Data Collection Summary
| Data Type |
Purpose |
Retention |
User Control |
| IP Address (Server Logs) |
Server operations |
14 days |
None |
| Analytics page views (self-hosted Umami) |
Traffic analysis |
Indefinite |
Blockable; no cookie set |
| User Agent (Server Logs) |
Server operations |
14 days |
None |
| Analytics events (card opens, report opens, searches, view switches) |
Feature-use analysis |
Indefinite |
Blockable; no cookie set |
| Welcome Acknowledgement |
Consent tracking |
Until cleared (or session-only) |
Full control |
| Bookmarks |
User convenience |
Until cleared |
Full control |
| Theme Preference |
User convenience |
Until cleared |
Full control |
| Language Preference |
User convenience |
Until cleared |
Full control |
| Read/Unread Status |
UI state |
Until cleared |
Full control |
What This Site Does Not Do
This site does not:
- ✗ Use a commercial analytics provider (no Google Analytics, Adobe, Meta Pixel or similar)
- ✗ Set cookies (the analytics instance sets none)
- ✗ Track visitors across other websites
- ✗ Build advertising profiles or device fingerprints
- ✗ Share data with advertisers or third parties
- ✗ Implement cross-site tracking or remarketing
- ✗ Retain server-log IP addresses beyond 14 days
Note: Usage analytics run on a self-hosted instance and record interaction events. See Usage Analytics below.
User-Submitted Data
When a report is submitted to flag incorrect incident data:
Data Collected
- Incident ID (which incident was flagged)
- Description (explanation of the issue, max 500 characters)
- Language (interface language when submitted)
- Timestamp (automatic)
Server Logs
Apache Access Logs
Retention: 14 days (GDPR-compliant)
Purpose: Server operations, security monitoring, troubleshooting
Data Logged:
- IP addresses
- Request timestamps
- HTTP methods and paths
- Response status codes
- User agent strings
- Referrer headers
Automatic Deletion: Logs older than 14 days are automatically deleted via system log rotation.
Public data endpoint:
The open data endpoint holds caller IP addresses in memory to enforce its rate limit. They are not written to disk and are discarded when the service restarts.
Usage Analytics
How It Is Collected
Usage analytics run on a self-hosted Umami instance at segelflug.io, operated by the same person as this site. No data reaches a commercial analytics provider. The instance sets no cookies and stores no raw IP address; an approximate country and a session identifier derived from a rotating hash are recorded instead. Analytics run regardless of the storage and maps preferences.
Events Recorded
- Incident actions: Opening or sharing an incident. The incident number is recorded with the event. Bookmarking and flagging are counted without it.
- Interface events: Displaying the welcome screen, switching interface language, and switching between the list, map and statistics views.
- Searches: That a search was run. The text entered in the search field is not sent.
What Is Not Recorded
- ✗ Search terms, or any other free text entered on the site
- ✗ Raw IP addresses (used transiently to derive a country, then discarded)
- ✗ Cookies of any kind
- ✗ Which incidents a visitor bookmarked or flagged
- ✗ Names, e-mail addresses, accounts, or activity on other websites
How It Works
A page view is recorded when a page is opened. An event is recorded when one of the actions above occurs. Only two events carry an incident number — opening and sharing — and no event carries free text.
Note: Search terms never leave the browser, and the analytics data cannot show which incidents a given visitor bookmarked or flagged.
Legal Basis
Processing rests on the following:
- ✓ No cookie or comparable device storage is used, so no consent is required under ePrivacy rules
- ✓ No name, e-mail address or account is associated with any event
- ✓ Raw IP addresses are not stored by the analytics instance
- ✓ Legitimate interest in understanding how the site is used (Art. 6(1)(f) GDPR)
Opting Out
The analytics instance honours the browser's Do Not Track setting, and its requests are blocked by any standard content blocker. The site functions normally either way. Requests concerning recorded data can be sent to the address in the imprint.
Data Retention
Analytics events are retained indefinitely.
Local Storage (Browser)
Opt-In
Local storage is disabled by default. It must be explicitly enabled via the welcome screen or in the settings menu.
What Gets Stored (When Enabled)
- Welcome Acknowledgement: Consent/acknowledgement of the welcome screen (stored permanently when "Enable Storage & Continue" is clicked)
- Bookmarks: Incident IDs that have been bookmarked
- Theme Preference: Dark/light mode selection
- Language Preference: Interface language choice
- Read/Unread Status: Identifiers for read/unread visual indicators (stored locally, never transmitted)
Note: All localStorage data remains client-side only. Nothing is transmitted to the server.
Session-Only Option (sessionStorage)
If "Continue (Session Only)" is chosen on the welcome screen, the acknowledgement is stored in sessionStorage instead of localStorage. This means:
- The welcome screen will not appear again during the current browser session
- When the browser is closed, the session data is automatically cleared
- The welcome screen will appear again on the next visit
- No persistent storage is used
User Control
- Can be disabled at any time via settings
- All data is immediately purged when disabled
- Can be cleared via browser settings
No Cookies
No cookies are set.
Third-Party Services
Note: Google Maps is the only third-party service on this site, and it is loaded only with consent, given via the welcome screen or the settings menu. All other libraries are served from this site's own server.
Google Maps JavaScript API
Purpose: Interactive map view with incident markers
Data Transmitted:
- IP address (automatic with all web requests)
- User agent (automatic HTTP header)
- Map interactions (zoom, pan, clicks)
- Incident coordinates (for markers)
When Loaded: Only when consent is given to use the map feature (via welcome screen or settings)
Privacy Policy: Google Privacy Policy
User Consent Choices
On the welcome screen and in the settings menu, two toggles control data handling:
- Enable Local Storage: When enabled, preferences (bookmarks, theme, language, viewed incidents) are saved in localStorage and persist across sessions. When disabled, preferences are stored in sessionStorage and cleared when the browser closes.
- Enable Maps: When enabled, the map view loads Google Maps, which shares the IP address with Google. When disabled, no third-party service is loaded.
These settings can be changed at any time via the settings menu (gear icon).
Last Updated: 2 September 2026