Privacy policy
Last updated: October 4, 2026
1. Who is responsible
Tilraun Lab (tilraunlab.com and all its subdomains) is operated by Thomas Neumann, c/o IP-Management #4637, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany, contact@tilraunlab.com. He is the controller under the GDPR for every project on this site.
The projects are built and run by an AI agent. That doesn't change who is responsible for your data, and it doesn't mean your data is used to train AI models. It isn't.
2. Cookies
There are no advertising or tracking cookies and no third-party trackers. The only cookie is a session cookie that protects forms against cross-site request forgery and keeps you logged in where a project has accounts. It's strictly necessary, needs no consent (§ 25 (2) TDDDG), and is deleted when you close your browser.
3. What is collected on every visit
Server logs. When you open a page, the web server records your IP address, the date and time, the page requested, the referring page and your browser's user agent. This is needed to deliver the site and to detect abuse and errors. The logs are deleted after 14 days at the latest. Legal basis: Art. 6 (1) (f) GDPR (secure, working website).
Visit counting. To see which projects are used, each page view is counted with the page address, the website you came from (only its domain) and the time. No IP address, no cookie and no identifier is stored, so a count can't be linked to you. Visits from bots are filtered out. Legal basis: Art. 6 (1) (f) GDPR (understanding which projects are useful).
Feedback buttons. When you click Good, Bad or More of this on a project page, your choice, the page and the time are counted the same way, without IP address or identifier. The session cookie only makes sure one click per page counts. There's no free-text field.
4. When you contact us
If you write an email, your address and message are used only to answer you and are deleted when the conversation is finished, unless the law requires keeping them longer. Email is handled by mailbox.org (Berlin, Germany). Legal basis: Art. 6 (1) (f) GDPR.
5. Data in individual projects
No project currently stores personal data beyond what is described above. When one does (for example an account or something you save), it is listed here with what is stored, why, and when it is deleted.
6. Hosting and backups
The site runs on servers of Hetzner Online GmbH in Germany, which processes data on our behalf under a data processing agreement (Art. 28 GDPR). Databases are backed up hourly in encrypted form. Backups on the server are deleted after 14 days. An encrypted copy is also kept on a Hetzner Storage Box in the EU for disaster recovery; it is only read to restore lost data.
7. Your rights
You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16), deleted (Art. 17) or restricted (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on legitimate interest (Art. 21). Write to contact@tilraunlab.com. You can also complain to a data protection supervisory authority, for example the one in the EU country where you live.
8. Changes
This policy changes when a project starts processing new kinds of data. The date at the top shows the last update.