Ceyu

Privacy policy

Last updated: 28 July 2026

This policy covers two different things, and it is worth keeping them apart while reading: this website, which collects almost nothing, and the Ceyu application, which necessarily processes more.

1. Controller

Larisa Schlosser, 16 Erlenhain, 88480 Achstetten, Germany.
Data protection contact: privacy@ceyu.org.

We have not appointed a data protection officer; the statutory thresholds under § 38 BDSG are not met. Enquiries go to the address above and are handled by the controller.

2. This website

The website sets no cookies unless you accept analytics, and it loads no external fonts, no advertising network and no embedded media. The typefaces are served from this domain. The single third-party measurement tool, Google Analytics, is described in 2.3 and is not requested at all before consent.

2.1 Server logs

The site is delivered by Cloudflare. Delivering a page requires processing your IP address, and Cloudflare records request metadata (time, requested URL, referrer, user agent, response status) for operation and abuse defence.

Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in delivering the site securely and reliably.

2.2 Local storage

Two values are stored in your browser: your language preference, and your answer to the analytics banner. They stay on your device, are never transmitted, and are technically necessary for the function you asked for (§ 25 (2) TDDDG) — storing a refusal is what keeps the banner from asking again. Details in the cookie notice.

2.3 Analytics

Cloudflare Web Analytics runs without cookies, cross-site identifiers or personal profiles. Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in knowing whether the site is read at all.

Google Analytics 4 (measurement ID G-1Q419N2J2M, provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) is loaded only after you accept it on the banner. It then sets first-party cookies (_ga, _ga_<container>, up to two years) and processes pages opened, approximate location from a shortened IP address, device and browser type, and the referring site or campaign. Google Consent Mode v2 is set to deny advertising storage, advertising user data and ad personalisation permanently, so the data is not used for advertising. Transfers to Google LLC in the United States rely on its certification under the EU–US Data Privacy Framework and on standard contractual clauses.

Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG — consent, which you can withdraw at any time with effect for the future by clearing this site's data in your browser; the banner then returns with nothing loaded.

2.4 Contacting us

When you use the protected online support form, we process your email address, selected topic, subject, message, submission time and the technical abuse-check result in order to answer and secure your request. Cloudflare Turnstile performs the bot check; the submitted challenge token is verified server-side and is not retained with the ticket. The request is encrypted in transit, in the queue and at rest. If the protected channel is unavailable, the form instead hands the prepared message to your own email program and the data reaches us only if you send that email.

We process support requests under Art. 6 (1) (b) or (f) GDPR and retain them only as long as needed for the enquiry, security review and applicable statutory retention periods. Support staff do not receive access to unrelated workspace content through this form.

3. The Ceyu application

3.1 What is processed

  • Account data: name, email address, user ID, organisation ID, membership, role and authentication metadata.
  • Workspace content: boards, tasks, projects, comments, assets, templates, imports and exports — that is, what you create.
  • Collaboration metadata: room identifiers, revision identifiers, presence state, sync checkpoints and conflict/replay metadata.
  • Billing data: billing contact, subscription and invoice references. Card details are handled by the payment provider and never reach us.
  • Security and audit records: events relevant to access control and incident review.

3.2 End-to-end encryption, and its boundary

With cloud sync enabled, workspace content is encrypted on your device before upload with a key that is never transmitted to us. We store ciphertext we cannot read.

This does not extend to account data, billing data or the collaboration metadata that sync requires in order to function. Those are processed in the ordinary way. Any product claiming that everything about it is end-to-end encrypted is overstating it.

Local-first storage means workspace content need never leave your device at all. Organisation administrators can enforce a workspace-wide local-only policy.

3.3 Purposes and legal bases

PurposeLegal basis
Providing the service under the contractArt. 6 (1) (b) GDPR
Billing and invoicingArt. 6 (1) (b) and (c) GDPR
Security, abuse prevention, service integrityArt. 6 (1) (f) GDPR
Statutory retention (commercial and tax law)Art. 6 (1) (c) GDPR
Optional AI featuresArt. 6 (1) (a) GDPR — your consent, given by enabling and using them

3.4 AI features

AI-assisted features are opt-in and can be disabled for an entire workspace by an administrator. When you use one, the context you selected for that request is sent to the model provider named in the subprocessor list below, together with usage metadata.

Your workspace content is not used to train models. With AI features switched off, nothing is sent.

4. Subprocessors

We use the following processors under Art. 28 GDPR. This list is kept current; the authoritative version is the one on this page.

ProviderRoleData
CloudflareHosting, edge delivery, object and key-value storage, WAF, queues, operational loggingAccount and session metadata, sync metadata, assets, audit and security logs, request metadata
WorkOSAuthentication, SSO, directory sync, rolesAccount identifiers, email address, organisation membership, roles, authentication metadata
Creem (Armitage Labs OÜ, Estonia)Merchant of record: checkout, subscriptions, invoices, taxBilling contact data, checkout and subscription identifiers, invoice references
OpenRouterModel routing for AI features, when enabledThe prompt context you selected, plus usage metadata
Google Ireland LimitedGoogle Analytics 4 on the website, only with consentPages opened, shortened IP address, device and browser type, referring site or campaign

4.1 Transfers outside the EU

Some of these providers process data outside the European Economic Area, including in the United States. Transfers are covered by EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

Relational tenant metadata is stored in Cloudflare D1 with server-side tenant authorization; storage jurisdiction follows the configured Cloudflare deployment. If your organisation requires that content never leaves your own machines, use the workspace-wide local-only storage policy.

5. Retention

DataKept for
Account profileWhile the account is active; deleted or anonymised within 30 days of a verified deletion request
Workspace contentWhile the workspace is active; soft-deleted first, then purged after the retention window
Presence and realtime metadataAt most 30 days
Security and audit logs90 to 365 days, depending on risk and legal requirements
BackupsRolling window, approximately 30 days, encrypted at rest
Transient tokens and noncesPurged after their defined lifetime
Invoices and accounting recordsStatutory periods under German commercial and tax law (up to 10 years)

6. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15)
  • have inaccurate data corrected (Art. 16)
  • have data erased (Art. 17)
  • restrict processing (Art. 18)
  • receive your data in a machine-readable format (Art. 20)
  • object to processing based on legitimate interests (Art. 21)
  • withdraw consent at any time, with effect for the future (Art. 7 (3))

Use the data request page or write to privacy@ceyu.org. We verify identity before disclosing or deleting anything — otherwise a request form would be a way to attack someone else's account.

6.1 Right to complain

You may lodge a complaint with a supervisory authority. The competent authority for our seat is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

7. Additional rights for residents of US states

Several US states grant their residents rights that go beyond, or are worded differently from, the GDPR. Those rights are described here. If you live in the EU or the UK, section 6 already covers you and this section changes nothing.

7.1 Notice at collection

We collect the categories of personal information listed in section 3.1 — identifiers (name, email address, account and organisation IDs), commercial information (subscription and invoice references), internet activity (request metadata and security logs) and the content you create in your workspace. We collect it for the purposes in section 3.3 and keep it for the periods in section 5. We collect it from you directly and from the processors in section 4.

We do not collect sensitive personal information as defined by the CCPA for the purpose of inferring characteristics about you.

7.2 We do not sell or share your personal information

Ceyu does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have never done so. Because there is nothing to opt out of, there is no “Do Not Sell or Share My Personal Information” mechanism on this site — its absence is the point rather than an omission.

The same applies under the Virginia CDPA, the Colorado Privacy Act, the Connecticut CTDPA and the Utah UCPA: we do not sell personal data, do not process it for targeted advertising, and do not carry out profiling that produces legal or similarly significant effects.

7.3 Your rights

Depending on your state of residence you may have the right to:

  • Know and access — the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of recipients
  • Delete — the personal information we hold about you, subject to the statutory exceptions in section 5
  • Correct — inaccurate personal information
  • Portability — a copy in a portable, machine-readable format
  • Opt out — of sale, sharing for cross-context behavioural advertising, and targeted advertising. As stated above, we do none of these
  • Limit use of sensitive personal information — we do not use it in a way that triggers this right
  • Non-discrimination — we will not deny service, charge a different price or provide a lower quality of service because you exercised a right
  • Appeal — if we decline a request, residents of Virginia, Colorado and Connecticut may appeal. Reply to our decision and we will review it and respond in writing within the statutory period

7.4 How to exercise them

The same route as everyone else: the data request page or privacy@ceyu.org. We verify identity before acting, and we respond within 45 days, extendable once by a further 45 days where the request is complex — we will tell you if that happens.

An authorised agent may submit a request on your behalf with written permission signed by you; we may still contact you directly to confirm it. Requests are free.

7.5 California “Shine the Light”

California Civil Code § 1798.83 lets California residents ask once a year for a list of the personal information disclosed to third parties for their direct marketing purposes. We disclose nothing for that purpose, so such a request will return an empty list.

8. Security

Transport is encrypted with TLS. Access is tenant-scoped and follows least privilege. Backups are encrypted at rest. Security-relevant events are recorded in an append-only audit trail. Vulnerability reports are welcome at security@ceyu.org.

9. Children

Ceyu is a tool for professional work and is not directed at children. You must be at least 18 to hold an account — see section 3 of the terms of service.

We do not knowingly collect personal data from children. Under Art. 8 GDPR, consent-based processing for a child under 16 would require parental authorisation; we avoid the question by not accepting minors in the first place. The same applies to COPPA in the United States, which covers children under 13. If you believe a child has created an account, write to privacy@ceyu.org and we will delete it.

10. Changes to this policy

We update this policy when the processing changes. The date at the top always reflects the current version. Material changes affecting existing users are announced in the application before they take effect.