kp ENDE

Privacy

2 August 2026 · Information under Art. 13 GDPR

This is a translation for convenience. The German version at Datenschutzerklaerung is the authoritative text.

1. Controller

Responsible for the processing of personal data on this site within the meaning of Art. 4(7) GDPR:

Khashayar Pakfar
Einsteinstrasse 21
10409 Berlin
Germany
Email
me@kpakfar.me

An email to that address is enough for any privacy question or to exercise any of the rights below.

2. Recipients

This site processes as little as it can. No cookies, no analytics, no advertising. Data reaches exactly these parties:

Cloudflare EU / US
Hosting and delivery of this site. IP address, user agent, and time of every request. Every page view. Legal basis Art. 6(1)(f) GDPR.
OpenRouter USA third country
The language model kp answers with. The text of your question and the earlier messages of this session. A single question triggers up to 4 language-model calls, plus one more each time kp searches my notes while answering. The job match on /job-match also sends the job description you paste: its text goes through 2 language-model calls. Only when you ask kp something, or when you paste a job description into the job match on /job-match. Legal basis Art. 6(1)(f) GDPR.
n8n (Stellenanzeigen-Leser / job link reader) EU
Reads the job posting behind a link you submit and hands me back its text. Only the link you type. The posting is fetched by that reader, not by your browser: the job board sees its address, not yours. Only when you submit a link on /job-match and ask me to read it. Pasting the text yourself never triggers it. Legal basis Art. 6(1)(f) GDPR.
n8n (Hinweis an mich / notification to me) EU
Tells me when kp could not answer a question, so I can write the note that was missing. Your question, kp's answer to it, the time, and the page you were on. No IP address, no name, no identifier. Both texts are cut off after 500 characters. Only when kp had nothing to say to your question. An answered question triggers nothing. At most 20 such notices a day. Legal basis Art. 6(1)(f) GDPR.
OpenFreeMap server location unknown
Map tiles for the map page. Your IP address and the map view you are looking at. Your browser fetches the tiles from the provider directly, not through this server. Only when you open the map page. Legal basis Art. 6(1)(f) GDPR.

The legitimate interest under Art. 6(1)(f) GDPR is, in all three cases, running this site safely and in working order: delivering the pages, answering your questions, and drawing the map. Retention periods are in section 6.

3. Chat with kp

Step What is sent
Search Your question text to OpenRouter, to find relevant notes
Answer Your question text and session history to OpenRouter, in up to 4 steps
No match The question, cut to 200 characters, plus a timestamp, written to the server log

When kp cannot answer from my notes, the question is logged cut to 200 characters with a timestamp, so I can see which content is missing. No IP address and no identifier. Please do not type personal data into the chat.

4. Map

The map page loads its tiles from OpenFreeMap. Your browser connects to the provider directly rather than through this server, and the provider sees your IP address and the map view. If you never open the map page, that connection is never made. No other page loads anything from a third party.

5. Storage in your browser

Your conversation with kp is kept in your browser's session storage under the key kp-thread-v1. It stays on your device, leaves it only as part of your next question, and is deleted when you close the tab.

6. Retention

No visitor profile is built on this server: there is no account and no database of visitor data. What sits where, and for how long:

Cloudflare
Your question to kp and its answer are kept for 90 days, so I can see what people ask and what I still need to write. Only those two texts, the time, the page you were on, and what the answer cost, how long it took and which notes it read. No IP address, no name, no cookie, no session id: an entry cannot be tied to a person, or to another entry. Please do not type personal data into the chat. How long Cloudflare keeps connection data is governed by Cloudflare's own retention periods.
OpenRouter
OpenRouter receives your question only in order to answer it. My own retention of the question and answer (90 days) is described under Cloudflare above. How long OpenRouter and the respective model provider keep the request is governed by their terms.
n8n (Stellenanzeigen-Leser / job link reader)
The text that came back sits in a cache for at most ten minutes, so the same link is not fetched twice. After that it is gone, and it never reaches a database.
n8n (Hinweis an mich / notification to me)
From there the notice is passed on to me as a message, and it stays until I delete it; it does not expire on its own. Please do not type personal data into the chat.
OpenFreeMap
The connection runs directly between your browser and the provider; no record of it is created here. Retention is governed by the provider's terms.
Log line when kp cannot answer
Appears in the hosting platform's runtime log. I have set up no durable log archive and copy the line into no database.
Conversation in session storage
Until you close the tab. It lives on your device only.

7. Not used

No cookies. No analytics or tracking tools. No advertising. No externally hosted fonts. No account and no stored profile. The Nominatim geocoding service is queried only when the site is built, never by visitors.

8. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). An email to the address above is enough.

You may also lodge a complaint with a supervisory authority, for Berlin the Berliner Beauftragte fuer Datenschutz und Informationsfreiheit.