Legal · Germany
Privacy Policy
Provider details are not yet fully configured in the server environment. The marked fields must be completed and reviewed before legal publication.
Convenience translation. This English version is provided for reference only. Only the German version is legally binding.
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
[BETREIBER_NAME not configured] [STRASSE_HAUSNUMMER not configured] [PLZ_ORT not configured], [LAND not configured] Email: [email protected]
No data protection officer has been appointed, as the statutory requirements for a mandatory appointment are not met. [VERIFY not configured]
2. Overview: what data we process
We process personal data only to the extent necessary to provide Wandelraum:
- Account data: email address (for registered accounts), pseudonymous account identifier (for guest access).
- Content data: your questions, the draw data generated server-side (cards, lines, hexagrams), and the history of your AI dialogues.
- Payment and credit data: credit balance, transaction history; payment processing is handled by Stripe (see Section 8).
- Usage and metadata: IP address, time of access, browser/device type (server logs, security functions); pseudonymous audience metrics only with your consent (see Section 10).
3. Legal bases
Unless stated otherwise in the individual case, we base processing on:
- Art. 6 (1)(b) GDPR (performance of contract and pre-contractual measures),
- Art. 6 (1)(a) GDPR (consent, e.g. for optional audience measurement),
- Art. 6 (1)(f) GDPR (legitimate interests, esp. security, stability, and abuse prevention),
- Art. 6 (1)(c) GDPR (legal obligations, esp. retention under commercial and tax law).
4. Hosting and content delivery (Cloudflare)
Our website is delivered via the network of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (CDN, DDoS protection, TLS). In this process, Cloudflare processes technically necessary connection data (incl. IP address). The legal basis is Art. 6 (1)(f) GDPR (secure and performant delivery). A data processing agreement is in place with Cloudflare; transfers to the USA are safeguarded by Cloudflare's certification under the EU-U.S. Data Privacy Framework.
The origin server is operated by [HOSTING_ANBIETER_NAME_ANSCHRIFT not configured]; server location: [SERVER_REGION not configured]. Server logs (IP address, timestamp, requested resource, status code) are deleted after 90 days unless security-related analysis is required.
5. Bot protection (Cloudflare Turnstile)
To protect forms and interfaces against automated abuse, we use Cloudflare Turnstile. Turnstile evaluates technical browser signals without presenting a classic CAPTCHA puzzle. The legal basis is Art. 6 (1)(f) GDPR (abuse prevention).
6. Accounts and sign-in
Guest access: You can try Wandelraum without providing an email address. For this purpose, a pseudonymous account is created whose identifier is stored on your device. Guest access is bound to that device. Inactive guest accounts and the associated dialogues are deleted after 30.
Email sign-in: When signing in by email, we send you a sign-in link ("magic link"). Delivery is handled via Resend. Legal basis: Art. 6 (1)(b) GDPR.
Sign-in with Google or Apple: If you wish, you can sign in with your Google or Apple account. We receive only the email address you release (with Apple, optionally an anonymized relay address) and an account identifier. The respective provider is itself responsible for processing carried out during the sign-in process on its side.
Authentication and data storage are provided via Supabase Inc., 970 Toa Payoh North #07-04, Singapore / Supabase infrastructure in [SUPABASE_REGION not configured]. A data processing agreement is in place with Supabase.
7. AI dialogues (core feature)
Wandelraum generates readings in dialogue with an AI language model. For this purpose, we transmit your question, the draw data generated server-side, and the dialogue history so far to OpenRouter, Inc.. A data processing agreement is in place with the provider; your content is not used there to train models.
The legal basis is Art. 6 (1)(b) GDPR (provision of the reading you requested).
Important note: Please do not enter special categories of personal data into your questions (e.g. health data, religious beliefs) or data of third parties whose transmission you cannot take responsibility for. The dialogues serve entertainment and self-reflection; human review of content takes place only where necessary for abuse prevention or at your own request.
Your dialogues are visible only in your account, are not published, and are blocked from search engines. You can delete dialogues in your account; deleted dialogues are removed from backups within 30 days.
8. Payment processing (Stripe)
Purchases of AI reply credits are processed via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. You enter your payment details (e.g. card number) directly with Stripe; we ourselves do not receive or store complete payment details, only the payment status, amount, time, and a truncated identifier of the payment method. Your statement will show "58FAST.COM AI".
Legal bases: Art. 6 (1)(b) GDPR (payment processing) and Art. 6 (1)(c) GDPR (statutory retention obligations). We retain booking and invoice data in accordance with commercial and tax law retention periods (§ 257 HGB, § 147 AO).
9. Credit and transaction history
We maintain a credit history for your account (grants, reservations, consumption, reversals). This data is necessary for the performance of the contract and the traceability of billing (Art. 6 (1)(b) and (c) GDPR).
10. Cookies, local storage, and audience measurement
Technically necessary (legal basis § 25 (2) TDDDG, Art. 6 (1)(b)/(f) GDPR): session and sign-in information, language setting, your cookie decision, guest access identifier.
Optional audience measurement (only with consent, § 25 (1) TDDDG, Art. 6 (1)(a) GDPR): We measure the use of our pages with our own cookieless/pseudonymous analytics without sharing data with advertising networks. You can revoke your consent at any time with effect for the future via "Cookie settings" in the page footer.
11. Contacting us
If you contact us via the contact form or by email, we process your information to handle the inquiry (Art. 6 (1)(b) or (f) GDPR). We delete inquiries once they have been resolved and no retention obligations stand in the way.
12. Transfers to third countries
Where service providers process data outside the EU/EEA (esp. the USA), this takes place on the basis of an adequacy decision (EU-U.S. Data Privacy Framework) or the EU Standard Contractual Clauses with supplementary measures.
13. Retention periods
We store personal data only for as long as necessary for the stated purposes:
- Account and content data: until you delete your account or the content; guest accounts as per Section 6.
- Payment-related data: in accordance with statutory retention periods (6, 8, or 10 years).
- Server logs: as per Section 4.
14. Your rights
You have the following rights vis-à-vis us regarding your personal data:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- revocation of consent with effect for the future (Art. 7 (3) GDPR).
Right to object (Art. 21 GDPR): Where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation.
To exercise your rights, an email to [email protected] is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for us: [ZUSTAENDIGE_AUFSICHTSBEHOERDE not configured].
15. No automated decision-making
The AI-generated readings serve entertainment and self-reflection only. No automated decision-making with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place.
16. Data security
All connections are TLS-encrypted. We employ state-of-the-art protective measures (incl. Content Security Policy, access restrictions, server-side generation and immutability of draw data).
17. Changes to this policy
We will adapt this privacy policy if our processing operations or the legal situation change. The version published on this page at the relevant time applies.
Version: 6 August 2026
The German version is authoritative. Translations are provided for convenience.