Skip to content
RevealpostCreate

Privacy

This page describes what data occurs when you use RevealPost, why we process it and when it disappears again. It is written to be understood without a law degree.

The important part first

  • There is no sign-up and no user account.
  • We set no advertising or analytics cookies, embed no third-party fonts and measure no behaviour.
  • The reaction photos are end-to-end encrypted. The key is created in the browser and never reaches our server. We cannot look at the photos — not even on request.
  • Storage is in the European Union: the database and the file storage are pinned to it. Delivery itself runs over Cloudflare’s worldwide network — see “Hosting” below.

Controller

Carsten Michels
Heiligenbornstraße 28
66359 Bous
Germany
Email: info@carstnmusic.com

No data protection officer has been appointed; the conditions of Art. 37 GDPR are not met.

What we process, why and for how long

DataPurposeLegal basisRetention
Content of a reveal (occasion, text, language)Showing the page you createdArt. 6 (1) (b) GDPR — performance of the serviceuntil the reveal expires or you delete it
Encrypted reaction photosShowing them to the creatorArt. 6 (1) (b) GDPR; towards the guest Art. 6 (1) (a) — the photo is taken deliberately90 days, then deleted automatically
Creator session cookieRecognising you as the creatorArt. 6 (1) (b) GDPR; § 25 (2) no. 2 TDDDG — strictly necessaryuntil the session expires
Logs of the code that runs the site, Cloudflare’s “Workers Logs” (IP address, time, requested address)Operation, security, abuse preventionArt. 6 (1) (f) GDPR — legitimate interestkept by Cloudflare for at most seven days; no export set up — see “Hosting”
Counters limiting requests per IP addressPreventing automated requests from overloading the serviceArt. 6 (1) (f) GDPRtransient, at most 60 seconds

The reaction photos

Anyone who opens a reveal can send a photo back afterwards. This is voluntary; everything else works the same without it.

How the encryption works

When a reveal is created, a key pair is generated in the creator's browser. The public part is stored; the private part exists only in the creator's personal link and, additionally, encrypted on their device.It never reaches our server.

Your photo is encrypted on your device before it is uploaded. What we hold is ciphertext. Only the holder of the creator's personal link can open it.

What that means in practice

  • We cannot view your photo, cannot analyse it and cannot hand it over — not even if someone asks us to.
  • We can, however, delete it: the file is with us, just unreadable.
  • If the creator loses their link, the photo is unreadable for good. For them, and for us.

Withdrawing your photo

After sending, a deletion key is stored on your device. While it is there, the reveal page shows “Sent by you” and you can withdraw the photo yourself — without asking us and without the creator. It is then removed from the database and from file storage.

What the photo contains

The image is redrawn when it is taken. All metadata is dropped in the process, in particular the location. Only the picture itself leaves your device, nothing beyond it.

Storage on your device

We store only what the requested function needs. Under § 25 (2) no. 2 TDDDG no consent is required for this, which is why there is no cookie banner.

Creator session cookie
Recognises you as the creator of your own reveal. Without it you could not finish creating it.
Key storage (IndexedDB)
Keeps your personal key encrypted on this device so you do not need the long link every time.
Deletion keys for your own photos
So that you can withdraw a photo you sent.
Language choice
Remembers which language you want to read the site in.

How much of this reaches us differs — and the difference matters:

  • Your personal key never leaves your device. It sits encrypted in browser storage, is decrypted there and used there. That is why we cannot look at the photos.
  • The session identifier is sent to us — that is what a cookie is for. It travels with every request while the session lasts and is worthless afterwards.
  • The deletion key is sent when you use it. It stays with you until you withdraw a photo; at that moment we need it to see that you are the one allowed to.
  • The language choice stays with you.

You can delete all of it at any time through your browser settings — after that you will need the full link again for your photos.

Hosting

The site runs on Cloudflare, Inc. Cloudflare processes the data on our behalf as a processor under Art. 28 GDPR.

What is in the EU: the database and the file storage — that is, the reveals themselves and the encrypted reaction photos. This is set at creation time and cannot be changed afterwards.

What is not pinned: delivery. The code that assembles the page runs in whichever Cloudflare data centre is closest to you — which can be outside the EU if you open it from there. Doing so necessarily produces connection data, including your IP address. It is processed for delivery and for defending against attacks and is not used to recognise you.

How long the logs are kept: The logs of the code that runs the site — Cloudflare calls them “Workers Logs” — are kept by Cloudflare for at most seven days. We have not set up any export: one would be technically possible and would store the data elsewhere and for longer; we do not do it. We do not analyse the logs and build no statistics from them — they serve operation and the defence against abuse.

What we do not do

  • No advertising, no ad network, no profiling.
  • No analytics or statistics services using personal data.
  • No fonts, maps, videos or buttons from third-party servers.
  • No sharing of your data for advertising. There is nothing to sell, and we do not do it.
  • No automated decision-making within the meaning of Art. 22 GDPR.

Your rights

You have the right to

  • access to the data stored about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • object to processing based on legitimate interests (Art. 21 GDPR),
  • withdraw consent with effect for the future (Art. 7 (3) GDPR).

One limitation we state openly: because we cannot decrypt the photos, we cannot give information about their content. We can tell you that a photo exists, how large it is and when it arrived — and we can delete it.

Complaint to a supervisory authority

You may lodge a complaint with a data protection supervisory authority, in particular in the country of your residence, your place of work or the place of the alleged infringement (Art. 77 GDPR). The authority responsible for us — by the controller’s seat in Saarland — is theUnabhängiges Datenschutzzentrum Saarland, Fritz-Dobisch-Straße 12, 66111 Saarbrücken, Germany,poststelle@datenschutz.saarland.de.

Changes

If the processing changes, we change this page. The version published here is the one that applies.

Note: the German version is the legally binding one.Zur deutschen Fassung