Draft. Needs a legal read before it ships.

Anything marked [TO FILL] is waiting on a decision a person has to make, starting with the legal business name.

The German version is a plain translation of this draft, not a separately drafted text. It needs the same legal read.

Privacy policy

Last updated: [TO FILL]

This page covers code-addict.dev: the account, the checkout and the dashboard. Each extension has its own policy describing what it does on your machine, and those live on the extension's own site.

If you never buy anything

Reading these pages creates no account and stores nothing that identifies you.

Counting page views

The public pages count views with Umami, which we run on our own server in Nuremberg, Germany. There is no Google Analytics, no tag manager and no advertising pixel, and the counting script is served from this domain — so no third party sees your request and none receives the result.

The signed-in pages are not counted at all — the address of those pages would say which subscription you were looking at — and nothing is written to your device, which is why you were not asked to accept anything.

A page view records:
  • the path you opened, and its query string if it had one
  • the page that linked you here, and the page title
  • your browser, operating system, device type, screen size and language
  • the country your IP address maps to. The same lookup can also yield a region and a city; ours resolves neither

Your IP address itself is not stored. It is used to look up that country and to derive an identifier so opening a second page is not counted as a second person, and then it is gone. There is no column for it in the database, and none for your browser user-agent string either.

None of it follows you to another website and none of it is combined with anything else. The legal basis is our legitimate interest in knowing which pages get read, under Art. 6 (1) (f) GDPR. Rows older than 12 months are deleted every night.

The script reads one value, a umami.disabled key in localStorage, only to check whether you have switched the counting off yourself. It never writes it.

To switch it off for yourself, open your browser's developer console on this site and run localStorage.setItem('umami.disabled', 1).

If you create an account

  • Supabase stores your email address and which licences the account holds. [TO FILL — hosting region and the data processing agreement.]
  • Paddle is the merchant of record and handles the payment. Card details go to Paddle and never reach us. We receive the fact that a payment succeeded and what it was for.

Cookies

One session cookie, set when you sign in, so that moving between pages does not sign you out again. It is strictly necessary for a service you asked for, which is why there is no banner asking you to accept it. Signing out clears it.

Your rights

You can ask what is held about you, have it corrected or deleted, object to processing, and complain to a supervisory authority. You can do the first two yourself on your account page: it downloads everything held about the account as a file, and deletes the account outright. Paddle keeps its own payment records for as long as tax law requires.

[TO FILL — contact address for requests, supervisory authority, retention periods.]

Controller: [TO FILL — legal entity, address, email.]