Skip to main content

Privacy Policy

Last updated: 2026-04-23

Our Privacy-First Commitment

This site and the apps Agata Hexe Studio publishes are designed around a single principle: when we don't need data, we don't collect it; when we do need it, we ask and explain. The principles below apply across the studio. Each individual app declares its specific data flows in its own privacy section. • When we DO need data, we ask and explain. Optional collection is opt-in by default. Before we introduce a new data flow we (1) ask for explicit consent, (2) explain in plain language what we want and why, (3) explain what we will do with it, (4) make sure you can withdraw at any time without losing the rest of the service. • Local when possible. Apps perform their core function on your device. For most of our apps (Aurora Control, Argus Capture, Agata Stack), your data does not leave your machine for the app to work — only license verification is remote. • Per-app transparency. Some apps include opt-in analytics, crash diagnostics, or advertising — typically when there is a free tier that needs sustainable funding (e.g. Osiris Focus uses Firebase Analytics and AdMob, both gated by an in-app consent banner). The exact SDKs and what they collect is declared inside each app and on its product page. • No third-party behavioral profiling. We do not use Mixpanel, Amplitude, PostHog, Segment, or similar behavioral-profiling SDKs anywhere in the ecosystem. When we collect product analytics it is via Firebase (Google Ireland) under an Art. 28 GDPR Data Processing Agreement, with anonymized identifiers. • No cross-app or cross-device tracking. Activity in one of our apps is never linked to activity in another. We do not fingerprint devices. Advertising identifiers (when applicable) are reset by the user via system settings. • Paddle as Merchant of Record. Payments go through Paddle, which means we never see your card details. We only receive the email needed to deliver your license. • EU controller, safeguarded international transfers. Controller in Germany (NRW). Hosting and database run in Google Cloud (United States) under the EU–U.S. Data Privacy Framework and Standard Contractual Clauses. All sub-processors are covered by Data Processing Agreements (Art. 28 GDPR). This page reflects our current operational commitments. The full Privacy by Design Statement, including the GDPR mapping, is published in our compliance repository on GitHub. If anything described in this section ever changes, we update this page in the same release.

1. General Information

This privacy policy explains how Agata Hexe® Studio collects, uses, and protects your data when you visit our website agatahexe.com. We take the protection of your personal data very seriously and treat it confidentially in accordance with applicable data protection regulations and this privacy policy.

2. Controller

The controller responsible for data processing on this website is: Agata Hexe Studio Nicolas Lipko c/o COCENTER, Koppoldstr. 1 86551 Aichach, Germany Phone: +49 251 37984013 Email: [email protected]

3. Hosting

This website is hosted on Firebase App Hosting (Google Cloud Platform), operated by Google LLC, in the us-central1 region (United States). When you visit our website, the hosting infrastructure and our CDN provider (Cloudflare) may process server log files including your IP address, browser type, operating system, referral URL, and date and time of access. This data is processed on the basis of Art. 6(1)(f) GDPR to ensure the secure and efficient provision of the website. Because the hosting and database run in the United States, this involves a transfer of personal data outside the EU/EEA. We rely on appropriate safeguards under Chapter V GDPR: Google LLC is certified under the EU–U.S. Data Privacy Framework, and transfers are additionally covered by the Standard Contractual Clauses incorporated into Google's Cloud Data Processing Addendum. Cloudflare acts as a processor under its own Data Processing Addendum, which also incorporates the Standard Contractual Clauses.

4. Cookies

This website uses only cookies and local storage entries that are technically necessary, plus optional analytics. Optional categories require your explicit consent. You can manage your preferences at any time using the "Cookie Settings" link in the footer of every page, which opens the Customize panel of the consent banner. Cookies and local storage we may set, by category: ESSENTIAL (always on, no consent required): • ahx-consent-v1 — Stores your granular consent choices (analytics on/off, marketing on/off, version, timestamp). localStorage, persistent until you clear it or rotate the version. • ahx-a11y — Records your high-contrast accessibility mode preference. Cookie, 1 year (or until cleared). • lang — Records your selected interface language. Cookie, 1 year. • theme — Records your light/dark mode preference. localStorage, persistent. • i18nextLng — Internal i18next runtime language cache. localStorage, persistent. ANALYTICS (opt-in, off by default): • _ga, _ga_<ID> — Google Analytics 4 with anonymized IP. Stores a pseudonymous device identifier for aggregate site usage measurement. Up to 2 years. Not set unless analytics consent is granted. MARKETING (opt-in, off by default): • None today. Reserved for future advertising or remarketing features. If we ever introduce them, this list will be updated and re-consent will be requested. We do not set any cross-site tracking, ad-targeting, or social-media-pixel cookies on this website. Legacy migration: visitors who consented under our previous single-flag system (ahx-ga-consent) are automatically migrated to the new granular format on first visit. Their original choice is preserved (granted maps to analytics-on; denied stays denied).

5. Analytics

We use Google Analytics 4 (provided by Google Ireland Limited) to understand how our website is used. Analytics is completely disabled by default and only activated after you give explicit consent. When enabled, Google Analytics uses cookies to collect anonymized usage data including pages viewed, session duration, and general geographic region. IP anonymization is active. No personal data is transmitted before consent is granted. Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG (consent for storage of and access to information in the user's terminal equipment). Essential cookies and local storage entries rely on § 25(2) no. 2 TDDDG (strictly necessary to provide a service explicitly requested by the user). You can withdraw your consent at any time via the "Cookie Settings" link in the footer.

6. Contact Form

When you use our contact form, the data you provide (name, email address, reason, and message) is transmitted to us via email. We use this data solely to respond to your inquiry. The data is processed on the basis of Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). We use Resend as our email delivery service. Your data may be processed on servers outside the EU. Resend maintains appropriate safeguards in accordance with GDPR requirements.

7. Bot Protection (Cloudflare Turnstile)

Our contact form is protected against spam and automated abuse by Cloudflare Turnstile, provided by Cloudflare, Inc. Turnstile is a privacy-preserving alternative to traditional CAPTCHAs. It does not use tracking cookies and does not perform device fingerprinting for advertising purposes. When you interact with the contact form, Turnstile may process limited technical information (such as your IP address and browser characteristics) solely to distinguish humans from bots. This data is not used for advertising or cross-site tracking. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing spam and securing our contact form). The service is only activated when you begin interacting with the form.

8. Newsletter Subscription (Double Opt-In)

If you subscribe to our newsletter, we use a double opt-in process as required by German law (UWG § 7). After entering your email address, you will receive a confirmation email with a unique link. Your email is only added to our newsletter list after you click the confirmation link — which is valid for 48 hours. Data we store: your email address, selected language, subscription timestamp, IP address at signup, and confirmation status. The IP address is stored as evidence of consent and is kept for the duration of the subscription. Legal basis: Art. 6(1)(a) GDPR (consent). You can unsubscribe at any time by contacting [email protected]. The unsubscribe link will also be included in every newsletter email.

9. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected. Contact form submissions are retained for the duration of the correspondence and deleted when no longer needed. Newsletter subscriptions are retained until you unsubscribe. Unconfirmed newsletter signups are automatically deleted 48 hours after the confirmation link expires. Analytics data is automatically deleted after 14 months.

10. Your Rights

Under GDPR, you have the following rights regarding your personal data: • Right of access (Art. 15 GDPR) • Right to rectification (Art. 16 GDPR) • Right to erasure (Art. 17 GDPR) • Right to restriction of processing (Art. 18 GDPR) • Right to data portability (Art. 20 GDPR) • Right to object (Art. 21 GDPR) • Right to withdraw consent (Art. 7(3) GDPR) • Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) To exercise any of these rights, please contact us at [email protected].

11. Third-Party Services

This website uses the following third-party services: • Firebase App Hosting (Google LLC) — Website hosting and deployment, United States (us-central1) • Firebase (Google Ireland Limited) — Newsletter subscriber database • Google Analytics 4 — Website analytics (only with consent) • Cloudflare Turnstile — Privacy-preserving bot protection on contact form • Resend — Email delivery for contact form and newsletter confirmations • Google Fonts — Typography (self-hosted via Next.js, no external requests)

12. Children's Data

This website and our products are not directed at children under 16. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected] and we will delete it. Legal basis: Art. 8 GDPR (age of consent for information society services — set at 16 in Germany) and COPPA (US, for children under 13).

13. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information. Categories of personal information we collect: • Identifiers (email address, IP address) • Internet activity information (pages viewed, if analytics consent is granted) • Commercial information (contact form submissions, newsletter subscriptions) Purpose: to operate and improve our website, respond to inquiries, and send newsletter content you explicitly requested. Sale or sharing of personal information: We do not sell or share your personal information for monetary or other valuable consideration. We do not share your information with third parties for their own direct marketing or cross-context behavioral advertising. Sensitive Personal Information: We do not collect Sensitive Personal Information as defined by CPRA (§ 1798.140(ae)). We do not use or disclose such information; no "Limit the Use of My Sensitive Personal Information" link is required. Global Privacy Control (GPC): Our site recognizes the browser-level Global Privacy Control signal. If your browser sends GPC:1, we treat it as a request to opt out and do not enable analytics tracking. Your CCPA/CPRA rights: • Right to know what personal information we collect, use, disclose, and share • Right to delete personal information we have collected • Right to correct inaccurate personal information • Right to opt out of the sale or sharing of personal information (not applicable — we do not sell or share) • Right to limit use of Sensitive Personal Information (not applicable — we do not collect it) • Right to non-discrimination for exercising these rights To exercise any of these rights, contact [email protected]. We respond within 45 days. Retention: We retain personal information only as long as necessary for the purpose it was collected (see Section 9). Retention periods match those described for GDPR compliance.

14. Changes to This Policy

We reserve the right to update this privacy policy to reflect changes in our practices or legal requirements. The latest version will always be available on this page.