Who is responsible
This notice covers Xtrackers / Create at xtrackers.stg-create.studio (also available at xtrackers-stgcreate.vercel.app).
bitfuel GmbH, Hanauer Landstraße 136A, 60314 Frankfurt am Main, Germany, operates this private Xtrackers / Create workspace and is the controller for account administration and operation of the workspace.
For privacy enquiries, contact hello@bitfuel.de. Further company and contact details are in the legal notice. If your enquiry concerns material supplied by a customer organisation, identify the project so we can establish responsibility and coordinate the request with that organisation.
Accounts and invitations
When you register, we process your name, email address and password through Supabase Authentication. Profiles also contain your role, approval status and last-seen time. We use this information to authenticate you, control access and administer accounts.
If an administrator or project owner invites you, your email address, optional name and access role come from that person. We use them to send an invitation and assign the specified access. Sign-in links, registration confirmations and password recovery messages are sent when these functions are requested.
Your name and email address may be visible to administrators and people managing project membership. Your name is also displayed with comments and other attributed contributions. An email address and authentication details are required for account access; without them, we cannot provide a signed-in workspace.
Email delivery involves our email provider and your recipient email provider. A successful send response confirms acceptance for delivery; it does not prove arrival in your inbox.
Projects and collaboration
We process uploaded source files, project content, assets, comments and replies, edit overlays, saved versions, access assignments and creation jobs. Records can include account identifiers, contributor names, timestamps and progress or error logs.
Project content and collaboration records are available according to the project’s permissions. A project can be limited to members or made available to all approved users of the workspace. Administrators have broader management access. Shared brand assets under the shared assets area can be retrieved without an account.
ZIP, HTML, PDF and PowerPoint downloads create copies outside the workspace. Changing access or removing a file from Projects does not remove copies already downloaded by recipients. PDF and PowerPoint generation processes project HTML, saved edits and permitted assets on the application’s server before returning the file. Only upload or share personal data and third-party materials that you are authorised to use for the intended purpose.
Customer contacts
Authorised staff can maintain customer names, descriptions and websites, together with contact names, email addresses, positions and phone numbers. We also store who created or updated records and when they were created, updated or archived. These details come from the authorised person entering them and are used to organise customer work and select project recipients.
Staff can access the customer directory. Project owners and administrators can also select contacts belonging to the customer assigned to that project. Saving a contact does not send an email; sharing access through the invitation function does. Customer-linked projects are limited to assigned members.
Archiving a customer or contact retains the record and does not revoke project access already granted.
Activity history
Administrators can review an activity history for access administration, change tracking and investigation of errors or misuse. Entries can include the acting user’s identifier, name and email address, timestamp, action, affected object or project, changed field names and limited before-and-after values. The history is not a complete copy of private chats or uploaded files.
Activity entries have no automatic expiry in the current application. Deleting an account does not automatically erase its attributed activity entries. See Retention and deletion.
AI assistance
Using AI assistance sends the material needed for the request to the provider of the selected model. The application integrates OpenAI and Anthropic. This can include your prompt, current project or slide text, your chat history for the project, attached source files, relevant open comments including contributor names, and your account name or email address and role.
To understand comments placed on a slide, the assistant can receive slide identifiers, pin positions, element text and geometry, comments and replies with author names. Larger review jobs can render images of the affected slides with marked comment pins. This renders the project itself; it does not capture other applications or the rest of your screen.
The project memory stores shared notes, summaries of editing and publishing work, references to the selected design system and saved design changes. Records can include contributor identifiers and timestamps. Editors, owners and administrators can access this memory, and relevant entries are included in AI requests and generation jobs. Earlier private chat conversations are not automatically copied into the shared memory.
Larger generation and revision jobs also use the project’s GitHub Actions workflow to prepare files and publish results. Job records and logs can include prompts, file names, generated content and processing details. Using another model can change the AI provider receiving the input.
If an administrator connects Higgsfield, a requested image or video generation sends its media prompt and generation parameters to Higgsfield through its MCP service. The generated file is retained in this workspace and passed to the project agent for insertion. The provider connection is shared by authorised project editors; its authorization credentials remain on the server.
Administrators can review AI usage records for cost allocation. These records include the provider and model, reported tokens or estimated media credits, available monetary charges or clearly labelled estimates, request identifiers, timestamps and the customer, project and user assigned when the operation started. Historical records can retain this attribution after a chat, account or project is deleted. They do not contain the chat prompt or provider credentials and currently have no automatic expiry.
AI responses and generated slides can be inaccurate. Review them before use or distribution. Do not include sensitive personal data or confidential material unless its use with the selected service is authorised by your organisation.
Provider handling and retention depend on the selected service and account configuration. This workspace does not promise EU-only AI processing or zero retention. See Services and recipients for the status of international processing information.
Services and recipients
The workspace uses these services to deliver the functions described above:
- Vercel: website and API hosting, deployment and delivery of project files. Requests can include IP addresses, requested URLs, browser information, timestamps and error details. A comment mirror to Vercel Blob can additionally store collaboration data when configured.
- Supabase: authentication, database, file storage, realtime updates and server functions for accounts, collaboration and AI requests. The project’s database region is Frankfurt, Germany (
eu-central-1).
- united-domains: domain services and outgoing account email from the configured workspace sender. Mail processing includes recipients, message content and delivery metadata.
- GitHub: source control, automated generation and deployment workflows, project files, change history and job logs.
- OpenAI and Anthropic: AI processing when a corresponding model is used, as described in AI assistance.
- Higgsfield: image and video generation when connected by an administrator and requested in the project chat.
Project authors may also include links or media from external services. Opening those resources can disclose request data to their providers. Local copies of the app’s fonts, logos and background media are served with the website.
International processing
The listed cloud and AI services can involve processing outside the European Economic Area, including the United States. The database region does not determine all locations used for delivery, support, AI or automated workflows.
The specific contractual entities and international-transfer arrangements for the service accounts used by this workspace are still being verified. For current information or a copy of the applicable safeguards, contact hello@bitfuel.de. This notice will be updated when that verification is complete.
For reference, Supabase’s published data processing addendum and Vercel’s published data processing addendum describe their standard provisions. These documents alone do not confirm the configuration or contractual arrangements of this workspace.
Purposes and legal grounds
The intended purposes are to provide the workspace, manage authorised access, support collaboration, process requested AI work, deliver account messages, and investigate faults or misuse.
For business collaboration, access administration and security, we rely on Article 6(1)(f) GDPR. Our legitimate interests are operating a restricted business workspace, enabling authorised project work, protecting its content and investigating technical faults or misuse. We take the rights and interests of the people concerned into account.
Article 6(1)(b) GDPR applies where processing is necessary to perform a contract with you or to take steps at your request before entering into one. Processing required by a legal obligation is based on Article 6(1)(c). Employment-related processing and customer-provided content may be governed by the relevant organisation’s arrangements and notices. Registration or reading this notice does not constitute consent.
Cookies and browser storage
The app uses browser storage for sign-in and requested workspace functions. The current application does not integrate advertising cookies or a third-party analytics SDK.
Sign-in
The stg_at cookie contains the current access token so the server can protect pages and files. It expires with the access-token lifetime, is renewed when the session is refreshed, and is removed on sign-out. Supabase also stores session and refresh information in local storage so the session can survive a page reload or browser restart. The session may remain until sign-out, expiry or revocation, or until you clear site data.
Drafts and preferences
The editor can keep an unsaved draft in local storage to recover your work. Project briefings may use session storage while you work in the tab. Version-saving markers help finish interrupted saves. These work-recovery records are separate from optional preferences and some have no time-based expiry. Closing the browser or signing out does not necessarily remove them.
Your controls
You can sign out through the account menu and remove stored data for this site through your browser settings. Save your work first: clearing site data may sign you out, reset preferences and remove unsaved local drafts. This does not delete data held in the workspace or copies already downloaded.
Section 25(2) TDDDG permits storage or access without consent where it is strictly necessary to provide the service you explicitly request. This applies to required sign-in functions. Any additional storage requiring consent must be assessed separately.
Workspace preferences are optional and off by default. Choosing “Allow preferences” lets this browser remember your AI model, chat visibility, editor snapping and graph motion settings across visits. Choosing “Essential only” keeps these preferences in memory for the current page and removes previously stored optional preferences, without removing your sign-in or drafts. Use “Cookies & storage” in the footer, or the project’s cookie settings button, to change or withdraw your choice. Your choice is stored locally under stg:cookie-consent for 180 days, after which the app asks again and stops reading or writing optional preferences until you agree. If browser storage is unavailable, your choice applies only to the current page.
Retention and deletion
The current application does not apply a single automatic expiry to accounts, uploaded source files, comments, jobs or saved project versions. Administrators can manually remove records. Retention depends on the purpose of the record and requires review; signing out is not a request to delete server-side information.
Deleting an account does not by itself erase every contribution. Comment and reply text, stored author names, activity records and attributed project memory can remain in the project history. Archiving customer records retains their contacts. Similarly, removing a project’s hub entry does not by itself erase repository history, backups, all source files or downloads held elsewhere. A deletion request needs to cover the relevant systems and copies.
The criteria for a retention review are whether an account still needs authorised access; whether customer work and the corresponding projects or versions remain in use; whether invitations, delivery records or job logs are needed to resolve an outstanding request or failure; and whether records are needed for a security incident, legal obligation or the establishment, exercise or defence of legal claims. Data no longer required for these purposes should be deleted or anonymised, subject to applicable legal obligations.
There is currently no automated routine applying these criteria across all services. For an individual deletion or retention enquiry, contact hello@bitfuel.de. The review must include the relevant database records, uploads, repository history, provider-held copies and any applicable retention exceptions.
Your rights
Subject to the applicable conditions under the GDPR, you can request access to your personal data, correction, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. If processing is based on consent, you can withdraw that consent for the future without affecting the lawfulness of processing before withdrawal.
Contact the operator using the details in the legal notice. We may need information to verify your identity and locate the records concerned. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work or the alleged infringement.
The supervisory authority at our location is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit.
The workspace’s AI functions generate content and assist with edits. They are not designed to make decisions about people with legal or similarly significant effects. Account approval and access management are handled by authorised people.