Privacy policy
Last updated: October 7, 2026Deutsche Fassung
This is an English translation for convenience. Only the German version is legally binding.
Draft for the closed beta. It will be reviewed by a lawyer before the public launch.
1. Controller
Studio Treo – Tobias Affüpper, Feldstraße 12, 40721 Hilden, Germany, email: koppel@treo.studio. We are not required to appoint a data protection officer.
2. What this covers
Koppel is a tool that lets web developers edit their sites’ custom CSS and JavaScript in their own editor and deliver it through our CDN. This policy describes which data we process about users of the dashboard and the editor extension. For visitors of our customers’ websites, see section 6.
3. What data we process
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address, optionally your name | Account, sign-in with one-time codes, notifications about changes to production | Art. 6(1)(b) GDPR (contract) | Until you delete your account |
| Projects, uploaded code, builds, releases | Providing the service | Art. 6(1)(b) GDPR | Until the project or account is deleted; older releases according to your plan’s limits |
| Name of the device or editor, time of last use | List of signed-in editors, signing out individual devices | Art. 6(1)(b) GDPR | Until signed out, at most 90 days after last use |
| Email address on the beta waitlist, where you came from (website, extension) | Telling you when the beta has a spot for you (double opt-in: only after you confirm the link we send) | Art. 6(1)(a) GDPR (consent), withdrawable anytime by email | Unconfirmed: deleted after 7 days; confirmed: until you get access or ask us to remove you |
| Email addresses of people you invite to a workspace; your email address and name, visible to the members of your workspaces | Working together in teams | Art. 6(1)(b) GDPR | Invites: until accepted or revoked; they expire after 7 days and are deleted within a day; membership: until you leave or are removed |
| Domains on which your snippet was loaded, with time | Showing that the installation works and linking to your sites | Art. 6(1)(b) GDPR | The 20 most recent domains per project, until the project is deleted |
| Log of security-relevant actions (e.g. publishing, an editor signing in) | Security, traceability within a team | Art. 6(1)(f) GDPR (legitimate interest in security) | Until the workspace is deleted; personal entries together with the account |
| IP address at sign-up | Limiting mass account creation | Art. 6(1)(f) GDPR | 30 days |
| Normalized email address (e.g. without a “+tag”) | Preventing duplicate accounts and re-registration after a ban | Art. 6(1)(f) GDPR | With the account; after a ban for abuse, as long as the ban lasts |
| Technical server logs (IP address, time, requested URL) | Operations, debugging, defending against attacks | Art. 6(1)(f) GDPR | At most 7 days at our service providers |
| Database backups | Recovery after failures (Art. 32 GDPR) | Art. 6(1)(f) GDPR | 30 days, encrypted |
The dashboard only sets cookies that are technically necessary for signing in. There is no tracking and no advertising.
4. Recipients and processors
We use the following service providers, each under a data processing agreement (Art. 28 GDPR):
- Supabase Inc. (USA): database and sign-in, stored in Frankfurt am Main (EU). Transfers to the USA are possible; basis: EU-US Data Privacy Framework or standard contractual clauses.
- Cloudflare Inc. (USA): delivery (CDN), server functions, storage of your code in the EU (R2, EU jurisdiction), bot protection (Turnstile). Basis for transfers: EU-US Data Privacy Framework.
- Sendinblue SAS / Brevo (France): sending sign-in codes and notifications.
- GitHub Inc. (USA): creating the daily encrypted database backup. Basis: EU-US Data Privacy Framework.
- Vercel Inc. (USA): hosting the dashboard; IP addresses and access data are briefly processed in server logs. Basis for transfers: EU-US Data Privacy Framework.
The current list is in our DPA & subprocessors.
5. Editor extension
The extension for VS Code, Cursor and other editors uploads your project’s files when you save. It keeps its sign-in token in your operating system’s keychain and sends no usage statistics to us. Code you publish through Koppel is publicly accessible. Don’t put secrets in it; the extension warns you about common key formats.
6. Visitors of our customers’ websites
When a website includes the Koppel snippet, the visitor’s browser loads CSS and JavaScript files from our CDN. Cloudflare processes the IP address technically in order to deliver the files. We set no cookies, build no profiles and do not analyze visitor data. For this processing we act on behalf of our customer, the operator of the website. The customer is responsible for what the delivered code itself does.
7. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests. You can delete your account with all projects yourself under Settings → Delete account. Your code is always fully available locally in your editor folder. You can lodge a complaint with a data protection supervisory authority, for example the one where you live or the authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (Kavalleriestraße 2–4, 40213 Düsseldorf, Germany).
8. Changes
When the service changes, we update this policy. We inform you about material changes by email.