Legal

Privacy Policy

What xyst.wtf collects, why, how long it's kept, and what you can make us do about it. Written to the GDPR and the CCPA, and kept honest by the fact that the retention limits below are the ones the server actually enforces.

In effect 27 July 2026

01Who is responsible

xyst.wtf is run by one person, not a company. The controller for the purposes of Art. 4(7) GDPR is:

Kay David Kalex c/o Online-Impressum #4165
Europaring 90
53757 St. Augustin
Germany
[email protected]

There is no data protection officer. A sole trader of this size isn't required to appoint one under §38 BDSG, and pretending otherwise would just give you a title to write to instead of a person. Write to the address above.

02What we collect and why

Each row is a thing we hold, the reason we hold it, and the legal basis under Art. 6 GDPR that permits it.

Email address and password To create your account, sign you in, and send verification and account emails. The password is stored only as an Argon2 hash — it is never kept in a readable form. Contract (Art. 6(1)(b))
Username, display name, bio, avatar, background To publish the page you asked us to publish. Everything you choose to put on your public page. Contract (Art. 6(1)(b))
Discord ID, username, avatar and email To sign you in and, if you turn it on, show your Discord presence. Only if you choose to sign in with Discord or connect it later. Consent (Art. 6(1)(a)) — disconnect at any time in Settings
IP address, browser, device and platform To keep sessions secure, throttle brute-force and signup abuse, and count views. Recorded when you sign in and when someone visits a page. Legitimate interests (Art. 6(1)(f)) — running the service securely
Country and referring site To give a page owner the visitor breakdown their dashboard shows. Country is derived from the visitor's IP at country level only. We do not use precise location. Legitimate interests (Art. 6(1)(f))
Links, uploaded images and audio To store and serve the content of your page and, if you bought it, your file host. Contract (Art. 6(1)(b))
Which products you bought and when To unlock what you paid for and answer questions about it. Card details never reach us — see Lemon Squeezy below. Contract (Art. 6(1)(b))
Two-factor secret and backup-code hashes To check the second factor when you sign in, if you turned it on. Contract (Art. 6(1)(b))
Abuse signals and risk scores To find people running many accounts to inflate view counts. Derived from the data above — chiefly which accounts share an IP range. Legitimate interests (Art. 6(1)(f)) — keeping the leaderboard honest

We don't run analytics or advertising trackers of any kind. There is no Google Analytics, no advertising pixel, and no third-party script on the site other than the Cloudflare bot check on the sign-in and sign-up forms.

03Cookies

Three, all of them strictly necessary, none of them used to track you:

Because all three are strictly necessary to deliver a service you asked for, §25(2) TDDDG lets us set them without a consent banner. If we ever add one that isn't, you'll be asked first.

04Profile views

When someone opens a public xyst.wtf page we record the visit: IP address, the country derived from it, the referring site, and the browser and device family. The page's owner sees this as counts and breakdowns, never as individual visitor records, and never as your IP address.

A visit counts once per device per day. The marker that enforces this is deleted after 24 hours. The view record itself is deleted after 24 months.

05Abuse detection and automated processing

To stop one person running many accounts to inflate their own view counts, we keep a record of which IP addresses an account has been seen at and score accounts for patterns that suggest multi-accounting. That record is deleted 12 months after an address was last seen.

The scoring is automatic. The decisions are not. A high score flags an account for a person to look at; it does not by itself restrict, hide or delete anything. That means no decision producing legal or similarly significant effects is made solely by automated means within the meaning of Art. 22 GDPR. You can object to this processing at any time under Art. 21: write to us and a person will review the account by hand.

06How long we keep things

Your account and everything on your pageUntil you delete your account
Sign-in sessions14 days
Profile views (IP, country, referrer, device)24 months
IP history used for abuse detection12 months after an address was last seen
“Already counted today” markers24 hours
Email rate-limit log7 days
Email verification codes15 minutes

Deleting your account erases it immediately and for good. Everything keyed to it goes with it in the same transaction (your page, links, uploads, audio, sessions, view history, IP history and purchase records), and your username is released for anyone else to claim. There is no grace period and no way for us to restore it afterwards.

07Who else sees it

We don't sell personal data and never have. These are the only companies that receive any, each because they perform a specific job:

Cloudflare, Inc. Stores uploaded images and audio (R2), and runs the bot check on the sign-in and sign-up forms (Turnstile). USA / global
Lemon Squeezy, LLC Merchant of record for every purchase. They take the payment and hold the card details; we only receive confirmation that an order happened. USA
Resend Delivers verification and account emails. USA
Discord, Inc. Sign-in and avatars — only if you connect Discord. USA
Google LLC (YouTube) Contacted only at the moment you import an audio track by URL. USA

All of them except Lemon Squeezy act as processors on our instructions under Art. 28 GDPR. Lemon Squeezy is the merchant of record for purchases, which makes it the seller and its own controller for payment data: your card details go to them and never reach us.

08Transfers outside the EU

The application and its database are self-hosted in Germany. Your account and your page never leave the EU on our infrastructure.

The companies in section 07 are established in the United States, so using them involves a transfer under Chapter V GDPR. Those transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework adequacy decision. You can ask us for a copy of the safeguards for any given transfer.

09Your rights

Under the GDPR you have the right to:

AccessAsk what we hold about you and get a copy.
RectificationHave anything inaccurate corrected — most of it you can edit yourself in the dashboard.
ErasureDelete your account from Settings, which erases it immediately, or ask us to do it.
RestrictionAsk us to stop processing while a dispute is resolved.
PortabilityReceive the data you gave us in a machine-readable form.
ObjectionObject to anything we do on the basis of legitimate interests, including abuse scoring.
Withdraw consentDisconnect Discord at any time; withdrawing does not affect what happened before.

Write to [email protected] and we'll answer within one month, as Art. 12(3) requires. We don't charge for this, and we won't treat you differently for asking.

If you think we've got it wrong you can complain to a supervisory authority. Ours is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), and you may also go to the authority where you live or work.

10California residents

This section is the notice required by the California Consumer Privacy Act as amended by the CPRA. We are almost certainly not a “business” as the CCPA defines one (we are far below all three thresholds), but the rights below are honoured regardless.

Categories we collect

Identifiers Yes Email address, username, IP address, account ID, Discord ID.
Commercial information Yes Which products you bought and when.
Internet or network activity Yes Pages viewed, referring site, browser and device.
Geolocation data Yes Country only, derived from IP. Never precise location.
Audio, visual or similar Yes Images and audio you upload.
Sensitive personal information Limited Login credentials are held only as hashes and never used to infer anything about you.
Biometric information No
Professional or education information No
Inferences used to build a profile No

Sale and sharing

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in §1798.140. We have never done either. We do not sell or share the personal information of consumers under 16. Because there is nothing to opt out of, there is no “Do Not Sell or Share My Personal Information” link on this site.

Your California rights

Send requests to [email protected]. We'll confirm within 10 business days and answer within 45. An authorised agent may act for you if they provide written permission that we can verify with you directly. We verify requests against the email address on the account; for a deletion we'll also ask you to confirm from that address, because deletion here is irreversible.

11Children

xyst.wtf is not for anyone under 16. Art. 8 GDPR sets the age of digital consent at 16 and Germany has not lowered it, so 16 is our floor rather than the 13 that US-based services often use. We don't knowingly collect anything from a child below it. If you believe a child has made an account, write to [email protected] and we'll delete it.

12Security

Passwords are hashed with Argon2 and are not recoverable, not by you and not by us. Sessions are HTTP-only cookies that expire after 14 days. Two-factor authentication is available in Settings. Every form submission is checked against a CSRF token, and the site sets a strict Content Security Policy that forbids inline and third-party scripts. Uploaded images have their EXIF, XMP and IPTC metadata stripped before storage, so a photo you upload does not carry your camera's GPS coordinates to your visitors.

None of which makes a breach impossible. If one happens and it puts your rights at risk, we'll tell the supervisory authority within 72 hours and tell you without undue delay, as Arts. 33 and 34 require.

13Changes

If this policy changes materially we'll update the date at the top and say so on the site before the change takes effect. Continuing to use xyst.wtf after that means the new version applies.