Privacy Policy

Auf Deutsch übersetzen

Last updated: 6 August 2026

We take the protection of your personal data seriously and process it confidentially in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This policy explains what personal data we process on brainmute.app and why. It currently covers the website and the waitlist only. The Brainmute app itself is not yet released; data processing inside the app will be covered by a separate app privacy policy at launch.

Contents
  1. Controller
  2. Legal bases
  3. Hosting and server log files
  4. Content delivery network and security
  5. Self-hosted fonts
  6. Waitlist sign-up and email processing
  7. Email contact and routing
  8. Cookies, local storage and analytics
  9. Transfers to third countries
  10. Storage periods
  11. Your rights
  12. Withdrawal of consent and objection
  13. Right to lodge a complaint
  14. Data security
  15. Minors
  16. Changes to this policy

1. Controller

Controller within the meaning of Art. 4 (7) GDPR is:

Luis Kleemann
Engelbergerstraße 3
79106 Freiburg im Breisgau
Germany

Email: [email protected]

A data protection officer is not required by law (no core activity of regular, large-scale or sensitive data processing under Art. 37 GDPR / § 38 BDSG).

2. Legal bases

Where we process personal data, we rely on the following legal bases:

3. Hosting and server log files

Our website is hosted by:

Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, USA

Further information can be found in Cloudflare's privacy policy.

When you visit the site, Cloudflare automatically processes the following data in server log files, which your browser transmits for technical reasons: IP address, date and time of access, requested file, amount of data transferred, HTTP status code, browser type and version, operating system, and referrer URL.

Purpose: delivery of the website, IT security, and defence against attacks and bot traffic.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a technically sound and secure website).
Storage period: server log files are kept for a maximum of 14 days. This data is not merged with other data sources.

4. Content delivery network and security

Cloudflare is also used as a content delivery network (CDN) and web application firewall (WAF). All traffic between your browser and our site is routed through Cloudflare's global network and malicious requests are filtered out. Processing your IP address is technically necessary for this.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in the performance and security of the site).

5. Self-hosted fonts

This site uses the fonts Inter, JetBrains Mono, Space Grotesk and Instrument Serif (all under the SIL Open Font License). The font files are served exclusively from our own server (Cloudflare Pages). No connection to Google Fonts or any external font CDN is made when the fonts are loaded, so no IP address is transmitted to a font provider.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a consistent presentation).

6. Waitlist sign-up and email processing

On brainmute.app you can enter your email address to join the waitlist and be informed before the public launch of the app.

Data collected

Double opt-in and storage

After you enter your address, we store your email (in plain text) together with a SHA-256 hash, the sign-up timestamp, your IP address and your browser user agent for a maximum of 72 hours in our key-value store (provided by our processor Cloudflare), and send a confirmation email with a one-time link. If you do not click it, this data is automatically deleted after 72 hours. After confirmation, the plain-text address and the browser user agent are deleted from our key-value store; what remains there is the SHA-256 hash of your address, the sign-up and confirmation timestamps, your IP address, and an internal reference ID of our email provider. At the same time we create a second, separate record that carries your unsubscribe link and is stored for a maximum of 400 days. It contains only the SHA-256 hash of your address and the internal reference ID, no plain-text address. It is needed so that the unsubscribe link from your confirmation email keeps working after you have confirmed. In addition, your address is stored as a plain-text contact at our email provider Resend (USA), together with the log data (source, sign-up time, confirmation time, IP address, consent version), in order to send the launch email and to be able to prove your consent. The transfer to the USA is safeguarded by the EU-US Data Privacy Framework and standard contractual clauses (see section 9).

If your contact cannot be created at our email provider, for example because of a technical fault, we additionally store an error record in our key-value store for a maximum of 400 days. It consists of the SHA-256 hash value of your email address, the sign-up and confirmation timestamps and a short technical error message. It contains no plain-text address. Its sole purpose is to make failed sign-ups visible so that the fault can be identified and corrected. Legal basis: our legitimate interest in a functioning and verifiable sign-up process (Art. 6 (1) (f) GDPR). You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 (1) GDPR). This record is deleted automatically after 400 days at the latest.

Purpose

A maximum of two emails: (1) the confirmation email, and (2) a single launch notification with a mandatory unsubscribe link. No further newsletter is sent without separate consent.

Legal basis

The processing of your email address for sending you information is based on your consent (Art. 6 (1) (a) GDPR in conjunction with § 7 (2) no. 3 UWG). We base the retention of the proof of consent (log data such as timestamps, IP address, consent version) on Art. 6 (1) (c) in conjunction with Art. 5 (1) (a), (2), Art. 7 (1) GDPR as well as Art. 6 (1) (f) GDPR. This retention continues, within the statutory limitation periods (three years, § 31 (2) no. 1 OWiG or § 195 BGB), even after a withdrawal.

Processors

ProviderPurposeLocation and safeguards
Cloudflare, Inc.Workers, key-value store, form processingUSA. Data Privacy Framework certified, plus standard contractual clauses and a data processing agreement.
Resend, Inc.
(San Francisco, CA, USA)
Sending the emails and storing the confirmed contactUSA. Data Privacy Framework certified, plus standard contractual clauses and a data processing agreement.

A data processing agreement under Art. 28 GDPR exists with both providers. Transfers to the USA are covered as described in section 9.

Storage period and withdrawal

Unconfirmed sign-ups are deleted automatically after 72 hours. Confirmed entries are kept until you withdraw your consent, and in any case no later than 12 months after sign-up or 30 days after the launch email is sent, whichever comes first. You can withdraw at any time via the unsubscribe link in every email or informally to [email protected]. After withdrawal we delete your email address; your plain-text address is removed from our systems and from our email provider. For a maximum of 400 days we retain only a pseudonymized record, consisting of the SHA-256 hash value of your email address, the time of your withdrawal and an internal reference ID of our email provider, which no longer points to any contact once the contact has been deleted. This serves solely to handle repeated calls to the same unsubscribe link correctly and to document the receipt and processing of your withdrawal, thereby meeting our data-protection accountability obligations. The legal basis is our legitimate interest (Art. 6 (1) (f) GDPR). You have the right to object to this processing at any time on grounds relating to your particular situation (Art. 21 (1) GDPR; see the section "Withdrawal of consent and objection"). This record is automatically deleted after 400 days at the latest.

7. Email contact and routing

Emails to [email protected] are received and stored in a mailbox at IONOS SE (Elgendorfer Straße 57, 56410 Montabaur, Germany) in order to process your request. IONOS acts as our processor pursuant to Art. 28 GDPR; the applicable data processing agreement forms part of the IONOS General Terms and Conditions. Processing takes place within the European Union (primarily in Germany). To our current knowledge, there is no transfer of personal data to a third country. Data processed: sender address, recipient address, subject, message content, attachments and headers.

Legal basis: Art. 6 (1) (b) GDPR (pre-contractual requests) or Art. 6 (1) (f) GDPR (legitimate interest in communication).
Storage period: until your request has been dealt with; statutory retention obligations, in particular commercial and tax retention periods, remain unaffected.
Provision of data: providing your data is voluntary; without your email address and the content of your message we cannot process your request.

8. Cookies, local storage and analytics

This site does not use cookies for analysis, marketing or tracking. There is no Google Analytics, no Meta pixel and no TikTok pixel.

Cloudflare may set one technically necessary cookie (__cf_bm, lifetime max. 30 minutes) for bot defence. Legal basis: § 25 (2) no. 2 TDDDG (strictly necessary) and Art. 6 (1) (f) GDPR.

We use Cloudflare Web Analytics (Cloudflare, Inc., USA) for aggregate, privacy-friendly reach measurement. It does not set any cookies and does not store personal data (in particular no IP addresses, no device fingerprints and no cross-site identifiers). Identifying individual visitors is technically impossible, so no consent under § 25 TDDDG is required. Legal basis for the processing: Art. 6 (1) (f) GDPR. More information: cloudflare.com/web-analytics-privacy.

Because no marketing or tracking cookies are used, this site does not require a cookie consent banner. If tracking tools are added in future, this policy will be updated and, where required, your consent obtained beforehand.

9. Transfers to third countries

For the operation of the website, data is transferred to providers based in the USA (Cloudflare, Resend). The USA is a third country. We ensure an adequate level of protection through:

You can request a copy of these safeguards at [email protected].

10. Storage periods

We store personal data only as long as necessary for the respective purpose or as required by statutory retention obligations. Specific periods: server log files max. 14 days; the __cf_bm cookie max. 30 minutes; unconfirmed waitlist sign-ups max. 72 hours; confirmed waitlist entries until withdrawal, at the latest 12 months after sign-up or 30 days after the launch email, whichever comes first; the separate record carrying the unsubscribe link max. 400 days; after withdrawal, a pseudonymized record (SHA-256 hash value of the address, time of withdrawal and an internal reference ID) for a maximum of 400 days; if a contact cannot be created at our email provider, a pseudonymized error record (SHA-256 hash value of the address, sign-up and confirmation timestamps, technical error message) for a maximum of 400 days.

11. Your rights

As a data subject you have the following rights:

To exercise your rights, an informal message to [email protected] is enough.

12. Withdrawal of consent and objection

You can withdraw any consent at any time with effect for the future (Art. 7 (3) GDPR), for example by clicking the unsubscribe link in our emails. The lawfulness of processing carried out before the withdrawal is not affected. Where data is processed on the basis of legitimate interest, you can object under Art. 21 GDPR for reasons arising from your particular situation.

13. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example at the authority of your habitual residence or of our place of business:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20
70173 Stuttgart, Germany
Web: baden-wuerttemberg.datenschutz.de

14. Data security

This site uses SSL/TLS encryption for security and to protect the transmission of confidential content, recognizable by "https://" and the padlock symbol in your browser.

15. Minors

The waitlist is intended for persons aged 16 or over (Art. 8 (1) GDPR). For younger persons, the consent of a legal guardian is required. If we become aware that data of a person under 16 has been collected without such consent, we will delete it without delay.

16. Changes to this policy

We may adapt this policy when the legal situation or the actual data processing changes (for example when new services are integrated). The version published at brainmute.app/privacy-policy applies.