Privacy Policy
Last updated: June 2026
This Privacy Policy explains how personal data is processed when you use the Sightdeck AI website and purchase or manage a license. It follows the requirements of the EU General Data Protection Regulation (GDPR).
1. Controller
The controller responsible for data processing on this website is:
Christian Dangl
Schlierseestrasse 20
83101 Rohrdorf
Deutschland / Germany
For any privacy-related request, please use the contact form.
2. Data We Process
We process personal data only for the purposes described below.
2.1 Server log files
When you visit this website, the hosting infrastructure automatically records technical data such as your IP address, the requested URL, the date and time of the request, the referring page, and your browser and operating system. This data is required to deliver the site reliably and securely. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a stable, secure service). Log data is not merged with other data sources and is deleted after 14 days.
2.2 Contact form
When you submit the contact form, we process the information you provide (such as your email address and message) solely to handle your request. Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps and contract performance) or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
2.3 Purchase and license data
When you buy a license, your payment is processed by our payment provider Paddle (see section 3). We store the resulting license record — including your email address, the plan purchased, and the transaction reference — to issue and manage your license and to provide the "My licenses" and "Manage subscription" functions. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(c) GDPR (statutory retention obligations for invoices and tax records).
2.4 Desktop application
Sightdeck AI is a local-first desktop application: your tasks, projects, and settings are stored on your own device. Your license is verified entirely offline: the app checks the cryptographic signature of your license code locally on your device and does not contact a license service or transmit your license code to us. All credentials you enter for optional integrations and any AI provider keys are stored encrypted on your device using the operating system's secure storage — the macOS Keychain on macOS, the Data Protection API (DPAPI) on Windows, and the system keyring (libsecret) on Linux — and are not transmitted to us. When you use an integration or an AI provider, the app communicates with that third-party service directly from your machine under the credentials you supplied. The app does not send usage analytics or telemetry to us. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in license integrity).
3. Payment Processing (Paddle)
Payments and subscription billing are handled by Paddle.com Market Limited, which acts as the Merchant of Record for purchases of Sightdeck AI. In plain terms, this means Paddle — not us — is the official seller of record and handles billing, taxes, and payment compliance on our behalf. When you check out, the payment and billing data you enter is processed by Paddle under its own privacy policy. We receive only the data required to issue and manage your license (such as your email address, plan, and transaction reference); we do not receive or store full payment card details. Legal basis: Art. 6(1)(b) GDPR.
4. Disclosure to Third Parties
We do not sell your personal data. Data is shared only with processors that help us run the service (such as our hosting provider and Paddle), and only to the extent necessary for the purposes described above. These processors are bound by data processing agreements as required by Art. 28(3) GDPR.
5. Data Retention
We keep personal data only as long as necessary for the purpose it was collected for, or as long as statutory retention periods require. In particular, invoices and tax records are retained for the legally mandated period (typically 10 years under German tax law); other data, such as contact-form messages, is kept only for as long as needed to handle your request. After the applicable period, the data is deleted or anonymised.
6. Your Rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15 GDPR);
- have inaccurate data corrected (Art. 16 GDPR);
- have your data erased (Art. 17 GDPR);
- restrict processing of your data (Art. 18 GDPR);
- receive your data in a portable format (Art. 20 GDPR);
- object to processing based on legitimate interest (Art. 21 GDPR).
To exercise any of these rights, contact us via the contact form. You also have the right to lodge a complaint with a data protection supervisory authority. The authority competent for the controller is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.
7. Data Security
This website is served over an encrypted TLS/SSL connection to protect data in transit. Please note that data transmission over the internet (for example, by email) can have security gaps; complete protection against access by third parties is not possible.
8. Changes to This Policy
We may update this Privacy Policy to reflect changes to our service or legal requirements. The current version is always available on this page.