Privacy policy
This website is built to use as little personal data as possible. There is no account, no advertising, and no user profiles.
1. Controller
The controller under the General Data Protection Regulation (GDPR) is:
Maximilian Braun
Burgstallgasse 10
93309 Kelheim, Germany
Email: info@causefound.com
2. The essentials in short
- We do not use personal or cross-site tracking and do not run ads.
- There is no user account and no login.
- All fonts, images, and scripts are loaded from our own server.
- Only when you actively use the AI chat is your entered text passed to external AI providers (details in section 8).
3. Cookies and local browser storage
We do not use tracking, analytics, or advertising cookies and therefore do not need a consent banner. For features you explicitly use, your browser uses only its own local storage.
- On the chat page, a random session ID sits in sessionStorage and disappears when the browser session ends.
- Your objection to chat storage sits in localStorage until you clear browser data.
- An already submitted “Did this help?” answer is remembered per entry in localStorage. The browser also remembers whether you answered or skipped the optional question about the helpful or difficult check step.
These storages are required to provide the feature you requested (§ 25 (2) no. 2 TDDDG). They are not used for tracking and do not leave your device as such.
4. Hosting and server logs
This website is provided via Hostinger International Ltd. (61 Lordou Vironos str., 6023 Larnaca, Cyprus). Processing on our behalf is governed by Hostinger’s data processing addendum under Art. 28 GDPR. We have chosen Germany as the primary server location.
Hostinger uses sub-processors for some technical services. These can include providers for data centers, failover, network, and email infrastructure. Depending on the concrete service, processing outside the European Economic Area can occur. Where there is no adequacy decision of the European Commission for the respective third country, Hostinger relies on EU standard contractual clauses under Art. 46 (2) (c) GDPR. The current list of sub-processors and agreed safeguards is in the Hostinger data processing addendum.
When pages are requested, the server processes technically necessary connection data (in particular IP address, date and time, page requested, amount of data transferred, browser identifier). These data are required for page delivery, system security, and fault analysis. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in secure, stable operation). Access logs available to us in the hosting panel are viewable there for up to seven days. Provider-internal security and operations logs are processed by Hostinger only as long as needed for secure operation or legal duties, per the data processing addendum. We do not combine them with other data.
We create backups of the SQLite database that are automatically deleted after at most 14 days. They exist only for recovery after a technical outage and are not otherwise analyzed. Data deleted from the active database may therefore still exist in a protected backup until that retention period ends.
5. Reach and performance measurement
To detect technical problems and the usefulness of central features, your browser sends a few fixed measurement values to our server. These include a coarse page class such as home, search, or error-code page, plus events such as opening the chat, starting a chat request, a strong database match, or submitted feedback. On the first page view, the browser assigns the referrer locally to a fixed class. Possible classes are Google, Bing, ChatGPT, Perplexity, other AI services, direct visit, and other origin. Only this class is sent to our server. Full page addresses, search parameters, referrers, chat contents, device IDs, and durable user IDs are not transmitted. The browser remembers the fixed origin class only for the current session in sessionStorage.
For page views the server stores only daily counters per page class and origin class. For ten percent of page views the browser also captures the technical performance metrics LCP, INP, and CLS. Our server immediately bins these into fixed classes good, needs improvement, or poor. Only daily counters per page class, metric, and rating class are stored. No individual measurement records or profiles are created. Aggregated daily counters are retained so long-term technical regressions remain visible.
To protect the measurement endpoint against abuse, the server uses a separate daily rotating HMAC of the IP address. The IP address itself is not stored. The check value is technically separate from chat, contact, and feedback and is deleted after at most three days. The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is secure operation, technical quality control, and improving optionally used features.
6. Site search
Local instant search results run in your browser. For that, your browser loads a static search index from our server. If you search via the chat field or open a search page with a prefilled question, that input is processed as a chat message. Section 8 applies.
7. “Did this help?” feedback
When you submit feedback, we store the answer (yes/no), the affected error-code entry, and the date. If you answer the optional follow-up, we also store the number of the helpful or difficult check step. Solely to prevent abuse we also store a daily rotating, non-reversible HMAC of your IP address. The IP address itself is not stored. Because the check value rotates daily, feedback across multiple days cannot be linked. The check value is also technically separate from the values used for chat and the contact form. After at most three days we keep only the daily count in a statistic and delete the check value. Aggregated counts remain. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in honest, abuse-resistant statistics). We publish analyses only from at least 30 responses per entry. Long-term daily counts no longer contain personal data.
So the same question is not shown repeatedly, your browser remembers your answer locally (localStorage). This information does not leave your device and is required for the feature (§ 25 (2) no. 2 TDDDG). You can delete it at any time via browser data.
8. AI chat
On our website you can optionally use an AI chat for appliance diagnosis. When you send a message or open the search page with a prefilled question, your browser sends the message and the recent messages of the current conversation to our server. For a chat on a blog post or deepdive, the browser also sends only the identifier of the page. Our server loads the matching editorial page content. Depending on the conversation, the external AI service processes these inputs in separate steps.
- An abuse check assesses whether the message belongs to the intended appliance-diagnosis topic. Short answers to a previous follow-up question can skip this check.
- A triage step extracts from the conversation only the fields needed for search, such as brand, appliance type, model number, and error code or symptom.
- With a strong database match or a matching editorial page context, an answer model produces the chat reply. It receives the matching verified error-code entries or the editorial content.
- Without a strong database match, the answer model does not invent a diagnosis in chat. The chat links to matching pages and may offer the temporary problem-solving page described below.
For this processing our server forwards the conversation text needed, any page context, and matching verified entries to the following provider:
- OpenRouter, Inc. (USA) as a routing service for AI language models. Technical execution is by model-hosting providers that OpenRouter marks as zero-data-retention endpoints. The concrete selection depends on the model and can change. Processing can take place inside or outside the EU, especially in the USA.
Your IP address is not sent to these providers. All requests go through our server. On every model request we technically require zero data retention and forbid use of inputs and outputs for training or other data collection. OpenRouter still stores technical billing and operations metadata such as model, token count, runtime, and timestamp, but not conversation contents.
When no exact verified entry matches, the chat offers its own problem-solving page. With the chat reply your browser first receives only a signed page job and a safe base content. Only when you open the page does the browser send that job to our server. Our server has the structured page data produced via the AI service above. Your browser stores the result only for the current session in sessionStorage so you can reload the page. These page data are not stored as their own article on our server, are not open to search engines, and disappear when the browser session ends or site data is cleared. The general rules for storing the actual chat history continue to apply. The chat and the temporary problem-solving page visibly mark their automatically generated content as AI-generated.
By default we store chat histories for up to 30 days in the active database on our server in Germany. Stored are the messages you enter, the chat replies, a random session ID created in the browser, and technical timestamps. We do not store IP address, browser identifier, or a user account in the chat history. For backups the 14-day period from section 4 also applies.
The purpose of storage is to detect missing content, improve chat match quality, debug system errors, and spot abuse patterns. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in improving and securely operating the service). You can object to storage directly in the chat via “Do not store chat history”. The interface confirms the objection only after our server has deleted the previously stored history and blocked the session for further writes. After that we store neither further message text nor new coverage gaps for that browser. A temporary opt-out mark with the random session ID remains for up to 30 days so delayed or concurrent writes are also blocked.
Only when chat storage is enabled do we, for requests without a matching entry, store automatically detected appliance fields (brand, appliance type, model number, error code or symptom keyword) without message text, IP address, or session ID. These coverage gaps help us prioritize which guides to prepare next and are deleted after at most 365 days.
To prevent abuse we limit the number of requests per user via a daily rotating, non-reversible check value of the IP address. This value is stored only to enforce the per-minute and per-day limits and is deleted after at most three days. The IP address itself is not stored. Processing to answer your actively submitted chat message is based on Art. 6 (1) (f) GDPR (legitimate interest in providing the optionally used diagnosis feature). OpenRouter processes the content as a processor under a contract per Art. 28 GDPR. Transfers to third countries rely on EU standard contractual clauses under Art. 46 (2) (c) GDPR. Details are in the OpenRouter data processing agreement. Still, please do not enter personal or confidential data. For appliance diagnosis, symptom, error code, and model number are enough.
9. Contact form, error reports, and email
Through our forms (contact and “Report an error in our data”) you can send us messages. We process the form fields, your message, for error reports the affected page or error code, and optionally your name and email address for follow-up. The stored message contains neither your IP address nor its check value. To prevent abuse, only the separate rate-limit table uses a daily rotating, purpose-bound check value of your IP address. It is deleted after at most three days.
The message is stored on our server in Germany and deleted after at most 365 days. When mail sending is technically configured, we also send a copy to our mailbox. The email provider then also processes the message. Without mail configuration it remains only in our database. If you write us directly by email, your message does not land in the website database but only with the email provider and in our inbox. Mailbox copies are also deleted after at most 365 days. Depending on the seat and infrastructure of the email provider, processing outside the European Economic Area can occur. In that case transfer only happens on the basis of an adequacy decision or suitable safeguards under Art. 46 GDPR. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in handling voluntary requests and keeping content correct).
10. Voluntary nature of your data
Providing your data is neither legally nor contractually required. Technically necessary connection data are required so we can deliver the website to your browser. Without a chat message we cannot produce a chat reply. Without a message in the contact or error-report form we cannot handle the request. Name and email address in these forms are optional. Without an email address we cannot reply to you personally.
You can also use the AI chat after objecting to chat history storage. The text still has to be processed temporarily by our server and the AI providers named in section 8 to produce the requested answer. It is then not stored in our chat history.
11. Your rights
Where the legal conditions are met, you have the following rights regarding your personal data. Access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), and objection to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR). If processing is based on your consent, you can withdraw it at any time with effect for the future. Simply contact info@causefound.com.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). For us the competent authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach.
12. No automated decision-making
Automated decision-making with legal effect or profiling within the meaning of Art. 22 GDPR does not take place. The AI chat only gives non-binding repair hints.
13. Status and changes
Status of this policy: July 2026. When the site technology changes (for example new features or providers), we update this policy accordingly.