The short version — plain English
EU-hosted
Your data stays in Europe

Our server and analytics (Matomo) are hosted in Germany. Only screenshots (OpenAI) and payment data (Stripe) leave the EU.

Screenshots are never stored

Uploaded images go directly to OpenAI for processing and are never written to our servers.

Only 2 third parties

OpenAI (screenshot processing) and Stripe (payments). No advertising networks, no data brokers.

Delete anytime

Email us and your account and all associated data will be erased within 30 days.

Contents
  1. Data controller
  2. Data we collect
  3. How we use your data
  4. Legal basis (GDPR)
  5. Third-party sub-processors
  6. Analytics — Matomo
  7. International data transfers
  8. Data retention
  9. 9. Cookies & local storage
  10. 10. Children's privacy
  11. 11. Changes to this policy
  12. 12. Contact & complaints

1. Data controller

RizzlerGPT is operated by:

Kirpeit Solutions

Germany

Email: kirpeit@kirpeit-solutions.de

Kirpeit Solutions is the data controller responsible for your personal data under the GDPR and applicable data protection law. When this policy says "we", "us" or "our", it refers to Kirpeit Solutions.

2. Data we collect

Data you provide directly

DataWhenPurpose
Email addressSign-in or subscriptionAuthentication (magic link), subscription management, transactional emails
Payment dataPremium subscriptionProcessed entirely by Stripe — we never receive or store card details

Data collected automatically

DataPurposeStored whereRetention
IP addressFree-tier rate limiting, abuse preventionOur EU server90 days
Browser user-agentDebuggingOur EU server90 days
Usage events (success / error / paywall hit)Product analytics, billing integrityOur EU server12 months
Anonymised page/event analyticsUnderstanding traffic patternsMatomo, self-hosted on our EU server13 months
Session cookie (a session token)Keeping you logged inYour browser30 days

Data we explicitly do not collect or store

Note on OpenAI: Screenshots are processed by OpenAI's API (USA). OpenAI may use API inputs to improve their models unless you opt out via their platform. We recommend reviewing OpenAI's Privacy Policy. We have selected OpenAI's API tier, which offers stronger data protection than their consumer products.

3. How we use your data

We send only transactional emails (login links, billing confirmations). We do not send marketing or promotional emails.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.

5. Third-party sub-processors

We share personal data with exactly two external sub-processors. All other processing — including analytics, email, and database storage — takes place on our own EU-hosted server.

ProviderPurposeData sharedLocationSafeguard
OpenAI, LLC AI processing of uploaded screenshots Screenshot images only — no account data, no email USA Standard Contractual Clauses (SCCs)
Stripe, Inc. Recurring subscription payment processing Email address, subscription status, payment method (card data handled entirely by Stripe) Ireland / USA Standard Contractual Clauses (SCCs); Stripe Ireland Ltd. is EU-based

We have no relationship with advertising networks, data brokers, social media platforms, or marketing tools. We do not use Google Analytics, Meta Pixel, or any equivalent tracking service.

6. Analytics — Matomo

We use Matomo, an open-source analytics platform, to understand how visitors use RizzlerGPT. Matomo is installed and operated on our own server in Germany. No analytics data is sent to any third party.

Matomo is configured with the following privacy settings:

Your opt-out: You can opt out of Matomo analytics at any time by enabling the "Do Not Track" (DNT) setting in your browser — Matomo respects this signal. Alternatively, contact us at kirpeit@kirpeit-solutions.de to request exclusion.

7. International data transfers

The majority of your data never leaves the European Union — our server, database, analytics, and email are all EU-based.

The following transfers to third countries occur:

California (CCPA/CPRA): California residents have the right to know what personal information we collect, the right to delete, the right to correct, and the right to opt out of sale. We do not sell or share personal data for cross-context behavioural advertising. To submit a CCPA request, email kirpeit@kirpeit-solutions.de.

United Kingdom: Transfers are conducted under the UK GDPR and the International Data Transfer Agreement (IDTA) where applicable.

Other jurisdictions: We make reasonable efforts to comply with applicable local privacy law. If you have a concern specific to your jurisdiction, please contact us.

8. Data retention

Data typeRetention periodReason
Account (email, premium status)Until deletion request + 30 days to fully eraseService provision
Session tokens30 days from last loginAuthentication
Magic link tokens1 hour (auto-expired; deleted on use)Security
IP address & user-agent logs90 daysAbuse prevention
Usage event logs12 monthsProduct analytics
Matomo analytics data13 monthsTraffic analysis
Billing records10 yearsGerman tax law (§ 257 HGB, § 147 AO)
Uploaded screenshotsNot stored — deleted immediately after API responsePrivacy by design

9. Cookies & local storage

Cookies we set

NameTypePurposeDuration
a session tokenEssentialKeeps you logged in after magic-link authentication. HttpOnly, Secure, SameSite=Lax.30 days

Browser local storage

We store one item in your browser's local storage:

Matomo cookies

Matomo may set first-party cookies (a session token, a session token) to distinguish visits. These cookies do not leave our domain, are never shared with third parties, and can be blocked by enabling "Do Not Track" in your browser. No third-party cookies are set by Matomo.

We set no advertising cookies, social media cookies, or any cross-site tracking cookies.

10. Children's privacy

RizzlerGPT is intended for users aged 16 and over (or 13 and over where local law permits a lower age). We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us at kirpeit@kirpeit-solutions.de and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. For material changes — such as adding a new sub-processor or changing the legal basis for any processing — we will notify registered users by email at least 14 days before the changes take effect. Continued use of RizzlerGPT after the effective date constitutes acceptance of the updated policy.

12. Contact & complaints

Kirpeit Solutions

Email: kirpeit@kirpeit-solutions.de

Response time: within 5 business days

Right to lodge a complaint

If you are in the EEA and believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection authority. As we are based in Germany, the lead supervisory authority is:

Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI)

www.bfdi.bund.de

UK residents may contact the Information Commissioner's Office (ICO). You may also contact the supervisory authority in your own EU member state.