Privacy policy
Last updated: July 18, 2026
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation is:
Tom Schönefeld
c/o COCENTER GmbH
Koppoldstr. 1
86551 Aichach
Germany
Email: contact@priviot.com
Phone: 0156 79814609
Priviot is an independent, individual project by Tom Schönefeld.
2. Scope
This privacy policy applies to the website priviot.com as well as to the redirect via priviot.de.
It also applies to email communication via addresses on the priviot.com domain, in particular contact@priviot.com, as well as to the ticketing system (feedback form).
Priviot PDF and Priviot Write generally process documents locally on your device. Priviot Paste stores snippets locally by default. These document or text contents are not transferred automatically to Priviot servers.
Accounts and sign-in are already available; the processing required for that is provided via the technical service provider Supabase (see Section 9). If you deliberately enable optional Paste sync, only client-side encrypted snippets and the technical metadata required for versioning and synchronization are transferred. The separate sync passphrase is not sent to Priviot or Supabase. This privacy policy will be updated before additional cloud, payment, telemetry, or AI features are introduced.
3. Principle: privacy first
Priviot follows the approach of processing as little personal data as possible.
The website currently does not use any analytics tools, marketing pixels, or ad tracking. No evaluation of user behavior for marketing purposes takes place.
4. Ticketing system
Feedback and support requests can be submitted through the ticketing system on the website or by email.
The following data is stored in the process:
- The category and selected product assignment of your request
- The content of your message
- Your email address, if you voluntarily provide it
- The page from which you submitted the form
- The time of submission
Signed-in users can also create account-based support tickets. The ticket number, category, subject, message history, account association, status, and timestamps are stored. Files attached voluntarily are stored in a private Supabase storage area and are accessible only to the respective account holder and authorized administrators.
This data is stored in a database and is only accessible to authorized administrators in the internal support area.
The legal basis is Art. 6 (1)(f) GDPR. The legitimate interest lies in processing your request. If the request relates to a contractual use, the legal basis is Art. 6 (1)(b) GDPR.
Please do not send confidential documents, third-party personal data, or sensitive content through the ticketing system unless this is necessary to process your request.
Tickets are deleted once they are no longer required for processing, unless statutory retention obligations or legitimate documentation interests require otherwise.
5. Cookies, tracking, and analytics
This website uses technically necessary cookies or comparable storage technologies (e.g. your browser's local storage) to the extent required for operation – in particular to keep you signed in after logging in.
These technically necessary storage technologies are permitted without separate consent under § 25 (2) TDDDG (German Digital Services Data Protection Act) and/or Art. 6 (1)(f) GDPR, since certain functions (e.g. signing in) would not work without them.
Beyond that, this website currently does not use any cookies for analytics or marketing purposes. No third-party tracking or advertising services are embedded.
If analytics tools, marketing pixels, external media, embedded content, or non-essential cookies are used in the future, this privacy policy will be updated and, where required, consent will be obtained.
6. External fonts, scripts, and content
The website is designed so that fonts, scripts, and design resources are hosted locally.
If external services such as font CDNs, video embeds, maps, captcha services, or analytics services are integrated in the future, this may result in personal data being transferred to third parties. In that case, this privacy policy will be updated accordingly.
7. Hosting and server log files
This website is hosted by ALL-INKL.COM – Neue Medien Münnich (referred to below as "ALL-INKL"). ALL-INKL automatically processes technical data transmitted by your browser when you visit the website, in particular your IP address, the date and time of access, the page accessed, the amount of data transferred, the browser and operating system used, and the previously visited page (referrer).
I collect these server log files solely to ensure trouble-free operation, detect misuse, and maintain the security of the website. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in a secure and stable website operation).
According to ALL-INKL, server log files are deleted after no more than seven days.
A data processing agreement pursuant to Art. 28 GDPR is in place with ALL-INKL.
8. AI-assisted tools in development and maintenance
AI-assisted tools may be used in the development and maintenance of Priviot to support work on code, text, error analysis, or technical concepts. These tools do not receive direct access to the production database, user accounts, waitlist entries, or tickets. Personal user, account, ticket, or waitlist data is not deliberately transmitted to AI service providers. Synthetic, anonymized, or non-personal data should be used for development, testing, and error analysis. Should personal data be processed by AI service providers in the future, this privacy policy will be updated accordingly in advance.
9. Supabase as a technical service provider
Priviot uses Supabase as a technical service provider for user accounts, authentication and login, waitlist entries, the ticketing system, selected application preferences, and optional encrypted Paste sync. The personal data required for these functions is processed by Supabase.
Where Supabase processes personal data on my behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
The primary storage location of project data depends on the region selected for the Supabase project. The data processing agreement concluded with Supabase incorporates the EU Standard Contractual Clauses for any transfers to third countries.
10. Transfers to third countries
A transfer to a third country occurs where personal data is transmitted or otherwise made available to a recipient outside the European Union or the European Economic Area. Merely using a provider established in a third country does not automatically constitute such a transfer if no personal data is disclosed to that provider.
The AI-assisted tools described in Section 8 are not deliberately provided with personal user, account, ticket, or waitlist data. AI service providers are therefore currently not recipients of this data. If this changes in the future, the required legal basis and safeguards for any transfer to a third country will be determined before processing begins, and this privacy policy will be updated accordingly.
In connection with Supabase and its subprocessors, access from or a transfer to a third country cannot be completely ruled out depending on technical operations, support, or onward processing. Where this occurs, the transfer is based on an adequacy decision under Art. 45 GDPR or appropriate safeguards under Art. 46 GDPR, in particular the EU Standard Contractual Clauses.
11. Retention period
Personal data is only stored for as long as necessary for the respective purpose.
Account and sign-in data (e.g. email address and sign-in timestamps) is stored for as long as your account exists. You can delete your account yourself at any time via the account page. Doing so removes the active user account and the data directly associated with it – including waitlist entries – from the production systems. Previously issued technical session tokens may remain valid until the end of their short validity period, but they cannot be used to renew the deleted session. Statutory retention obligations and technically necessary, time-limited logs or backups may be exempt from immediate deletion.
Optionally synchronized Paste content is stored only in encrypted form and remains associated with the account. It is deleted together with directly associated account data when the account is deleted; time-limited backups may expire later for technical reasons.
Waitlist entries are stored until you remove yourself, delete your account, or the respective product launches and the notification purpose no longer applies.
Tickets are deleted once the request has been fully processed and no statutory retention obligations or legitimate documentation interests require otherwise.
Server log files are deleted by ALL-INKL after no more than seven days (see Section 7).
12. Your rights
Subject to the statutory requirements, you have the following rights:
- Right of access under Art. 15 GDPR
- Right to rectification under Art. 16 GDPR
- Right to erasure under Art. 17 GDPR
- Right to restriction of processing under Art. 18 GDPR
- Right to data portability under Art. 20 GDPR
- Right to object to processing under Art. 21 GDPR
- Right to withdraw consent given, with future effect
- Right to lodge a complaint with a data protection supervisory authority