Privacy Notice
Version 1.2 · Effective date: 16 September 2026
1. Controller and contact
The controller responsible for the Paintdeck service under the General Data Protection Regulation is:
Kurt Gierke
Hämmerlingstr. 136
12555 Berlin
Germany
Email: mail@paintdeck.net
2. Scope of this notice
This notice covers the Paintdeck marketing website, the browser and native applications, and the Paintdeck API. It explains what personal data is processed, why it is processed, who receives it, when it is public, how long it is retained, and how you can exercise your rights.
The marketing website uses cookieless analytics as described in section 3 and does not display a cookie-consent banner. It does not use advertising, newsletter forms, third-party embeds or non-essential cookies. Technical language, color-mode and analytics objection preferences may be stored on your device to remember your selections.
3. Service data and analytics
Requests, security and diagnostics
Paintdeck and its delivery providers process connection and request data, including IP address, time, URL, HTTP method/status, browser information and referrer where supplied, to deliver content, secure the service and prevent abuse. The legal bases are Article 6(1)(b) GDPR for requested features and Article 6(1)(f) GDPR for operating, securing and troubleshooting the service.
We send operational logs and minimized error and database-performance diagnostics from staging and production to Grafana Cloud. These include route templates, response times/statuses, release information, sanitized error locations and SQL structure, and aggregated execution/error counts. Diagnostic events exclude user content, account/device identifiers, IP addresses, credentials and query values. IP addresses are used transiently to rate-limit error reports. Operational failure logs may also include request identifiers, hosts, concrete URL paths without query values and error details that incidentally contain personal data; sensitive structured request fields are redacted or omitted.
Diagnostics help us resolve failures and improve reliability under Article 6(1)(f) GDPR; they are stored in Grafana Cloud rather than the application database. Logs and diagnostics follow the retention configured for the relevant infrastructure or Grafana Cloud plan and are not used for advertising profiles.
Website-only cookieless analytics
Self-hosted Umami measures production marketing-website pageviews, estimated visits, campaigns, store clicks, feature exploration, support email clicks and legal downloads. Our current iOS, Android and browser app and API collect no usage analytics. Our legal basis is Article 6(1)(f) GDPR: understanding website use and improving the website and promotional activities.
Events contain known public page paths, timestamps, fixed event names, all supplied utm_* campaign parameters and their values, and the referring URL provided by the browser. Referring URLs may be empty or limited by browser settings and can include paths and query parameters. Other query parameters and fragments from the visited page, page titles, account identifiers and user content are not added to events. Campaign values and referring URLs are transmitted as supplied and may contain personal information; do not include personal information in campaign links. Website pages displayed in frames or explicitly marked as embedded are excluded from analytics.
Umami receives the IP address and browser user agent with website requests. These can be used to derive pseudonymous visit/session identifiers, device information and approximate country, region or city. Cookieless does not mean location-free. Our deployment rotates the identifier salt daily; counts are estimates, not identified people. We do not supply visitor identities or link visits to Paintdeck accounts.
We use no tracking cookies, device-stored visitor identifiers, session recordings or advertising profiles. Umami is self-hosted on our Hetzner server in Germany. Encrypted recovery backups are stored at Scaleway in France. Umami supplies the software and does not host this installation.
Disable website analytics in Analytics settings. This browser's choice persists until storage is cleared. Do Not Track, Global Privacy Control and unavailable preference storage also disable collection. Current apps need no analytics setting. Older versions may display the retained account preference; their old ingestion is disabled during cutover.
Opt-out does not erase history. Earlier analytics records, new Umami records and encrypted backups remain until separately deleted, without automatic expiry. Backups can include identifier-generation secrets; rotation does not erase history. Authorized operators review retention and delete unneeded data. Contact section 1 for rights requests. Without account links, we may be unable to locate visits by email address.
4. Accounts and authentication
Email accounts, legal acceptance, and one-time codes
To create or use an account, Paintdeck processes your email address, a generated or selected username, optional full name, email-verification state and time, role, permissions, publishing-restriction state, accepted Terms version and time, internal account identifier, and creation and update timestamps. Providing an email address and accepting the applicable Terms are required to create an account; providing a full name is optional. The legal basis is Article 6(1)(b) GDPR.
For passwordless email authentication and identity verification for electronic contract withdrawal, Paintdeck processes the email address, code purpose, a hashed one-time code, request identifier, attempt count, issue time, expiry time, and consumption time. The code expires after 10 minutes and expired records are removed by periodic cleanup. Scaleway Transactional Email receives the recipient address and email content to deliver the message.
Passkeys
If you use a passkey, Paintdeck processes the credential identifier, public-key material, signature counter, supported transports, optional device label, last-use time, and creation and update timestamps. Paintdeck does not receive your biometric data or device unlock secret. Passkey challenges expire after five minutes and are removed by periodic cleanup. Your device and operating-system provider may separately process data needed to create, store, synchronize, and use a passkey under its own terms.
Sessions and token storage
Access tokens identify an authenticated account and expire after 15 minutes. Refresh tokens expire after 30 days, are rotated during use, and are stored by the API only as cryptographic hashes together with their family, status, expiry, usage timestamps, and optional device label. Expired server records are removed periodically. On the web, the current refresh token is stored in local storage; in the iOS application it is stored using secure device storage. Logging out removes the device-side token and revokes the applicable server-side token family.
5. Account features and user content
The data in this section is processed under Article 6(1)(b) GDPR to provide the features you choose to use. Where stated below, Article 6(1)(f) GDPR also applies to Paintdeck's legitimate interests in supporting users and maintaining a safe, reliable community.
Paint inventory and wishlist
Paintdeck stores the paint variants associated with your account, owned quantities, wishlist selections, and related timestamps so that it can provide your private paint collection.
Recipes
Recipes can contain a title, notes, ordered steps and instructions, catalogue or custom paint references and snapshots, images and crop focal points, visibility, source-attribution details for an in-app copy, revision information, and timestamps. Your recipes start private. If you copy another painter's public recipe, the copy is a new private recipe in your account and keeps the source title and username for attribution.
Projects, groups, and progress entries
Projects can contain a title, notes, status, linked recipes, ordered images and crop focal points, visibility, revision information, and timestamps. You can organize projects in groups containing a name, description, cover image, and crop focal point. Progress entries can contain a note, photo, crop focal point, revision information, and timestamps. Projects and groups are private unless the public-visibility rules in section 6 apply. Progress entries on a public project form part of that public project.
Uploaded images
Paintdeck accepts JPEG, PNG, and WebP images for profile avatars, recipes, projects, project groups, and project progress. It reads the source format and dimensions to validate and orient the image, then re-encodes it as WebP in bounded sizes. This re-encoding removes embedded source metadata such as EXIF location and camera details. Paintdeck stores the processed image renditions and technical records including the account, purpose, object key, media type, size, checksum, storage and moderation state, and timestamps. Images follow the visibility of the profile or content to which they are attached.
Public profiles, Discover, saves, and likes
Your username and painter profile exist so other people can identify public content. The optional display name, bio, and avatar are processed when you add them. Discover uses a limited projection of eligible public recipes, projects, and progress entries to display a public feed.
If you save a public recipe or project, Paintdeck stores your account, the saved item, and the time. Saves and save counts are private and are not shown to the content owner or the public. If you like an eligible public recipe, project, or progress entry, Paintdeck stores your account, the liked item, and the time. The item’s aggregate like count is public, including to people without an account; the identities of painters who liked it are not public. Paintdeck shows only you whether your own account has liked an item. Saves and likes are also processed under Article 6(1)(f) GDPR for the legitimate interest of presenting useful community features and aggregate engagement.
Feedback
If you submit feedback, Paintdeck processes your account identifier and username, the feedback title, description, category, status, administrative replies, and creation and update timestamps. Submission is optional. Processing is based on Article 6(1)(b) GDPR to provide the requested feedback feature and Article 6(1)(f) GDPR for the legitimate interest of understanding reports, supporting users, and improving Paintdeck.
6. Public visibility and access without an account
Your username and painter profile are public by default. The public profile exposes the username and, if supplied and approved, display name, bio, and avatar; it never exposes your email address, full name, internal account identifier, permissions, saves, blocks, or individual like history.
Paint collections, recipes, projects, and project groups start private. A recipe or project becomes public only when you use its publish action and it passes the applicable safety checks. A group’s name, description, and approved cover can appear on your public profile when it contains a public project. Approved progress entries and images attached to a public project are public with that project. Private linked recipes, internal group ordering, and private content are not included in public responses.
Public profiles and published recipes and projects have stable URLs under app.paintdeck.net/painters/, app.paintdeck.net/recipes/, and app.paintdeck.net/projects/. They and their public images, attribution, author details, progress entries, and aggregate like counts can be accessed without a Paintdeck account. Production public routes may be indexed by search engines and linked to, cached, copied, or captured by other people and services outside Paintdeck's control.
You can remove optional profile details, delete content, or unpublish a recipe or project. Unpublishing stops Paintdeck from presenting the source content publicly but does not delete it from your private workspace and cannot recall external screenshots, copies, or search caches. A recipe copied earlier through Paintdeck remains in the recipient's account with source attribution. Likes remain recorded while content is merely unpublished and reappear in its aggregate count if it is republished; deleting the content deletes its like and save records.
7. Reports, blocks, screening, and moderation
Signed-in painters can report public profiles, recipes, projects, and progress entries. A report records the reporter and target accounts, target type and identifier, reason, status, relevant content snapshot and files at report time, revision, review details, and timestamps. The snapshot prevents later edits from changing what an administrator reviews. Report information is available only to authorized administrators and service providers needed to operate the report workflow. The reported painter does not receive the reporter's identity. A privacy-minimized email notification contains the report identifier, target type, time, and administration link, but not the report reason, reporter, owner, or reported content.
Blocking records the two account identifiers and time so that Paintdeck can hide the blocked painter's content from the blocker and provide the block list. A block and the identity of the blocker are not disclosed to the blocked painter or the public.
When public-facing profile content is added or changed, or a recipe, project, progress entry, or image is published or republished, Paintdeck may process the relevant public-facing text and image through automated screening. Text workflow records can contain the screened content snapshot, revision, content hash, status, retry information, decision reference, and timestamps. Image records contain the checksum and moderation state. Reusable decision records contain content hashes, provider and model identifiers, category results and scores, decision, policy version, and timestamps. Pending or reported content and relevant images can be reviewed by authorized administrators. Administrators can record case states, notes, actions, reviewer information, and publishing restrictions.
This processing is based on Article 6(1)(b) GDPR to provide publishing, reporting, and blocking features; Article 6(1)(f) GDPR for the legitimate interests of preventing abuse, enforcing the Community Guidelines, protecting painters and the service, and documenting consistent decisions; and Article 6(1)(c) GDPR where processing is necessary to meet a legal obligation concerning unlawful content or authorities.
8. Camera permission and barcode scanning
On supported iOS devices, you can grant camera permission to scan a paint barcode. Apple’s VisionKit processes camera frames on the device. Paintdeck does not upload or store camera images. The application receives the recognized barcode value and format and sends the barcode value to the Paintdeck API to look up a paint or update your collection. Use of the scanner is optional and is based on Article 6(1)(b) GDPR when you request the feature. Camera permission is controlled through the operating system and can be withdrawn in device settings.
9. Recipients and service providers
Personal data is disclosed only where needed to operate Paintdeck, comply with law, or establish, exercise, or defend legal claims.
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, hosts our self-managed Umami analytics service in Germany under its data-processing terms. Scaleway also stores encrypted recovery backups of this service, including analytics records, configuration and database state.
- BunnyWay d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (bunny.net), provides the public website and application delivery, CDN, API compute, database, and image object storage. Paintdeck constrains API compute to Germany. The production database has primary locations in Germany and Sweden and read replicas in Frankfurt, Stockholm, New York, Los Angeles, and Sydney. Production image storage is based in Germany with replicas in Sweden, New York, Los Angeles, and Sydney. CDN delivery can involve the edge location selected for a request. Bunny.net processes stored service data and request or security metadata under its data-processing terms.
- Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France, provides Transactional Email, automated backup and recovery-verification jobs, encrypted database and uploaded-file backup storage, and Secret Manager in the Paris region (
fr-par). Backup jobs transiently process production database exports, stored uploaded images, and file inventories, encrypting backup content before object-storage upload. Recovery checks decrypt copies in isolated temporary storage and remove the temporary data afterwards. File inventories contain storage paths, checksums, and sizes and are also encrypted. Access credentials and backup decryption keys are held in access-restricted Secret Manager storage; decryption keys are made available to recovery-verification jobs. Scaleway processes these data and authentication and service-email recipients, message content, and delivery events under its data-processing terms. Backups and recovery checks support the legitimate interest in service continuity and recovery from data loss under Article 6(1)(f) GDPR. - OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland, provides the Moderation API. Paintdeck sends only relevant public-facing text and resized, metadata-free copies of images submitted for publication. It does not include your email address, authentication data, account identifier, or a permanent private file URL. The Moderation endpoint is not used to train OpenAI models and does not retain application state or abuse-monitoring content under OpenAI's published API data controls.
- Raintank, Inc. d/b/a Grafana Labs, 165 Broadway, 23rd Floor, New York, NY 10006, United States, provides Grafana Cloud in an EU region for staging and production API logs, application/API error events, and database-performance diagnostics described in section 3. It also receives backup and recovery-check status, duration, and limited technical failure codes, without database contents, uploaded files, storage paths, or credentials.
- Apple and operating-system services may process device and account information independently when you obtain the application, manage permissions, use secure device storage, or create and synchronize a passkey. Their processing is governed by the settings and privacy terms of the service you use.
- Public authorities, courts, advisers, or other recipients may receive data where legally required.
10. International transfers
Paintdeck configures its primary API processing in Germany. The production database has primary locations and read replicas in Germany and Sweden, with further read replicas in the United States and Australia. Production image storage is based in Germany with replicas in Sweden, the United States, and Australia. Transactional email, backup processing, recovery verification, encrypted backup storage, and backup key management are in France, and Grafana Cloud is in an EU region. CDN routing and the support, affiliate, or subprocessor operations of BunnyWay, Scaleway, OpenAI, Grafana Labs, or another provider can also involve processing outside the European Economic Area. Where a transfer to a country without an EU adequacy decision occurs, Paintdeck relies on the safeguards made applicable through the relevant provider agreement, such as the European Commission's Standard Contractual Clauses, and supplementary measures where required.
11. Retention, unpublishing, and deletion
- Authentication one-time codes expire after 10 minutes and passkey challenges after five minutes. Access tokens expire after 15 minutes and refresh tokens after 30 days; expired server records are cleaned up. Incomplete, unverified signup records without a credential are removed after the five-minute registration challenge period.
- Account details, credentials, profile data, paint collection data, recipes, projects, groups, progress entries, images, feedback, saves, likes, blocks, and related feature timestamps remain while the account is active or until you delete or remove the relevant item. Removing a save, like, block, optional image, or other supported item deletes its active record. Deleting a source recipe, project, progress entry, or account also deletes associated saves and likes through database relationships, which reduces the public aggregate count.
- Unpublishing a recipe or project changes its visibility but does not delete its private source, images, saves, or likes. Report cases retain their report-time evidence after later edits or unpublishing so that Paintdeck can review and document the report.
- On account deletion, the active account and associated feature records are deleted. Stored image records are marked for deletion and the image objects are removed by cleanup. Moderation evidence or audit records may be retained where and for as long as necessary to handle a report or appeal, enforce safety rules, comply with law, or establish, exercise, or defend legal claims. Records kept for those purposes are restricted from ordinary feature use.
- Paintdeck retains monthly aggregate counts of account deletions without account identifiers. Account-linked active-use days for the current month are removed after the month ends or on account deletion; retained daily statistical snapshots do not contain account identifiers.
- Application/API error events, database-performance diagnostics, and other Grafana logs follow the configured Grafana Cloud plan retention period. Grouping events in a dashboard does not create a separate application-database record or extend log retention. CDN, compute, email-delivery, and security records follow the applicable configured or provider retention; failed-delivery addresses may remain on an email blocklist while needed to prevent repeated failures or abuse.
- Text and image screening decisions and content hashes can be retained for moderation audit and safe reuse; a cached decision is reused for at most 90 days under the current policy. Active text workflow snapshots are replaced when the same target is resubmitted and are removed when that submission is completed or made private. Provider-side Moderation requests have no application-state or abuse-monitoring retention under OpenAI's published endpoint controls.
- Encrypted production database and uploaded-file backups are stored in restricted, versioned Scaleway object storage. Deleting active data or images does not immediately remove earlier backup copies or file inventories. Automatic backup expiration is currently disabled, so backup recovery points, file payloads, and earlier object versions remain until manually removed; a fixed maximum retention period is not currently enforced. Backups are used only for disaster recovery and isolated recovery checks, not as ordinary application data sources.
- Withdrawal and rights-request records, including the verified account email, supplied name, accepted Terms version and time, declaration receipt time, and processing timestamps, may be retained as necessary to demonstrate compliance and handle related legal claims.
You can permanently delete your account and its associated active data from the Account section of your profile. You can also request deletion by emailing mail@paintdeck.net from your account address. We may need to verify your identity before acting on an emailed request.
12. Your rights
Subject to the conditions in applicable law, you may request:
- access to and a copy of your personal data;
- rectification of inaccurate or incomplete data;
- erasure of your data;
- restriction of processing;
- data portability for processing based on contract or consent and carried out automatically;
- objection to processing based on legitimate interests; and
- withdrawal of consent at any time where processing is based on consent.
You can edit or remove supported account, profile, content, save, like, and block data directly in Paintdeck. To exercise any other right, contact mail@paintdeck.net. You also have the right to lodge a complaint with a data-protection supervisory authority. The authority responsible for the controller is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany, datenschutz-berlin.de.
13. Automated decision-making
When you explicitly publish or republish public content, Paintdeck uses automated moderation to decide whether it can be published immediately, must wait for administrator review or retry, or is rejected as an exceptionally clear Community Guidelines violation. Provider failures are held for retry or review, and an existing approved version can remain public while an edit is checked. A screening result does not automatically suspend or ban your account. This content-safety decision does not produce legal or similarly significant effects about you. You can contest a decision using the appeal procedure in the Community Guidelines or by contacting Paintdeck.
14. Changes to this notice
This notice will be reviewed when Paintdeck adds or materially changes features, providers, analytics, advertising, embeds, forms, permissions, public visibility, or retention behavior. The version and effective date at the top identify the current notice.