Authoritative version is German. This English translation is for convenience only.

Privacy Policy

Hebepunkt — Hebepunkt — applicable to wovenkeep.com, app.wovenkeep.com and gutachten.osinova.de
As of: 04.07.2026

1. Data Controller

Adrian Bätz – Hebepunkt
Einzelunternehmen (sole proprietorship)
Owner: Adrian Bätz
Elbinger Str. 9, 91207 Lauf a.d. Pegnitz
Email: info@wovenkeep.com

2. Overview of Processing

We process personal data only to the extent necessary for providing our services or where you have given consent.

3. Legal Basis

We process data on the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR) — Registration, use of SaaS services, billing
  • Legitimate interests (Art. 6(1)(f) GDPR) — Security, abuse prevention, debugging
  • Consent (Art. 6(1)(a) GDPR) — optional click statistics, optional features
  • Legal obligation (Art. 6(1)(c) GDPR) — Invoices, tax records

4. Data Collected

4.1 Registration and Customer Account

  • Email address, name, password (hashed with bcrypt)
  • Optional: Address, phone, country, language
  • Legal basis: Contract performance
  • Retention: Until account deletion, then 10 years for billing data (Section 147 AO)

4.2 Usage Data

  • IP address (anonymized after 24h), timestamp, pages visited
  • Device type, browser type (no fingerprinting)
  • Legal basis: Legitimate interest (security, debugging)
  • Retention: 30 days

4.3 Payment Data

  • Payment data is processed directly by Stripe Inc.
  • We store: Stripe customer ID, billing history, payment status
  • We do NOT store: credit card numbers, bank details
  • Legal basis: Contract performance

4.4 Content Data (Wovenkeep)

  • Campaigns, NPCs, scenes, media — content created by the customer
  • Processing exclusively for service provision
  • No access by the Provider except for support purposes with consent
  • Legal basis: Contract performance, DPA (Art. 28 GDPR) where applicable

4.5 Content Data (Gutachter)

  • Appraisal texts, photos of machines, PDF documents
  • May contain personal data of third parties (clients)
  • Legal basis: Contract performance, DPA

4.6 Telemetry and usage analytics (beta)

During the closed beta phase of Wovenkeep (invite-only, expected to run for around 8 weeks) we collect technical usage data to improve the product, diagnose errors and plan server capacity and costs. This section describes what we collect — and what we explicitly do not.

Principles (apply to everything below):

  • We collect no content: no campaigns, texts, notes, character or NPC names, no chat or game content.
  • We collect no names or identifiers of your players.
  • There is no session replay and no heatmaps; we do not record what you see or type on your screen.
  • Web analytics runs on a self-hosted Umami instance on our own servers — no analytics data flows to third-party analytics services.

a) Web analytics (Umami, self-hosted, cookieless)

On the game master (GM) views of your instance we embed the analytics script of our own Umami instance. It sets no cookies and stores nothing in your browser (no localStorage). We collect: page views, use of the GM areas (tabs), session duration, browser, operating system and language setting, device class and screen size, plus coarse location (country/region/city). Location is derived from the IP address on receipt; the IP address itself is discarded immediately and never stored. To distinguish sessions, a short-lived, non-reversible hash identifier is derived from technical characteristics (including the IP address and browser signature); the IP address itself is never stored and the identifier rotates automatically. The hostname (your instance's subdomain) is recorded as a technical instance identifier. Player pages are not covered by web analytics — GM views only.

We use the normal, blockable analytics script and do not employ any technique that circumvents ad or tracking blockers. If your browser blocks the script, we treat this as an objection and no web analytics data is collected. The “Do Not Track” and “Global Privacy Control” signals are respected.

Retention: 12 months, then automatic deletion.

b) Feature events (server telemetry)

Your instance reports to our central platform that certain features were used — not with what content. These events are linked to your customer account and your instance. Events include:

  • Login; game session started/resumed/ended
  • Campaign created or duplicated; NPC created; export used
  • AI feature used (which feature, not its content)
  • Voice interview and voice dictation used
  • Player joined/disconnected (only the number of players and devices and the session duration in coarse buckets — no names, no identifiers, no location data of your players)
  • Technical errors in the browser (error category and the page template involved only, free of personal content)
  • “First time” milestones (e.g. first campaign created)

Events contain no content data and no identifiers of your players. Retention: 180 days, then automatic deletion (we will review a shorter period after the beta). If a customer account is deleted, its events are deleted no later than 30 days after account deletion.

c) Technical raw telemetry (pseudonymous)

In addition, a technical raw telemetry path exists: technical event data with an instance identifier, with IP addresses anonymised immediately (pseudonymous, not anonymous). Raw data retention: 30 days, after which only aggregated, anonymous statistics remain.

Legal basis and objection (tier 1: a–c)

The legal basis for a) to c) is our legitimate interest (Art. 6(1)(f) GDPR) in improving Wovenkeep, diagnosing errors and planning capacity during the beta. You can object to this processing at any time (Art. 21 GDPR): the GM settings of your instance contain a telemetry toggle. Switching it off stops all three paths a) to c) for the entire instance — web analytics (gated server-side via the configuration endpoint) as well as feature events and raw telemetry (the technical gate acts before both server-side transmission paths). If you object, we also delete the account-related event data already collected for your account. Beta access does not depend on it.

Optional click statistics (tier 2, consent only)

Additionally — and only if you actively enable it in the GM settings — we collect granular click events (which UI element was clicked, as a technical element identifier, without content). The legal basis is your consent (Art. 6(1)(a) GDPR). The toggle is off by default; consent is voluntary, not tied to beta access, and can be withdrawn at any time via the same toggle (Art. 7(3) GDPR); the lawfulness of processing before withdrawal remains unaffected.

Players

Players who join a game session via a link shared by their game master are not covered by web analytics; no analytics script runs on player pages. Server-side, only aggregated values arise about players: the number of connected players and devices and the session duration in coarse buckets — no names, no entered player names, no identifiers, no location data. Players are invited by their game master sharing a link; the platform does not send e-mails to players' addresses. We are the controller for this telemetry; players are briefly informed on the join page before joining and referred to this privacy policy.

Analysis and recipients

Analysis is carried out exclusively internally by the Hebepunkt team (internal dashboards and an internal weekly report). Telemetry data is not merged with marketing data, not shared with third parties and not used for advertising. Processing takes place on our servers at IONOS in Germany and France (see section 5.1); we operate the web analytics (Umami) ourselves — no external analytics service is involved. Events contain no internal user IDs of your players; events linked to your account (item b) are subject to your data subject rights under section 7 (access, erasure, objection, etc.).

5. Recipients and Third-Country Transfers

5.1 Processors

Provider Purpose Location Guarantee
IONOS SE Hosting, servers Germany DPA, German data centers
Stripe Inc. Payment processing USA DPA, EU SCCs, DPF
Anthropic PBC AI features (optional) USA DPA, EU SCCs
Mistral AI SAS AI features (fallback) France (EU) DPA, processing within the EU, EU SCCs
Groq, Inc. Speech transcription (speech-to-text) USA DPA, EU SCCs
Google LLC AI image generation (character portraits) USA DPA, EU SCCs
Mailbox.org Email delivery Germany DPA, German servers

AI providers and your own AI access (BYOK)

For AI features we use one of the providers listed above depending on the function; if the primary provider is unavailable, a fallback provider named in the list (e.g. Mistral AI, EU) may be used instead. If you as a customer provide your own AI access (your own API key or your own endpoint, "Bring Your Own AI"), your AI requests are transmitted exclusively to the provider you have chosen; for that provider you are then the controller, and the above list does not apply in that respect.

5.2 Third-Country Transfers

For transfers to the USA (Stripe, Anthropic, Groq, Google) we rely on:

  • EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR
  • Additional technical measures (encryption, pseudonymization)

6. Cookies and Tracking

6.1 Essential Cookies

  • Session cookie (authentication) — mandatory
  • Language preference — mandatory
  • Legal basis: Legitimate interest, no consent required

6.2 Cookieless analytics (beta telemetry)

Our web analytics (self-hosted Umami) uses no cookies and stores nothing in your browser; no cookie banner is required for it. Scope, legal bases, objection (toggle in the GM settings) and the optional consent-based click statistics are described in section 4.6. No Google Analytics is used and no data is shared with advertising networks.

7. Data Subject Rights

You have the following rights:

  • Access (Art. 15 GDPR) — What data we store about you
  • Rectification (Art. 16 GDPR) — Correction of inaccurate data
  • Erasure (Art. 17 GDPR) — Deletion of your data ("right to be forgotten")
  • Restriction (Art. 18 GDPR) — Restriction of processing
  • Data portability (Art. 20 GDPR) — Export of your data in a machine-readable format
  • Objection (Art. 21 GDPR) — Objection to processing based on legitimate interests
  • Withdrawal of consent (Art. 7(3) GDPR) — At any time without giving reasons

To exercise your rights, contact: info@wovenkeep.com

Data export and account deletion are also available directly in the customer area (self-service).

8. Right to Complain

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Competent supervisory authority: Bayerisches Landesamt fuer Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany

9. Data Security

We implement technical and organizational measures:

  • TLS encryption (HTTPS) for all connections
  • Password hashing with bcrypt (not reversible)
  • Regular backups (encrypted with Restic)
  • Access control (role-based, two-factor authentication)
  • Servers in Germany (IONOS data centers)

10. Changes

We reserve the right to adapt this privacy policy. The current version is always available at the respective product URL.

11. Email waiting list (product updates)

On wovenkeep.com you can sign up with your email address for product updates (waiting list). Purpose: occasional information about new features, launch news and beta invitations. Legal basis: your consent (Art. 6(1)(a) GDPR), given via double opt-in — your address is only used after you click the confirmation link. We store: email address, chosen language, timestamps of signup and confirmation, and the IP address at signup and confirmation (proof of consent, Art. 7(1) GDPR). Retention: until you withdraw. Every mail contains an unsubscribe link; unsubscribing deletes the record completely. You can also withdraw informally by mail to info@wovenkeep.com.

Placeholders that must be added before publication:

  • Company name + legal form + address
  • Data protection contact address
  • Competent supervisory authority
  • URL of the privacy policy