Privacy Policy
As of: September 2026
This translation is provided for information only. The German version is legally binding: German privacy policy.
1. Controller
Nick Schäfer, Quellenkontor, An der Mannsfaust 9, 60599 Frankfurt am Main, Germany, email nick@nicksadvisory.com.
2. In short
We collect as little as possible. For an account, we only need your email address. There's no tracking, no advertising and no cookies other than the sign-in cookies. We don't store the parameters of your queries, such as dates. We only count how many requests an account makes per month.
3. Visiting the website and the API
The website, the API and the MCP server run on Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. The server functions run in Frankfurt am Main. When you visit, Vercel processes technically necessary data such as IP address, timestamp, the address requested and browser identifier, to deliver the page and protect it against attacks. Vercel keeps logs only briefly. We have a data processing agreement (Auftragsverarbeitungsvertrag) with Vercel. For transfers to the USA, Vercel relies on the EU-US Data Privacy Framework and standard contractual clauses. The legal basis is Art. 6(1)(f) GDPR (secure operation) and, for customers, Art. 6(1)(b) GDPR.
We serve fonts from our own domain. Visiting the page sends no requests to Google or other third parties.
4. Account and sign-in
For an account, we store your email address, your plan, monthly usage counters, the names of your keys and when they were used. For API keys and sign-in links, we only store checksums (hashes), never the plain text. To protect sign-in from abuse, we store the email address and a pseudonymized hash of the IP address for every sign-in attempt, generated with a secret key, not the address itself. We delete these entries automatically after 24 hours. The data is held by Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513, in a data center in Frankfurt am Main. We have a data processing agreement with Supabase. For possible access from third countries, for example during maintenance or support, this agreement includes the European Commission's standard contractual clauses. The legal basis is Art. 6(1)(b) GDPR, and for abuse protection Art. 6(1)(f) GDPR.
We send the sign-in link through Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France). Brevo processes your email address for this purpose as our processor (Auftragsverarbeiter).
If you write to us through the contact form, we send the subject, email address, optionally the company, and your message by email through Brevo to our inbox. We store none of this on the website, only a pseudonymized hash of the IP address with a timestamp, to limit mass submissions. We delete this after 24 hours. We keep the email for as long as we need it to handle your request. The legal basis is Art. 6(1)(b) GDPR for requests related to a contract, otherwise Art. 6(1)(f) GDPR.
5. Signing in with Google
Instead of the email link, you can sign in with your Google account if we've enabled this option. Google confirms only your email address to us (scope "openid email", no name, no profile picture, no access to any other Google data). We use it to find your account or create a new one, exactly as with the email link. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; processing may also take place at its parent company Google LLC, USA. For this transfer to the USA, Google relies on the EU-US Data Privacy Framework (an adequacy decision by the European Commission). Details in Google's privacy policy.
6. Signing in with GitHub
You can also sign in with your GitHub account if we've enabled this option. We only request the "user:email" scope and take over your verified primary email address from your GitHub profile, no other profile data. We use it to find your account or create a new one, exactly as with the email link. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement). The provider is GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA (part of Microsoft). For this transfer to the USA, GitHub relies on the EU-US Data Privacy Framework (an adequacy decision by the European Commission). Details in GitHub's privacy statement.
7. Payments
We process paid plans through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Stripe processes payment and billing data both on its own responsibility and as our processor. We never receive full card data. The legal basis is Art. 6(1)(b) and (c) GDPR.
8. Webhooks
If you create webhooks, we store the address, the datasets you chose and the delivery status. We only send information about changed data to this address, never personal data.
9. Cookies and browser storage
After signing in, we set two technically necessary cookies for 30 days: qk_sitzung keeps you signed in, qk_angemeldet contains only the value 1, so the header can show the way to your account. We delete both when you sign out. If you sign in with Google or GitHub, we also set, for at most 10 minutes, a technically necessary cookie that protects the process against forgery (state and PKCE); it's removed again once the provider calls back. If you choose a language in a code example, your browser remembers that choice in local storage (qk-variante). All of this is required for the function you requested (§ 25(2) TDDDG, German Telecommunications Digital Services Data Protection Act). There are no other cookies or trackers.
10. Retention period
We store account data until you delete your account. You can do that yourself, at any time, in your account. Sign-in links expire after 20 minutes; we delete sign-in attempts and contact-form entries after 24 hours. We keep invoices and other accounting records for eight years, and commercial books and financial statements for ten years (§ 147 AO, German Fiscal Code; § 257 HGB, German Commercial Code).
11. Service providers at a glance
As of September 24, 2026. If this list changes, we'll update this policy.
| Service provider | Purpose | Location | Place of processing |
|---|---|---|---|
| Vercel Inc. | Hosting for the website, API and MCP server | USA | Frankfurt am Main, delivered worldwide |
| Supabase Pte. Ltd. | Database for accounts, keys and counters | Singapore | Frankfurt am Main |
| Sendinblue SAS (Brevo) | Sending sign-in emails and contact-form messages | France | EU |
| Stripe Payments Europe, Ltd. | Payments and invoices | Ireland | EU, partly USA |
| Google Ireland Limited | Sign-in with Google (optional), confirms only the email address | Ireland, parent company Google LLC in the USA | EU, partly USA |
| GitHub, Inc. (Microsoft) | Sign-in with GitHub (optional), confirms only the primary email address | USA | USA |
12. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Write to the address given above. You can also lodge a complaint with a data protection supervisory authority, for example the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit).
13. No automated decisions
We do not make automated decisions within the meaning of Art. 22 GDPR, and we do not build profiles.