Privacy policy
Last updated: 17.09.2026
1. Controller
Maximilian HolzapfelBornstraĂe 2
06268 Querfurt
Germany
For privacy enquiries: Contact form. Further contact details are available in the legal notice.
The legal notice and privacy policy are accessible without signing in. Like the other application pages, they use a technical session and CSRF security tokens to verify requests and for internal navigation. No visit or location records are created in the process. Technical hosting logs may be generated independently.
2. Data processed and stored
The following overview distinguishes permanent database records, temporary processing and settings in your browser. Automatic recording of visits and IP locations is disabled.
| Function and purpose | Data | Storage and deletion |
|---|---|---|
| User account and permissions | Discord ID and profile name, internal account ID, assigned roles, active status and a session revocation version. Sign-in uses Discord exclusively; the website does not store website passwords. | Database. Accounts are created administratively or on first sign-in with Discord. Roles are managed on the website. Deleting an account also removes its roles and Discord link, including profile details. Retention rule: Until administrative deletion. Automatic deletion of accounts, roles and associated most recent sign-ins is not currently implemented; a binding deletion policy remains to be established. |
| Discord sign-in and account profile | Discord ID, username, optional display name and profile picture identifier, associated website ID, and timestamps of linking and profile updates. | Database until administrative account deletion or a valid deletion request. Profile data is replaced on another Discord sign-in or an explicit profile refresh. Profile pictures are fetched temporarily on the server and are not permanently stored as image files. See the section Discord sign-in and profile. |
| Removed sign-in and location data | The former sign-in, IP history and location tables have been removed from the active database. | No new records are created for these removed functions. An access-restricted backup of the removed tables exists outside the web directory for technical recovery. It is not used for ongoing functions; no automatic deletion period is configured for this cleanup backup. |
| Session and access protection | Session identifier, CSRF security token and, when signed in, username, user ID and roles. An IP address does not grant sign-in or access permissions. | Session data on the server and identifiers in the browser. Signing out clears and ends the application session. Server-wide retention: The Apache/PHP configuration uses file-based sessions, a session cookie without a fixed browser lifetime and a cleanup age threshold of 1,440 seconds (24 minutes). The active cleanup timer runs every 30 minutes. Sessions in use may persist longer; this does not imply an exact maximum retention period of 24 minutes. |
| IP/ACL/pearl calculators and hash tool | Entered values; hashing also uses text, an optional HMAC key or an uploaded file. | Processed on the server for the respective response. The tool code does not permanently store these inputs. Uploads are temporarily held in PHPâs upload directory and are not moved to permanent storage. Technical hosting logs must be considered separately. |
| Tire calculator | Entered tire sizes. | Calculated in the browser. The tool does not send results to the server. |
| Video archive | Video ID and an aggregated view count for each video. After approximately ten counted seconds of playback, the player sends a counting request. The server technically receives the IP address and connection data in this process. | The MariaDB database stores video metadata and the total count, but no viewer IP address, user ID or personal playback history. Video files and thumbnails are hosted on the operatorâs server. Administrative uploads temporarily store file chunks, metadata and the uploading administratorâs account ID; abandoned uploads are removed at the next cleanup after 24 hours of inactivity at the latest. The counter remains until the entry is changed or removed. Videos themselves may contain player names, chat, voices or other visual/audio information. |
| Blocklists | The local security service provides blocked IP addresses. The download outputs MD5 hashes of these addresses. | The operator must specify the security serviceâs storage and retention periods. An MD5 hash of an IP address is not reliably anonymized information. |
| Email contact | Sender address, message, date and any voluntarily supplied information/attachments. | Processed by the email service used to handle your enquiry. Deleted when the purpose no longer applies unless required retention prevents this; the specific operational rule remains to be confirmed. |
Hosting, technical logs and backups
Hosting provider and location: Host-Unlimited.de (Bieber IT GmbH), Braunschweiger StraĂe 22, 38518 Gifhorn, Germany. Server location according to the operator: Germany.
When you access the website, your IP address, requested URL, time, and transmitted browser and connection information are processed technically. Which of these are actually logged by the web server, an upstream proxy or a security service depends on their configuration.
Scope of logs and deletion periods: Apache access logs contain the IP address, any HTTP login name, date/time, requested URL, HTTP status, amount of data transferred, referrer, browser identifier and virtual host accessed. Error logs record technical errors and may contain additional request information. Daily rotation and 14 archive files in addition to the active file are configured. With daily rotation this corresponds to roughly 14 days plus the active file; empty files are not rotated. This is therefore not a fixed maximum retention period. The rotation timer is active. This does not comprehensively cover additional provider/security logs.
Backups and retention: Only the website source code is backed up. Database contents, usage data and log data are not backed up.
According to the operator, no external analytics or tracking tools are configured. The aggregate video counter is a separate feature without permanently stored viewer identifiers.
Administrators have access to account, sign-in and log data within their permissions. Removing browser cookies alone does not delete these records.
3. Cookies and browser storage
site_language stores your explicitly chosen language (German or English) for up to six months. The cookie is used only for presentation, not tracking. You can change the language at any time or delete the cookie in your browser settings.
- PHP session cookie (according to the Apache/PHP configuration, named
LaLaLavaChicken): identifies the application session. The cookie uses HttpOnly, Secure on HTTPS and SameSite=Lax so that Discordâs return redirect can be matched to your session. Its name and lifetime depend on the server configuration. - CSRF protection: a random token is stored in your server session and sent in forms or request headers for write requests. It is no longer appended to navigation links. A previously set separate
csrf_tokencookie is removed. bsThemein local storage: stores your chosen light or dark appearance until changed or the site data is deleted. This value is not used as an analytics identifier.- Eaglercraft: the former local game client is disabled. Existing saved games, particularly in the world store
worlds, may remain in your browser database until you delete them through your browser settings. The external game link does not create a new saved game here.
Session protection and explicitly requested settings may fall under the necessity exemption in section 25(2) TDDDG. Non-essential access to your device generally requires prior consent. The optional map is activated only after you explicitly click âConsent and load mapâ. You can disable it again on the same page. That choice is not stored permanently and must be made again on the next page visit. External games are provided solely as links.
4. External services and recipients
- Hosting: Host-Unlimited.de, operated by Bieber IT GmbH, provides the server infrastructure. Hosting providerâs privacy information. Information on the providerâs own website does not replace the log retention periods specifically agreed for this hosting arrangement.
- OpenStreetMap: Only after you consent does the map tool load tiles directly from servers of the OpenStreetMap Foundation. These receive your IP address and browser request data in particular. The Foundation is based in the United Kingdom; map requests may be served through a worldwide network of cache servers. The page provides a button to disable the map at any time. OpenStreetMap Foundation privacy policy.
- Local styling and fonts: Bootstrap, Leaflet, platform detection and the video archiveâs icon fonts are served from the websiteâs own server. Your browser does not connect to jsDelivr or other external CDNs for these resources.
- External games: HTMLGames and Eaglercraft are no longer embedded. You leave this website and access a game provider only when you click a link marked as external. The providerâs processing of connection data, advertising, cookies and saved games is subject to its own information and choices.
- Clash of Clans / Supercell: The website server retrieves configured player profiles using player identifiers and a server-side API key. The relevant model does not pass the browser IP address as a parameter. Publicly displayed information includes player name, tag, level, trophies and clan details.
- Email via Gmail: Messages to the contact address are processed through Googleâs email service. Contractual arrangements, storage location and any transfers to third countries must be confirmed by the operator.
- Discord: Optional sign-in and display of your own Discord profile are described in the following section. Discord itself is subject to the Discord privacy policy.
- External links: Social media links and other ordinary links open the respective service when clicked. Its privacy information also applies from that point onwards.
For recipients outside the European Economic Area, appropriate conditions for the transfer must be assessed. This version does not assert any unverified adequacy decisions, standard contractual clauses or data processing agreements.
5. Discord sign-in and profile pictures
Your choice: The website redirects you to Discord only when you start Discord sign-in, account linking or a profile refresh. There you confirm access to your basic profile data. The website does not retrieve Discord profile data for visitors who do not use these features.
Data and purpose: Your Discord ID uniquely links you to your website account. Your username, optional display name and profile picture identifier help you recognize your linked account in your personal account overview and navigation. We also store the internal account ID and linking/update timestamps. Normal OAuth sign-in does not request your email address, messages, contacts or server lists. The profile overview is not a public member directory.
If you enable âExtended Discord infoâ and authorize the additional Discord access, we store your server list with names, IDs, icon hashes, ownership, your permissions and available approximate member counts. Opening a server also retrieves and stores your nickname, role IDs, join date, boost start where available and membership status. This overview is available only to your signed-in account and does not change website permissions. Turning the option off deletes the additional stored data, as does account deletion. The overview displays its snapshot date.
For optional membership lookups, an access token remains only in the server-side website session and is used by the application for at most one hour. It is neither returned to the browser nor stored in the account database; refresh tokens are not stored. Logging out or disabling the option in that session requests revocation. After expiry, a new login or a session change, Discord authorization may be needed again. Normal profile requests still discard tokens immediately. Server icons are loaded through our server like profile pictures.
Profile pictures: Your browser loads the profile picture through this website. Our server fetches the image for your stored Discord ID and image identifier from cdn.discordapp.com . The image service receives our serverâs IP address and the requested image URL; our application does not forward your browser IP, website cookies or OAuth tokens to the image service. The website does not permanently store the image file and serves it with a no-cache instruction. Animated Discord profile pictures are displayed as GIFs with their animation. If no image is available, a local fallback is shown.
Shared permission management: The website and Omnibot check permissions using account and Discord IDs, assigned roles and, where relevant, server and channel IDs. When a check requires Discord roles, our bots query Discord for the userâs membership and roles on the assigned server. These requests use bot credentials, not your OAuth token. The retrieved member roles are used for the current request and are not stored as an additional permanent website member directory. Discord receives the requested server and user IDs and our serverâs connection data. Community features additionally store optional gamer profiles, event sign-ups, teams, player searches, help posts, knowledge and snippets under your Discord ID and server ID. Profile publication and direct messages are optional. Calendar links grant access to your confirmed events and can be rotated; only a token hash is stored. Server backups contain roles, channels and permissions, optionally member-role assignments; up to 30 backups are retained per server. Transfer jobs and role synchronization log affected IDs and progress. Expired player searches and snippets are cleaned up; other community posts have no general automatic deletion period.
Permissions and change log: Role rules, recipient IDs and optional expiry times are stored in the database. Changes to roles, assignments and managed accounts are logged with the acting account ID, time, action and affected details; passwords and access tokens do not belong in this log. This supports access control and tracing unauthorized changes. Expired assignments no longer take effect but are not automatically deleted. Direct assignments to the website account and its Discord ID are removed when that account is deleted. Change logs are not automatically removed and must be reviewed separately for a valid deletion request. No automatic deletion period is currently configured for these records.
Sign-in and security: The single-use sign-in code and resulting access tokens are processed on the server during sign-in. Tokens are not stored permanently; after retrieving the basic profile, the website requests their revocation from Discord and discards them even if an error occurs. A random, single-use session value protects the return redirect and is valid for no more than ten minutes. Discord sign-in creates a normal website session; no additional sign-in history entry is created. Callback URLs containing the code and security value may appear in technical web server logs; the logging rules above apply.
Legal bases: The sign-in and account linking you request are based on Article 6(1)(b) GDPR insofar as processing is necessary to provide your access. Displaying basic profile details serves our legitimate interest in clearly identifying and recognizing the linked account under Article 6(1)(f) GDPR. We also rely on Article 6(1)(f) GDPR for measures against unauthorized access. You may object to processing based on legitimate interests under the statutory conditions.
Recipients: When redirected to Discord, your browser connects directly to Discord. Discord independently processes connection data and your sign-in there, among other things. For users in the European Economic Area, Discord identifies Discord Netherlands B.V. as controller in its privacy policy. Discord also describes international data processing and the safeguards it uses there. Details are available in the Discord privacy policy. This website does not thereby claim to have its own data processing agreement with Discord.
Updates and deletion: We retrieve new profile data on your next Discord sign-in or through âRefresh profileâ. The account link and profile details remain stored until administrative account deletion; no automatic deletion period is configured. For correction, deletion or enquiries about the link, contact Contact form . Deleting the website account also removes the Discord link and stored profile details. You can additionally revoke authorization in Discord under âAuthorized Appsâ. This does not automatically delete the website account or end an active website session; use âSign outâ for that.
The Discord sign-in terms of use describe access to the website. Accepting them does not replace any separately required data protection consent.
6. Legal bases and your rights
Necessary provision, protection and administration of the website may be based on legitimate interests under Article 6(1)(f) GDPR. These interests are reliable operation and protection against abuse. A balancing of interests is required. Optional, non-essential features may require consent under Article 6(1)(a) GDPR.
The optional map is loaded on the basis of your consent under Article 6(1)(a) GDPR. Accounts and permissions provide access to protected features; your contact enquiry is processed for communication and a response. Where Article 6(1)(f) GDPR is relied on, these are the legitimate interests pursued.
You are not obliged to use an account, send a message or activate the external map. Without the data required for those functions, sign-in, answering an enquiry or displaying the map is not possible; other publicly available pages remain usable.
Subject to the applicable statutory conditions, you can request access, rectification, erasure, restriction of processing and data portability. You can withdraw consent with future effect. You may object to processing based on legitimate interests for reasons relating to your particular situation.
You may lodge a complaint with a data protection supervisory authority, particularly in the place of your habitual residence, workplace or the suspected infringement. Authority responsible for the operator: State Commissioner for Data Protection of Saxony-Anhalt; datenschutz.sachsen-anhalt.de. Contact and complaint options.
Use the contact address above. Do not send passwords; necessary follow-up questions may be asked to securely identify a request. The application is not intended to make automated decisions with legal or similarly significant effects.