Not ready for publication
This page still contains placeholders. The operator's full legal name and a service-of-process address are required by § 5 DDG and must be filled in at src/lib/legal/operator.ts before this site goes live.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
<Vorname Nachname><Straße und Hausnummer>
<PLZ> Berlin
Germany
- hello@emailonsteroids.com
No data protection officer has been appointed. The thresholds in Art. 37 GDPR and § 38 BDSG are not met: fewer than 20 people are permanently engaged in automated processing, and our core activity does not require large-scale regular and systematic monitoring of individuals.
2. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). Any consent you have given can be withdrawn at any time with effect for the future.
An informal message to hello@emailonsteroids.com is enough for all of these. Most of this information is also visible in your account, where you can delete your data yourself.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is the Berlin Commissioner for Data Protection and Freedom of Information, but you may equally approach the authority where you live.
3. Visiting the website
When you open a page, our hosting provider processes the connection data the request needs: IP address, timestamp, requested resource, HTTP status, bytes transferred, referrer and user agent.
- Purpose
- delivering the page, keeping it stable, and defending against attacks
- Legal basis
- Art. 6(1)(f) GDPR — legitimate interest in secure operation
- Retention
- short-term, then deleted
Fonts are served from our own origin. There is no connection to Google Fonts or any other content delivery network, and your IP address is not disclosed to a third party in the process.
4. Waiting list
If you request an invite we store the email address you enter and the time of the request.
- Purpose
- to notify you when an invite becomes available
- Legal basis
- Art. 6(1)(a) GDPR — consent
- Retention
- until you are invited, until you withdraw, or 24 months after the request at the latest
The form's confirmation message is deliberately identical for a new address and one already stored, so it does not reveal whether an address is on the list.
5. Account and sign-in
For an account we process your email address, authentication data, the ingest address assigned to you, and plan and usage data.
- Purpose
- providing the service and controlling access
- Legal basis
- Art. 6(1)(b) GDPR — performance of the contract
- Retention
- for as long as the account exists; after deletion only where statutory retention periods require it
6. Test content and email ingest — our role as processor
The core of the service is rendering emails you supply. You can paste HTML, forward a message to your personal ingest address, or submit content through the API. That content regularly contains personal data of third parties — recipient names, salutations, addresses, personalised links.
For that content you are the controller and we are a processor within the meaning of Art. 28 GDPR. We process it solely to produce the previews and analyses you asked for, never for our own purposes. A data processing agreement is available on request and is required for business use.
Inbound messages are received by Cloudflare Email Routing and passed to us with a signature. When rendering, external images are not fetched where that is technically avoidable.
Do not send the service emails containing special categories of personal data under Art. 9 GDPR — health, religious or trade-union data among them. The service is not designed for it.
7. Previews and share links
Screenshots are stored encrypted and are reachable only through your account. When you create a share link, the page is reachable by anyone who knows the link: the link itself is the credential.
Share links carry a lifetime you choose, are excluded from search engines, and are deleted together with their files when they lapse. An expired link answers with status 410 (Gone).
8. Payments
Payments are handled by Stripe. Your payment details — card number, bank details — are processed by Stripe alone and never reach our servers. From Stripe we receive a customer identifier, the subscription status, the plan and the term.
- Legal basis
- Art. 6(1)(b) GDPR for performing the contract; Art. 6(1)(c) GDPR for tax retention
- Retention
- invoice data for 10 years under § 147 AO and § 257 HGB
9. Cookies and local storage
We set no analytics, advertising or tracking cookies, and we embed no service that does. There is therefore no consent banner: under § 25(2) no. 2 TDDDG no consent is required for strictly necessary storage, and a banner asking for it anyway would be misleading.
| Name | Purpose | Lifetime |
|---|---|---|
| Supabase session | keeps you signed in | the session, or until you sign out |
| eos_locale | remembers the language you chose | 1 year |
| Theme preference | remembers light or dark rendering (stored locally in the browser) | until you clear it |
The language cookie contains only “en” or “de” and no identifier that could be used to recognise you.
10. Recipients and international transfers
We use the processors below. There are no other recipients; your data is not sold and not passed on for advertising.
| Provider | Task | Data processed |
|---|---|---|
| Vercel Inc. | hosting and delivery | connection data, request contents |
| Supabase Inc. | database, authentication, file storage | account data, test content, previews |
| Stripe Payments Europe, Ltd. | payment processing | payment and subscription data |
| Cloudflare, Inc. | receiving inbound email | inbound messages and their envelope data |
Some of these companies are established in the United States or rely on group companies there. Transfers are based on standard contractual clauses under Art. 46(2)(c) GDPR and, where the provider is certified, additionally on the adequacy decision for the EU-US Data Privacy Framework.
11. Changes to this policy
We update this policy when the service or the law changes. The version published here is the one that applies, and the date of the last change is shown at the foot of the page. For material changes we additionally notify signed-in users by email.
Last updated: 14 August 2026