Privacy Policy
Version 1.2, in force from 3 September 2026
The legal documents are kept in English only. One wording is the wording that governs; a translation would be a second one, and two texts drift apart.
1The short version
We do not look at what is on your server. We do not read, copy, scan, index, analyse or review the data, code, prompts, conversations or files on it, we do not use any of it to train or evaluate anything, and we do not do this for security review either. No automated system of ours reads it. Clause 8 of the Terms of Service says the same thing as a contractual promise, including the narrow cases where we do touch the machine.
What is left is the ordinary business of running a website and a subscription: an account, an email address, a payment, a message you send us. This document says what that is, who else sees it and what you can make us do about it.
2Who is responsible
The controller for the data described here is the operator of combobulating: Ohmyfin Limited, a company registered in England and Wales under company number 15431563, with its registered office at 275 New North Road, Islington Suite 1422, London, England, N1 7AA . Write to hello (at) combobulating (dot) ai for anything in this document, including a request under section 9. We answer from that address, and we answer people, not ticket numbers.
We have not appointed a data protection officer, because we are not required to. If that changes we will name one here.
3What we collect, and why
| What | Why | Legal basis | How long |
|---|---|---|---|
| Name, email address, password (hashed) | To have an account and to log into it | Performance of the contract | While the account exists, then 30 days |
| The optional answers on your profile: whether you have run an agent, what you would pay, what you want to be contacted about | To know who we are building for, and not to ask a practitioner beginner questions | Consent, and every answer is optional and editable | While the account exists |
| Plan, subscription state, invoices | To sell you a server and to account for it | Contract, and legal obligation for the accounting records | As long as tax law requires, normally up to 10 years |
| Payment details | To take payment | Contract | We never hold card numbers; Stripe does. See section 5 |
| Messages you send: the contact form, a quote request, a consultation request, and the IP address, browser and language they arrived with | To answer you, and to tell a person from a bot | Contract before it is signed, and our legitimate interest in not being flooded with spam | 2 years from the last message in the thread |
| A case you offer us, and the files you upload with it | To review, edit, translate and publish it. See section 6 | Contract, and consent for anything personal you chose to include | Published cases stay up; declined material is deleted within 12 months |
| Whether you found a walkthrough worth watching, and the note you chose to leave with it | To decide what the next walkthrough looks like. You have to be signed in to answer, so it is tied to your account; nothing you write is published, and it is never shown to another reader | Consent, and both the verdict and the note are optional and you can take them back | While the case is published, or until you withdraw it |
| Counts of which buttons are pressed, by day, page and language | To see which parts of the site are used. These are totals only: no identifier, no IP address, no account and no cookie is stored with them, so no count can be traced back to a person, including you. See section 7 | Legitimate interest in knowing what is used. There is nothing personal in the result to weigh against it | Indefinitely, because a count of presses is not about anyone |
| Session and security logs: IP address, browser, timestamps | To keep you logged in and to see an attack for what it is | Legitimate interest in the security of the service | Up to 90 days |
| Server operations data: which machine is yours, when it was provisioned, how much CPU, memory and disk it is using, whether it is up | To run the machine and to bill it. It is about the box, not about what is on it | Contract | While you rent it, then 90 days |
We do not sell data, we do not rent it, and we do not use it for advertising by anyone else. We do not profile you or make automated decisions with legal effects about you.
4Your server, and who is responsible for what is on it
Two different things share one machine and the law treats them differently.
- Your account and your subscription: we decide what to collect and why, so we are the controller, and section 3 is the list.
- Everything you or your agents put on the server: you decide what it is and what it is for, so you are the controller and we are your processor for the hosting of it. If that data includes personal data about other people, having a lawful basis for it is your job, as clause 6 of the Terms of Service says.
If you need a data processing agreement under Article 28 GDPR, ask us at hello (at) combobulating (dot) ai and we will sign one.
5Who else processes data
These are everyone outside the team who handles data for us, what they do and where. We use no others, and we will update this list before we add one.
| Who | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Hosts the servers we rent to you and the servers this website runs on | Germany and Finland (EU) |
| IONOS SE | Hosting, domains and DNS for parts of our infrastructure | Germany (EU) |
| STRATO GmbH | Domains, DNS and mail for some of our addresses | Germany (EU) |
| Anthropic PBC | The language model behind Claude Code, and the pipeline that checks, structures and translates a case you send us. Note that when your agents call Claude they do it under your own Anthropic account, on your agreement with Anthropic, and we are not in the middle of it | United States |
| Stripe Payments Europe Ltd | Takes payment and holds the card details we never see | Ireland (EU), with group companies in the United States |
| Google Ireland Ltd (Google Analytics) | Counts visits so we can tell whether anything we write is read. Runs only for someone who has pressed accept on the cookie banner. See section 7 | Ireland (EU), with group companies in the United States |
Transfers outside the EEA. Anthropic is in the United States, and Stripe and Google have group companies there. Those transfers are made under the European Commission's standard contractual clauses, together with the measures those providers publish. Everything else in the list stays in the EU.
6Cases you send us, and the pipeline that reads them
If you offer us a case, what you upload goes through an automated pipeline that uses a language model to check it for problems, work out whether it says enough, structure it, expand it and translate it. That is Anthropic processing your material, on our account, as our processor.
Two things follow, and they are the reason this has a section of its own. First, do not upload anything confidential, personal or secret: strip customer names, credentials and anything under an NDA before you send it, as clause 14 of the Terms of Service requires. Second, this is the one place where a machine of ours reads something you wrote, and it happens because you sent it to us to be published. It is nothing to do with the server you rent, which nobody reads.
Uploaded files are held on a quarantine store, are scanned for malware, are never served to the web, and are deleted with the submission.
7Cookies and analytics
The site sets two cookies of its own and neither one needs your consent: a session cookie, so you stay logged in, and a CSRF token, so a form you submit is the form we sent you. Both go when the session ends. If you answer the cookie banner we set a third, holding nothing but the word you pressed, so that we do not have to ask you again on the next page. It lasts twelve months.
Google Analytics runs only if you press accept. We use it to count visits, so that we can tell whether anything we write here is read. It does not load, and it sets nothing, until you have pressed accept on the banner, wherever in the world you are, and we do not treat carrying on browsing as consent. When it does run it sets two cookies of its own, holding a random identifier for the browser rather than anything that names you; they last up to two years. We do not send Google your name, your email address or anything you have written to us.
The footer of every page carries a one click control to take that consent back, which is the same one click it took to give. Take it back and the tag stops loading on the very next page you open; the cookies Google has already set stay in your browser until they expire or you clear them, which your browser can do at any time.
We put the banner in front of visitors in the EEA and the UK, and in front of anyone whose country we cannot work out. To decide which you are, we look your IP address up in a copy of the MaxMind GeoLite2 country database that sits on our own server. That lookup happens in memory, we do not store your address to do it, and nothing about it leaves our machines: asking a geolocation service would mean handing your address to a company in order to decide whether we are allowed to track you.
We also count presses, and that one is not about you. When you press something on this site the browser sends us the name of the button, the page it was on and the language you were reading in, and our own server adds one to a total for that day. That is the whole of it. Nothing is written to your browser and nothing is read from it, no identifier of any kind is made, the address the message arrived from is thrown away rather than stored, and if you are signed in your account is not mentioned. The table it lands in holds a day, a button, a page and a number, which means it cannot answer the question «what did this person do», by design and not by policy. That is why it runs for everyone, including anyone who pressed reject: there is nothing here to consent to under the cookie rules, because nothing is stored on your device and nothing about you is stored on ours.
There is no advertising, no advertising network and no tracking pixel on this site.
8Security
Passwords are stored hashed and never in a readable form. The site is served over TLS. Uploads are scanned before they are stored and are kept off the web. Administrative access to the servers is by key, limited to the people who need it, and used only for the purposes in clause 8 of the Terms of Service.
No security is perfect. If a breach puts your rights at real risk we will tell the supervisory authority within 72 hours and tell you without undue delay.
9Your rights
Under the GDPR and the UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to you in a portable form. You can object to anything we do on the basis of legitimate interest, and you can withdraw a consent at any time, which does not undo what we did before you withdrew it.
Write to hello (at) combobulating (dot) ai. We answer within one month. You do not have to give a reason, and we will not make it hard. Some things we have to keep whatever you ask, mainly invoices, and we will tell you which and why.
You can also complain to a supervisory authority in the country you live or work in. We would rather you told us first, and we will still fix it if you do not.
10Children
The service is for adults and is not directed at children. We do not knowingly collect data about anyone under 18. If you think we have, tell us and we will delete it.
11Changes
We will publish a new version here with a new date, and where a change matters we will tell you by email at least 30 days beforehand. The date at the top of this page is always the date of the version you are reading.
Questions, requests and notices under this document: hello (at) combobulating (dot) ai
The other documents: Terms of Service Acceptable Use Policy