Privacy policy
This notice is tailored to JackSoundWorks and jackboyman.com (overview). Have it reviewed by a professional, especially around payments, AI processing, and newsletter flows.
1. Controller
As stated in the Imprint.
2. Website hosting
Static pages are delivered via hosting providers (for example Cloudflare Pages). When you open a page, technically necessary data (such as IP address, time, user agent) may be processed by that provider. Details are in the processor or privacy notices of the respective host.
3. AI Tools (sign-in, credits, AI)
For the “AI Tools” page, the following also applies:
- Supabase (auth / database): Sign-in via magic link (email). Account and usage or credit data are stored according to the project configuration. Provider: Supabase Inc.
- Vercel (API): Server functions for balance, generation, and Stripe Checkout run there.
- Anthropic (Claude): Your inputs are processed via the API to generate text (on Anthropic infrastructure). No Anthropic account data is stored in the browser.
- Stripe (payments): Payment processing for credit packs. Card data is handled by Stripe, not stored on our servers.
4. Guest book
The guest book may use a service such as Firebase. Which data is stored follows from the form (for example name, message) and the Firebase configuration.
5. Newsletter
The newsletter link goes to Beehiiv. Beehiiv’s privacy rules apply there; we only receive the data you provide on that platform.
6. Cookies & local storage
AI sign-in may store information in the browser (for example local or session storage for the session). This template does not describe non-essential tracking cookies - if you add analytics, describe it here.
7. Legal bases (extract)
Where we perform contracts (for example AI Tools use, credit purchase): Art. 6 (1) lit. b GDPR. Where we rely on legitimate interests (for example security, abuse prevention): Art. 6 (1) lit. f GDPR. Where consent applies (external newsletter): Art. 6 (1) lit. a GDPR.
8. Retention
We keep personal data only as long as needed for the purposes or where the law requires. Set concrete periods with your lawyer or processors.
9. Your rights
Under the GDPR you have rights including access, rectification, erasure, restriction of processing, data portability, objection, and complaint to a supervisory authority.
10. Privacy contact
Email: Loaded from js/legal-config.js
App-specific: the Android app “Panda Notes” still has its own page red-panda-privacy-policy.html.