Privacy Policy
Last updated: April 2026
1. Data Controller
1PrimeSystems - Tom Silas Helmke
Tom Silas Helmke
c/o Online-Impressum #4746
Europaring 90, 53757 Sankt Augustin
Email: tshfm78@gmail.com
2. Supervisory Authority
Data Protection Authority of North Rhine-Westphalia (LDI NRW)
Postfach 20 04 44, 40102 Düsseldorf
https://www.ldi.nrw.de
3. Data Protection Officer
A data protection officer is not required to be appointed for this service under Art. 37 GDPR in conjunction with § 38 BDSG (solo operation, no large-scale processing of personal data). Please direct data protection inquiries to the controller at the address above.
4. Principle: Data Minimization and Local Processing
MetaDataGone was built according to "Privacy by Design." File contents and metadata are processed exclusively locally in your browser. Only a few technically required connections (e.g. license verification, map tiles) involve external providers.
a) No File Uploads
All files you select are processed exclusively locally in your browser (client-side). At no point are files, file contents, or embedded metadata transmitted to our servers or third-party servers.
b) No Tracking, No Analytics
We do not use analytics tools (no Google Analytics, no Matomo, no Plausible, no other tracking) and do not create user profiles.
c) No User Accounts
MetaDataGone does not require registration or login. No email addresses, usernames, or passwords are stored.
5. Legal Bases and Purposes of Processing
Below you will find, for each processing activity, the purpose, the data processed, the legal basis under Art. 6 GDPR, the recipients, and the retention period.
5.1 License Verification (/api/verify-license)
- Purpose:
- Verification of the Premium license key to unlock paid features.
- Data:
- License key (entered by user), User-Agent and Accept-Language headers for rate-limit bucketing, proof-of-work challenge response.
- Legal basis:
- Art. 6(1)(b) GDPR (performance of a contract — delivery of purchased Premium functions).
- Recipients:
- Sold through Link, LLC (f/k/a Lemon Squeezy LLC), USA. See section 8 (International Data Transfers).
- Retention:
- License keys are not stored server-side. Rate-limit data is kept in the memory of the serverless function only and is cleared when the instance terminates (typically within minutes).
5.2 OpenStreetMap Tiles and Nominatim Geocoding
- Purpose:
- Displaying GPS coordinates extracted from metadata on a map; optional location search when editing GPS.
- Data:
- Your IP address (to the OSM tile servers for tile delivery); the search term entered by the user (only when actively searching). GPS coordinates from your file are NOT transmitted.
- Legal basis:
- Art. 6(1)(f) GDPR (legitimate interest — visualising the detected GPS data as a core function of a privacy tool).
- Recipients:
- OpenStreetMap Foundation (United Kingdom). An EU adequacy decision for the UK is in place (Art. 45 GDPR).
- Trigger:
- The map is only loaded when GPS coordinates are found in your file. Geocoding only runs on explicit input.
5.3 Hosting (Vercel)
- Purpose:
- Delivery and technical operation of the website; abuse protection.
- Data:
- IP address, browser type, referrer, HTTP request timestamp, requested URL.
- Legal basis:
- Art. 6(1)(f) GDPR (legitimate interest in secure, performant delivery of the website).
- Recipients:
- Vercel Inc., USA (server region Frankfurt, Germany). See section 8.
- Retention:
- Vercel retains access and function logs per standard retention of the booked tier (typically 1–7 days). Details at vercel.com/docs/observability/logs.
5.4 Payment Processing (LemonSqueezy Checkout)
- Purpose:
- Processing Premium purchases and delivering the license key.
- Data:
- Name, email address, payment information, billing address (all inputs happen directly on the external LemonSqueezy checkout page, not on our site).
- Legal basis:
- Art. 6(1)(b) GDPR (performance of a contract — purchase and license delivery).
- Recipients:
- Sold through Link, LLC (f/k/a Lemon Squeezy LLC), USA — as merchant of record and independent controller (not processor). See section 8.
- Retention:
- Transaction data is retained by LemonSqueezy according to their commercial and tax retention obligations (typically 10 years). We do not store payment data ourselves.
LemonSqueezy Privacy: https://www.lemonsqueezy.com/privacy
5.5 Donations (Ko-fi, voluntary)
- Purpose:
- Accepting voluntary support.
- Data:
- Collected directly by Ko-fi. We do not receive payment data.
- Legal basis:
- Art. 6(1)(a) GDPR (consent through voluntary click on the Ko-fi link).
- Recipients:
- Ko-fi Labs Ltd. (United Kingdom). An EU-UK adequacy decision is in place.
Ko-fi Privacy: https://ko-fi.com/privacy
6. Cookies and Local Storage
We only use strictly necessary cookies and local storage values. Under § 25(2) No. 2 TTDSG these do not require consent. No tracking, analytics, or marketing cookies are used.
6.1 Cookie: NEXT_LOCALE
- Purpose:
- Store the user-selected language (German or English) so the site opens in the preferred language on subsequent visits.
- Contents:
de/en- Type:
- First-party, functional, SameSite=Lax
- Lifetime:
- 1 year (or until manually removed)
- Legal basis:
- § 25(2) No. 2 TTDSG (strictly necessary) in conjunction with Art. 6(1)(f) GDPR (legitimate interest).
The cookie is set automatically on your first visit and when you change the language. You may delete it at any time via your browser settings. Without the cookie, your language selection will not persist across sessions.
6.2 Local Storage / SessionStorage
The following values are stored exclusively on your device and never transmitted to our or third-party servers:
mdg_license— Premium license status and tier. Lifetime: until license expiry (3 years) or manual deletion.mdg_theme— Light/dark theme. Lifetime: until manually removed.mdg_backoff— Temporary cool-down after failed entries. Session storage — cleared when the tab closes.mdg_free_strip_count— Counter of free removals in the current browser tab. Session storage.
Legal basis: § 25(2) No. 2 TTDSG in conjunction with Art. 6(1)(f) GDPR.
6.3 External Cookies During Checkout
When switching to the Premium checkout, you are redirected to the external LemonSqueezy page. Further cookies may be set there. See LemonSqueezy Privacy (https://www.lemonsqueezy.com/privacy).
7. Data Processing Agreements
Data Processing Agreements (DPAs) under Art. 28 GDPR have been concluded with all processors handling personal data on our behalf (in particular Vercel). Lemon Squeezy acts as merchant of record and therefore as independent controller; the relationship is governed by their respective terms.
8. International Data Transfers
Some of our service providers process data in the United States. We rely on the following legal bases for those transfers:
8.1 Vercel Inc. (Hosting, USA)
Vercel Inc. is certified under the EU-US Data Privacy Framework (EU-US DPF). The European Commission adopted an adequacy decision for this framework on 10 July 2023. We transfer personal data to Vercel on the basis of this adequacy decision pursuant to Art. 45 GDPR.
Current certification: dataprivacyframework.gov/s/participant-search
8.2 Sold through Link, LLC (LemonSqueezy) (Payment Processing, USA)
Sold through Link, LLC — operating under the name "Lemon Squeezy" — processes payment data in the United States. We could not confirm a public EU-US Data Privacy Framework certification as of the date of this policy. Transfers therefore rely on the European Commission's Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR, as incorporated in the LemonSqueezy Data Processing Agreement.
LemonSqueezy DPA: lemonsqueezy.com/dpa
8.3 Residual Risks for US Transfers
Despite the adequacy decision or SCCs, residual risks remain: US authorities may under certain laws (notably the CLOUD Act and FISA 702) be able to access personal data; EU data subjects have limited legal remedies compared to EU residents. We minimise these risks through exclusively client-side file processing, TLS-encrypted connections, and strictly minimising the data transmitted to US providers.
9. Retention Periods at a Glance
| Data category | Retention |
|---|---|
| File contents and metadata | Browser RAM only; cleared when the tab closes |
| API rate-limit bucket | Max. 15 min in serverless function memory |
| Vercel logs | Typically 1–7 days (Vercel default) |
| License key (browser) | Until license expiry (3 years) or manual deletion |
| NEXT_LOCALE | 1 year |
| LemonSqueezy transaction data | Commercial/tax law, typically 10 years |
10. Fonts and Local Assets
All fonts (Inter, JetBrains Mono) and static assets are bundled with the site. NO external font services such as Google Fonts are called.
11. Your Rights
Under Art. 15–21 GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability and objection. We generally respond to requests within one month.
Contact: tshfm78@gmail.com
You have the right to lodge a complaint with the competent supervisory authority (LDI NRW, see section 2) if you believe that the processing of your personal data violates the GDPR.
12. Technical Notes and Limitations
- Steganographic watermarks or hidden pixel-level payloads are not reliably detected or removed by standard browser-based methods.
- Filenames and path information are not embedded file metadata and are not changed by the cleanup process.
- Animated GIF files are exported as a static image during cleanup; animation frames are lost.
- HEIC files (iPhone) are converted to a browser-compatible JPEG format before metadata is removed and the result is verified.
13. Changes to this Privacy Policy
We reserve the right to update this privacy policy as needed. The current version is always available on this page; the date at the top is updated whenever changes are made.