Privacy policy
We collect as little personal data as possible. No analytics, no tracking, no advertising cookies.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Codext GmbH
Frankenstraße 10, 74549 Wolpertshausen, Germany
Managing director: Daniel Ehrhardt
Email: kontakt@codext.de · Phone: +49 7904 5203106
2. Scope
This policy covers the website autoseo.codext.de (including its sign-up, login and customer dashboard) and the AutoSEO Cloud service. It does not cover self-hosted installations of the open-source AutoSEO software: whoever operates such an installation is responsible for the data processed in it.
3. Hosting and server logs
The website and all AutoSEO Cloud instances run on servers located in Germany, provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We operate and deploy the applications ourselves with the open-source platform Coolify on these servers. Hetzner acts as our processor under a data processing agreement (Art. 28 GDPR).
When you access the website, our servers process technical data that your browser transmits automatically: IP address, date and time of the request, requested URL, referrer, HTTP status and user agent. We process this data to deliver the website and to keep it secure and stable (Art. 6(1)(f) GDPR). Log data is kept only as long as necessary for these purposes.
4. Cloudflare (DNS and CDN)
We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, for DNS and as a content delivery network and security proxy for autoseo.codext.de. Requests to the website pass through Cloudflare's network, which processes your IP address and request data to deliver content and protect against attacks. Customer instances under *.autoseo.codext.de only use Cloudflare for DNS resolution; their traffic is not proxied. Legal basis is our legitimate interest in a secure and fast website (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-U.S. Data Privacy Framework; in addition, the EU Standard Contractual Clauses apply. More information: cloudflare.com/privacypolicy.
5. Account and magic-link sign-in
To create an account, you only provide your email address. We send you a one-time sign-in link (magic link) instead of using passwords. We store your email address, the instance address you choose, your subscription status and security-relevant events (such as sign-ins). This is necessary to provide the service you requested (Art. 6(1)(b) GDPR).
Transactional emails — sign-in links, provisioning notices and billing messages — are sent through an email delivery provider acting as our processor. We do not send newsletters or marketing emails.
6. Payments via Stripe
Subscriptions are paid through Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. When you check out, you enter your payment details directly with Stripe; we never see or store full card numbers. Stripe shares with us the information we need for billing and bookkeeping, such as name, email, billing address, VAT ID, payment status and the last digits of the payment method. Legal bases are the performance of the contract (Art. 6(1)(b) GDPR) and our statutory retention obligations (Art. 6(1)(c) GDPR). Stripe may process data in the USA; data transfers are covered by the EU-U.S. Data Privacy Framework and Standard Contractual Clauses. More information: stripe.com/privacy.
7. Cookies and local storage
We only use strictly necessary cookies: after you sign in, a session cookie (HttpOnly, Secure) keeps you logged in, and short-lived cookies may protect sign-in and checkout flows. Your light or dark mode preference is stored in your browser's local storage and never sent to us. These are exempt from consent under § 25(2) TDDDG. We do not use analytics, tracking pixels, advertising cookies or third-party embeds. Fonts are served from our own servers.
8. Data in your AutoSEO Cloud instance
Each AutoSEO Cloud customer gets an isolated instance with its own database and data volume. For personal data that you and your users store or process in your instance (for example team members, clients or tracked content), you are the controller and we act as your processor under Art. 28 GDPR. We provide a data processing agreement on request — just email kontakt@codext.de.
Third-party services that you connect to your instance — such as AI providers, DataForSEO, Google Search Console or Google Analytics — receive data according to your configuration and are engaged by you under their own terms.
9. Contacting us
If you contact us by email, we process your message and contact details to answer your request (Art. 6(1)(b) or (f) GDPR) and delete them when they are no longer needed, unless statutory retention obligations apply.
10. Links to GitHub and other sites
Our website links to the AutoSEO repository on GitHub and other external sites. No data is transferred to these sites until you click a link; after that, the provider's privacy policy applies.
11. Retention
We keep account data for as long as you have an account. After your subscription ends, your instance is stopped and its data is deleted after 30 days. Invoices and bookkeeping records are retained for the periods required by German commercial and tax law (up to 10 years, § 257 HGB, § 147 AO).
12. Your rights
Under the GDPR, you have the right to:
- access your personal data (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR),
- withdraw any consent you have given, with effect for the future (Art. 7(3) GDPR).
To exercise these rights, email kontakt@codext.de. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
13. Security
All connections are encrypted with TLS. Within AutoSEO, stored secrets are encrypted with AES-256-GCM, and API keys and tokens are stored only as hashes. Each Cloud instance runs isolated with its own database.
14. Changes
We update this policy when our services or legal requirements change. The current version is always available on this page. See also our terms of service and imprint.
Last updated: