Privacy policy
Last updated: 28 July 2026
This policy covers two different things, and it is worth keeping them apart while reading: this website, which collects almost nothing, and the Ceyu application, which necessarily processes more.
1. Controller
Larisa Schlosser, 16 Erlenhain, 88480 Achstetten, Germany.
Data protection contact: privacy@ceyu.org.
We have not appointed a data protection officer; the statutory thresholds under § 38 BDSG are not met. Enquiries go to the address above and are handled by the controller.
2. This website
The website sets no cookies unless you accept analytics, and it loads no external fonts, no advertising network and no embedded media. The typefaces are served from this domain. The single third-party measurement tool, Google Analytics, is described in 2.3 and is not requested at all before consent.
2.1 Server logs
The site is delivered by Cloudflare. Delivering a page requires processing your IP address, and Cloudflare records request metadata (time, requested URL, referrer, user agent, response status) for operation and abuse defence.
Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in delivering the site securely and reliably.
2.2 Local storage
Two values are stored in your browser: your language preference, and your answer to the analytics banner. They stay on your device, are never transmitted, and are technically necessary for the function you asked for (§ 25 (2) TDDDG) — storing a refusal is what keeps the banner from asking again. Details in the cookie notice.
2.3 Analytics
Cloudflare Web Analytics runs without cookies, cross-site identifiers or personal profiles. Legal basis: Art. 6 (1) (f) GDPR — our legitimate interest in knowing whether the site is read at all.
Google Analytics 4 (measurement ID G-1Q419N2J2M,
provider Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland)
is loaded only after you accept it on the banner. It then sets first-party
cookies (_ga, _ga_<container>, up to two years) and
processes pages opened, approximate location from a shortened IP address, device
and browser type, and the referring site or campaign. Google Consent Mode v2 is
set to deny advertising storage, advertising user data and ad personalisation
permanently, so the data is not used for advertising. Transfers to Google LLC in
the United States rely on its certification under the EU–US Data Privacy
Framework and on standard contractual clauses.
Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG — consent, which you can withdraw at any time with effect for the future by clearing this site's data in your browser; the banner then returns with nothing loaded.
2.4 Contacting us
When you use the protected online support form, we process your email address, selected topic, subject, message, submission time and the technical abuse-check result in order to answer and secure your request. Cloudflare Turnstile performs the bot check; the submitted challenge token is verified server-side and is not retained with the ticket. The request is encrypted in transit, in the queue and at rest. If the protected channel is unavailable, the form instead hands the prepared message to your own email program and the data reaches us only if you send that email.
We process support requests under Art. 6 (1) (b) or (f) GDPR and retain them only as long as needed for the enquiry, security review and applicable statutory retention periods. Support staff do not receive access to unrelated workspace content through this form.
3. The Ceyu application
3.1 What is processed
- Account data: name, email address, user ID, organisation ID, membership, role and authentication metadata.
- Workspace content: boards, tasks, projects, comments, assets, templates, imports and exports — that is, what you create.
- Collaboration metadata: room identifiers, revision identifiers, presence state, sync checkpoints and conflict/replay metadata.
- Billing data: billing contact, subscription and invoice references. Card details are handled by the payment provider and never reach us.
- Security and audit records: events relevant to access control and incident review.
3.2 End-to-end encryption, and its boundary
With cloud sync enabled, workspace content is encrypted on your device before upload with a key that is never transmitted to us. We store ciphertext we cannot read.
This does not extend to account data, billing data or the collaboration metadata that sync requires in order to function. Those are processed in the ordinary way. Any product claiming that everything about it is end-to-end encrypted is overstating it.
Local-first storage means workspace content need never leave your device at all. Organisation administrators can enforce a workspace-wide local-only policy.
3.3 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the service under the contract | Art. 6 (1) (b) GDPR |
| Billing and invoicing | Art. 6 (1) (b) and (c) GDPR |
| Security, abuse prevention, service integrity | Art. 6 (1) (f) GDPR |
| Statutory retention (commercial and tax law) | Art. 6 (1) (c) GDPR |
| Optional AI features | Art. 6 (1) (a) GDPR — your consent, given by enabling and using them |
3.4 AI features
AI-assisted features are opt-in and can be disabled for an entire workspace by an administrator. When you use one, the context you selected for that request is sent to the model provider named in the subprocessor list below, together with usage metadata.
Your workspace content is not used to train models. With AI features switched off, nothing is sent.
4. Subprocessors
We use the following processors under Art. 28 GDPR. This list is kept current; the authoritative version is the one on this page.
| Provider | Role | Data |
|---|---|---|
| Cloudflare | Hosting, edge delivery, object and key-value storage, WAF, queues, operational logging | Account and session metadata, sync metadata, assets, audit and security logs, request metadata |
| WorkOS | Authentication, SSO, directory sync, roles | Account identifiers, email address, organisation membership, roles, authentication metadata |
| Creem (Armitage Labs OÜ, Estonia) | Merchant of record: checkout, subscriptions, invoices, tax | Billing contact data, checkout and subscription identifiers, invoice references |
| OpenRouter | Model routing for AI features, when enabled | The prompt context you selected, plus usage metadata |
| Google Ireland Limited | Google Analytics 4 on the website, only with consent | Pages opened, shortened IP address, device and browser type, referring site or campaign |
4.1 Transfers outside the EU
Some of these providers process data outside the European Economic Area, including in the United States. Transfers are covered by EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Relational tenant metadata is stored in Cloudflare D1 with server-side tenant authorization; storage jurisdiction follows the configured Cloudflare deployment. If your organisation requires that content never leaves your own machines, use the workspace-wide local-only storage policy.
5. Retention
| Data | Kept for |
|---|---|
| Account profile | While the account is active; deleted or anonymised within 30 days of a verified deletion request |
| Workspace content | While the workspace is active; soft-deleted first, then purged after the retention window |
| Presence and realtime metadata | At most 30 days |
| Security and audit logs | 90 to 365 days, depending on risk and legal requirements |
| Backups | Rolling window, approximately 30 days, encrypted at rest |
| Transient tokens and nonces | Purged after their defined lifetime |
| Invoices and accounting records | Statutory periods under German commercial and tax law (up to 10 years) |
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased (Art. 17)
- restrict processing (Art. 18)
- receive your data in a machine-readable format (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent at any time, with effect for the future (Art. 7 (3))
Use the data request page or write to privacy@ceyu.org. We verify identity before disclosing or deleting anything — otherwise a request form would be a way to attack someone else's account.
6.1 Right to complain
You may lodge a complaint with a supervisory authority. The competent authority for our seat is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
7. Additional rights for residents of US states
Several US states grant their residents rights that go beyond, or are worded differently from, the GDPR. Those rights are described here. If you live in the EU or the UK, section 6 already covers you and this section changes nothing.
7.1 Notice at collection
We collect the categories of personal information listed in section 3.1 — identifiers (name, email address, account and organisation IDs), commercial information (subscription and invoice references), internet activity (request metadata and security logs) and the content you create in your workspace. We collect it for the purposes in section 3.3 and keep it for the periods in section 5. We collect it from you directly and from the processors in section 4.
We do not collect sensitive personal information as defined by the CCPA for the purpose of inferring characteristics about you.
7.2 We do not sell or share your personal information
Ceyu does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act as amended by the CPRA. We have never done so. Because there is nothing to opt out of, there is no “Do Not Sell or Share My Personal Information” mechanism on this site — its absence is the point rather than an omission.
The same applies under the Virginia CDPA, the Colorado Privacy Act, the Connecticut CTDPA and the Utah UCPA: we do not sell personal data, do not process it for targeted advertising, and do not carry out profiling that produces legal or similarly significant effects.
7.3 Your rights
Depending on your state of residence you may have the right to:
- Know and access — the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of recipients
- Delete — the personal information we hold about you, subject to the statutory exceptions in section 5
- Correct — inaccurate personal information
- Portability — a copy in a portable, machine-readable format
- Opt out — of sale, sharing for cross-context behavioural advertising, and targeted advertising. As stated above, we do none of these
- Limit use of sensitive personal information — we do not use it in a way that triggers this right
- Non-discrimination — we will not deny service, charge a different price or provide a lower quality of service because you exercised a right
- Appeal — if we decline a request, residents of Virginia, Colorado and Connecticut may appeal. Reply to our decision and we will review it and respond in writing within the statutory period
7.4 How to exercise them
The same route as everyone else: the data request page or privacy@ceyu.org. We verify identity before acting, and we respond within 45 days, extendable once by a further 45 days where the request is complex — we will tell you if that happens.
An authorised agent may submit a request on your behalf with written permission signed by you; we may still contact you directly to confirm it. Requests are free.
7.5 California “Shine the Light”
California Civil Code § 1798.83 lets California residents ask once a year for a list of the personal information disclosed to third parties for their direct marketing purposes. We disclose nothing for that purpose, so such a request will return an empty list.
8. Security
Transport is encrypted with TLS. Access is tenant-scoped and follows least privilege. Backups are encrypted at rest. Security-relevant events are recorded in an append-only audit trail. Vulnerability reports are welcome at security@ceyu.org.
9. Children
Ceyu is a tool for professional work and is not directed at children. You must be at least 18 to hold an account — see section 3 of the terms of service.
We do not knowingly collect personal data from children. Under Art. 8 GDPR, consent-based processing for a child under 16 would require parental authorisation; we avoid the question by not accepting minors in the first place. The same applies to COPPA in the United States, which covers children under 13. If you believe a child has created an account, write to privacy@ceyu.org and we will delete it.
10. Changes to this policy
We update this policy when the processing changes. The date at the top always reflects the current version. Material changes affecting existing users are announced in the application before they take effect.