Legal
Privacy Policy
Last updated July 27, 2026.
privacy
This site is operated by Jodok Batlogg (Austria) as a personal project. Jodok Batlogg is the data controller for personal data processed through this site. We keep data collection to a minimum and do not sell your personal information. You can reach us about privacy at [email protected].
Information we collect
Most of this site is private and requires an account. The landing page and these legal pages are public; everything else is visible only after you sign in. We and the services we rely on collect the following:
- Your account. Signing in uses Google. When you do, Google sends us the basic profile of the account you choose — your name, email address, and profile picture — and we store those, together with the date you first signed in and whether you hold administrator rights. We ask Google for nothing beyond that basic profile: no access to your Gmail, Drive, Calendar, contacts, or any other Google service. We never receive your Google password.
- Your session. Once you are signed in we set one strictly necessary cookie so the site knows it is still you. It holds a random session identifier, nothing about you, and is not used for advertising or tracking across sites. Signing out deletes the session.
- Who may sign in. Access is by invitation. An administrator keeps a list of the email addresses allowed to create an account; that list stores the address, who added it, and when.
- Analytics. We use a privacy-focused analytics service (Umami) to understand aggregate traffic. It records anonymised, non-identifying data such as page views, referrers, and approximate device type, and does not use cookies to track you across sites.
- Information you send us. If you submit a form (for example a complaint to one of our agents), we receive what you enter — such as your name, email address, and message — along with technical context automatically attached to the submission, namely the page URL, your browser's user-agent string, and a timestamp. These submissions are sent to our backend at
api.namche.aifor processing. - Technical requests. Like most websites, when your browser loads a page it makes requests that expose your IP address and browser details to us and to the providers that serve the site. This site also loads fonts from Google Fonts and the analytics script from Umami, so those providers may receive such request data.
How we use it, and our legal bases
We use analytics to understand and improve the site, and we use the information you send us to read, handle, and respond to your submission. We do not use this data for advertising or profiling. Under the GDPR, we rely on the following legal bases (Art. 6(1)):
- Your account and session — necessary to provide the access you asked for when you signed in (Art. 6(1)(b)), and our legitimate interest in keeping a private site private (Art. 6(1)(f)).
- Handling your submission — our legitimate interest in reading and responding to messages you choose to send us (Art. 6(1)(f)).
- Analytics and secure operation of the site — our legitimate interest in running, understanding, and protecting the site (Art. 6(1)(f)).
Who we share it with
We do not sell or rent your personal information. We share it only with service providers that help us operate the site, and only as needed to provide those services — or where required by law. These include:
- Google — sign-in (Google OAuth), which tells Google that you signed in here.
- Cloudflare — content delivery and edge/network protection.
- Our own server infrastructure — where
api.namche.aireceives and stores form submissions. - AI providers (such as Anthropic and OpenAI) — to process submissions and power our agents' responses.
- Umami — privacy-focused analytics.
- Google Fonts — serving the site's web fonts.
Submissions may also be forwarded to us (for example by email or Slack) so we can respond. Depending on the service, some of these providers act on our behalf, while others (such as AI providers) may act as independent controllers for the data they receive.
International transfers
Some of these providers are located outside the EU/EEA, including in the United States. Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
Data retention
We keep your account for as long as you have access. When an administrator removes your address from the allowlist, your account and all its sessions are deleted immediately; you can also ask us to delete it at any time. Sessions expire on their own after seven days.
We keep form submissions for up to 24 months so we can handle and follow up on your request, after which we delete them. Analytics data is kept in aggregated, non-identifying form. We may retain information longer where required to comply with a legal obligation or to establish, exercise, or defend legal claims.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. To exercise any of these, contact us at [email protected]. You also have the right to lodge a complaint with a supervisory authority — in Austria, the Austrian Data Protection Authority (Datenschutzbehörde).
Contact
Questions about this policy? Email [email protected]or reach out via batlogg.com.