Privacy
This page explains what data is collected when you visit this website, join the waitlist, or want to sign in to the app, and what happens to it. There isn't much, and none of it goes to third parties.
Who is responsible
I am responsible for this website, the waitlist, and the app:
Theodoridis AthanasiosRumpenheimerstr. 49
63075 Offenbach am Main, Germany
Email: info@xreos.app
Send privacy questions to this address.
Where the site runs
The website runs on a server I rent from 1blu (1blu AG, Berlin). The server needs your IP address to send you the page; there's no way around that.
For this website, the server keeps no access log: it doesn't record which page you open or when. Only when something goes wrong does it note the error, so I can find it; your IP address may be part of that note. These notes are deleted after seven days. The legal basis is my legitimate interest in running the site securely (Art. 6(1)(f) GDPR).
So that nothing is lost if something breaks, I back up the website's data every night and each time before I change anything on it, waitlist included. These backups stay on the server at 1blu for seven days. Another copy is stored encrypted at Hetzner (Hetzner Online GmbH, Gunzenhausen) and is deleted after 30 days. There are no other copies. So anything I delete stays in the backups for a while; after six weeks at most, it's gone from there too.
The language cookie
If you choose a language in the footer or in the bar at the top of the page, the website remembers your choice in a cookie named “sprache”. It contains only the code: de, en, or el. It lasts one year and makes sure you land in your language on your next visit.
The site sets this cookie only because you chose a language yourself; it needs the cookie to apply your choice (§ 25(2) of the German TDDDG). There are no other cookies.
The waitlist
If you join the waitlist, I store your email address, the language of the page you joined on, the time you joined, and the time you confirmed. I use this to send you an email when Xreos launches, and an occasional one when there's something new.
First you get an email with a link to confirm. If you click it, you're on the list. If you don't, your address and everything stored with it are deleted after seven days.
Every email has a link to unsubscribe. It's the one way that leaves no lasting trace: one click deletes your address, with no confirmation step. It stays in the backups until they expire; after six weeks at most, it isn't stored anywhere. If you write to me instead, I'll remove you from the list by hand. In that case, your address is still kept in one place.
Every change I make by hand goes into the Xreos records: your address, the time, and a short reason like “at your request.” That way, I can later prove who was removed from the list, when, and why. Your address stays there forever. Nothing in the records can be changed or deleted, not even at your request. They're stored on the same server as this website and, like everything on it, in the backups too. The legal basis is my legitimate interest in being able to prove this (Art. 6(1)(f) GDPR).
The emails are sent by my own mail server. No third-party service sees your address. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time, with the link or by email.
The app
The Xreos app is at app.xreos.app, on the same server at 1blu as this website. It's in closed beta right now: only someone with an invite code from me can create an account. For everyone else, there's just the home page and sign-in. Here's what gets collected there.
If you enter an email address at sign-in that has no account, the app doesn't send an email. It still remembers the address for a while, so that nobody on the outside can tell whether an account exists, and so that nobody gets unlimited attempts with it. It's deleted after a little over a day. If a backup runs during that time, the address stays in it until the backup expires; after six weeks at most, it's gone from there too.
The app itself never writes your IP address anywhere. It keeps it only in server memory, to block too many attempts, for a little over a day; every restart wipes it.
The app sets cookies only once you submit your address, and only the ones sign-in can't work without (§ 25(2) of the German TDDDG). Two of them remember for 15 minutes that you're signing in on this device; one of them holds what you typed. After you sign in, the app deletes both and sets a third one that keeps you signed in.
For the app, too, the server keeps no access log. If something goes wrong, it notes the error, just as it does for the website, and the notes are deleted after seven days. The legal basis for all of this is my legitimate interest in running things securely (Art. 6(1)(f) GDPR).
Your rights
You can ask me what data I have about you. You can have it corrected, deleted, or sent to you in a common format, and have its processing restricted. You can object to processing based on legitimate interest. Just write to the address above.
You can complain to a data protection authority if you think I'm handling your data wrongly.
No analytics, no sharing
The website doesn't count visitors, doesn't use analytics tools, and doesn't load anything from other servers, not even fonts. I don't pass your data on to anyone. 1blu can see it only because the server is in their data center, and they aren't allowed to do anything with it. Hetzner only holds the encrypted copy; nobody there can read it.