Legal information
The legal notice and privacy policy for CIND3R3LLA. The German version is the legally binding one.
This is a convenience translation. The legally binding version is the German one: Deutsch.
Privacy policy
Controller
Sascha Dämgen IT and More Systems
Inhaber: Sascha Dämgen
Am Neumarkt 22
45663 Recklinghausen
Germany
Email: info@it-and-more.systems
For CIND3R3LLA: cind3rella@cind3r3lla.com
No data protection officer has been appointed. We are not required to appoint one, and we state this rather than leaving the question open.
The archive, and what it publishes
CIND3R3LLA archives messages from a public group chat and republishes them as a public web archive. The following are processed: message text, images, video, voice messages, files, links, the sender’s display name, and the time a message was sent.
The legal basis is your consent, Art. 6(1)(a) GDPR. Consent is given individually by each member through an explicit opt-in, and it is always first-person: nobody can opt in on your behalf, and a request to publish somebody else is refused.
Publication is FORWARD-ONLY. Nothing you sent before you opted in is ever published, and opting in again later does not reach back.
Published content is on the OPEN WEB. It is publicly accessible, it is searchable, and it is indexed by search engines. This is the most consequential fact on this page, and it is the reason consent is asked for explicitly rather than assumed.
Withdrawing consent
You may withdraw your consent at any time, without giving reasons. Withdrawal takes effect immediately across every public surface: pages, media, feeds, the sitemap, structured data and search on our site.
Publication is derived from your current consent on every read rather than stored as a flag, which is why withdrawal is immediate rather than a job that has to run.
After withdrawing you choose what happens to the content already published. HIDE keeps it, out of public view, and you can bring it back yourself at any time. DELETE destroys it, and that cannot be undone. Until you choose, the content stays hidden.
Content you sent while hidden is not republished if you later restore: restoring returns what was public before, not what you said while out of view.
Retention
Archived content is processed on the basis of the member’s consent and is retained while that consent and the purpose persist. Consent can be withdrawn at any time, and withdrawal takes effect immediately. Independently of this, published content is retained for a maximum of ten years. The operator may set a shorter period.
This retention limit is currently applied manually. Automated expiry is planned.
Media, and what we remove from it
Before an image is published, its metadata is stripped: EXIF, IPTC and XMP. This removes location coordinates, camera make, model and serial number, capture time, and any embedded owner or copyright name. Photographs from phones routinely carry the coordinates of where they were taken, and consenting to publish a picture is not consenting to publish your address.
The published copy is a stripped derivative. The original is retained separately and is ENCRYPTED AT REST. Formats for which no stripper is available on this instance are recorded as such rather than assumed clean.
Automated screening for known abuse material
Received images are intended to be compared against hash databases of KNOWN child sexual abuse material. This runs independently of consent, because safety and publication are separate questions: a file that is never published is still a file we received.
CURRENT STATUS: in development. No detection provider is connected, and no such screening runs today. We state this plainly rather than implying a protection that is not yet active.
When it is active, no human and no general-purpose model examines your content. Only cryptographic fingerprints are compared. Hash matching detects known material only; it cannot detect new material, and a non-match is not a statement that anything is safe.
Deferred deletion, and why hiding is never deferred
Content reported to us as illegal is held back from destruction until we have reviewed the report. This prevents evidence being destroyed before it can be examined.
HIDING IS NEVER DEFERRED. If you withdraw consent, your content leaves public view immediately, whether or not it is under review. Only physical erasure waits, and it runs automatically once the review concludes or the hold expires.
Preservation for legal obligations
Where material must be preserved for a legal obligation, it is segregated from ordinary storage, kept encrypted, withheld from every public path, and is not deletable by any route in the system, including by us.
The reporting process, retention periods for preserved material and the designated point of contact are still being settled with legal counsel. This section will be extended once they are.
The limits of erasure, stated honestly
Deleting removes content from the live archive immediately, including the stored original, every derivative, and our own record of the message.
Where backups exist, copies persist in them until those backups expire. Content already retrieved by third parties, including search engine caches, feed readers and anyone who copied it while it was public, is outside our control and cannot be recalled by us.
We do not use the word "unrecoverable", because overwriting guarantees nothing on modern storage.
Processors and third parties
Hosting: IONOS SE, Germany. Servers are located in Germany.
Cryptocurrency price providers are queried for market data only. No member content is transmitted to them, only the asset symbol being asked about.
AI processing runs on the operator’s own hardware. No conversation content is sent to an external model provider.
Video embeds load from a third party only after you click to play. Nothing is requested from the video provider before that click, and the preview image is served from our own domain.
Analytics are switched off by default and require your consent before any script loads.
Website visitors
Technically necessary storage: one cookie holding your language choice. It carries no identifier and requires no consent.
Consent-requiring storage: analytics, if the operator enables it. Nothing loads before you accept. Your answer to the banner, accepted or declined, is kept in your browser’s local storage so you are not asked again; declining leaves no analytics storage beyond that record of your refusal.
Server logs at our hosting provider record access data for operational security. Reports submitted through the public report form store a keyed, non-reversible token derived from your IP address rather than the address itself.
Operators of the console
Administrative access uses passkeys (WebAuthn) as the primary method. Sessions are stored server-side and expire. Every administrative action that changes state is written to an audit log, which records the actor, the action and the target, but not the content acted upon.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21), and the right to withdraw your consent at any time (Art. 7(3)) without affecting the lawfulness of processing before withdrawal.
How you exercise them here is unusual, and worth reading before you write to us. This service has no accounts. It knows you only as a member of a group chat, and the messaging protocol is built so that we cannot learn who you are. That protects you. It also means we cannot simply look you up.
The chat is the fastest route, and it costs you nothing
The strongest proof of identity available to us is your own connection. When you send /unpublish in the group, or ask her in plain language to stop publishing you, the protocol has already established that the message came from the member whose content it is. Nothing further is needed, you disclose nothing to us, and the effect is immediate: your content leaves every public surface at once.
Use this route wherever you can. It is faster than writing to us, the proof is stronger than anything an email can offer, and it costs you nothing.
What the chat can do today: withdraw your consent, immediately and without giving reasons, which is the fastest and most complete route and needs no correspondence at all; let you choose afterwards whether your content is hidden or destroyed, where hiding stays reversible by you and destruction deliberately asks you to type the word "delete" rather than accepting a simple yes; restore what you hid, by yourself, at any time; and tell you how many of your messages she holds and how many are public.
What the chat cannot do today, so these have to reach us by email: a copy of your data, correction of something recorded wrongly, a machine-readable export, and objection. If you chose to hide your content and later want it destroyed, that also has to come by email, because the chat offers no route from hidden to destroyed.
Email, and what it costs you
You can always contact the controller by other means, and the address is in the legal notice. You should know the price before you pay it.
If you contact us by email, we necessarily learn a connection between your email address and your identity in the community. The messaging protocol is designed to prevent exactly that link. Wherever possible, use the in-chat route instead, where your own connection proves who you are and you disclose nothing.
We do not store email addresses in the archive. There is no field for one anywhere in it. The connection exists only in our correspondence, and we delete that correspondence once your request is closed, which makes the disclosure a temporary cost rather than a permanent one. That is a commitment we keep by hand. It is not a control the system enforces.
How we check that a request is yours
An email alone cannot show that the sender is the member whose content is at stake. Acting on an unverified request would let anyone erase another member’s words, which is the same harm the first-person consent rule exists to prevent, arriving through a different door.
So we verify in-band. When a request reaches us by email, we ask you to confirm from inside the group chat, by sending the command yourself. The email is the prompt; your own connection is the proof. We record the decision we reach, whether we grant the request or refuse it.
A private confirmation code sent to you directly, rather than in the group, would be better. She has no private channel today: she cannot send you a direct message, and she would not read one. Adding that channel and a one-time code is planned, not available.
If you can no longer reach the identity you used
Two situations, and they are not equally hard.
You still hold your SimpleX identity but have left the group. Rejoin and use the in-chat route. Be aware that rejoining gives you a new member identity, and the archive cannot connect it to the old one: content you posted before stays published under the identity you had then, and the in-chat route will not reach it. For that content, write to us and we will handle it as set out below.
You have lost your SimpleX identity altogether. SimpleX has no account recovery: no password reset, no email, no central record. If your device is gone and your chat database was not backed up, you cannot prove you were that member, and no amount of correspondence reopens that door. We would rather tell you plainly than let you discover it.
Knowing what was published proves nothing. The archive is public, so anything you can describe about it a stranger can describe equally well. We cannot treat familiarity with published content as evidence that you wrote it.
Content that was never published is different. Messages we captured but never published are known to you and to us alone, so accurate knowledge of them is genuine evidence. It is the only such evidence available, and it will often not exist.
Where we cannot verify, what we do depends on what you ask for, because the risks are not symmetric. Wrongly granting access would disclose another member’s data to a stranger, which is a breach; without verification, the answer to an access request is no, and it stays no. Wrongly granting erasure would destroy another member’s words permanently.
So we do not treat an unverifiable erasure request as a refusal. We treat it as a request for restriction under Art. 18 GDPR, which is the right to have processing stopped rather than data destroyed. We take the content out of public view. That achieves what you actually want, which is that your words stop being public, and it is reversible if the request turns out to have been mistaken or malicious. If verification becomes possible later, destruction can follow.
Two limits, stated rather than implied. Restriction on this route is applied by us message by message, from the operator console, and it is reversible by us. Destruction is not something we can carry out for you from that console at all: the only route in this system that actually destroys content is the one you drive yourself in the chat.
A better answer is planned. The moment you opt in is the moment you are provably yourself, and therefore the moment to establish proof for later. We intend to have her issue a one-time recovery code then, privately, which you keep and can present afterwards from any channel to prove authorship without revealing any identity, with only a hash of it stored. This is planned and does not exist yet. If you opt in today, no such code is issued.
Complaints
You have the right to complain to a supervisory authority:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2-4
40213 Düsseldorf
Telephone: +49 211 38424-0
Email: poststelle@ldi.nrw.de