Wink
Sascha Ende Logo Sascha Ende Logo

Privacy Policy

Protecting your data is important to us. This privacy policy informs you about which data is processed on ende.app and for what purpose.

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is the operator of ende.app. The contact details can be found in the website's legal notice.

2. Principle of Data Processing

ende.app is designed to be data-minimizing. Personal data is only processed insofar as it is provided voluntarily or insofar as this is technically necessary for security or abuse-prevention reasons (e.g. IP address, recognition identifier).

There is no tracking for analytics or marketing purposes.

3. User Accounts

ende.app allows the use of largely anonymous user accounts.

  • User accounts are generally based on codes (UUID) or voluntary pseudonyms; real names are not collected.
  • An email address can be stored – to recover access to the account. Providing it is generally voluntary, but may in certain cases (see section 3a) be mandatory.
  • If no email address is provided, the account remains anonymous.

3a. Email Address (Account Recovery & Abuse Prevention)

Since accounts are based on anonymous codes (UUID), lost access is normally not recoverable without further information. For this reason, an email address can be stored during registration or in the settings.

  • Standard case – voluntary: Providing it is optional and serves to recover account access (e.g. password reset). Without an email address, the account remains anonymous.
  • Exception – mandatory: In the event of increased volume or for abuse prevention, providing an email address during registration may be temporarily made mandatory in order to curb automated or abusive mass registrations.
  • If an email address is provided, we send a confirmation/verification email to that address.
  • The email address is not used for newsletters, advertising, marketing, tracking or profiling and is not shared with third parties (except for the technically necessary email delivery service, see section 8c).
  • The address can be changed or deleted at any time and is deleted together with the account upon account deletion.

Legal basis: for voluntary provision, Art. 6(1)(a) GDPR (consent) as well as (b) (provision of the requested recovery function); for mandatory provision for abuse prevention, Art. 6(1)(f) GDPR (legitimate interest in protecting the platform).

4. Fingerprinting & Recognition for Abuse Prevention

To prevent abuse, automated access, security-relevant attacks, and to enforce usage limits (e.g. download limits), ende.app uses a fingerprinting and recognition procedure.

In this context, the following may be processed:

  • technical characteristics of the end device (browser and system information, technical configurations, time-related characteristics) which are combined on the end device into a pseudonymous fingerprint (hash value),
  • a pseudonymous random identifier for recognizing the device/browser (see section 10),
  • the IP address as well as technical information derived from it (see sections 6 and 8a).

The fingerprint is calculated on the end device; in doing so, no data is transmitted to third parties for the fingerprint itself. The aforementioned values, taken on their own, do not allow identification of users.

Purpose: protection against abuse, detection of automated use, enforcement of download/usage limits, technical stability.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the platform and its users). The reading of the aforementioned device characteristics is strictly technically necessary within the meaning of § 25 Abs. 2 Nr. 2 TDDDG in order to provide the explicitly requested service securely and reliably and to prevent abuse (e.g. circumventing download limits); consent is not required for this.

It is not used for analytics, profiling or marketing purposes; there is no evaluation of usage behavior for such purposes.

5. Data Processed

In the course of using ende.app, the following data may be processed:

  • self-chosen pseudonyms
  • the provided email address (voluntary for account recovery; in exceptional cases mandatory for abuse prevention)
  • pseudonymous technical fingerprints as well as a pseudonymous recognition identifier (Cookie / local storage)
  • IP address and technical characteristics derived from it (e.g. network operator, reputation assessment) for abuse prevention
  • technically necessary session data (e.g. session IDs)

No combination with other data sources for profiling purposes takes place.

5a. Optional Contact Details (e.g. Email Address)

At individual points on the website (e.g. in the guestbook or in contact functions), there is the option to voluntarily provide an email address.

  • Providing it is not required to use the platform.
  • The email address is used exclusively to respond to the respective inquiry or contribution.
  • There is no disclosure to third parties and no use for newsletters, advertising or marketing.

Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR, insofar as the contact is made in connection with an inquiry.

6. IP Addresses

To ensure security and for abuse prevention, ende.app processes the IP address of users. For this purpose, the IP address may be stored and transmitted to a specialized service for technical classification (e.g. network operator, reputation assessment, detection of automated access) (see section 8a). It is not used for analytics or marketing purposes.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).

7. Server Log Files

The hosting provider automatically collects and stores information in so-called server log files. These may include: IP address, date and time of the request, page accessed, browser and operating system used. This data serves exclusively the secure operation of the website and is not used to create user profiles.

8. Third-Party Services Used

ende.app uses no analytics, tracking, advertising or social media services and does not embed any external content for marketing purposes. For security, abuse prevention and technically necessary functions, only the following services are used:

a) AbuseIPDB – IP Reputation Check Provider: AbuseIPDB LLC, 562 Independence Road, East Stroudsburg, PA 18301, USA. To detect abuse and automated access, the incoming IP address is automatically checked against the AbuseIPDB database (query only) in order to obtain reputation and network operator information. No user, log or usage data is actively reported or uploaded to AbuseIPDB; only the IP address to be queried is transmitted. No profiling beyond this takes place. This involves a transfer to the USA. Purpose: security and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). You may object to the processing pursuant to Art. 21 GDPR, insofar as an attribution of the IP address to your person is at all possible in an individual case.

b) Cloudflare Turnstile – Captcha Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. At individual points (e.g. before downloads from suspicious networks or in cases of increased abuse risk), a captcha is displayed to distinguish between a human and automated access. In this context, Cloudflare processes, among other things, the IP address as well as technical browser and interaction data. Turnstile is designed for data minimization and does not serve advertising or tracking. Purpose: spam/abuse protection. Legal basis: Art. 6(1)(f) GDPR. Cloudflare is certified under the EU-U.S. Data Privacy Framework; additionally, EU Standard Contractual Clauses apply.

c) Email Delivery – Zoho ZeptoMail Provider: Zoho Corporation B.V. (European branch), delivery via the EU data center of ZeptoMail (zeptomail.zoho.eu). To send confirmation and recovery emails, the email address and the respective mail content are processed. The processing takes place within the EU. Purpose: technical delivery of the requested or required emails. Legal basis: Art. 6(1)(b) and (f) GDPR. No advertising use.

d) Google Drive (optional connection in the creator tools) Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users in the EEA). In certain creator tools, you can optionally connect to your Google Drive in order to save and load files there. This feature is optional and not required to use the platform.

  • Scope of access: The connection uses only Google's restricted drive.file permission scope. This means ende.app can access only the files you create or open with the creator tools in Google Drive — not the rest of your Drive content.
  • Processing in the browser: Sign-in (OAuth) and file access happen directly in your browser, between your device and Google. The access token is held only for the duration of the session in the browser and is not transmitted to or stored on ende.app's servers.
  • No storage on our side: ende.app does not store any Google user data (neither files, file contents, file listings, nor tokens) on its own servers.
  • Purpose: solely the saving/loading of the files you create or edit with the creator tools, as requested by you.
  • No sharing / repurposing: Google user data is not sold, not shared with third parties, and not used for advertising, profiling, training AI models, or any purpose other than this feature.
  • Revocation: You can revoke the granted permission at any time in your Google Account under "Security → Third-party apps/access".

ende.app's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Purpose: providing the optional Drive save feature. Legal basis: Art. 6(1)(a) GDPR (consent by connecting) and (b) GDPR (provision of the requested function).

9. Hosting

The website is hosted by:

Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany

Data processing takes place – with the exception of the services mentioned in section 8 – exclusively on servers within the European Union.

10. Cookies & Local Storage

ende.app uses no tracking or marketing cookies. Only the following are used:

  • technically necessary cookies (e.g. session, security mechanisms),
  • a pseudonymous recognition identifier for abuse prevention and the enforcement of usage limits, which is stored as a first-party cookie and/or in the browser's local storage (localStorage/IndexedDB).

The recognition cookie is stored for a maximum of 30 days since the last visit (renewed on a rolling basis with each visit) and then expires automatically. The identifier stored in the browser's local storage remains until the browser data is deleted. Neither serves to analyze usage behavior, and neither is shared with third parties.

The storage or reading of information on the end device (cookies, localStorage/IndexedDB as well as the collection of technical device characteristics for the fingerprint) takes place on the basis of § 25 Abs. 2 Nr. 2 TDDDG: These functions are strictly technically necessary in order to provide the explicitly requested service securely and reliably and to prevent abuse (e.g. circumventing download limits). Consent is not required for this; no consent-requiring tracking or marketing cookies are set.

11. Retention Period

  • Recognition cookie: a maximum of 30 days since the last visit (rolling).
  • Locally stored identifier (localStorage/IndexedDB): until the user deletes the browser data.
  • Email address: until deletion by the user or until account deletion.
  • Security/abuse data (e.g. IP-related logs, fingerprint assignments): only for as long as is necessary for the purpose of abuse prevention; afterwards deletion or anonymization.

12. Users' Rights

Under the GDPR, users have in particular the right to access, rectification, erasure, restriction of processing, data portability, and to object to the processing. There is also a right to lodge a complaint with a data protection supervisory authority.

Since much of the data is processed exclusively on a pseudonymous basis, attribution to individual users may in certain cases not be technically possible.

13. Changes to This Privacy Policy

This privacy policy may be amended if the legal or technical conditions change. The current version is always available on the website.

Last updated: July 2026