Privacy Policy
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) for the data processing on this website is:
Dr. Ingo Glaser
Krumbacherstraße 8
80798 Munich
Germany
Email: [email protected]
Note on local processing: Stript is a local-first application. Your documents are processed exclusively on your own device (see Section 2.6). The online services described below activate and renew evaluation and Pro entitlements. They do not receive documents or document-derived information.
2. What Data We Collect
2.1 Newsletter
When you subscribe to our newsletter, we collect your email address and selected language. Sign-up uses a double opt-in. After entering your address, you receive a confirmation email. For this purpose, the address is transmitted to our email provider Resend. An active contact is only created in the newsletter distribution list after you click the confirmation link. If you do not confirm, you will not receive the newsletter.
We use your email address exclusively to send you the newsletter: occasional product news about Stript and practical content on data protection and the use of AI (roughly monthly). Our newsletter emails contain no tracking pixels and no personalized tracking links. We do not measure who opens an email or clicks a link.
You can unsubscribe at any time using the link in each newsletter issue or by contacting us. You will then receive no further newsletter. Resend subsequently retains the address with an unsubscribed status so that the withdrawal is reliably respected and no further newsletter issue is sent. Any additional retention takes place only to the extent necessary to respect or demonstrate the withdrawal.
Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time with effect for the future.
2.2 Purchase and Licensing
When you purchase Stript Pro, the following data arises:
- Email address (for delivery of the license key and purchase confirmation)
- Payment data (e.g., credit card, PayPal)
The purchase contract is concluded with Lemon Squeezy as Merchant of Record (the seller). All payment processing, invoicing, and VAT remittance is carried out by Lemon Squeezy. We do not store any payment data ourselves. We receive from Lemon Squeezy only the order data required to create and deliver the license (in particular your email address). Lemon Squeezy processes your data in accordance with its own privacy policy as the controller responsible for the payment and sale transaction.
Legal basis: Art. 6(1)(b) GDPR (contract performance / licensing).
Order and license data arising on our side is retained for the duration of the contractual relationship and within statutory retention periods. These include the tax and commercial-law retention obligations under § 147 AO. The retention period for accounting vouchers was shortened to 8 years in 2025. The commercial records (invoices) for the sale transaction are maintained by Lemon Squeezy as Merchant of Record.
2.3 Server Log Data / Hosting
This website is served via Cloudflare Pages. When you access it, Cloudflare, as hosting/CDN provider, automatically processes technical connection data (including IP address, date and time, the resource requested, browser type, and operating system) in order to deliver the website and ensure its stability and security. The newsletter sign-up function additionally uses your IP address only transiently to limit duplicate/spam submissions (rate limiting) and does not store it. Cloudflare’s privacy policy applies to the retention of hosting logs.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technically secure provision of the website).
2.4 Web Analytics
We use Cloudflare Web Analytics to understand how our website is used. Cloudflare Web Analytics collects aggregated, non-identifying data (pages visited, referrer, country derived from the IP without storing it, device/browser/OS type). It uses no cookies, stores or reads no information on your device, and does not track individual visitors. Consent under § 25 TDDDG is therefore not required.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding website usage to improve our service).
2.5 Cookies and Device Storage
This website uses no cookies and stores or reads no information on your device. No tracking, analytics, or marketing cookies are used. Consent under § 25 TDDDG (German Telecommunications Digital Services Data Protection Act) is therefore not required. The fonts used are served locally (self-hosted). There is no integration of Google Fonts or comparable third-party CDNs with data transfer.
2.6 Desktop Application (local-first)
The Stript desktop application processes all documents exclusively on your local machine. No document content, file name, path, document identifier, source commitment, mapping, detection result, entity information, or export activity is transmitted to us or any third party. Optional crash reports are off by default and are transmitted only with your explicit consent. The desktop application makes the following network connections:
- During initial setup, the application downloads the AI models once. The models are fetched from our distribution host downloads.stript.io, which is served through Cloudflare R2. As with any web request, Cloudflare sees your IP address. No document data is transmitted.
- To activate the Free Evaluation for one verified email identity on one active device, you enter an email address and accept the applicable Terms or AGB and this Privacy Policy. The address is normalized by trimming it and converting it to lowercase. It is used transiently to send a verification link through Resend. Stript does not retain the raw address in the evaluation database. Instead, we retain a keyed cryptographic hash of the normalized address, a random evaluation identity, accepted legal-document versions, locale, acceptance time, active device-key and meter-key thumbprints, device assurance level, grant epoch, grant times, and signed security timestamps.
- After activation, the application synchronizes only the aggregate number of evaluation documents used, from zero to five, the number of pending reservations, the meter sequence, a privacy-safe signed checkpoint, the grant epoch, device signature, security timestamps, and app and protocol versions. It does not transmit individual processing records. This synchronization normally occurs at startup when the previous attempt was more than 24 hours ago. A successful synchronization renews the evaluation grant for up to 30 days. No online request is made for each document. If no successful synchronization has occurred within 30 days, only the start of another new evaluation document pauses until the grant is renewed. Existing documents, samples, restoration, anonymization, and exports remain available.
- Evaluation transfer, recovery, and erasure use the same evaluation service. A normal transfer synchronizes the aggregate count before replacing the active device. Recovery after a lost or wiped device does not automatically restore uncertain credits. Verified erasure removes the active evaluation record and retains only an abuse-prevention tombstone as described below.
- Activation, validation, and deactivation of a Pro license take place through Lemon Squeezy’s license API. Activation transmits the license key and a generic device label, such as “Stript (macOS)”. Validation and deactivation transmit the license key and the instance identifier assigned by Lemon Squeezy to that activation. The machine hostname and document data are never transmitted.
- The application renews the separate signed Pro entitlement when needed. For this purpose, it sends the license key, the instance identifier, and the native device-key thumbprint to a function we operate on stript.io, which is served through Cloudflare. The function has Lemon Squeezy validate the license and returns a device-bound signed confirmation token. The function does not store or log the license key or instance identifier. The application attempts to renew the token if it is missing or more than three days old. Continued unlimited processing of new documents requires at least one successful Pro license verification within every 30-day period. If that verification has not succeeded for more than 30 days, unlimited new-document processing pauses until verification succeeds. Existing Pro documents and their workflows remain available. Free Evaluation credits are unaffected. Free Evaluation verification and Pro verification are separate and do not renew one another.
- When the application starts, it checks whether a newer version is available. This fetches a small static version file from stript.io and/or downloads.stript.io. It is an ordinary web request carrying no personal data beyond what is technically necessary, such as the IP address processed by our hosting provider.
- An update is downloaded only at your initiative. If a newer version is available and you choose to install it, the application downloads the update package from downloads.stript.io and verifies its cryptographic signature before installing. Like the update check, this transmits no personal data beyond what any web request necessarily includes. No update is downloaded or installed without your action.
- Optional crash reports are transmitted only with your explicit consent and are off by default. If you enable the feature in the settings, the application transmits a crash report to our own infrastructure (Cloudflare, Section 4.2) when a technical error occurs. A report contains only the app version, the operating system and processor architecture, and a scrubbed technical error description. This consists of the error type and code locations. User paths, file names, and similar details are removed on your device before transmission. Crash reports contain no document content, no detection results, and no user or device identifier. We do not store any IP address on receipt. Because reports carry no identifiers, we cannot determine who a report came from. As with any web request, the hosting provider sees your IP address during transmission. Reports are deleted after at most 90 days and are used solely to diagnose and fix defects. The feature can be disabled again at any time. Doing so deletes any reports still queued on your device. The application shows you a sample of the exact report content beforehand.
Incomplete evaluation challenges are deleted within 24 hours. Active evaluation records are retained while the evaluation remains active. Transfer, recovery, and security-review records are retained for 24 months. After verified erasure, we retain only a keyed identity tombstone for 36 months to prevent repeated evaluation activation with the same identity. The tombstone contains no raw email address. Anonymous aggregate operational counters may be retained without individual identifiers. Stript does not store raw IP addresses at application level. To limit abusive verification requests, the evaluation service retains a keyed cryptographic hash derived from the IP address for at most one hour. Cloudflare additionally processes IP addresses as part of delivering and protecting the service, including rate limiting.
3. Legal Bases
- Newsletter: Art. 6(1)(a) GDPR (consent, double opt-in). You may withdraw your consent at any time with effect for the future. The limited retention of the unsubscribe status is based on Art. 6(1)(f) GDPR. Our legitimate interest is to reliably respect the withdrawal and prevent further newsletter messages.
- Crash reports (optional): Art. 6(1)(a) GDPR (consent). You may withdraw your consent at any time with effect for the future by disabling the feature in the settings. Reports not yet transmitted are deleted from your device.
- Purchase/licensing: Art. 6(1)(b) GDPR (contract performance).
- Free Evaluation activation, grant renewal, transfer, recovery, and erasure: Art. 6(1)(b) GDPR (contract performance). The processing required to protect the five-document allowance against fraud and manipulation is also based on Art. 6(1)(f) GDPR. Our legitimate interest is to protect the evaluation model and the security of the service while collecting as little identifying information as possible.
- Pro entitlement verification: Art. 6(1)(b) GDPR (contract performance). Device binding and security checks are also based on Art. 6(1)(f) GDPR. Our legitimate interest is to prevent unauthorized license use and protect the licensing service.
- Server log data / hosting: Art. 6(1)(f) GDPR (legitimate interest in provision and security).
- Web analytics: Art. 6(1)(f) GDPR (legitimate interest in understanding website usage).
4. Recipients / Data Processors
We use carefully selected service providers with whom, where required, data processing agreements under Art. 28 GDPR are in place.
4.1 Resend (USA)
We use Resend (Plus Five Five, Inc., USA) for sending newsletter messages and Free Evaluation verification links. For evaluation activation, Resend receives the email address, verification link, language, and the technical delivery data required to send the message. This evaluation email does not subscribe you to the newsletter. Resend processes the data on our behalf. See Section 5 regarding the transfer of data to the USA.
More information: resend.com/legal/privacy-policy
4.2 Cloudflare, Inc. (USA)
This website is hosted via Cloudflare Pages. We also use Cloudflare Web Analytics, Cloudflare R2 for software downloads and updates, and Cloudflare Workers with an EU-jurisdiction SQLite-backed Durable Object for the evaluation service at api.stript.io. If you enable optional crash reports, Cloudflare also receives and stores them. Cloudflare processes technical access data and the evaluation data described in Section 2.6 on our behalf. See Section 5 regarding the transfer of data to the USA.
More information: cloudflare.com/privacypolicy
4.3 Lemon Squeezy (USA)
We use Lemon Squeezy as Merchant of Record for payment processing and license management. The provider is Sold through Link, LLC (formerly Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, Utah 84101, USA. Lemon Squeezy processes purchase data (email, payment information). For the sale and payment transaction, Lemon Squeezy acts as an independent controller. Where Lemon Squeezy additionally processes data on our behalf (license management), this is based on Lemon Squeezy’s data processing agreement (lemonsqueezy.com/dpa). See Section 5 regarding the transfer of data to the USA.
More information: lemonsqueezy.com/privacy
5. Transfers to Third Countries (USA)
The providers named in Section 4 are based in the USA. Personal data may therefore be transferred to the USA. Where a provider is certified under the EU-US Data Privacy Framework (DPF), the transfer takes place on the basis of the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR). In addition, or in the event that a certification no longer exists, we base the transfer on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Cloudflare (Cloudflare, Inc.): certified under the EU-US DPF. Standard Contractual Clauses are additionally available.
- Resend (Plus Five Five, Inc.): certified under the EU-US DPF. Standard Contractual Clauses are additionally available.
- Lemon Squeezy (Sold through Link, LLC): not certified under the EU-US DPF. The transfer is based on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR. See Lemon Squeezy’s data processing agreement.
6. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) to processing based on Art. 6(1)(f) GDPR
- Right to withdraw consent (Art. 7(3) GDPR) with effect for the future
To exercise your rights, please contact: [email protected]
7. Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Website: lda.bayern.de
8. No Automated Decision-Making
There is no solely automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The AI-assisted PII detection in the desktop application runs locally on your device and serves as a tool for you. It makes no legally significant decisions about you.
9. Changes
We reserve the right to update this privacy policy to comply with current legal requirements or to implement changes to our services.
Last updated: 15.07.2026