Skip to content

Legal

Privacy Policy

What we store, why we store it, where it lives, and how you get rid of it.

Last updated August 9, 2026

Who is responsible

The controller under the GDPR is LL Platforms UG (haftungsbeschränkt), Wuhlestraße 7 a, 12683 Berlin, Germany. You can reach us at support@cotscreener.com. We have not appointed a data protection officer. We are not required to.

The short version

  • We show no ads and we never sell data.
  • No analytics, no tracking cookies. Only essential session cookies.
  • Account data is stored in the EU, in Frankfurt, Germany.
  • We email you about your account, and otherwise only what you asked for or agreed to.
  • You can delete your account and its data yourself, at any time.

Visiting the site

Our infrastructure runs on Cloudflare. When you open a page, the server processes technical data: your IP address, browser type, the requested page and a timestamp. We use it to deliver the site and to keep it secure, for example against attacks. The legal basis is our legitimate interest in a working, safe service (Art. 6 (1) (f) GDPR). Log data is kept briefly and then deleted.

Cloudflare is operated by Cloudflare, Inc., USA. Transfers to the USA rest on the EU-US Data Privacy Framework and on standard contractual clauses.

Your account

When you create an account we store your email address and your password. The password is stored only as a hash. We never see the plain text. If you use the app, we also store what you set up there: your display name if you add one, your watchlist, your alerts and your settings. We need this data to provide the service, so the legal basis is the contract with you (Art. 6 (1) (b) GDPR).

The database runs on Supabase. Our project is hosted on AWS in Frankfurt, Germany (eu-central-1). Supabase, Inc. is a US company. We have a data processing agreement with standard contractual clauses in place.

Your data stays until you delete your account under Settings. Deleting the account removes your profile, watchlist, alerts and settings.

Signing in with Google

You can sign in with a Google account instead of a password. This is optional. If you use it, we receive your email address and a stable account identifier from Google Ireland Limited. The legal basis is the contract (Art. 6 (1) (b) GDPR). Google processes its own data under the Google privacy policy.

Emails we send

We send account emails, for example to confirm your address or to reset your password. If you set up alerts, we send the alert emails you asked for. The legal basis is the contract (Art. 6 (1) (b) GDPR). We send these emails through Resend, Inc., USA, under standard contractual clauses.

The Friday brief

The Friday brief is our weekly newsletter, and anyone can subscribe without an account. It runs on consent (Art. 6 (1) (a) GDPR), collected through double opt-in: entering your address only creates a pending entry, and you receive nothing until you click the link in the confirmation email.

For a subscription we store your email address, whether it is pending, confirmed or unsubscribed, a random token that identifies your confirmation and unsubscribe links, and the times of those steps. We need the confirmation timestamp to prove that consent was given, which the GDPR requires of us (Art. 7 (1)).

Every issue carries a one-click unsubscribe link. When you use it we stop sending immediately and mark the entry as unsubscribed rather than deleting it, so the address cannot be added again by accident and so we can still show when the consent existed and when it ended. If you would rather have the entry erased entirely, write to us and we will do that.

If you have an account, the brief runs on your account instead of on a separate subscription. You turn it on with the checkbox when you sign up, or later under Settings, and you can turn it off again in the same place.

Emails about the product

If you agree to it, we send occasional emails about the product itself: new features, tips for getting started, and offers on the Pro plan. These run on consent (Art. 6 (1) (a) GDPR), you choose them yourself, and every one of them has an unsubscribe link. Saying no changes nothing about your account, and we do not send them to anyone who has not agreed.

We store when you agreed to the brief and to these emails, whether that was at sign-up or in Settings, and when you last turned them off again. We keep that record because the law asks us to prove consent was given (Art. 7 (1) GDPR). It disappears with your account.

Upgrading to Pro

Paid subscriptions are processed by Paddle as merchant of record. The checkout is run by Paddle.com Market Limited, London, or Paddle Payments Limited, Dublin, for EU customers. Paddle is your contract partner for the purchase and processes your billing and payment data under its own responsibility. We never see your full payment details. We only receive the status of your subscription. Details are in the Paddle privacy policy.

Cancelling a contract

If you cancel through the cancel contract page, we store your name, your email address, the cancellation type, an optional reason, an optional end date and the time of receipt. German law requires this page and the confirmation (§ 312k BGB), so the legal bases are our legal obligation (Art. 6 (1) (c) GDPR) and our interest in documenting the cancellation (Art. 6 (1) (f) GDPR). We keep these records for the statutory limitation period.

Writing to support

If you email us, we process your address and the content of your message to answer it. The legal basis is the contract or our legitimate interest in handling requests (Art. 6 (1) (b) and (f) GDPR).

Cookies and local storage

We set only essential cookies. They keep you signed in and expire with your session. Essential cookies need no consent banner (§ 25 (2) TDDDG), which is why you never see one here. Interface preferences, for example collapsed chart panels, stay in your browser’s local storage and are never sent to us. We use no analytics and no third-party trackers.

International transfers

We prefer EU infrastructure. Where a provider is a US company (Cloudflare, Supabase, Resend, Google), transfers rest on the EU-US Data Privacy Framework and on standard contractual clauses, as described above.

How long we keep things

  • Your account and everything in it stays until you delete it. Deleting the account removes it immediately.
  • Newsletter entries stay while you are subscribed, and after an unsubscribe we keep the entry as the record of when the consent existed. Ask us and we erase it.
  • Cancellation records stay for the statutory limitation period, because they document a legal declaration.
  • Server logs are kept only as long as they are useful for running and defending the service, then deleted.
  • Support emails stay as long as the conversation needs, and are deleted once it is settled and nothing legal requires keeping it.

Where German commercial or tax law requires longer retention, that applies instead, and the data is then only kept, not used.

Your rights

  • Access to the data we hold about you (Art. 15 GDPR).
  • Correction of wrong data (Art. 16 GDPR).
  • Deletion (Art. 17 GDPR).
  • Restriction of processing (Art. 18 GDPR).
  • Data portability (Art. 20 GDPR).
  • Objection to processing based on legitimate interest (Art. 21 GDPR).
  • Objection to direct marketing at any time, with no reason needed and no consequences (Art. 21 (2) GDPR). We then stop immediately.
  • Withdrawal of any consent, effective for the future (Art. 7 GDPR).

Email support@cotscreener.com to exercise any of these rights. You can also complain to a data protection authority (Art. 77 GDPR). Our registered office is in Hamburg, so our authority is the Hamburg Commissioner for Data Protection and Freedom of Information. Your local authority works too.

What we do not do

No automated decision-making, no profiling, no sale of personal data, no ads.

Security

All traffic is encrypted with TLS. Passwords are stored as hashes. Access to production data is limited to what running the service requires.

Changes

We update this policy when the service changes. The date at the top tells you the current version. If a change matters for you, we point it out in the app or by email.

Privacy Policy — COT Screener