— Privacy invariants
The privacy contract — same on SaaS and self-hosted.
- No cookies. No
localStorage. NosessionStorage. - No fingerprinting. No third-party tag managers.
- EU/EEA-only data processing on Netcup VPS in Nuremberg.
- Daily rotating salts. Same visitor, different hash each day.
- Art. 28(3) DPA on every plan, signed 2026-04-24.
- Sub-processor list updated within 7 days of any upstream change.
- Self-hosted by construction — your data never leaves your box.
- DNT and GPC respected on by default.