← Back

Privacy Policy for Quellina

Last updated: September 2026 · Draft, have it reviewed legally before public launch

1. Controller

The service provider named in the Imprint is responsible for data processing. Privacy requests can be sent to contact@quellina.com.

2. Legal basis

We process personal data in particular on the basis of consent pursuant to Art. 6 para. 1 lit. a GDPR, for the performance of the user contract pursuant to Art. 6 para. 1 lit. b GDPR, to comply with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR and on the basis of legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.

3. Data subject rights

Subject to statutory requirements, you have rights to information, rectification, erasure, restriction of processing, data portability and objection. Consent can be revoked at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

4. Processing during use

4.1 Hosting and server logs

The application is provided via Vercel. When accessed, technically necessary log data such as IP address, time, requested URL, referrer, browser and device information may be processed. The purposes are delivery, stability, abuse prevention and error analysis. Legal basis is Art. 6 para. 1 lit. f GDPR.

4.2 Map and POI data

The map is rendered with map tiles from third-party providers: OpenFreeMap (vector map and 2D/3D view), OpenTopoMap (topographic view) and, as a fallback, the standard OpenStreetMap tile servers. POI queries are forwarded to the Overpass API via a Quellina endpoint on the server side. When map tiles are retrieved, the respective tile server technically receives your IP address, among other data. OpenStreetMap and Overpass data may be incomplete or outdated.

4.3 Location function

The browser only asks for your explicit permission to access the device location. It is used to centre the map and for POI queries. Quellina does not create a location or route history in Supabase. The browser and operating system manage the permission; it can be revoked there at any time.

4.4 Magic Link sign-in

For community status reports, an email address is processed for passwordless sign-in. Authentication and session management are handled by Supabase. Authentication data, session information and technically necessary log data are processed. Legal basis is Art. 6 para. 1 lit. b GDPR.

4.5 Community status reports

When a report is submitted, we store the OSM ID, POI type, reported status, timestamps and the internal user ID. The aggregated status, timestamps and number of reports are displayed publicly; the email address is not. The data serves the community status layer and abuse prevention.

4.6 Supabase

Supabase provides database and authentication for the Quellina DEV / production system. The application is designed for an EU project region. Depending on the service configuration, Supabase sub-processors and international transfer mechanisms may be relevant; the applicable data protection agreements are decisive.

4.7 Matomo

After your consent, we use a self-hosted Matomo instance at analytics.m-fa.de with Quellina Site ID 4. Matomo processes usage information such as pages visited, referrer, browser and device information and a truncated or anonymised IP address according to the server configuration. The purpose is statistical improvement of the application. Legal basis is Art. 6 para. 1 lit. a GDPR. Without consent, the Matomo script is not loaded. After consent, Matomo may set first-party cookies (e.g. _pk_id, _pk_ses) to recognise returning visits; declining consent deletes them.

You can change your consent at any time with effect for the future on the Cookies & Tracking page.

4.8 Local storage and PWA

Quellina uses browser storage and cache storage for the accepted safety notice, PWA settings, analytics consent, offline app shell, already loaded map tiles and unsynchronised status reports. Offline reports remain on the device until synchronisation or manual deletion of browser data.

4.9 Contact

If you contact us by email, we process your details to handle the request. The legal basis is Art. 6 para. 1 lit. b or lit. f GDPR, depending on the content. Statutory retention obligations remain unaffected.

5. Retention period

We store personal data only as long as necessary for the respective purpose, abuse prevention or legal obligations. Account data and status logs are processed until account deletion or expiry of defined deletion and retention periods. Technical backups may persist for a limited period.

6. Recipients and third-country transfers

Recipients may include Vercel, Supabase, operators of OpenStreetMap / Overpass infrastructure and, after consent, the self-hosted Matomo infrastructure. Where providers process data outside the European Economic Area, the transfer is based on the applicable legal instruments, in particular adequacy decisions or standard contractual clauses.

7. Security

We implement appropriate technical and organisational measures, including TLS transport encryption, role-based database rules, restricted write permissions and input validation. Absolute protection against all risks cannot be guaranteed.