Version 1.1 - last updated 2026-10-02
The controller is HostingBrain ApS, CVR 46679091, Denmark. Write to hello@hostingbrain.ai about anything on this page. Full details are in section 9.
| What we hold | Why | Lawful basis | How long |
|---|---|---|---|
| Access-key record — email, organisation, plan, the address you signed up from | Give you access and apply your plan's limits | Contract, Art. 6(1)(b); abuse prevention, Art. 6(1)(f) | Life of the account plus 12 months |
| Contact-form request — work email, organisation, role, plan of interest, your question | Reply to you and arrange a walkthrough | Pre-contract steps, Art. 6(1)(b) | 24 months from the request |
| Product request log — key hash, organisation, which query ran, the parameters, timing | Run the service, apply limits, prevent abuse | Contract, Art. 6(1)(b); abuse prevention, Art. 6(1)(f) | 90 days at parameter level |
| Calls without a key, and refused requests - the address the request came from, the client software, and for calls without a key which query ran and its parameters | Rate limiting and abuse prevention | Legitimate interest, Art. 6(1)(f) | The address: up to 30 days |
| Feedback — your message and what it refers to | Fix a wrong or missing answer | Legitimate interest, Art. 6(1)(f) | 24 months |
| Web server log — time, IP address, country, page, referring page, browser string | Security, and a daily count of visits | Legitimate interest, Art. 6(1)(f) | None once the site is served from Cloudflare Pages; until then 90 days |
| Purchase record - order number, what you bought, amount, billing name, email, the kind of tax ID if one was given (not the number) | Deliver your report or give you access to your plan, answer support and refund questions | Contract, Art. 6(1)(b) | 24 months from the purchase |
| Observational data — public infrastructure signals at domain level | The market analysis the product performs | Legitimate interest, Art. 6(1)(f) | Kept as the historical record |
The outside parties involved are listed in section 5, retention in section 6, and your rights in section 7.
We process (a) account data about you as a user, and (b) observational data about public internet infrastructure, which is what the product analyses.
The service is written for organisations and their professional advisers, and anyone may buy it. It is not directed at children, and we do not knowingly hold data about anyone under 16. We do not ask for special-category data — health, beliefs, biometrics and the rest of Art. 9 — and you should not send it to us.
Account data reaches us at the six points below. Each one is listed with what it holds and why we may hold it under the GDPR.
You can sign in with Google or ask for a key by email. Google sign-in gives us your Google account identifier, your email address and the name on the account; the sign-in itself happens at Google, and we never see your password. The email form gives us your email address, your organisation if you type one, and the IP address the form was sent from — we keep that address to cap automated signups.
The key record itself holds your organisation, your email address, the plan you are on, whether the key is active or revoked, the date it was created and — once billing is live — the Polar customer reference. The key is stored only as a one-way hash; we cannot read it back to you.
Both routes record which version of the Terms and this policy you accepted, when you accepted it, and whether you asked for product updates. Basis: performing the contract you are entering (Art. 6(1)(b)), and legitimate interest in preventing abuse (Art. 6(1)(f)).
If you connect through an assistant rather than a header, we also hold the connection tokens that stand in for your key. Access tokens expire after 90 days and refresh tokens after a year; both can be revoked at any time from our side.
The contact form sends your work email, your organisation, your role, the plan you asked about, the question you want answered and an optional market or operator. Those six fields are the whole form; nothing else on the page is collected, and there is no hidden field.
We store those fields with the IP address the request came from, and a status we use to track whether we have replied. So that a request is not missed, a founder's phone is alerted that one has arrived; the alert says only that, and carries nothing about you. Basis: steps taken at your request before a contract (Art. 6(1)(b)).
Requests are read by us and answered by email. They are not passed to a sales tool, a CRM or an advertising platform, because we run none.
Every call to the product records the hash of your access key, your organisation, which query ran, the parameters you passed, how many rows came back, how long it took, whether it succeeded, and the name and version of the client software. We do not store the answers themselves, and a call made with an access key is not recorded against your IP address. Purpose: running the service, applying the usage limits your plan sets, preventing abuse and improving the product. Basis: performing our contract with you (Art. 6(1)(b)), and legitimate interest in preventing abuse (Art. 6(1)(f)).
The parameters stay inside that store. They are not sent to any outside party, not used to train a model, and never visible to another customer — the boundary is built into the system, not a promise about how we behave. We also count calls per key per day, which is how a plan's limits are applied.
Parameters are reduced to theme-level aggregates after 90 days, for research confidentiality. Each call older than that becomes part of a daily count per query, per outcome and per kind of subject it asked about - an operator, a market, a domain, a technology or free text, never which one. The parameters themselves, the key hash and the organisation are deleted; what remains is counts that name nobody. We do not sell account or usage data.
Without an account, and refused requests. Part of the product answers without an access key. For those calls we keep the address the request came from, the name and version of the client software, which query ran and the parameters passed. For requests the service turns away before they run - no key, a key it does not accept, or too many requests without a key - we keep the address, the kind of client software and the reason. The address is kept for up to 30 days. Records of refused requests are then deleted, and the address is removed from the record of calls made without a key, which after that names no one. After 90 days those calls are reduced to counts like any other call, as described above. We never use the address to work out who you are, and we never publish it. Basis: legitimate interest in keeping the service available and preventing abuse (Art. 6(1)(f)).
The product has a feedback channel for reporting a wrong number or a missing answer. It stores your message, what it refers to, the version of the data you were on, your organisation, your key hash and the client you sent it from. The channel only takes messages in — nothing written to it is served back through the product. We read it to fix the product. Basis: legitimate interest in improving a service you use (Art. 6(1)(f)).
We are moving this site to Cloudflare Pages, which serves it as static files and keeps no server log for us. Until the move is complete, our own web server keeps a standard access log with one line per request: the time, your IP address, the country the request came from, the page requested, the referring page and the browser string. Basis: legitimate interest in keeping the service secure and knowing whether anyone is reading it (Art. 6(1)(f)).
While that log exists, once a day we read it to produce a summary: how many page views, how many distinct visitors, the top few countries, pages and referring sites. The summary is counts only — it names no visitor and carries no address. Nothing else reads the log.
The site sets no cookies of its own and carries no advertising or analytics trackers. There is no third-party script on any page of this site, so no outside party learns that you visited. The security service in front of the site may set a cookie of its own to tell visitors from automated traffic.
Every purchase and every paid subscription goes through Polar, which acts as the merchant of record: Polar sells to you or your organisation, takes the payment and handles VAT. There is no other way to pay us. What you type at checkout - your name, email, billing address or country, a company tax ID if you give one, and payment details - goes to Polar, and card payments are processed by Stripe as Polar's card processor. We never see card numbers.
When the payment is confirmed, Polar tells us the order: its number, the product, the amount, the billing name, your email, and whether and what kind of tax ID was given. We keep those fields (the tax ID's kind, not its number) to deliver your report or give you access to your plan, to answer support and refund questions, and to show the licensee's name inside the file. The file itself is kept until its download link expires, 30 days after delivery, and then deleted. Basis: performing the contract you entered (Art. 6(1)(b)).
A Pro or Analyst subscription keeps even less with us. Polar issues your API key and holds your subscription, and we keep no order record for it. When you use the key, we check it with Polar and keep Polar's identifier for the key - never the key itself - with the usage records described in section 2.3. When the subscription ends, Polar revokes the key.
Polar's own privacy policy covers what it does as the seller. Purchases are governed by our terms of sale, data licence and refund policy.
Our dataset is derived from publicly observable internet infrastructure - DNS, and the responses web and mail servers give to anyone who connects - at domain level. Where a domain belongs to a sole proprietor, some of this may constitute personal data under GDPR. We process it under legitimate interest (Art. 6(1)(f)): market research on aggregate infrastructure, with data minimisation — no consumer profiling, no marketing to data subjects, aggregate-level reporting by default.
Your rights: if a domain concerns you, you may request access, correction or objection at hello@hostingbrain.ai. Objections are honoured by excluding the domain from analytical output.
The product runs on our own EU-located hardware. These outside parties are involved, and no others:
Transfers outside the EU. These four are US-headquartered. Where they process account data outside the EU, the transfer rests on the European Commission's standard contractual clauses in their data-processing terms. We ask for EU data residency where a service offers it.
We may also disclose account data if a Danish or EU authority lawfully requires it. Beyond that, account data does not leave the service described on this page.
Each period is applied by a daily run, so a record goes on the first run after its period ends and can outlast it by up to a day.
An IP address stored alongside a signup or a contact request is deleted with that record, on the period above. These periods are applied automatically, by a job that runs every day. If you ask us to delete something sooner, we do — see the next section. Purchase records are the exception: we keep them for their full 24 months, because they are needed for refunds, re-issued reports and support.
Under the GDPR you may ask us to:
Where a use rests on your consent — product updates by email — you may withdraw that consent at any time, and withdrawing it does not affect what came before.
Write to hello@hostingbrain.ai. We answer within one month, and we do not charge for it. If we need to be sure it is you, we ask from the address on the account rather than for a document.
On request we delete your access key, your sign-in record and the requests you have sent us, and we remove the identifiers that tie usage records to you. What is left is counts that name nobody. Purchase records are kept until their 24 months have passed (see section 6).
If you think we have handled your data wrongly, you may complain to your national supervisory authority. In Denmark that is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby — datatilsynet.dk.
This page carries a version and a date at the top, and both change when the substance does. When a change is material we ask you to accept the new version the next time you sign in, and we record which version you accepted.
Controller: HostingBrain ApS, CVR 46679091, VAT DK46679091, Store Kannikestræde 10, 1169 København K, Denmark — hello@hostingbrain.ai. We have not appointed a data protection officer; the founder answers privacy mail directly.