← back to the homepage

Privacy Policy

This is a courtesy translation of the German Datenschutzerklärung, which is the legally binding version required under the GDPR/German data protection law. In case of any discrepancy, the German original controls.

1. Controller within the meaning of the GDPR

Martin Becke
Mettinger Str. 13
49586 Neuenkirchen
Germany
Email: scimbe@gmail.com

2. Purposes of processing and legal bases

3. Scope of processing — what we technically cannot see

The actual payload is transmitted end-to-end encrypted (Noise protocol); the operator has no technical means of inspecting the content of the transmitted data. Only routing/operational metadata is processed (e.g. which tunnel was active when), account metadata (user identifier, registration time), and, where applicable, billing metadata (see item 6).

4. Server log files

For technical reasons, information is automatically captured on every access (IP address, timestamp, requested resource, user agent) to ensure trouble-free operation and IT security. Legal basis: Art. 6(1)(f) GDPR.

5. Cookies

Only technically necessary cookies are used: a session cookie for sign-in and a short-lived cookie for CSRF protection during login. These are required under § 25(2) no. 2 TTDSG (German Telecommunications Telemedia Data Protection Act) to provide the service you explicitly requested — no consent is required for these. No analytics, marketing, or tracking cookies are used.

6. Payment service providers

No real payments are currently processed through this domain (research/demo operation). Should a payment service provider be integrated for billing in the future, this notice will be updated accordingly before any real payments are processed.

7. Hosting

This application is operated on independently administered server infrastructure.

8. Disclosure to third parties

Personal data is not disclosed to third parties, except where legally required or necessary for the pursuit of legal claims.

9. Retention period

Account and operational metadata is retained for as long as an account exists, or as long as a statutory retention obligation applies; server log files are deleted after a reasonable period.

Where the operator has enabled it, the tunnel edge additionally keeps a minimal, host-local record of accepted connections — timestamp, source IP address, transport, and the routing token or channel identifier already used for authorization elsewhere — for the operator's own evidentiary purposes (for example, demonstrating to a competent authority that a given relayed session originated from a real client, rather than from the edge's own address). No request content, headers, or user-agent data is included. This record is not exposed through any network-reachable interface; it is accessible only by direct, host-local access to the operator's server. Entries are automatically deleted after 7 days by default, unless the operator has configured a different retention period.

10. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing (Art. 15–21 GDPR), and the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).

11. Responsibility for third-party services on this platform

Users who operate their own workflow pipelines or agents through this platform are independently responsible for the personal data they process as part of their own service (their own data-protection responsibility for their respective service). This privacy policy covers only the infrastructure provided by the operator itself — see also the Terms of Use, item 5.