Privacy policy

Last updated: October 7, 2026Deutsche Fassung

This is an English translation for convenience. Only the German version is legally binding.

Draft for the closed beta. It will be reviewed by a lawyer before the public launch.

1. Controller

Studio Treo – Tobias Affüpper, Feldstraße 12, 40721 Hilden, Germany, email: koppel@treo.studio. We are not required to appoint a data protection officer.

2. What this covers

Koppel is a tool that lets web developers edit their sites’ custom CSS and JavaScript in their own editor and deliver it through our CDN. This policy describes which data we process about users of the dashboard and the editor extension. For visitors of our customers’ websites, see section 6.

3. What data we process

DataPurposeLegal basisRetention
Email address, optionally your nameAccount, sign-in with one-time codes, notifications about changes to productionArt. 6(1)(b) GDPR (contract)Until you delete your account
Projects, uploaded code, builds, releasesProviding the serviceArt. 6(1)(b) GDPRUntil the project or account is deleted; older releases according to your plan’s limits
Name of the device or editor, time of last useList of signed-in editors, signing out individual devicesArt. 6(1)(b) GDPRUntil signed out, at most 90 days after last use
Email address on the beta waitlist, where you came from (website, extension)Telling you when the beta has a spot for you (double opt-in: only after you confirm the link we send)Art. 6(1)(a) GDPR (consent), withdrawable anytime by emailUnconfirmed: deleted after 7 days; confirmed: until you get access or ask us to remove you
Email addresses of people you invite to a workspace; your email address and name, visible to the members of your workspacesWorking together in teamsArt. 6(1)(b) GDPRInvites: until accepted or revoked; they expire after 7 days and are deleted within a day; membership: until you leave or are removed
Domains on which your snippet was loaded, with timeShowing that the installation works and linking to your sitesArt. 6(1)(b) GDPRThe 20 most recent domains per project, until the project is deleted
Log of security-relevant actions (e.g. publishing, an editor signing in)Security, traceability within a teamArt. 6(1)(f) GDPR (legitimate interest in security)Until the workspace is deleted; personal entries together with the account
IP address at sign-upLimiting mass account creationArt. 6(1)(f) GDPR30 days
Normalized email address (e.g. without a “+tag”)Preventing duplicate accounts and re-registration after a banArt. 6(1)(f) GDPRWith the account; after a ban for abuse, as long as the ban lasts
Technical server logs (IP address, time, requested URL)Operations, debugging, defending against attacksArt. 6(1)(f) GDPRAt most 7 days at our service providers
Database backupsRecovery after failures (Art. 32 GDPR)Art. 6(1)(f) GDPR30 days, encrypted

The dashboard only sets cookies that are technically necessary for signing in. There is no tracking and no advertising.

4. Recipients and processors

We use the following service providers, each under a data processing agreement (Art. 28 GDPR):

  • Supabase Inc. (USA): database and sign-in, stored in Frankfurt am Main (EU). Transfers to the USA are possible; basis: EU-US Data Privacy Framework or standard contractual clauses.
  • Cloudflare Inc. (USA): delivery (CDN), server functions, storage of your code in the EU (R2, EU jurisdiction), bot protection (Turnstile). Basis for transfers: EU-US Data Privacy Framework.
  • Sendinblue SAS / Brevo (France): sending sign-in codes and notifications.
  • GitHub Inc. (USA): creating the daily encrypted database backup. Basis: EU-US Data Privacy Framework.
  • Vercel Inc. (USA): hosting the dashboard; IP addresses and access data are briefly processed in server logs. Basis for transfers: EU-US Data Privacy Framework.

The current list is in our DPA & subprocessors.

5. Editor extension

The extension for VS Code, Cursor and other editors uploads your project’s files when you save. It keeps its sign-in token in your operating system’s keychain and sends no usage statistics to us. Code you publish through Koppel is publicly accessible. Don’t put secrets in it; the extension warns you about common key formats.

6. Visitors of our customers’ websites

When a website includes the Koppel snippet, the visitor’s browser loads CSS and JavaScript files from our CDN. Cloudflare processes the IP address technically in order to deliver the files. We set no cookies, build no profiles and do not analyze visitor data. For this processing we act on behalf of our customer, the operator of the website. The customer is responsible for what the delivered code itself does.

7. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests. You can delete your account with all projects yourself under Settings → Delete account. Your code is always fully available locally in your editor folder. You can lodge a complaint with a data protection supervisory authority, for example the one where you live or the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Kavalleriestraße 2–4, 40213 Düsseldorf, Germany).

8. Changes

When the service changes, we update this policy. We inform you about material changes by email.