Privacy policy
This is a convenience translation. The German version is the legally binding one.
Last updated: July 22, 2026
1. Data controller
Fynn-Luca Chilcott, , , Germany
Email:
2. The essentials at a glance
- The Personarium desktop app runs entirely locally on your device. Your chats, characters, images, and API keys never reach our servers.
- Our server stores only what is needed for your account, membership, and the public Hub: your email address, your membership status, and content you deliberately publish.
- The website does not use any analytics or tracking services, does not load fonts or scripts from third-party servers, and uses only strictly necessary cookies. A cookie banner is therefore not required (§ 25 Abs. 2 TDDDG, German Telecommunications-Digital-Services-Data-Protection Act).
3. Hosting and server logs
The website and the Hub run on a server we operate at Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) in a German data center. We have a data processing agreement with Hetzner (Art. 28 GDPR). When you access the website, we process your IP address to the extent technically necessary to deliver the pages and to defend against abuse (rate limits). Rate-limit counters are held exclusively in volatile memory and expire automatically after a short time (seconds up to a maximum of 24 hours). Legal basis: Art. 6 Abs. 1 lit. f GDPR (secure, functional operation).
4. Cookies
We use only strictly necessary first-party cookies: a session cookie that keeps you signed in after login, and — only during a passkey sign-in or registration — a short-lived security cookie for the WebAuthn ceremony. Neither is used for tracking, advertising, or analytics; the session cookie becomes invalid when you sign out or when the session expires. Legal basis: § 25 Abs. 2 Nr. 2 TDDDG, Art. 6 Abs. 1 lit. b GDPR.
5. Waitlist
If you sign up for the waitlist, we store your email address and your chosen language. Signup uses a double opt-in process: your entry only becomes active once you click the confirmation link; the time of confirmation is logged as evidence. We automatically delete unconfirmed entries after 7 days. You can remove yourself from the list at any time — with an informal email to ; your entry will then be deleted. Legal basis: Art. 6 Abs. 1 lit. a GDPR (consent, revocable at any time).
6. Account and sign-in
A Hub account only requires your email address. Sign-in is passwordless, using either a passkey (WebAuthn) or an email sign-in link. For passkeys, we store only the public key and an identifier — biometric data never leaves your device. When you register, you confirm that you are at least 18 years old; we log this self-declaration for evidentiary purposes. Sign-in sessions are time-limited and stored server-side so that we can revoke sessions centrally (e.g., in case of abuse); alongside a session we store the IP address and browser identifier transmitted at sign-in. Expired sessions, including these details, are deleted automatically. Legal basis: Art. 6 Abs. 1 lit. b GDPR (contract or pre-contractual measures).
7. Consent and evidence log
We log, with a timestamp, legally significant declarations (acceptance of the Terms of Service, acknowledgment of the right of withdrawal, age self-declaration, waitlist confirmation, deletion request for your account). These logs serve solely as statutory evidence and are detached from your account when it is deleted; we retain them for as long as the evidence may be legally required (typically until the statutory limitation periods expire). Legal basis: Art. 6 Abs. 1 lit. c and f GDPR.
8. Membership and payment (Stripe)
The paid membership is processed through our payment provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland; the transfer of data to Stripe, Inc. in the USA is safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses). When you sign up, we pass your email address and an account identifier to Stripe. You enter payment data (card or account data, billing address) directly with Stripe — we never see it. We store only your membership status, identifiers from Stripe, and the term of the paid period. Stripe is subject to its own statutory retention obligations (e.g., tax law), which may require longer retention at the payment provider. Details: Stripe Privacy Policy. Legal basis: Art. 6 Abs. 1 lit. b and c GDPR.
9. Cancellation and withdrawal
The cancellation and withdrawal forms can be used without signing in and process the email address you provide solely to match your request to your contract, carry it out, and send you the legally required confirmation. Legal basis: Art. 6 Abs. 1 lit. b and c GDPR.
10. Published character cards
Cards you deliberately publish on the Hub are public — they can be read without signing in and may be indexed by search engines. What is visible is the card content and, at your choice, either your freely chosen display name or “Anonymous” (the internal link to your account remains in place for moderation and statutory obligations; your email address is never displayed). Published cards remain online even after a membership ends. When you delete your account, you choose whether your cards are removed or remain online — without your display name, shown as “Anonymous”; you can withdraw individual cards at any time. Please do not publish third parties’ personal data in card content. Legal basis: Art. 6 Abs. 1 lit. b GDPR.
11. Moderation of published content
Every card is reviewed before publication — by us personally and/or automatically. During automated text review, the card text (never your name or email address) is sent to two AI services: OpenAI (moderation check) and OpenRouter (rule check), both headquartered in the USA; the transfer is safeguarded by EU standard contractual clauses and/or the EU-US Data Privacy Framework. Images are checked exclusively locally on our server and never leave it. We store review reports for up to 90 days, unless a publication or an open review depends on them. For any rejection or removal, we provide you with a statement of reasons in text form (Art. 17 DSA). Legal basis: Art. 6 Abs. 1 lit. c GDPR (protection of minors, DSA obligations) and lit. f GDPR (safe SFW operation). Details on the safeguards for the third-country transfer: OpenAI privacy policy and OpenRouter privacy policy.
Automated decisions (Art. 22 GDPR): In the case of clear violations of the child-protection rules (in particular a character age declared as under 18), the rejection of a publication and the suspension of the account may happen automatically, without prior human review. The basis is an automated comparison of the submitted content with our publication rules; the consequence is non-publication or an account suspension. You have the right to request a review by a human, to state your position, and to contest the decision — informally via .
12. Reports of unlawful content
You can report content via the report form — anonymously if you wish. We process the report category, your explanation, and, if you provide it, your email address for follow-up questions and to notify you of the outcome. Legal basis: Art. 6 Abs. 1 lit. c GDPR (Art. 16 DSA).
13. Bug reports
When you report a bug from the app, we process the title, description, the system data shown to you (app version, operating system, architecture, language, database schema version), any images you optionally attach, and an optional error log (max. 50 entries, automatically stripped of key-like patterns before sending) — solely to fix the bug. Attached images are scanned automatically and locally before any human review. We delete completed reports (fixed, rejected, or duplicate) 365 days after closure, including images; regardless of that, images placed in quarantine are already deleted after 90 days. We do not pass bug reports on to third parties. Legal basis: Art. 6 Abs. 1 lit. b and f GDPR.
14. Security and abuse data
To protect the Hub (in particular the protection of minors), we log violations of the publication rules and any resulting measures (e.g., rejections, suspensions) against the relevant account. Only the operator has access; we keep an internal, ongoing log of our moderation decisions for evidentiary and accountability purposes (Art. 5 Abs. 2 GDPR). Legal basis: Art. 6 Abs. 1 lit. c and f GDPR.
15. Email delivery
We send transactional emails (confirmation links, sign-in links, contract confirmations, cancellation and withdrawal confirmations, moderation notices, inactivity reminders) through the provider Resend (Plus Five Five, Inc., USA) acting as our processor. This involves processing your email address and the content of the respective message. The transfer to the USA is safeguarded by the EU-US Data Privacy Framework and EU standard contractual clauses (details: Resend privacy policy). Legal basis: Art. 6 Abs. 1 lit. b and f GDPR.
16. Backups
We create regular backups of the server database on servers in Germany. Deleted data may persist in backups until the respective backup is deleted or overwritten; backups are used exclusively for restoration. Legal basis: Art. 6 Abs. 1 lit. f GDPR, Art. 32 GDPR.
17. Retention periods at a glance
- Unconfirmed waitlist entries: 7 days.
- Moderation review reports: 90 days (unless tied to a publication or an open review).
- Bug reports: 365 days after closure; quarantined images 90 days after upload.
- Account: deleted immediately on request; automatically after 365 days without sign-in and without payment in case of inactivity (with a reminder 30 days beforehand).
- Published cards: until withdrawn, or as you choose when deleting your account (see Section 10).
- Sign-in sessions: until sign-out or expiry; expired sessions are deleted automatically.
- Evidence logs (Section 7): until the evidentiary purpose no longer applies.
18. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20). You can revoke consent you have given at any time, with effect for the future. To do so, contact us informally at . You can also delete your account yourself at any time in your account settings. You have the right to lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence or with the authority responsible for us, the Independent Centre for Data Protection Schleswig-Holstein (ULD).
Right to object (Art. 21 GDPR): Where we process personal data based on legitimate interests (Art. 6 Abs. 1 lit. f GDPR), you have the right to object to that processing at any time on grounds relating to your particular situation. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
19. The desktop app (Bring Your Own Key)
The desktop app stores all content (characters, chats, images, audio) exclusively on your device; API keys live in your operating system’s keychain. The app contains no telemetry and no automatic crash reporting. AI features use the providers you choose yourself (e.g., OpenRouter, fal.ai) with your own keys: your inputs go directly from your device to the respective provider — based on your own contract with that provider and without any involvement of our servers. Our servers are contacted by the app only for sign-in and license checks, update checks (which technically transmit your IP address and app version), fetching central configuration files (model presets at app start, the prompt library when the character editor opens — without sign-in and without any account reference; only the IP address is transmitted, as with any web request), Hub features you trigger, and bug reports you send. Legal basis for these server contacts: Art. 6 Abs. 1 lit. b GDPR (performance of the contract, including the update obligation under § 327f BGB) and Art. 6 Abs. 1 lit. f GDPR (secure, up-to-date operation).
20. Changes
We update this policy whenever our features or legal bases change; the version published here at any given time applies.