KontextNews

Legal

Privacy Policy

Last updated: 7 October 2026.

This policy explains how KontextNews handles personal data. It applies to kontextnews.online, the dashboard and the API.

Controller

Alexandru Mihail Cîrstea, trading as Codex Neuralis, Darmstadt, Germany. Contact: privacy@codexneuralis.com.

What we collect

  • Account data: your email address. Authentication is handled by Supabase; we never see your password.
  • API keys: stored only as a SHA-256 hash. The raw key is shown to you once.
  • Usage data: API calls per key (endpoint, units, timestamp) for metering and quotas.
  • Technical data: IP address, user agent and request path, for security and abuse prevention (rate limiting, bans, access logs).
  • Cookies and local storage: see the Cookie Policy.

Why we process it (legal bases)

PurposeDataLegal basis
Provide the serviceaccount, keys, usageContract (Art. 6(1)(b))
Security and abuse preventionIP, user agent, access logsLegitimate interest (Art. 6(1)(f))
Billing and taxpayment and invoice dataContract, legal obligation
Analytics cookiesusage, if enabledConsent (Art. 6(1)(a))

Sub-processors

ProviderRoleLocation
HostingerWebsite hostingEU (Frankfurt)
OVHAPI and database hostingEU
SupabaseAuthenticationEU / US (SCCs)
StripePaymentsEU / US (SCCs)

We do not sell personal data. Each provider acts under a data processing agreement.

Retention

  • Account data: while the account is active, then deleted on request.
  • Usage data: rolling window for quotas and reporting.
  • Access logs and IP bans: up to 30 days.
  • Invoices: as required by tax law (Germany: up to 10 years).

Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent at any time. To exercise any right, email privacy@codexneuralis.com. You may also lodge a complaint with your supervisory authority (in Germany, the Hessian Commissioner for Data Protection and Freedom of Information).

International transfers

Hosting is in the EU. Where a provider transfers data outside the EEA, the transfer relies on the EU Standard Contractual Clauses.

Security

TLS in transit, secrets encrypted at rest, least-privilege database roles, per-key rate limiting and automatic banning of abusive traffic.

Changes

We may update this policy. Material changes are reflected by the date at the top of this page.

See also: Terms of Service · Cookie Policy · Data Processing Agreement.