Privacy notice
Information pursuant to Art. 13 GDPR · As of: July 2026
This site is a preview: the JACVault product has not opened for U.S. applicants yet, so there are no accounts and no payments here. This notice covers what the site itself does — hosting, a bot check on the sign-up form, analytics you can switch on or off, and the early-access list. The privacy policy of the product comes with the product, and this page will point to it.
Who is responsible
The controller for this processing is:
Alexander Vitanyi, Pettenkoferstr. 10, 10247 Berlin, Germany
You can reach us any time at [email protected].
Visiting this site
This website is hosted by Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA) as our processor under a data-processing agreement pursuant to Art. 28 GDPR. Like any web host, Cloudflare processes the connection data that a request produces — including your IP address, the page you requested, your browser and the time — to deliver the page and to keep the service available.
That happens for every visit and does not depend on your consent: without it there is no way to send you a page at all. The legal basis is our legitimate interest in operating a working, secure website (Art. 6 (1) (f) GDPR). We do not build visitor profiles from it and do not use it to identify you.
How long: Cloudflare keeps such request logs for a maximum of seven days and deletes them afterwards. We do not receive them at all — access to raw request logs is an enterprise feature we do not use, and log retention is off by default. What our hosting dashboard shows us are aggregate counts, never individual visits.
Nothing of ours is stored on your device when you arrive. We set no cookie, and your browser storage stays empty until you act: deciding in the cookie banner stores that decision, and dismissing or following the hint that points German-speaking visitors to jacvault.de stores which site you picked. If you allow analytics, PostHog adds its own identifiers. All of them are listed under "Cookies and browser storage" below.
The bot check on the sign-up form
The early-access form is protected by Cloudflare Turnstile, which separates automated submissions from real ones. Without it, anyone could make our server send confirmation emails to addresses that never asked for them.
For that check, Cloudflare processes technical characteristics of your browser and your IP address, on our behalf and under the same Art. 28 agreement. Turnstile sets no advertising cookies, follows you to no other site, and builds no profile of you. The legal basis is our legitimate interest in protecting the form and our sending domain from abuse (Art. 6 (1) (f) GDPR).
How long: the token your browser receives is single-use and expires after five minutes. Our server checks it once and stores neither the token nor anything else about the check — nothing from it is attached to your entry on the list. For the signals on its own side Cloudflare does not name a fixed period in its Turnstile Privacy Addendum, so we do not quote one here; you can read it at https://www.cloudflare.com/turnstile-privacy-policy/
Analytics — only if you say yes
If you agree in the banner, we use PostHog to see in aggregate how this site is used. We use it to find out which pages actually help people — not to recognise individuals.
For every page view, PostHog receives which page you opened — its address including any parameters in the link you followed, and the page title — and which page the visit started on. It also receives where the visit came from: the address of the page that linked to you including any parameters it carries, its domain, the search engine if it was one, and any campaign parameters in that link, such as utm_source, utm_medium and utm_campaign. And it receives roughly which region the visit comes from, derived from the IP address.
Along with that go technical characteristics of your device and browser: browser and browser version, operating system, device type, browser language, screen size, window size and time zone.
Finally there are the identifiers listed further down, a random identifier for each page view, the time of the page view, and details of the measurement itself: the version of the analytics library, our project key, and which of PostHog's optional features are active for this site. The identifiers and those timestamps are what show us how long a visit lasts and which pages follow one another.
This only happens after your consent, and it is the only thing the banner asks for. The legal basis for storing the identifiers and for the analysis is your consent (§ 25 (1) TDDDG, Art. 6 (1) (a) GDPR). Without it no analytics script is loaded at all, and no analytics identifiers are written to your browser storage.
You can withdraw your consent at any time, with effect for the future, via "Cookie settings" in the footer. When you do, we switch the measurement off and delete the identifiers it set.
The measurement runs over our own subdomain t.jacvault.com, so your browser does not talk to a third-party domain. Behind it is PostHog's EU infrastructure: the data is processed and stored in PostHog Cloud EU, on servers in Frankfurt, Germany. Our processor under Art. 28 GDPR is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, which runs that EU infrastructure; support and administration can involve access from the United States. PostHog Inc. is certified under the EU–U.S. Data Privacy Framework, so such a transfer is based on the European Commission's adequacy decision of 10 July 2023. See PostHog's own privacy policy for details: https://posthog.com/privacy
Analytics data is stored in PostHog Cloud EU for as long as our plan keeps it. We cannot shorten that: PostHog fixes event retention by plan, it is not a setting we control.
What we can tell you is that there is nothing in there that points to you as a person. We do not create person profiles, and the measurement is not linked to a person record — the identifier is a random value that lives in your browser and nowhere else. That also means we cannot pick your data out of the measurement on request, because we have no way of connecting it to you (Art. 11 GDPR). What you can do at any time is withdraw your consent under "Cookie settings": the measurement stops and the identifiers are deleted from your device.
Cookies and browser storage
To remember your decision about analytics, we store one entry in your browser ("jac-cookie-consent"). It is technically necessary to respect your choice, contains no personal data and is never sent to anyone (Art. 6 (1) (f) GDPR).
If you dismiss the hint that points German-speaking visitors to jacvault.de — or follow it to jacvault.de — we store a second entry ("jac-site-pref") so we do not show it to you again. Same story: no personal data, never sent anywhere (Art. 6 (1) (f) GDPR).
Everything beyond those two — the identifiers PostHog needs — is only stored after you have said yes, and is removed again when you withdraw.
Both of those entries stay on your device until you clear your browser storage; they carry no expiry date of their own. PostHog's identifiers, if you allowed analytics, are a cookie that expires after twelve months plus a few browser-storage entries that last until you clear them or close the tab. Withdrawing your consent removes all of them right away.
The early-access list: what we collect
Your email address. We do not ask for a name, and there is no account.
The form on this site posts to jacvault.com. While you sign up, your browser talks only to us and to Cloudflare, which runs the bot check described above and hosts this site — not to our email provider: we pass the address on to it from our own server.
When you click the confirmation link, we record the exact moment of that click alongside your address. That timestamp is our proof that the consent was actually given (Art. 7 (1) GDPR), and we do not use it for anything else.
The early-access list: what we use it for
To tell you when JACVault opens for U.S. applicants, and to send at most one or two updates before that.
That is the whole purpose. No newsletter, no product marketing beyond those messages, no profiling, no advertising, and no automated decision-making.
The legal basis is your consent, Art. 6 (1) (a) GDPR. You give it by submitting the form and confirming the link in the email we send — until you click that link, no entry is created. You can withdraw your consent at any time, with no reason and no consequence. Withdrawing does not affect the lawfulness of what happened before.
The early-access list: who processes it for us
We use Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; commercial register Berlin-Charlottenburg, HRB 133191) to store the list and to send the emails. Brevo acts as our processor under a data-processing agreement pursuant to Art. 28 GDPR, and the processing takes place on servers inside the EU. Brevo receives your address from our server, not from your browser. What Brevo itself does with data is described in its privacy policy: https://www.brevo.com/legal/privacypolicy/
Your address is not sold, not rented, and not passed on to anyone else. There is no ad tracking on this page, and the confirmation email contains no images and no tracking pixel: there is nothing in it that loads from a server when you open it.
The early-access list: how long we keep it
Only as long as the purpose lasts: until we have sent you the launch notification, or until you withdraw your consent — whichever comes first. Your address is deleted after that. And once the launch notification has gone out, the list has done its job and is deleted as a whole.
If you never confirm, no list entry is ever created. The address only appears in our email provider's sending log for that one message and is not used for anything else.
Every email we send carries a way off the list. The confirmation email has an unsubscribe address in it — as a link at the bottom and in the message header your email app reads; the launch and update emails will carry a one-click unsubscribe link. You can also just write to [email protected] and we will remove you.
Data leaving the EU
Two of our processors are US companies: Cloudflare (hosting and the bot check) and PostHog (analytics, if you switch them on). Both are certified under the EU–U.S. Data Privacy Framework, so transfers to them are based on the European Commission's adequacy decision of 10 July 2023.
Brevo, which holds the early-access list, is a German company and processes the data inside the EU.
Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16) or deleted (Art. 17), to restrict its processing (Art. 18), to object to it (Art. 21), to receive it in a portable form (Art. 20) and to withdraw any consent you gave (Art. 7 (3)). For the early-access list these rights apply in full; for the anonymous analytics measurement they are limited by Art. 11 (2) GDPR, for the reason explained above — we simply have no way to connect the data back to you.
Write to [email protected] and we will handle it. You also have the right to complain to a supervisory authority — for us that is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).