Skip to content
NEXDIARY

Legal

Privacy policy

In short, so you don't have to read it all: this website sets no cookies, counts no visitors and loads not a single file from another server. Fonts, pictures, scripts and the film on the home page all live here. Exactly one thing is stored on your device, and only if you choose it yourself: whether you want the page light or dark.

1. Controller

The controller for data processing on this website under the General Data Protection Regulation (GDPR) is:

Projekt Nexapps, nexdiary
Email: contact@nexapps.dev

No data protection officer has been appointed; the conditions of § 38 BDSG are not met.

2. Hosting

This website is hosted by:

ALL-INKL.COM, Neue Medien Münnich
Owner René Münnich
Hauptstraße 68
02742 Friedersdorf, Germany

The host processes the data that arise when the website is called up on my behalf, based on a data processing agreement under Art. 28 GDPR. The servers are in Germany; no data is transferred to third countries.

3. Server log files

When this website is called up, the server automatically collects information your browser sends and stores it in log files:

  • IP address of the requesting device
  • date and time of the request
  • name and address of the file requested
  • amount of data transferred and whether the request succeeded
  • the page visited before, if your browser sends it
  • browser, version and operating system

Purpose: delivering the website, operational security, troubleshooting and fending off attacks.
Legal basis: Art. 6(1)(f) GDPR. The legitimate interest lies in providing the website in a technically sound and secure way.
Retention: the logs are deleted after seven days at the latest. If they are needed to clear up a specific incident, they are kept until it is resolved.

This data is not combined with other data sources and not used to identify you as a person.

4. What is stored on your device

No cookies. This website sets none, neither its own nor anyone else's.

One entry in local storage, only when you trigger it. When you click the light or dark button at the top, the page stores your choice under the name nd-theme in your browser's local storage. The value is exactly one of the words light or dark. It contains no identifier, is never sent to a server and serves only to show the page the way you set it on your next visit.

As long as you don't press the button, nothing is stored and the page follows your device's setting. You can delete the entry at any time in your browser settings by removing the site data for this address.

Under § 25(2) no. 2 TDDDG, no consent is required for this storage, because it is strictly necessary to provide a service you explicitly asked for: you chose the appearance yourself. Beyond that there is no storage and no access to information on your device, which is why this page has no consent dialog.

The language switch remembers nothing. It is an ordinary link to a second page. The copy button on code examples puts the text into your clipboard and nowhere else.

5. No audience measurement

There is no analytics and no usage tracking, neither with a tool of our own nor with anyone else's. No tracking pixel, no statistics software, no visitor profiles.

6. No content from other servers

No fonts, map services, video platforms, ad networks or third-party scripts are embedded. The film at the top of the home page, too, is no embedded video: your browser draws it from files on this server as you scroll. It stores nothing and sends nothing anywhere. When you call up this website, your browser connects to no other server.

Links to other projects are ordinary links. Only when you click one does its operator learn of your visit, and then their privacy policy applies.

7. Contact by email

If you write to me, I process your address and the content of your message to answer it. The legal basis is Art. 6(1)(f) GDPR, and for an enquiry about a contract also (b). I delete the message once it is dealt with and no retention duty stands in the way.

8. The application itself

This policy applies to this website. It does not apply to nexdiary as an application: that runs on your own server, and you are then responsible for it. There is no version run by us, no account with us and no place where diaries, photos or any other data of your family could end up with us.

Since you, as the operator, are the controller, it needs saying when nexdiary connects to the outside. By default nexdiary asks GitHub for the newest version, at most once a day and only when someone opens the page “About nexdiary”. Only that request goes out, with your server's address, but without names, accounts, entries or settings. As the operator you can switch it off on that same page.

Reminders and a few notices arrive by Web Push as soon as a person signs up a device for them. The message goes encrypted to the push service of their browser, that is to Google, Mozilla, Apple or Microsoft. The service sees the time, the size and the device, but not the content. It never holds an entry; it may name the question of the day, the name of whoever sent a time capsule, and the network of a new sign-in.

Everything else is off by default or needs an address that you enter yourself: your mail server for invitations, reset links and the notice of a new sign-in, your sign-in provider over OpenID Connect and, if you use the button for it, once your authentik, in which nexdiary creates the provider and the application. No AI service is set up by default. If you enter one, a press of the button sends it the notes of one day with their times, without names, date, photos or values, and summing up sends the pages of a week or a month. Without a press of the button something goes out only if you and the person have both switched on writing up automatically in the morning; a local model on your own network keeps everything in the house. Immich is closed by default. If you open it, nexdiary talks to the Immich a person connects themselves and sends nothing from the diary. What each provider does with the data is in their terms.

9. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Contact the address above for this.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), for example the data protection authority responsible where you live.

10. Changes

If something about the website changes, this policy will be adjusted. You will always find the current version at this address.