Privacy Policy
Last updated: September 2026
1. Controller
The controller within the meaning of the GDPR is:
Karl J. Pilz, sole proprietor
Agentur Web2Null.at
Sagmüllerweg 8
5081 Anif-Niederalm
Austria
Phone: +43 660 149 54 89
E-Mail: hi@finde-deinen-sinn.de
No data protection officer has been appointed; the conditions of Art. 37 GDPR are not met. Please send any data protection matter directly to the e-mail address above.
2. Principles and Scope
We process your personal data exclusively in accordance with the EU General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG). For users in Germany, the TDDDG and the BDSG apply in addition.
This policy covers the web application "Finde deinen Sinn" at finde-deinen-sinn.de and describes, as concretely as possible, which data is actually processed, for what purpose and on what legal basis.
3. What Data We Process
- Account data: your name, your e-mail address (in plain text — needed for login, confirmation and notification e-mails and password resets), your password (stored exclusively as a bcrypt hash, never in plain text), your language setting and timestamps for registration and the last change. Purpose: providing your account. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
- Self-assessment: your answers to the four Ikigai core questions and, in addition, the notes you record yourself (what you like and what you do not like, where you see yourself as stronger and where as weaker). Purpose: creating and displaying your Ikigai result. Legal basis: Art. 6(1)(b) GDPR.
- Invitation data: see section 5.
- Feedback from invited people: the individual answers (named strengths, free-text answers, assessment of closeness) are linked solely to the respective invitation, never to a name. Purpose: creating your aggregated summary. Legal basis: towards you Art. 6(1)(b) GDPR, towards the person giving feedback Art. 6(1)(a) GDPR (consent, given by submitting the feedback).
- AI coach chat: your messages and the replies of the coach. Purpose: providing the coaching feature. Legal basis: Art. 6(1)(b) GDPR. Details in section 6.
- Derived data: the aggregated evaluation calculated from the feedback answers (word clouds, top strengths, blind spots, self vs. others comparison) and the tip suggestions derived from it. Legal basis: Art. 6(1)(b) GDPR.
- Server log files: see section 8. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).
Important note on free-text fields: in the free-text fields (self-assessment, feedback, AI coach) you decide yourself what you write. Please do not enter any special categories of personal data within the meaning of Art. 9 GDPR — that is, no information about health, sexual orientation, religious or philosophical beliefs, political opinions, trade union membership or ethnic origin. If you nevertheless enter such data voluntarily, we process it on the basis of your explicit consent under Art. 9(2)(a) GDPR. You can withdraw that consent at any time by deleting the entry concerned or your account.
4. Recipients
We pass data on only to the following processors:
- ALL-INKL.COM – Neue Medien Münnich, owner René Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany: hosting, database and e-mail delivery (SMTP). Server location is Germany. A data processing agreement pursuant to Art. 28 GDPR is in place.
- OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland: operation of the AI coach and of the voice quick capture. Data is transmitted only when you actively use the coach or record a voice note. Details in section 6.
Beyond that we do not pass on any data. No analytics, tracking or advertising services are used, and we do not sell data.
Operator access: as the operator we technically have administrative access to the database. We use it solely for operating the service, troubleshooting and preventing abuse — not to read through your content.
5. Invitations (Third-Party Data)
When you ask someone for feedback, you enter their e-mail address. We handle it as follows:
- We send exactly one e-mail per invitation; the same address cannot be invited more than once from the same account. There are no reminder, follow-up or advertising e-mails.
- In the database we do not store the address in plain text, but only as an HMAC hash and in masked form (e.g. an***@example.com) so that you can tell in your overview whom you invited.
- As with any e-mail, the address is inevitably visible in transit (e.g. in the mail server's outbound queue). That cannot be avoided technically.
- The feedback link is valid for 14 days. Unanswered invitations are deleted automatically no later than 30 days after expiry.
You are responsible for inviting only people you know personally and who may reasonably expect such a message from you. By sending an invitation you confirm this to us.
Information for invited people (Art. 14 GDPR): you received this invitation because someone you know asked you for feedback via "Finde deinen Sinn". The controller responsible for sending it is the operator named above. Processed are your e-mail address (once for sending, afterwards only as a hash value and in masked form) and, if you respond, your feedback. The legal basis for sending is Art. 6(1)(f) GDPR; the legitimate interest lies in the personal feedback request of the inviting person. You can object to this processing at any time — informally by e-mail to hi@finde-deinen-sinn.de or directly via the unsubscribe link in the invitation. In both cases your address is permanently blocked for further invitations (for this we store only the hash value of your address) and the associated invitation record is deleted.
How anonymous is the feedback really? The content of the feedback is only shown once at least 3 responses have been received — this limit is enforced on the server. Strengths and keywords appear as combined counts; free-text answers are only shown once at least three exist, and appear without names in a neutral, content-based order, so they cannot reliably be attributed to an individual person. However, because the inviting person knows which address they invited, they can see in their overview whether and when a particular invitation was answered. Anonymity therefore applies to the content of the feedback, not to the fact that someone took part.
6. AI Coach and Transfer to the USA
The AI coach uses the OpenAI API. Our contractual partner is OpenAI Ireland Ltd. in Dublin. Data is transmitted exclusively when you actively send a message in the coach.
The following is transmitted:
- your current message,
- a short context from your self-assessment and the aggregated feedback summary,
- the last up to 10 messages of the current conversation.
Not transmitted are: your name, your e-mail address and your account ID.
Processing also takes place at OpenAI, L.L.C. in the USA. This constitutes a transfer to a third country (Art. 44 et seq. GDPR). The safeguard used is the EU Standard Contractual Clauses, which form part of the data processing agreement (DPA) with OpenAI.
OpenAI does not use data submitted via the API for training; it is stored for up to 30 days for abuse detection and deleted afterwards.
Quick capture (voice and text): if you use the quick capture, your entry is transmitted to OpenAI in order to derive individual keywords from it. With voice input this is first the short audio recording (max. approx. 25 seconds), which is converted into text there; afterwards — and with text input right from the start — the text itself is transmitted so that it can be assigned to the four Ikigai areas or to your notes. Text entry is therefore not an alternative without transmission; it merely avoids the audio recording. The same safeguards as described above apply (OpenAI Ireland Ltd. and OpenAI, L.L.C. in the USA, EU Standard Contractual Clauses, no use for training, storage for up to 30 days for abuse detection). We do not store the recording — stored are only the keywords you subsequently accept yourself. Using the quick capture is entirely voluntary, and access to your microphone only happens after you have granted it in your browser.
OpenAI privacy policy: openai.com/policies/privacy-policy
7. Cookies
We use technically necessary cookies only:
- Session cookie: after you sign in, a signed httpOnly cookie keeps you logged in (lifetime 30 days).
- CSRF protection cookie: short-lived, set only during the sign-in process.
- Maintenance cookie "fds_dev_bypass": purely technical and httpOnly; it is set only when we, as the operator, actively enter a maintenance password during a maintenance window.
Because we use no cookies that require consent, there is no cookie banner on this website.
The language is controlled via the URL (e.g. /datenschutz for German, /en/datenschutz for English) — no language cookie is set. Fonts are served locally from our own server; no connection to Google is established. There is no analytics, no pixel, no external CDN and no social media plugin.
8. Hosting, Log Files and E-Mail
The application is hosted at ALL-INKL.COM in Germany; your data is therefore stored on servers in Germany.
When our pages are accessed, server log files are generated (IP address, date and time, URL requested, amount of data transferred, referrer, browser and operating system identifier). They serve operational security and the defence against attacks (Art. 6(1)(f) GDPR), are deleted after 7 days and are not combined with your account.
Transactional e-mails (registration confirmation, password reset, invitations, notice of new feedback) are sent via the SMTP server of the same provider, TLS-encrypted. There is no newsletter.
Privacy information of the hosting provider: all-inkl.com/datenschutzinformationen/
9. Retention Periods
- Account and all linked content: until you delete your account. Deleting your account yourself in the settings deletes everything — self-assessment including your own notes, invitations, feedback responses, coach conversations and tips.
- E-mail confirmation links: 24 hours.
- Password reset links: 1 hour.
- Invitations: as described in section 5 (link valid for 14 days, unanswered invitations deleted no later than 30 days after expiry).
- Server log files: 7 days.
- Backups: overwritten on a rolling basis.
10. Your Rights
You have the rights set out in Art. 15 to 21 GDPR: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out until then remains unaffected.
You can exercise much of this yourself: in the settings you can permanently delete your account together with all data and export your data as a JSON file (machine-readable within the meaning of Art. 20 GDPR); in addition you can download your evaluation as a PDF.
For anything else an informal e-mail to hi@finde-deinen-sinn.de is enough. We reply within one month at the latest.
11. Right to Lodge a Complaint
The competent supervisory authority is the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at. Irrespective of this, under Art. 77 GDPR you may also contact the supervisory authority of your place of residence — in Germany the data protection authority of your federal state.
12. No Automated Decision-Making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The AI coach offers suggestions and food for thought — it does not decide anything about you.
13. Minimum Age
Using "Finde deinen Sinn" requires a minimum age of 16. The service is not directed at children, and we do not knowingly process data of people under 16.
14. Data Security
The connection to the website is TLS-encrypted throughout. Passwords are stored exclusively as bcrypt hashes, never in plain text. Session cookies are signed and httpOnly. E-mails are transmitted TLS-encrypted. Only the operator has access to the systems.
15. Changes to This Policy
We adapt this privacy policy when features of the application or the legal situation change. The current version is always available at this URL.