01Who is responsible
xyst.wtf is run by one person, not a company. The controller for the purposes of Art. 4(7) GDPR is:
Kay David Kalex c/o Online-Impressum #4165Europaring 90
53757 St. Augustin
Germany
[email protected]
There is no data protection officer. A sole trader of this size isn't required to appoint one under §38 BDSG, and pretending otherwise would just give you a title to write to instead of a person. Write to the address above.
02What we collect and why
Each row is a thing we hold, the reason we hold it, and the legal basis under Art. 6 GDPR that permits it.
We don't run analytics or advertising trackers of any kind. There is no Google Analytics, no advertising pixel, and no third-party script on the site other than the Cloudflare bot check on the sign-in and sign-up forms.
04Profile views
When someone opens a public xyst.wtf page we record the visit: IP address, the country derived from it, the referring site, and the browser and device family. The page's owner sees this as counts and breakdowns, never as individual visitor records, and never as your IP address.
A visit counts once per device per day. The marker that enforces this is deleted after 24 hours. The view record itself is deleted after 24 months.
05Abuse detection and automated processing
To stop one person running many accounts to inflate their own view counts, we keep a record of which IP addresses an account has been seen at and score accounts for patterns that suggest multi-accounting. That record is deleted 12 months after an address was last seen.
The scoring is automatic. The decisions are not. A high score flags an account for a person to look at; it does not by itself restrict, hide or delete anything. That means no decision producing legal or similarly significant effects is made solely by automated means within the meaning of Art. 22 GDPR. You can object to this processing at any time under Art. 21: write to us and a person will review the account by hand.
06How long we keep things
Deleting your account erases it immediately and for good. Everything keyed to it goes with it in the same transaction (your page, links, uploads, audio, sessions, view history, IP history and purchase records), and your username is released for anyone else to claim. There is no grace period and no way for us to restore it afterwards.
07Who else sees it
We don't sell personal data and never have. These are the only companies that receive any, each because they perform a specific job:
All of them except Lemon Squeezy act as processors on our instructions under Art. 28 GDPR. Lemon Squeezy is the merchant of record for purchases, which makes it the seller and its own controller for payment data: your card details go to them and never reach us.
08Transfers outside the EU
The application and its database are self-hosted in Germany. Your account and your page never leave the EU on our infrastructure.
The companies in section 07 are established in the United States, so using them involves a transfer under Chapter V GDPR. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework adequacy decision. You can ask us for a copy of the safeguards for any given transfer.
09Your rights
Under the GDPR you have the right to:
Write to [email protected] and we'll answer within one month, as Art. 12(3) requires. We don't charge for this, and we won't treat you differently for asking.
If you think we've got it wrong you can complain to a supervisory authority. Ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), and you may also go to the authority where you live or work.
10California residents
This section is the notice required by the California Consumer Privacy Act as amended by the CPRA. We are almost certainly not a “business” as the CCPA defines one (we are far below all three thresholds), but the rights below are honoured regardless.
Categories we collect
Sale and sharing
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in §1798.140. We have never done either. We do not sell or share the personal information of consumers under 16. Because there is nothing to opt out of, there is no “Do Not Sell or Share My Personal Information” link on this site.
Your California rights
- Know what we collect, where it came from, why we collect it and who receives it.
- Delete what we hold: do it yourself from Settings, or ask us.
- Correct anything inaccurate.
- Limit the use of sensitive personal information. We don't use it to infer characteristics, so there is nothing to limit.
- Non-discrimination: exercising any of these never costs you service or money.
Send requests to [email protected]. We'll confirm within 10 business days and answer within 45. An authorised agent may act for you if they provide written permission that we can verify with you directly. We verify requests against the email address on the account; for a deletion we'll also ask you to confirm from that address, because deletion here is irreversible.
11Children
xyst.wtf is not for anyone under 16. Art. 8 GDPR sets the age of digital consent at 16 and Germany has not lowered it, so 16 is our floor rather than the 13 that US-based services often use. We don't knowingly collect anything from a child below it. If you believe a child has made an account, write to [email protected] and we'll delete it.
12Security
Passwords are hashed with Argon2 and are not recoverable, not by you and not by us. Sessions are HTTP-only cookies that expire after 14 days. Two-factor authentication is available in Settings. Every form submission is checked against a CSRF token, and the site sets a strict Content Security Policy that forbids inline and third-party scripts. Uploaded images have their EXIF, XMP and IPTC metadata stripped before storage, so a photo you upload does not carry your camera's GPS coordinates to your visitors.
None of which makes a breach impossible. If one happens and it puts your rights at risk, we'll tell the supervisory authority within 72 hours and tell you without undue delay, as Arts. 33 and 34 require.
13Changes
If this policy changes materially we'll update the date at the top and say so on the site before the change takes effect. Continuing to use xyst.wtf after that means the new version applies.