Privacy Policy
This is a static website. There is no account, no login, no contact form, no newsletter and no checkout — nothing where you enter data yourself. The only processing is what technically happens when a page is requested, plus an anonymous audience measurement.
Controller
Sascha Henning
Dresdner Landstr. 11
01744 Dippoldiswalde
Germany
E-mail: sascha@saschahenning.de
Hosting and server logs
The site is hosted on Cloudflare Pages (Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA). When a page is requested, Cloudflare processes the technically necessary access data: IP address, date and time, requested address, referring page, browser and operating system identifier. This data serves delivery, security and attack mitigation.
The legal basis is Art. 6(1)(f) GDPR — my legitimate interest in operating the site securely and without disruption. Processing takes place under Cloudflare’s data processing agreement. Cloudflare also processes data in the USA, based on the EU Standard Contractual Clauses and Cloudflare’s certification under the EU-U.S. Data Privacy Framework.
Cloudflare runs its own security mechanisms for attack detection that execute when a page loads. Cloudflare also collects its own cookie-free audience measurement (“Cloudflare Web Analytics”).
Audience measurement with Umami
To see which content is being read, I use Umami — self-hosted analytics
software. There is no external analytics provider: the data runs on my own
instance at insights.saschahenning.de, on a server in Germany, reached — like
this website — through Cloudflare. The data is evaluated by me alone and is
neither sold nor combined with other data sources.
Umami sets no cookies and stores nothing on your device. Your IP address is not stored; it only feeds into a non-reversible hash whose key rotates daily. That allows page views within a single day to be grouped into a session, but not traced back to a person, and not across days or across other websites.
Collected are: the page requested, the referring page, the page language, browser, operating system, device type, screen size and country of origin. In addition, these clicks are counted:
- downloading a file (a PDF, for example)
- clicking a link to another website
- switching the language
- clicking a link inside this site
- switching between light and dark appearance
- clicking the e-mail address in the imprint
Only what was clicked is recorded — never who clicked it.
The legal basis is Art. 6(1)(f) GDPR, my legitimate interest in knowing whether and how the site is used. No cookies are set and no identifiers are placed on your device, so I do not ask for consent under § 25 TDDDG.
You can object to the measurement at any time — informally, by e-mail to the address above. Common script or tracking blockers in your browser are also effective.
Storage on your device
This site stores exactly one item locally in your browser: the appearance you
picked (light or dark), under the key theme in localStorage. It never leaves
your device and only serves to keep your choice on your next visit. The legal
basis is § 25(2) no. 2 TDDDG — the storage is necessary for the function you
explicitly asked for. You can delete the entry at any time in your browser
settings.
The PioTime App
Under piotime.saschahenning.de I offer PioTime, an app for tracking
field-ministry hours. It runs in the browser and can be installed to the
home screen. This policy applies to it as well — with the following
specifics.
Your entries stay on your device. Everything you record in PioTime — hours, notes, credits, Bible studies, goals and backup files — the app stores exclusively locally in your browser. There is no account and no storage on the internet; the app sends your entries to no one, not even to me. That also means: I cannot recover lost data. The backup file you can create in Settings stays in your hands alone.
The app is delivered via Cloudflare; the section “Hosting and server logs” applies. Usage is counted with the same self-hosted Umami instance as on this website; the section “Audience measurement with Umami” applies. The app consists of a single page — there is nothing more than that one page view to count.
Error reports
When a technical error occurs in the app, it sends an error report to
GlitchTip — like Umami, self-hosted software on my own instance
(glitchtip.saschahenning.de), with no external service provider. A report
contains the error message, the technical sequence leading up to it (such
as the app’s network requests), the app version, and browser and operating
system identifiers. It does not contain your entries, notes or inputs, and
your IP address is not stored in it.
Error reports cannot be turned off in the app. The reason is simple: PioTime is free, and these reports are my only way to find and fix bugs. The legal basis is Art. 6(1)(f) GDPR — my legitimate interest in a working app. Error reports are automatically deleted after 90 days.
Feedback
Using the “Feedback” item in the app’s settings, you can send me a message.
Only with this click does anything leave your device: the app hands the app
version, your set language, colour scheme, and whether it is running
installed or in the browser, to my feedback form
(feedback.saschahenning.de), so I can technically place your report. Your
name is not included — unless you write it into the message yourself.
Otherwise, the section “Contact by e-mail” applies to your report
accordingly.
Device syncing
You can use PioTime on multiple devices and pair them with a QR code. This is voluntary: without pairing, the app never connects to the sync server, and you can dissolve an existing pairing at any time in Settings.
Pairing generates a key on your device that exists only in the QR code and never reaches my server. Your data is encrypted on the device and only then transmitted. As a result, the server holds only an encrypted data package that only your paired devices can read — plus a random identifier with no link to your person, the package’s size, and the time of the last sync. There is still no account; the server does not know names, e-mail addresses or content.
If you dissolve the pairing, the package is deleted immediately. If no device syncs for three months, the server deletes it on its own. The server copy is a convenience, not a backup: it can disappear at any time — your devices always keep the complete dataset, and your backup file remains the protection against data loss. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by pairing and can withdraw at any time by dissolving the pairing.
Support
Using the “Support” item in the app’s settings, you can voluntarily support PioTime — with six monthly amounts or a one-time payment. Nothing happens without your click: there is no connection to Stripe unless you open the link.
Tapping one of the amounts takes you to a payment page operated by Stripe (Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin D02 H210, Ireland). There, Stripe always asks for your e-mail address, and for some payment methods also your billing address — for a SEPA direct debit, for example. Your card or account details go directly to Stripe; neither I nor the app ever see them.
For my own bookkeeping, I learn that and how much you supported. The legal basis is the payment itself — contract fulfilment under Art. 6(1)(b) GDPR — which you decide to enter by tapping.
Contact by e-mail
If you write to me, I process your details to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR. My mailbox is operated by Microsoft (Microsoft Ireland Operations Limited, One Microsoft Place, Dublin 18, Ireland). Your message is kept until its purpose no longer applies and no retention obligations remain.
Links to other websites
This site links to external offerings, among them JASP, Widget Builder, CongPlan, LinkedIn and my own apps. As soon as you follow a link, that provider’s privacy policy applies. I have no influence on their processing.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR). Please use the e-mail address above.
You may also lodge a complaint with a supervisory authority. The one responsible for me is:
Die Sächsische Datenschutzbeauftragte
Devrientstraße 5
01067 Dresden
Germany