ALEAMATRIX

Privacy Policy

Note: This is a convenience translation. The legally binding version is the German original at legal/datenschutz.html. In case of discrepancy, the German text prevails.

Information on the processing of personal data under the General Data Protection Regulation (GDPR / DSGVO).

1. Controller

Rudolf Kramer
Vichtenstein 153/2, 4091 Vichtenstein, Austria
Email: rkrmobil@gmail.com

Controller within the meaning of Art. 4 no. 7 GDPR. Full details in the Imprint.

2. Principle: as little data as possible

AleaMatrix is designed as an application that runs largely in the browser. The actual visualisation and computation happens on your device, and the application can be used without signing up. Anyone using it without an account leaves us only the technically unavoidable server log files (point 3).

Anyone who creates an account additionally uses features for which data must be stored on our servers — such as cross-device backup of tips. What is collected in that case is set out in point 9. A paid subscription adds payment processing (point 10); sending system messages adds the email service provider (point 11).

Not used: tracking cookies, advertising identifiers, web analytics services or newsletter mailings.

3. Hosting & server log files

The website is operated with the following hosting service providers:

When you access the site, the respective host automatically processes so-called server log files that your browser transmits. These typically include:

This processing is technically necessary for the secure and stable operation of the website. The legal basis is the legitimate interest in error-free, secure operation (Art. 6(1)(f) GDPR). A data-processing agreement (Art. 28 GDPR) is in place with the host. The storage period of the logs at IONOS is up to 8 weeks (with anonymised IP address).

4. Local storage in the browser (favourites/tips)

When you save tips, the application uses your browser's local storage (localStorage and IndexedDB). These data – essentially your stored tips, order, colour and display settings – serve to preserve your input across visits.

Without sign-up, this data remains exclusively on your device and is not transmitted to us or to third parties. We have no access to it.

With a signed-in account, tips and colour settings are additionally stored on our servers so that they remain available on multiple devices. Details in point 9.

You can delete the locally stored data at any time yourself, e.g. via the application's own features or by clearing browser data. For the copy stored on our servers, account deletion applies (see "Deleting your account").

5. Fonts

Fonts used are served locally from our own server. There is no connection to third-party servers (e.g. Google Fonts); in particular, your IP address is not transmitted to third parties for this purpose.

6. Cookies

No cookies are set for analytics, tracking or marketing purposes. To the extent that local browser storage (see point 4) is used, this happens solely for the features you have triggered.

7. Web analytics / tracking

As of this policy, no web analytics, audience-measurement or tracking services are used. (Should such services be used in the future, this will only happen with your explicit consent via a consent banner, and this policy will be updated accordingly.)

8. Getting in touch

If you write to us by email, we process your input to handle the request (Art. 6(1)(b) or (f) GDPR). The data are deleted as soon as they are no longer needed and no statutory retention obligations stand in the way.

If you use the contact form in the application, we additionally store, in addition to your message: name and email address, if provided, the chosen type of request, the interface language, the browser identifier (user agent) and a hash of your IP address. The IP address itself is not stored in plain text; the hash serves solely to detect large-scale abuse of the form. Delivery to us takes place via the email service provider named in point 11. The legal basis is our legitimate interest in handling requests and in protection against abuse (Art. 6(1)(f) GDPR); for contract-related requests Art. 6(1)(b) GDPR.

9. User account and cross-device backup

Signing up is voluntary. If you create an account, we process:

If you enable cross-device backup, your stored tips (chosen system, numbers, storage slot, date, origin and order) and your colour settings are added.

The legal basis is the performance of the user contract (Art. 6(1)(b) GDPR). The data are stored for the duration of the account; for deletion see the section "Deleting your account". Account and tip data reside with the database service provider named in point 12 on servers in the European Union.

10. Payment processing

For paid subscriptions we use the payment service provider Stripe. You enter your payment details — in particular full card numbers — directly with Stripe. These data are never transmitted to us at any point and are not accessible to us.

We only store the customer number assigned by Stripe, the subscription identifier and the status of the subscription. We need this information in order to unlock the tier you booked and to process cancellations.

The legal basis is the performance of the contract (Art. 6(1)(b) GDPR). Stripe's own privacy provisions additionally apply to its processing.

11. Sending emails

We send system messages via the email service provider Brevo. This includes confirmation of registration, password reset, welcome after sign-up, payment and cancellation confirmations, reminders before the trial expires, and forwarding messages from the contact form.

Your email address and the content of the respective message are transmitted for this purpose. A newsletter is not sent; these are exclusively messages that are triggered by your use. The legal basis is the performance of the contract (Art. 6(1)(b) GDPR) or our legitimate interest in reliable operation (Art. 6(1)(f) GDPR).

12. Service providers used

Data-processing agreements pursuant to Art. 28 GDPR are in place with all the following service providers. They process data exclusively on our instructions.

Service providerPurposePlace of processing
IONOS SE, GermanyHosting of the website (aleamatrix.com) and server log filesGermany
Supabase Inc., USADatabase, sign-in and account managementEuropean Union (data centre Frankfurt am Main)
Stripe Payments Europe Ltd., IrelandPayment processing for subscriptionsEuropean Union, partly USA
Brevo (Sendinblue SAS), FranceSending of system emailsEuropean Union

Where a service provider is based outside the European Union or a transfer there cannot be ruled out, such transfer is based on the Standard Contractual Clauses of the European Commission under Art. 46(2)(c) GDPR together with supplementary protective measures.

13. External data sources

The historical draw data shown is drawn from publicly accessible archives and contains no personal data. Source references: see Data sources. The data are delivered statically; when you view the page, no connections to third-party servers are established for this purpose.

14. Your rights

Under the GDPR you have in particular the following rights:

To exercise them, an informal message to rkrmobil@gmail.com or the contact form in the app is sufficient.

14a. Deleting your account (right to be forgotten, Art. 17)

You can delete your account yourself at any time: Menu → 👤 → "Account & subscription" → "Delete account permanently". After confirmation, the following happens:

14b. Data access & export (Art. 15 & 20)

Also in the "Account & subscription" area you will find the button "Export my data as JSON". The download contains all data we have stored about your account (profile, tips, colour settings, contact requests sent by you). The format is machine-readable and suitable for data transmission to other providers.

14c. Usage logs for error analysis and complaint handling

To make your account activity traceable and to handle support and complaint enquiries quickly, we log selected activities in an internal log: sign-in/sign-out, registration, change of the main system, change of tier (Trial → Premium → Free), stored or deleted tips, cloud-sync operations, blocked feature calls (when a feature is not available at your freemium tier), data exports and account deletion requests as well as submissions of contact forms.

What is NOT logged: click behaviour, mouse positions, screen recordings, the contents of your tips or colour settings. We collect no advertising identifiers and do not embed external analytics providers.

Your IP address is stored for this purpose only as a cryptographic hash (SHA-256 with a project-internal salt), from which the plain-text IP can no longer be reconstructed. The hash serves exclusively for abuse detection (e.g. rate limits).

Retention period: 90 days. After that, the log entries are permanently deleted by a daily automated cron job. Upon account deletion, the entries immediately lose the link to your account (the foreign key is set to NULL) — the history thus becomes non-personal and expires permanently within 90 days at the latest.

Legal basis: legitimate interest in a functioning customer service and in the security of our services (Art. 6(1)(f) GDPR). Information about the log entries stored for your account can be requested as described under "14b. Data access & export".

14d. Abuse protection for the free trial

To prevent endless trials we store, after each account creation, a cryptographic hash (SHA-256 with a project-internal salt) of the email address used. The hash alone allows no conclusions about the plain-text address. It is checked at sign-up: if you already had a trial with the same address in the last 12 months, your new account starts directly in the free version — instead of the 30-day trial. Legal basis: legitimate interest in the abuse protection of trials (Art. 6(1)(f) GDPR). In hardship cases (illness, stay abroad and the like) please contact us via the contact form — the block can be lifted manually.

15. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. Within the EU you can turn to the supervisory authority of your Member State or to the authority responsible for the operator. Competent authority at the operator's registered office: Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.

16. Data security

Transmission is encrypted via HTTPS (TLS). We take appropriate technical and organisational measures to protect your data.

17. Use of artificial intelligence (transparency pursuant to Art. 50 of the EU AI Act)

For transparency in accordance with Article 50 of the EU AI Act (Regulation (EU) 2024/1689, effective since 2 August 2026):

18. Currency & changes

This privacy policy is dated August 2026. It will be adapted as the website is further developed or when additional service providers are added.