Privacy
The Gestura Index is built for data minimisation: as little as possible is collected — only what running the service actually requires. This policy describes each processing activity individually, with its legal basis and retention period.
The essentials at a glance
Controller
The controller responsible for data processing on this website is Patric Pesch, Sülzgürtel 64, 50937 Köln, Germany, contact@gestura.eu. No data protection officer has been appointed; the statutory conditions requiring one are not met.
Visiting the website (server logs)
Art. 6(1)(f) GDPR · deleted by the provider after a short periodWhen you open a page, your browser transmits technically necessary data to the server — including your IP address, date and time, the requested address, the status code and the amount of data transferred. These logs are created by the hosting provider; they serve operations and attack mitigation only, are not combined with other data and are not evaluated for statistics or analytics. The legal basis is the legitimate interest in a functioning, secure service (Art. 6(1)(f) GDPR). The provider deletes these logs automatically after a short period.
Local storage in your browser
§ 25(2)(2) TDDDG · until you clear your browser's local storageNo cookies are set. Three items are kept in your browser's local storage so the site behaves the way you operate it:
gestura_index_theme Your choice between the light and dark appearance.gestura-basket The identifiers of the entries you added to your selection. This list leaves your device only when you explicitly hand the selection over to the extension.gestura_pages_hidden Which information pages are currently visible, so the navigation does not flicker briefly on your next visit.All three are strictly necessary for the service you explicitly requested and therefore exempt from consent under § 25(2)(2) TDDDG — which is why there is no consent banner here. None of them contains an identifier that could recognise your device, none is transmitted to the server, and all can be deleted at any time through your browser settings. The language choice lives in the page address (/de, /en) and is not stored at all.
Abuse protection
Art. 6(1)(f) GDPR · 15 minutes to 24 hoursWrite access to the API is rate-limited so that individual senders cannot overload the service or distort ratings and reports. For this, your IP address is counted briefly in a cache — not in the database, with no link to content, and only for the duration of the respective window (15 minutes to 24 hours depending on the operation). The entry then expires by itself. The legal basis is the legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
Submitting and managing entries
Art. 6(1)(b) GDPRWhen you submit a menu or search engine you receive a secret edit token that is stored in your own browser only. The server keeps just a hash of it (Argon2id) — the token itself is never stored and cannot be derived from the hash. This lets you update or delete your entry later without creating an account, without an email address and without a password. The legal basis is performance of the usage relationship (Art. 6(1)(b) GDPR). If you lose the token you lose access to the entry; there is no recovery path, because we hold nothing that would let us identify you.
Submitted content is public
Menus and search engines that are submitted are by their nature meant to be browsed and downloaded by others — that is the purpose of the index. Only submit content you are willing to share publicly; do not include personal data in names, descriptions or URLs. Optional screenshots for an entry are re-encoded server-side and stored without metadata; third-party URLs are never embedded.
Anonymous install counters
Downloads increment an anonymous, aggregated install counter per entry. This counter cannot be traced back to a person, a device or an IP address — it is a plain number, not a record of who downloaded what.
Reports
Art. 6(1)(f) GDPRReports about an entry are processed anonymously: only the reported entry, the reason, an optional comment and the timestamp are stored — no identifier of the reporting person and no IP address. The legal basis is the legitimate interest in keeping the directory free of abuse (Art. 6(1)(f) GDPR).
Optional accounts
Art. 6(1)(b) GDPR · deleted after 365 days without useAn account is not required to use the index; it is pure convenience. An account consists solely of a random access token — of which only a short selector and a hash (Argon2id) are stored, plus the times of creation and last access. There is no email address, no name, no password and no profile. The legal basis is Art. 6(1)(b) GDPR. Accounts unused for 365 days are deleted automatically along with all associated data.
Ratings
Art. 6(1)(b) GDPRWith an account you can leave one star rating with an optional comment per entry. The rating, the comment and the timestamp are stored, linked to the account, so that you can change or withdraw your own rating. Comments are publicly visible; do not write anything there that could identify you. The legal basis is Art. 6(1)(b) GDPR.
Settings synchronisation
Art. 6(1)(b) GDPR · deleted after 365 days without accessIf you want to synchronise your Gestura settings across several browsers, you can transfer them through this service. Synchronisation is a second switch, independent of the general integration and with a confirmation of its own — enabling the integration does not by itself synchronise anything. The data is encrypted on your device alone and reaches the server as ciphertext only; the key never leaves your device. We can neither read nor merge the contents — merging is done by the extension. Synchronisation is addressed via an identifier derived from your secret, which is stored server-side only as a SHA-256 hash; the identifier itself is not stored and request bodies are not logged. What is stored is the ciphertext, its checksum and size, and the times of last modification. The legal basis is Art. 6(1)(b) GDPR. States not accessed for 365 days are deleted automatically.
Update checks from the extension
Art. 6(1)(b) GDPR · not storedThe Gestura extension can ask the index whether newer versions of the installed menus and search engines exist. In doing so it transmits their identifiers and version numbers — with no account, no device identifier and no user identifier. The request is answered and not stored. This connection does not arise by itself: the gestura.eu integration is switched off by default in the extension and takes effect only after you have explicitly confirmed it; if its scope is extended later, the extension asks again. The legal basis is Art. 6(1)(b) GDPR.
Index administration
Art. 6(1)(b) and (f) GDPRModeration happens in a closed administration area. It stores the name and email address of the administrating persons, their passkeys (public keys, no biometric data) and a log of administrative actions — the latter to keep decisions accountable. A cookie is set only in this area: a strictly necessary session cookie that ends when the browser is closed and is never set for visitors. Invitations to the administration area are sent by email via the hosting provider's mail server. The legal bases are Art. 6(1)(b) and (f) GDPR.
Recipients and processors
The website and API are operated at ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany, which also holds the server logs and handles mail delivery. A data processing agreement under Art. 28 GDPR is in place with this provider. There are no other recipients: no analytics or advertising services, no social networks, no external fonts and no content delivery networks. The pages load no resources from third-party servers.
Transfers to third countries
No personal data is transferred to countries outside the European Union. Servers and processors are located in Germany.
Your rights
You have the following rights vis-à-vis the controller:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
One point matters especially here: because the service deliberately works without identification, we cannot attribute most data to a person. For an anonymous account, an edit token or a synchronisation state we can only respond if you present the corresponding token — without it we are neither obliged nor able to keep additional data for the sole purpose of identifying you (Art. 11 GDPR). This is not an evasion but the flip side of data minimisation: what we do not hold cannot be disclosed or misused either.
To exercise your rights, an informal message to contact@gestura.eu is sufficient.
Right to lodge a complaint
Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is the Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany. You may also contact the supervisory authority where you habitually reside.
No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. Providing data is neither legally nor contractually required; without the details described above, however, the respective function cannot be used.
Changes to this policy
This policy is updated whenever the processing activities described here change — for example when new features are added. The version in force is always available on this page.
