Privacy Policy

Last updated: 3 July 2026

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

Marius Erdmann (kontiTec)
Brunnenstraße 1a, 56459 Langenhahn, Germany
E-mail: info@gruenki.de · Phone: +49 152 53622816

A data protection officer is not legally required and has therefore not been appointed. Please direct privacy-related inquiries to the e-mail address listed above.

2. Overview

gruenki is an AI chat service. We only process the data required to operate the service. Your content is processed and stored in Germany; personal content is held field-encrypted (encrypted at rest) in the database. We do not use your content for advertising, do not sell it, and do not train any AI models with it.

3. What data we process

4. Purposes and legal bases

We process this data to provide you with the service (performance of a contract or usage relationship, Art. 6(1)(b) GDPR) and to ensure IT security and stable operation (legitimate interest, Art. 6(1)(f) GDPR). We document your consent to the terms of use and to this privacy policy as evidence (Art. 5(2) GDPR). Where consent is required for individual, optional processing operations, it is based on Art. 6(1)(a) GDPR and can be withdrawn at any time. Providing account data (e-mail) is required for registration and use of the service; you provide chat content and uploads voluntarily.

5. Storage location and security

Your data is processed and stored in Germany. Personal content is stored field-encrypted (encrypted at rest). The data of different users and teams is strictly separated from one another at a technical level (tenant separation). The connection is encrypted (HTTPS).

6. Processors and third-party services

To provide individual functions, we use service providers who act on our behalf:

If you use gruenki as a controller in the context of commissioned processing (e.g. as a club, organisation or business processing personal data of third parties), we will provide you with a data processing agreement (DPA under Art. 28 GDPR) on request. Please send your enquiry to info@gruenki.de.

7. Cookies and local storage

We do not use advertising or tracking cookies. For sign-in, a technically necessary item is stored in your browser's local storage so that you stay signed in (Section 25(2) TDDDG – technically required). Cookies from Google (e.g. the g_state item used by the Google sign-in) are only set after you have actively clicked "Continue with Google" and thereby consented to the Google sign-in (Section 25(1) TDDDG) – not already when the page is opened. If you subscribe to a paid plan, you are redirected to our payment service provider for the payment, who sets the cookies required for the payment on its own page.

8. Logging (security/access log)

To ensure security (Art. 32 GDPR), we log security-relevant events – e.g. sign-ins, account and role changes, password changes, as well as export and deletion requests. This log contains exclusively metadata (time, affected account, type of action) and no content of your messages or files. The legal basis is our legitimate interest in IT security (Art. 6(1)(f) in conjunction with Art. 32 GDPR). These logs are automatically deleted after 90 days.

Error reports from the mobile apps: If a technical error occurs in the iOS/Android app (e.g. a failed function or an aborted purchase), the app transmits a technical error report to our server in Germany. It contains exclusively technical details (error message, affected processing step, device type and OS version) and never the content of your messages. Nothing is transmitted unless an error occurs. We do not use external crash or analytics services (such as US crash reporters). The legal basis is our legitimate interest in stability and troubleshooting (Art. 6(1)(f) GDPR); the reports are deleted with the automatic rotation of the server logs (typically after a few weeks).

9. Retention period and deletion deadlines

We store personal data only for as long as is necessary for the respective purpose (storage limitation, Art. 5(1)(e) GDPR). Specifically:

10. Consent and evidence

Upon registration, we document that and when you agreed to the terms of use and to this privacy policy in their respective valid version (version status and time). If these documents are updated, we will ask you to confirm again at your next login. This serves the purpose of demonstrability (Art. 5(2) GDPR).

11. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. You can withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR). You can trigger a complete export of your data and the deletion of your account at any time directly within the service.

In addition, you have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (LfDI RLP), Hintere Bleiche 34, 55116 Mainz – but you may contact any supervisory authority.

12. Automated decisions and AI notice

No automated decision in an individual case, including profiling, with legal effect or similarly significant impairment (Art. 22 GDPR) takes place. Note: The AI assistant's responses are generated automatically, may be incorrect, and do not constitute binding decisions or professional advice.

← Back to home