Privacy policy.

What data Noticed processes, why, and what rights you have. In short: only what you enter, no bank access, no tracking.

Last updated: October 2026

1. Controller

Tech Bummens UG (haftungsbeschränkt), Plettenbergstr. 59/1, 78628 Rottweil, Germany, email: support@usenoticed.app

2. What we process

  • Account: email address and password (stored only as a secure bcrypt hash).
  • Contracts: the details you enter yourself (name, provider, terms, notice periods, optionally cost and notes).
  • Consents: when and where you agreed to marketing emails or the newsletter, and your IP address at that moment (proof under Art. 7 (1) GDPR).
  • Sign-in security: for each browser you sign in from, a random identifier (stored only as a hash), the browser and operating system name, and the time of the last sign-in. If our hosting provider supplies it, we also include the approximate location (city/country derived from your IP address) in security emails; we do not store it.
  • Email delivery: send logs as well as delivery, bounce and complaint notifications.

3. Purposes and legal bases

  • Providing the service, deadline reminders and account emails: performance of contract (Art. 6 (1) (b) GDPR).
  • Newsletter and news/offers: only with your consent (Art. 6 (1) (a) GDPR), for the newsletter via double opt-in. You can withdraw at any time via the link in every email or in your account settings.
  • Security notifications (new sign-in, password or email address changed) and recognising known browsers: legitimate interest in protecting your account (Art. 6 (1) (f) GDPR).
  • Monthly overview email: performance of contract (Art. 6 (1) (b) GDPR); you can switch it off in your settings at any time.
  • Suppression list for undeliverable addresses and complaints: legitimate interest in reliable email delivery (Art. 6 (1) (f) GDPR).

4. Sending email with Resend

We send emails via Resend (operated by Plus Five Five, USA). Resend processes your email address and the content of the emails on our behalf under a data processing agreement (Art. 28 GDPR) and stores data in the USA. Resend is certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45 GDPR); in addition, its data processing agreement includes the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR).

5. Hosting

Our website and app run on servers of a hosting provider in Switzerland, which processes data only on our behalf under a data processing agreement (Art. 28 GDPR). Switzerland has an adequacy decision of the European Commission (Art. 45 GDPR), so it ensures a level of data protection equivalent to the EU.

6. Contract scan with Grok (xAI)

If you choose to scan a screenshot or photo of a contract, we send the image to the AI service Grok by X.AI LLC (USA) to read out the contract details. This only happens when you start a scan yourself. We do not store the images – they are processed in memory, sent to xAI and discarded. Only the details you then save in the form are stored. Legal basis: performance of contract (Art. 6 (1) (b) GDPR), at your request.

Data is transferred to the USA on the basis of the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR), which are part of xAI's data processing addendum. xAI does not use the data for training. It stores requests and responses encrypted for up to 30 days, only to investigate abuse, and then deletes them automatically.

7. Households

If you join a household, the other members see your email address and the contracts you share with them, and receive their reminders. Contracts you don't share stay private. If you invite someone, we use their email address only to send the invitation; open invitations expire after 7 days.

8. Cookies

We only use two technically necessary cookies: one keeps you signed in, the other recognises your browser so we can warn you about sign-ins from new devices. We do not use tracking or advertising cookies.

9. Retention

Account and contract data is stored until you delete your account, which you can do at any time in your settings. Proof of consent is kept as long as we need it as evidence.

10. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a data protection supervisory authority.

Privacy policy – Noticed