Privacy Policy
Last updated 2026-06-24
This policy explains what personal data Benjamin Hellmich(“getAdvantage”, “we”) processes when you use getadvantage.app, why, the legal basis for each use, and the rights you have under the EU General Data Protection Regulation (GDPR). We aim to be precise and honest: getAdvantage measures how AI reads a website at the moment of a scan — the resulting scores are measurements, never guarantees.
Who is responsible
The data controller is Benjamin Hellmich. Contact for any data request: legal@getadvantage.app. The full Impressum (§ 5 DDG) is at /impressum.
What we collect and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Account email & bcrypt-hashed password | Create, secure and operate your account | Contract — Art. 6(1)(b) |
| Email submitted to the report unlock (“email gate”) | Unlock your full report and, where you ask, email it to you | Consent — Art. 6(1)(a) |
| Feedback you submit in the in-app feedback widget (your message + an optional email) | Improve the product and, where you leave an email, reply to you | Consent — Art. 6(1)(a) |
| Sites/URLs you scan and the resulting scores | Provide the scan, history and benchmark features (facts observed on public pages) | Contract — Art. 6(1)(b) |
| Billing data (handled by Stripe — your card never touches our servers) | Process subscriptions and invoices | Contract — Art. 6(1)(b) |
| First-party, server-side funnel events (no cookie, no device storage, no PII in the event) | Understand and improve the product funnel | Legitimate interest — Art. 6(1)(f) (improving and securing the Service) |
The session cookie aboard_session (one cookie; a signed JWT carrying your account id + email) | Keep you logged in — strictly necessary, no tracking or ad cookies | Contract — Art. 6(1)(b) |
| Your client IP address (processed transiently in memory, never written to storage) | Rate-limiting and abuse/fraud prevention | Legitimate interest — Art. 6(1)(f) (preventing abuse and protecting the Service) |
We do not sell your data, run advertising trackers, or build cross-site profiles. We confirmed by code audit that the site loads no third-party trackers of any kind. Scan results contain only publicly-observable facts about the pages you submit.
Cookies and consent
We set exactly one cookie — aboard_session — which is strictly necessary to keep you logged in (httpOnly, Secure in production,SameSite=Lax, 30-day lifetime). Our analytics are cookieless and server-side: we measure funnel events on our own servers without storing or reading any information on your device. Because we store no non-essential information on your device and access none, the device-access consent requirement of § 25 TDDDG is not triggered, so no cookie consent banner is required.
Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The AI-readability score is a measurement of how AI assistants may read a public page at scan time — it has no legal or similarly significant effect on any data subject.
Is providing data mandatory?
Providing your email address is a contractual requirement to create an account: without it we cannot establish the account or provide the Service. All other processing is either necessary to deliver a feature you request or based on your consent, which you can withdraw at any time.
Sub-processors
We share data only with the processors required to run the Service. Each acts under a GDPR Art. 28 data-processing agreement. The current list is also maintained at /subprocessors, and our processor terms (DPA) are at /dpa.
| Processor | Purpose | Region | Transfer safeguard |
|---|---|---|---|
| Vercel Inc. | Application hosting & content delivery | USA (EU region pinned: fra1) | EU Standard Contractual Clauses / EU-US Data Privacy Framework where certified |
| Neon Inc. | Managed PostgreSQL database (accounts, scans, billing mirror) | EU (Frankfurt) | EU — no third-country transfer |
| Stripe Payments Europe, Ltd. (with Stripe, Inc., USA) | Subscription billing & payment processing | EU / USA | EU Standard Contractual Clauses / EU-US Data Privacy Framework |
| OpenAI, L.L.C. | AI perception & copy generation on scanned content (API; not used to train models) | USA | EU Standard Contractual Clauses |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | USA | EU Standard Contractual Clauses |
| Cloudflare, Inc. | Authoritative DNS and inbound email routing / forwarding for getadvantage.app and plusxplus.de | USA (global anycast edge) | EU Standard Contractual Clauses / EU-US Data Privacy Framework |
| Advantage Studio (Mission Control) | Internal operations console operated by the platform operator — receives a captured lead email + domain for founder operations | EU / USA | Intra-operator; EU Standard Contractual Clauses where applicable |
When you submit an email through the report unlock, that lead email and the scanned domain are also forwarded to our internal operations console (Advantage Studio / Mission Control), operated by the getAdvantage operator, so we can follow up on founder enquiries. No other personal data is sent there.
International transfers
Our database (Neon, Frankfurt) keeps account, scan and billing-mirror data in the EU. Some processors are based in the United States — in particular Vercel (hosting, EU region pinned), OpenAI(AI perception & copy generation; the API is not used to train models), Resend (transactional email) and Stripe’s US entity. Where data is transferred outside the EU/EEA it is protected by EU Standard Contractual Clauses (2021/914) and, where a provider is certified, the EU-US Data Privacy Framework. A copy of the relevant safeguards is available on request.
Retention
We keep account and scan data while your account is active. After you close your account we delete account and scan data within about 30 days, except where a longer period is legally required. Billing records are retained for the statutory period under German tax and commercial law (§ 147 AO / § 257 HGB — generally 8–10 years). Gate-capture (lead) emails are kept until you ask us to remove them. The client IP used for rate-limiting exists only transiently in memory (a window of minutes) and is never persisted.
Security
We apply appropriate technical and organisational measures under Art. 32 GDPR: bcrypt (cost-12) password hashing; signed JWT sessions in httpOnly+Secure cookies; strict tenant isolation (every database query is scoped to your account id); TLS in transit; a Postgres database hosted in the EU (Neon, Frankfurt); SSRF-guarded outbound fetches that re-validate DNS/IP and block private ranges; a global Content-Security-Policy, HSTS and security headers; per-IP rate limiting; secrets kept only in environment variables (never in the repository); and signature verification on billing webhooks. The same measures are summarised in our DPA.
Your rights
You have the right to access, rectify, export (data portability), restrict, object to and erase your personal data, and to withdraw any consent at any time without affecting prior processing. To exercise any of these, email us. You may also lodge a complaint with your competent data-protection supervisory authority.
Children
getAdvantage is a tool for builders and is not directed to children under 16. We do not knowingly collect personal data from children.
Withdrawal & consumer rights
If you are a consumer, you may have a statutory right of withdrawal for paid subscriptions. How that right works, and the official model withdrawal form, are set out at /widerruf.
Changes
We may update this policy as the Service evolves; the “last updated” date above always reflects the current version.