Info & Help
Privacy Policy
Protecting your data is important to us. This privacy policy informs you about which data is processed on ende.app and for what purpose.
1. Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is the operator of ende.app. The contact details can be found in the website's legal notice.
2. Principle of Data Processing
ende.app is designed to be data-minimizing. Personal data is only processed insofar as it is provided voluntarily or insofar as this is technically necessary for security or abuse-prevention reasons (e.g. IP address, recognition identifier).
There is no tracking for analytics or marketing purposes.
3. User Accounts
ende.app provides pseudonymous user accounts.
- User accounts are generally based on codes (UUID) or voluntary pseudonyms; real names are not collected.
- New accounts require an email address. It is used to confirm the account, to restore access and for abuse prevention.
- Accounts created before this change without an email address remain anonymous and can still be used.
3a. Email Address (Account Recovery & Abuse Prevention)
Since accounts are based on anonymous codes (UUID), lost access cannot be recovered without further information. For this reason an email address is required when registering; existing accounts without one can add it at any time in the settings.
- Rule – required: An email address must be given when registering. Without one, no new account can be created.
- Existing accounts – without an address: Older accounts without an email address remain anonymous. An address can be added at any time in the settings; without one, access cannot be restored.
- If an email address is provided, we send a confirmation/verification email to that address.
- The email address is not used for newsletters, advertising, marketing, tracking or profiling and is not shared with third parties (except for the technically necessary email delivery service, see section 8c).
- The address can be changed at any time and is deleted together with the account upon account deletion.
Legal basis: for voluntary provision, Art. 6(1)(a) GDPR (consent) as well as (b) (provision of the requested recovery function); for mandatory provision for abuse prevention, Art. 6(1)(f) GDPR (legitimate interest in protecting the platform).
4. Recognition for Abuse Prevention
To prevent abuse, automated access and security-relevant attacks, and to enforce usage limits (e.g. download limits), ende.app uses a recognition procedure.
In this context, the following may be processed:
- a pseudonymous random identifier for recognizing the device/browser (see section 10),
- for logged-in users, an encrypted identifier stored in the browser's local storage that records which user accounts have been used in this browser — to detect abusive multiple accounts (see section 10),
- the IP address as well as technical information derived from it (see sections 6 and 8a).
No reading of technical device characteristics (device fingerprinting) takes place. The aforementioned identifiers are random values or encrypted and, taken on their own, do not allow identification of users; no data is transmitted to third parties.
Purpose: protection against abuse, detection of automated use and of abusive multiple accounts, enforcement of download/usage limits, technical stability.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting the platform and its users). The storage and reading of the aforementioned identifiers is strictly technically necessary within the meaning of § 25 Abs. 2 Nr. 2 TDDDG in order to provide the explicitly requested service securely and reliably and to prevent abuse (e.g. circumventing download limits); consent is not required for this.
It is not used for analytics, profiling or marketing purposes; there is no evaluation of usage behavior for such purposes.
Consequences of abuse: Creating or using several user accounts in order to get around download limits is prohibited. Where such abuse is detected, all accounts involved are deleted and the email addresses used are permanently blocked from registering again. For this purpose the blocked addresses are stored in a block list (see section 11).
5. Data Processed
In the course of using ende.app, the following data may be processed:
- self-chosen pseudonyms
- the email address provided (required for new accounts; used for confirmation, access recovery and abuse prevention)
- a pseudonymous recognition identifier (cookie / local storage) as well as, for logged-in users, an encrypted identifier of the user accounts used in this browser (local storage)
- IP address and technical characteristics derived from it (e.g. network operator, reputation assessment) for abuse prevention
- technically necessary session data (e.g. session IDs)
No combination with other data sources for profiling purposes takes place.
5a. Optional Contact Details (e.g. Email Address)
At individual points on the website (e.g. in the guestbook or in contact functions), there is the option to voluntarily provide an email address.
- Providing it is not required to use the platform.
- The email address is used exclusively to respond to the respective inquiry or contribution.
- There is no disclosure to third parties and no use for newsletters, advertising or marketing.
Legal basis: Art. 6(1)(a) GDPR (consent) or Art. 6(1)(b) GDPR, insofar as the contact is made in connection with an inquiry.
6. IP Addresses
To ensure security and for abuse prevention, ende.app processes the IP address of users. For this purpose, the IP address may be stored and transmitted to a specialized service for technical classification (e.g. network operator, reputation assessment, detection of automated access) (see section 8a). It is not used for analytics or marketing purposes.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention).
7. Server Log Files
The hosting provider automatically collects and stores information in so-called server log files. These may include: IP address, date and time of the request, page accessed, browser and operating system used. This data serves exclusively the secure operation of the website and is not used to create user profiles.
8. Third-Party Services Used
ende.app uses no analytics, tracking, advertising or social media services and does not embed any external content for marketing purposes. For security, abuse prevention and technically necessary functions, only the following services are used:
a) AbuseIPDB – IP Reputation Check Provider: AbuseIPDB LLC, 562 Independence Road, East Stroudsburg, PA 18301, USA. To detect abuse and automated access, the incoming IP address is automatically checked against the AbuseIPDB database (query only) in order to obtain reputation and network operator information. No user, log or usage data is actively reported or uploaded to AbuseIPDB; only the IP address to be queried is transmitted. No profiling beyond this takes place. This involves a transfer to the USA. Purpose: security and abuse prevention. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). You may object to the processing pursuant to Art. 21 GDPR, insofar as an attribution of the IP address to your person is at all possible in an individual case.
b) Cloudflare Turnstile – Captcha Provider: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. At individual points (e.g. before downloads from suspicious networks or in cases of increased abuse risk), a captcha is displayed to distinguish between a human and automated access. In this context, Cloudflare processes, among other things, the IP address as well as technical browser and interaction data. Turnstile is designed for data minimization and does not serve advertising or tracking. Purpose: spam/abuse protection. Legal basis: Art. 6(1)(f) GDPR. Cloudflare is certified under the EU-U.S. Data Privacy Framework; additionally, EU Standard Contractual Clauses apply.
c) Email Delivery – Zoho ZeptoMail Provider: Zoho Corporation B.V. (European branch), delivery via the EU data center of ZeptoMail (zeptomail.zoho.eu). To send confirmation and recovery emails, the email address and the respective mail content are processed. The processing takes place within the EU. Purpose: technical delivery of the requested or required emails. Legal basis: Art. 6(1)(b) and (f) GDPR. No advertising use.
d) Google Drive (optional connection in the creator tools) Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (for users in the EEA). In certain creator tools, you can optionally connect to your Google Drive in order to save and load files there. This feature is optional and not required to use the platform.
- Scope of access: The connection uses only Google's restricted
drive.filepermission scope. This means ende.app can access only the files you create or open with the creator tools in Google Drive — not the rest of your Drive content. - Processing in the browser: Sign-in (OAuth) and file access happen directly in your browser, between your device and Google. The access token is held only for the duration of the session in the browser and is not transmitted to or stored on ende.app's servers.
- No storage on our side: ende.app does not store any Google user data (neither files, file contents, file listings, nor tokens) on its own servers.
- Purpose: solely the saving/loading of the files you create or edit with the creator tools, as requested by you.
- No sharing / repurposing: Google user data is not sold, not shared with third parties, and not used for advertising, profiling, training AI models, or any purpose other than this feature.
- Revocation: You can revoke the granted permission at any time in your Google Account under "Security → Third-party apps/access".
ende.app's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Purpose: providing the optional Drive save feature. Legal basis: Art. 6(1)(a) GDPR (consent by connecting) and (b) GDPR (provision of the requested function).
9. Hosting
The website is hosted by:
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Germany
Data processing takes place – with the exception of the services mentioned in section 8 – exclusively on servers within the European Union.
10. Cookies & Local Storage
ende.app uses no tracking or marketing cookies. Only the following are used:
- technically necessary cookies (e.g. session, security mechanisms),
- a pseudonymous recognition identifier for abuse prevention and the enforcement of usage limits, which is stored as a first-party cookie and/or in the browser's local storage (localStorage/IndexedDB),
- for logged-in users, an encrypted identifier of the user accounts used in this browser to detect abusive multiple accounts, stored in the browser's local storage (localStorage/IndexedDB).
The recognition cookie is stored for a maximum of 30 days since the last visit (renewed on a rolling basis with each visit) and then expires automatically. The identifiers stored in the browser's local storage remain until the browser data is deleted. They do not serve to analyze usage behavior and are not shared with third parties.
The storage or reading of information on the end device (cookies, localStorage/IndexedDB) takes place on the basis of § 25 Abs. 2 Nr. 2 TDDDG: These functions are strictly technically necessary in order to provide the explicitly requested service securely and reliably and to prevent abuse (e.g. circumventing download limits). Consent is not required for this; no consent-requiring tracking or marketing cookies are set.
11. Retention Period
- User accounts (inactivity): accounts that have not been logged into for 6 months are deleted automatically and without prior notice; every login restarts the period. Any remaining usage data can no longer be attributed to a person.
- Accounts with an unconfirmed email address: if an email address provided during registration is not confirmed within 3 hours, the account is deleted automatically.
- Recognition cookie: a maximum of 30 days since the last visit (rolling).
- Locally stored identifiers (localStorage/IndexedDB): until the user deletes the browser data.
- Email address: until deletion by the user or until account deletion.
- Blocked email addresses: Addresses blocked because of abuse (see section 4) remain stored in the block list permanently – including after the associated account has been deleted – as the block would otherwise have no effect.
- Security/abuse data (e.g. IP-related logs, account associations): only for as long as is necessary for the purpose of abuse prevention; afterwards deletion or anonymization.
12. Users' Rights
Under the GDPR, users have in particular the right to access, rectification, erasure, restriction of processing, data portability, and to object to the processing. There is also a right to lodge a complaint with a data protection supervisory authority.
Since much of the data is processed exclusively on a pseudonymous basis, attribution to individual users may in certain cases not be technically possible.
13. Changes to This Privacy Policy
This privacy policy may be amended if the legal or technical conditions change. The current version is always available on the website.
Last updated: September 2026