Privacy Policy

patchletter is built to be deliberately data-minimal: the only required datum is an email address. No tracking pixels in emails, no advertising cookies, no consent banner. Application, database and object storage run on our own server in Germany.

1. Controller

patchletter UG (haftungsbeschränkt) i. G., represented by its Managing Director Kolja Sagorski, Meisterweg 16, 45896 Gelsenkirchen, Germany hello@patchletter.com

2. What data we process — and why

a) Account & sign-in (magic link)

To sign you in, we store your email address and the time of confirmation (double-opt-in record). There is no password. The sign-in link is valid for 30 minutes; the confirmation link for a new registration is valid for 24 hours. For the logged-in session we set one technically necessary cookie. Requesting a sign-in link adds a second, equally necessary one: it holds a random value with no personal reference and makes sure the code from the sign-in email only works in the browser where you started signing in; it expires after one hour. Both are set only once you sign in. On top of that there is a cookie for your chosen language — that one already on your first visit, and again on every language switch. There are no advertising or tracking cookies. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

b) Update emails & newsletter

As a core service, patchletter sends product-related update/security notifications as well as a general patchletter newsletter (service and security news, product announcements). We store your subscribed products and delivery settings as well as a log of the emails sent (subject, referenced releases where applicable, provider ID) for 12 months. Our emails contain no open trackers. Every email includes a one-click unsubscribe link; unsubscribing also stops the newsletter. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). You can opt out of the newsletter at any time in the dashboard or via the unsubscribe link.

c) Deliverability events

Our mail service reports non-delivery (bounce) and complaints to us. We store these events for 24 months and suppress affected addresses from sending. Legal basis: legitimate interest in deliverability and abuse prevention (Art. 6(1)(f) GDPR).

d) Server logs

When the website is accessed, technically necessary logs are created (IP address, time, requested URL, user agent). They serve operation and attack detection and are deleted after 14 days. Legal basis: Art. 6(1)(f) GDPR.

e) Bot protection (ALTCHA)

Registration and sign-in use a self-hosted proof-of-work check (ALTCHA) so automated requests are harder. The check runs only on our server in Germany; no data is sent to a third party and no cookies are set for it. Legal basis: Art. 6(1)(f) GDPR (abuse prevention).

f) Analytics (Umami)

We use Umami for analytics. It runs on our own server in Germany; no third party is involved. Umami sets no cookies and stores nothing on your device. Per page view we record: the page address (without query parameters), the referrer, browser, operating system, screen resolution, browser language and a location derived from your IP address down to city level. That lookup happens locally on our server; the IP address itself is not stored. From these details Umami forms a pseudonymous session identifier. In addition we count clicks on individual elements we have named ourselves (for example the subscribe button) — only the name we assigned to the element is stored, plus, in two cases, one further detail we defined ourselves (the category chosen, the number of products selected). No coordinates, no screen recording and no text you see or enter. We do not combine any of this with your account, do not link it across devices and do not pass it on. Legal basis: Art. 6(1)(f) GDPR (understanding how our service is used). We do not show a consent banner for it; we consider that justifiable because the measurement works without cookies, without third parties and without profiling, and is limited to the details listed above.

g) Tool suggestions

When you suggest a tool, we store the name/URL/note and, optionally, your email address (only to notify you if it is added).

h) Error monitoring

To find faults we run Bugsink, a self-hosted error monitor on the same server. If an error occurs, technical context is recorded (URL, browser, error message and, where applicable, the ID of a logged-in account). No third party is involved. Legal basis: Art. 6(1)(f) GDPR.

i) Contacting us by email

Email you send to an @patchletter.com address is received and stored for us by our mail provider mailbox.org (Heinlein Hosting GmbH) in Berlin, Germany. We process the content solely to handle your request. Legal basis: Art. 6(1)(b) and (f) GDPR.

Two addresses are additionally processed by machine and are not read by a person. Reports that receiving mail servers send to dmarc@patchletter.com about our own domains (DMARC and SMTP-TLS reports) are forwarded to our server in Germany and evaluated automatically. We store the reporting operator, the reporting period, the published policy and, per sending mail server, its IP address, the number of messages, how they were handled and the DKIM/SPF result. We do not store the report file itself, nor message content, recipient addresses, subject or sender of the report email. Purpose: to detect whether forged mail is being sent in our name and to decide on a stricter DMARC policy. Legal basis: Art. 6(1)(f) GDPR — the security of our email delivery. An IP address here identifies a sending mail server, not a visitor; we nevertheless treat it as personal data as a precaution.

The second such address is unsubscribe@patchletter.com. Every email we send carries it in its List-Unsubscribe header (RFC 8058), so that one click in your mail program is enough to unsubscribe. Mail arriving there is matched against the unsubscribe code it carries and processed automatically; nothing else is evaluated. Legal basis: Art. 6(1)(c) GDPR in conjunction with your right to object.

j) Webhooks (optional)

You can optionally set up delivery targets in the dashboard so update notifications reach your own endpoint or a chat channel instead of only your inbox. For each target we store the name you choose, the target URL, a secret for the signature, the format and the delivery status; for each delivery we store which release it concerned, whether it worked, the HTTP status code and, if applicable, the error message. The messages themselves contain only product data — product name, version, release channel, links and time of detection. No email address and no other account data is transmitted.

Where the data goes is your decision: the target is the address you enter. If you point it at a service run by someone else — a chat provider, for example — that provider receives the message and processes it under its own terms; where that provider is located and what it does with the data is outside our control. We do not use targets for any purpose of our own. Legal basis: performance of a contract (Art. 6(1)(b) GDPR), since the delivery is the feature you asked for. Delete a target in the dashboard at any time; nothing is sent to it afterwards.

3. Recipients & processors

Analytics (Umami), error monitoring (Bugsink) and bot protection (ALTCHA) we run ourselves on the same server in Germany — no third party is involved there.

One more recipient exists only if you create it yourself: a webhook target you set up (see 2j). We do not choose it, and it is not a processor acting for us — you instruct us to deliver there. The messages contain product data only, no account data.

A transfer to the USA therefore occurs in one case only: DNS resolution (Cloudflare). It is based on Standard Contractual Clauses (Art. 46 GDPR) or, where the provider is certified, the EU-US Data Privacy Framework. Email you send to us stays in Germany since 21 August 2026 — it is received and read at mailbox.org and no longer forwarded abroad.

4. Retention & deletion

5. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). To exercise them, contact hello@patchletter.com. Right to complain: the competent supervisory authority is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Germany).

Last updated: 22 August 2026