Martin Becke
Mettinger Str. 13
49586 Neuenkirchen
Germany
Email: scimbe@gmail.com
The actual payload is transmitted end-to-end encrypted (Noise protocol); the operator has no technical means of inspecting the content of the transmitted data. Only routing/operational metadata is processed (e.g. which tunnel was active when), account metadata (user identifier, registration time), and, where applicable, billing metadata (see item 6).
For technical reasons, information is automatically captured on every access (IP address, timestamp, requested resource, user agent) to ensure trouble-free operation and IT security. Legal basis: Art. 6(1)(f) GDPR.
Only technically necessary cookies are used: a session cookie for sign-in and a short-lived cookie for CSRF protection during login. These are required under § 25(2) no. 2 TTDSG (German Telecommunications Telemedia Data Protection Act) to provide the service you explicitly requested — no consent is required for these. No analytics, marketing, or tracking cookies are used.
No real payments are currently processed through this domain (research/demo operation). Should a payment service provider be integrated for billing in the future, this notice will be updated accordingly before any real payments are processed.
This application is operated on independently administered server infrastructure.
Personal data is not disclosed to third parties, except where legally required or necessary for the pursuit of legal claims.
Account and operational metadata is retained for as long as an account exists, or as long as a statutory retention obligation applies; server log files are deleted after a reasonable period.
Where the operator has enabled it, the tunnel edge additionally keeps a minimal, host-local record of accepted connections — timestamp, source IP address, transport, and the routing token or channel identifier already used for authorization elsewhere — for the operator's own evidentiary purposes (for example, demonstrating to a competent authority that a given relayed session originated from a real client, rather than from the edge's own address). No request content, headers, or user-agent data is included. This record is not exposed through any network-reachable interface; it is accessible only by direct, host-local access to the operator's server. Entries are automatically deleted after 7 days by default, unless the operator has configured a different retention period.
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing (Art. 15–21 GDPR), and the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
Users who operate their own workflow pipelines or agents through this platform are independently responsible for the personal data they process as part of their own service (their own data-protection responsibility for their respective service). This privacy policy covers only the infrastructure provided by the operator itself — see also the Terms of Use, item 5.