Privacy policy
Short version: this website sets no cookies, loads nothing from foreign servers, uses no analytics or tracking tools and embeds no third-party services. Fonts are served from the same server as the page. What remains is exactly what is technically unavoidable when a website is requested — plus whatever you choose to write to us.
Draft. This text is a prepared template, not legal advice. Before going live it must be reviewed by a lawyer and completed with the actual details of the controller, the host and any processors.
Last updated: August 2026
1. Controller
The controller for data processing on this website within the meaning of Art. 4(7) GDPR is the entity named in the legal notice.
- Placeholder Name / company — see legal notice, to be filled in there
- Placeholder Postal address — see legal notice, to be filled in there
- Placeholder Email address for data protection requests — to be filled in
- Placeholder Data protection officer, if required under Art. 37 GDPR — usually not required for a one-person project, please verify
2. What this website does not do
- No cookies. The site stores nothing on your device — no cookies, no local storage, nothing comparable. That is why there is no consent banner.
- No tracking, no analytics. No analytics, statistics, heatmap or advertising tools are embedded. We do not count visitors.
- No third-party content. No content delivery networks, no embedded videos, no maps, no social media buttons, no external scripts. Opening this page triggers no connection to any third-party server.
- No external fonts. The Inter typeface is served locally from our own server. No connection is made to Google Fonts or any other font service, and no IP address is transmitted to third parties in the process.
- No profiling and no automated decision-making within the meaning of Art. 22 GDPR.
3. Server log files at the host
When this website is requested, the hosting provider processes access data for technical reasons. This data is generated on every website request and cannot be avoided technically.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure, stable and attack-resistant operation of the website. This data is not combined with other sources and is not evaluated for marketing purposes.
- IP address of the requesting device
- Date and time of the request
- Name and path of the requested file
- Amount of data transferred and confirmation of successful retrieval
- Browser and operating system identifier transmitted (user agent)
- Placeholder Name and address of the hosting provider — to be filled in
- Placeholder Log retention period as stated by the host (typically 7 to 30 days) — to be filled in
- Placeholder Data processing agreement under Art. 28 GDPR with the host — to be concluded and confirmed here
- Placeholder Place of processing (EU/EEA, or third country plus the transfer basis under Chapter V GDPR) — to be filled in
4. Contacting us by email
If you write to us by email, we process your details solely to handle your request and any follow-up questions. The legal basis is Art. 6(1)(f) GDPR (answering the request), or Art. 6(1)(b) GDPR for contract-related enquiries.
We delete this data once it is no longer needed for that purpose and no statutory retention obligation applies. This website deliberately has no contact form.
5. The browser extension
The wallet extension is separate software and not part of this website. For completeness: it contains no analytics, telemetry or crash-reporting function. Key material is stored encrypted on the user’s device only and is never transmitted to us. We operate no server that receives user data from the extension.
Important, and stated plainly: when the extension fetches balances or transactions, it talks to the configured Stellar endpoints (Horizon or Soroban RPC). As with any network connection, your IP address becomes visible to the operator of that endpoint, together with which account is being queried. Those operators are independent controllers with their own privacy policies. In developer mode you can choose the endpoint freely and therefore decide for yourself who sees this.
Transactions on the Stellar network are public and permanently visible in an open ledger. That is a property of the technology and outside our control. A request for erasure under Art. 17 GDPR cannot technically be enforced against a public, decentralised ledger — please take that into account.
6. Recipients of data
Your data is not passed on to third parties, with the exception of the hosting provider that operates the website on our behalf as a processor under Art. 28 GDPR. No data is sold and none is shared for advertising purposes.
7. Your rights
You have the following rights regarding your personal data. Exercising them is free of charge; please contact the address given in the legal notice.
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Complaint to a supervisory authority (Art. 77 GDPR) — the competent authority is the data protection authority of the controller’s federal state
- Placeholder Competent supervisory authority including address — to be filled in based on the controller’s location
8. Transport security
The website is served exclusively over an encrypted connection (HTTPS/TLS). We additionally set restrictive security headers, including a Content Security Policy that blocks loading content from foreign sources.
9. Changes to this policy
We update this policy when the website or the legal situation changes. The version published here applies. As there are no user accounts, we cannot notify you actively — checking the date above is enough.
This detail must be completed before publication.