Legal
Data Privacy
Last updated: 26 July 2026
This privacy notice explains what personal data is processed when you visit maxjulianfischer.com, who receives it, and what rights you have under the EU General Data Protection Regulation (GDPR / DSGVO). I only collect what is technically necessary to operate the website and its apps, and I follow the principle of data minimisation.
1. Controller
The data controller under Art. 4 (7) GDPR is:
Max Julian Fischer
Raumerstraße 12
10437 Berlin, Germany
Email:
hello@maxjulianfischer.com
2. Hosting & server logs (Vercel)
This site is hosted on the infrastructure of Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit the site, Vercel automatically records standard access data in server log files for security, performance and troubleshooting purposes. This includes:
- anonymised IP address
- date and time of the request
- requested URL and HTTP status code
- referring URL
- browser type, version and operating system
Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in the secure and reliable operation of the website. Retention: Vercel keeps request logs for a limited period (see Vercel's privacy policy).
Vercel is headquartered in the United States. Data transfers are covered by the EU-US Data Privacy Framework (Vercel is self-certified) and by Standard Contractual Clauses under Art. 46 (2) (c) GDPR. A Data Processing Agreement is in place.
3. Data security & encryption
All connections to this site are encrypted end-to-end using TLS (HTTPS). You can verify this by the padlock icon in your browser's address bar. Data at rest with the processors listed in this policy is encrypted according to their respective security standards. Passwords for the Kitchen app are never stored in plain text; only a salted hash is kept.
4. Contact by email
When you write to hello@maxjulianfischer.com, your email address and the content of your message are processed only to respond to your inquiry. Legal basis: Art. 6 (1) (b) GDPR where your inquiry relates to a contract or pre-contractual step, otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering your message). Correspondence is kept as long as needed to complete the exchange and any statutory retention periods, then deleted.
5. Cookies & local storage
The public portfolio pages do not use tracking cookies, analytics or advertising cookies. No consent banner is required for the public site.
When you sign in to the Kitchen Visualizer app, Supabase (see section 6) sets a small number of strictly necessary cookies and local storage entries to keep you signed in. Legal basis: § 25 (2) no. 2 TDDDG — strictly necessary for a service you actively requested — and Art. 6 (1) (b) GDPR (contract performance).
6. Accounts, authentication & database (Supabase)
For the Kitchen Visualizer app I use Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992, as a processor for authentication, database and file storage. When you create an account or use the app, the following data is processed on Supabase's infrastructure:
- email address and a salted password hash (never plain text)
- account creation and sign-in timestamps
- images you upload as inspiration or room references
- generated images and project metadata linked to your account
Legal basis: Art. 6 (1) (b) GDPR — performance of the user agreement for the app. A Data Processing Agreement (DPA) under Art. 28 GDPR is in place. See Supabase's privacy policy for details.
7. AI image analysis & generation (OpenAI, Google Gemini)
The Kitchen Visualizer app processes the images you upload through third-party AI services in order to analyse the scene and generate new visualisations. Two providers are used:
- OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA — image understanding via the OpenAI API.
- Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA) — image generation via the Gemini API.
When you use the app, the images you upload and the prompts you create are sent to these providers for processing. Both providers state that API inputs and outputs are not used to train their general-purpose models by default (see the OpenAI API data usage policy and the Google Gemini API terms). Requests may be retained by the provider for a short period for abuse monitoring before deletion.
Legal basis: Art. 6 (1) (b) GDPR — the processing is necessary to provide the visualisation service you requested. Transfers to the US are covered by the EU-US Data Privacy Framework (both OpenAI and Google LLC are certified) and by Standard Contractual Clauses under Art. 46 (2) (c) GDPR.
Please do not upload personal photos, faces or sensitive content. The app is intended for photos of rooms and interior inspiration only.
8. AI-generated content
In line with Art. 50 of the EU AI Act, I want to be transparent: images produced by the Kitchen Visualizer are generated by an AI model. They are visualisations, not photographs, and may contain inaccuracies. Do not rely on generated images for structural, safety or purchasing decisions without independent verification.
9. Embedded media (Vimeo)
Some project pages may embed videos hosted by Vimeo Inc., 330 W 34th Street, 5th Floor, New York, NY 10001, USA. When a page containing a Vimeo embed is loaded and you play the video, Vimeo may set cookies and receive information about your device (IP address, browser, referring URL). If you do not play the embedded video, no data is transmitted beyond the initial iframe request.
Legal basis: Art. 6 (1) (f) GDPR — legitimate interest in presenting portfolio work in a rich, video-based format. Vimeo is certified under the EU-US Data Privacy Framework. See Vimeo's privacy policy for details.
10. International data transfers
Some of the processors above are located in the United States (Vercel, OpenAI, Google, Vimeo). Transfers are protected by:
- the EU-US Data Privacy Framework where the provider is self-certified (adequacy decision of the EU Commission of 10 July 2023); and
- Standard Contractual Clauses under Art. 46 (2) (c) GDPR as an additional safeguard.
11. No automated decision-making
I do not use automated decision-making within the meaning of Art. 22 GDPR, including profiling, that produces legal effects concerning you or similarly significantly affects you. The image generation performed by the Kitchen Visualizer is a service you actively request and does not constitute an automated decision about you.
12. Retention
Server logs are kept only as long as needed to detect and address technical or security issues, then deleted or anonymised. Account data and uploaded images in the Kitchen app are kept until you delete your account or the specific project. Email correspondence is kept until your inquiry is fully resolved. You can request deletion at any time (see section 13).
13. Your rights
Under the GDPR you have the following rights regarding your personal data:
- right of access (Art. 15)
- right to rectification (Art. 16)
- right to erasure / "to be forgotten" (Art. 17)
- right to restrict processing (Art. 18)
- right to data portability (Art. 20)
- right to object to processing (Art. 21)
- right to withdraw consent at any time (Art. 7 (3))
Right to object (Art. 21 GDPR): you have the right to object, on grounds relating to your particular situation, at any time to processing based on our legitimate interests (Art. 6 (1) (f) GDPR). This applies in particular to the server-log processing described in section 2 and to the Vimeo embeds described in section 9.
To exercise any of these rights, send an email to hello@maxjulianfischer.com. No specific form is required.
14. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority for Berlin is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin, Germany
datenschutz-berlin.de
15. Changes to this policy
As the site or its apps evolve, this policy may be updated to reflect new services or legal requirements. The date at the top of this page reflects the latest revision.