Privacy Policy for Quellina
Last updated: September 2026 · Draft, have it reviewed legally before public launch
1. Controller
The service provider named in the Imprint is responsible for data processing. Privacy requests can be sent to contact@quellina.com.
2. Legal basis
We process personal data in particular on the basis of consent pursuant to Art. 6 para. 1 lit. a GDPR, for the performance of the user contract pursuant to Art. 6 para. 1 lit. b GDPR, to comply with legal obligations pursuant to Art. 6 para. 1 lit. c GDPR and on the basis of legitimate interests pursuant to Art. 6 para. 1 lit. f GDPR.
3. Data subject rights
Subject to statutory requirements, you have rights to information, rectification, erasure, restriction of processing, data portability and objection. Consent can be revoked at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.
4. Processing during use
4.1 Hosting and server logs
The application is provided via Vercel. When accessed, technically necessary log data such as IP address, time, requested URL, referrer, browser and device information may be processed. The purposes are delivery, stability, abuse prevention and error analysis. Legal basis is Art. 6 para. 1 lit. f GDPR.
4.2 Map and POI data
The map is rendered with map tiles from third-party providers: OpenFreeMap (vector map and 2D/3D view), OpenTopoMap (topographic view) and, as a fallback, the standard OpenStreetMap tile servers. POI queries are forwarded to the Overpass API via a Quellina endpoint on the server side. When map tiles are retrieved, the respective tile server technically receives your IP address, among other data. OpenStreetMap and Overpass data may be incomplete or outdated.
4.3 Location function
The browser only asks for your explicit permission to access the device location. It is used to centre the map and for POI queries. Quellina does not create a location or route history in Supabase. The browser and operating system manage the permission; it can be revoked there at any time.
4.4 Magic Link sign-in
For community status reports, an email address is processed for passwordless sign-in. Authentication and session management are handled by Supabase. Authentication data, session information and technically necessary log data are processed. Legal basis is Art. 6 para. 1 lit. b GDPR.
4.5 Community status reports
When a report is submitted, we store the OSM ID, POI type, reported status, timestamps and the internal user ID. The aggregated status, timestamps and number of reports are displayed publicly; the email address is not. The data serves the community status layer and abuse prevention.
4.6 Supabase
Supabase provides database and authentication for the Quellina DEV / production system. The application is designed for an EU project region. Depending on the service configuration, Supabase sub-processors and international transfer mechanisms may be relevant; the applicable data protection agreements are decisive.
4.7 Matomo
After your consent, we use a self-hosted Matomo instance at analytics.m-fa.de with Quellina Site ID 4. Matomo processes usage information such as pages visited, referrer, browser and device information and a truncated or anonymised IP address according to the server configuration. The purpose is statistical improvement of the application. Legal basis is Art. 6 para. 1 lit. a GDPR. Without consent, the Matomo script is not loaded. After consent, Matomo may set first-party cookies (e.g. _pk_id, _pk_ses) to recognise returning visits; declining consent deletes them.
You can change your consent at any time with effect for the future on the Cookies & Tracking page.
4.8 Local storage and PWA
Quellina uses browser storage and cache storage for the accepted safety notice, PWA settings, analytics consent, offline app shell, already loaded map tiles and unsynchronised status reports. Offline reports remain on the device until synchronisation or manual deletion of browser data.
4.9 Contact
If you contact us by email, we process your details to handle the request. The legal basis is Art. 6 para. 1 lit. b or lit. f GDPR, depending on the content. Statutory retention obligations remain unaffected.
5. Retention period
We store personal data only as long as necessary for the respective purpose, abuse prevention or legal obligations. Account data and status logs are processed until account deletion or expiry of defined deletion and retention periods. Technical backups may persist for a limited period.
6. Recipients and third-country transfers
Recipients may include Vercel, Supabase, operators of OpenStreetMap / Overpass infrastructure and, after consent, the self-hosted Matomo infrastructure. Where providers process data outside the European Economic Area, the transfer is based on the applicable legal instruments, in particular adequacy decisions or standard contractual clauses.
7. Security
We implement appropriate technical and organisational measures, including TLS transport encryption, role-based database rules, restricted write permissions and input validation. Absolute protection against all risks cannot be guaranteed.