Privacy Policy
Last updated: March 2026
1. Controller
The controller responsible for the processing of personal data within the meaning of the GDPR is:
Philipp Brosig (FIL)
Bahnhofstr. 11
27383 Scheeßel
Germany
Email: fil@secbrain.io
2. Overview of Data Processing
SecBrain is a productivity platform for personal organization. We process personal data only to the extent necessary to operate the platform and provide the agreed services. Data is never shared with third parties for advertising purposes.
3. Hosting
SecBrain's infrastructure is hosted entirely on servers of Hetzner Online GmbH (Germany). All data is stored and processed exclusively within the European Union. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with Hetzner.
4. Registration and User Account
Using SecBrain requires registration with an email address and password. Passwords are stored exclusively as secure hashes — they are never accessible in plain text, neither by us nor by anyone else.
The authentication system uses session tokens and CSRF tokens to ensure session security. These are managed server-side and invalidated upon logout.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
5. User Data in the App
SecBrain stores the content you actively create within the application. Depending on your usage, this may include:
- Tasks, projects, sprints, and goals
- Activities, areas, and ideas
- Contacts, persons, companies, and customers
- Events and appointments
- Objects, animals, and other entries
- Diary entries, reports, and notes
- Issues and problems
This data belongs to you. It is processed solely for the purpose of operating your personal workspace and is not analyzed, sold, or shared with third parties.
Diary entries and reports may contain sensitive personal information. We recommend not entering data whose loss or unauthorized access could harm you — and to create regular backups of your data.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
6. Email Communication
SecBrain sends system-required emails via our own SMTP server, such as registration confirmation or password reset links. Only the data necessary for delivery (email address, timestamp) is processed. No marketing emails are sent without your explicit consent.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
7. Push Notifications
If you enable push notifications, for example for reminders about todos, deadlines, or birthdays, we use Firebase Cloud Messaging (FCM) provided by Google Ireland Limited and Google LLC. Your device receives an identifier (FCM token) that we store in order to deliver notifications to you.
Please note: a notification contains the title of the relevant entry in plain text, for example the name of a todo, a schedule, or a person, and for journal entries the first characters of the text. This information passes through Google's infrastructure so that delivery can work. If you would rather it did not, leave notifications disabled. Every SecBrain feature remains usable without them.
This processing may involve a transfer to the USA. It takes place on the basis of the European Commission's standard contractual clauses. You can withdraw your consent at any time by disabling notifications in your device or browser settings.
Legal basis: Art. 6(1)(a) GDPR (consent)
8. Subscriptions and Payment Processing
We use RevenueCat, Inc. (USA) to manage Premium subscriptions. A pseudonymous user identifier and the status of your subscription are transmitted for this purpose. Content you create in SecBrain is not transmitted to RevenueCat.
If you purchase a subscription on the web, payment is processed by Stripe (Stripe Payments Europe Limited, Ireland, and Stripe, Inc., USA). Payment details such as card data are processed exclusively by Stripe; we never receive them.
If you purchase the subscription as an in-app purchase, Apple (Apple Inc. and Apple Distribution International Limited) or Google (Google Ireland Limited) handles the purchase under their own responsibility. We only receive the information whether an active subscription exists. The respective provider's privacy terms apply to that processing.
Where data is transferred to the USA, this takes place on the basis of the European Commission's standard contractual clauses.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
9. Web Analytics with Umami
To improve our website, we use Umami — a privacy-friendly analytics tool hosted on our own servers at Hetzner. No data is transmitted to external services.
Umami collects anonymized usage data such as pages visited, time spent, and browser type. IP addresses are neither stored nor shared. No cookies are set for analytics purposes, and no cross-device profiles are created.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving our website)
10. Cookies and Local Storage
SecBrain uses technically necessary cookies and browser storage (LocalStorage/SessionStorage) to maintain your session and keep the app functional. These cannot be disabled as they are essential to the platform's operation. No tracking or advertising cookies are used.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating the platform)
11. Sharing Data with Third Parties
We do not sell your personal data and do not share it for advertising purposes. Data is shared only where necessary to operate the service, where required by law, or where you have given consent. The following are used: Hetzner Online GmbH (Germany) for hosting and storage, Google for delivering push notifications, RevenueCat, Inc. (USA) for managing subscriptions, and Stripe (Ireland and USA) for payment processing on the web. For a purchase through the Apple App Store or Google Play, Apple or Google handles the purchase under their own responsibility. Data processing agreements under Art. 28 GDPR are in place with our processors; transfers to the USA rely on the European Commission's standard contractual clauses.
12. Data Deletion and Retention
You can request deletion of your account at any time by emailing fil@secbrain.io. Following deletion, all personal data associated with your account will be irreversibly removed within 30 days, unless statutory retention obligations apply.
We recommend creating regular backups of your content.
13. Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): you can find out what data we store about you.
- Rectification (Art. 16 GDPR): you can request correction of inaccurate information.
- Erasure (Art. 17 GDPR): you can request removal of your information.
- Restriction (Art. 18 GDPR): you can request that processing be limited.
- Data portability (Art. 20 GDPR): you can receive your information in standard format.
- Objection (Art. 21 GDPR): you can challenge processing based on legitimate interests.
To exercise these rights, please contact: fil@secbrain.io
You also have the right to lodge a complaint with a data protection authority. The competent supervisory authority for Lower Saxony is the State Commissioner for Data Protection of Lower Saxony (Landesbeauftragter für den Datenschutz Niedersachsen).
14. Data Security
We implement technical and organizational measures to protect your data against unauthorized access, loss, or misuse. All transmission between your device and our servers is encrypted via HTTPS. Passwords are stored exclusively as secure hashes.
Beyond that, every text you enter is stored encrypted in the database: the names, descriptions, and reports of your activities, schedules, and todos, as well as your contacts, journal entries, and diary entries. Not encrypted are structural details such as dates and times, priorities, or how entries are linked to one another, because they are required to operate the application.
15. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy as needed — for example, when features change or legal requirements evolve. The current version is always available at /privacy. For material changes, we will notify you by email.
