Legal
Privacy Policy
Last updated: 1 September 2026
1. Overview
This privacy policy explains which personal data is processed when you use EmiGuide, the purposes of processing, and your rights. Recommendations are generated with the assistance of AI but do not replace legal, tax, or immigration advice.
2. Data Controller
The data controller is Florian Zelder, Kastanienweg 15d, 58093 Hagen, Deutschland. Email: contact@emiguide.ai.
3. Data We Collect
Depending on the features you use, we process the following categories of data:
- Account data: name, email address, profile image, sign-in provider, and technical authentication data; for email sign-in, a non-reversible password hash.
- Profile data: country of residence and passport, languages, household roles and age groups, budget, climate, work, travel, tax and lifestyle preferences, and voluntary aggregate health-related requirements without diagnoses or links to individuals.
- Usage and evidence data: sessions, timestamps, technical identifiers and, for consent records, IP address, user agent, text version and a checksum of the consent wording.
- Communication data: voluntary additional profile context and questions and answers in the AI adviser. These free-text fields may contain personal data if you enter it.
- Contract and payment data: selected product, amount, currency, payment status and Stripe customer, checkout and payment identifiers. Card or bank details are processed directly by Stripe.
- Withdrawal data: name, email address, contract reference, content, and the date and time of the withdrawal statement and receipt confirmation.
4. Legal Basis & Purpose
Account administration, profile storage, reports and Q&A features are processed to perform the user contract (Art. 6(1)(b) GDPR). We process voluntary health-related requirements only on the basis of your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR). Payments and contract administration are based on Art. 6(1)(b) GDPR; withdrawal statements, receipt confirmations and legally required retention are based on Art. 6(1)(c) GDPR. Security, abuse-prevention and consent evidence are processed on the basis of our legitimate interests in secure and accountable operation (Art. 6(1)(f) GDPR), unless a more specific legal basis applies.
5. Data Minimisation and AI Processing
The profile does not request household members' names, exact ages or medical diagnoses. Profile inputs are transformed into minimized features for country assessment, such as role, age group, budget bracket and aggregate care needs. Because these features remain linked to your profile, we treat them as personal data and do not describe them as anonymous.
Optional profile free text and questions to the AI adviser are inserted unchanged into the relevant AI prompt and sent to the AI service used. Do not enter names, contact details, specific diagnoses or other information that identifies you or anyone else. AI prompt and response content is not stored in technical LLM traces; only operational metadata and placeholders remain there.
6. Recipients and Processors
Data is disclosed only to recipients that need it for the relevant feature. Depending on the active configuration, these include:
- Sign-in providers: Google LLC or Apple Inc. when you choose the respective sign-in method. Local email sign-in does not transmit credentials to these providers.
- Stripe Payments Europe, Ltd. and affiliated Stripe entities for checkout, payment processing, fraud prevention and payment records. Account/profile identifiers are also transmitted as transaction metadata.
- AI services: depending on the operating configuration, OpenRouter, Inc. including the model provider selected there, OpenAI, L.L.C. for embeddings, or another AI provider configured by the operator. Minimized profile features and, when you use those features, free text or questions are transmitted.
- Hosting and database: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, acting as processor. The application and a PostgreSQL database operated by us run on the same Hetzner Cloud server in Helsinki, Finland; there is no additional external database provider.
- Email transport service: the SMTP provider configured for production receives sender and recipient addresses and the receipt-confirmation content where required for delivery. The specific provider and any third-country safeguards will be added here before production launch.
7. Transfers to Third Countries
Google, Apple, Stripe, OpenRouter, OpenAI or downstream model providers may process data outside the European Economic Area, particularly in the United States. Depending on the provider, transfers are based on an adequacy decision including the EU-US Data Privacy Framework or appropriate safeguards such as EU Standard Contractual Clauses. The providers and safeguards actually used in production must be verified against the executed contracts before publication.
8. Cookies and Local Storage
We use technically necessary session and security cookies and a language preference. Your cookie selection is stored in your browser's local storage. Optional tracking technologies may only be used after your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG; technically necessary storage access is based on Section 25(2)(2) TDDDG.
9. Your Rights (GDPR Art. 15–21)
You have the following rights regarding your personal data:
- Right of access (Art. 15) — export your data at any time via Account settings
- Right to rectification (Art. 16) — update your profile data
- Right to erasure (Art. 17) — delete your account and directly associated profile data through Account settings, unless legal obligations require retention
- Right to restriction of processing (Art. 18) — request restricted processing where the statutory conditions apply
- Right to data portability (Art. 20) — download your data as JSON
- Right to object (Art. 21) — contact us at contact@emiguide.ai
- Withdrawal of consent (Art. 7(3)) — at any time with effect for the future; prior processing remains lawful
- Right to lodge a complaint (Art. 77) — with a data protection authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia
10. Retention Periods
Accounts, reports, Q&A content and consent records are generally stored until account deletion. Raw profile answers are additionally removed after 12 months without a profile update. Withdrawal statements and delivery evidence are generally retained until the end of the third calendar year after final processing, or longer while a legal dispute is pending. Content-free technical LLM traces are deleted after 30 days and AI cost and token metadata after 12 months. Caddy access logs and container logs are retained for no more than 14 days. Daily PostgreSQL backups created by us are deleted after no more than 14 days; enabled Hetzner Cloud backups comprise no more than the last seven daily versions. Because a database backup may temporarily be contained in a Cloud backup, an individual deletion may technically remain in nested backup copies for up to 21 days. Accounting vouchers and invoices are generally retained for eight years from the end of the year in which they were created in accordance with Section 147 AO and Section 14b UStG, unless a longer legal period or pending proceeding applies. Data held by Stripe is additionally subject to its legal retention obligations.
11. Requirement to Provide Data
An email address and the profile and payment data required for the selected service are needed for the account, contract and report. Health-related requirements and free text are voluntary. Without consent to process selected health requirements, those requirements cannot be considered in the analysis.
12. Automated Decisions
EmiGuide generates automatically weighted recommendations. They do not produce legal effects or similarly significantly affect you; no automated decision-making within the meaning of Art. 22 GDPR takes place.
13. Contact
Send privacy enquiries to contact@emiguide.ai or by post to the address stated above.