Legal

Privacy Policy

This policy explains what data is processed when you visit this website or use the applications offered through it.

Last updated:

Scope

This Privacy Policy applies to www.sebastiannichtern.com, including the applications at /apps/incomecalc and /apps/tradingbot, and the associated public and restricted hosts bot.sebastiannichtern.com and bot-private.sebastiannichtern.com.

Third-party websites and services linked from the site have their own privacy notices. Data is transferred to them only when you follow an external link, unless this policy expressly describes otherwise.

Controller

q-ops GmbH

Mildestieg 31

22307 Hamburg

Germany

Represented by Managing Director Sebastian Ulrich Nichtern

Email: info@sebastiannichtern.com

Website delivery and hosting

The website and its applications are delivered through Vercel. Each request causes the hosting infrastructure to process technical connection data so that it can deliver the requested page, protect the service, and investigate errors.

Data processed
IP address, date and time, requested URL, HTTP method and status code, referrer, browser and device information, and technical error data.
Purpose
Website delivery, load distribution, prevention of abuse, stability, and error analysis.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service.
Retention
Logs are kept only for as long as they are required for operations, security, and error analysis. The specific period depends on the type of log and the Vercel configuration.
Recipient / provider
Vercel Inc., United States.

Vercel Privacy Notice

Audience measurement with Vercel Web Analytics

We use Vercel Web Analytics to understand the use of individual pages in aggregate. According to Vercel, the service does not use cookies, does not store IP addresses in analytics data points, and does not track visitors across different websites or days. A daily hash generated from the request is discarded after 24 hours.

Data processed
Page path, time, referrer, approximate location, device type, operating system, and browser. We do not record custom events containing contact details.
Purpose
Anonymous audience measurement and improvement of the service.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is a data-minimising assessment of website use.
Retention
The visitor hash is discarded after 24 hours. Reports are provided only in aggregate.
Recipient / provider
Vercel Inc., United States.

Vercel Web Analytics privacy information

Local storage and essential cookies

Some settings are stored only in your browser so that the applications work as selected on your next visit. These include the website appearance, the appearance of the unlisted Bali page, calculator values, and display options for the trading dashboard.

You can delete this data at any time using your browser settings. Without local storage, the relevant convenience settings will be reset.

Data processed
Display preferences, calculator state, and dashboard view options in Local Storage. Required cookies are also used for calculator drafts and authentication to the private dashboard.
Purpose
Remembering selected settings, restoring a calculator draft, and secure session management.
Legal basis
Section 25(2)(2) TDDDG and, where personal data is involved, Article 6(1)(f) GDPR. Storage is required for the requested functions and their secure operation.
Retention
Local Storage data remains on the device until you or the application deletes it. Cookie durations are described in the following sections.
Recipient / provider
Processing on your device and, for session features, the providers named below.

Income calculator and draft synchronisation

Calculations take place directly in your browser. Inputs are stored locally and are also sent automatically to our server as a pseudonymous draft so they can be restored on a later visit. The draft is linked to a random session identifier, not to a name or user account.

Calculator values can allow inferences about personal or financial circumstances. Use sample values when precise personal information is unnecessary, and do not enter names or other directly identifying information.

Data processed
This includes employment type, income or revenue, federal state, age, tax class, church tax option, children, insurance type, and contribution settings. A random session identifier, update time, and technical checksum are also stored.
Purpose
Performing the requested calculation and restoring the last draft.
Legal basis
Article 6(1)(f) GDPR and Section 25(2)(2) TDDDG. Our legitimate interest is a reliable calculator that can restore an interrupted session.
Retention
The server draft and signed, HTTP-only session cookie expire after 30 days. Local values remain until they are deleted in the browser.
Recipient / provider
Upstash Inc., United States, as the Redis database provider.

Upstash Privacy Policy

Trading dashboard and Supabase

The public trading dashboard reads approved, non-personal bot and market data from Supabase. For the private operator area, Supabase also processes login details and manages the authentication session. The private area is restricted to an authorised operator.

Data processed
Technical connection data for public access. Login additionally involves an email address, password transmission to Supabase, session identifiers, signed access tokens, authentication status, and security logs.
Purpose
Providing current dashboard data, authentication, access control, and protection of the private area.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is secure delivery and access control. Authentication cookies are required under Section 25(2)(2) TDDDG.
Retention
Authentication cookies remain valid for the session duration set by Supabase and are deleted or invalidated on sign-out. Account data remains until the operator account is deleted; security logs are retained only for required operational and legal periods.
Recipient / provider
Supabase, Inc., United States. The primary data region depends on the configuration of the Supabase project.

Supabase Privacy Policy

TradingView chart

The public trading dashboard loads an interactive stock chart from TradingView. Your browser therefore connects directly to TradingView. TradingView states that embedded widgets do not set cookies. It processes the IP address briefly to deliver data and protect its servers against DDoS attacks.

Data processed
IP address, URL of the embedding page, widget type, displayed symbol, and standard technical connection data.
Purpose
Displaying the interactive market chart and protecting the widget infrastructure.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is the understandable visualisation of publicly available market data.
Retention
TradingView states that it retains the IP address only briefly to protect its servers. TradingView's own periods apply to any other data.
Recipient / provider
TradingView, Inc., United States.

TradingView Privacy PolicyTradingView widget privacy information

Optional AI project assistant

When you actively use the optional project assistant, we process your message, the bounded conversation history required for the answer, and Sebastian's complete public CV profile. An ordinary page visit does not trigger an AI request. When the separately gated email-draft function is enabled, the assistant can generate an editable subject and body after you explicitly request a draft or clearly accept its immediately preceding offer, then immediately attempt to open a local draft through a mailto: link. This hands the fixed recipient info@sebastiannichtern.com, subject, and body to the email application or webmail protocol handler configured on your device; the selected service's own privacy terms then apply to its processing. The invocation only requests that a draft be opened or populated and does not send an email. This website cannot observe whether a handler opened or a message was sent. You can edit the draft before sending, copy it, or use the direct link to try opening it again.

The request is processed by a Vercel server function configured for Frankfurt and sent exclusively to the fixed https://api.tensorx.ai/v1 endpoint. TensorX Ltd in Ireland acts as processor and provides model inference and model routing. Only z-ai/glm-5.2 as the default, deepseek/deepseek-v4-pro, moonshotai/kimi-k2.6, and deepseek/deepseek-v4-flash-0731 as the low-cost continuation model are enabled. Each selectable model may generate the email draft only after its own technical qualification; there is no hidden second Flash request for drafts. A failure never causes an automatic switch to another model provider or API endpoint.

TensorX states in its Terms and Data Processing Agreement that inference content is processed transiently on infrastructure in Dublin and Helsinki, is not retained, and is not used for model training. Non-retention and non-use for model training are separate service-level commitments by TensorX; the API does not provide request-level evidence of region, retention, deletion, or use. TensorX's Privacy Policy separately describes account-level usage, API, cost, billing, and security metadata; API and security logs may be retained there for up to 12 months.

After a response is displayed, this website stores the completed user message and completed assistant response in Neon Postgres. Neon is part of Databricks. The database project is provisioned in AWS Europe (Frankfurt); this does not mean that every operational or support activity by all providers is confined to Frankfurt. Displayed responses classified as complete, truncated, or incomplete are stored. Storage is used for internal review, debugging, and assistant-quality evaluation, not model training or marketing profiling. It runs later on a best-effort basis: a database failure does not change, delay, or replace the AI response already delivered to you.

Alongside the completed exchange, Neon stores only a pseudonymous HMAC-derived conversation key and message and request IDs, requested, selected, and responding model, selection reason, completion status, token counts when available, the privacy-notice version, and UTC timestamps. Email addresses are not collected as separate fields or metadata; an email address entered in message content remains stored as part of the completed exchange. Neon does not store pending prompts or failed prompts without a displayed response, partial output, repeated conversation context, CV grounding, internal instructions or reasoning, drafts, raw session or conversation IDs, cookies, or source IP addresses.

Neon storage is not used to restore chat history for visitors. There is no public retrieval API, backfill of older browser conversations, shareable chat URL, cross-device history, or owner admin page. Initially, only the owner can inspect records through the Neon SQL Editor.

The linked Databricks list identifies its general subprocessors. The Neon Product Schedule additionally identifies Grafana Labs, Inc. in the United States as a Neon-specific subprocessor.

A draft you edit is sent to TensorX again when you explicitly choose Regenerate or a dedicated revision action, or attach it for one requested revision. Without such an explicit action, the current draft is not attached to a request, including other or unrelated messages. Drafts, including edited versions, are stored neither in Neon nor in application logs.

Vercel processes technical connection and security data, in particular the source IP address for bot and abuse protection and premium-model-attempt limits. The application does not add the source IP address, session identifier, session hash, or email address as fields in the TensorX request; TensorX nevertheless receives the technical connection from the Vercel server function. An essential signed, HTTP-only, Secure, SameSite session cookie contains a random anonymous identifier and premium-attempt timestamps. The cookie is issued without a Max-Age or Expires attribute as a browser-session cookie and is normally discarded by the browser when that session ends. Separately, premium attempts are counted in a rolling 60-minute window; that window is not the cookie's lifetime. Completed messages, at most the pending user prompt while a response is pending, interrupted, or failed, and the last schema-valid edited email draft remain in the current tab's sessionStorage for the browser session. Temporarily blank or otherwise schema-invalid field values remain only in page memory and are lost on reload; the last schema-valid draft is then restored. Partial assistant output is not stored there. This website's tab-scoped storage is separate from any storage by your email application or webmail service.

Conversation and draft content is included neither in analytics nor in technical application logs. There are no analytics events for generating or editing a draft, copying it, or invoking the mailto: link. Content-free application logs about persistence and daily cleanup follow the platform's separate operational retention periods; TensorX metadata logs are also separate from the website's 30-day conversation storage. Use public or non-confidential information only. Do not enter secrets, confidential information, or third-party personal data. AI output can be incomplete or incorrect.

Data processed
For inference: your input, bounded conversation context, Sebastian's complete public CV profile, and the generated answer or email draft. In Neon: only the completed, displayed user/assistant exchange, a pseudonymous HMAC conversation key, and the listed limited generation metadata. This also involves the essential session cookie and separate technical connection, usage, cost, and security metadata.
Purpose
Generating the requested answer or email draft, internal review, debugging, and assistant-quality evaluation, secure operation, and abuse prevention; not model training or marketing profiling.
Legal basis
Article 6(1)(f) GDPR for providing this voluntary information service, limited 30-day storage for internal quality and error review, and secure operation. Our legitimate interest is the reliable, accountable improvement of the assistant, balanced by data minimisation, pseudonymisation, a short deletion period, and the voluntary usage context. Article 6(1)(b) GDPR may additionally apply to generation where a request specifically seeks steps before entering into a contract. The technically necessary session cookie relies on Section 25(2)(2) TDDDG.
Retention
A server-stored conversation is deleted 30 days after its latest stored response; each further successfully stored response restarts that conversation's period. A protected daily cleanup deletes expired conversations. In the current tab's sessionStorage, completed messages, at most the pending user prompt while a response is pending, interrupted, or failed, and the last schema-valid edited draft remain until the browser session ends; partial output is not stored there. Temporarily blank or otherwise schema-invalid draft fields remain only in page memory and are lost on reload. The essential cookie lasts for the browser session and the separate premium-attempt window rolls over 60 minutes. Content-free Vercel application logs follow their own operational periods; TensorX describes up to 12 months for certain separate API and security logs.
Recipient / provider
Vercel Inc., United States, as hosting provider; TensorX Ltd, Ireland, as processor for model inference and routing; and Neon, part of Databricks, as the Neon Postgres storage provider. The database project runs in AWS Europe (Frankfurt); other operational processing follows the providers' and subprocessors' published terms.

TensorX Terms of ServiceTensorX Data Processing AgreementTensorX Privacy PolicyTensorX subprocessorsNeon/Databricks contractual and privacy termsDatabricks general subprocessorsNeon security information

Contact by email

The website does not use a contact form. If you contact us by email, we process the contact details you provide, the content of your message, and technical email metadata.

Data processed
Email address, name and any other details you provide, message content, timestamps, and technical email metadata.
Purpose
Processing and responding to your request and, where applicable, taking steps before entering into or performing a contract.
Legal basis
Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR based on our interest in responding to your message.
Retention
Messages are deleted after the enquiry is complete unless they are required for a business relationship, legal defence, or statutory retention. Depending on their type, business and tax records may be retained for six, eight, or ten years.
Recipient / provider
q-ops GmbH and technical service providers used to operate email.

Recipients and international transfers

We disclose personal data only where this is required for the purposes described above, required by law, or based on your consent. Recipients may include hosting, database, authentication, email, and AI service providers, as well as public authorities and legal advisers.

Some providers are established in the United States or use subprocessors outside the European Economic Area. Project-assistant content is processed for inference through the fixed TensorX interface and subsequently stored in the Neon database project on AWS Europe (Frankfurt). TensorX does not identify per request which subprocessors are involved. The database project's location likewise does not mean that every operational or support activity by Neon, Databricks, or their subprocessors is confined to Frankfurt. Where an international transfer occurs, the applicable safeguard depends on the recipient and may be an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or the European Commission's Standard Contractual Clauses and supplementary safeguards.

General retention period

Where no specific period is stated, we keep personal data only for as long as it is required for the relevant purpose. It is then deleted or anonymised unless statutory retention duties, legitimate security needs, or the establishment, exercise, or defence of legal claims require a longer period.

Your rights

Subject to the statutory requirements, you have the following rights in particular:

  • Access to your personal data under Article 15 GDPR
  • Rectification of inaccurate data under Article 16 GDPR
  • Erasure under Article 17 GDPR
  • Restriction of processing under Article 18 GDPR
  • Data portability under Article 20 GDPR
  • Objection to processing based on legitimate interests under Article 21 GDPR
  • Withdrawal of consent at any time for the future under Article 7(3) GDPR

To exercise your rights, email info@sebastiannichtern.com. We may request reasonable evidence of your identity.

Right to complain

You have the right to lodge a complaint with a data protection supervisory authority. The following authority is responsible for q-ops GmbH in particular:

Hamburg Commissioner for Data Protection and Freedom of Information

Ludwig-Erhard-Straße 22

20459 Hamburg

Changes to this policy

We update this Privacy Policy when features, providers, or legal requirements change. The version published on this page with the date shown above is the applicable version.