Privacy policy

Last updated: 5 October 2026.

This information applies to the public websites at tokenschmiede.de and tokenschmiede.com, including the blog, contact form and fape download request. Separate applications on subdomains and future products provide additional information with the relevant offering. The Personal gogcli privacy policy separately describes the private Google CLI setup.

1. Controller and contact

Sebastian Kouba, TokenSchmiede
Bacherweg 6, 82054 Sauerlach, Germany
Email:

You can also send privacy inquiries using the contact form.

2. Website and hosting

The website runs on a server provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Fonts and website files load from our own server. There are no advertising pixels, audience measurement or embedded analytics services.

To deliver the website, the server processes your IP address and technical request data. The upstream server logs in particular the IP address, time, requested URL and HTTP method, status code and amount of data transferred. This supports delivery, troubleshooting and prevention of abuse. The legal basis is Article 6(1)(f) GDPR, with the legitimate interest of secure and reliable operation.

Access logs rotate daily; at most 14 daily archive files are retained. Operational and error logs for the website and comment services are additionally limited to three files of 10 MB each per service. Information about a specific security incident may be retained separately for as long as its investigation or enforcement of claims requires. Hetzner processes hosting data as a technical service provider. Further information: Hetzner privacy policy.

3. Cookies and browser storage

Normal reading, using the contact form and requesting a download use no cookies, Local Storage or Session Storage. We therefore do not show a general cookie banner. Language selection uses links and does not store a browser preference.

The optional comment feature loads only after you select “Show comments”. No request to the comment service is made beforehand. Your choice is not stored permanently. The next section describes the subsequent processing.

4. Optional comments

We run Remark42 on the same server. Selecting “Show comments” permits loading the comment feature and its browser storage for settings and drafts. You can decline by selecting “Keep hidden”. The legal basis for this optional activation is your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG where browser storage is involved. Cookies necessary for an explicitly chosen login fall under section 25(2), no. 2 TDDDG.

Reading and writing comments involves processing technical request data. When you submit a comment, we store its content, your chosen name, the time and its association with the article. Comments appear publicly. Remark42 also uses technical identifiers and IP-related information to prevent abuse. The legal basis for this security processing is Article 6(1)(f) GDPR. Please do not publish confidential data in comments.

No account is required to comment. If you voluntarily sign in through GitHub, a connection to GitHub is established. GitHub supplies the account information authorized for login, such as user ID and profile name. Profile images may load from GitHub servers. GitHub (GitHub, Inc. or GitHub B.V.) is an external provider that also processes data outside the EU. GitHub states its certification under the EU-US Data Privacy Framework and also lists standard contractual clauses as a transfer basis. Before choosing this option, read the GitHub privacy statement. Anonymous commenting is available as an alternative.

Comments generally remain for as long as the associated article is public. You can request deletion. Deletion removes publicly displayed personal content unless statutory reasons prevent this. Backup copies are overwritten through regular backup rotation and are not used for ongoing operation.

You can withdraw consent for future loading by reloading the page and leaving comments hidden. You can additionally remove existing cookies, settings and drafts through your browser’s website data controls. You can end an existing login through the comment feature. Withdrawal does not retroactively invalidate previously lawful processing.

5. Contact form and email

The contact form requires your email address and message; your name is optional. We cannot handle your inquiry without the required information. Your details are transmitted to our server over an encrypted connection and saved in an inbox with restricted access. Contact inquiries are never displayed publicly. A hidden form field and IP addresses briefly held in memory limit automated abuse. No external CAPTCHA services load.

The legal basis for general inquiries is Article 6(1)(f) GDPR, with the legitimate interest of answering inquiries. Article 6(1)(b) GDPR applies to steps toward a specific contract or its performance. Article 6(1)(c) GDPR applies to legally required retention. A contact inquiry does not require separate consent to the privacy policy.

Form inquiries are automatically deleted from the inbox after 180 days. If information must be kept longer for a contract, statutory evidence or litigation, only the necessary part is retained separately. Backups may contain deleted data until their regular rotation.

When you email us or we reply by email, our Google Workspace email service is used (Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland). It processes email addresses, content and technical metadata. Google may also process data outside the EU. Its contractual data protection terms provide in particular for standard contractual clauses and, where applicable, an adequacy decision for these transfers. Information: Google data processing terms. General email inquiries are deleted after completion unless needed for the purposes described above.

6. fape beta and waitlist

At /fape/ you can register interest in the fape beta even when no places are available. The initially unchecked checkbox records your consent to storage of your email address, optional explanation and consent record, and to emails about confirmation, beta access, beta updates and feedback requests. The legal basis is Article 6(1)(a) GDPR. Consent does not cover advertising for other offerings. An explanation is optional; we read it to adjust the waitlist order if appropriate. There is no automated AI assessment.

On our Hetzner server, we store the email address, optional explanation, time, wording and version of consent, delivery state, confirmation time, and waitlist, priority and beta access status. Random, unguessable links allow confirmation, download and deletion. Only the button on the confirmation page confirms a request. Confirmed applicants receive access automatically when places are available; otherwise they remain on the waitlist and receive an email once access is granted. There are no open pixels, click statistics or cookies. IP addresses briefly held in memory, volume limits and a hidden form field prevent abuse (Article 6(1)(f) GDPR).

Emails are sent automatically from our contact email address through Google Workspace SMTP. Google processes the recipient address, email content and technical metadata. The provider and transfer bases are described under “Contact form and email”. The download itself is hosted on our server. The download link is neither a personal account nor a license management system.

Unconfirmed requests are deleted after 48 hours. Confirmed entries are retained until you withdraw or the fape beta program ends. An expired software build or lack of places does not delete your registration. You can delete your data at any time through the deletion link in an email or on the confirmation page, withdrawing consent for future processing. Alternatively, use our contact form. Earlier requests with consent dated 1 October 2026 retain their original limit of one email and at most 30 days of retention; this is not extended automatically. Sent emails cannot be recalled. Copies in the Google mailbox are retained separately where needed for delivery issues or evidence, then deleted. Backups may contain deleted records until regular rotation.

7. Your rights

Subject to the statutory conditions, you may request access, rectification, erasure, restriction of processing and data portability (Articles 15 to 20 GDPR). You may withdraw consent at any time with effect for the future.

For processing based on legitimate interests, you may object on grounds relating to your particular situation (Article 21 GDPR). You may object to direct marketing at any time without giving reasons. Send inquiries by email: , or use the contact form.

You may complain to a data protection supervisory authority, particularly where you live or where you suspect an infringement. The authority responsible for the operator is the Bavarian State Office for Data Protection Supervision: Promenade 18, 91522 Ansbach, complaint to BayLDA (German).

8. Recipients and automated decisions

The operator and the technical providers described above have access where needed for their tasks. Data is not sold. There is no automated decision-making with legal or similarly significant effects and no profiling for advertising.