Privacy Policy
1. Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is the operator of this site — an individual in Germany running the project privately and non-commercially. The operator participates anonymously; postal contact and legal service are handled through a contact channel listed in the site footer.
There is no designated data protection officer; the project does not meet the thresholds of Art. 37 GDPR / § 38 BDSG.
2. Summary
This site has no user accounts, no analytics, no advertising, no tracking pixels, no third-party embeds and no profiling. It collects the minimum needed to run a shared canvas fairly and keep bots out. Concretely: an anonymous session cookie, your IP address held only in memory for rate-limiting, a Cloudflare bot check, and your text prompt — which is used to generate an image and then discarded, with only a cryptographic hash of it kept.
Because no analytics or marketing cookies are used, there is no cookie consent banner.
3. What is processed, why, and on what legal basis
3.1 Anonymous session cookie
When you first interact with the canvas, a cookie is set containing a randomly generated, signed session identifier. It contains no name, no email address, no account and no profile — it exists solely to enforce “one submission per session per round” and to show you the result of your own submission.
- Purpose: fairness of the round lottery, abuse prevention, delivering the function you requested.
- Legal basis: § 25(2) no. 2 TDDDG (TTDSG) — strictly necessary to provide the service you explicitly requested; therefore no consent is required. For the processing of the identifier itself: Art. 6(1)(f) GDPR (legitimate interest in a functioning, non-manipulable art experiment), and Art. 6(1)(b) GDPR where you actively participate.
- Storage duration: 4 days (the event window plus a short buffer).
3.2 IP address (transient, never stored)
Your IP address is visible to the server when your browser makes a request, as with any website. It is used only in volatile memory, for the duration of a round, to count submissions per network and block flooding. It is never written to a database, never written to a log file, and never persisted in any form; the in-memory counters are discarded each round.
- Purpose: abuse prevention, rate-limiting, protecting a fixed generation budget from being drained.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the security, integrity and availability of the service.
- Storage duration: none (transient, cleared per round).
Note that the hosting provider (see section 4) processes connection data, including IP addresses, independently at the network level for delivery and security purposes.
3.3 Cloudflare Turnstile (bot check)
Before a submission is accepted, a Cloudflare Turnstile challenge runs in your browser. Turnstile is a privacy-oriented alternative to a CAPTCHA: it evaluates signals from the browser environment (such as browser characteristics and interaction behaviour) to decide whether the request comes from a human, and issues a single-use token that the server verifies. It usually requires no interaction from you. According to Cloudflare, Turnstile does not use the data for advertising or cross-site tracking. Loading the widget transmits your IP address and browser data to Cloudflare.
- Purpose: blocking automated submissions and scripted abuse.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing abuse; § 25(2) no. 2 TDDDG for any strictly necessary access to your device.
- Recipient: Cloudflare, Inc. / Cloudflare Germany GmbH, as processor (see section 4).
3.4 Your prompt text
The text prompt you submit (maximum 200 characters) is processed to check it against automated moderation and, if your submission wins the round lottery, to generate an image.
- Handling: the prompt text is held in memory only for the duration of the round and the generation call, then discarded. What is stored persistently is only a SHA-256 hash of the prompt, used for deduplication, abuse detection and reconstructing the event log for the timelapse. The plain text is not stored in the database and is not published.
- Legal basis: Art. 6(1)(b) GDPR (carrying out the participation you initiated) and Art. 6(1)(f) GDPR (operating and documenting the experiment, preventing abuse).
- Please do not put personal data in your prompt. Prompts are free text sent to a third-party AI provider. Do not include your name, anyone else's name, contact details, or any information about identifiable people.
3.5 Shapes and generated images
The shape you draw and the image the AI generates inside it are public by design. They are painted onto a shared canvas that anyone can view, screenshot and share, they form part of a collective artwork, and they are recorded in an event log so that a timelapse film and other derivative works can be produced after the event. They are not linked to any name and cannot be traced back to you by visitors; a short, non-identifying fragment of the winning session identifier may be shown briefly in the result notification.
- Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR — realising the artwork you chose to contribute to, and the operator's interest in documenting and archiving the experiment.
3.6 What is not done
- No analytics or statistics tools (no Google Analytics, no self-hosted alternative).
- No advertising, no ad networks, no remarketing.
- No cross-site tracking, fingerprinting for tracking purposes, or profiling.
- No user accounts, registration, newsletter or email collection.
- No automated decision-making with legal effect within the meaning of Art. 22 GDPR (the round lottery is a random draw and has no legal or similarly significant effect).
- No sale or commercial sharing of personal data.
4. Recipients and processors
| Recipient | Role & data |
|---|---|
| Cloudflare (Workers, R2, D1, Turnstile) |
Hosting, edge delivery, object and database storage, and the bot check. Processes connection data (including IP address), the session cookie, stored images, prompt hashes and event-log entries. Acts as processor under Art. 28 GDPR on the basis of Cloudflare's data processing addendum. |
| OpenAI (image generation & moderation) |
Receives the prompt text together with a fixed system prompt and the shape mask, in order to run moderation and generate the image. Receives no cookie, no session identifier and no direct identifier of you. Established in the USA (OpenAI, L.P. / OpenAI Ireland Ltd. for EEA users). |
| Google (Gemini image models — testing only) |
May be used as an alternative image-generation provider during testing or as a fallback. Same data as above: prompt text and shape mask only. |
No other recipients. Data is disclosed to public authorities only where legally required.
5. Transfers to third countries
Processing may involve transfers to the United States, in particular to Cloudflare, Inc. and to the AI provider used for generation. These transfers are safeguarded by the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures (transport encryption, data minimisation), and — where the recipient is certified — by the EU–US Data Privacy Framework adequacy decision under Art. 45 GDPR.
Despite these safeguards, a residual risk remains that US authorities may access data. Because the only content transferred to the AI provider is your prompt text and the shape you drew, you can eliminate this risk for yourself simply by not including personal information in your prompt.
6. Retention
| Data | Retained |
|---|---|
| Session cookie / session identifier | 4 days |
| IP address | Not retained — in memory only, cleared each round |
| Prompt text | Not retained — in memory only, discarded after generation |
| Prompt hash (SHA-256) | Duration of the project and thereafter for archival and timelapse purposes |
| Generated images, shapes, event log | Duration of the project and thereafter for archival and timelapse purposes, as part of the artwork |
| Turnstile token hashes | Duration of the current round only |
Because the images, shapes and event log constitute the artwork itself and the source material for the timelapse film, they are kept indefinitely for archival and artistic purposes. They contain no personal identifiers.
7. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — confirmation of whether data about you is processed and a copy of it;
- Rectification (Art. 16) — correction of inaccurate data;
- Erasure (Art. 17) — deletion of your data;
- Restriction of processing (Art. 18);
- Data portability (Art. 20) — receipt of data you provided in a machine-readable format;
- Objection (Art. 21) — to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR;
- Withdrawal of consent (Art. 7(3)) — where processing exceptionally rests on consent, with effect for the future;
- Complaint to a supervisory authority (Art. 77) — in particular in the EU Member State of your residence, place of work or the place of the alleged infringement.
Requests can be sent via the contact channel listed in the site footer.
An important practical limitation: the project deliberately stores almost nothing that could identify you. There is no account, IP addresses are never persisted, and prompt text is discarded after generation. In most cases the operator is therefore unable to link any stored record to you as an individual and, under Art. 11 GDPR, is not obliged to obtain additional information solely in order to do so. You can delete the session cookie yourself at any time through your browser settings; it expires on its own after 4 days. If you want a specific generated area removed from the canvas, describe where and when it was drawn and the operator will consider removing it — note that the Terms of Use reserve the right to remove or overpaint any content in any case.
8. Security
All traffic is served exclusively over HTTPS. The session identifier is cryptographically signed to prevent tampering. Prompts are stored only as one-way hashes. The service runs on Cloudflare's edge platform with its standard technical and organisational protections.
9. Changes
This policy may be updated if the technical setup changes — for example if the image provider changes. The version published on this page is the current one.
10. Contact
For privacy questions, rights requests and data protection matters, please use the contact channel listed in the site footer.