Privacy policy (Datenschutzerklärung)
Short version: this site loads nothing from third-party servers. We count page views with a cookieless audience measurement (Umami) that we run on our own server: no cookies, no data passed on, your IP address is processed only briefly and not stored. The only cookie is the session cookie of your account, set when you sign in. We process personal data when you write to us, request a free catchment snapshot, sign in, or book a Health Check or monitoring. Details below.
1. Controller
Portalix UG (haftungsbeschränkt)
Thalkirchner Str. 103, 81371 München, Germany
Managing director: Stefan Böck
E-mail: hello@anycast.dev
We are not required to appoint a data protection officer.
2. Hosting, server logs and audience measurement
This website and our measurement backend are hosted on servers in Frankfurt, Germany, operated by noez GmbH (noez.de) as our hosting provider (processor under Art. 28 GDPR). The web server keeps no access log. Only when a request causes an error does the web server write an entry to its error log; this entry contains your IP address. Error logs are rotated daily and deleted after 14 days. We use these entries to keep the site secure and to diagnose faults. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in a secure and functioning website).
The site is delivered with HTTPS only. No content is loaded from third-party servers: fonts are system fonts, there are no embedded scripts from other providers and no tracking pixels. Page views are counted by a script served from this domain, see the next paragraph. The only cookie is the account session cookie described in section 4; it is strictly necessary for the sign-in and needs no consent.
Audience measurement. We measure the use of this website with Umami, an open-source software that we run on our own server. The counter script is served from this domain (/_s/script.js) and reports page views back to this domain (/_s/api/send), from where they are passed to our Umami instance; no third-party service is involved. No cookies are set and no data is stored on your device. When you visit a page, your IP address is processed only briefly in order to determine country, region and city and to assign page views to a session. The IP address is not stored. We record the page visited, the page title, the referring page, browser, operating system, device type, screen size, browser language and approximate location. We do not record what you enter in forms, such as the zone or e-mail address of a snapshot request. Your account pages and snapshot reports do not contain the counter. This does not allow us to identify you. The data is not passed on to third parties. Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in improving our website).
3. Contact by e-mail
If you e-mail us, we process your e-mail address, the content of your message and any data you include in order to handle your request. Legal basis: Art. 6 (1) (b) GDPR where the request concerns a contract or pre-contractual steps, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries). We keep correspondence as long as required to handle the matter and to meet statutory retention obligations.
4. Free catchment snapshot and your account
Requesting a snapshot. When you request a free catchment snapshot we store the zone you entered, your e-mail address, the time of the request and your IP address (the IP only to limit the number of requests per visitor). We look up the public nameservers of the zone and measure them from RIPE Atlas; the report contains nameserver names and addresses and per-node measurement data, no personal data. We e-mail you the link to the report. Legal basis: Art. 6 (1) (b) GDPR (the snapshot is a service you asked for, and a pre-contractual step towards the paid services). IP addresses are deleted after 30 days. Zone, e-mail and report are kept while you have an account with us, and deleted on request.
Report links. A report is reachable by anyone who knows its link; the link is random and not listed anywhere. Do not forward it if you do not want others to see it. Measurements are carried out on the RIPE Atlas platform, where measurement results are public by design (the measurement IDs are printed in the report); they contain nameserver addresses and probe data, not your e-mail address.
Signing in. There is no password. When you sign in we send a one-time link to your e-mail address; it is valid for 20 minutes. After signing in we set a session cookie (anycast_session, HttpOnly, Secure, valid 30 days) so that you stay signed in. In your account you see the snapshots requested with your address and your subscriptions. Sign-in links, sessions and the IP address recorded with them are deleted automatically (links after one day, sessions when they expire, IP addresses after 30 days). Legal basis: Art. 6 (1) (b) GDPR.
E-mail delivery. Sign-in links, report links and service e-mails are sent through Mailgun (Sinch Mailgun, EU region, servers in the EU) as our processor under Art. 28 GDPR. Mailgun receives your e-mail address and the message content for delivery only.
Operational notifications. When a snapshot finishes or an order arrives, our operator receives an internal notification with the zone and a report link; it does not contain your e-mail address.
5. Booking a Health Check or monitoring (payment)
Bookings and subscriptions are handled via a payment page provided by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. When you pay, Stripe processes the data required for the payment (name, e-mail address, billing address, VAT ID if given, payment details) and the zone you enter on the payment page. Stripe acts as an independent controller for payment processing; its privacy policy is available at stripe.com/privacy. We receive confirmation of the payment together with your name, e-mail, billing address and the zone, store the subscription status in your account and use these data to deliver the service and for our accounting. Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (c) GDPR (statutory retention of accounting records, 10 years under § 147 AO / § 257 HGB). Stripe may transfer data to the United States; such transfers are covered by the EU standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
6. Measurement data
When we carry out a free snapshot, a Health Check or monitoring we measure the nameservers and anycast addresses you ask us to measure. This data concerns network infrastructure, not individuals. Measurements are taken from public measurement platforms (RIPE Atlas) and, where agreed, from our own measurement lab. The lab's method, probe source addresses, abuse contact and public opt-out are documented at anycast.org. Results for a specific network are shared only with the customer who ordered them; anything we publish is aggregated or published with the operator's consent.
7. Recipients
We pass personal data to third parties only where described above (noez GmbH as hosting provider and Mailgun as e-mail provider, both processors under Art. 28 GDPR; Stripe for payments as independent controller) or where we are legally obliged to. Measurement requests to RIPE Atlas contain nameserver addresses, never your personal data. We do not sell data and do not use it for advertising.
8. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future. To exercise these rights, e-mail hello@anycast.dev.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
9. Changes
We update this policy when the site or our services change. The current version is always available at this address.
Last updated: 2026-10-02