Privacy Policy
Umfeld processes contact data — which, by its nature, means personal data, and not only your own. Here's what that data is, why we process it, who gets to see it, and how you can stop the processing again.
01Data controller
The controller responsible for data processing on this website and within the Umfeld service, as defined in Art. 4(7) GDPR, is:
von Reyher Media UG (haftungsbeschränkt) Nonnendamm 33-35 13627 Berlin Deutschland Email: kontakt@vonreyher.media
02The idea in two sentences
Umfeld is a personal CRM: it mirrors your Google address book and enriches it with context you enter yourself. We do not sell data, we do not analyze your contacts for advertising, and we do not use your content to train AI models.
03Hosting and log data
The application and database run with providers within the EU, or on the basis of a data processing agreement under Art. 28 GDPR. Accessing the site produces technically necessary server logs:
- truncated IP address, date and time of the request
- the requested URL, HTTP status code, and amount of data transferred
- referrer URL as well as browser and operating system identification (user agent)
The legal basis is Art. 6(1)(f) GDPR: our legitimate interest in secure and stable operation. Logs are deleted after 30 days at the latest, unless they are needed to investigate a specific case of misuse.
The web application, the database, and all background services run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in data centers located in Germany. A data processing agreement under Art. 28 GDPR is in place with Hetzner. No transfer to countries outside the EU takes place for hosting.
04Account and sign-in with Google
An Umfeld account is created exclusively via “Sign in with Google.” There is no separate password. From Google, we receive and store:
- your Google account ID, name, email address, and profile picture
- an access token and a refresh token, so contact sync can run even without an active session
- the permissions (scopes) you actually granted
The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract). The tokens are stored in our database and used only for the synchronization described below. You can revoke access at any time in your Google account ; synchronization then stops immediately.
05Synchronizing your Google contacts
With your consent given in the Google permission dialog, Umfeld reads your address book via the Google People API. We only request read access:
- contacts.readonly: reading your contacts. This is the foundation of the service. Umfeld does not write anything back to Google.
We store the contact data present in your address book: names, email addresses, phone numbers, postal addresses, organizations and job titles, birthdays and anniversaries, notes, profile pictures, as well as technical identifiers from Google (resourceName, etag, sync token) that make incremental updates possible in the first place.
Use of this data is subject to the Google API Services User Data Policy, including its Limited Use requirements. In practice this means: we use contact data exclusively to provide you with Umfeld’s features. We do not share it with third parties, do not use it for advertising, and do not use it to train or fine-tune AI models.
06Other people's data: your role
Umfeld holds almost exclusively data about other people. That is not a side effect but the purpose of the service, and it comes with a responsibility we cannot take off your hands:
- If you use Umfeld purely privately for your personal circle, the household exemption under Art. 2(2)(c) GDPR generally applies. The GDPR is then not applicable to your use.
- If you use Umfeld professionally or commercially, you are yourself the controller under the GDPR for the contacts stored there, with all associated obligations, in particular the information duties under Art. 14 GDPR toward the data subjects.
- In both cases, we process this data only on your instructions and do not inspect its content, except where unavoidable for troubleshooting.
For business use we provide a data processing agreement under Art. 28 GDPR at umfeld.app/dpa; it becomes part of the service contract upon its conclusion. If a data subject contacts us directly, we forward the request to you or help you answer it.
07Access by AI clients (MCP)
Umfeld provides a server based on the Model Context Protocol. When you connect an AI client (such as Claude, ChatGPT, or an editor), you grant that client its own access token, scoped to your account, via an OAuth dialog.
- Access happens only if and as long as you grant it; you can revoke it at any time in the “Connections” area.
- Once a client retrieves data, that data leaves our service and becomes subject to that provider's own privacy policy. Check what the provider does with transmitted content before connecting.
- We log which client last accessed your data and when, to give you an overview.
The legal basis is Art. 6(1)(a) and (b) GDPR.
08AI features (OpenAI)
Umfeld generates short summary texts from your contact data and converts notes into vectors (embeddings) so you can search them by meaning. For this, we transmit the necessary data to OpenAI, L.L.C. (USA) as a processor via their API.
- Only the data of the relevant contact or note is transmitted, never your entire address book at once.
- Content you have marked as private (private relationship chapters, private notes, private facts) is not transmitted and does not appear in summaries or search.
- Under OpenAI's API terms, content submitted via the API is not used to train models.
- We store the generated texts and vectors in our database; they are deleted together with the contact or note.
The legal basis is Art. 6(1)(b) GDPR. The transfer to the USA relies on the standard contractual clauses under OpenAI’s Data Processing Addendum.
09Cookies
Technically necessary are a session cookie that recognizes you after sign-in and the associated security cookies of the OAuth flow. These cannot be switched off; the legal basis is § 25(2) no. 2 TDDDG (the German telecommunications-digital-services data protection act). Beyond those we set a cookie for audience measurement only after your explicit consent (section 10). Your decision itself is also stored in a cookie and can be changed at any time via „Cookie settings“ in the footer. We set no advertising cookies.
10Audience measurement (PostHog)
If you consent in the cookie banner, we use PostHog to measure which pages are opened and which elements are clicked. The purpose is to see where people drop off and which content actually gets read. Without your consent PostHog is not loaded at all: no scripts are fetched and no cookies are set.
- The provider is PostHog. We use the EU cloud (eu.i.posthog.com), and processing takes place in the European Union.
- Collected are the pages opened, the controls clicked, browser and device type, an approximate location derived from the IP address, and a randomly generated identifier stored in the cookie.
- Session replay is disabled. We see no recordings of your session.
- The measurement data is not merged with your Umfeld account and is not sold to third parties.
The legal basis is your consent under Art. 6(1)(a) GDPR and § 25(1) TDDDG. You can withdraw it at any time via „Cookie settings“ in the footer; withdrawal takes effect going forward. On withdrawal the identifier stored in your browser is reset. Event data already collected is stored in PostHog’s EU cloud and deleted once the retention period configured there expires.
11Retention period
We store your contact and context data for as long as your account exists. If you delete your account, the account, tokens, and all associated contact, interaction, and graph data are completely removed from the production database within 30 days; backups expire after a further 30 days at the latest. Statutory retention obligations remain unaffected.
12Data security
Contact data is sensitive data, and mostly data about third parties. We protect it with the following technical and organizational measures:
- Every connection is encrypted: the application is reachable over HTTPS (TLS) only, with enforced transport security (HSTS). This includes the synchronization with Google and access by AI clients.
- The database is not reachable from the internet. It runs on an internal network on servers located in Germany; only the web application and its encrypted endpoints are exposed, and a firewall blocks everything else.
- The OAuth access tokens issued by Google are stored server-side only. They never leave the server and are not passed to the browser or to any third party.
- Access to contact data always requires your authenticated session. AI clients only gain access after your explicit OAuth authorization, per client, revocable at any time.
- Administrative access to the server is restricted to key-based SSH authentication.
- Google user data is not sold, not used for advertising, and not used to train AI models. For the AI overview feature, OpenAI processes data as a processor; under OpenAI's API terms, data submitted via the API is not used to train models.
- If you delete your account, all stored data including synchronized contacts and OAuth tokens is deleted completely and irreversibly (see retention period).
Should we detect a personal data breach despite these measures, we will notify the competent supervisory authority and, where required, affected users in accordance with Articles 33 and 34 GDPR.
13Your rights
You have the following rights against us:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability in a common, machine-readable format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
An informal message to kontakt@vonreyher.media is sufficient for any request. Regardless of this, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
14Changes to this policy
We adapt this policy when the service or the legal situation changes. The version published here is authoritative; we announce material changes in advance by email or within the application. You can find the terms of service under Terms of Service.