Legal information
Privacy policy
autofetch
Last updated: 4 August 2026
This English translation is provided for accessibility and information. In case of differences, the German privacy policy is the authoritative version.
Protecting personal data is important to us. This policy explains which data autofetch processes, why it is needed and which rights you have.
1. Controller
Han Esser
Schloßgasse 6a
65239 Hochheim am Main
Germany
Email: support@autofetch.de
2. Data and purposes
2.1 Account
For registration and account operation, autofetch processes your email address, username, a securely hashed password, registration and verification times. An IP address is not permanently linked to the user account.
Legal basis: Article 6(1)(b) and (f) GDPR.
2.2 Technical access data and server logs
Upstream access and security logs may contain the network address, time, requested path and response status where needed to secure and operate the service. Full IP addresses are deleted automatically after no more than seven days, including rotated and compressed files, and are not permanently linked to an account, session, watch or download activity. Application error logs omit IP addresses, full query parameters, referrers and user agents.
2.2.1 Anonymous statistics for public pages
For publicly accessible pages, we collect only anonymous usage figures, such as how often individual pages are viewed and through which general sources they are found.
These figures are not connected with IP addresses, user accounts, sessions or devices. The signed-in user area and activities performed there are not part of this evaluation. Individual visitors are neither recognised nor tracked.
The underlying reduced statistics data is deleted after no more than 30 days.
2.3 Watches, jobs and clients
The server stores the configuration, metadata, job and status information needed to provide the service. Downloads themselves are performed by a client on your device and are not relayed through or stored as media files on the autofetch server.
2.4 Email and support
Your email address is used for account verification, requested password resets, important service notices, optional notifications and support. Support submissions may contain your description, client version, system information and redacted log excerpts.
Product updates about important new features and client releases are sent only after explicit, optional consent. The option is not preselected during registration and can be withdrawn at any time in notification settings. autofetch stores the current consent state and the time it was granted or last changed.
Operational messages about a specific account, support case, security event or important service problem are handled separately where required to provide or secure the service. Emails contain no tracking pixels and no open or click tracking.
2.5 Privacy requests and administrative records
When you exercise a data-protection right, autofetch processes the information needed to handle the request. This includes the request type and receipt date, status and deadline, a limited record of the method and result of identity verification, completion time and internal handling notes. Copies of identity documents are not stored in this system.
Sensitive administrative actions such as access exports, processing restrictions and account deletion are logged with the time, action and acting administrator account. The audit record contains no IP address, passwords, tokens or generated export contents.
Legal basis: Article 6(1)(c) GDPR and Article 6(1)(f) GDPR.
2.6 No tracking or profiling
autofetch uses no advertising trackers, marketing analytics or cross-site profiles. User data is not sold to advertisers.
3. Data sharing and service providers
Personal data is generally not shared with third parties.
For the technical operation of autofetch, we currently use only IONOS SE as our hosting provider and processor. IONOS processes the relevant data solely to provide and secure the required technical infrastructure and in accordance with our instructions.
No other external service providers currently receive personal data. If additional providers are used for operating the service in the future, they will be listed in this privacy policy before they are introduced.
Any other disclosure takes place only where we are legally required to do so.
4. Hosting and location
The service is hosted in Germany. Personal data is processed within the European Union unless this policy explicitly states otherwise.
5. Retention
- Account data: until account deletion, then normally deleted within 30 days unless a legal obligation applies.
- Access and security logs containing full IP addresses: no longer than seven days.
- Reduced anonymous public traffic logs: no longer than 30 days.
- Technical events: transient watch-start and empty-result events are not stored persistently. Watch-completion events are retained for no longer than two days, technical job-transition events for no longer than seven days, and other technical events for no longer than 30 days.
- Short-lived client security counters: normally no longer than two hours; they contain a client ID but no IP address.
- Configuration, activity and status data: while needed for the account and according to the activity-retention setting selected by the user.
- Automated email notifications: metadata for actual delivery attempts is retained for no longer than 30 days. Expected non-delivery because notifications are disabled is not persistently logged.
- Account and security emails: delivery metadata for verification and password reset is retained for no longer than 365 days; expired email tokens are deleted after a further 30 days.
- Administrative mailing history: recipient, subject, content and delivery status are retained for no longer than three years. Records still needed after account deletion are pseudonymised and technical provider details are removed.
- Support communication: while needed to resolve the request and reasonable follow-up questions.
- Product-update consent: until withdrawn; the change time is retained to manage consent transparently.
- Privacy requests and admin audit records: while needed to handle, fulfil and demonstrate the request or to safeguard sensitive administrative actions. Any records that must remain after account deletion are pseudonymised.
Privacy exports are generated only on request in the protected admin area, streamed directly and not stored permanently in a public location.
6. Cookies and device storage
Only technically necessary cookies are used:
autofetch.sid: a random session identifier required for sign-in, session security and CSRF protection; removed on sign-out or after no more than seven days.autofetch_locale: contains onlydeorenand remembers an explicitly selected language for no more than one year. For signed-in users the language is also stored in the account so the interface and emails can use it.
The browser language may be read on a first visit but is not thereby saved permanently and never overrides an explicit selection.
autofetch does not currently use localStorage or sessionStorage to retain search terms, sorting preferences or tracking identifiers.
7. Your rights
Subject to the legal requirements, you have rights of access, rectification, erasure, restriction, data portability and objection under Articles 15–21 GDPR, and may withdraw consent where processing relies on consent. Contact support@autofetch.de. You may also complain to a competent data-protection authority.
8. Security
Measures include HTTPS/TLS, secure password hashing, protected session cookies, access restrictions and regular security updates.
9. Changes
This policy may be updated when the service or legal requirements change. Material changes will be communicated where required.