Privacy Policy (Datenschutzerklärung)
1. Privacy at a Glance
Protecting your personal data is our top priority. Below, we inform you about what data we collect, process, and store during your visit and use of our platform (Free Community Edition).
Controller: Felix Frenzel, Hellerstraße 9, 96047 Bamberg, Germany, E-Mail: info@clean-core.io.
2. Data Collection & Processing Purposes
We process personal data of our users only as far as necessary to provide a functional platform as well as our contents and services.
- Google Authentication (Firebase Auth): To sign in, we use Google Sign-In. This securely reads your name, email address, and profile picture from your Google account to authenticate your user session and establish access privileges.
- Email and password (Firebase Auth): You can also register with an email address and a password instead of using Google. In that case we process the email address, the first and last name you enter, and — optionally — the motivation you provide. The password itself is handled by Firebase Authentication and is never visible to us. This section previously described only Google Sign-In, although this second path has always existed.
- Firestore User Profiles: We store metadata about your platform usage (e.g., number of performed code transformations, system limits, as well as your first and last name) in our secure database.
- Bring Your Own Key (BYOK): Providing your own key is optional; without it, transformations use a shared community key within your free quota. If you configure your own Google Gemini API key in the settings, this key is encrypted and stored in our secure Firestore instance. It is used exclusively to forward your transformation requests directly via a secure backend proxy to the Gemini API, never exposing your key to the browser.
3. Processing of Source Code & Project Assets
The ABAP source files you upload and the generated modernization artifacts (such as solution designs, TypeScript code, and test cases) are stored in our secure Google Firebase cloud environment in Europe.
Important Security Notice: We do not sell, rent, or use your uploaded source code for commercial purposes. For AI-driven modernization, source code is transmitted via secure, authenticated channels to the Google Gemini API using stateless API requests. Under Google's applicable API data-use terms, this content is not used to train Google's foundational AI models. Which terms apply depends on the key: for the paid Gemini API the “not used for training” terms apply directly, while a free-tier key is governed by Google's free-tier data-use terms, which differ. When you use your own key (BYOK), the terms of your own Google account apply. We state the applicable terms rather than an absolute promise we cannot control.
4. Hosting & Subprocessors
To provide this service, we rely on the following subprocessors:
- Google Cloud Platform & Firebase: Hosting, authentication, and database operations on European servers in the Belgium (europe-west1) region — data residency in the EU, operated in line with GDPR requirements.
- Google Gemini API: Generative AI models used exclusively for code transformation, via secure stateless proxy layers.
- Resend: Transactional email delivery (e.g. access-approval and status notifications). Your email address is processed to send these messages.
International transfers: Google and Resend are US-based providers. Where personal data is transferred outside the EU/EEA, it is safeguarded by the EU Standard Contractual Clauses (SCCs) and the providers' data-processing terms; hosting and storage of your projects remain in the EU (europe-west1).
5. Your Rights Under GDPR (including Art. 17 Deletion)
Since our platform is hosted in compliance with EU regulations, you have all rights under the General Data Protection Regulation (GDPR):
- Right of Access (Art. 15 GDPR)
- Right to Rectification (Art. 16 GDPR)
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Data Portability (Art. 20 GDPR)
- Right to Withdraw Consent (Art. 7 Abs. 3 GDPR)
- Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
To exercise these rights, particularly to erase your data, you can trigger account deletion directly in your Profile Settings under the Danger Zone, which immediately deletes your live database and authentication entries. Residual copies in encrypted backups age out within 30 days (see section 6). Alternatively, contact us at info@clean-core.io.
6. Legal Basis & Data Retention
Legal basis (Art. 6 GDPR): We process account and usage data to perform the service you request (Art. 6(1)(b)), to operate and secure the platform under our legitimate interest (Art. 6(1)(f)), and — where applicable — on your consent (Art. 6(1)(a)), which you may withdraw at any time.
Retention: Personal data is retained for the life of your account and removed on account erasure (Art. 17); residual copies in encrypted backups age out within 30 days. Security audit records may be kept longer where required for accountability. Detailed per-collection retention is documented in our internal data-retention policy.
7. Cookies & Tracking
Clean-Core.io uses only strictly necessary cookies and local storage required to authenticate you and maintain your session via Google Firebase Authentication. We do not use analytics, advertising, or tracking cookies, and we embed no third-party marketing or profiling trackers. Because only essential, functional storage is used, no cookie-consent banner is required (§ 25(2) TDDDG / ePrivacy Directive).