Skip to content
Datenschutzerklärung

Privacy policy

What we store, why, for how long, and how you get it back or get rid of it.

Controller

Jakob Puosi
Kerschensteinerstraße 44
82166 Gräfelfing
Germany
jpuosi@gmail.com

The controller within the meaning of the GDPR (Verantwortlicher, Art. 4 (7) GDPR) is the person named above. We have not appointed a data protection officer; the conditions of Art. 37 GDPR and § 38 BDSG are not met for an operation of this size. Write to the address above with any question about your data — it reaches the person who decides.

What this site does not do

This section is here because it is shorter than the alternative. browsepublicfinance.com uses no analytics service, no advertising or tracking cookies, no external fonts and no embedded third-party content — no social plugins, no video embeds, no external maps. Every page is delivered from our own server, including its styles and its graphics. Because there is nothing to consent to, there is no consent banner. No profile is built from your reading for advertising, and nothing is sold or passed to data brokers. The one thing we count ourselves is how often each page is opened per day — a bare number with no one behind it, described under “Server logs”.

Account

Data: your email address, a hash of your password (scrypt, never the password itself), the times at which the account was created, confirmed and last used to sign in, your access level, and what you create in the account — your reading interests.

Purpose: to give you an account, to authenticate you, and to provide what the account can do.
Legal basis: Art. 6 (1) (b) GDPR — performance of a contract and steps taken at your request before entering into it.
Recipients: none beyond Hetzner Online GmbH, which runs the servers as our processor (see “Hosting”).
Retention: until the account is deleted, which you can ask for at any time; the data goes with it.

Session cookie

Data: a cookie named bpf_session. It contains your user ID and an expiry date, signed so that it cannot be altered. It carries no rights and no profile; your access level is read from the database on every request.

Purpose: to keep you signed in.
Legal basis: Art. 6 (1) (b) GDPR; storing it on your device is strictly necessary to provide the service you asked for, so no consent is required (§ 25 (2) no. 2 TDDDG).
Retention: 30 days, or until you sign out or delete it in your browser.

Language cookie

Data: a cookie named lang. It contains nothing but the code of the language you are reading the site in — en or de — and no identifier; on its own it says nothing about who you are. Every visitor gets it, with or without an account: it is set on the first page you open that exists in both languages, with the language of that page, and set again whenever you read a page in the other language — switching by the language toggle is exactly that.

Purpose: to remember your choice of language. A first-time visitor whose browser prefers the other language is shown a hint that the page also exists in that language; the cookie is how the site knows it has already said so, and the hint appears once rather than on every page. The language preference your browser sends with every request (the Accept-Language header) is read for that decision and not stored.
Legal basis: storing it on your device is strictly necessary to provide the service you asked for — the site in the language you chose — so no consent is required (§ 25 (2) no. 2 TDDDG). It is not read for any other purpose.
Retention: one year, or until you delete it in your browser.

Server logs

Data: for each request, the IP address in shortened form, the time, the address requested, the response status, the amount of data sent, and the browser identification (user agent). The address is shortened before the entry is written — the last octet of an IPv4 address and the host part of an IPv6 address are removed — so the access log records the network a request came from, not the individual connection. The full address is written only when the application rejects a request as forged: a form sent without a valid security token — and, once payments are open, a payment notification with an invalid signature. Those are the lines one needs to trace an attack.

Purpose: to operate the service, to find faults and to defend against attacks and abuse.
Legal basis: Art. 6 (1) (f) GDPR; our legitimate interest is a service that runs and can be defended.
Recipients: Hetzner Online GmbH as our processor (see “Hosting”).
Retention: the logs are rotated by size, not by date: when a log file reaches a fixed size it is closed, and once a fixed number of such files exists the oldest is deleted. How long an entry survives therefore depends on the amount of traffic — typically weeks, longer when traffic is low. We keep no long-term log archive and no log backup. Logs are not combined with account data and are not used to analyse behaviour.

Page counts: apart from the log, the application counts how often each page is opened — one number per calendar day, per address (the path) and per language, and that is the whole record. It holds no IP address, no cookie, no browser identification and no account: whether the reader was signed in is not written down, nor which pages one visit took in. The count shows us which pages are read and which are not, and nothing beyond that — nothing in it leads back to a person, so it is not personal data and cannot be traced to you.

Search

Data: the words you type into the search, stored as you entered them (up to 2 000 characters), with the time, the filter you set, which documents were found and how long the search took. No user ID, no email address and no IP address is stored with the query — an entry cannot be traced back to the account or the connection it came from, and searching does not require an account. The query also appears once in the application log, in the line that records that a search ran.

Purpose: the quality of the search. What people actually look for is the only thing that shows whether the search finds it — a query that comes back empty is how a gap in the material, a missing synonym or a broken filter is found.
Legal basis: Art. 6 (1) (f) GDPR; our legitimate interest is a search that works and gets better. Because the entry carries no identifier, the weight on your side is slight.
Recipients: none. The queries stay in our own database on our own server; they are not sent to the language model (see “How the briefings are made” below).
Retention: these entries are currently kept without a fixed deletion period; a limit is being introduced, and this section will name it when it is in place. Until then, the honest advice is the same one that applies to any search box: it is a search over public documents, it needs nothing about you, so please do not type anything into it that you would not want kept.

Email

There is no mailing and no newsletter. We send exactly four kinds of message, each one triggered by an action on the site — three of them by you, one of them by someone else:

  • Confirming your address when you create an account — the account stays inactive until you follow that link.
  • A notice that an account with your address already exists, sent to you when someone enters your address in the sign-up form. No second account is created, and the person who typed it learns nothing: the page looks the same either way. The message goes to you, so that the attempt is not invisible to the one person it concerns, and it contains a link to sign in.
  • A password reset link, when you ask for one.
  • Confirmation of a cancellation, which § 312k (4) BGB requires us to give you in text form.

Processor: Resend Inc. dispatches these messages on our behalf as a processor under Art. 28 GDPR, on a data processing agreement. What reaches it is your email address and the text of the message — nothing else from your account.

Legal basis: Art. 6 (1) (b) GDPR for the account messages, because without a confirmed address there is no account; Art. 6 (1) (f) GDPR for the notice that an account already exists — the legitimate interest is protecting the holder of that account, who is the only person entitled to learn of the attempt, and it is also what keeps the sign-up form from becoming a way to test whether an address is registered here (for a confirmed account the message is at the same time part of administering it, Art. 6 (1) (b) GDPR); Art. 6 (1) (c) GDPR for the cancellation confirmation, which is a statutory duty.

Transfer: the processor is based in the United States. The transfer is covered by the EU–US Data Privacy Framework where the provider is certified under it, and otherwise by standard contractual clauses under Art. 46 (2) (c) GDPR.

Payment

Today there is no payment. No subscription can be taken out, no payment provider is engaged, and no payment data of yours is processed — not by us, not by anyone on our behalf. What follows is what will apply once paid subscriptions open, and this section will name the provider before the first payment is possible.

Paid subscriptions will be sold by a payment provider as merchant of record. You would enter your payment details in that provider's own payment window. Card details would never reach our server, and we would neither see nor store them.

Roles: for the payment, the invoice and the tax obligations attached to them, the provider would act as an independent controller, not as our processor. Its own privacy notice, published on its website, would apply to that processing.
What we would receive back: the fact that a subscription exists, which plan it is, and its status — enough to unlock your access, and no payment data.
Legal basis: Art. 6 (1) (b) GDPR for the contract; Art. 6 (1) (c) GDPR for the retention obligations under commercial and tax law that would follow from it.
Retention: subscription status for as long as the account exists; documents subject to retention obligations for the statutory periods, which are six or ten years under German law.

Hosting

The service runs on a server rented from Hetzner Online GmbH, Gunzenhausen, Germany, in its data centre in Finland. The provider is the company, the data centre is the place — they are two different countries, and both are in the European Union.

Hetzner Online GmbH processes data only on our instructions, as our processor under Art. 28 GDPR and on a data processing agreement (Auftragsverarbeitungsvertrag) concluded with us, and only to run the server. No data is stored outside the EU for the operation of this site.

How the briefings are made, and the language model

The briefings are written with the help of a language model operated by DeepSeek. What is sent there are the public source documents — the publications of central banks, statistical offices, supervisors, ministries and international institutions that we read anyway — together with our own instructions. No user data is sent: not your email address, not your reading interests, not your search queries, and nothing that could identify you.

DeepSeek is based in China. As long as only public documents are transmitted, this concerns no personal data of yours. If that changes — the chat function is the case to watch: it would send what a user types to the model — this is a transfer to a third country without an adequacy decision within the meaning of Art. 44 ff. GDPR, and it is named here as one. Such a transfer would be based on standard contractual clauses under Art. 46 (2) (c) GDPR or, where none apply, on your explicit consent after being informed of the risks under Art. 49 (1) (a) GDPR. As things stand, the chat is not part of the offer and is enabled for administrators only; if it is opened to customers, it will be with the consent step described here and this section will say so.

Personal ordering, and no automated decisions

There is no automated decision-making producing legal effects concerning you and no profiling within the meaning of Art. 22 GDPR. The order in which items appear can be adapted to what you have said you want to read about.

Personalisation reflects stated reading interests, not financial circumstances. We never ask for your positions, your holdings, your assets, your investment objectives or your risk appetite — not in the profile, not in a form, not anywhere — and so we cannot order anything by them. That sentence stands at the head of every briefing, and it is a design constraint, not a promise of good behaviour.

Your rights

You have the right to:

  • obtain confirmation and a copy of the data we hold about you (Art. 15 GDPR),
  • have inaccurate data corrected (Art. 16 GDPR),
  • have your data erased (Art. 17 GDPR),
  • have processing restricted (Art. 18 GDPR),
  • receive the data you provided in a structured, commonly used and machine-readable format and have it transmitted to another controller (Art. 20 GDPR),
  • object at any time, on grounds relating to your particular situation, to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR),
  • withdraw consent at any time, with effect for the future, where processing is based on consent (Art. 7 (3) GDPR),
  • lodge a complaint with a supervisory authority (Art. 77 GDPR).

For a complaint you may turn to the supervisory authority of your habitual residence or place of work, or to the authority responsible for us. Responsible for us is the data protection authority of the German federal state in which we are established, and that is Bavaria:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany

To exercise any of these rights, write to jpuosi@gmail.com. We answer within one month and ask for nothing beyond what is needed to be sure it is you.

Is any of this required?

Reading browsepublicfinance.com requires nothing from you: no account, no name, no email address. An account requires an email address, because it is how you sign in and how we reach you about the account — without it there is no account, and that is the only consequence. Payment data is required for nothing at all today, because no subscription can be taken out; once one can, it will be given to the seller, not to us.

Changes to this policy

We update this policy when the service changes. The date below says when it was last changed. Where a change affects a processing operation that concerns you materially, we say so by a notice on the site, shown to you when you sign in.

Last updated: 2026-09-03.

← All legal documents