Nib3d

Datenschutzerklärung

Nib3d ist ein CAD-Programm für Stift und Maus, im Browser und als Android-App. Es arbeitet auf deinem Gerät: Modelle, Einstellungen und Verlauf bleiben dort. Mit meinem Server spricht Nib3d nur, wenn du ein Konto anlegst oder angemeldet bist – und auch dann so wenig wie möglich. Diese Erklärung sagt, was dabei verarbeitet wird.

1. Verantwortlicher

Mika Groenewold · Mikas Services
c/o POSTFLEX PFX-525-513
Emsdettener Straße 10
48268 Greven
Deutschland
E-Mail: kontakt@nib3d.de · Kontaktformular

Einen Datenschutzbeauftragten muss ich nicht benennen; für alle Fragen zum Datenschutz erreichst du mich direkt unter der genannten Adresse.

2. Aufruf der Seite und Server-Protokolle

Beim Aufruf von Nib3d (Webseite, Programmdateien, Schnittstelle der App) verarbeitet der Webserver technisch deine IP-Adresse, um die Antwort an dich zu schicken. Gespeichert wird sie nicht: Das Zugriffsprotokoll enthält nur Zeitpunkt, Anfragemethode, aufgerufenen Pfad (ohne Parameter), Statuscode und übertragene Datenmenge; Fehlerprotokolle nur schwere Störungen ohne Adresse. Die Protokolle sind auf wenige Megabyte begrenzt und werden laufend überschrieben. Um Missbrauch zu bremsen (etwa massenhafte Anmeldeversuche), hält der Webserver die IP-Adresse höchstens einige Minuten im Arbeitsspeicher.

Die Verbindung ist per TLS verschlüsselt. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO; das berechtigte Interesse liegt im sicheren und fehlerfreien Betrieb.

3. Hosting, E-Mail und Namensauflösung

Nib3d und das Postfach kontakt@nib3d.de laufen auf einem von mir gemieteten und selbst verwalteten Server der netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Standort Deutschland. netcup hat keinen inhaltlichen Zugriff auf die Daten; ein Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO besteht. netcup setzt dafür die Anexia-Gesellschaften in Klagenfurt (Österreich) und Karlsruhe als Unterauftragsverarbeiter ein; eine Übermittlung in ein Drittland findet nicht statt.

Jede Nacht kopiere ich die Datenbank und die (ohnehin Ende-zu-Ende-verschlüsselten) Sicherungen auf einen eigenen Server in Deutschland, dessen Speicher verschlüsselt ist; dort bleibt jeder Stand 30 Tage. Gelöschte Daten verschwinden also spätestens nach 30 Tagen auch aus diesen Kopien.

Auch die Namensauflösung (DNS) der Domain nib3d.de übernimmt netcup. Dabei sehen die Namensserver nur die Anfrage deines Netzbetreibers oder DNS-Resolvers, nicht aber deine Seitenaufrufe.

4. Speicherung auf deinem Gerät

Deine Modelle, Einstellungen und Vorschaubilder speichert Nib3d im Browser (IndexedDB, localStorage) bzw. in der App auf deinem Gerät. Das ist für die Funktion des Programms unbedingt erforderlich (§ 25 Abs. 2 Nr. 2 TDDDG) und verlässt das Gerät nicht, solange du keine Sicherung nutzt.

Angemeldet setzt Nib3d im Browser ein einziges Cookie, __Host-nib: eine zufällige Sitzungskennung, ohne die du nicht angemeldet bleibst (HttpOnly, nur für diese Seite, unbedingt erforderlich nach § 25 Abs. 2 Nr. 2 TDDDG). Die App hält die Sitzung stattdessen in ihrem privaten Speicher; dieser ist von Android-Sicherung und Geräteumzug ausgenommen. Weitere Cookies, Werbe- oder Analysekennungen gibt es nicht.

5. Konto

Ein Konto brauchst du nur für die Cloud-Funktionen (Sicherung, Teilen, gemeinsames Bearbeiten) und den Support. Es kommt ohne E-Mail-Adresse, Namen und Passwort aus: Dein Konto ist ein zufälliger Schlüssel aus 28 Zeichen, den dein Gerät erzeugt und der es nie verlässt. Der Server erhält nur einen daraus abgeleiteten Wert und speichert davon wiederum nur einen geheimen Prüfwert (HMAC). Aus dem, was auf dem Server liegt, lässt sich dein Schlüssel nicht zurückrechnen – deshalb kann ich ihn auch nicht wiederherstellen.

Zum Konto speichere ich: den Prüfwert, eine öffentliche Konto-ID (z. B. „7KQD-93MX“, für Support und Discord; damit kann man sich nicht anmelden), den Tag der Anlage und der letzten Nutzung, für jedes angemeldete Gerät einen Prüfwert der Sitzungskennung samt Ablaufdatum und Geräteart (Web/App), den Stand der AGB und Datenschutzerklärung, dem du beim Anlegen zugestimmt hast, sowie gegebenenfalls Abo-Stufe, Laufzeit, Speicherkontingent, eine Einschränkung oder Sperre und eine Notiz von mir (Abschnitt 12). Keine IP-Adressen, keine Gerätekennungen, keinen Browser-Fingerabdruck.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (Bereitstellung des Kontos). Du kannst dein Konto jederzeit in den Einstellungen selbst löschen; dann ist es samt Sicherungen, Teilungen, Support-Verlauf und Meldungen sofort weg (Ausnahme: Zahlungsbelege, Abschnitt 8). Konten, die zwei Jahre lang nicht genutzt wurden und kein laufendes Abo haben, lösche ich automatisch. Unter „Daten exportieren“ bekommst du jederzeit alles, was der Server zu deinem Konto hat, als Datei (Art. 15, 20 DSGVO).

6. Sicherung, Teilen und gemeinsames Bearbeiten

Sicherungen werden auf deinem Gerät verschlüsselt, bevor sie hochgeladen werden – mit einem Schlüssel, der aus deinem Kontoschlüssel abgeleitet wird und den der Server nicht kennt. Ich sehe weder Inhalte noch Projektnamen, nur verschlüsselte Daten, ihre Größe und den Tag. Beim Teilen gilt dasselbe: Titel, Namen der Beteiligten und Inhalte sind Ende-zu-Ende-verschlüsselt; der Schlüssel steckt nur im Einladungslink hinter dem „#“, der nie an einen Server geht. Gespeichert werden Mitgliedschaften, verschlüsselte Einträge und ihre Größe.

Bei der Live-Synchronisierung erfährt der Server nur, dass sich etwas geändert hat, und gibt diesen Hinweis an deine anderen Geräte bzw. die anderen Beteiligten weiter. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO.

7. Schutz vor automatisierten Anmeldungen (Cloudflare Turnstile)

Damit niemand massenhaft Konten anlegt oder das Kontaktformular mit Nachrichten flutet, nutze ich beim Anlegen eines Kontos und beim Kontaktformular Turnstile der Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Dabei werden deine IP-Adresse und technische Angaben zum Browser an Cloudflare übertragen, und Cloudflare kann im Browser einen technischen Wert speichern. Mein Server prüft das Ergebnis anschließend bei Cloudflare, ohne dabei deine IP-Adresse mitzuschicken.

Das geschieht ausschließlich nach ausdrücklicher Einwilligung. Vor dem Klick auf „Einverstanden, Prüfung laden“ wird nichts von Cloudflare geladen und nichts dorthin übertragen. In der App öffnet sich dafür eine Seite von Nib3d mit derselben Frage. Deine Entscheidung merke ich mir nur für die Dauer deines Besuchs (sessionStorage); dieser Eintrag enthält keine Daten über dich.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. a DSGVO in Verbindung mit § 25 Abs. 1 TDDDG. Du kannst die Einwilligung jederzeit widerrufen – mit dem Knopf unten oder durch Schließen des Tabs; die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung bleibt unberührt. Ohne Einwilligung kannst du kein neues Konto anlegen; Nib3d selbst funktioniert ohne Konto weiter, und mich erreichst du per E-Mail. Die Übermittlung in die USA erfolgt auf Grundlage des EU-US Data Privacy Framework, unter dem Cloudflare zertifiziert ist, sowie der EU-Standardvertragsklauseln.


Setzt die Einwilligung in Turnstile für diesen Besuch zurück und lädt die Seite neu.

8. Abo und Zahlung (Mollie)

Ein Abo schließt du über die Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Niederlande, ab. Deine Zahlungsdaten (etwa Kartennummer oder Konto) gibst du direkt bei Mollie ein; Mollie verarbeitet sie in eigener Verantwortung (Datenschutzhinweise von Mollie). Ich übermittle an Mollie nur Betrag, Abo-Stufe, Intervall und als Kundenbezeichnung deine öffentliche Konto-ID – keinen Namen und keine E-Mail-Adresse. Von Mollie erhalte ich den Zahlungsstatus, Betrag, Zeitpunkt und Kennnummern von Kunde, Zahlung und Abo; je nach Zahlungsart kann Mollie mir auch Angaben wie den Namen des Karteninhabers oder Kontos anzeigen.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO, für die Aufbewahrung Art. 6 Abs. 1 lit. c DSGVO. Zahlungsbelege (Betrag, Stufe, Status, Zeitpunkt, Kennnummer) bewahre ich wegen § 147 AO und § 14b UStG acht Jahre auf – auch nach Löschung des Kontos, dann ohne Verbindung zum Konto. Mollie führt zur Betrugsprävention eigene Prüfungen durch.

Rechnungen und Vertragsbestätigung. Zu jeder Zahlung erstelle ich eine Rechnung (zu Erstattungen eine Rechnungskorrektur, beim Abschluss eine Vertragsbestätigung). Darauf steht deine öffentliche Konto-ID und – nur wenn du sie in den Einstellungen unter Abo einträgst – Name, Firma oder Anschrift. Trägst du dort eine E-Mail-Adresse ein, schicke ich dir die Belege dorthin; Über eine fehlgeschlagene Abbuchung informiere ich dich dann ebenfalls dort. Beide Angaben sind freiwillig, gelten für künftige Belege und lassen sich jederzeit ändern oder leeren (Art. 6 Abs. 1 lit. b DSGVO). Eine Kopie jeder Rechnung und Rechnungskorrektur geht per E-Mail an meine Buchhaltungssoftware Accountable (Sitz in Belgien), die sie als Auftragsverarbeiterin für meine Buchführung speichert (Art. 6 Abs. 1 lit. c DSGVO). Die Belege bewahre ich acht Jahre auf (§ 147 AO, § 14b UStG).

9. Discord (freiwillig)

Wenn du es selbst startest, verknüpft Nib3d dein Konto mit deinem Discord-Konto, damit du auf dem Nib3d-Server die Rolle deiner Abo-Stufe bekommst. Anbieter ist die Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA. Die Anmeldung und Freigabe geschieht bei Discord (OAuth 2.0, Berechtigungen „identify“ und „role_connections.write“). Ich erhalte dabei deine Discord-Nutzerkennung und deinen Anzeigenamen und speichere sie zusammen mit einem Zugangstoken, um die Rolle aktuell zu halten. An Discord übermittle ich deine öffentliche Konto-ID und deine Abo-Stufe als Zahl.

Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO (die von dir gewünschte Verknüpfung). Du kannst sie in den Einstellungen jederzeit lösen; dann setze ich die Stufe bei Discord auf 0 und lösche die gespeicherten Discord-Daten – ebenso beim Löschen des Kontos. Die Übermittlung in die USA erfolgt auf Grundlage des EU-US Data Privacy Framework. Für den Discord-Server selbst gilt die Datenschutzerklärung von Discord.

Die Knöpfe „Discord-Server“ und „Spenden“ (PayPal; PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxemburg) sind einfache Links: Erst wenn du sie anklickst, rufst du die Seite des jeweiligen Anbieters auf; vorher wird nichts übertragen.

10. Support-Chat und Meldungen

Angemeldet kannst du mir im Support-Chat schreiben und Fehler oder Wünsche melden. Support-Nachrichten speichere ich im Klartext – ich kann sie lesen, damit ich antworten kann; die App sagt das auch dort. Bei einer Meldung gehen außerdem mit, was der Dialog vorher anzeigt: Seite, Gerätemodell, System- und App-Version, Bildschirmgröße und Sprache. Beides gehört zu deinem Konto, steht im Datenexport und wird mit dem Konto gelöscht; Meldungen lösche ich außerdem, sobald sie erledigt sind. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO, für Meldungen Art. 6 Abs. 1 lit. f DSGVO (Verbesserung von Nib3d).

11. Kontaktformular und E-Mail

Wer das Kontaktformular nutzt, übermittelt Name, E-Mail-Adresse und Nachricht; dazu wird der Zeitpunkt vermerkt, keine IP-Adresse. Die Nachricht landet in meinem Postfach im Admin-Bereich von Nib3d; ich antworte per E-Mail. Spätestens sechs Monate nach Eingang wird sie automatisch gelöscht, sofern keine gesetzlichen Aufbewahrungsfristen entgegenstehen. Für E-Mails an kontakt@nib3d.de gilt dasselbe; sie liegen auf dem Server aus Abschnitt 3. Auf der Seite Verträge hier kündigen übermittelst du öffentliche Konto-ID, E-Mail-Adresse, Art und Zeitpunkt der Kündigung und freiwillig Name und Grund; die Bestätigung schickt mein Server von kontakt@nib3d.de an deine Adresse, mit einer Kopie in mein Postfach (Art. 6 Abs. 1 lit. b und c DSGVO, § 312k BGB). Auch das wird nach sechs Monaten gelöscht, solange die Kündigung nicht strittig ist. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO bei Anfragen zu einem Vertrag (etwa einem Widerruf), sonst Art. 6 Abs. 1 lit. f DSGVO (Beantwortung deiner Anfrage).

12. Schutz vor Missbrauch

Damit der Speicher nicht als Ablage für fremde Dateien oder für Angriffe missbraucht wird, sehe ich im Admin-Bereich je Konto Kennzahlen wie belegten Speicher, Anzahl und Größe der Sicherungen, geteilte Projekte und Meldungen. Auffällige Werte (etwa sehr viel Upload an einem Tag) werden zur Prüfung markiert; entschieden wird von mir persönlich, es gibt keine automatisierte Entscheidung im Sinne des Art. 22 DSGVO. Ich kann ein Konto einschränken (kein Hochladen und Teilen mehr, Lesen und Support bleiben) oder sperren und dazu eine Notiz anlegen; beides steht in deinem Datenexport. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (Sicherheit des Dienstes und Schutz der anderen Nutzer).

13. Geschäftspost

Meine Geschäftsanschrift ist eine Serviceadresse der Postflex GmbH, Emsdettener Straße 10, 48268 Greven. Post dorthin – etwa ein Widerruf – nimmt Postflex entgegen und leitet sie an mich weiter; dabei verarbeitet Postflex Absender, Anschrift und je nach Versandart den Inhalt. Das geschieht ausschließlich nach meinen Weisungen; ein Vertrag zur Auftragsverarbeitung nach Art. 28 DSGVO liegt vor. Rechtsgrundlage ist Art. 6 Abs. 1 lit. b DSGVO bei Post zu einem Vertrag, sonst Art. 6 Abs. 1 lit. f DSGVO.

14. Speicherdauer im Überblick

DatenWie lange
Zugriffsprotokoll (ohne IP)laufend überschrieben, wenige Megabyte
IP-Adresse zur Missbrauchsbremseeinige Minuten, nur im Arbeitsspeicher
Sitzung eines Gerätsbis zur Abmeldung, höchstens 180 Tage nach der letzten Nutzung
Prüfwert einer von einem neueren Gerät verdrängten Sitzung (damit das alte Gerät erfährt, warum es abgemeldet ist)30 Tage
Konto, Sicherungen, Teilungen, Support, Meldungen, Discord-Verknüpfungbis du sie oder das Konto löschst; ungenutzte Konten ohne Abo nach zwei Jahren
Kontaktformular und Kündigungsseitehöchstens sechs Monate
Nächtliche Kopien von Datenbank und Sicherungen30 Tage
Zahlungsbelege, Rechnungen, Rechnungskorrekturen, Vertragsbestätigungenacht Jahre (§ 147 AO, § 14b UStG)
E-Mail-Adresse und Anschrift für Belegebis du sie änderst oder das Konto löschst
Einwilligung in Turnstile (nur im Browser)bis zum Schließen des Tabs

15. Deine Rechte

Du kannst Auskunft über die zu deiner Person gespeicherten Daten verlangen (Art. 15 DSGVO), deren Berichtigung (Art. 16), Löschung (Art. 17) oder Einschränkung der Verarbeitung (Art. 18) sowie die Übertragung der Daten, die du mir bereitgestellt hast, in einem gängigen Format (Art. 20). Vieles davon geht in Nib3d direkt: Daten exportieren und Konto löschen stehen in den Einstellungen. Eine erteilte Einwilligung kannst du jederzeit mit Wirkung für die Zukunft widerrufen.

Widerspruchsrecht (Art. 21 DSGVO): Soweit ich Daten auf Grundlage eines berechtigten Interesses verarbeite, kannst du der Verarbeitung aus Gründen, die sich aus deiner besonderen Situation ergeben, jederzeit widersprechen. Ich verarbeite die Daten dann nicht mehr, es sei denn, ich kann zwingende schutzwürdige Gründe nachweisen, die deine Interessen überwiegen, oder die Verarbeitung dient der Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen.

Weil ich keine Namen oder E-Mail-Adressen zu Konten kenne, nenne mir bei Anfragen zu einem Konto bitte die öffentliche Konto-ID oder schreib aus dem Support-Chat. Für alle Anliegen genügt eine E-Mail an kontakt@nib3d.de.

Unabhängig davon steht dir ein Beschwerderecht bei einer Datenschutz-Aufsichtsbehörde zu, etwa der deines Wohnsitzes. Für mich zuständig ist das Bayerische Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, lda.bayern.de.

Die Bereitstellung von Daten ist weder gesetzlich noch vertraglich vorgeschrieben; Nib3d lässt sich ohne Konto nutzen. Eine automatisierte Entscheidungsfindung einschließlich Profiling findet nicht statt.

16. Was ich nicht mache

Kurz gesagt: Nib3d finanziert sich über Abos, nicht über deine Daten. Deshalb gilt:

17. Änderungen

Ich passe diese Erklärung an, wenn sich Nib3d, die Abläufe oder die Rechtslage ändern. Die aktuelle Fassung steht immer unter nib3d.de/privacy.

Stand: 8. Oktober 2026

Privacy Policy

This translation is for convenience; the German version is binding.

Nib3d is a CAD program for pen and mouse, in the browser and as an Android app. It works on your device: models, settings and history stay there. Nib3d only talks to my server when you create an account or are logged in – and even then as little as possible. This policy explains what is processed.

1. Controller

Mika Groenewold · Mikas Services
c/o POSTFLEX PFX-525-513
Emsdettener Straße 10
48268 Greven
Germany
Email: kontakt@nib3d.de · contact form

I am not required to appoint a data protection officer; for any privacy question you reach me directly at the address above.

2. Visiting the site and server logs

When you use Nib3d (website, program files, the app's interface), the web server technically processes your IP address to send the response to you. It is not stored: the access log contains only time, request method, requested path (without parameters), status code and size; error logs only serious faults, without addresses. Logs are capped at a few megabytes and continuously overwritten. To slow down abuse (such as mass login attempts), the web server keeps IP addresses in memory for a few minutes at most.

Connections are TLS-encrypted. Legal basis: Art. 6(1)(f) GDPR; the legitimate interest is secure and reliable operation.

3. Hosting, email and DNS

Nib3d and the mailbox kontakt@nib3d.de run on a server I rent and manage myself from netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, located in Germany. netcup has no access to the content; a data processing agreement under Art. 28 GDPR is in place. netcup uses the Anexia companies in Klagenfurt (Austria) and Karlsruhe as sub-processors; no data is transferred to a third country.

Every night I copy the database and the backups (which are end-to-end encrypted anyway) to a server of my own in Germany with encrypted storage; each copy is kept there for 30 days. Deleted data is therefore gone from these copies after 30 days at the latest.

netcup also runs the name servers (DNS) for nib3d.de. They only see the lookup from your network provider or DNS resolver, not your page requests.

4. Storage on your device

Nib3d stores your models, settings and thumbnails in the browser (IndexedDB, localStorage) or in the app on your device. This is strictly necessary for the program to work (§ 25(2) no. 2 TDDDG) and does not leave the device unless you use backups.

When you're logged in, Nib3d sets exactly one cookie in the browser, __Host-nib: a random session identifier without which you wouldn't stay logged in (HttpOnly, this site only, strictly necessary under § 25(2) no. 2 TDDDG). The app keeps the session in its private storage instead, excluded from Android backup and device transfer. There are no other cookies, ad or analytics identifiers.

5. Account

You only need an account for the cloud features (backup, sharing, collaborative editing) and support. It works without email address, name or password: your account is a random 28-character key that your device generates and that never leaves it. The server only receives a value derived from it and stores only a secret check value (HMAC) of that. Your key cannot be calculated back from what is on the server – which is also why I can't recover it.

For the account I store: the check value, a public account ID (e.g. “7KQD-93MX”, for support and Discord; it can't be used to log in), the day it was created and last used, for each logged-in device a check value of the session identifier with expiry and device type (web/app), the version of the Terms and Privacy Policy you accepted when creating it, and where applicable subscription tier, term, storage quota, a restriction or block and a note from me (section 12). No IP addresses, no device identifiers, no browser fingerprint.

Legal basis: Art. 6(1)(b) GDPR (providing the account). You can delete your account yourself at any time in the settings; it is then gone immediately, including backups, shares, support history and reports (except payment records, section 8). Accounts unused for two years without a running subscription are deleted automatically. “Export data” gives you everything the server has on your account as a file at any time (Art. 15, 20 GDPR).

6. Backup, sharing and collaborative editing

Backups are encrypted on your device before upload – with a key derived from your account key that the server does not know. I see neither contents nor project names, only encrypted data, its size and the day. Sharing works the same way: titles, names of participants and contents are end-to-end encrypted; the key is only in the invite link after the “#”, which never reaches a server. Stored are memberships, encrypted entries and their size.

For live sync the server only learns that something changed and passes this notice on to your other devices or the other participants. Legal basis: Art. 6(1)(b) GDPR.

7. Protection against automated sign-ups (Cloudflare Turnstile)

To prevent mass account creation or flooding of the contact form, I use Turnstile by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA, when an account is created and in the contact form. Your IP address and technical browser data are sent to Cloudflare, and Cloudflare may store a technical value in the browser. My server then verifies the result with Cloudflare without sending your IP address.

This happens only with your explicit consent. Before you click “Agree and load check”, nothing is loaded from Cloudflare and nothing is sent there. In the app, a Nib3d page with the same question opens for this. I remember your decision only for the duration of your visit (sessionStorage); this entry contains no data about you.

Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. You can withdraw consent at any time – with the button below or by closing the tab; processing up to then remains lawful. Without consent you can't create a new account; Nib3d itself keeps working without an account, and you can reach me by email. The transfer to the USA is based on the EU-US Data Privacy Framework, under which Cloudflare is certified, and on the EU Standard Contractual Clauses.


Resets your consent to Turnstile for this visit and reloads the page.

8. Subscription and payment (Mollie)

Subscriptions are handled by Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. You enter your payment details (such as card number or account) directly at Mollie, which processes them under its own responsibility (Mollie's privacy notice). I only send Mollie the amount, tier, interval and, as customer label, your public account ID – no name and no email address. From Mollie I receive the payment status, amount, time and reference numbers of customer, payment and subscription; depending on the payment method, Mollie may also show me details such as the name of the card or account holder.

Legal basis: Art. 6(1)(b) GDPR, for retention Art. 6(1)(c) GDPR. I keep payment records (amount, tier, status, time, reference) for eight years under § 147 AO and § 14b UStG – also after the account is deleted, then without a link to the account. Mollie runs its own fraud checks.

Invoices and contract confirmation. For every payment I create an invoice (a credit note for refunds, a contract confirmation when you subscribe). It shows your public account ID and – only if you enter them in the settings under Subscription – name, company or address. If you enter an email address there, I send the documents to it and also let you know there when a charge fails. Both are optional, apply to future documents and can be changed or cleared at any time (Art. 6(1)(b) GDPR). A copy of every invoice and credit note goes by email to my accounting software Accountable (based in Belgium), which stores it as my processor for bookkeeping (Art. 6(1)(c) GDPR). I keep these documents for eight years (§ 147 AO, § 14b UStG).

9. Discord (optional)

If you start it yourself, Nib3d links your account to your Discord account so you get your tier's role on the Nib3d server. The provider is Discord Inc., 444 De Haro Street, Suite 200, San Francisco, CA 94107, USA. Login and approval happen at Discord (OAuth 2.0, permissions “identify” and “role_connections.write”). I receive your Discord user ID and display name and store them with an access token to keep the role up to date. I send Discord your public account ID and your tier as a number.

Legal basis: Art. 6(1)(b) GDPR (the link you requested). You can unlink at any time in the settings; I then set your tier at Discord to 0 and delete the stored Discord data – likewise when you delete the account. The transfer to the USA is based on the EU-US Data Privacy Framework. The Discord server itself is covered by Discord's privacy policy.

The “Discord server” and “Donate” buttons (PayPal; PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg) are plain links: only when you click them do you visit the provider's site; nothing is transferred before.

10. Support chat and reports

When logged in, you can write to me in the support chat and report bugs or wishes. I store support messages in plain text – I can read them so I can reply; the app says so there too. A report also includes what the dialog shows beforehand: page, device model, system and app version, screen size and language. Both belong to your account, are part of the data export and are deleted with the account; I also delete reports once they're handled. Legal basis: Art. 6(1)(b) GDPR, for reports Art. 6(1)(f) GDPR (improving Nib3d).

11. Contact form and email

The contact form sends name, email address and message; the time is noted, no IP address. The message lands in my inbox in Nib3d's admin area; I reply by email. It is deleted automatically six months after arrival at the latest, unless legal retention periods apply. The same applies to emails to kontakt@nib3d.de, which are stored on the server from section 3. On the cancel contracts here page you send your public account ID, email address, type and date of the cancellation and, optionally, name and reason; my server emails the confirmation from kontakt@nib3d.de to your address, with a copy to my inbox (Art. 6(1)(b) and (c) GDPR, § 312k BGB). This is also deleted after six months unless the cancellation is disputed. Legal basis: Art. 6(1)(b) GDPR for requests about a contract (such as a withdrawal), otherwise Art. 6(1)(f) GDPR (answering your request).

12. Preventing abuse

So that storage isn't misused as a dump for other files or for attacks, the admin area shows me per-account figures such as storage used, number and size of backups, shared projects and reports. Unusual values (such as a lot of uploads in one day) are flagged for review; I decide personally, there is no automated decision within the meaning of Art. 22 GDPR. I can restrict an account (no more uploading and sharing; reading and support remain) or block it, and add a note; both appear in your data export. Legal basis: Art. 6(1)(f) GDPR (security of the service and protection of other users).

13. Business mail

My business address is a service address of Postflex GmbH, Emsdettener Straße 10, 48268 Greven. Postflex receives mail sent there – such as a withdrawal – and forwards it to me, processing sender, address and, depending on the type of shipment, the content. This happens only on my instructions; a data processing agreement under Art. 28 GDPR is in place. Legal basis: Art. 6(1)(b) GDPR for mail about a contract, otherwise Art. 6(1)(f) GDPR.

14. Retention at a glance

DataHow long
Access log (without IP)continuously overwritten, a few megabytes
IP address for rate limitinga few minutes, in memory only
Session of a deviceuntil logout, at most 180 days after last use
Check value of a session pushed out by a newer device (so the old device learns why it was logged out)30 days
Account, backups, shares, support, reports, Discord linkuntil you delete them or the account; unused accounts without subscription after two years
Contact form and cancellation pagesix months at most
Nightly copies of database and backups30 days
Payment records, invoices, credit notes, contract confirmationseight years (§ 147 AO, § 14b UStG)
Email address and address for documentsuntil you change them or delete the account
Consent to Turnstile (browser only)until the tab is closed

15. Your rights

You can request access to the data stored about you (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17) or restriction of processing (Art. 18), and portability of the data you provided in a common format (Art. 20). Much of this works directly in Nib3d: export data and delete account are in the settings. You can withdraw any consent at any time with effect for the future.

Right to object (Art. 21 GDPR): Where I process data based on a legitimate interest, you can object at any time on grounds relating to your particular situation. I will then stop, unless I can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

Since I don't know names or email addresses of accounts, please give your public account ID for requests about an account, or write from the support chat. For everything, an email to kontakt@nib3d.de is enough.

You also have the right to lodge a complaint with a data protection supervisory authority, for example the one where you live. The authority responsible for me is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, lda.bayern.de.

Providing data is neither legally nor contractually required; Nib3d can be used without an account. There is no automated decision-making, including profiling.

16. What I don't do

In short: Nib3d is paid for by subscriptions, not by your data. That means:

17. Changes

I update this policy when Nib3d, the processes or the law change. The current version is always at nib3d.de/privacy.

Last updated: 8 October 2026