Controller
The controller within the meaning of the General Data Protection Regulation is:
Schmitzundkunzt e.V.
(Postal address)
Wittekindstr. 35
50937 Cologne
Germany
For privacy-related enquiries, please preferably use our contact form.
Open contact formData processed at a glance
Depending on how you use JustSawIt, the following categories of data may be processed:
Data is not collected merely for stockpiling. Each processing activity is connected with a platform function or security purpose.
Registration and user account
When you create an account, we process the information needed to provide and secure it, including your alias, e-mail address, cryptographic password hash, language settings, verification and account status.
Passwords are not stored in plain text. The alias is the identity normally displayed within the platform; the e-mail address is not publicly displayed through the account.
E-mail addresses are used in particular for account management, verification, security-related messages, password recovery and, where enabled, notifications about relevant finds.
Find reports, images and public content
When a find is reported, the submitted information is stored and displayed according to the platform’s visibility rules. This may include the title, categories, images, submission time, location information and, where used, AI-generated search and comparison data.
Please do not upload images or titles containing unnecessary personal data, recognisable persons, private documents, licence plates or other sensitive information.
Uploaded images may be processed automatically for technical and security purposes, for example by resizing, optimisation or removal of technical metadata, insofar as this is necessary for secure and efficient platform operation.
Public preview links may allow people without an account to view limited information about a find. Protected details remain subject to the platform’s access rules.
Location data and map display
Location data is processed to place a reported find on the map and make it discoverable. This concerns the location of the find, not continuous tracking of the person using the platform.
Location information may be displayed with different precision depending on login status and function. Public previews are designed to withhold exact protected details.
Users who are not logged in or whose accounts have not yet been confirmed and activated are shown only an approximate find location for privacy and security reasons. Exact addresses and coordinates are available only to registered, confirmed and activated members.
When external map tiles or geocoding services are used, technical connection data such as the IP address may be transmitted to the relevant provider.
Moderation, reports and trust system
Find reports and user activity may be reviewed to maintain quality and prevent misuse. Authorised moderators and administrators may review finds, process reports and document relevant actions.
Trust levels and trust-related events may support moderation. They do not constitute decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR.
Moderation decisions and security-relevant moderation events may be logged in order to document decisions, detect misuse and protect the integrity of the platform.
E-mail notifications and daily digests
Registered users may configure notifications for categories or areas. We process the selected settings, matching finds, queue status and delivery logs.
Notifications may be bundled into a daily digest. A secure preview token may display the finds included in a digest for a limited period.
Notifications are sent automatically through an internal notification system and may be delivered with a technical delay. Before sending, the system checks whether the account is active and whether the relevant notification setting is still enabled.
Temporarily failed delivery attempts may be retried automatically. Delivery logs are used for error analysis, prevention of duplicate delivery and reliable operation.
Notification settings can be changed or disabled in the user area. Essential account and security messages may still be sent.
Contact form and support tickets
When you use the contact form, the selected topic, name or account alias, e-mail address, subject, message, ticket number, time, technical security data and subsequent communication are stored in the support system.
For authenticated users, alias and e-mail address are taken from the account. Authorised staff can assign tickets, add internal notes, change status and reply by e-mail.
Spam protection uses a calculation task, honeypot, minimum submission time and rate limiting. For rate limiting, an IP-derived hash is stored instead of the plain IP address.
Technical connection and security data
When the website is accessed, the web server and security systems may process technical data such as IP address, time, requested address, referring page, browser, operating system, device information, response status and transferred data volume.
Technical security measures such as session management, form protection through CSRF tokens, rate limiting, abuse detection and security-related system logs are also used to protect the platform.
This data is used to deliver the service, detect errors, protect sessions, investigate attacks and ensure stable operation. Administrative and moderation actions may also be recorded in audit logs.
Operational monitoring may process aggregated counts, queue and cron statuses, database and file-storage sizes, backup statuses and technical version information. Automated backups may contain account, find, moderation and other platform data for recovery purposes. Access to monitoring and backup functions is restricted to authorised administrators.
Cookies, sessions and progressive web app
JustSawIt uses technically necessary session mechanisms to maintain login status, protect forms and prevent unauthorised requests. CSRF tokens protect form submissions.
As a progressive web app, program files, icons and other resources may be stored in the browser cache or service-worker storage. You can remove them through browser or device settings.
No consent-requiring advertising or tracking cookies are currently intended. If introduced in the future, the required information and consent options will be provided first.
AI-assisted image recognition with Cloudflare Workers AI
When creating a find report, you can voluntarily use AI-assisted image recognition.
After you explicitly click “Analyse photo”, the selected image is transmitted once through our server to the external AI service Cloudflare Workers AI in order to recognise visible contents and generate appropriate metadata, comparison data and search terms.
This feature is used only at the user’s request.
The contents recognised by the AI are displayed for transparency. If the user submits the find, they are stored as additional search and comparison data for that find.
AI assistance is provided solely as a tool and does not replace your own review of the find report.
The service is provided by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
Data processed and purpose
- the selected image and the image file type;
- technical request data required to transmit and process the request;
- the language selected for the response;
- operational metadata such as time, model, processing duration, response status, usage values and, where available, a provider request identifier.
The purpose is to recognise visible objects in a find photo and generate additional search and comparison data. The AI analysis alone does not save the find; storage takes place only when the user submits the complete find report. No decision with legal or similarly significant effects is made solely by the AI.
Voluntary use and storage
The feature is optional and the find report can be completed without it. The temporary analysis upload is not stored by EbenGesehen as an additional AI copy. If you later submit the report, the selected find photo is stored as part of the report under the rules described in the section “Find reports, images and public content”. Operational AI logs do not contain the image itself, but may contain the metadata listed above.
Cloudflare states that customer content submitted to Workers AI is not made available to other Cloudflare customers and is not used to train AI models or improve Cloudflare or third-party services without explicit consent. Cloudflare’s processing and any technically necessary retention are governed by the applicable Cloudflare contractual and data-protection terms.
Legal basis, processor and international transfers
The legal basis is Article 6(1)(b) GDPR because the processing is carried out at your explicit request to provide the optional analysis function. Cloudflare acts as a processor where it processes personal data on our behalf. The contractual basis includes Cloudflare’s Data Processing Addendum under Article 28 GDPR.
Because Cloudflare is a globally operating US provider, processing may also involve locations outside the European Economic Area. Where required, transfers are safeguarded by the mechanisms provided in Cloudflare’s Data Processing Addendum, including the EU Standard Contractual Clauses and other applicable transfer safeguards.
Please do not use the analysis for images showing recognisable children or young people, private documents, licence plates, access data, health information or other sensitive information. Avoid recognisable third parties unless you have a lawful basis for the image.
Further information about the processing of personal data is available in Cloudflare’s privacy information.
Recipients and service providers
Personal data is accessible only to authorised persons who need it for operation, support, moderation, security or administration.
Technical service providers may process data on our behalf, particularly for hosting, server operation, backup, e-mail delivery and the optional AI image analysis described above. Where required, processors are contractually bound under Article 28 GDPR.
Disclosure to authorities or other third parties takes place only where a legal basis exists.
Transfers outside the European Economic Area are not intended unless required by a specifically used service. Where relevant, the legally required safeguards will be applied.
Storage periods
Data is stored only as long as necessary for the stated purpose or statutory retention requirements.
- Account data: generally until account deletion, subject to required residual storage.
- Find data: until expiry, archiving or deletion, with limited records retained where necessary for moderation.
- Notification queues and delivery logs: for operational monitoring and duplicate prevention.
- Support tickets: during processing and for an appropriate documentation period thereafter.
- Security and server logs: for the period required to detect errors and misuse.
- AI usage logs: only as long as necessary for quota monitoring, error analysis, security and operational documentation; the analysed image itself is not contained in these logs.
Where longer storage is required by statutory obligations, legitimate interests or the documentation of security-relevant events, the data is restricted for other purposes or processed only to the extent necessary for that purpose.
Your data protection rights
Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent.
You also have the right to lodge a complaint with a supervisory authority. For the operator’s registered office, the competent authority is the State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia.
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Postfach 20 04 44
40102 Düsseldorf, Germany
Changes to this privacy policy
We may update this privacy policy when functions, legal requirements or technical processes change. The version published on this page is the current version.