Privacy notice
1. Controller
Fabian Baur, Adolf-Schmetzer-Straße 16, 93055 Regensburg
Email: kontakt@zitierfest.de
2. Hosting
The website and the MCP server run on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, in the Nuremberg data centre, Germany. Hetzner processes the data as a processor (Art. 28 GDPR). IP addresses are not stored, not even in access logs. To prevent overload and abuse, the server counts requests per IP address in memory only, for at most one day (for example to limit sign-in emails or calls without credentials); these counters are discarded continuously (Art. 6(1)(f) GDPR, legitimate interest: secure operation). Fonts are served from our own server; there is no connection to Google or other third parties.
Audience measurement
To learn which pages are read, we count page views with Umami. Umami runs on the same server in Germany; no data are transferred to third parties and no cookies are set. Only the page viewed (without query parameters), its title and the referring page are transmitted. We remove screen size and language before sending. Umami derives an identifier from the IP address and browser identification whose random component changes regularly; the IP address itself is not stored. Pages for the account, sign-in and newsletter are not measured. If “Do Not Track” is enabled in your browser, no measurement takes place. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in a website that meets users’ needs).
3. User account and sign-in
For an account we store your email address, the time of registration and of your last sign-in, and your API keys. For a key, only an irreversible hash is stored, not the key itself. You sign in with a code or link sent by email. We only set technically necessary cookies: for the session (30 days) and to protect against forged requests (§ 25(2) no. 2 TDDDG). There are no other cookies.
If you connect an application such as Claude via the sign-in dialog, we store the authorisation (name of the application, time) and hashes of the access tokens issued. The application receives no account data, only the permission to use Zitierfest on your behalf. You can revoke authorisations at any time under “Mein Konto” (my account).
If you register via a link with a referral identifier (such as “?ref=newsletter”), we store this identifier with your account. Voluntarily, you can state under “Mein Konto” how you heard about Zitierfest (choice of fixed answers). We evaluate both only as counts, to learn which channels lead to Zitierfest. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in this evaluation); both are deleted together with the account.
The legal basis is Art. 6(1)(b) GDPR (provision of the account). The data are deleted as soon as you delete your account, which you can do yourself at any time under “Mein Konto”. In our backups, which are transferred encrypted, they remain for up to 60 days and are then overwritten automatically. Sessions and sign-in codes are not included in the backups.
4. Use of the MCP server: content of requests
When you use the service via an AI assistant, we process the request transmitted to Zitierfest. For every tool call, the server logs: time, name of the tool, the information passed (truncated to 500 characters), such as the provision or decision retrieved, a docket number or search terms, as well as result status, size of the response, duration and your account identifier (the identifier of your API key or connected application). This links the entries to your account; you can see the evaluation under “Mein Konto” (my account). We do not receive the rest of your chat with Claude or another AI assistant. IP addresses and the responses are not stored either.
Purpose: provision of the service, enforcement of the daily quota, error analysis and improvement of the collection (such as detecting missing laws), and prevention of abuse. The legal basis is Art. 6(1)(b) GDPR for the provision including the daily quota and Art. 6(1)(f) GDPR for error analysis, improvement and prevention of abuse; the legitimate interest lies in these purposes.
The server rejects requests without valid credentials. In that case it additionally logs the reason for the rejection (such as missing or invalid credentials), the type of credentials presented (such as API key or access token, not the credentials themselves), the HTTP method and the user agent truncated to 120 characters, i.e. the identifier of the calling program, likewise without IP address. This serves to detect abuse and to find sign-in errors.
Retention: rejected requests are aggregated per minute and deleted automatically after 30 days, all other log entries described in this section after 90 days.
Claude is a service of Anthropic PBC. Which data Anthropic processes when you use Claude is governed by its privacy terms. If you connect Zitierfest to another client, such as ChatGPT (OpenAI) or Cursor, the terms of that provider apply to its processing.
Error reports
If you report an error via the “Fehler melden” (report an error) function, we store your description (at most 500 characters), the statute and provision concerned, the time and your account identifier in order to check and fix the error. Legal basis: Art. 6(1)(f) GDPR. Deletion after 365 days at the latest.
5. Email delivery via Resend
We send sign-in codes and newsletters via Resend (Resend, Inc., USA) as a processor. Your email address and the content of the email are transmitted to Resend. Delivery runs via servers in the EU (Ireland). As Resend is a US company, access from the USA cannot be ruled out; Resend is certified under the EU-US Data Privacy Framework (adequacy decision of the European Commission, Art. 45 GDPR); in addition, the EU standard contractual clauses have been agreed in the data processing agreement (Art. 46(2)(c) GDPR). Opens and clicks are not tracked.
6. Newsletter
For the newsletter we store your email address and the time of subscription and confirmation (double opt-in) in order to be able to prove consent. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via the unsubscribe link in every email. Confirmed addresses are added to the recipient list at Resend. After you unsubscribe, the address is removed from the list; proof of the earlier consent may be kept for up to three years.
7. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). An informal email to the address above is sufficient.
You can also lodge a complaint with a data protection supervisory authority, for example the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
As of October 2026 · See also the terms of use