Privacy Policy

Last updated: March 2026

1. Data Controller

David Pogorzelski โ€” Software and Data Solutions
Geissbergstrasse 18, 10777 Berlin, Germany
Email: me@davidpogorzel.ski

2. Data We Collect

We collect only the minimum data necessary to provide our Service:

  • Email address โ€” when you register via magic link
  • Payment data โ€” processed by Paddle as Merchant of Record (we do not store card details)
  • Usage analytics โ€” anonymized, cookieless analytics via Umami (no personal data stored)
  • Server logs โ€” IP address, browser type, timestamps (retained for security purposes)

3. How We Use Your Data

  • To provide and maintain the Service (account access, subscription management)
  • To process payments via Paddle
  • To send transactional emails (magic links, subscription confirmations)
  • To improve the Service based on anonymized usage patterns

We do not sell your personal data. We do not use your data for advertising.

4. Authentication (Supabase)

We use Supabase Auth for magic link sign-in. Your email address is transmitted to Supabase (Supabase Inc., San Francisco, USA). Processing is based on Art. 6(1)(b) GDPR (contract performance). Supabase sets a technically necessary session cookie โ€” no consent is required for this.

5. Payment Processing (Paddle)

Payments are processed by Paddle (Paddle.com Market Limited, UK), acting as Merchant of Record. Paddle processes your payment data independently. We receive only your email address, subscription status, and transaction ID. Legal basis: Art. 6(1)(b) GDPR.

Paddle's privacy policy: paddle.com/legal/privacy

6. Analytics (Umami)

We use Umami, a privacy-friendly, cookieless analytics solution. No cookies are set, no personal data is stored, and all data is collected anonymously. No tracking consent is required.

7. Hosting (Vercel)

This website is hosted by Vercel Inc. (San Francisco, USA). Vercel processes technically necessary access data (IP address, timestamp, requested resource). Legal basis: Art. 6(1)(f) GDPR (legitimate interest). Vercel is certified under the EU-US Data Privacy Framework.

8. Cookies

fpreds.com uses only technically necessary cookies (authentication session). We do not use tracking cookies, advertising cookies, or third-party cookies. No cookie consent banner is required.

9. Data Retention

Account data is retained for the duration of your account. Upon account deletion, your personal data is removed within 30 days. Server logs are retained for up to 30 days. Anonymized analytics data is retained indefinitely.

10. Your Rights (GDPR)

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)

To exercise your rights, contact us at: me@davidpogorzel.ski

11. International Data Transfers

Some of our service providers (Supabase, Vercel) are based in the USA. Data transfers are conducted under EU-US Data Privacy Framework adequacy decisions or Standard Contractual Clauses. Paddle is based in the UK, covered by the UK Adequacy Decision.

12. Right to Complain

You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the data protection authority of the German state where you reside or where the alleged violation occurred.

Terms of ServiceRefund PolicyImpressum