Skip to content
Denkraum.
DeutschEnglish
← Back to app

Privacy

Updated: October 9, 2026Version 1.28-demo

Controller and contact

Controller
AnaOpti GmbH
Address
Berger Straße 175 60385 Frankfurt am Main Germany
Email
info@anaopti.com
Privacy contact
datenschutz@anaopti.com

1. Scope and internal demo

Denkraum is an internal demo without production approval. Use only fictional or anonymised content for chats, files and dictation, including names and metadata. A recognisable voice is not anonymised merely because the spoken content is fictional. We process real account, contact and connection data as described here.

2. Account and sign-in

For your account we process your chosen display name, email address, account identifier, password hash, confirmation and reset requests, session start, last activity and a broad browser and operating system category. We do not store readable passwords. These details are required for the account and requested features; an account is not possible without them (Article 6(1)(b) GDPR).

For optional two-factor authentication we store the secret in encrypted form and recovery codes as hashes. For passkeys we store the public key, identifier, chosen name and technical usage information. We do not receive your device's private keys or biometric data. The legal basis for these sign-in features is Article 6(1)(b) GDPR.

For API access you create, we store the key hash, name, owner, selected permissions, expiry, last use and security confirmation; for organisation access we also store the organisation. The readable key is displayed once. Revocation or expiry blocks it; records are cleaned up when a subsequent session is created. Security logs have their own retention periods.

3. Organisations and company sign-in

For collaboration we store organisation names, memberships, roles, teams, team leads, permissions, invitation addresses, security policies and AI settings. These details come from you, authorised people or your organisation's technical user management. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure collaboration with controlled access rights.

For company sign-in (SSO), we receive your user identifier and verified email address from the selected identity provider. The stored account link enables your sign-in (Article 6(1)(b) GDPR). The provider's privacy information applies to that provider. Authorised organisation administrators can see their organisation's memberships and security events, but not private chats.

Pending invitations and your “Decide later” choice are stored on the server against your account email address. They remain available after sign-in on other devices. Invitation codes are not saved in persistent browser storage; membership is created only when you explicitly join.

4. Chats and shared files

We store chat titles, messages, AI replies, processing status, timestamps, model, confidentiality level and source evidence. Chats belong to your account within the selected organisation. Other members and organisation administrators cannot read them through the app.

For personal and shared content within an organisation we store file and folder names, original files, extracted text, search index, processing status, timestamps, confidentiality levels, AI access settings, authors and file sharing settings. Organisation permissions, personal visibility, team membership and parent folders jointly determine access. Processing chats and files serves the requested features (Article 6(1)(b) GDPR).

Text extraction and optical character recognition in images (OCR) take place on our server. Originals remain available to download. Transfer to AI follows the rules below.

Persistent API jobs store the request ID, input, file selection, access reference, status and progress. They may continue after disconnection and can be explicitly cancelled. The job input is removed on completion; the request ID, status and saved chat reply remain until the chat or account is deleted.

5. AI providers and automatic selection

Denkraum uses the OpenAI API and AI hosting by Mittwald CM Service GmbH & Co. KG. By default, “Unrestricted” uses OpenAI; “Confidential” and “Strictly confidential” use mittwald. Owners and administrators can change this assignment; the model is shown in the chat. The level guarantees neither data location nor approval under data protection law.

The highest level of accessible file sources and previous chat sources determines the provider for the entire request. New chats without file sources start as “Unrestricted”. Deselecting, deleting or downgrading a source does not lower the chat's level. If the assigned provider is unavailable, there is no automatic provider switch.

The provider receives the input, required conversation context and sources read, which may include file names, paths, text passages, calculations, images and PDF pages. Transfer from our server is encrypted. Display name, account email address and visitor IP address are not attached automatically; information within the content is transmitted with it. The provider sees the server connection; API keys remain on the server. Linking to the account and providing the AI feature are based on Article 6(1)(b) GDPR.

According to mittwald, models run on its own infrastructure; inputs and replies are neither stored nor used for training. For billing and operation, mittwald processes the server IP address, API key, request time and token count: https://developer.mittwald.de/de/docs/v2/platform/aihosting/access-and-usage/data-protection/.

Under OpenAI's contractual terms, OpenAI Ireland Ltd. is the contracting party for customers in the European Economic Area. The data processing agreement forms part of those terms and provides for adequacy decisions or EU standard contractual clauses for transfers to third countries: https://openai.com/policies/data-processing-addendum/. We use the global API endpoint; exclusively European processing is not guaranteed.

OpenAI does not use API content for training by default unless data sharing is enabled. For chat replies and dictation transitions we disable retrievable response storage. Abuse monitoring logs may nevertheless contain content for up to 30 days, or longer where required by law or security needs; encrypted prompt caches may retain it for up to 24 hours. For audio transcription, OpenAI states that content is not stored in abuse monitoring logs or as application state. Images suspected of depicting child sexual abuse may be retained for manual review. Neither Zero Data Retention nor a particular data region has been established for this demo: https://developers.openai.com/api/docs/guides/your-data/.

Contractual documentation for OpenAI and mittwald is not yet available. Only fictional or anonymised content data is permitted. The app does not anonymise automatically; replacing names is insufficient where people remain identifiable. File and model approvals are technical settings, not consent under data protection law.

Changes to model assignments or confidentiality levels may terminate ongoing requests. Content already transferred cannot be retrieved; deletion in the app does not end the provider's retention periods.

External links in AI replies open only after your confirmation. The destination website then receives your IP address and technical connection data; its privacy information applies. External images are not loaded automatically.

6. Dictation

After you start dictation and grant microphone access, the browser detects speech segments locally and sends them encrypted through our server to the organisation's dictation provider. Owners and administrators choose mittwald or OpenAI; mittwald is the default. Speech recognition and sentence transitions use the same provider, independently of the chat model and without automatic switching. The browser runtime and segment detection models come from our server. The legal basis is the requested text input (Article 6(1)(b) GDPR).

The transcription model receives audio and up to 500 characters of the previous dictation. For punctuation and capitalisation at the transition, a text model from the same provider receives that context and up to 1,000 characters of the next segment. The text remains an editable draft; only sending it transfers it to the chat model. The storage and transfer information above applies to providers.

Audio remains temporarily in browser and server memory, without files or backups in Denkraum. Processed segments are released; pending segments can be resent after transfer errors while the chat remains open. Changed AI settings prevent further calls from the existing dictation; the browser discards pending audio as soon as it detects the change. “Keep text”, Escape, switching chats or leaving the page also release the buffers. Cancellation does not retrieve content already transferred. The browser storage information below applies to drafts.

7. File access and source evidence

The AI may search and read organisation files with general AI access and files and folders additionally selected for the chat. Selections remain saved until removed; folders also include files added later. Restrictions in parent folders prevent automatic access to files below them, which then require selection. Current permissions and approvals are checked on retrieval.

Text passages read, calculations and page images remain as evidence in the private chat. The complete extracted text version of the file used is also saved with the reply, so evidence can be displayed in its original context. Revoking access or deleting originals does not delete this evidence, these text versions or replies generated from them. Conversation context may transmit the contained information to the AI again. New file retrievals require current permissions and approvals. Delete the corresponding chat to remove saved evidence and text versions.

8. Cookies and browser storage

The “__Host-session” cookie keeps you signed in. It contains a random session key and expires after twelve hours at the latest. After 30 minutes without server-registered activity, the session becomes invalid; signing out also ends it. For passkey sign-in, “__Host-passkey_binding” is additionally set for up to five minutes to bind the process to your browser.

Company sign-in also sets the “__Host-identity_binding” cookie for up to five minutes. Organisation policies may require shorter sessions. The selected organisation, chat drafts and unconfirmed send requests are stored in the tab's session storage so they survive navigation or reloading. Chat drafts are removed when you sign out in that tab; session storage generally ends with the browser session.

When you collapse or expand the desktop sidebar, we save this choice under “denkraum-sidebar” in persistent browser storage (Local Storage). The entry contains only “collapsed” or “expanded”, without account or content data. It remains after sign-out and closing the browser until you replace it with a new choice or clear the website's browser data. This setting is not sent to our server.

Your language choice is saved under “platform-language” in persistent browser storage and in a cookie for up to one year. Your account stores the setting across devices. Without a manual choice, we use German for a German browser language and English otherwise. You can choose the language at any time. Account emails use the saved choice or the request language. The setting contains no content data and can be changed at any time or removed by clearing website data; the account setting remains until changed or the account is deleted.

This storage access is necessary for the features you request (section 25(2), no. 2 TDDDG). Personal data processing for sign-in and use is based on Article 6(1)(b) GDPR. We do not use visitor analytics, advertising trackers or externally loaded fonts.

9. Connection data and security

To establish connections, analyse errors and prevent abuse, we process IP address, time, requested path and technical request and response data. This uses access and error logs and temporarily hashed identifiers for rate limiting. Security events contain time, action, result and affected account or organisation identifiers, some pseudonymised. For organisation changes, we also record changed roles, policies, names, descriptions and team assignments as before/after values or differences. Long texts are replaced by a verification fingerprint; passwords, access keys and chat or file content are excluded from these change records. Pseudonyms are not anonymous data. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is secure, reliable operation.

Web server logs rotate daily; up to 14 archives are retained in addition to the current file. Rotation may be skipped for empty files. The app system journal is limited to 14 days and 200 MB. System and mail logs generally rotate weekly with four archives.

For AI quotas we store provider, account and organisation identifier, time window, reserved and confirmed token counts, audio duration and, where applicable, calculated costs, but no inputs, replies or recordings. During further use, expired bookings and budget windows are deleted in batches after the configured retention period (90 days by default). Active budget windows remain; cleanup is independent of account deletion.

Security events in the app database are deleted in groups: 30 days after the last event in a group, or earlier under high volume. Individual events may therefore remain for longer than 30 days. Cleanup is independent of account deletion.

10. Hosting and account emails

The app, data storage, our own mail server and encrypted backups run on infrastructure in Germany provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen. HTTPS protects the connection. Content is not end-to-end encrypted; authorised server administrators can technically access it.

We send account emails, including confirmation after account deletion you initiate, through our own mail server; the sender is denkraum@anaopti-bond.com, or denkraum-dev@anaopti-bond.com in development. We process recipient address, content and delivery status (Article 6(1)(b) GDPR). Handover to our mail server is encrypted; your email provider receives the message addressed to you. The sending process removes encrypted mail jobs from the app after handover or expiry. Deletion confirmations remain independently of the deleted account for delivery retries, up to the configured delivery period (72 hours by default).

Before a complete rebuild of the demo database, we record affected account email addresses in encrypted form on the operator's device. After a successful rebuild, we explain the reason, relevant changes and how to register again. The personal registration link is valid for 48 hours and can be used once when setting a password. Recipient addresses, links and delivery status are deleted from the operator's device after completed handover to the mail server, or within seven days in case of delivery problems. Passwords, private content and previous organisation permissions are not retained.

Healthchecks.io, operated by SIA Monkey See Monkey Do, Latvia, monitors availability. The service receives the check identifier, status, server IP address, time and connection data, plus the operator's alert address. User email addresses, visitor IP addresses and stored content are not transmitted. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is reliable operation. Subprocessors may process data outside the European Economic Area: https://healthchecks.io/privacy/.

Contractual evidence of data processing agreements is not yet available. The application has no production approval. Even when only test content is used, real account, contact and connection data remains subject to data protection law.

11. Storage and deletion

Private chats, their evidence and text versions are deleted with the chat, your account, your organisation membership or the organisation. Leaving or being removed from an organisation also deletes private file areas and their subfolders. Shared files outside these areas remain until the file or organisation is deleted. Suspension and leaving a team remove access without deleting private content. Deleting an original file does not remove evidence copies or text versions in other members' existing chats. Automatic deletion due to inactivity is not configured. After the database entry is removed, storage cleanup removes originals from active file storage; they are no longer accessible through the app in the meantime.

Before deleting your account you must transfer responsibility for organisations you own or close them. Account deletion removes your memberships, private chats, private files including their subfolders, sessions, passkeys and two-factor data. Shared files in continuing organisations remain. You must delete previously downloaded copies separately.

Regular registration, password reset and email change links are valid for 30 minutes; return links after a complete demo rebuild for 48 hours, and organisation invitations for seven days. Expired process data is cleaned up during subsequent related operations; link expiry therefore does not itself delete the record.

Backups enable recovery after data loss (Article 6(1)(f) GDPR; legitimate interest in reliable operation). Deletion in the app does not retroactively change existing backups. The last 14 app backups, 14 backups per database host and seven mail server backups are retained locally.

Externally, one encrypted backup is retained from each of the last 48 available hourly, 30 daily and twelve monthly periods. Without new backups, older backups may remain for longer than twelve months. Up to seven daily Storage Box snapshots may additionally contain copies of archives already deleted. After restoration, completed deletions and blocks must be reapplied before use resumes.

12. Contact

For enquiries and content reports we process contact details, message content and necessary review information: under Article 6(1)(b) GDPR for contractual matters, point (c) for legal obligations and otherwise point (f) to handle legitimate concerns. We delete the details after completion unless needed for legal obligations or the establishment, exercise or defence of legal claims.

13. Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction of processing and data portability. Contact our privacy contact; the export features do not limit these rights. You can also obtain information and, where applicable, a copy of safeguards for transfers to third countries there.

You may object to processing based on legitimate interests on grounds relating to your particular situation.

You may complain to a data protection supervisory authority, particularly where you live, work or suspect an infringement. Our competent authority is the Hessian Commissioner for Data Protection and Freedom of Information: Postfach 3163, 65021 Wiesbaden, poststelle@datenschutz.hessen.de, https://datenschutz.hessen.de.

We do not make solely automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR.

Legal notice Privacy Terms of use Contact