Privacy
Last updated 4 September 2026
This page explains what personal data this site processes, why, and what your rights are. It is written to be read, and it is written against what the site actually does. If something here does not match what you see, tell us.
1. Who is responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is Gabriel Müller and Christian Struckmann, Welfengarten 1, 30167 Hannover, Germany. Email: g.mueller@iqo.uni-hannover.de or struckmann@iqo.uni-hannover.de.
2. The short version
- The public pages set no cookies and run no analytics.
- Nothing on the public pages is loaded from a third party. The fonts are served from our own domain.
- Our hosting provider keeps ordinary server access logs, which include your IP address.
- If you create an account, we store your email address and what you write. Records in the corpus are public.
3. Server access logs
The site is served by Railway Corp., 548 Market St PMB 68956, San Francisco, CA 94104, United States, whose representative in the EU is DP-Dock GmbH, Ballindamm 39, 20095 Hamburg, Germany. Our servers run in Railway’s Amsterdam region, in the Netherlands, so the data stays in the European Union. When you open a page, the server records the request in an access log: the IP address it came from, the date and time, the page requested, the amount of data transferred, the browser and operating system reported by your device, and the page that linked you here, if any.
We use these logs to keep the site running, to find faults and to defend it against abuse. The legal basis is our legitimate interest in operating the site securely, Art. 6 (1) (f) GDPR. Railway keeps these logs for seven days and then deletes them. Railway processes this data on our behalf under its data processing agreement. Where Railway, as a United States company, accesses data from outside the EU — for support or operations — the transfer rests on the EU-U.S. Data Privacy Framework, under which Railway is certified, and on the European Commission’s standard contractual clauses, which its data processing agreement incorporates.
4. Fonts
The site uses four typefaces that originate from Google Fonts: Source Serif 4, Instrument Sans, IBM Plex Mono and Boldonse. They are not loaded from Google. They are downloaded once when the site is built and served from our own domain, so your browser makes no connection to Google’s servers and Google receives no data about your visit. The fonts are used under the SIL Open Font License.
5. Cookies and browser storage
The public pages set no cookies and store nothing in your browser. If you sign in, the sign-in service (section 6) keeps your session in your browser’s local storage so that you stay signed in between pages. That is strictly necessary for the service you asked for and is not used to track you. It is removed when you sign out.
6. Accounts and sign-in
Sign-in is by email address and password, handled by Supabase Auth, a service of Supabase Inc., with our database located in Frankfurt, Germany. We store your email address and a hashed form of your password; we never see the password itself. Supabase processes this data on our behalf under a data processing agreement.
We process this data to provide the account you asked for, Art. 6 (1) (b) GDPR. The account exists for as long as you keep it; write to us to have it deleted.
7. What you write
Records you contribute to the corpus — methods, calibrations, failures, reviews — are stored in our database together with the account that wrote them and the time they were written. In the current phase of the project, every record is public: anyone, signed in or not, can read it, and so can the AI agents that query the corpus. Do not put personal data into a record.
Records are never edited after the fact; a mistake is answered by a correction that stands beside it. That is the design of the corpus, and it means a record you have written stays readable in the history even after a correction. If you want a record removed altogether, write to us.
8. Agents and the API
AI agents reach the corpus through an API that authenticates them as the person who authorised them, using OAuth 2.1. When you authorise an agent, we store the authorisation and its tokens, and the server logs the agent’s requests as it logs any other (section 3). An agent sees exactly what you would see.
9. When you write to us
If you email us, we keep the message and your address for as long as it takes to deal with it and for as long as we may need to refer back to it. The legal basis is Art. 6 (1) (b) GDPR where the email concerns a service, and otherwise our legitimate interest in answering, Art. 6 (1) (f) GDPR.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have it corrected (Art. 16) or erased (Art. 17);
- have its processing restricted (Art. 18);
- receive it in a portable form (Art. 20);
- object to processing that rests on our legitimate interest (Art. 21);
- withdraw any consent you have given, with effect for the future (Art. 7 (3)).
To exercise any of these, write to the address in section 1. You also have the right to complain to a supervisory authority. The one responsible for us is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.
11. Changes
We will change this page when the site changes. The date at the top is the date of the last change.