Legal
Privacy Policy
Last updated: 7 October 2026.
This policy explains how KontextNews handles personal data. It applies to kontextnews.online, the dashboard and the API.
Controller
Alexandru Mihail Cîrstea, trading as Codex Neuralis, Darmstadt, Germany. Contact: privacy@codexneuralis.com.
What we collect
- Account data: your email address. Authentication is handled by Supabase; we never see your password.
- API keys: stored only as a SHA-256 hash. The raw key is shown to you once.
- Usage data: API calls per key (endpoint, units, timestamp) for metering and quotas.
- Technical data: IP address, user agent and request path, for security and abuse prevention (rate limiting, bans, access logs).
- Cookies and local storage: see the Cookie Policy.
Why we process it (legal bases)
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the service | account, keys, usage | Contract (Art. 6(1)(b)) |
| Security and abuse prevention | IP, user agent, access logs | Legitimate interest (Art. 6(1)(f)) |
| Billing and tax | payment and invoice data | Contract, legal obligation |
| Analytics cookies | usage, if enabled | Consent (Art. 6(1)(a)) |
Sub-processors
| Provider | Role | Location |
|---|---|---|
| Hostinger | Website hosting | EU (Frankfurt) |
| OVH | API and database hosting | EU |
| Supabase | Authentication | EU / US (SCCs) |
| Stripe | Payments | EU / US (SCCs) |
We do not sell personal data. Each provider acts under a data processing agreement.
Retention
- Account data: while the account is active, then deleted on request.
- Usage data: rolling window for quotas and reporting.
- Access logs and IP bans: up to 30 days.
- Invoices: as required by tax law (Germany: up to 10 years).
Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent at any time. To exercise any right, email privacy@codexneuralis.com. You may also lodge a complaint with your supervisory authority (in Germany, the Hessian Commissioner for Data Protection and Freedom of Information).
International transfers
Hosting is in the EU. Where a provider transfers data outside the EEA, the transfer relies on the EU Standard Contractual Clauses.
Security
TLS in transit, secrets encrypted at rest, least-privilege database roles, per-key rate limiting and automatic banning of abusive traffic.
Changes
We may update this policy. Material changes are reflected by the date at the top of this page.
See also: Terms of Service · Cookie Policy · Data Processing Agreement.