Legal
Privacy policy
Last updated: 2026-07-26. This template describes the processing currently present in the code and must be reviewed regularly by the operator.
1. Controller
The controller under the General Data Protection Regulation (GDPR) is:
Benneth MüllerBorgfelder Straße 16
20537 Hamburg
Deutschland
Email: ben@creaiter.com
2. Processing overview
Creaiter is a learning platform publicly available at creaiter.com. The dashboard, feed, and Creaites can be explored without an account. An optional user account can be created for personal areas. Without a configured PostHog project token, no analytics code is loaded and no analytics data is sent.
Server-side newsletter delivery, uploads, payments, automated decision-making, user profiles, roles, and server-side progress synchronization are not implemented.
3. Local browser storage
The following data remains exclusively in your browser's localStorage and cannot be viewed by the operator:
- Theme selection (light, dark, or system) for the requested presentation.
- Feed progress, Vibe Points, quiz answers, and the last visited card.
- Course completion for SQL, Build Briefing, and the Vibe Coding Loop, including each best first-attempt score, completed-attempt count, and already claimed learning points; questions, free text, lab states, and individual course answers are not stored.
- The on/off setting for microlearning sound feedback.
- Badges earned in the microlearnings together with the time they were awarded.
- The collapsed state of the platform sidebar.
- The email address entered in the newsletter demo and its local timestamp; it is neither sent nor transferred.
- Your optional analytics and session replay decision, including status and time, so consent or rejection can be respected.
- After consent, PostHog's own local storage with a random device, session, and window identifier; withdrawing removes it.
These technically necessary or explicitly requested local stores rely on section 25(2)(2) TDDDG and, where personal data is involved, Article 6(1)(b) or (f) GDPR. Optional analytics storage begins only after consent.
4. Optional AI mode in the SQL coach
Every SQL question you voluntarily submit is sent to the Creaiter server route. Without a server-side OpenAI key, only the fixed course knowledge answers it and nothing is transferred to an AI provider. If optional AI mode is configured, the question may be forwarded to the OpenAI Responses API; the interface labels such a response as an “AI answer”.
- The trimmed question of no more than 500 characters, selected language, and current course step are transmitted.
- To prevent abuse, the Creaiter server keeps only in memory a randomly salted hash derived from the IP address and origin, together with a counter and expiry time. The rate limit uses a 60-second window; expired entries are removed on the next matching request, during capacity pruning, or no later than the end of the server instance. The plain IP, question, and answer are not logged.
- In optional AI mode, OpenAI additionally receives tightly bounded course instructions. No files, URLs, databases, previous questions, account data, or tools are transmitted or enabled.
Creaiter stores neither the question nor the answer in a database or chat history. The provider request sets store: false. This is not a promise of Zero Data Retention: according to OpenAI, default abuse-monitoring logs may contain inputs and outputs for up to 30 days. Without approved Zero Data Retention, supported models may also keep encrypted prompt-cache tensors GPU-local for up to 24 hours. The data controls of the API project in use and actual retention must be reviewed before production activation.
Processing the voluntarily submitted question serves the learning assistance explicitly requested and is assigned to Article 6(1)(b) GDPR in this template. The short-lived abuse limit supports secure operation under Article 6(1)(f) GDPR. This assessment, the OpenAI DPA, and possible international transfers must be reviewed legally before production activation.
The optional technical recipient is OpenAI. OpenAI data controls · OpenAI DPA
5. Optional PostHog analytics and session replay
The integration remains fully inactive without a public PostHog project token. Once configured, the SDK including its recording feature is dynamically loaded only after your explicit consent; without consent no analytics code is loaded and nothing is recorded.
One purpose is to understand in aggregate which pages are entered and left. The other is to reconstruct your session as a replayable recording (session replay) so usability problems, drop-offs, and interface errors can be traced and fixed. Third, a set of strictly defined usage events shows how far posts are read, which paths are taken out of them, and how far someone gets in a course, in the feed, and in the sign-up flow; the permitted event names and values are exhaustively enumerated in the source code (src/features/analytics/product-events.ts).
- A cleaned page URL and path without query parameters or hash.
- The time a page is viewed or left.
- A random pseudonymous device identifier and technical browser, operating system, screen, and device information.
- The IP address technically transmitted during the connection and potentially processed by the service.
- A technical reconstruction of the rendered page and your interactions — mouse movement, clicks, scrolling, resizing, and changes to the displayed page content — that can be played back as a session recording.
- A random session and window identifier used to join the individual segments of one recording.
- When a recording starts, a configuration is additionally fetched from eu-assets.i.posthog.com; the IP address is technically transmitted in the process.
- Sixteen product usage events without personal reference. For content: the reading depth reached in an article (25/50/75/100 per cent), the use of an article element (table of contents, visual, quiz, FAQ, sources, share, related posts, key takeaways), a click on a call to action, and the outcome of a newsletter sign-up. For the learning path: the start of a course, the learning step shown along with its number, the result of the first attempt at a task (correct or incorrect only, never the answer given), the completion of a run with score and attempt number, and the collection of the reward. For the feed: the first view of a card along with its position, the completion of a card, and the result of a feed quiz. In addition: opening a Creaite or use case, starting a video, switching the language, and the outcome of a sign-in, sign-up or password flow — recording only that an attempt was made and whether it succeeded, never the email address, never the password, and never the error message. Only values from a list fixed in the source code are transmitted, along with whole numbers from fixed ranges and the short names of published content, cards and courses — no free text, no input, no search terms.
Typed input is masked in the browser and never leaves your device in clear text. Selection elements such as checkboxes and radio buttons cannot technically be masked; the areas concerned are therefore excluded from the recording entirely. The contents of sign-in, sign-up, password recovery, password reset, the founder chat, SQL coach, newsletter forms, the email address shown in the account area and all quiz, course-assessment, checklist and selection areas are not recorded. On the authentication routes recording is additionally paused as soon as the route change is detected; during in-page navigation the address and technical metadata of that route may briefly still appear in the recording — form contents never do. Addresses are always stored in the recording without query parameters or fragment. Network payloads, console output, and canvas or WebGL graphics are not recorded either. Person profiles, identification, autocapture, heatmaps, exception capture, surveys, experiments, and feature flags remain switched off in code.
The masking contract lives in the source code (src/features/analytics/replay-config.ts) and is passed to the SDK locally on every start. Locally binding and not loosenable through the PostHog interface are: the masking of typed input, the exclusion and redaction classes, disabling canvas and WebGL recording, disabling console recording, and disabling heatmaps. For network payload recording a project setting can still load the additional module; request headers and bodies nevertheless remain excluded by the local switch-off. Retention, sampling and the server-side blocklist for the authentication routes are project settings and are set there bindingly.
Session recordings are deleted automatically in the PostHog project after 30 days.
The legal bases are your consent under Article 6(1)(a) GDPR and section 25(1) TDDDG. You can withdraw it at any time for the future through the globally available analytics settings.
The technical recipient is PostHog Inc.. The default configuration uses PostHog Cloud EU with processing in Frankfurt. PostHog privacy policy · DPA · GDPR documentation
PostHog is a US company with European entities and subprocessors. The provider states that Cloud EU user data is stored in Germany; where further third-country transfers occur, PostHog cites the EU-US Data Privacy Framework and Standard Contractual Clauses. The configuration fetch before a recording starts also goes to PostHog's EU infrastructure. Before activation, the DPA, region, access, and provider settings must be reviewed.
Retention periods are configured in the PostHog project and must match the information given here; the event retention set there applies to analytics events. Withdrawing consent ends collection immediately, removes local PostHog storage, and blocks further collection; data already transmitted is deleted after the stated period.
6. YouTube videos (click to load)
On the videos page we embed videos from YouTube — strictly as a two-click solution. Before you click “Play video”, no iframe is loaded into the page, no connection to Google or YouTube is opened and no preview image is fetched from a Google server. Only your click starts the connection.
- your IP address
- details about your browser, operating system, device and screen resolution
- the referring page, shortened to the domain creaiter.com
- information about the playback of the specific video
- data that YouTube stores in or reads from your browser; if you are signed in to Google, YouTube can link the request to your account
We use YouTube's privacy-enhanced mode via the domain youtube-nocookie.com. This mode prevents your playback behaviour from being used for personalised advertising. It is explicitly not data-free: the data listed above is still transmitted to Google and playback-related information is still stored in your browser.
The legal basis for storing and accessing information on your device is Section 25 (1) TDDDG, and for the subsequent processing Art. 6 (1) (a) GDPR — your consent in both cases. Clicking “Play video” is that consent; it covers that single playback only. We do not store your consent, so it ends at the latest when the page is reloaded. Without a click there is no processing.
The recipient is Google Ireland Ltd.; this company is responsible for YouTube for users in the European Economic Area and Switzerland. Google privacy policy
Google also processes data in the USA. This is based on the EU standard contractual clauses and the EU-US Data Privacy Framework; access by US authorities cannot be fully ruled out.
7. Hosting and technical logs
The website is hosted by Netlify, Inc., 101 2nd Street, San Francisco, CA 94105, USA, acting as a processor. On every request, Netlify processes technically necessary connection and log data, in particular the IP address, timestamp, requested URL or resource, and browser and device information. The purposes are delivery of the website, stability, troubleshooting, security, and prevention of abuse. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and reliable operation of the service.
Netlify may process data in the United States and through published subprocessors. Processing is governed by Netlify's DPA; for transfers to the United States, Netlify cites its certification under the EU-US Data Privacy Framework and, additionally, the EU Standard Contractual Clauses. Technical log data is processed only for as long as required for operation, security, troubleshooting, or legal obligations; specific service- and plan-dependent periods follow the provider agreement and Netlify settings.
8. Supabase content and user accounts
Published blog revisions and editorial AI news are read server-side from a Supabase project in Frankfurt. For registration, sign-in, sign-out, email confirmation, and password recovery, the browser instead connects securely to Supabase Auth. Guests do not receive an authentication session merely by exploring public content.
- Registration and sign-in process the email address, a Supabase-issued user ID, and necessary authentication and session data.
- The password is transmitted only to Supabase for authentication; Creaiter neither stores nor reads a plain-text password.
- Sign-in is maintained through technically necessary session cookies set by the Supabase SSR integration.
- This version stores no profile, role, or server-side progress data.
Account processing serves the registration and sign-in voluntarily requested by you and contractual or pre-contractual steps under Article 6(1)(b) GDPR. Necessary session cookies rely on section 25(2)(2) TDDDG. Account and authentication data remain until account deletion or the retention periods agreed with Supabase; a self-service deletion feature is not yet implemented and deletion can be requested through the contact above.
9. External links
Articles, news, and legal pages may link to external sources. Only when you open such a link does the respective provider process data under its own terms. Creaiter does not embed those pages automatically.
10. Retention
Local browser data remains until you change it in the app, reset feed or course progress, or clear website storage in your browser. Creaiter does not persist SQL coach questions or answers; the provider periods described in the coach section apply to an optional OpenAI request. Authentication sessions end on sign-out or expiry; account and authentication data are processed until account deletion or under the retention periods agreed with Supabase. Withdrawing analytics ends collection immediately, deletes local PostHog persistence, and blocks further collection; recordings already transmitted are deleted after the period named in the PostHog section.
11. Your rights
Where personal data is processed, you have in particular the following rights:
- Access under Article 15 GDPR.
- Rectification under Article 16 GDPR.
- Erasure under Article 17 GDPR.
- Restriction of processing under Article 18 GDPR.
- Data portability under Article 20 GDPR.
- Objection to processing based on legitimate interests under Article 21 GDPR.
To exercise your rights, send a message to ben@creaiter.com.
12. Withdrawal of consent
You can withdraw analytics consent at any time in analytics settings (Article 7(3) GDPR). The withdrawal ends collection immediately and also takes effect in other open tabs; data already collected may have been transmitted to PostHog by then and is deleted after the stated storage period. Processing before withdrawal remains lawful.
13. Right to lodge a complaint
Under Article 77 GDPR, you may lodge a complaint with a data protection authority. For the controller in Hamburg, the following authority is available in particular:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit14. Requirement to provide data
You are not required to create an account or allow analytics; public content remains available without an account. An email address and password are technically required for registration, sign-in, and password recovery. Necessary local state is created only when you use the relevant feature.
15. Changes
This policy will be reviewed and updated when the scope or retention of analytics and session replay changes, Supabase email delivery and retention periods are configured for production, or data flows, hosting, or providers change.