Write, Paste, and Notes can be used with a signed-in account and configured per supported service.
Private content, attachments, and content metadata are encrypted client-side before transfer. The separate sync passphrase or local key is not sent to Priviot or Supabase. Operations still require account/object IDs, product and object type, schema, revision, device ID, server time, deletion marker, ciphertext hash, size, and encrypted blob references.
Disabling a service stops future sync for that service. It does not automatically delete content stored locally.
9. Sharing and collaboration
Where sharing or collaboration is used in a supplied version, room or share ID, members, roles, invitation token or hash, devices, change times, and status may be processed. Content updates and snapshots may be encrypted; organisational metadata and access control remain visible to the service.
Art. 6(1)(b) GDPR applies to the requested share or collaboration. Abuse prevention and access evidence may rely on Art. 6(1)(f).
10. Priviot AI and external AI providers
Local Priviot models and compatible local third-party models run on the device. Local use does not send processed content to Priviot.
Users can also deliberately configure external AI providers such as OpenAI, Anthropic, Google Gemini, or compatible API services. Only after a provider is selected and a request is submitted does the application send the prompt, supplied context, and required document or text excerpts directly to that provider. There is no automatic cloud fallback.
API keys are stored locally through the operating system's protected credential storage and are not sent to Priviot. The selected provider processes data under its own terms and privacy information. International transfers and provider-specific storage or logging periods may apply.
Art. 6(1)(b) GDPR applies to technical provision of the expressly requested connection. Users must have authority to disclose third-party personal data to an external provider.
11. Voluntary Priviot Write telemetry
Priviot Write may offer voluntary technical telemetry. It is disabled by default and sends events only after explicit activation.
Events may cover app start, opening and saving with format, outcome, duration and size classes, feature use, collaboration, performance, DOCX compatibility, and technical app, platform, and version details. Document content, filenames, and complete paths are not part of the intended events.
For abuse prevention, the forwarded IP address and an hourly value may be transformed with HMAC into a short-lived rate-limit key. Telemetry events are retained for up to 180 days and rate-limit keys for up to two days. Disabling telemetry stops future collection and clears the local queue.
The legal basis is consent under Art. 6(1)(a) GDPR, which can be withdrawn in Priviot Write with future effect.
12. Support, feedback, tickets, and attachments
Requests may process product or area, category, subject, message, optional email, account ID, page URL, status, message history, and timestamps.
Voluntary attachments use private storage. Filename, path, type, size, and uploader assignment are also processed. Access is limited to the account holder and authorised administrators.
Art. 6(1)(b) GDPR applies to contractual requests and Art. 6(1)(f) to other requests, error analysis, and abuse prevention.
13. Transactional email
Priviot may send transactional email for registration and security, organisation invitations, invitation acceptance or rejection, account deletion, ticket creation, ticket replies, and stopping sync.
Recipient, language, message type, ticket number or product reference, creation time, delivery attempts, delivery status, and technical error details may be processed. Failed deliveries may be retried automatically and held for technical review after repeated failure.
Art. 6(1)(b) GDPR applies to requested account and service communication and Art. 6(1)(f) to security and delivery evidence. These are not advertising emails.
14. Public blog author profiles
Published posts may show an author name and selected author image publicly. Author account ID, language, title, excerpt, content, publication state, and timestamps are also processed internally.
Publication occurs only for posts expressly released for publication. Public information is available worldwide and may be indexed by search engines.
15. Downloads and update checks
Manual downloads and automatic update checks create ordinary web requests containing the connection data described in Section 4. Packaged non-store builds may check shortly after startup and periodically thereafter.
Priviot Proof may also retrieve signed dictionary manifests and packages. These requests do not contain document content.
16. Optional calendar and performance features
If a Notes calendar feed is offered and activated, a secret feed token or hash and a deliberately reduced calendar projection containing date/time and a generic title may be processed. Disabling the feed removes server-provided entries. The secret feed URL must be protected like a credential.
If performance data is expressly shared through System Manager, daily device ID, average and peak CPU and memory use, sample count, and sharing state may be processed. Document content is not included. Disabling stops further submissions.
17. Providers, recipients, and international transfers
Priviot uses ALL-INKL for website/download hosting and Supabase for authentication, database, Storage, Edge Functions, Realtime, accounts, organisations, tickets, and sync. Processor activities require agreements under Art. 28 GDPR.
A deliberately selected external AI provider receives the content described in Section 10.
Depending on the provider, subprocessor, support access, or selected AI service, data may be accessible outside the EU or EEA. Where Priviot is responsible, transfers rely on an adequacy decision under Art. 45 GDPR or safeguards under Art. 46, in particular the EU Standard Contractual Clauses. An EU project region does not by itself rule out all non-EEA access.
18. Retention and account deletion
Personal data is deleted when no longer needed and no statutory duty or overriding legitimate ground applies.
- Regular website logs: no more than seven days; potentially longer for security incidents.
- Account, profile, device, organisation, and sync data: generally for the life of the account, membership, or expressly used function.
- Pending organisation invitations: generally valid for seven days; status and security data may be needed longer.
- Write telemetry: up to 180 days; rate-limit keys up to two days.
- Tickets, attachments, and delivery records: while required for handling, delivery, security, or statutory evidence.
- Public blog information: while the post or author profile is published.
The account area provides an account-deletion function. It starts deletion of the active authentication account and directly associated product data. Data linked to organisation responsibilities, authorship, support, security, statutory duties, time-limited logs, or backups may require additional review, transfer of responsibility, or technical expiry. Users may contact contact@priviot.com for access or complete erasure requests.
19. Data-subject rights and objection
Subject to statutory conditions, users have rights of access, rectification, erasure, restriction, portability, withdrawal of consent with future effect, and complaint to a supervisory authority.
Where Priviot relies on legitimate interests, you may object at any time on grounds relating to your particular situation.
Requests may be sent to contact@priviot.com.
20. Changes to this policy
This policy is updated when processing, providers, or legal requirements change. An update does not replace required consent or create a unilateral contractual amendment right.
