1. Scope and controller
This notice applies to the public website at prismabot.org. The website and PrismaBot project are owned by, and the website is operated under the responsibility of:
Christopher Schmidt
[email protected]
2. Website delivery and security
The site is hosted on a privately administered virtual server and delivered through Cloudflare's network and Cloudflare Tunnel. When a page is requested, technical request information is processed to deliver the response and protect the site. This can include the visitor's IP address, date and time, requested path, HTTP method and status, browser and device headers, referring origin, and security signals generated by Cloudflare.
The site does not use advertising trackers, third-party analytics scripts, social-media tracking pixels, account registration, or project-operated behavioral profiles.
3. Operational logs
The PrismaBot web container records only a reduced operational access line containing the time, request method, requested path, protocol, response status, and response size. It does not place IP addresses, referrer values, user-agent strings, or URL query parameters in its application access log.
Cloudflare and the infrastructure provider may process request and security records under their own configured retention schedules. These records are used for delivery, availability, abuse prevention, incident response, and troubleshooting.
4. “I'm interested” counter
The site displays an optional interest button for the planned PrismaBot release. Merely opening the site does not cause PrismaBot to create an interest cookie or write to local storage or session storage.
When a visitor explicitly selects “I'm interested”, the service creates a random signed identifier in a secure, HTTP-only, same-site cookie. The cookie is used to recognize that browser's completed submission and prevent the same browser from increasing the counter repeatedly. Its maximum lifetime is 400 days, and it can be removed through the browser's cookie controls.
The server stores a keyed hash of the random identifier, the submission time, and the coarse referral category described below. The token itself is not stored in the database. For abuse prevention, the source IP address is converted immediately into a keyed network hash; the raw address is not retained by the counter. Rate-limit records are used only to constrain repeated submissions.
The public API returns only the total count and whether the current browser has already submitted interest. The referral breakdown is not public.
5. Referral categories
Referral classification occurs only if the visitor selects the interest button. The browser classifies the referring hostname into one of four values: Google Search, other search engine, external site, or direct or unknown. Only that category is sent with an accepted submission.
The full referring URL, search query, and referring hostname are not stored by the counter. The category is not written to local storage or session storage and exists in the page only long enough to submit the requested interest.
6. Contact messages
If a visitor writes to [email protected], the supplied email address, message, attachments, and related mail metadata are processed to read and answer the request. Visitors should not send credentials, platform tokens, or unrelated sensitive information.
7. Purposes and legal bases
Website delivery, security, reduced operational logging, abuse prevention, the voluntarily activated interest counter, and privacy-minimal referral measurement are processed on the basis of legitimate interests under Article 6(1)(f) GDPR. Those interests are providing a reliable public pre-release page, protecting it from misuse, preventing counter inflation, and measuring genuine product interest without detailed tracking.
Contact messages are processed to answer the request. Depending on its content, the basis is Article 6(1)(b) GDPR for pre-contractual communication or Article 6(1)(f) GDPR for general correspondence and project support.
The interest cookie is created only after the visitor requests an interest submission and is used to provide that one-per-browser function. No optional advertising or analytics cookies are used.
8. Recipients and international transfers
Technical request information may be processed by Cloudflare as the site's content-delivery, tunnel, and security provider and by the virtual-server provider as the infrastructure host. Email is processed by the configured mail provider. Information is not sold or shared for advertising.
Cloudflare operates internationally and may process information outside the European Economic Area. Applicable safeguards are governed by Cloudflare's data-processing terms, including recognized transfer mechanisms where required. Visitors can review Cloudflare's Privacy Policy for further information.
9. Retention
- The interest cookie expires after at most 400 days unless removed earlier.
- Accepted interest records are retained while the pre-release interest campaign is active and will be deleted or reduced to non-identifying aggregate totals within 90 days after that campaign ends.
- Network rate-limit hashes are retained only for the short abuse-prevention window and routine cleanup period.
- Reduced application logs are retained only as needed for operations, security, and troubleshooting.
- Contact messages are retained until the request is resolved and for any additional period required to document the correspondence or meet legal obligations.
10. Your rights
Subject to the conditions in applicable law, visitors may request access, correction, deletion, restriction, or portability of their personal data and may object to processing based on legitimate interests. Requests can be sent to [email protected].
Visitors also have the right to lodge a complaint with a competent data-protection supervisory authority. Because the interest system deliberately avoids names and stores only pseudonymous hashes, a visitor may need to provide the browser cookie value or other information that allows a record to be located; the controller will not collect additional identifying data merely to identify an otherwise unidentifiable record.
11. Changes to this notice
This notice may be updated when the website, providers, or processing purposes change. The effective date at the top identifies the current version. Materially new processing will be described before it begins.