Under Account > Privacy (Konto > Datenschutz) you control your consents, see who processes your data, and exercise your GDPR rights: from data export to account deletion. Everything in one place, no support ticket needed.
Consents
Three switches govern what you allow. Changes take effect immediately and are logged.
Support access
The switch Support darf mein Konto einsehen (support may view my account) is off by default. If you enable it, support may look into your account for a limited time to troubleshoot. Every single access is logged.
When a session ends
A session ends on its own, in one of four ways. You do not have to wait for any of them:
- You withdraw the grant. This takes effect immediately and also ends a session that is currently running.
- Your grant period expires. Even if the session itself would still have time left.
- The session reaches its maximum duration. It is set when the session starts and is never longer than your grant.
- 30 minutes without activity. A tab left open does not keep the access alive.
Support can also end a session at any time. Under Bisherige Zugriffe (past accesses) each session shows which reason applied.
What you can review afterwards
Under Bisherige Zugriffe (past accesses) every session is listed with the person, the time, the mode (view only, or view and change) and the reason support gave. Was wurde angesehen? (what was viewed) expands the log of that one session:
- Geöffnet (opened) means the screen was only viewed.
- Geändert (changed) means something really was changed there. That can only happen if you had granted the "view and change" mode.
- Versucht (attempted) means the action was rejected and changed nothing. Billing, credits, integrations and the credential vault are always blocked during a support session.
If the same screen was opened several times in a row, the count follows it ("8 mal"). For very long sessions you see the last 200 steps, and the page says so.
Expanding the log is available to whoever manages the members of this workspace, so owners and administrators. The reason is the same as for granting access: the log shows which screens were opened, and that concerns everyone's data.
Data processors
The page transparently shows which partners process data. EU endpoints are preferred; any US processing is safeguarded by EU standard contractual clauses (SCC).
- Supabase: database and authentication, EU (Frankfurt).
- Vercel: application hosting and delivery, EU (Frankfurt).
- Cloudflare R2: file and media storage, EU.
- AI services: processing in AI tools, EU preferred, US processing via SCC.
The complete list of data processors is available under Data processing. Where your data lives in general is explained in Data storage and security.
Your activity log
The My activity log section lists your own account actions in the current workspace, for example changed consents, a data export or a role change. This lets you trace what happened with your account at any time.
Export your data
Start the export
In the Your rights section click Herunterladen (download). You receive your profile, preferences, consents, memberships and your assistant conversations as a JSON file (Art. 15 and 20 GDPR).
Sign in again if asked
For security reasons the platform may require a fresh sign-in before the export. In that case, briefly sign in again and restart the export.
Delete your account
Account deletion anonymizes your account with a 30-day grace period (Art. 17 GDPR):
Request deletion
Type your email address exactly as confirmation and click Löschung endgültig beantragen (request final deletion).
30-day grace period
Your account is only anonymized after 30 days. Until that date you can withdraw the request at any time via Löschung widerrufen (withdraw deletion).
Automatic execution
Once the period has passed, the platform carries out the deletion without any further action on your part: you leave all workspaces, your profile is anonymized (name, email address, phone number, profile picture and consents are removed), and signing in is no longer possible afterwards. Invoices and audit entries subject to statutory retention remain, without any personal reference.
Further reading
- GDPR on the platform: how the platform handles personal data overall.
- Privacy policy: the legal basis in full.