Data Privacy

Data Collection Summary

Data Type Purpose Retention User Control
IP Address (Server Logs) Server operations 14 days None
Analytics page views (self-hosted Umami) Traffic analysis Indefinite Blockable; no cookie set
User Agent (Server Logs) Server operations 14 days None
Analytics events (card opens, report opens, searches, view switches) Feature-use analysis Indefinite Blockable; no cookie set
Welcome Acknowledgement Consent tracking Until cleared (or session-only) Full control
Bookmarks User convenience Until cleared Full control
Theme Preference User convenience Until cleared Full control
Language Preference User convenience Until cleared Full control
Read/Unread Status UI state Until cleared Full control

What This Site Does Not Do

This site does not:

Note: Usage analytics run on a self-hosted instance and record interaction events. See Usage Analytics below.

User-Submitted Data

When a report is submitted to flag incorrect incident data:

Data Collected

Server Logs

Apache Access Logs

Retention: 14 days (GDPR-compliant)

Purpose: Server operations, security monitoring, troubleshooting

Data Logged:

Automatic Deletion: Logs older than 14 days are automatically deleted via system log rotation.

Public data endpoint: The open data endpoint holds caller IP addresses in memory to enforce its rate limit. They are not written to disk and are discarded when the service restarts.

Usage Analytics

How It Is Collected

Usage analytics run on a self-hosted Umami instance at segelflug.io, operated by the same person as this site. No data reaches a commercial analytics provider. The instance sets no cookies and stores no raw IP address; an approximate country and a session identifier derived from a rotating hash are recorded instead. Analytics run regardless of the storage and maps preferences.

Events Recorded

What Is Not Recorded

How It Works

A page view is recorded when a page is opened. An event is recorded when one of the actions above occurs. Only two events carry an incident number — opening and sharing — and no event carries free text.

Note: Search terms never leave the browser, and the analytics data cannot show which incidents a given visitor bookmarked or flagged.

Legal Basis

Processing rests on the following:

Opting Out

The analytics instance honours the browser's Do Not Track setting, and its requests are blocked by any standard content blocker. The site functions normally either way. Requests concerning recorded data can be sent to the address in the imprint.

Data Retention

Analytics events are retained indefinitely.

Local Storage (Browser)

Opt-In

Local storage is disabled by default. It must be explicitly enabled via the welcome screen or in the settings menu.

What Gets Stored (When Enabled)

Note: All localStorage data remains client-side only. Nothing is transmitted to the server.

Session-Only Option (sessionStorage)

If "Continue (Session Only)" is chosen on the welcome screen, the acknowledgement is stored in sessionStorage instead of localStorage. This means:

User Control

No Cookies

No cookies are set.

Third-Party Services

Note: Google Maps is the only third-party service on this site, and it is loaded only with consent, given via the welcome screen or the settings menu. All other libraries are served from this site's own server.

Google Maps JavaScript API

Purpose: Interactive map view with incident markers

Data Transmitted:

When Loaded: Only when consent is given to use the map feature (via welcome screen or settings)

Privacy Policy: Google Privacy Policy

User Consent Choices

On the welcome screen and in the settings menu, two toggles control data handling:

These settings can be changed at any time via the settings menu (gear icon).

Last Updated: 2 September 2026