Privacy policy
This policy explains, as required by Art. 13 GDPR, which personal data is processed when you use InfinityKB (infinitykb.cloud). InfinityKB is a privately operated service for a closed group of users; there is no self-registration, no advertising and no tracking. This is a translation — the German version is legally binding.
1. Controller
Michael Schich, Heimerdinger Str. 56, 71229 Leonberg, Germany, e-mail: infinitykb@gmx.de
2. Hosting
The application runs on a virtual server of Hostinger International Ltd. (61 Lordou Vironos Str., 6023 Larnaca, Cyprus) in a data centre in Germany. Hostinger processes, as a processor, the technical data that arises from operating a server. The basis is the data processing agreement under Art. 28 GDPR that forms part of Hostinger's terms. Legal basis: legitimate interest in secure and reliable operation (Art. 6(1)(f) GDPR).
3. Accounts, sign-in and sessions
Accounts are created by the administrator only. Stored are the user name, the password as a cryptographic hash (scrypt — the password itself is never stored) and the chosen language. Signing in sets a session cookie (technically necessary, lifetime 180 days, no tracking). The browser also keeps local settings (e.g. language, dismissed hints) in localStorage; this data does not leave the device. Legal basis: performance of the user relationship (Art. 6(1)(b) GDPR) and Section 25(2) no. 2 TDDDG for the strictly necessary cookie. A consent banner is therefore not required.
4. Access and sign-in log
For the security of the system, sign-ins, accesses and failed sign-in attempts (including the user names used) are logged with a timestamp and shown to the administrator. Legal basis: legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
5. Content and history
Boards, notes, links, files, voice memos and tasks are stored on the server. Changes to tasks and updates of dynamic AgentWidgets are kept with user name and time, so that it stays traceable who changed what. Shared boards are visible to the users they are shared with. Legal basis: performance of the user relationship (Art. 6(1)(b) GDPR).
6. AI features (OpenAI)
Some features that you trigger actively use the OpenAI API: transcription of voice memos, summaries of links and YouTube transcripts, image descriptions, diagram and text suggestions. The respective content (audio, text, images) is sent to OpenAI (OpenAI Ireland Ltd. or OpenAI L.L.C., USA). Transfers to the USA rely on the EU-US Data Privacy Framework or EU standard contractual clauses; under OpenAI's API terms, API data is not used to train the models. If you do not use these features, nothing is sent to OpenAI. Legal basis: performance of the user relationship (Art. 6(1)(b) GDPR).
7. Maps (OpenStreetMap)
Map cards load their map tiles directly in the browser from openstreetmap.org (OpenStreetMap Foundation, United Kingdom — the EU Commission has issued an adequacy decision for the UK). The OpenStreetMap Foundation receives the browser's IP address. Address search and reading real-estate pages run on the server instead (Nominatim, hitta.se) — only the server's IP address is sent, not the users'. Legal basis: legitimate interest in displaying the maps users created (Art. 6(1)(f) GDPR); maps only appear on boards where a user created them.
8. AI agents (MCP, e.g. Claude or Codex)
Boards can be released to AI agents explicitly and per board — either through a key created by the board owner or through a personal consent on an approval page (OAuth). Only after such a release can the connected service (e.g. Anthropic PBC, USA — EU-US Data Privacy Framework) read the content of the released boards and, depending on the role, change it. Every release can be revoked at any time (in the board's share dialog and in the admin area); changes made by agents are logged with a 🤖 marker. Legal basis: consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time with effect for the future.
Codex (OpenAI) as an additional recipient. If a board is released to an agent with the runtime Codex (or an agent hands part of its work to Codex), OpenAI is an additional recipient (OpenAI Ireland Ltd. or OpenAI L.L.C., USA — EU-US Data Privacy Framework or EU standard contractual clauses). Within such an agent run, Codex sends the board content it reads (tickets, comments, widgets and cards of the released boards) as well as the code and files of the working directory the agent works with to OpenAI; the release, its revocation and the 🤖 logging apply as above. Without a Codex connection or a Codex sub-run, nothing is sent to OpenAI this way. Legal basis: consent (Art. 6(1)(a) GDPR), which can be withdrawn at any time with effect for the future.
9. Backups and retention
Backups of the data are made regularly on the server. Content exists until users delete it; the administrator deletes accounts on request, and the boards of a deleted account pass to the administrator. Log data is kept only as long as needed for security and traceability.
10. Your rights
You have the right towards the controller to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You can withdraw a consent at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority, e.g. the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
11. No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
As of October 2026 · See also: Legal notice (Impressum)