Privacy
Datenschutzerklärung
Every detail on this page is filled in and each one is a fact we checked — what the system actually stores and for how long, and what our providers' own published terms say. What has not happened is a lawyer reading it end to end. This notice stays until that does, because a policy that reads as settled while being wrong is worse than one that says where it stands.
Who is responsible
Tetyana Samoylenko, Hamburg, Germany, trading as Shortirex. The full postal address, email address and telephone number are in the Imprint, and that email is the address to write to about anything on this page. As a sole trader we are below the thresholds of Art. 37 GDPR and have not appointed a data protection officer, which is why the contact is the trader herself rather than a separate office.
What we collect, and on what basis
| Data | Why | Legal basis |
|---|---|---|
| Email address and password hash | To give you an account | Art. 6(1)(b) — performance of a contract |
| Session cookie | To keep you signed in | Art. 6(1)(b), strictly necessary |
| Subscription and payment status | To provide the paid service | Art. 6(1)(b); retention under Art. 6(1)(c) for tax law |
| Server logs | Operation and security | Art. 6(1)(f) — legitimate interest; access logs are deleted after 14 days |
What we do not collect
- No access to your YouTube account. The product never asks for a connection or a permission, and cannot post, read your analytics or see anything private.
- No tracking or advertising cookies, and no analytics that profile you.
- The videos we analyse are public videos published by other people. Nothing about your own channel is read.
Who else receives data
Everyone below is named with what they do, where they do it, and the contract that governs it. A processor acts only on our instructions under Art. 28 GDPR. Paddle does not, and is listed apart for that reason.
- Hosting — Hetzner Online GmbH, Gunzenhausen, Germany. Runs the server this site is served from, in a data centre in Germany. Agreement on processing under Art. 28 GDPR; the data does not leave the EU.
- Generating scripts and naming topics — Anthropic PBC, United States. Receives the text of public YouTube videos and the topic you type into the form. It does not receive your email address, your password, your payment details or any identifier of your account. Data processing addendum incorporating Standard Contractual Clauses, controller-to-processor module.
- Public video data — Google (YouTube Data API). We read public information about other people's videos. Nothing about you travels the other way: the queries contain video and channel identifiers, never your account or anything you typed.
- Analytics — self-hosted, on this server. We measure page visits with a self-hosted tool (umami) running on our own machine. It sets no cookie, stores no identifier of you, and anonymises IP addresses before deriving country-level statistics; the data never leaves our server and is not shared with anyone. The measurement requests go to this site's own address — no third party is contacted.
- Embedded players — Google (YouTube). Source videos on the report page can be watched in place. Until you press play, the page shows only our own stored data and no request reaches Google — not even for a thumbnail. Pressing play loads the player from youtube-nocookie.com, YouTube's reduced-cookie domain; from that moment YouTube processes your IP address and device data under Google's own privacy policy. The plain link next to every player opens the video on YouTube instead, if you prefer not to load it here.
Operational alarms about the system — a failing data source, a rejected webhook, a failed backup — reach the operator over Telegram. They describe the fault, never a customer.
Paddle is the seller, not our processor
Paddle.com Market Ltd (United Kingdom) is the merchant of record for every order. It sells to you in its own name, takes the payment, handles the tax and issues the invoice. That makes it an independent controller of your payment data rather than a processor acting for us, and its own privacy policy governs what it does with that data. We never see or store your card details. What reaches us is your email address, which plan you bought, and whether it is paid.
Transfers outside the EU
The site and its data sit in Germany. Two recipients are outside the EU:
- Anthropic — United States. Standard Contractual Clauses under Art. 46(2)(c) GDPR, controller-to-processor module, incorporated by the commercial terms we accepted.
- Paddle — United Kingdom. The European Commission renewed its adequacy decision for the United Kingdom on 19 December 2025, so transfers there need no separate instrument; Paddle additionally relies on Standard Contractual Clauses.
Your rights
Access, rectification, erasure, restriction, portability, and objection, under Art. 15 to 21. Write to the address in the Imprint and we answer within one month. Deleting an account is done by hand rather than with a button, and it happens inside that month.
What erasure does, precisely, because "we delete everything" would be a promise we cannot keep: we remove what identifies you — your name, your email address, your password, the topics you typed in — and we keep the rows that identify nobody, such as how many reports were produced and when. The payment records stay because the law says they must, as the table below sets out. What is left afterwards is a number that means nothing outside this database. It is fair to add that this is not perfect anonymity for as long as Paddle still holds the invoice with your name on it; that link ends when its retention duty does.
You may also complain to a supervisory authority. The competent one for this business is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg. You are free to complain instead to the authority where you live or work.
Retention
| What | How long |
|---|---|
| Account: email, name, password hash | Until you ask us to delete it |
| Reports generated for your account | Until you ask us to delete them, or the account goes |
| Web server access logs | 14 days, then rotated out |
| Application logs | Capped in size and overwritten as they fill; recent operation only, never archived |
| Encrypted backups | 14 days |
| Invoices and payment records | Eight years — § 147(3) AO and § 14b(1) UStG, counted from the end of the year the document arose |
The last row is a statutory duty and overrides a deletion request for those records: we may not delete an invoice on request, and neither may Paddle, which issues it. Everything above it we delete when you ask.