Privacy policy
This is a translation for convenience. The German version is legally binding.
1. Controller
Julian Stosse (Einzelunternehmen)
In der Acht 44
66333 Völklingen
Deutschland
julian@stosse.group
2. In brief
- We do not store your prompts or the content of your ChatGPT conversations.
- This website sets no tracking or advertising cookies and embeds no third-party services (fonts, analytics, ads).
- To operate the plugins we only collect technical, non-content usage data (for example which tool was called, whether it succeeded and how long it took).
3. Visiting this website
When you visit plugins.stosse.group, our hosting provider Cloudflare processes technically necessary data: IP address, time, requested address, browser identifier (user agent) and, where applicable, the referring page. This is used to deliver the site and to protect it against attacks and abuse (for example limiting requests per IP address over 60 seconds). Some requests are briefly kept in Cloudflare operational logs for troubleshooting and then deleted automatically.
Legal basis: our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR).
4. Using our plugins in ChatGPT
OpenAI is responsible for ChatGPT itself; OpenAI's privacy policy applies. When ChatGPT calls one of our plugins, we only receive the information the tool needs to answer (for example a year and a German state). We process it to answer your request (Art. 6(1)(b) GDPR) and do not store it.
To operate the plugins we additionally collect usage metrics (Art. 6(1)(f) GDPR – reliability, cost control, improvement):
- Plugin, tool, version, outcome (success/failure), error class, response time and estimated cost of external data sources.
- Only for plugins that say so explicitly: a pseudonymous key (a cryptographic hash of an identifier that ChatGPT already provides anonymously), which lets us count returning use without knowing who you are.
- Only where technically available and stated for the plugin: the country of the request.
Prompts, conversation content, credentials and full personal identifiers are not collected; our systems discard data that looks like them.
5. Contact
If you email us, we process your details to handle your request (Art. 6(1)(b) or (f) GDPR) and delete them once it is resolved, unless statutory retention obligations apply.
6. Internal area (dashboard)
The dashboard is for our team only. Sign-in uses passkeys exclusively. For this we set a strictly necessary session cookie (Section 25(2) no. 2 German TDDDG) and store a hash of the session key, the time and the browser identifier, for at most 12 hours per session.
7. Recipients and transfers outside the EU
Cloudflare, Inc. (USA) processes data on our behalf for hosting, network, storage and analytics under a data processing agreement. Cloudflare is certified under the EU-U.S. Data Privacy Framework; the EU Standard Contractual Clauses apply in addition. Some plugins query external data sources to answer; these are named for the respective plugin.
8. Retention
- Individual usage events: up to 3 months.
- Hourly aggregates: 90 days; daily aggregates (counts only) kept for portfolio statistics.
- Operational logs at Cloudflare: a few days.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability (Art. 15–20 GDPR). Where we process data based on legitimate interests, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). Because we hold no identity data, we often cannot link records to a person; we will still help where we can: julian@stosse.group
You may also lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in your place of residence; the authority responsible for us is:
Unabhängiges Datenschutzzentrum Saarland Fritz-Dobisch-Str. 12 66111 Saarbrücken poststelle@datenschutz.saarland.de · https://www.datenschutz.saarland.de
No automated decision-making within the meaning of Art. 22 GDPR takes place.
Last updated: 2026-10-05