Privacy Policy
This is a courtesy translation; in the event of any discrepancy, the German version (âDatenschutzerklĂ€rungâ) prevails.
1. Controller
Constantin Persaud
LindenstraĂe 257
40235 DĂŒsseldorf
Germany
Email: support@typedhand.com
A data protection officer has not currently been appointed.
2. What data we process
In connection with the use of TypedHand we process in particular:
- Account data: email address, authentication data.
- Handwriting samples: the handwritten template files (PDF) uploaded by users, processed exclusively to generate a personal font. These are personal data.
- Generated documents: exported PDF files, insofar as they are created during use.
- Usage data: e.g. monthly export counter, plan.
- Anonymous base reach data (always, no consent required): page view and time on page, device type, referrer/origin URL. This data is collected without a cookie, without local storage and without a recognisable identifier â a page view cannot be linked to a person or to a later visit.
- Statistics/analytics data (only with consent): pseudonymous usage data such as page views, click and scroll interactions, a pseudonymous identifier, approximate origin, device/browser type, and session recordings (mouse/click movements; text inputs are masked and not captured).
- Consent/age data: the confirmation of being at least 16 years old, as well as the consent version and time. The date of birth is only requested for the age check and is not stored after the check.
- Payment data: handled via Stripe.
3. Purposes and legal bases (Art. 6 GDPR)
- Provision of the account, generation of the font and export: performance of the contract, Art. 6(1)(b) GDPR.
- Processing of handwriting samples to create the individual font: Art. 6(1)(b) GDPR; where necessary, explicit consent under Art. 6(1)(a) GDPR.
- Payment processing and retention of invoice data: legal obligation, Art. 6(1)(c) GDPR.
- Security and operation of the application, in particular preventing misuse and errors: legitimate interest, Art. 6(1)(f) GDPR.
- Age check at registration: legitimate interest in legally compliant operation, Art. 6(1)(f) GDPR.
- Anonymous base reach measurement (page views, time on page, device type, referrer) via PostHog: legitimate interest in knowing our advertising and traffic volume, Art. 6(1)(f) GDPR. This measurement happens without cookies, without local storage and without a personal identifier, so § 25(1) TDDDG (which only governs access to information stored in the terminal equipment) does not apply here; consent is therefore not required. You can object to this processing at any time under Art. 21 GDPR (see section 6).
- Any further-reaching reach measurement and product improvement using statistics tools (PostHog, Vercel Web Analytics), including person-level analysis across multiple visits and session recordings: solely on the basis of your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Without consent, no such analysis takes place. You can withdraw consent at any time with effect for the future â via âCookie settingsâ in the footer.
- Ad performance measurement using the TikTok Pixel: solely on the basis of your consent, Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Without consent, the pixel is not loaded. You can withdraw consent at any time with effect for the future â via âCookie settingsâ in the footer.
4. Processors and third-party providers
- Supabase (database, authentication, file storage of handwriting samples, fonts and exports). Processing and storage within the EU/EEA.
- Stripe (payment processing). Processing within the scope of payment handling within the EU/EEA.
- Vercel (hosting of the web application and â only with consent â Vercel Web Analytics for cookieless reach measurement). Processing and storage within the EU/EEA.
- PostHog (product analytics). Runs in two tiers: an anonymous base reach measurement (page views, time on page, device type, referrer, no cookies, no identifier) always, plus â only with consent â usage statistics and session recordings with a pseudonymous identifier. Processing via the EU cloud (Frankfurt, AWS eu-central-1); the provider is PostHog Inc., USA, on the basis of a data processing agreement. The service is called via our own subdomain (t.typedhand.com) as a reverse proxy.
- Cloudflare (tunnel/CDN/security functions, where used). Processing and storage within the EU/EEA.
- TikTok (TikTok Pixel for ad performance measurement and audience building) â only with consent. Provider is TikTok Technology Limited resp. TikTok Information Technologies UK Limited; data transfer to third countries (incl. the USA) is possible and is based on EU Standard Contractual Clauses (Art. 46 GDPR).
5. Retention period and deletion
We store account and handwriting data for as long as the account exists. After deletion of the account, all associated data is fully deleted within 14 days, including uploaded templates, generated fonts and stored export PDFs.
Invoice and accounting-relevant documents are stored for 10 years due to statutory retention obligations and deleted afterwards.
6. Your rights as a data subject
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent given at any time with effect for the future. You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
You can exercise some of these rights directly in your dashboard: âExport my dataâ (Art. 20) and âDelete account and dataâ (Art. 17).
Competent supervisory authority: Landesbeauftragte fĂŒr Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), KavalleriestraĂe 2â4, 40213 DĂŒsseldorf.
7. Minors (Art. 8 GDPR)
TypedHand is aimed exclusively at persons aged 16 and over. At registration we check the date of birth provided. Persons under 16 are blocked server-side; no account is created and no personal data is stored. The date of birth itself is discarded after the age check and not stored; we keep only the confirmation of being at least 16 years old, together with the consent version and time.
8. Cookies and local storage (TDDDG)
On your first visit we ask for your consent via a cookie banner. We distinguish three categories:
- Strictly necessary (always active): storage and access needed for login and session security (Supabase), the language choice (cookie âth_langâ) and to store your cookie decision (cookie âth_consentâ). Legal basis: § 25(2) TDDDG or Art. 6(1)(b) and (f) GDPR. No consent is required for this.
- Anonymous base reach measurement (always active, no consent required): a part of PostHog records page view, time on page, device type and referrer without setting cookies or accessing local storage (technically enforced:
disable_persistence, no person profile). Because nothing is stored on or read from your device, § 25 TDDDG does not apply; the legal basis is legitimate interest in reach measurement, Art. 6(1)(f) GDPR. - Statistics (only with consent): PostHog and Vercel Web Analytics. These services are only loaded and only set cookies or access local storage after you have consented. Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. To recognise you within a session, PostHog stores, among other things, a pseudonymous identifier (cookie âph_âŠâ) with a lifetime of up to 12 months.
- Marketing (only with consent): TikTok Pixel. The pixel is only loaded and only sets cookies after you have consented. Legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. The TikTok Pixel is used to measure ad performance and to build audiences for future ads.
Your cookie decision is stored for 6 months; after that we ask again. You can change or withdraw your consent at any time with effect for the future â via âCookie settingsâ in the footer. Withdrawal is as easy as giving consent.
9. Changes to this policy
Policy version: July 2026.
We adapt this privacy policy when the legal situation, the services used or our data processing change.