Privacy Policy
Last updated: September 19, 2026
This Privacy Policy describes what personal data we collect when you use meisterweb24.de and its related services, the purposes for which we process it, which providers we use, and what rights users have under the European Union General Data Protection Regulation (GDPR).
Responsible for data processing:
DevFlow Studios
E-mail: [email protected]
The controller ensures that personal data is processed in accordance with the applicable data protection laws, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
Depending on how you use the service, we may process the following data:
- e-mail address, used for registration and sign-in;
- username, if you provide one;
- display name, if you provide one;
- technical identifiers associated with the user account.
If you use your own API key (BYOK – Bring Your Own Key), we may store the API key in encrypted form so that the service can access it during later use.
We do not use the API key for our own purposes, and we do not sell it or pass it to third parties.
In connection with using the service, we may process:
- your current credit balance;
- credit top-ups and deductions;
- data related to purchases and transactions;
- the time and identifier of transactions.
We do not store card details in our own system; card payments are handled by a specialised payment provider, Stripe.
For the secure operation, debugging and accounting of usage, we may process technical and usage data, for example:
- which model you used;
- the time the model was run;
- the credit usage associated with the usage;
- technical log entries.
We do not use this data to build advertising profiles.
If you enable two-factor authentication (2FA), we process the 2FA secret required for it and the technical data related to authentication.
We use personal data only for the purposes necessary to operate the service, including:
- creating and managing the user account;
- sign-in and authentication;
- operating two-factor authentication;
- providing the execution of AI models;
- recording credit usage;
- handling purchases and transactions;
- maintaining system security;
- investigating technical faults;
- providing and improving the service;
- answering user enquiries.
We do not use personal data to create advertising profiles of users.
When you use the platform’s AI features, we may use external AI providers to process the requests.
The content of the AI request may be transmitted to the relevant AI provider to the extent necessary for the model you selected and for the operation of that service.
The service may provide access to AI models via OpenRouter, among others.
A key you provide as your own API key (BYOK) is not logged and is not used for purposes you have not authorised.
To operate the service we use external providers in certain cases. These may include:
- Supabase – database, authentication and related backend infrastructure;
- Vercel – hosting and application infrastructure;
- OpenRouter – access to AI models and forwarding of AI requests;
- Stripe – processing of online payments and transactions;
- Resend – delivery of transactional and sign-in e-mails;
- Google / Gemini – support for translating certain catalogue data, such as descriptions.
These providers can access the data they process only to the extent necessary to operate the service, and their own terms and privacy rules also apply.
Own API keys are particularly sensitive technical credentials. We therefore do not display them publicly, sell them or publish them.
Where the application supports storing API keys, we handle the keys with appropriate technical protection, in encrypted form.
Important: when providing your own API key, we recommend using only a key created for this purpose and for which you have set appropriate usage restrictions with the relevant provider.
The website essentially uses only technologies necessary to operate the service. These may include, for example:
- technical data needed to maintain the login session;
- language preference;
- display/theme preference;
- security and authentication functions.
We do not use third-party advertising cookies.
As the service currently operates, we do not use any advertising tracking system or behavioural profiling carried out by third parties.
We measure the use of our pages ourselves, on our own servers, without cookies and without third-party services. We do not store IP addresses: from the IP address, the browser identifier and a secret key we derive a code that changes daily, cannot be reversed and takes a different value the next day.
We record the page opened, the domain, the language, the country of the visit, the device type, the browser and operating system, the referring page and the time spent on the page. We also count calls to our public MCP interface and visits by automated crawlers.
We use this data solely for statistics about the use of our service. We do not share it with third parties and do not build user profiles from it. Raw records are deleted after 90 days; only an anonymous daily summary is kept.
We retain personal data only for as long as it is necessary to provide the service, to fulfil contractual or legal obligations, or to pursue our legitimate interests.
When a user account is deleted, we delete or anonymise the deletable personal data, taking into account the applicable retention obligations.
Certain transactional, accounting or legally retained data may need to be kept for the period prescribed by law.
We apply appropriate technical and organisational measures to protect personal data, among others against:
- unauthorised access;
- unauthorised modification;
- loss;
- destruction;
- unauthorised disclosure.
However, transmitting data over the internet cannot, by its nature, be guaranteed to be completely secure.
Data necessary to operate the service may in certain cases also be transferred to providers operating outside the European Economic Area.
In such cases the transfer must take place on an appropriate legal basis and with the safeguards required by the GDPR.
Under the GDPR you have, among others, the right:
- to request information about the processing of your personal data;
- to request access to the personal data processed about you;
- to request rectification of inaccurate data;
- to request erasure of your personal data;
- to request restriction of processing;
- to object to certain processing;
- to request data portability where its legal conditions are met;
- to withdraw consent at any time where processing is based on consent.
You can send a request to exercise these rights to the following e-mail address: [email protected]
We handle requests without undue delay, within the time limits set out in the GDPR.
If you consider that the processing of your personal data infringes the applicable data protection laws, you have the right to lodge a complaint with the competent data protection supervisory authority.
For users in the European Union this is typically the supervisory authority of their place of residence, place of stay or the place of the alleged infringement.
In Germany, the competent authority may, depending on the specific case and the competence of the controller, be the federal or a state data protection authority.
We reserve the right to amend this Privacy Policy where necessary, for example due to changes in the service, the technologies used or the relevant legislation.
The current version is available on the website at all times.
For privacy questions and access, rectification or erasure requests:
DevFlow Studios
E-mail: [email protected]