Legal · Privacy
Privacy policy.
This notice explains what Deniable processes, why it is needed, how long it is kept, and which service providers help operate the product.
1. Controller and contact
Krippl David
c/o flexdienst – #20185
Kurt-Schumacher-Straße 76
67663 Kaiserslautern, Germany
Contact: "support@deniable.net" · +49 (0) 156 79773216.
2. What we process
Depending on your use of Deniable, this may include your account email, verification and password-reset events, hashed API keys, API requests and credit usage, dataset orders, payment references, support messages, data-export requests, consent preferences, and limited security logs. Deniable is designed to provide synthetic documents; do not upload real customer records or special-category data.
3. Purposes and legal bases
We apply the following legal bases under Art. 6 GDPR:
- Account, authentication, API access and delivery: performance of a contract, Art. 6(1)(b).
- Payments, invoices, tax and accounting records: contract performance and compliance with legal obligations, Art. 6(1)(b) and (c).
- Security, abuse prevention, rate limits and service reliability: legitimate interests in protecting the service and its users, Art. 6(1)(f).
- Contact and pre-contract questions: steps at the requester’s request before a contract, Art. 6(1)(b), or legitimate interest in responding, Art. 6(1)(f).
- Google Analytics and any optional analytics: consent, Art. 6(1)(a). Consent can be withdrawn at any time in Cookie settings.
- Newsletter or marketing: only if introduced and separately consented to, Art. 6(1)(a). No newsletter is active by default.
We do not intentionally request or use special-category data under Art. 9 GDPR. If a support message contains such data accidentally, we use it only to handle the request, restrict access, and delete it when no longer needed; no Art. 9 processing purpose is planned for the product.
4. Retention periods
These are the operational targets, subject to legal holds and mandatory retention:
- Account and authentication data: while the account is active; after deletion, normally removed within 30 days unless a legal or security reason requires longer.
- Verification and password-reset tokens: usable only for their short expiry window, then removed or invalidated; cleanup target 30 days.
- API keys and usage records: while the account and audit history are needed; target 24 months after last activity, except records needed for disputes or billing.
- Invoices, payment references and accounting records: generally 10 years where German commercial and tax retention duties apply. Stripe may retain its own records under its legal obligations.
- Support tickets and contact messages: target 12 months after resolution, longer only for an active dispute or legal obligation.
- Security and rate-limit logs: target 90 days, shortened or extended when needed to investigate abuse or an incident.
- Consent records: while needed to demonstrate the choice and for a proportionate period afterwards.
5. Providers and their roles
Deniable uses processors and payment/analytics providers under applicable agreements:
- Netlify: hosting, deployment, CDN and server execution for the website and routes.
- Neon: PostgreSQL database and managed authentication; stores account, catalogue, API, billing-ledger and session data.
- Cloudflare R2: private object storage for dataset archives and related files; access is controlled by signed server-side requests.
- Resend: transactional email such as verification, password-reset, support confirmations, paid-invoice PDFs and account notices.
- Stripe: checkout, payment processing, tax calculation and refunds. Stripe processes payment details in its own payment environment; Deniable stores references and business records needed for fulfilment and accounting, not full card numbers.
- sevdesk: accounting and paid-invoice creation. Invoice data is sent to sevdesk after a successful payment and the resulting invoice PDF is delivered through Resend.
- Google Analytics: optional analytics only after consent, with IP anonymisation enabled.
6. International transfers
Some providers or their sub-processors may process data in the European Economic Area, the United Kingdom, the United States, or other countries. Where an adequacy decision does not apply, transfers use an approved safeguard such as Standard Contractual Clauses, or a specific Art. 49 GDPR derogation only where its strict conditions are met. Provider locations and safeguards should be recorded in the final processing register.
7. Cookies and consent
Essential browser storage supports authentication, security, and remembering this preference. Optional analytics is blocked until you choose “Accept analytics”. “Reject optional” is available without opening another screen, and consent can be withdrawn in Cookie settings. See the Cookie Policy for the category and provider details.
8. Automated decisions and profiling
Deniable does not use personal-data profiling or automated decisions with legal or similarly significant effects. Automated checks such as authentication, rate limits, credit-balance checks, disposable-email screening, and abuse safeguards are service-security controls, not eligibility or credit scoring decisions. A temporary block can be reviewed through support.
9. Security measures
Controls include TLS for data in transit, provider encryption at rest where available, hashed API keys, short-lived sessions and reset tokens, least-privilege server access, signed storage URLs, rate limits, immutable billing records, audit trails, backups and restore testing. No internet service can guarantee absolute security; suspected incidents are investigated and handled under applicable breach obligations.
10. Your rights and response times
You may request access, rectification, erasure, restriction, portability, objection, or withdrawal of consent where applicable under Arts. 7, 15–21 GDPR. We normally respond without undue delay and within one month of a verifiable request; complex requests may be extended by up to two further months with notice. Start with the data export request or contact "support@deniable.net". We may verify identity before disclosing or deleting data.
You also have the right to complain to a supervisory authority. For an operator established in Kaiserslautern, this is generally the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz; you may also contact the authority in your habitual residence.
11. Children and age limit
Deniable is a professional developer and business service and is not directed to persons under 18. We do not knowingly create accounts for children. If you believe a minor has provided data, contact us so it can be reviewed and removed where legally appropriate.
12. Changes
We may update this notice when the product, providers, or legal requirements change. Material changes will be highlighted on the website or communicated where required.
Last updated: 5 September 2026