Information on the processing of personal data pursuant to Art. 13 and 14 of the General Data Protection Regulation (GDPR)
Last updated: April 2026Jeremy Becker
Lohmannstraße 75
06366 Köthen (Anhalt)
Germany
Email: developer@haaremy.de
A data protection officer has not been appointed, as the requirements under Art. 37 GDPR in conjunction with § 38 BDSG are not met.
This privacy policy applies to all web applications, services, and offerings operated under the domain haaremy.de and its subdomains (hereinafter collectively “Services”). These include, but are not limited to:
Where individual services involve additional or different data processing, this will be noted separately within those services.
Each time our services are accessed, the following data is automatically collected:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| IP address | Connection establishment, security, abuse prevention | Art. 6(1)(f) GDPR |
| Time of access | Logging, error analysis | Art. 6(1)(f) GDPR |
| Requested resource (URL) | Service delivery | Art. 6(1)(f) GDPR |
| HTTP status code | Error analysis | Art. 6(1)(f) GDPR |
| Browser/device information (User-Agent) | Compatibility, security | Art. 6(1)(f) GDPR |
| Referrer URL | Error analysis | Art. 6(1)(f) GDPR |
This data is not merged with other data sources. Server logs are automatically deleted after a maximum of 14 days.
For services requiring registration, we operate a central Single Sign-On (SSO) system. The following data is processed:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, communication, password recovery | Art. 6(1)(b) GDPR |
| Username | Identification within services | Art. 6(1)(b) GDPR |
| Password (Argon2 hash) | Authentication | Art. 6(1)(b) GDPR |
| Display name (optional) | Display name | Art. 6(1)(a) GDPR |
| Date of birth (optional) | Age verification | Art. 6(1)(a) GDPR |
| Phone number (optional) | Contact search, account verification | Art. 6(1)(a) GDPR |
| Profile picture (optional) | Personalization | Art. 6(1)(a) GDPR |
| MFA key (stored encrypted) | Two-factor authentication | Art. 6(1)(f) GDPR |
| Session data, login timestamps, IP addresses | Security, session management | Art. 6(1)(f) GDPR |
The SSO sets an authentication cookie on the domain .haaremy.de, readable by all subdomains. This cookie contains exclusively an encrypted session identifier (JWT) and no personal data in plain text.
Our communication services (chat, messaging, notifications) process:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Message content | Communication between users | Art. 6(1)(b) GDPR |
| Metadata (timestamps, delivery status) | Message delivery, read receipts | Art. 6(1)(b) GDPR |
| Typing indicators | Real-time feedback | Art. 6(1)(f) GDPR |
| Media attachments (files, images, audio) | Data exchange | Art. 6(1)(b) GDPR |
| Block lists | User protection | Art. 6(1)(f) GDPR |
End-to-End Encryption: Direct messages in our chat services are transmitted and stored with end-to-end encryption (E2EE). The operator has no access to the plaintext of these messages. Encryption keys remain exclusively with the participating users.
Our cloud and collaboration services (file storage, document editing, LaTeX editor, wiki) process:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Uploaded files and documents | Storage, editing, sharing | Art. 6(1)(b) GDPR |
| Metadata (filename, size, type, timestamp) | File management | Art. 6(1)(b) GDPR |
| Share links and permissions | Collaboration | Art. 6(1)(b) GDPR |
| Version history | Document management | Art. 6(1)(b) GDPR |
Our password management service stores user credentials exclusively with client-side encryption. The operator has no access to stored passwords, notes, or other vault contents. Only the following is processed:
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
When accessing streaming content, the following is processed:
Legal basis: Art. 6(1)(b) GDPR. This service is not publicly accessible and is exclusively for authorized users.
When using our gaming and event services (web games, Minecraft server), the following is processed:
| Data Category | Purpose | Legal Basis |
|---|---|---|
| Player name / username | In-game identification | Art. 6(1)(b) GDPR |
| IP address | Connection, anti-cheat | Art. 6(1)(f) GDPR |
| Play time and connection data | Server operation, moderation | Art. 6(1)(f) GDPR |
| Game results, scores, leaderboards | Competition evaluation | Art. 6(1)(b) GDPR |
| Team data (name, members) | Team features | Art. 6(1)(b) GDPR |
| Minecraft UUID and skin data | Player-related display | Art. 6(1)(b) GDPR |
| In-game chat messages | In-game communication | Art. 6(1)(b) GDPR |
| Location data (only with explicit consent) | Map-based game features | Art. 6(1)(a) GDPR |
Minecraft servers communicate with Mojang/Microsoft authentication servers to verify player accounts. The player UUID is transmitted to Mojang. The Mojang/Microsoft Privacy Policy applies.
Our utility services (URL shortener, pastebin, SVG converter, meta search engine, deployment API, etc.) process:
Input data is only processed for the purpose specified by the user and not used for other purposes. Public content (e.g. public paste entries, short links) is accessible to anyone who knows the link.
Our meta search engine forwards search queries to external search engines. The following applies:
When contacting us via our support system, the following is processed:
Legal basis: Art. 6(1)(b) GDPR. Support data is deleted after the matter is resolved and any statutory retention periods have expired.
We use exclusively technically necessary cookies. No tracking cookies, analytics tools, or advertising cookies are used.
| Cookie / Storage | Purpose | Retention |
|---|---|---|
| sso_session / auth_token (.haaremy.de) | Cross-domain authentication via SSO (encrypted session ID) | 30 days (“Stay logged in”) or session end |
| session_id | Session management for individual services | Session end or max. 30 days |
| csrf_token | Protection against cross-site request forgery | Session end |
| cookie_consent (Local Storage) | Storage of cookie consent | 1 year |
| eula_accepted (Local Storage) | Storage of EULA acceptance | 1 year |
| Theme/language settings (Local Storage) | User interface | Until manually deleted |
All listed cookies are technically necessary and do not require separate consent pursuant to § 25 para. 2 TDDDG. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and functional provision of our services).
Personal data is generally not shared with third parties, except as described below.
For some of our subdomains, we use Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) as a DNS provider and reverse proxy. For subdomains routed through the Cloudflare proxy, traffic passes through Cloudflare servers before reaching our own servers. Cloudflare processes in particular the user's IP address.
Cloudflare is certified under the EU-US Data Privacy Framework and additionally uses Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Legal basis: Art. 6(1)(f) GDPR. Further information: Cloudflare Privacy Policy.
For sending system and notification emails (e.g. password resets, account notifications), we use the service mailbox.org (Heinlein Hosting GmbH, Schwedter Str. 9/9a, 10119 Berlin) as a data processor pursuant to Art. 28 GDPR. A data processing agreement (DPA) is in place. Data processing occurs exclusively in Germany.
When connecting to our Minecraft servers, the player UUID is transmitted to Mojang/Microsoft authentication servers for verification. This is technically mandatory for operating a Minecraft server. The Mojang/Microsoft Privacy Policy applies.
Some pages contain a PayPal donation link. Clicking it redirects you to PayPal (Europe) S.à r.l. et Cie, S.C.A. The PayPal Privacy Policy applies to data entered there.
We store personal data only as long as necessary for the respective purpose or as required by law:
| Data Category | Retention Period |
|---|---|
| Account data | Until deletion of the account by the user |
| Messages and chat history | Until deleted by the user or account deletion |
| Cloud files and documents | Until deleted by the user or account deletion |
| Game results and event data | For the duration of the respective event or game season |
| Minecraft player data | For the duration of active server use; inactive data after 12 months |
| Session data | Until session expiry (max. 30 days) |
| Server logs | Maximum 14 days |
| Support requests | 6 months after resolution |
| Paste/short link content | Per the expiry time chosen by the user or until manual deletion |
All services are operated on own, physical infrastructure in Germany (self-hosted). No cloud hosting with third-party providers (e.g. AWS, Google Cloud, Azure) is used.
Your data does not leave our own server infrastructure at any time – except in the cases described in Section 5 (Cloudflare, mailbox.org, Mojang, PayPal).
Many of our services are based on open-source software, including Nextcloud, Vaultwarden, Overleaf, OnlyOffice, and SearXNG. The sole responsible party for operation and data processing is the controller named above – not the respective open-source projects.
We implement comprehensive technical and organizational measures to protect your data:
Under the GDPR, you have the following rights:
To exercise your rights, contact: developer@haaremy.de
The competent supervisory authority is the State Commissioner for Data Protection Saxony-Anhalt, Leiterstraße 9, 39104 Magdeburg (datenschutz.sachsen-anhalt.de).
We reserve the right to update this privacy policy as necessary, in particular when expanding our services or when the legal situation changes. The current version is always available at legal.haaremy.de/en/privacy/. For material changes, registered users will be notified by email or in-app notification.