Back to the homepage

Last updated: October 2026

Privacy policy

Protecting your personal data matters to us. This policy explains which personal data we process when you visit this website, use the web app and the FeedKeeper app, and use FeedKeeper Cloud, for what purpose and on what legal basis.

Contents
  1. 1Controller
  2. 2Visiting this website and the web app
  3. 3Hosting and delivery
  4. 4Data processing when you use FeedKeeper Cloud
  5. 5The FeedKeeper app (iOS, iPadOS, macOS)
  6. 6Retention and account deletion
  7. 7Your rights

1Controller

visualfusion, Owner: Christian Hamann, Biebinger Strasse 14, 83365 Nussdorf, Germany
Email: hello@feedkeeper.cloud

2Visiting this website and the web app

When you open feedkeeper.cloud we process the connection data that is technically required (see section 4 h). Before you sign in, the website sets no cookies and uses no advertising services, apart from a language cookie (fk_lang, valid for one year, readable by scripts, HTTPS only) that is only created when you pick a language yourself and makes sure the home page and the web app appear in your language (Section 25(2) no. 2 TDDDG); for anonymous visit counting see section 4 j). Fonts and images are loaded only from our own server.

After you sign in, a technically necessary session cookie (feedkeeper.sid; without “Stay signed in” only until you close the browser, with the box ticked valid for 30 days, sent over HTTPS only and not readable by scripts) keeps you signed in (Art. 6(1)(b) GDPR, Section 25(2) no. 2 TDDDG). When you sign in with Apple, the website sets one more technically necessary cookie (feedkeeper.apple) for a few minutes; it ties the sign-in to this browser and is deleted afterwards. The web app also stores settings, an offline copy of your articles and changes not yet synchronised in your browser's local storage. This data leaves your device only to synchronise with your account.

3Hosting and delivery

FeedKeeper Cloud runs on servers of the hosting provider Uberspace (uberspace.de) in Germany. A data processing agreement under Art. 28 GDPR is in place with the provider.

Traffic is delivered through the network of Cloudflare, Inc. (USA). Cloudflare processes your IP address to deliver the website and protect it from attacks (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework.

4Data processing when you use FeedKeeper Cloud

User account

When you register we store your email address, your name and a cryptographically hashed password to provide your account and manage access (Art. 6(1)(b) GDPR). Email confirmation and password recovery codes are stored only as hashes and expire after ten minutes. Registrations whose email address is never confirmed are deleted after seven days. So that the free trial is used only once, we store a hash of your email address (without a “+” suffix, computed with a secret key and not reversible). It is kept for 24 months even after the account is deleted and is only checked when an account starts the trial (Art. 6(1)(f) GDPR, protection against abuse). If you change your email address, we send a code to the new address and a notice to the old one. If you sign in with “Continue with Apple”, we receive from Apple a fixed identifier of your Apple account, your name (only the first time and only if you share it) and your email address or Apple’s relay address (Art. 6(1)(b) GDPR). We store the identifier to recognise you and an encrypted authorisation key from Apple, which we use to end the link when you delete your account. Apple processes your sign-in under its own privacy notices; we pass nothing to Apple beyond what the sign-in needs. An account you created with Apple has no password at first; you then confirm deleting it with a code by email.

If you set up passkeys, we store their public keys, identifiers, names you choose, creation times and last-use times. We do not receive private keys or biometric data. If you enable optional two-factor authentication, we store the authenticator secret encrypted and the single-use recovery codes only as hashes. These data secure your access (Art. 6(1)(b) GDPR) and are deleted when you remove the respective method or delete your account.

Feeds and synchronisation

We store your subscribed feeds, read states, folders, saved articles, notes and editions in our database to synchronise them between your devices. Our server fetches the feeds, article pages (for the full text) and images on your behalf; the operators of those sources see the address of our server, not yours.

Devices and access tokens

When you sign in to the FeedKeeper app we store the device name, platform (iOS, iPadOS or macOS) and app version and create a device token. The same applies to personal access tokens you create for MCP access. You can revoke tokens at any time in the settings. This data serves the administration and security of your account (Art. 6(1)(b) and (f) GDPR).

Payments

Payments on the web are processed by Stripe Payments Europe, Ltd. Stripe handles your bank and card details directly; we only store transaction IDs and your subscription status. If you subscribe through an in-app purchase on the Apple App Store, Apple processes the payment under its own terms; we only receive your subscription status. On the pages of Stripe (Checkout and customer portal) Stripe’s privacy notices apply; cookies may be set there that we do not control.

Transactional emails

We send confirmation and recovery codes through the email server of our hosting provider Uberspace.

AI curation

For AI Pro accounts, the titles, excerpts and content of candidate articles, the names of their sources and the section identifiers are selected and summarised automatically through the API of Anthropic PBC (USA) with the Claude model. Your email address, name and account identifier are not transmitted. The legal basis is Art. 6(1)(b) GDPR; appropriate safeguards under Art. 46 GDPR apply to the transfer to the USA.

MCP access

If you connect FeedKeeper to an AI assistant or agent, the content the assistant retrieves is sent to its provider and processed under that provider's terms. The decision is yours; we have no influence on it.

Server logs

To ensure stability and IT security, our hosting provider and Cloudflare temporarily store access data (IP address, timestamp, requested paths, user agent) in server logs (Art. 6(1)(f) GDPR). Our application itself keeps no access log; counters for abuse protection exist only in memory.

Getting in touch

If you write to us through the contact form or by email to hello@feedkeeper.cloud, we process your name, email address, message, the chosen topic, the language and the page you write from in order to reply (Art. 6(1)(b) or (f) GDPR). The message is delivered to our mailbox through the mail server of our hosting provider Uberspace; to fend off abuse we add your IP address. The form is protected against spam by a hidden field, a timing check and a rate limit and embeds no external services. We do not store messages in the application's database. They stay in our mailbox until your request is settled and no statutory retention obligation applies.

Visit counting

On the pages of this website (home page, legal notice, privacy policy), but not in the web app after sign-in and not in the FeedKeeper app, we count visits with Umami. The software is self-hosted on our server analytics.visualfusion.de at Uberspace in Germany. It processes the page viewed, the referring page, browser, operating system, device type, screen size, language and a rough location (country, region, derived from the IP address). The IP address itself is not stored. Returning visitors are recognised only by an identifier that cannot be traced back to you without additional knowledge (a hash). No cookies are set, nothing is stored on your device, no data is passed on to third parties and no cross-site profiles are built. We respect your browser's Do Not Track setting. The legal basis is our legitimate interest in improving the website (Art. 6(1)(f) GDPR).

Cancellation

If you cancel through the “Cancel subscription” page, we process your name, email address, the type of cancellation, the time we received it and the result (which subscription ends on which date) to carry the cancellation out, to confirm it to you by email and to be able to prove its receipt (Art. 6(1)(b) and (c) GDPR, § 312k German Civil Code). The confirmation reaches you through the mail server of our host Uberspace, with a copy to our mailbox. We keep the record in the application’s database as long as claims from the contract can be made, at most until the end of the third year after the year of the contract’s end. Section 4 d applies to the execution at Stripe.

5The FeedKeeper app (iOS, iPadOS, macOS)

The app stores accounts, cached articles and images, notes and changes not yet synchronised on your device. Credentials are kept in the Keychain. The app contains no third-party advertising or analytics software, no tracking, and collects no data for us beyond what is described in section 4.

The app communicates with feedkeeper.cloud or with the server you connect yourself (your own FeedKeeper server, Miniflux, FreshRSS or Fever). In that case that server processes your data, not us. For accounts that do not run on FeedKeeper Cloud, the app may load article images directly from their servers, which then see your IP address; you can turn images off in the settings. You buy subscriptions through Apple (see section 4 d). Removing an account in the app deletes its local data, not your cloud account; you delete that as described in section 6.

6Retention and account deletion

Your data is kept for as long as your account exists. You can delete your account in the account settings of the web app or in the app itself. This permanently removes your account and all associated data, ends a running Stripe subscription and deletes your customer record at Stripe. Statutory retention obligations, for example for payment and invoice data, remain unaffected. Backups still contain deleted data until they are replaced by newer backups. You end an Apple subscription in your Apple ID settings.

7Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw any consent you gave at any time. You can also lodge a complaint with a data protection supervisory authority, for example the Bavarian State Office for Data Protection Supervision. Write to us at hello@feedkeeper.cloud.

Welcome back.

Sign in with your FeedKeeper Cloud account.

At least 10 characters.