Triaged

Privacy policy

Last updated: 28 September 2026

Controller and contact

Jenny Sever, Bertholdstraße 5, 75015 Bretten, Germany. Email: hi@tin.codes.

Visiting the website

When you access the website, we process your IP address, the time of access, the requested address and technical browser information to deliver and secure the service. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and reliable operation.

To prevent abuse of contract forms, we temporarily store a daily keyed hash derived from the connection IP address. The original IP is not stored in the form record. These hashes are removed after two days. This processing is based on our legitimate interest in preventing misuse (Article 6(1)(f) GDPR).

Hosting and backups

Datalix (Florian Kolb, Theodor-Heuss-Str. 1, 97230 Estenfeld, Germany) provides the server infrastructure on which Triaged runs, at CogentDC in Frankfurt am Main, Germany. The server processes requests and stores subscription references, usage counts and contract declarations. Encrypted database backups are retained for 14 days, including an off-server copy controlled by Jenny Sever. Datalix also provides server snapshots under the hosting agreement. See Datalix’s privacy notice for provider information.

Payments

Paddle processes checkout, billing details, payment methods, tax information, invoices and refunds as merchant of record under its own privacy notice. We send an account reference and receive transaction, customer and subscription identifiers, status and billing dates to provide paid access. The Free plan involves no payment processing. We do not receive your full payment-card details. Contract and statutory obligations are the bases for this processing (Art. 6(1)(b) and (c) GDPR).

Account and GitHub connection

Clerk, Inc. (United States) handles sign-in, sessions and account data. This includes your email address, your GitHub profile and the GitHub access tokens you authorize. We also store the names of linked repositories, webhook IDs, your project description, label settings and the latest processing status with Clerk. GitHub provides repository and issue data and receives the labels, and comments if enabled, that you ask us to apply.

This processing provides your account and the features you request, based on Art. 6(1)(b) GDPR. Security measures are additionally based on Art. 6(1)(f) GDPR. Provider information: Clerk and GitHub.

AI-assisted prioritization

To score an issue, your project description and the issue's title, body and labels are sent to OpenRouter, Inc. (United States) and to the model provider TypeSafe AI, Inc. (United States). This also applies to private repositories and manual previews. The application does not store full issue text in its usage database; it stores your account ID, the usage period (your billing period on the Pro plan, or the calendar month on the Free plan) and the number of scores.

For account holders on the Free and Pro plans this processing supports the requested service (Art. 6(1)(b) GDPR). Repository content can also concern other people; customers must have a lawful basis for submitting it. Where we process personal data on a business customer’s instructions, our data-processing agreement applies. Do not submit special-category data, secrets or material you are not authorised to share. Provider information: OpenRouter and TypeSafe.

Contract requests and contact

When you contact us, cancel or withdraw, we process the details identifying your contract, your declaration, your email address and the time of receipt. Declarations submitted through the forms are stored in our database. Email, including receipts, is sent through mailbox.org, a service of Heinlein Hosting GmbH in Germany.

The legal bases are Art. 6(1)(b) and (c) GDPR for performing the contract and meeting legal obligations, and Art. 6(1)(f) GDPR for keeping records and defending legal claims.

Cookies and local storage

Clerk uses strictly necessary session and security mechanisms. Your chosen appearance (light/dark) is stored locally. Both are required for features you request (Section 25(2) TDDDG).

Recipients and international transfers

The providers named above may process data outside the EU/EEA, in particular in the United States. Clerk’s data-processing addendum, OpenRouter’s data-processing agreement and TypeSafe’s addendum describe their processing and international-transfer arrangements, including standard contractual clauses where applicable. Contact hi@tin.codes for information about the safeguards applicable to your data. We do not promise EU-only AI processing or zero retention by all providers.

Retention

Account data and repository settings are kept while you use the service. You can unlink repositories in the dashboard and request deletion of your account at hi@tin.codes. Records of contracts and correspondence are kept as long as needed to process them, to meet statutory retention obligations, or to establish or defend legal claims.

Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction and data portability. You may object, on grounds relating to your particular situation, to processing based on legitimate interests. Contact: hi@tin.codes.

You can lodge a complaint with a data protection supervisory authority, in particular the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.