Privacy Policy
1. Controller
The controller within the meaning of the GDPR is BrightComb (sole proprietorship), owner Gor Davidovic Gevorkjan, Teichmummelring 65, 12527 Berlin, Germany, email hello@wildcomb.app. No data protection officer has been appointed because there is no legal obligation to do so.
This policy covers brightcomb.com and the calculators run there (BrightComb Compound Simulator). ElternPlan (elternplan.app) is governed solely by the privacy policy published on that site.
2. Principle
We process as little data as possible. There are no ad trackers, no analytics cookies and no sale of data. The calculators work without an account; calculator inputs are not stored, except that Pro calculations are sent to our server and discarded immediately after the response.
3. Hosting and server logs
The site is hosted by Vercel Inc. (USA). On access Vercel processes technically necessary data (IP address, time, requested URL, user agent) in server logs that are deleted after a short period. Legal basis: Art. 6 (1) (f) GDPR (operation and security). Vercel is certified under the EU-US Data Privacy Framework; standard contractual clauses are in place in addition.
4. Cookies
We only set technically necessary cookies that require no consent (§ 25 (2) German TDDDG): language and currency (12 months), sign-in session (30 days, only when signed in) and a “counted today” marker (24 hours, no content, see 5). There is no cookie banner because there is nothing to consent to.
5. Anonymous country statistics
To see which regions show interest, at most once a day per browser we increment a counter for the country of the request. Our hosting derives the country from the network zone; we do not store the IP address. Only the country code and a number are stored. No person can be identified; the statistics are public at /simulator/stats.
6. Account and sign-in
For Pro access we store your email address, the account creation time, the expiry date of Pro access, the Stripe payment reference and your preferred language. Sign-in links are valid for 15 minutes and deleted afterwards. Legal basis: Art. 6 (1) (b) GDPR (contract). Storage: Upstash Redis, Frankfurt data centre (Upstash Inc., processor with standard contractual clauses). Retention: until you ask us to delete the account, at the latest three years after the last Pro access expired.
7. Payment, billing country and consent log
Payments are processed by Stripe Payments Europe Ltd. (Ireland). Stripe receives your payment details, your email address and your billing address and processes them as an independent controller, including for fraud prevention. We receive no full card data from Stripe, only payment status, amount, currency, reference and the country of your billing address. Legal basis: Art. 6 (1) (b) GDPR (contract).
We store the country of your billing address in your account as evidence of the place of supply for VAT purposes and to monitor the distance-selling thresholds (§ 3a (5) German VAT Act, Art. 24b VAT Implementing Regulation). Legal basis: Art. 6 (1) (c) GDPR (legal obligation). In addition we keep an anonymous counter of sales per country and year that contains no personal data.
We log your consent to immediate performance and your acknowledgement of losing the right of withdrawal (§ 356 (5) BGB) with a timestamp and keep it together with the payment record for three years (Art. 6 (1) (c) and (f) GDPR, burden of proof and standard limitation period). Stripe's privacy notice: stripe.com/privacy.
Withdrawal via “Withdraw from contract”
If you declare a withdrawal via the online function, we store your name, email address, your optional details (order reference, message) and the time of receipt in order to confirm receipt and process the withdrawal (Art. 6(1)(b) and (c) GDPR). Storage: Upstash Redis (see 6). Retention: three years (regular limitation period). The acknowledgement of receipt is sent via Resend (see 8).
8. Email
Sign-in links and order confirmations are sent via Resend Inc. (USA, processor with standard contractual clauses). Recipient address, subject, content and delivery status are processed. We send no marketing emails. You receive a reminder before Pro access expires only if you opted in within your account.
9. Market data
Our server fetches macro data from FRED (Federal Reserve Bank of St. Louis); year-end values of indices, gold and bitcoin are stored as a static table. No user data is transmitted in the process.
10. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection (Art. 15 to 21 GDPR) and the right to lodge a complaint with a supervisory authority, e.g. the Berlin Commissioner for Data Protection and Freedom of Information. We delete account and data on an informal email to hello@wildcomb.app, unless retention obligations apply (invoice and tax data: ten years, § 147 German Fiscal Code).
Data subjects in the United Kingdom have equivalent rights under the UK GDPR and the Data Protection Act 2018 and may contact the Information Commissioner's Office (ICO). For residents of the United States: we do not sell personal data and do not share it for advertising purposes.
11. Security
Transmission is encrypted only (TLS). Accounts have no password, so no password leaks. Sign-in and calculation endpoints are rate limited.