This overview explains which personal data is processed in Netioon AI, for which purposes, to whom data may be disclosed, and which rights you have.
We process personal data only to the extent necessary to operate this website, provide user accounts, deliver AI functions, and protect the service. The GDPR, the German Federal Data Protection Act, and for access to end devices in particular Section 25 TDDDG are relevant.
Last updated: Jun 25, 2026, 9:31 PM
Controller: Maximilian Schaller
Address: Rehdorfer Str. 56, 90431 Nürnberg, Deutschland
Email: Maximilian-Schaller@netioon.de
When you access the website and its API endpoints, technically necessary connection and protocol data is generated, in particular:
This data is necessary to deliver the website, defend against attacks, trace errors, and keep the service stable.
If access logs are kept at server or reverse-proxy level, they may in particular contain the following data:
Processing is carried out for IT security, abuse prevention, troubleshooting, and technical administration.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest).
Server-side access logs are generally deleted after 14 days. Longer storage occurs only where this is required to investigate specific security incidents, abuse cases, or technical disruptions.
The log data is not used for advertising tracking or profiling.
Log data is not merged with other data sources.
If you use the app with a user account or guest access, the following data may in particular be processed and stored:
The legal basis for account data is Art. 6(1)(b) GDPR insofar as the processing is required to provide your user account, guest access, or the contractual use of the service.
The legal basis for chat, file, and audio content is Art. 6(1)(b) GDPR insofar as this is necessary to provide the requested functions.
The legal basis for these processing activities is Art. 6(1)(b) GDPR insofar as they are necessary for use of the platform, and Art. 6(1)(f) GDPR for system security, abuse prevention, and technical stability.
If you choose Google sign-in, you are redirected to Google. No Google login takes place unless you actively start it.
Depending on available Google data and the released standard information, the following data may in particular be transferred to us:
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
The legal basis for account sign-in is Art. 6(1)(b) GDPR. Security mechanisms of the OAuth flow, in particular state and nonce checks, are also based on Art. 6(1)(f) GDPR.
This website accesses information stored on your device or stores information there only where technically required or where you have explicitly consented. This includes in particular:
The legal basis for required access to or storage on your device is Section 25(2) No. 2 TDDDG. To the extent personal data is processed afterwards, this is based on Art. 6(1)(b) or Art. 6(1)(f) GDPR.
No tracking or marketing cookies are used.
Only if you consent, optional browser comfort storage may be used as well. At present, this mainly concerns storing your own OpenAI API key only locally on this device. That information is not automatically sent to our server with every request.
The legal basis for optional comfort storage is Section 25(1) TDDDG and Art. 6(1)(a) GDPR (consent).
To provide chat, image, and audio functionality, the content required for the respective feature is transmitted to OpenAI.
Depending on the feature used, the following data may in particular be transmitted:
Recipient/service provider: OpenAI, L.L.C., USA, or affiliated companies for the provision of API services.
OpenAI receives only the data necessary for the specific requested function. For live voice input, audio may be transmitted to OpenAI through a realtime connection while you speak so text can appear immediately in the composer. Integration is based on the provider's applicable contractual data protection terms.
The legal basis for the processing is Art. 6(1)(b) GDPR insofar as the AI function is provided at your request.
Where required, we rely on OpenAI's offered contractual and data protection terms, including DPA/SCC mechanisms.
If you use your own OpenAI API key in the settings, it is not stored server-side in your account. It can only optionally be stored locally in your browser if you allow the optional comfort storage for that purpose.
Note: According to OpenAI's current platform documentation, API data may by default be retained in abuse monitoring logs for up to 30 days unless a zero-retention setup or longer legal obligations apply.
This may also involve a transfer of personal data to the United States as a third country.
Appropriate safeguards, in particular Standard Contractual Clauses (SCCs) and the provider's contractual data protection rules, are used for third-country transfers.
Netioon Live is an optional voice chat. When you start it, your microphone is used only after browser permission and audio is transmitted through a realtime connection to OpenAI during the active session so speech can be understood and a spoken answer can be generated.
For the daily limit, Netioon stores only the date and used seconds. Netioon Live audio is not stored as an audio file in your account. Normal chats, text input, uploads, feedback, and memories remain separate and are governed by their respective sections.
Where OpenAI is used for Netioon Live, OpenAI processes the transmitted audio and response data as the technical provider of the AI function under the agreements and safeguards applicable to API usage.
The legal bases are Art. 6(1)(b) GDPR for providing the explicitly started voice chat function and Art. 6(1)(f) GDPR for abuse prevention, technical stability, and fair limitation of available Live time.
You can end Netioon Live at any time, mute the microphone, or revoke the browser microphone permission. The short start and end sounds are generated locally in the browser and do not transmit additional content.
Netioon AI can request external data sources when needed to show weather cards, routes, places, map markers, internet images, or source references in chat. These features are used only when required by your request or enabled settings.
The weather widget uses MET Norway, Open-Meteo, and, where needed, Nominatim/OpenStreetMap for location resolution. Requests are performed server-side; the browser then displays a chat attachment with the weather data.
Routes, geocoding, reverse geocoding, and POI searches use openrouteservice. The visible map loads map tiles from OpenStreetMap. External links may open OpenStreetMap destinations or prepared map views.
Internet image search queries DuckDuckGo Images, Wikimedia Commons, and Openverse. Netioon stores displayed images as chat attachments with source links so the answer remains traceable. Image rights usually remain with the respective rights holders; for reuse, you must check the source license and terms.
If general internet research is enabled, OpenAI may use web search or web context. Your query, relevant chat content, and technical metadata may be transferred to OpenAI so sources can be found and processed in the answer.
The legal bases are Art. 6(1)(b) GDPR for providing the explicitly requested features and Art. 6(1)(f) GDPR for technical stability, abuse prevention, source verification, and traceable result display.
You can disable internet research, internet image search, image generation, navigation, the weather widget, speech features, and uploads in settings. Without these features, the respective external requests are not used for new prompts.
The data stored server-side in this app is processed on the hosting used by us in Germany. In addition, certain comfort settings remain only in your browser.
As a rule, account data, attachments, memories, settings, credit data, and streak data are stored only for as long as they are needed for the account, use of the service, security, or legal duties. You can delete many contents yourself; data is also removed when your account is deleted unless statutory retention duties or legitimate security interests require longer storage. For guest access, the credit system uses a server-generated pseudonymous IP hash so a new guest account does not immediately reset the quota; the raw IP address is not stored in the credit database for this purpose. Chats additionally follow an automatic inactivity-based deletion period: unpinned chats are deleted after 15 days without new activity, and pinned chats after 2 months without new activity. Long chat histories may be loaded in chunks and rendered virtually in the interface; server-side storage continues to follow these deletion periods.
In the account settings, you can reset saved settings, delete chats, and remove your account entirely. Chats can also be renamed permanently and pinned. If you delete your account, your user account and the related server-side data such as settings, chats, memories, credit data, and streak data are deleted or, where complete deletion is exceptionally not possible, restricted or anonymized. Separately submitted feedback is additionally handled under the rules stated for feedback.
Hosting: Eigenhosting (eigener Server in Deutschland).
If you voluntarily submit information through the feedback button, only the data required for handling it is processed. Your submission is stored as a feedback thread and used only for handling the respective case.
Processing takes place solely for reviewing, prioritising, handling, and responding to bug reports and improvement suggestions.
The legal basis is Art. 6(1)(a) GDPR (consent).
The content is not disclosed to third parties. Access is limited to the parties responsible for operation and handling, plus technically necessary hosting providers.
Open feedback threads are generally stored until the respective process has been completed. After completion, they are usually deleted within 90 days unless longer retention is exceptionally required to handle an unresolved concern, ensure IT security, or establish, exercise, or defend legal claims.
If the Netioon team replies, that reply may be shown to you as a notice popup the next time you open the site. The popup remains marked as pending on the server until you actively click “Close” or “Reply”. Simply closing the browser window does not permanently remove the notice.
You may withdraw your consent at any time for the future and request deletion of your feedback.
Administrative functions exist for operating the platform, handling support and feedback cases, security checks, and access, rectification, erasure, or portability requests. Access is purpose-bound, role-restricted, and limited to what is required for the specific case.
The regular admin overview does not show chat messages or memory contents. It primarily shows account, status, usage, and metadata so private content is not exposed unnecessarily.
The legal bases are Art. 6(1)(b) GDPR for usage-related support handling, Art. 6(1)(c) GDPR for compliance with legal obligations and data subject rights, and Art. 6(1)(f) GDPR for IT security, abuse prevention, traceability of administrative actions, and reliable service operation.
If a verified deletion request exists or an appropriate authorization applies, server-side stored account data, chats, memories, settings, feedback entries, credit and streak data, and related sessions may be specifically deleted, blocked, or anonymized unless overriding statutory duties or legitimate retention interests apply.
Where a verified deletion request exists, not only complete accounts but also individual chats, memories, or feedback entries may be removed in a targeted manner where required to handle the respective request.
For verified access or data portability requests, a structured machine-readable export of server-side stored data may be created. This only concerns the handling of such requests and does not include purely browser-local storage on other devices.
Guest accounts are intended only as temporary one-time access and are deleted automatically on the server after 24 hours. This also removes the related server-side stored data and sessions. The guest credit balance is not tied to the individual guest account but to a server-generated pseudonymous IP hash, so logging out and starting again does not immediately create a fresh quota; the raw IP address is not stored in the credit database for this purpose.
Purely browser-local comfort storage on user devices cannot be deleted remotely, for example locally stored settings or a personal API key voluntarily stored there. Such content can generally only be removed on the respective device or by the user. Server-side sessions can, however, be revoked.
Within the scope of the law, you have in particular the following rights:
Please send requests to: Maximilian-Schaller@netioon.de
Competent or helpful supervisory contacts:
No automated decision is made within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
This service is not directed at children. Persons under the age of 16 should use the website and AI functions only with the consent of their legal guardians.
No analytics, profiling, advertising, or marketing tools are used. In particular, we do not use audience measurement, retargeting, or third-party trackers.
This privacy policy may be updated if functions, legal requirements, or service providers change. The version published on this website applies.