1. Controller

Jeremy Becker
Lohmannstraße 75
06366 Köthen (Anhalt)
Germany

Email: developer@haaremy.de

A data protection officer has not been appointed, as the requirements under Art. 37 GDPR in conjunction with § 38 BDSG are not met.

2. Scope

This privacy policy applies to all web applications, services, and offerings operated under the domain haaremy.de and its subdomains (hereinafter collectively “Services”). These include, but are not limited to:

Where individual services involve additional or different data processing, this will be noted separately within those services.

3. Categories of Data Processed and Purposes

3.1 Access Data (Server Logs)

Each time our services are accessed, the following data is automatically collected:

Data CategoryPurposeLegal Basis
IP addressConnection establishment, security, abuse preventionArt. 6(1)(f) GDPR
Time of accessLogging, error analysisArt. 6(1)(f) GDPR
Requested resource (URL)Service deliveryArt. 6(1)(f) GDPR
HTTP status codeError analysisArt. 6(1)(f) GDPR
Browser/device information (User-Agent)Compatibility, securityArt. 6(1)(f) GDPR
Referrer URLError analysisArt. 6(1)(f) GDPR

This data is not merged with other data sources. Server logs are automatically deleted after a maximum of 14 days.

3.2 Account Data (Authentication / SSO)

For services requiring registration, we operate a central Single Sign-On (SSO) system. The following data is processed:

Data CategoryPurposeLegal Basis
Email addressAccount creation, communication, password recoveryArt. 6(1)(b) GDPR
UsernameIdentification within servicesArt. 6(1)(b) GDPR
Password (Argon2 hash)AuthenticationArt. 6(1)(b) GDPR
Display name (optional)Display nameArt. 6(1)(a) GDPR
Date of birth (optional)Age verificationArt. 6(1)(a) GDPR
Phone number (optional)Contact search, account verificationArt. 6(1)(a) GDPR
Profile picture (optional)PersonalizationArt. 6(1)(a) GDPR
MFA key (stored encrypted)Two-factor authenticationArt. 6(1)(f) GDPR
Session data, login timestamps, IP addressesSecurity, session managementArt. 6(1)(f) GDPR

The SSO sets an authentication cookie on the domain .haaremy.de, readable by all subdomains. This cookie contains exclusively an encrypted session identifier (JWT) and no personal data in plain text.

3.3 Communication Services

Our communication services (chat, messaging, notifications) process:

Data CategoryPurposeLegal Basis
Message contentCommunication between usersArt. 6(1)(b) GDPR
Metadata (timestamps, delivery status)Message delivery, read receiptsArt. 6(1)(b) GDPR
Typing indicatorsReal-time feedbackArt. 6(1)(f) GDPR
Media attachments (files, images, audio)Data exchangeArt. 6(1)(b) GDPR
Block listsUser protectionArt. 6(1)(f) GDPR

End-to-End Encryption: Direct messages in our chat services are transmitted and stored with end-to-end encryption (E2EE). The operator has no access to the plaintext of these messages. Encryption keys remain exclusively with the participating users.

3.4 Cloud Storage and Collaboration

Our cloud and collaboration services (file storage, document editing, LaTeX editor, wiki) process:

Data CategoryPurposeLegal Basis
Uploaded files and documentsStorage, editing, sharingArt. 6(1)(b) GDPR
Metadata (filename, size, type, timestamp)File managementArt. 6(1)(b) GDPR
Share links and permissionsCollaborationArt. 6(1)(b) GDPR
Version historyDocument managementArt. 6(1)(b) GDPR

3.5 Password Manager

Our password management service stores user credentials exclusively with client-side encryption. The operator has no access to stored passwords, notes, or other vault contents. Only the following is processed:

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.6 Streaming and Media

When accessing streaming content, the following is processed:

Legal basis: Art. 6(1)(b) GDPR. This service is not publicly accessible and is exclusively for authorized users.

3.7 Gaming and Event Platforms

When using our gaming and event services (web games, Minecraft server), the following is processed:

Data CategoryPurposeLegal Basis
Player name / usernameIn-game identificationArt. 6(1)(b) GDPR
IP addressConnection, anti-cheatArt. 6(1)(f) GDPR
Play time and connection dataServer operation, moderationArt. 6(1)(f) GDPR
Game results, scores, leaderboardsCompetition evaluationArt. 6(1)(b) GDPR
Team data (name, members)Team featuresArt. 6(1)(b) GDPR
Minecraft UUID and skin dataPlayer-related displayArt. 6(1)(b) GDPR
In-game chat messagesIn-game communicationArt. 6(1)(b) GDPR
Location data (only with explicit consent)Map-based game featuresArt. 6(1)(a) GDPR

Minecraft servers communicate with Mojang/Microsoft authentication servers to verify player accounts. The player UUID is transmitted to Mojang. The Mojang/Microsoft Privacy Policy applies.

3.8 Utility and Tool Services

Our utility services (URL shortener, pastebin, SVG converter, meta search engine, deployment API, etc.) process:

Input data is only processed for the purpose specified by the user and not used for other purposes. Public content (e.g. public paste entries, short links) is accessible to anyone who knows the link.

3.9 Search (Meta Search Engine)

Our meta search engine forwards search queries to external search engines. The following applies:

3.10 Support and Tickets

When contacting us via our support system, the following is processed:

Legal basis: Art. 6(1)(b) GDPR. Support data is deleted after the matter is resolved and any statutory retention periods have expired.

4. Cookies and Local Storage

We use exclusively technically necessary cookies. No tracking cookies, analytics tools, or advertising cookies are used.

4.1 Cookie Overview

Cookie / StoragePurposeRetention
sso_session / auth_token (.haaremy.de)Cross-domain authentication via SSO (encrypted session ID)30 days (“Stay logged in”) or session end
session_idSession management for individual servicesSession end or max. 30 days
csrf_tokenProtection against cross-site request forgerySession end
cookie_consent (Local Storage)Storage of cookie consent1 year
eula_accepted (Local Storage)Storage of EULA acceptance1 year
Theme/language settings (Local Storage)User interfaceUntil manually deleted

All listed cookies are technically necessary and do not require separate consent pursuant to § 25 para. 2 TDDDG. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and functional provision of our services).

5. Recipients and Third-Party Services

Personal data is generally not shared with third parties, except as described below.

5.1 Cloudflare (DNS and DDoS Protection)

For some of our subdomains, we use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a DNS provider and reverse proxy. For subdomains routed through the Cloudflare proxy, traffic passes through Cloudflare servers before reaching our own servers. Cloudflare processes in particular the user's IP address.

Cloudflare is certified under the EU-US Data Privacy Framework and additionally uses Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Legal basis: Art. 6(1)(f) GDPR. Further information: Cloudflare Privacy Policy.

5.2 Mailbox.org (Email Delivery)

For sending system and notification emails (e.g. password resets, account notifications), we use the service mailbox.org (Heinlein Hosting GmbH, Schwedter Str. 9/9a, 10119 Berlin) as a data processor pursuant to Art. 28 GDPR. A data processing agreement (DPA) is in place. Data processing occurs exclusively in Germany.

5.3 Mojang/Microsoft (Minecraft)

When connecting to our Minecraft servers, the player UUID is transmitted to Mojang/Microsoft authentication servers for verification. This is technically mandatory for operating a Minecraft server. The Mojang/Microsoft Privacy Policy applies.

5.4 PayPal (Donations)

Some pages contain a PayPal donation link. Clicking it redirects you to PayPal (Europe) S.à r.l. et Cie, S.C.A. The PayPal Privacy Policy applies to data entered there.

6. Retention Periods

We store personal data only as long as necessary for the respective purpose or as required by law:

Data CategoryRetention Period
Account dataUntil deletion of the account by the user
Messages and chat historyUntil deleted by the user or account deletion
Cloud files and documentsUntil deleted by the user or account deletion
Game results and event dataFor the duration of the respective event or game season
Minecraft player dataFor the duration of active server use; inactive data after 12 months
Session dataUntil session expiry (max. 30 days)
Server logsMaximum 14 days
Support requests6 months after resolution
Paste/short link contentPer the expiry time chosen by the user or until manual deletion

7. Hosting and Server Location

All services are operated on own, physical infrastructure in Germany (self-hosted). No cloud hosting with third-party providers (e.g. AWS, Google Cloud, Azure) is used.

Your data does not leave our own server infrastructure at any time – except in the cases described in Section 5 (Cloudflare, mailbox.org, Mojang, PayPal).

7.1 Open-Source Software Used

Many of our services are based on open-source software, including Nextcloud, Vaultwarden, Overleaf, OnlyOffice, and SearXNG. The sole responsible party for operation and data processing is the controller named above – not the respective open-source projects.

8. Data Security

We implement comprehensive technical and organizational measures to protect your data:

9. Your Rights

Under the GDPR, you have the following rights:

To exercise your rights, contact: developer@haaremy.de

The competent supervisory authority is the State Commissioner for Data Protection Saxony-Anhalt, Leiterstraße 9, 39104 Magdeburg (datenschutz.sachsen-anhalt.de).

10. Changes to This Policy

We reserve the right to update this privacy policy as necessary, in particular when expanding our services or when the legal situation changes. The current version is always available at legal.haaremy.de/en/privacy/. For material changes, registered users will be notified by email or in-app notification.