Skip to content

Privacy policy

Privacy.

What we store, why we store it, how long we keep it, and what you can ask of us.

Last updated 8 October 2026 · Deutsch

Draft. The operator details marked below are added, and this text is reviewed, before CON takes its first payment.

The short version

  • No tracking cookies, no advertising, no selling or renting of data.
  • The demos on this site run in your browser and send nothing anywhere.
  • We store what you send us (an application, a signup, a cancellation) and what your membership needs to work.
  • A person reads every application, and only a person can decline one. While a wave runs we may accept applications automatically by simple rules; that only ever says yes.

1. Who is responsible

The controller under the GDPR is:

Controller
Jan Schmitt, Volbehrstr. 27, 90491 Nürnberg, Germany

We have not appointed a data protection officer, because the law does not require one for us.

2. Visiting this website

The website is hosted by Vercel Inc., USA. When you open a page, your browser sends technical data that every website receives: IP address, date and time, the page, the referring page, browser and operating system. Vercel processes this to deliver the page and to protect the service from attacks, and keeps the logs only for a short time.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is a working, secure website.

3. Counting visits

We use Vercel Web Analytics to see which pages are read and where people stop. It sets no cookies, stores nothing on your device and does not follow you to other websites. Besides page views we count named events, such as which button was pressed or which step of the application form was reached. These events never contain names, email addresses or text you typed.

Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is a website that works better for its visitors.

4. What we keep on your device

  • Your unfinished application. The form keeps your answers in your browser's local storage, so a closed tab costs nothing. It stays on your device and is deleted when you send the application.
  • Your login. When you log in, cookies keep you signed in. Without them the HQ cannot work.

Both are needed for a service you asked for, so no consent is required (§ 25 (2) no. 2 TDDDG). We set no other cookies.

5. Applications

When you apply, we store your answers (track, stage, the text about you), your Discord username, your email address and the time. We use them to decide on your membership and to answer you. Only CON staff can read them.

A person decides on every application that is not accepted automatically, and a decline is always decided by a person. While a wave runs, we may accept applications by simple rules, for example for as long as founding seats are left. Such an automatic decision only ever grants a seat; it never turns an application down.

Staff review applications in a private, staff-only channel of the CON Discord server. Our bot posts your answers, your Discord username and the decision there, never your email address. To show staff whether you are already on the server, the bot looks up the username you gave among the server's members; if you are, and once you are accepted, it may send you your personal link as a Discord direct message as well as by email. The channel post is deleted before the application is.

If you get a founding seat, we record its number and, when you claim it, link it to your Discord account as your membership.

To slow down automated floods we also store a keyed hash of your IP address. It cannot be turned back into the address and is deleted with the application.

Legal basis: Art. 6 (1) (b) GDPR (steps before a contract, at your request) and, for the hash, Art. 6 (1) (f) GDPR. An application that does not lead to a membership is deleted 12 months after the decision, so we can recognise a new application in a later wave.

6. Your account and login

You log in with Discord or with a link sent to your email address. With Discord, Discord Inc., USA, tells us your Discord ID, username, avatar and email address. We store them in your profile together with your plan.

Our database and login run on Supabase (Supabase Inc., USA), on servers in Western Europe (AWS region eu-west).

Legal basis: Art. 6 (1) (b) GDPR. We keep your profile for as long as you have an account, and delete it when you ask us to, unless the law requires us to keep parts of it.

7. Membership and payment

Payments are processed by Stripe Payments Europe, Ltd., Ireland. You enter your payment details with Stripe, not with us; we never see your full card or account number. Stripe tells us whether a payment went through, and creates your invoices.

Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for invoices. The law requires us to keep invoices and booking records for up to 10 years (§ 147 AO, § 257 HGB).

8. Emails we send you

We send emails about your application, your login and your membership through Resend, an email service in the USA. For each email we record the type, the recipient, the time and whether it was delivered. We do not track whether you open our emails or click their links.

If an address bounces or marks our email as spam, we put it on a block list, so we stop writing to it. Legal basis: Art. 6 (1) (b) GDPR for emails about your application and membership, Art. 6 (1) (f) GDPR for the send records and the block list. Send records are deleted after 12 months.

9. The newsletter

The newsletter is sent only after you confirm your address through the link in our first email (double opt-in). We store your email address, the wording you agreed to, which form you used, and when you signed up and confirmed. That record is our proof of your consent.

You can unsubscribe at any time with the link in every newsletter. Legal basis: Art. 6 (1) (a) GDPR. After you unsubscribe we keep the consent record for 3 years, to be able to prove it, and send you nothing more.

10. Cancellations and withdrawals

When you cancel or withdraw, we store what you declared, your name, email address, optional Discord username, and the time it arrived, and send you a confirmation. Like applications, these requests carry a keyed hash of your IP address against floods.

Legal basis: Art. 6 (1) (c) GDPR (§ 312k and § 356a BGB) and Art. 6 (1) (b) GDPR. We keep the record for 3 years after the end of the year it arrived in, the period in which claims from the contract can be raised.

11. Who else gets your data

Only the services named above, each bound by a data processing agreement (Art. 28 GDPR): Vercel (hosting), Supabase (database and login), Resend (email) and Stripe (payment). Discord receives what you post in the CON Discord server, under Discord's own terms, and the staff review posts described in section 5. Discord Inc. is based in the USA.

Vercel, Supabase, Resend and Discord are based in the USA. Transfers rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU standard contractual clauses (Art. 46 (2) (c) GDPR).

12. Your rights

You can ask us at any time, free of charge, to:

  • tell you what we store about you (Art. 15 GDPR)
  • correct it (Art. 16)
  • delete it (Art. 17)
  • restrict its use (Art. 18)
  • give it to you in a common format (Art. 20)
  • stop using it where we rely on our legitimate interest (Art. 21)
  • withdraw a consent, for the future (Art. 7 (3))

Write to team@centralonet.com. You can also complain to a data protection authority, for example the one in the German state or EU country where you live (Art. 77 GDPR).

13. Changes

When CON starts storing something new, this page changes first. The date at the top shows the latest version. Questions about this page: contact us.