Politika privatnosti
Verzija 2.4, na snazi od 4 oktobar 2026
Pravni dokumenti se vode samo na engleskom jeziku. Merodavan je jedan tekst; prevod bi bio drugi tekst, a dva teksta se vremenom razilaze.
1The short version
We do not look at what is on your server, except in four narrow cases. We do not read, copy, scan, index, analyse or review the data, code, prompts, conversations or files on it in the ordinary course of business, we never use any of it to train or evaluate anything, and no automated system of ours monitors it. A person from our team looks at it only when you ask us to, when you share a project with our team, when we have a specific reason to suspect a security incident on the machine, or when a court or authority in the United Kingdom or the European Union requires it by law, and in each case only as far as that case needs. Clause 8 of the Terms of Service sets out these cases as a contractual promise, with the limits we keep to in each.
What is left is the ordinary business of running a website and a subscription: an account, an email address, a payment, a message you send us. This document says what that is, who else sees it and what you can make us do about it.
2Who is responsible
The controller for the data described here is the operator of combobulating: Ohmyfin Limited, a company registered in England and Wales under company number 15431563, with its registered office at 275 New North Road, Islington Suite 1422, London, England, N1 7AA . Write to hello (at) combobulating (dot) ai for anything in this document, including a request under section 9. We answer from that address, and we answer people, not ticket numbers.
We have not appointed a data protection officer, because we are not required to. If that changes we will name one here.
3What we collect, and why
| What | Why | Legal basis | How long |
|---|---|---|---|
| Name and email address | To have an account. There is no password on this site, so the address is not a label on the account: it is the account, and signing in means showing you can read that mailbox | Performance of the contract | While the account exists, then 30 days |
| Your name and email address, used for mail about masterclasses and news of our own service, together with which of those mails went to you and whether you have unsubscribed | To invite you to live masterclasses and tell you what is new at combobulating. It is sent from noreply@combobulating.ai, only to people who have an account with us, and never about anyone else's products. Every one of these mails carries an unsubscribe link, and the unsubscribe button your mail program shows beside it works too, in one click and without signing in. Unsubscribing stops this mail and nothing else: sign-in codes and messages about your server keep coming, because the service cannot be used without them | Legitimate interest in telling the people who have an account with us about our own service. You can object at any time by unsubscribing, and we stop | While the account exists. If you unsubscribe we keep the date you did, so that we never write to you again by mistake |
| Sign-in codes, and the code that confirms a request for a call: the address one was sent to, the code itself stored hashed, how many wrong guesses were made against it, and the address on the internet it was asked for from | To let you in, and to stop somebody else being let in as you. The code is hashed rather than kept, because a six-digit code sitting readable in a database is a live session for whoever reads it, and the count of wrong guesses is what stops somebody working through the million of them | Contract, and our legitimate interest in the security of your account | The code stops working after ten minutes, or the moment it is used. The record that one was sent is kept |
| The optional answers on your profile: whether you have run an agent, what you would pay, what you want to be contacted about | To know who we are building for, and not to ask a practitioner beginner questions | Consent, and every answer is optional and editable | While the account exists |
| Plan, subscription state, invoices | To sell you a server and to account for it | Contract, and legal obligation for the accounting records | As long as tax law requires, normally up to 10 years |
| Payment details | To take payment | Contract | We never hold card numbers; Stripe does. See section 5. Stripe collects your billing address and, if you are a business, your VAT number, to work out the tax, and tells us the tax on each invoice. |
| Messages you send: the contact form, a quote request, a consultation request, a question under a case, and a support conversation about your machine, with the browser and the language they arrived with. The contact form and the question form record the address on the internet they came from as well; the other three do not | To answer you, and to tell a person from a bot | Contract before it is signed, and our legitimate interest in not being flooded with spam | 2 years from the last message in the thread |
| A request for a call (the Demo button): your name, your address, what you told us you know about agents and what you want from the call, with the browser and the language it arrived with; then the time you pick for it, and the time zone your browser was in when you picked it | To arrange the call and to know what it is about before it starts. The request is shown to the two founders, and the call is entered in their calendars with your name, your address and what you told us | Steps you asked us to take, and our legitimate interest in answering you | 2 years from the call, or from the request if no call follows |
| The consultation your plan includes: what you want to talk about, when suits you if you tell us in words, the time you pick for it off our calendars, and the time zone you picked it in | To hold the call and to know what it is about before it starts. A time you pick is entered in the two founders' calendars with your name, your address and what you want to talk about | Contract | 2 years from the call, or from the request if no call follows |
| A screenshot or a file you attach to a support message | To look at the fault rather than have it described to us. It is scanned before it is stored, is never served to the web, and is handed back only to you and to us through the thread it belongs to | Contract | With the thread it is attached to |
| A case you offer us, and the files you upload with it | To review, edit, translate and publish it. See section 6 | Contract, and consent for anything personal you chose to include | Published cases stay up; declined material is deleted within 12 months |
| Whether you found a walkthrough worth watching, and the note you chose to leave with it | To decide what the next walkthrough looks like. You have to be signed in to answer, so it is tied to your account; nothing you write is published, and it is never shown to another reader | Consent, and both the verdict and the note are optional and you can take them back | While the case is published, or until you withdraw it |
| Why you cancelled, if you tell us: the reason you picked, whether you would rent one again, and anything you chose to write | To find out what to build next. You are asked after the cancellation has already gone through, never before it, so nothing you answer or decline to answer changes anything about your subscription. Nothing you write is published or shown to another customer, and we write back about it only if you tick the box that says we may | Consent, and every answer is optional including the reason | 3 years from the cancellation |
| Counts of which buttons are pressed, by day, page and language, how many times each walkthrough has been played, how many players reached a quarter, a half, three quarters and the end of it, and how many times each article has been read | To see which parts of the site are used, to decide how long to make the next walkthrough, and to print under a walkthrough or an article how many times it has been watched or read. These are totals only: no identifier, no IP address, no account and no cookie is stored with them, so no count can be traced back to a person, including you. See section 7 | Legitimate interest in knowing what is used. There is nothing personal in the result to weigh against it | Indefinitely, because a count of presses is not about anyone |
| Reports of JavaScript errors: the error message, the script it came from, the page by name, and the browser family and version | To find and fix the pages that break in your browser. These are grouped by fault and counted, not logged one by one: no identifier, no IP address, no account, no cookie and not even the address of the page is stored with them, so no report can be traced back to a person, including you. See section 7 | Legitimate interest in a site that works. There is nothing personal in the result to weigh against it | Indefinitely, because a broken button is not about anyone |
| Which days you used what you bought: the day, one thing you did that day out of a short fixed list (opened your machine, asked it to restart or rebuild, connected a folder or changed what we may do to it, answered a change we proposed, watched a masterclass, took a case's files, asked for the call your plan includes), and which plan you were on at the time | To find out whether the people who buy something come back to it, which is the one thing a count of visits cannot tell us: seven visits is one person with a habit or seven people who each came once, and we would build different things for those two. This is the only measurement on this site that is kept against an account, and it is cut down to the least that can still answer that: the day and never the hour, the kind of thing and never which one, so it records that you watched a masterclass on a Tuesday and can never say which masterclass. It is not kept at all unless you have a live subscription, and how many times you did something in a day is not counted | Legitimate interest in knowing whether what we sell is worth what is paid for it. We weighed it against you and that is why it holds a day, a verb and a plan and nothing else. See section 7 | While the account exists, and deleted with it |
| Session and security logs: IP address, browser, timestamps | To keep you logged in and to see an attack for what it is | Legitimate interest in the security of the service | Up to 90 days |
| An SSH public key you give us: the key, the name you put on it and its fingerprint | To install it on your machine so you can log in with it. A public key is the half of a pair that is meant to be handed out; we never ask for the private half and you should never send it to anyone, us included | Contract | While the account exists. Removing a key marks it withdrawn rather than deleting the record, because the key is still on the machine until the file there is written again, and the record is what says so |
| On a Mini only: a log of the connections it opens to the internet, meaning which Mini, the address and port it connected to, and when. Never what was sent | A Mini shares its server's IPv4 address with the other Minis on it, so when a complaint names that address this is how we find the one Mini it was about, rather than cutting off all of them | Legitimate interest in the security of the service | Up to 90 days |
| Server operations data: which machine is yours, when it was provisioned, how much CPU, memory and disk it is using, whether it is up | To run the machine and to bill it. It is about the box, not about what is on it | Contract | While you rent it, then 90 days |
We do not sell data, we do not rent it, and we do not use it for advertising by anyone else. We do not profile you or make automated decisions with legal effects about you.
4Your server, and who is responsible for what is on it
Two different things share one machine and the law treats them differently.
- Your account and your subscription: we decide what to collect and why, so we are the controller, and section 3 is the list.
- Everything you or your agents put on the server: you decide what it is and what it is for, so you are the controller and we are your processor for the hosting of it. If that data includes personal data about other people, having a lawful basis for it is your job, as clause 6 of the Terms of Service says.
As your processor we act on your instructions, and asking us for help or sharing a project with our team is an instruction of that kind. The other two cases in clause 8 of the Terms, a suspected security incident and a legal obligation, are the ones data protection law itself asks of a processor: keeping the processing secure, and complying with UK or EU law it is subject to (Articles 32 and 28(3)(a) of the GDPR and the UK GDPR).
If you need a data processing agreement under Article 28 GDPR, ask us at hello (at) combobulating (dot) ai and we will sign one.
5Who else processes data
These are everyone outside the team who handles data for us, what they do and where. We use no others, and we will update this list before we add one.
| Who | What they do | Where |
|---|---|---|
| Hetzner Online GmbH | Hosts the servers we rent to you and the servers this website runs on | Germany and Finland (EU) |
| IONOS SE | Hosting, domains and DNS for parts of our infrastructure | Germany (EU) |
| STRATO GmbH | Domains, DNS and mail for some of our addresses | Germany (EU) |
| Anthropic PBC | The language model behind Claude Code, and the pipeline that checks, structures and translates a case you send us. Note that when your agents call Claude they do it under your own Anthropic account, on your agreement with Anthropic, and we are not in the middle of it | United States |
| Amazon Web Services EMEA SARL (Amazon SES) | Delivers the email we send you, sign-in codes and mail about masterclasses alike, and receives the email you send to our addresses | Sweden and Ireland (EU), with group companies in the United States |
| Stripe Payments Europe Ltd | Takes payment and holds the card details we never see | Ireland (EU), with group companies in the United States |
| Google Ireland Ltd (Google Calendar) | The calendar of one of the two founders. A call you book with us is entered in it with your name, your address and what you told us the call is about | Ireland (EU), with group companies in the United States |
| Google Ireland Ltd (Google Analytics) | Counts visits so we can tell whether anything we write is read. In the EEA and the UK it runs only for someone who has pressed accept on the cookie banner, and elsewhere until you turn it off in the footer. See section 7 | Ireland (EU), with group companies in the United States |
Transfers outside the EEA. Anthropic is in the United States, and Stripe, Google and Amazon have group companies there. Those transfers are made under the European Commission's standard contractual clauses, together with the measures those providers publish. Everything else in the list stays in the EU.
6Cases you send us, and the pipeline that reads them
If you offer us a case, what you upload goes through an automated pipeline that uses a language model to check it for problems, work out whether it says enough, structure it, expand it and translate it. That is Anthropic processing your material, on our account, as our processor.
Two things follow, and they are the reason this has a section of its own. First, do not upload anything confidential, personal or secret: strip customer names, credentials and anything under an NDA before you send it, as clause 14 of the Terms of Service requires. Second, this is the one place where a machine of ours reads something you wrote, and it happens because you sent it to us to be published. It is nothing to do with the server you rent, which nobody reads.
Uploaded files are held on a quarantine store, are scanned for malware, are never served to the web, and are deleted with the submission.
7Cookies and analytics
The site sets two cookies of its own and neither one needs your consent: a session cookie, so you stay logged in, and a CSRF token, so a form you submit is the form we sent you. Both go when the session ends. Open a page in English, Russian, Serbian or Portuguese and we set a third, holding those two letters and nothing else, so that the next time you arrive without saying which language you want you get the one you were reading. It lasts a year and you can change it at any time from the language control in the header. If you answer the cookie banner, or use the analytics control in the footer, we set a fourth, holding nothing but the word you pressed, so that your answer holds on the next page. It lasts twelve months.
Whether Google Analytics runs depends on where you are. We use it to count visits, so that we can tell whether anything we write here is read. In the EEA and the UK, and wherever we cannot work out where you are, it runs only if you press accept: it does not load, and it sets nothing, until you have pressed accept on the banner, and we do not treat carrying on browsing as consent. Everywhere else there is no banner and it runs from the first page you open, on our legitimate interest in knowing whether what we write is read, until you turn it off with the control in the footer. When it does run it sets two cookies of its own, holding a random identifier for the browser rather than anything that names you; they last up to two years. We do not send Google your name, your email address or anything you have written to us through Analytics.
The footer of every page carries a one click control that turns Analytics off, and back on again, wherever you are; where we show the banner, it appears once you have answered it. Turn it off and the tag stops loading on the very next page you open; the cookies Google has already set stay in your browser until they expire or you clear them, which your browser can do at any time.
We put the banner in front of visitors in the EEA and the UK, and in front of anyone whose country we cannot work out. To decide which you are, we look your IP address up in a copy of the MaxMind GeoLite2 country database that sits on our own server. That lookup happens in memory, we do not store your address to do it, and nothing about it leaves our machines: asking a geolocation service would mean handing your address to a company in order to decide whether we are allowed to track you. We use the same lookup to show prices in euro in Europe and in US dollars elsewhere; a switch on the pricing page changes it for your visit.
We also count presses, and that one is not about you. When you press something on this site the browser sends us the name of the button, the page it was on and the language you were reading in, and our own server adds one to a total for that day. That is the whole of it. Nothing is written to your browser and nothing is read from it, no identifier of any kind is made, the address the message arrived from is thrown away rather than stored, and if you are signed in your account is not mentioned. The table it lands in holds a day, a button, a page and a number, which means it cannot answer the question «what did this person do», by design and not by policy. That is why it runs for everyone, including anyone who pressed reject: there is nothing here to consent to under the cookie rules, because nothing is stored on your device and nothing about you is stored on ours.
The number under a walkthrough is the same kind of counting. When ten seconds of a video have actually played, your browser tells our server that it happened and the server adds one to a total kept against that video. The total is what the page prints. Nothing is written to your browser to do it and nothing is read from it, so watching the same walkthrough twice counts twice: we would rather the number were a little generous than mark your device to make it exact.
We also count how far into a walkthrough people get, and that is not about you either. As a video plays, your browser adds up the seconds of it that have actually played, and when that reaches a quarter, a half, three quarters and all of it, it tells us so. What arrives is the mark, which video it was and the language you were reading in, and our server adds one to a total for that day, in the same table the button presses land in. It is not a record of where you stopped or of which parts you watched: four counters go up, nothing is stored against you, nothing is written to your browser and nothing is read from it, and if you are signed in your account is not mentioned. We use it to decide how long to make the next one.
The number under an article is the same counting again. When one of our longreads has been the tab you are looking at for ten seconds, your browser tells our server that it happened and the server adds one to a total kept against that article in that language. The clock stops while the tab is in the background, so a link you opened and never came back to is not counted. Nothing is written to your browser to do it and nothing is read from it, exactly as above. The one thing our server does look at is the name your browser gives itself in the request, and it looks at it only to drop the search engines and scripts that would otherwise be counted as readers; it is used to make that decision and thrown away with the request, never stored beside the total or anywhere else.
And when a page breaks, the browser tells us what broke. If something in the site's own code throws an error while you are reading, your browser sends us the message, the script it came out of, the line it was on, and the name of the route the page was built from. It does not send the address of the page you were on, because an address on the customer side of the site carries a support reference and a case name, and this has no business holding either. We also record which browser family and major version it was, worked out here from the request and not stored as your browser sent it, because the fix usually depends on knowing that much and no more. Nothing is written to your browser and nothing is read from it, no identifier is made, the address the report arrived from is thrown away, and if you are signed in your account is not mentioned. Reports are grouped by fault rather than kept one by one, so the table holds a message, a script, a page and a number: it cannot answer «what did this person do» for the same reason the press counts cannot, by design and not by policy.
One measurement here IS about you, and it is the only one. If you are paying for something, we mark the DAY you used it: that you opened your machine, or watched a masterclass, or answered a change we proposed, together with the plan you were on. We do it because the question we need answered cannot be asked of a total. Everything above counts things and forgets people, and a total by day cannot tell one customer coming back every week from a stream of strangers arriving once; that difference is the whole of whether what we sell is useful, so we ask it about the smallest possible thing and about customers only. The mark holds the day and never the hour, the kind of thing and never which one, so it can say you watched a masterclass on a Tuesday and can never say which masterclass, which machine, which file. It does not count how many times. Nothing is written to your browser and nothing is read from it, and if you are not paying for anything nothing is written at all. It goes when the account goes. Section 3 is the row for it, and section 9 is how to ask for a copy of it or to object to it.
There is no advertising, no advertising network and no tracking pixel on this site.
8Security
There is no password on this site, so there is none to guess, reuse or leak: signing in is a six-digit code sent to your mailbox, and that code is stored hashed, stops working after ten minutes and dies the moment it is used. The site is served over TLS. Uploads are scanned before they are stored and are kept off the web. Administrative access to the servers is by key, limited to the people who need it, and used only for the purposes in clause 8 of the Terms of Service.
No security is perfect. If a breach puts your rights at real risk we will tell the supervisory authority within 72 hours and tell you without undue delay.
9Your rights
Under the GDPR and the UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to you in a portable form. You can object to anything we do on the basis of legitimate interest, and you can withdraw a consent at any time, which does not undo what we did before you withdrew it.
Mail about masterclasses and news you can stop yourself, at any time: the unsubscribe link at the foot of any of them does it in one click, with no need to sign in, write to us or give a reason.
Write to hello (at) combobulating (dot) ai. We answer within one month. You do not have to give a reason, and we will not make it hard. Some things we have to keep whatever you ask, mainly invoices, and we will tell you which and why.
You can also complain to a supervisory authority in the country you live or work in. We would rather you told us first, and we will still fix it if you do not.
10Children
The service is for adults and is not directed at children. We do not knowingly collect data about anyone under 18. If you think we have, tell us and we will delete it.
11Changes
We will publish a new version here with a new date, and where a change matters we will tell you by email at least 30 days beforehand. The date at the top of this page is always the date of the version you are reading.
Pitanja, zahtevi i obaveštenja u vezi sa ovim dokumentom: hello (at) combobulating (dot) ai
Ostali dokumenti: Uslovi korišćenja Pravila prihvatljive upotrebe