Legal
Privacy Policy
What we store, why we store it, where it lives, and how you get rid of it.
Last updated September 30, 2026
Who is responsible
The controller under the GDPR is LL Platforms UG (haftungsbeschränkt), Wuhlestraße 7a, 12683 Berlin, Germany. You can reach us at support@cotscreener.com. We have not appointed a data protection officer. We are not required to.
The short version
- We show no ads and we never sell data.
- No analytics tools and no tracking cookies. Only essential session cookies.
- Account data is stored in the EU, in Frankfurt, Germany.
- We email you about your account, and otherwise only what you asked for or agreed to.
- You can delete your account and its data yourself, at any time. Only records the law makes us keep, such as billing records, outlast it.
Visiting the site
Our infrastructure runs on Cloudflare. When you open a page, the server processes technical data: your IP address, browser type, the requested page and a timestamp. We use it to deliver the site and to keep it secure, for example against attacks. The legal basis is our legitimate interest in a working, safe service (Art. 6 (1) (f) GDPR). We keep no request logs of our own: Cloudflare processes this data transiently to deliver and protect the site, and what we can see are aggregate statistics, not stored records of your visit. Our own operational logs record events, not visits; where they mention an email address it is masked, and they never contain your IP address in the clear.
Cloudflare also tells us which country a request comes from, derived from the IP address. We use it for one thing: to show prices in euros inside the EU and in US dollars everywhere else. It is used only to build the page you are loading and is never stored. The legal basis is our legitimate interest in showing you the price that applies to you (Art. 6 (1) (f) GDPR).
Cloudflare is operated by Cloudflare, Inc., USA. Transfers to the USA rest on the EU-US Data Privacy Framework and on standard contractual clauses.
Your account
When you create an account we store your email address and your password. The password is stored only as a hash. We never see the plain text. If you use the app, we also store what you set up there: your display name if you add one, your watchlist, your alerts and your settings. We need this data to provide the service, so the legal basis is the contract with you (Art. 6 (1) (b) GDPR).
The database runs on Supabase. Our project is hosted on AWS in Frankfurt, Germany (eu-central-1). Supabase, Inc. is a US company. We have a data processing agreement with standard contractual clauses in place.
Your data stays until you delete your account under Settings. Deleting the account removes your profile, watchlist, alerts and settings immediately, and cancels a running Pro subscription so nothing is charged again. What deletion does not remove are the records the law requires us to keep — billing records and contract declarations, see “How long we keep things” below (Art. 17 (3) (b) GDPR).
Signing in with Google
You can sign in with a Google account instead of a password. This is optional. If you use it, we receive your email address, the name on your Google account and a stable account identifier from Google Ireland Limited; the name becomes your display name here, and you can change it in Settings. The legal basis is the contract (Art. 6 (1) (b) GDPR). Google processes its own data under the Google privacy policy.
Emails we send
We send account emails, for example to confirm your address or to reset your password, and emails about your subscription, for example when a free trial starts or before a yearly term ends. If you set up alerts, we send the alert emails you asked for. The legal basis is the contract (Art. 6 (1) (b) GDPR). We send these emails through Resend, Inc., USA, under standard contractual clauses.
The Friday brief
The Friday brief is our weekly newsletter, and anyone can subscribe without an account. It runs on consent (Art. 6 (1) (a) GDPR), collected through double opt-in: entering your address only creates a pending entry, and you receive nothing until you click the link in the confirmation email.
For a subscription we store your email address, whether it is pending, confirmed or unsubscribed, and the times of those steps. Two separate random tokens identify your links: a short-lived one that only confirms the subscription and expires after 24 hours, and one that only powers the unsubscribe link in each email. We need the confirmation timestamp to prove that consent was given, which the GDPR requires of us (Art. 7 (1)).
Every email carries a one-click unsubscribe link. When you use it we stop sending immediately and mark the entry as unsubscribed rather than deleting it, so the address cannot be added again by accident and so we can still show when the consent existed and when it ended. If you would rather have the entry erased entirely, write to us and we will do that.
If you have an account, the brief runs on your account instead of on a separate subscription. You turn it on with the checkbox when you sign up, with the offer on the Markets page, or later under Settings. You turn it off under Settings or with the unsubscribe link in every brief.
Emails about the product
If you agree to it, we send occasional emails about the product itself: new features, tips for getting started, and offers on the Pro plan. These run on consent (Art. 6 (1) (a) GDPR), you choose them yourself, and every one of them has an unsubscribe link. Saying no changes nothing about your account, and we do not send them to anyone who has not agreed.
We store when you agreed to the brief and to these emails, whether that was at sign-up, in Settings or through the offer on the Markets page, and when you last turned them off again. We keep that record because the law asks us to prove consent was given (Art. 7 (1) GDPR). It disappears with your account.
Upgrading to Pro
Paid subscriptions are processed by Paddle as merchant of record. The checkout is run by the Paddle entity named there and on your invoice. Paddle is your contract partner for the purchase and processes your billing and payment data under its own responsibility. We never see your full payment details. When you open the checkout, Paddle’s own software runs in your browser and may set its own cookies for the purchase; that happens under Paddle’s responsibility and is described in the Paddle privacy policy.
What we receive from Paddle are messages about your subscription: its identifier, its status, the price, the billing-period dates and a customer identifier. We store these messages as our billing ledger — they are what your Pro access, our bookkeeping and any later dispute rest on. The legal bases are the contract (Art. 6 (1) (b) GDPR) and our legal obligations to keep commercial records (Art. 6 (1) (c) GDPR); the retention is listed below.
We also use these records to decide which checkout to offer you, for example whether a free trial applies. When you switch to yearly billing, or when a yearly term continues month to month, we send that change to Paddle for your subscription. The legal basis is the contract (Art. 6 (1) (b) GDPR).
Anonymous counts
We count, per day, how often a few steps happen in the app: a Pro page shown to a free account, the plans page opened, the checkout opened. We store only the day, the step and the total. Nothing about who took the step: no account, no IP address, no cookie. The totals show us where the app fails to convince, and they cannot be traced back to anyone.
Cancelling or withdrawing from a contract
If you cancel through the cancel contract page, we store your name, your email address, the cancellation type, an optional reason, an optional end date, an optional contract reference and the time of receipt. If you declare a withdrawal through the withdraw contract page, we store the same kind of record: name, email address, an optional contract reference, the purchase date you state, an optional reason and the time of the declaration. German law requires these pages and their confirmations (§ 312k, § 356a BGB), so the legal bases are our legal obligation (Art. 6 (1) (c) GDPR) and our interest in documenting the declaration (Art. 6 (1) (f) GDPR).
To carry a declaration out, we also record which subscription it matched, what happened to it, and whether the confirmation email was sent. The confirmation email goes to the account address and contains a single-use link to reverse the ending — the protection that lets these forms work without a login: only the mailbox owner can use it. The link expires with the billing period and its token is deleted when used. These records are kept for the statutory limitation period and then deleted automatically.
Writing to support
If you email us, or use the contact form on the support page, we process your name (if you give one), your address, the subject and the content of your message to answer it. Form submissions are stored in our database and forwarded to our support inbox through Resend, the same processor that carries our other email; you also receive a short acknowledgement. The legal basis is the contract or our legitimate interest in handling requests (Art. 6 (1) (b) and (f) GDPR).
Protecting the public forms
The cancellation, withdrawal, support and newsletter forms work without an account, which also makes them a target for scripts. To keep them from being abused as a mail cannon, we record when an email was last sent to an address for a given purpose, and we count how often each connection uses these forms per hour. For that count your IP address is never stored as such: it is turned into a keyed pseudonym (an HMAC) that we cannot reverse, and the entries are deleted automatically after seven days. The legal basis is our legitimate interest in a service that cannot be turned against strangers’ inboxes (Art. 6 (1) (f) GDPR).
Cookies and local storage
We set two kinds of cookies, and both exist only because you asked for what they do. The sign-in cookies keep your session alive between visits; they are stored for up to 400 days, are renewed while you use the app, and are removed when you sign out. If you choose a light or dark appearance in the app, that choice is kept in a cookie for one year; if you never touch the setting, the app follows your system and the cookie holds that default. Cookies like these are strictly necessary for a service you explicitly requested (§ 25 (2) TDDDG), so no consent banner is needed — which is why you never see one here. During a password reset, one further cookie marks that your reset link was verified, so only that browser can set the new password; it is limited to the reset page and expires after fifteen minutes. Interface preferences, for example collapsed chart panels, stay in your browser’s local storage and are never sent to us. We use no analytics and no third-party trackers.
International transfers
We prefer EU infrastructure. Where a provider is a US company (Cloudflare, Supabase, Resend, Google), transfers rest on the EU-US Data Privacy Framework and on standard contractual clauses, as described above.
How long we keep things
- Your account and what you set up in it stays until you delete it. Deleting the account removes it immediately from the live database; residual copies in our database provider’s encrypted backups rotate out automatically within a few weeks and are used only for disaster recovery, never to bring deleted data back.
- Billing records — the subscription messages Paddle sends us — fall under statutory commercial and tax retention (§ 257 HGB, § 147 AO: up to ten years). They are kept for those periods even after an account deletion, only for those purposes, then deleted.
- Newsletter entries stay while you are subscribed, and after an unsubscribe we keep the entry as the record of when the consent existed. Ask us and we erase it.
- Cancellation and withdrawal records document a legal declaration, so we keep them for the statutory limitation period of three years from the end of the year of the declaration (§ 195 BGB). They are then deleted automatically.
- Form-protection entries (send cooldowns and the pseudonymised hourly counters) are deleted automatically after seven days. The one-time records that a Pro welcome email or the notice before a yearly term ends went out hold only the subscription identifier and a time. They stop a second copy from being sent and are kept with the billing records.
- Server logs — we store none of our own; see “Visiting the site” above.
- Support messages are deleted automatically two years after the request, unless a legal duty requires keeping a specific exchange longer.
Where German commercial or tax law requires longer retention, that applies instead, and the data is then only kept, not used.
Your rights
- Access to the data we hold about you (Art. 15 GDPR).
- Correction of wrong data (Art. 16 GDPR).
- Deletion (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on legitimate interest (Art. 21 GDPR).
- Objection to direct marketing at any time, with no reason needed and no consequences (Art. 21 (2) GDPR). We then stop immediately.
- Withdrawal of any consent, effective for the future (Art. 7 GDPR).
Email support@cotscreener.com to exercise any of these rights. You can also complain to a data protection authority (Art. 77 GDPR). Our registered office is in Hamburg, so our authority is the Hamburg Commissioner for Data Protection and Freedom of Information. Your local authority works too.
What we do not do
No automated decision-making, no profiling, no sale of personal data, no ads.
Security
All traffic is encrypted with TLS. Passwords are stored as hashes. Access to production data is limited to what running the service requires.
Changes
We update this policy when the service changes. The date at the top tells you the current version. If a change matters for you, we point it out in the app or by email.