Privacy Policy
Last updated: March 2026
1. Privacy at a Glance
This website does not use analytics or advertising tracking. All fonts are hosted locally — no connections to Google Fonts or other CDN services are established. Technically necessary connections are made for hosting, payment processing, and licence delivery via the service providers listed below.
2. Data Controller
LokalSkribe UG (haftungsbeschränkt)
Managing Director: Martin Schmid
Zirlerstraße 4
82194 Gröbenzell
Germany
Email: support@lokalskribe.eu
3. Hosting
This website is hosted by Hostinger International Ltd., 61 Lordou Vironos str., 6023 Larnaca, Cyprus. When you visit the website, information (e.g. IP address, time of access) is automatically stored in server log files. This serves to ensure smooth operation and IT security. Legal basis under Art. 6(1)(f) GDPR (legitimate interests).
4. Payment Processing (Stripe)
For checkout and payment processing, we use Stripe (Stripe Inc., 354 Oyster Point Blvd, South San Francisco, CA 94080, USA). When you make a purchase, the following data is transmitted to Stripe: name, email address, billing address, payment details (credit card data etc.) and session/transaction identifiers. Stripe processes this data to execute the payment and prevent fraud. As Stripe is based in the USA, personal data may be transferred to the USA. Stripe is certified under the EU–U.S. Data Privacy Framework. Legal basis under Art. 6(1)(b) GDPR (performance of a contract). Stripe's privacy policy: stripe.com/privacy.
5. Order Processing & Licence Management (Cloudflare Worker)
For checkout creation, licence assignment, download delivery, and confirmation email dispatch, we use Cloudflare Workers (Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA). Data processed includes: email address, session and order identifiers, licence data, IP address, and the consent to waive the right of withdrawal. As Cloudflare is based in the USA, personal data may be transferred to the USA. The transfer is based on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Legal basis under Art. 6(1)(b) GDPR (performance of a contract).
6. Email Delivery (Resend)
For sending the purchase confirmation and licence key, we use the email service Resend (Resend Inc., USA). Your email address and the content of the confirmation email are transmitted to Resend. As Resend is based in the USA, personal data may be transferred to the USA. The transfer is based on Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR. Legal basis under Art. 6(1)(b) GDPR (performance of a contract). For more information: resend.com/privacy
7. Optional Crash Reporting (Sentry)
The LokalSkribe desktop software offers an optional crash reporting feature that is disabled by default and can be enabled by the user in the settings (opt-in). When enabled, only technical data is transmitted: error messages, operating system version, GPU model, and software version. No audio content, transcription text, file names, or other personal data is transmitted. Data is processed via Sentry (Functional Software Inc., USA) and stored in the EU (Frankfurt, Germany). The user can disable this feature at any time in the settings. Legal basis under Art. 6(1)(a) GDPR (consent).
8. Retention Periods
Server logs (Hostinger): Access data is automatically deleted after 30 days.
Purchase data (Stripe): Transaction and payment data is retained for the duration of the statutory retention obligation (10 years under German tax law, §§ 147 AO, 257 HGB).
Licence data (Cloudflare KV): Licence keys, email addresses and associated activation data are retained for the duration of the contractual relationship and subsequently for the duration of the statutory retention obligations.
Crash reports (Sentry): Technical error reports are retained for a maximum of 90 days.
9. Locally Hosted Fonts
This website uses the "Inter" typeface, which is hosted locally on our server. No connections to external servers (such as Google Fonts) are established. No personal data is transmitted to third parties when fonts are loaded.
10. SSL Encryption
This website uses SSL encryption for security reasons. An encrypted connection can be identified by "https://" in your browser's address bar and the padlock symbol.
11. Your Rights under GDPR
You have the following rights as a data subject:
Access (Art. 15 GDPR): You may request information about your stored personal data.
Rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
Erasure (Art. 17 GDPR): You may request the deletion of your data.
Restriction (Art. 18 GDPR): You may request the restriction of processing.
Data portability (Art. 20 GDPR): You may receive your data in a machine-readable format.
Objection (Art. 21 GDPR): You may object to the processing of your data.
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority.
The competent supervisory authority is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
For users in the United Kingdom: The UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018) applies in addition. The rights described above apply equally under UK GDPR.
12. Changes to this Privacy Policy
We reserve the right to update this privacy policy as necessary to reflect current legal requirements or changes to our services.