Privacy Policy
Last updated: 6 October 2026
This policy explains how Jein (jein.dev) processes personal data on this website (https://jein.dev), in the dashboard and in the API (https://app.jein.dev), under Articles 13 and 14 of the General Data Protection Regulation (GDPR). A German version is available at https://jein.dev/datenschutz/. The English version is binding; the German version is a courtesy translation.
Controller
Setorli Blagogee
c/o Autorenglück #40488
Albert-Einstein-Str. 47
02977 Hoyerswerda
Germany
E-mail for data protection matters: privacy.jein@snblago.com
Other matters: legal.jein@snblago.com
Phone: +49 173 4362355
Data protection officer
We have not appointed a data protection officer. We are not required to: fewer than 20 people regularly process personal data at Jein (§ 38(1) BDSG), and our core activities do not consist of large-scale monitoring or of processing special categories of data (Article 37(1) GDPR). Please send any data protection question to privacy.jein@snblago.com.
Overview
Jein is a service for developers aged 18 or over, including those working on personal projects. We collect as little as we can:
- To run your account we need your e-mail address. Login is handled by our identity provider, Auth0.
- We never store or log the content of API requests (state, instructions, questions) or the answers. They are held in memory only while the request is processed.
- Our application logs contain internal ids, routes, status codes and timings, but no IP addresses, no browser details, no e-mail addresses and no request content.
- Analytics on this website runs only if you consent. It uses no cookies.
- Our servers and our database are in the EU (Frankfurt, Germany).
Visiting this website
When you open this website, the dashboard or the API, your browser or software sends technical data to our hosting provider, DigitalOcean: IP address, date and time, the requested address, the referring page if your browser sends it, browser and operating system (user agent), and TLS connection data. DigitalOcean processes this data on our behalf to deliver the pages and to protect the service against attacks. Connections are received by DigitalOcean's edge network, operated by Cloudflare, Inc., at the location nearest to you, where the encrypted (TLS) connection is terminated. Requests to the dashboard and the API are then forwarded to our servers in Frankfurt; the website's static files are delivered directly from the edge network.
- Purpose: delivering the website and the service, security and stability.
- Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is a secure and working website.
- Retention: We do not store visitor IP addresses in our own application logs. DigitalOcean and its edge provider Cloudflare may process and retain IP addresses and connection metadata to deliver and secure the service. Their precise retention periods for our App Platform setup are not publicly documented.
The edge network sets one strictly necessary cookie, __cf_bm, which lasts 30 minutes and is used to tell bots from people (see the cookie policy). We set no cookies of our own on this website. It loads no third-party fonts, scripts or content, except the analytics script if you consent (see next section).
Analytics on this website (only with consent)
If you click "Accept" in the cookie banner, or switch on "Statistics" in the cookie settings, we use Plausible Analytics to measure how this website is used. Plausible is provided by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia, which processes the data on our behalf in the EU.
- Data: pages viewed (the full page address, including any parameters in it), referring website, campaign parameters (UTM) in the address, country (derived from the IP address), device type, browser and operating system, how far you scroll and how long a page is in view, and the custom events "Signup CTA" (signup-button clicks), "Docs link" (documentation-link clicks) and "Sandbox run" (successful sandbox runs, without text, question, options or answer). Plausible does not store your IP address or user agent. To tell visits apart for one day only, it computes a hash of IP address, user agent and our domain with a salt that is deleted every 24 hours. Plausible sets no cookies, writes nothing to your browser's storage (its script only reads the entry
plausible_ignore, used to exclude a site owner's own browser) and builds no profiles across websites or days. We only ever see aggregated figures. - Purpose: understanding which pages and sources bring visitors, so we can improve the website.
- Legal basis: your consent, Article 6(1)(a) GDPR, and, for access to your device by the analytics script, § 25(1) TDDDG.
- Withdrawal: you can withdraw consent at any time with effect for the future, via the "Cookie settings" link at the bottom of every page. If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not load the script.
- Retention: Plausible stores an individual record for each page view, each custom event and each measurement of scroll depth and time on page (without IP address, user agent or cookie identifier) and shows us aggregated reports; we only use the aggregated reports. The records are kept as long as our website is set up in our Plausible account; when we stop using Plausible, we delete the site and with it all records.
We store your choice in your browser's local storage (jein-consent) so we do not ask again on every page. Details are in the cookie policy at https://jein.dev/cookies/.
Website sandbox
You can try Jein on this website without an account. For this public sandbox, Jein is the controller: you are a visitor, not a customer, and no customer Data Processing Agreement applies.
- Data and retention: your browser sends the text, question and options you type to our API, which returns the answer. We process this content and the answer in memory only for the duration of the request; we never store or log them or use them to train models. No account or usage-metering record is created. Operational metadata is logged as described under "Application logs".
- IP address: to protect the sandbox against overload, we count requests per IP address in the server's memory. These counters are never written to disk or logs and disappear when the server restarts or when newer entries replace them.
- Purpose and legal basis: showing how the service works and protecting it from abuse, Article 6(1)(f) GDPR (our legitimate interests).
- Recipients: DigitalOcean and its edge provider Cloudflare, as for the API; see "Visiting this website", "Recipients and processors" and "Transfers to third countries" for hosting, connection metadata and transfer safeguards.
Please don't enter personal data. If you consent to statistics, a successful sandbox run also sends the "Sandbox run" event described above; it contains no text, question, options or answer.
Cookies and similar storage
The dashboard uses only cookies and storage that are strictly necessary or that remember a setting you chose (colour theme, code-sample language). They are allowed without consent under § 25(2) No. 2 TDDDG. The full list with names, purposes and lifetimes is in our cookie policy at https://jein.dev/cookies/.
Your account and login
To create an account and sign in you use Auth0, an identity service of Okta, Inc., San Francisco, USA, which acts as our processor.
- Data at Auth0: your e-mail address, whether it is verified, your password (stored only as a hash by Auth0) and login events (time, IP address, browser details, success or failure). Auth0 sends the e-mails for address verification and password reset.
- Data in our database: your e-mail address, the verification state, the Auth0 user id ("subject"), the creation date of your account and login, which version of our Terms of Service you accepted and when, and, if you came to the signup through one of our announcement or ad links, the short label in that link (for example
reddit-ml; only lowercase letters, digits and hyphens, at most 32 characters). - Purpose: creating and running your account, signing you in securely, sending service messages about your account, proving that you accepted the Terms, counting which of our announcements and ads lead to signups (with the link label), and protecting logins against attacks (Auth0's attack protection uses your IP address and a device identifier).
- Legal basis: Article 6(1)(b) GDPR (performance of the contract). For the record of your acceptance of the Terms, Article 6(1)(f) GDPR; our legitimate interest is being able to prove the contract terms. For protecting logins against attacks, Article 6(1)(f) GDPR; our legitimate interest is secure accounts. For the link label, Article 6(1)(f) GDPR; our legitimate interest is knowing which announcements and ads bring new customers. It is deleted with your account. If you use Jein for a business that is our customer (for example as its employee) and are not yourself the contracting party, the legal basis for this section and for the sections "API keys" and "Usage metering" is Article 6(1)(f) GDPR instead of Article 6(1)(b): our legitimate interest in performing our contract with that business.
- Retention: until you delete your account. When you delete it in the dashboard, we delete your e-mail address and your login record from our database immediately and delete your user at Auth0 without undue delay, at the latest within one month (automatically where this is set up, otherwise by hand). Until your Auth0 user is deleted, your Auth0 user id is kept in a separate deletion work list, and it is removed from that list as soon as the deletion at Auth0 is complete. While it is on that list, a new signup or login with the same Auth0 login is refused, so that a new account cannot take over a login that is about to be deleted. Auth0 keeps its login event logs for a few days only, according to our plan (at most 30 days).
API keys
For each API key we store its name, a public prefix, a one-way hash of the key (never the key itself), who created it, and when it was created, last used and revoked.
- Purpose: authenticating API requests, letting you manage your keys.
- Legal basis: Article 6(1)(b) GDPR.
- Retention: until you delete your account. On deletion all API keys are deleted at once.
Our role for request content
This section covers requests made through a customer account, via the API or dashboard playground. For input and answers in the public website sandbox, Jein is the controller as described under "Website sandbox" above.
For customers acting as controllers under the GDPR, we process request content as a processor on their behalf (Article 28 GDPR), under the Data Processing Agreement (https://jein.dev/dpa/). The customer is responsible for its legal basis and its privacy notice to the people concerned.
For purely personal or household use, you are not a controller subject to the GDPR for that activity (Article 2(2)(c)). We remain subject to the GDPR as the service provider (recital 18) and process your request content as a controller, solely to return the response. The legal basis for processing your personal data for this purpose is Article 6(1)(b) GDPR (performing our contract with you). Please avoid including other people's personal data in personal-use requests: your contract with us is not, by itself, a legal basis for processing their data. We do not require personal data in request content.
In both roles, content and answers are processed in memory for the request only, never stored or logged and never used to train models. The recipients, international-transfer safeguards and security measures described below apply in both cases.
Processing of API requests
When you as a customer send a request to the API from your software, or you run one in the dashboard playground, we process the content you send (state, instructions, questions) and return the answer. Our role depends on your use, as explained under "Our role for request content" above.
- The content and the answer are held in memory only for the duration of the request. We never write them to a database, a file or a log, and we do not use them to train models.
- To protect the API, the login and the signup against overload, we count requests per IP address in the server's memory. These counters are never written to disk or logs and disappear when the server restarts or when newer entries replace them. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a stable and secure service.
Usage metering
For each customer API request that the model processes we record: account id, API key id (none for playground runs), request id, model, number of questions, token counts, processing time, whether the client disconnected, and the time. We also keep monthly totals per account.
- Purpose: enforcing the free monthly quota, showing you your usage, capacity planning and, once paid plans exist, billing.
- Legal basis: Article 6(1)(b) GDPR for the quota, the usage display and billing; Article 6(1)(f) GDPR for capacity planning (our legitimate interest in providing enough capacity; you can object, see "Right to object").
- Retention: while your account exists; after deletion as described under "After you delete your account". Once paid plans exist, records relevant to invoices are kept for the periods required by tax and commercial law (§ 147 AO, § 257 HGB; 8 or 10 years).
After you delete your account
When you delete your account, we delete all API keys and per-request usage records at once.
When you delete your account, we delete your e-mail address and login record at once. Copies in our database backups are overwritten automatically within 7 days; we use backups only to restore the service, and after a restore we repeat all deletions. If we have to keep a copy of the database as evidence of a security incident, we never restore it into the service, and we delete it once the incident is closed, at the latest after three months.
We keep the monthly usage totals for capacity statistics and planning, and the account record, marked as deleted, with its creation and deletion dates. We keep a deletion record with the date and the number of records deleted and kept for proving and, after restoring a backup, repeating the deletion. These records are pseudonymous personal data and are kept at most 24 months after the account deletion; then we delete these records. They carry only the internal account id.
These records are pseudonymous personal data, not anonymous: they no longer contain your e-mail address, but they are still linked by internal ids. Until your Auth0 user is deleted (at the latest one month after the account deletion), the deletion work list also links the account id to your Auth0 user id; that link is removed as soon as the deletion at Auth0 is complete. Until then we can still find these records from your Auth0 login. Afterwards we normally cannot find them from your e-mail address alone; we can link them to you only if you give us information that identifies them, for example your internal account id (Article 11(2) GDPR).
- Purpose: capacity statistics and planning, and, for the deletion record, proving and, after restoring a backup, repeating the deletion.
- Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is planning capacity and being able to prove deletions; you can object (see "Right to object").
- Retention: at most 24 months after the account deletion; then we delete these records. Once paid plans exist, records relevant to invoices are kept for the periods required by tax and commercial law instead.
Application logs
Our servers write a log line for each request: time, request and trace ids (including a request id your software sends, if it is a UUID or ULID), method and route, status code, error code and error description, duration, where applicable model and token counts, and the internal ids of the account, API key and user involved. The logs contain no IP addresses, no user agents, no e-mail addresses and no request content.
- Purpose: operating the service, finding errors and detecting misuse.
- Legal basis: Article 6(1)(f) GDPR. Our legitimate interest is a secure, working service.
- Retention: the logs are shown in our hosting provider's live log view and are not stored beyond it; we do not forward them to any log storage.
Contacting us
If you e-mail us, we process your e-mail address, name if given, and the content of your message to answer you. If a message contains content of API requests with personal data of other people, we use it only to answer you and delete it once your request is closed, unless the law requires us to keep it.
- Legal basis: Article 6(1)(b) GDPR if your message concerns your contract or its preparation, otherwise Article 6(1)(f) GDPR (our legitimate interest in answering enquiries).
- Retention: three years after the end of the year of our last exchange (the regular limitation period, §§ 195, 199 BGB), unless a longer statutory period applies. Content of API requests with other people's personal data is deleted earlier, once your request is closed (see above).
Recipients and processors
We share personal data only with the service providers below, who process it on our behalf under data processing agreements (Article 28 GDPR), or where we are legally required to (for example to authorities on a court order).
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC, USA | Hosting of website (static files via DigitalOcean's content delivery network), API and database | Frankfurt, Germany (website files: edge locations near you) |
| Cloudflare, Inc., USA (engaged by DigitalOcean) | Edge network: receives connections, bot protection | Location nearest to you |
| Okta, Inc. (Auth0), San Francisco, USA | Login and account e-mails | See transfers below |
| Plausible Insights OÜ, Tartu, Estonia | Website analytics, only with consent | EU |
The current list of subprocessors for the API is at https://jein.dev/subprocessors/.
Transfers to third countries
Our servers and database are in the EU. DigitalOcean, Cloudflare and Okta are US companies, so access from the USA cannot be ruled out (for example for support or under US law); Cloudflare receives connections at the location nearest to you, which can be outside the EU, and Auth0 stores identity data in the region of our Auth0 tenant (see https://jein.dev/subprocessors/). DigitalOcean, Cloudflare and Okta were listed as active in the official DPF list on 25 September 2026 (Cloudflare: active; re-certification under review). Okta's entry covers Auth0, LLC and Auth0 International LLC. The European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework on 10 July 2023 (Article 45 GDPR). In addition, the data processing agreements of DigitalOcean and Okta include the EU Standard Contractual Clauses (Article 46(2)(c) GDPR); for Cloudflare they apply under DigitalOcean's agreement with Cloudflare. You can ask us for a copy of these safeguards at privacy.jein@snblago.com. Plausible transfers no data outside the EU.
Your rights
You have the right to:
- access your personal data and receive a copy (Article 15 GDPR);
- have inaccurate data corrected (Article 16);
- have your data erased (Article 17). You can delete your account yourself in the dashboard at any time;
- restrict processing (Article 18);
- receive the data you provided in a structured, machine-readable format (Article 20). We send an export on request by e-mail;
- withdraw consent at any time with effect for the future (Article 7(3)), for analytics via "Cookie settings";
- object to processing, as described in the next section (Article 21).
Send requests to privacy.jein@snblago.com. We answer within one month. We may ask you to confirm your identity, usually by writing from the e-mail address of your account.
Right to object
If we process your personal data on the basis of Article 6(1)(f) GDPR (legitimate interests), you have the right to object at any time, on grounds relating to your particular situation (Article 21(1) GDPR). We will then stop the processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. To object, write to privacy.jein@snblago.com.
We do not use personal data for direct marketing.
Right to lodge a complaint
You can complain to a data protection supervisory authority (Article 77 GDPR), in particular in the EU member state where you live or work or where the alleged infringement took place. The authority responsible for us is:
Die Sächsische Datenschutz- und Transparenzbeauftragte
Postfach 11 01 32, 01330 Dresden, Germany
Website: https://www.datenschutz.sachsen.de
No automated decision-making
We make no decisions about you that are based solely on automated processing, including profiling (Article 22 GDPR). The answers the API returns are produced for our customers, who decide how to use them.
Do you have to provide data?
You are not legally obliged to provide personal data. Your e-mail address is, however, required to conclude and perform the contract for your account: we use it to sign you in and to send you messages about the contract. Without it we cannot create an account, so you cannot use the dashboard or create API keys.
Security
We protect personal data with technical and organisational measures, including: encryption in transit (TLS) for all public connections, encrypted and signed session cookies, API keys stored only as hashes, row-level access control in the database so each account sees only its own data, hosting in the EU, and no storage of request content. The measures are described in Annex 1 of our Data Processing Agreement (https://jein.dev/dpa/).
Changes to this policy
We update this policy when our processing or the law changes. The date at the top shows the latest version. If a change affects your account significantly, we will tell you by e-mail.