Privacy policy
Last updated: Sep 25, 2026
1. Who we are
Michael Sann (Podshalocef), operating invowerk (“we”), is the data controller for the personal data described here. Contact us at contact@invowerk.dev. The operator’s full name and address are in the legal notice.
2. Data we collect
- Account: your email address, your sign-in sessions (IP address and browser identifier), and authentication data. Sign-in runs on an authentication service on the same servers, not an external provider.
- API keys: key name, prefix, creation date, and expiry date. The secret is stored only as a hash.
- Content you submit: the files, documents, and text you send. They are used only to produce your response. They are processed in memory and never stored. They are never sold or used to train models.
- Usage and billing: request counts, credit usage, plan, and subscription status.
- Technical: IP address and request metadata, used for security and rate limiting.
3. Lawful basis (GDPR Art. 6)
- Contract: providing your account, the API/MCP service, and billing.
- Legitimate interest: security, abuse prevention, and rate limiting.
4. Retention
Account data is kept while your account is active and deleted on request. Billing records may be retained as required by law (in Germany currently 8–10 years for accounting records).
Content you submit and its results are processed in memory for a single request. They are never stored, so nothing reaches the backups. There is nothing to delete.
Server logs with IP addresses and request paths are deleted after 90 days at the latest. The web server's access log is kept for 7 days. Request metrics and traces, which contain no file or HTML content, are deleted after 30 days.
Encrypted backups are kept on a rolling schedule for up to ~13 months, for disaster recovery. Deleted data leaves live systems at once and ages out of backups within that window. After any restore from a backup, accounts that were already erased are deleted again.
5. Subprocessors
- Hetzner (Germany): servers and backups
- Polar: payments and subscription billing, as merchant of record
- Scaleway (EU): transactional email
- Bunny.net: content delivery network (CDN), EU routing
6. Cookies and browser storage
This site sets one cookie: your login session cookie. It is set only when you sign in, and it keeps you signed in. It expires after 7 days without use, or when you sign out. The cookie is strictly necessary, so the site shows no consent banner. If you do not sign in, the site sets no cookies.
The site sets no analytics, advertising, or cross-site tracking cookies. It loads no third-party analytics script. Page views are counted as daily totals per page, without cookies or IP addresses.
If you use the theme switch, your browser saves your choice in its local storage. The choice stays on your device and is not sent to the server. The API reference at /docs saves its display settings, such as the code sample language, the same way.
A tool page may keep its last result in your browser's session storage for the next page. It is deleted when read or when you close the tab.
7. Your rights
You can access, rectify, erase, export, and object to the processing of your data. From your account page you can export your data or delete your account, or email us.
8. International transfers
Our infrastructure is EU-based. Where a subprocessor transfers data outside the EU, it is covered by Standard Contractual Clauses or an adequacy decision.
9. AI features
invowerk offers an MCP server for AI agents. Requests through it are processed only to provide the service. Request content is never used to train models.
10. Changes and complaints
This policy may change. Material changes will be announced. You can file a complaint with your local data protection authority.