Privacy at a glance
Last updated: June 27, 2026
2026-06-27
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. For detailed information on the subject of data protection, please refer to our privacy policy listed below this text.
Self-Engine is not directed at children or young people under the age of 16. We do not knowingly process personal data of persons under the age of 16. Persons under the age of 16 must not provide us with personal data without the consent of the holders of parental responsibility.
If we become aware that we have processed personal data of a person under the age of 16 without the required consent, we will delete that data without undue delay. If you have reason to believe that a child has provided us with personal data, please contact us at kontakt@self-engine.com.
Data processing on this website is carried out by the website operator. You can find their contact details in the section 'Information about the responsible party' in this privacy policy or in the imprint.
Your data is collected in two ways: directly from you when you register or contact us by email, and automatically by our systems when you visit the website. The automatically collected data primarily consists of technical access data (e.g., browser type, operating system, time of page view, and IP address) processed by Vercel's infrastructure to provide the website securely and reliably. The IP address is personal data; details on its processing by our hosting provider can be found in the "Hosting" section.
Your data is used to provide and improve the application, to manage your user account, to bill paid subscriptions, to enable offline synchronization across your devices, and to ensure the security and stability of the service. Anonymous technical data is used to analyze and optimize the performance of the website.
You have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have the right to request the correction or deletion of this data. If you have given your consent to data processing, you can revoke this consent at any time for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority. You can contact us at any time if you have further questions about data protection.
This website is hosted by an external service provider (hoster). The personal data collected on this website is stored on the hoster's servers. This may primarily include IP addresses, contact requests, meta and communication data, contract data, contact details, names, website accesses, and other data generated via a website.
The hoster is used for the purpose of fulfilling contracts with our users (Art. 6 para. 1 lit. b GDPR) and in the interest of secure, fast, and efficient provision of our online offering by a professional provider (Art. 6 para. 1 lit. f GDPR). We use only technically necessary cookies and do not employ any consent-requiring storage of, or access to, information on your end device within the meaning of § 25 TDDDG.
Our hoster will only process your data to the extent necessary to fulfill its performance obligations and follow our instructions regarding this data.
We use Vercel as our hosting provider. The provider is Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit this website, Vercel automatically collects various log files including your IP addresses. This data is used to provide and ensure the stability and security of the service. For more information, see Vercel's privacy policy: https://vercel.com/legal/privacy-policy
Vercel provides a standard Data Processing Addendum (DPA) as part of their Terms of Service. By accepting Vercel's terms, this addendum applies automatically and governs the processing of personal data in accordance with GDPR Art. 28.
This website uses Vercel Analytics to analyze how our website is used. According to Vercel, this involves processing event- and request-based usage data such as visited pages, referrers, technical browser and device information, and shortened or hashed identifiers. The data helps us understand product usage and improve reliability and usability. Vercel Analytics does not set cookies and does not store information on, or access information stored in, your end device; consent under § 25 TDDDG is therefore not required.
This application offers the option to sign in using your GitHub account. This service is provided by GitHub Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. The sign-in is technically handled by our authentication service Clerk (see section "Authentication and Account Management (Clerk)").
When you click 'Sign in with GitHub', you are redirected to GitHub's servers. GitHub authenticates your identity and sends us a token along with basic profile information. We do not receive your GitHub password.
• GitHub user ID
• Email address (if set as public or permission granted)
• Username and display name
• Profile picture URL
The data is used exclusively for authentication and to create and manage your user account in Self-Engine.
The processing is based on your consent (Art. 6 para. 1 lit. a GDPR), which you give by actively choosing to sign in with GitHub, and on the performance of a contract (Art. 6 para. 1 lit. b GDPR) for providing the application.
GitHub Inc. is based in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). GitHub is additionally certified under the EU-U.S. Data Privacy Framework.
For more information, see GitHub's privacy policy: https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement
This application offers the option to sign in using your Google account. This service is provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. The sign-in is technically handled by our authentication service Clerk (see section "Authentication and Account Management (Clerk)").
When you click 'Sign in with Google', you are redirected to Google's servers. Google authenticates your identity and sends us a token along with basic profile information. We do not receive your Google password.
• Google user ID
• Email address
• Display name
• Profile picture URL
The data is used exclusively for authentication and to create and manage your user account in Self-Engine.
The processing is based on your consent (Art. 6 para. 1 lit. a GDPR), which you give by actively choosing to sign in with Google, and on the performance of a contract (Art. 6 para. 1 lit. b GDPR) for providing the application.
Google LLC is based in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Google is additionally certified under the EU-U.S. Data Privacy Framework.
For more information, see Google's privacy policy: https://policies.google.com/privacy
Self-Engine offers the option to connect your Google Calendar in order to synchronize events between Self-Engine and Google Calendar. This feature is only activated if you explicitly connect it in the settings. The service is provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
Once connected, Self-Engine receives read and write access to your Google Calendar. We read events within a window of roughly one year into the past and one year into the future, and we can create, update, or delete events you create or modify in Self-Engine within your Google Calendar (bidirectional synchronization).
• Event data (title, description, location, start and end time, time zone, status, and availability)
• Technical event identifiers (event IDs, etag, information about recurring events)
• Information about your primary calendar (name, time zone, access role)
The synchronized event data is stored on our Supabase servers (EU region) to enable synchronization and offline use. The Google refresh token required for access is stored exclusively server-side and in encrypted form.
The processing serves solely to provide the calendar feature you have activated and to synchronize your events between Self-Engine and Google Calendar.
Processing is based on your consent (Art. 6(1)(a) GDPR), which you grant by connecting your Google Calendar, as well as on the performance of a contract (Art. 6(1)(b) GDPR) to provide the feature.
Google LLC is based in the USA. The data transfer is carried out on the basis of the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Google is additionally certified under the EU-US Data Privacy Framework.
You can disconnect the integration at any time in the settings. Doing so deletes the stored refresh token and ends synchronization. You can additionally revoke the granted access at any time directly in your Google account under the security settings.
Self-Engine's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use calendar data exclusively to provide and improve the calendar feature and do not share it for advertising purposes. For more information, please see Google's privacy policy: https://policies.google.com/privacy?hl=en
For registration, sign-in, and management of your user account, we use Clerk, a service provided by Clerk, Inc., 660 King Street #345, San Francisco, CA 94107, USA. Sign-in via GitHub or Google is also technically handled by Clerk.
• Email address and login credentials (passwords are stored exclusively in hashed form)
• Name, username, and profile picture (if provided)
• When signing in via GitHub or Google: the profile information transmitted by these providers
• Technical data for security purposes (IP address, browser and device information, sign-in timestamps)
• Session information (cookies or tokens to maintain your session)
• Registration, sign-in, and session management
• Management of your user account (e.g., changing your email address or password)
• Account security and protection against abusive sign-in attempts
The processing is carried out for the performance of the user agreement (Art. 6 para. 1 lit. b GDPR). The processing of technical data for security purposes is based on our legitimate interest in the security of the service (Art. 6 para. 1 lit. f GDPR).
Clerk, Inc. is based in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
A Data Processing Agreement in accordance with Art. 28 GDPR is in place with Clerk. For more information, see Clerk's privacy policy: https://clerk.com/legal/privacy
For concluding and processing paid subscriptions, we use the payment service provider Stripe. The provider for customers in the European Economic Area is Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland; the parent company is Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. Subscription management (checkout, plan and status management) is technically handled by our service provider Clerk (see section "Authentication and Account Management (Clerk)").
• Name and email address
• Payment data (e.g. card number, expiry date, security code or details of the chosen payment method) – collected directly by Stripe
• Billing data (selected plan, price, billing period, and where applicable billing address and country)
• Transaction data (time, amount, and status of payments)
• Subscription status (e.g. trial, active, canceled), which is managed via Clerk and processed within the application
• Technical data for fraud prevention and payment security (e.g. IP address, browser and device information), processed by Stripe
• Conclusion and processing of the subscription, including recurring payments
• Management of the trial period, renewal, and cancellation of the subscription
• Fraud prevention and security of the payment process
• Compliance with legal obligations, in particular under tax and commercial law
The processing is carried out for the performance of the subscription contract (Art. 6 para. 1 lit. b GDPR). Where we store billing and transaction data due to statutory retention obligations, this is based on Art. 6 para. 1 lit. c GDPR. Processing for fraud prevention is based on the legitimate interest in secure payment processing (Art. 6 para. 1 lit. f GDPR). For fraud prevention and compliance with its own legal obligations (e.g. anti-money-laundering), Stripe processes data in part as an independent controller.
During the payment process, Stripe may use technically necessary cookies and similar identifiers for fraud prevention and the secure execution of the payment. These are required for the payment processing you have explicitly requested (Section 25 (2) no. 2 TDDDG).
Stripe may transfer personal data to Stripe, Inc. in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR); Stripe is also certified under the EU-US Data Privacy Framework. Subscription and billing metadata is additionally processed by Clerk, Inc. (USA); for details, see the section "Authentication and Account Management (Clerk)".
We store billing and transaction data for as long as this is necessary for the administration of the subscription and as long as statutory retention obligations (in particular under commercial and tax law) apply. After these periods expire, the data is deleted.
For more information, see Stripe's privacy policy: https://stripe.com/privacy
For storing your application data, we use Supabase, a service provided by Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. Authentication is not handled by Supabase but by Clerk (see section "Authentication and Account Management (Clerk)").
• Your user identifier (user ID) from our authentication service Clerk
• User profile data (name, settings, preferences)
• Content data you create in the application (projects, time entries, appointments, financial data, habits)
• Technical data (login times, IP addresses for security purposes)
• Storage and management of your application data
• Provision of application features
• Data synchronization across devices
• Security and fraud prevention
The processing is based on the performance of a contract (Art. 6 para. 1 lit. b GDPR) and your consent (Art. 6 para. 1 lit. a GDPR).
Your data is stored on Supabase servers, which are located in the EU region to ensure GDPR compliance.
Supabase Pte. Ltd. is a company based in Singapore. Data transfers to third countries are based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Despite the use of EU servers, administrative access from Singapore may occur. Supabase includes standard contractual clauses (SCCs) in their terms of service to ensure appropriate safeguards for international data transfers.
All data is encrypted both in transit (TLS/SSL) and at rest. Access to your data is restricted to your own user account via access rules (Row Level Security).
Supabase provides a standard Data Processing Addendum (DPA) as part of their Terms of Service. By accepting Supabase's terms, this addendum applies automatically and governs the processing of personal data in accordance with GDPR Art. 28. For more information, see Supabase's privacy policy: https://supabase.com/privacy
This application uses PowerSync, an offline synchronization technology that allows you to use the application even without an internet connection.
PowerSync creates a local SQLite database on your device that contains a copy of your data from the Supabase database. Changes you make offline are automatically synchronized with the server once you are back online.
• All your content data (projects, time entries, appointments, financial data)
• User settings and preferences
• Synchronization status and metadata
The local database is stored in your device's browser storage (IndexedDB). This data remains on your device and is only synchronized with your user account.
The local database uses your browser's security mechanisms. When you log out or clear your browser data, the local database is also removed.
Local storage is based on the performance of a contract (Art. 6 para. 1 lit. b GDPR) as it is necessary to provide the application's offline functionality.
More information about PowerSync: https://www.powersync.com/legal/privacy-policy
Self-Engine offers an optional AI assistant that lets you manage your entries (e.g., time entries, appointments, habits, and financial data) using natural language. This feature is disabled by default and only becomes active once you explicitly enable it in the settings. To operate it, we use the service OpenRouter provided by OpenRouter, Inc., 135 Greene Street, Apt. 3N, New York, NY 10012, USA. OpenRouter acts as a technical intermediary (gateway) that forwards your requests to the respectively selected AI model provider.
When you send a message to the assistant, your input is transmitted server-side via OpenRouter to the selected AI model in order to generate a response. Access to the AI model takes place exclusively via our server; the access key required for OpenRouter is not transmitted to your browser.
• Your inputs addressed to the assistant (freely entered text)
• Language setting, time zone, and the current point in time
• Aggregated hints about your data (e.g., the number of your projects, appointments, habits, or cashflows) - without the associated content
• If you have the assistant retrieve data or prepare actions: the content data required for this (e.g., project names, time entries, appointments, or financial data), which is transmitted to the AI model as context
Processing serves exclusively to provide the assistant function you have enabled, in particular to answer your requests and to prepare and execute the actions you confirm.
The transmission of your inputs to the AI model is based on your consent (Art. 6 para. 1 lit. a GDPR), which you grant by enabling the AI assistant in the settings, as well as on the performance of a contract (Art. 6 para. 1 lit. b GDPR) to provide the feature. You can withdraw your consent at any time with effect for the future by disabling the AI assistant again in the settings. We process the usage metadata stored server-side (number of requests, token consumption, and estimated costs) independently of this, on the basis of our legitimate interest in abuse and cost control (Art. 6 para. 1 lit. f GDPR) and for contract and billing handling (Art. 6 para. 1 lit. b GDPR); withdrawing your consent to the AI processing does not affect this processing.
OpenRouter forwards your request to the provider that supplies the respectively selected AI model. In the production environment, a DeepSeek model is currently used predominantly; depending on the configuration, other providers available via OpenRouter (e.g., Anthropic) may also be used. We use OpenRouter's Zero Data Retention option and restrict routing to providers that support it. According to OpenRouter, neither the intermediary nor the respective model provider permanently stores the data you transmit or uses it to train AI models. Depending on the model and routing, the processing - which occurs without permanent storage - may also take place by providers outside the European Union.
The history of your conversations with the assistant is stored exclusively locally in your browser (LocalStorage) and is not stored on our servers. For transmission to the AI model, we use OpenRouter's Zero Data Retention option; according to OpenRouter, your inputs and the responses are not permanently stored by the intermediary or the model provider, nor used for training. We have not enabled the optional logging of inputs (prompt logging). On our servers, we only store usage metadata (e.g., the number of requests, token consumption, and estimated costs) for billing and abuse prevention, but no content of your conversations.
OpenRouter, Inc. is based in the USA. The data transfer takes place on the basis of the European Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Depending on the selected model provider, processing may also take place in further third countries outside the EU/EEA; due to the Zero Data Retention option used, it takes place — according to OpenRouter — without permanent storage.
The AI assistant only makes suggestions and prepares actions. Changes to your data (e.g., creating or modifying entries) are only carried out after your explicit confirmation. There is no solely automated decision producing legal effects within the meaning of Art. 22 GDPR. AI-generated content may also be incomplete or incorrect and should be reviewed by you.
For more information, see OpenRouter's privacy policy: https://openrouter.ai/privacy
This website uses cookies and similar technologies. Cookies are small text files that are stored on your device and saved by your browser.
We use essential cookies that are technically necessary for the operation of the website. These cookies serve exclusively to provide our services and cannot be deactivated.
Essential cookies used:
• Authentication cookies of our sign-in service Clerk (session tokens) for login
• Security cookies to protect against CSRF attacks
• Language preference cookies
• Browser storage (LocalStorage, IndexedDB) for offline functionality
Processing is based on legitimate interest (Art. 6 para. 1 lit. f GDPR) in the technically error-free and secure provision of our website.
You can set your browser to inform you about the setting of cookies and only allow cookies on a case-by-case basis, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. Disabling cookies may limit the functionality of this website.
As part of our data processing, data is partially transferred to service providers in third countries outside the EU/EEA.
Vercel Inc. is based in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Vercel has implemented additional technical and organizational measures to ensure an adequate level of data protection.
Clerk, Inc. is based in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
As part of payment processing, Stripe may transfer personal data to Stripe, Inc. in the USA. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). Stripe is also certified under the EU-US Data Privacy Framework.
When the AI assistant is enabled, OpenRouter, Inc. may process personal data in the USA and forward it to the respective AI model providers. Data transfer is based on the EU Commission's standard contractual clauses (Art. 46 para. 2 lit. c GDPR). We use OpenRouter's Zero Data Retention option, so that — according to OpenRouter — processing takes place without permanent storage. Depending on the selected model provider, processing may also take place in further third countries outside the EU/EEA. For details, see the "AI Assistant (OpenRouter)" section.
Although your data is stored on EU servers, Supabase Pte. Ltd. is based in Singapore. Administrative access from Singapore may occur. Data transfer is based on standard contractual clauses (Art. 46 para. 2 lit. c GDPR).
If you contact us by email (kontakt@self-engine.com), we will store your email address and the content of your message for the purpose of processing your inquiry and in case of follow-up questions. We do not pass on this data without your consent. This data is deleted as soon as your inquiry has been conclusively processed and there are no legal retention obligations.
The processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest in the effective processing of inquiries addressed to us). If your inquiry is related to the performance of a contract, the legal basis is Art. 6 para. 1 lit. b GDPR.
When you use the feedback form in the application, we process your information in order to receive and handle bug reports, feature suggestions, and other feedback.
• the message you enter
• optionally provided reproduction steps
• an optionally provided email address for follow-up questions or the account email address you explicitly choose to use
• technical context to classify your feedback, in particular the current page within the application and the current application version
• a temporarily processed hashed identifier derived from your IP address or, if unavailable, from the user agent, used for abuse prevention and rate limiting
The processing is carried out to receive, review, and respond to feedback, to analyze and resolve reported issues, and to improve the stability and usability of our application.
The processing is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in the efficient handling of feedback, troubleshooting, and protecting the feedback form against abusive use. If you voluntarily provide a contact email address, we use it solely to assign your feedback and contact you if follow-up questions are necessary.
We use Resend, a service of Plus Five Five, Inc., USA, as a processor to send feedback messages. The content contained in your feedback is transmitted to Resend for this purpose. Processing in the USA cannot be ruled out. According to its own information, Resend provides appropriate safeguards for international data transfers, in particular through a Data Processing Addendum and applicable transfer mechanisms.
Please include only the information necessary for your feedback. Confidential or particularly sensitive information should not be submitted through the feedback form.
We generally store feedback content only for as long as necessary to process your feedback and any related follow-up. The identifier used temporarily for rate limiting is processed only for the duration of the relevant protection window in volatile server memory and is then discarded.
Unless a more specific storage period has been specified within this privacy policy, your personal data will remain with us until the purpose for data processing no longer applies. If you assert a legitimate request for deletion or revoke consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods); in the latter case, deletion will take place after these reasons cease to apply.
We use technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or complete loss, destruction or unauthorized access by third parties. Our security measures are continuously improved in line with technological developments.
• SSL/TLS encryption for all data transfers
• Passwords are stored exclusively in hashed form (by our authentication service Clerk)
• Regular updates of the systems and dependencies we use
• Access controls and authentication systems
• Regular backups via our infrastructure providers
• Data encryption at rest and in transit
The responsible party for data processing on this website is:
See imprint for contact details.
For questions about data protection or to exercise your rights, please contact: kontakt@self-engine.com
The competent supervisory authority for data protection matters is:
Promenade 18 91522 Ansbach Germany
Phone: +49 (0)981 180093-0
Email: poststelle@lda.bayern.de
You have the right to receive your data stored with us in a structured, commonly used and machine-readable format. Contact us at the email address provided above to request a copy of your data.
You can delete your user account and all associated data at any time. You can perform the deletion in the account settings of the application or send us an email. After deletion, your personal data will be removed from our production systems. Backup copies are overwritten as part of the regular backup cycles (see retention periods), unless there are legal retention obligations.
Deleted data is removed from production systems as promptly as technically and organizationally feasible. Backups and recovery media are overwritten or deleted in line with the applicable backup and retention cycles, unless legal retention obligations (for example under tax law) require longer storage.
We do not carry out automated decision-making including profiling within the meaning of Art. 22 GDPR. The optional AI assistant likewise does not make any solely automated decisions producing legal effects; it merely prepares actions and only carries them out after your explicit confirmation. Your data is not used for advertising purposes, not passed on to third parties for marketing purposes, and not used for tracking across different websites.
We reserve the right to adapt this privacy policy so that it always complies with current legal requirements or to implement changes to our services in the privacy policy, e.g., when introducing new services.
In the event of significant changes, we will inform you through a clear notice in the application. Your next visit will then be subject to the new privacy policy.
This privacy policy is currently valid and dated June 27, 2026.
As a data subject, you have the following rights:
You have the right to obtain confirmation as to whether personal data concerning you is being processed and, if so, to receive information about this personal data and further information in accordance with Art. 15 GDPR.
You have the right to request the correction of inaccurate personal data concerning you and, if necessary, the completion of incomplete personal data (Art. 16 GDPR).
You have the right to request the deletion of your personal data under the conditions of Art. 17 GDPR. This right includes, among other things, the right to have data deleted if the personal data is no longer necessary for the purposes for which it was collected.
You have the right to request the restriction of processing under the conditions of Art. 18 GDPR.
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format and to transmit this data to another controller (Art. 20 GDPR).
You have the right to object at any time to the processing of your personal data on the basis of Art. 6 para. 1 lit. e or f GDPR for reasons arising from your particular situation (Art. 21 GDPR).
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
If you have given your consent to the processing of your data, you can revoke this consent at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent until revocation is not affected by this.
The productivity engine built around you — time tracking, finances, calendar, and habits, all in one place.
© 2026 Self-Engine. All rights reserved.