Skip to content

New Flows can now belong to an account. Your old edit link keeps working — open it and attach the flow to an account, and you can edit it from any browser you sign in with.

Sign in

Privacy policy

This page explains what happens to data when you visit AWTRIX Hub, when you sign in, and when you publish a flow or an icon. It describes the site as it actually works — there is no tracking, no advertising, no analytics, and no third-party content embedded in these pages.

1. Who is responsible

Controller within the meaning of Art. 4 (7) GDPR:

Stephan Mühl Softwareentwicklung
Sole proprietor: Stephan Mühl
Weinbergstraße 10
63477 Maintal, Germany
admin@blueforcer.de

There is no statutory obligation to appoint a data protection officer for a service of this size, and none has been appointed.

2. Visiting the site

When you open a page, your browser sends technical data that the web server records in a log file:

Purpose: delivering the site, finding faults, and defending against attacks and abuse.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is operating a functioning and secure website.
Retention: application logs are deleted after 14 days. Web server logs are rotated and overwritten continuously.

Your IP address is also used briefly to enforce rate limits — for example, a maximum of five flow submissions per hour. While you are signed in, that counter is kept per account instead of per IP address. These counters live in a temporary in-memory store and expire on their own within an hour. Legal basis: Art. 6 (1) (f) GDPR, interest in preventing spam and abuse.

3. No third-party content, no tracking

All fonts, stylesheets, scripts and images needed to display these pages are served from our own server. That includes the icon editor, which runs from our own server rather than being embedded from somewhere else, and the sign-in buttons, whose provider logos are served from here like everything else. We do not embed fonts, libraries or images from content delivery networks, and we use no analytics, no advertising, no social media plugins and no consent management platform. When you look at a page, your IP address is therefore not transmitted to any third party.

The pages do contain ordinary hyperlinks to other sites — the AWTRIX documentation, GitHub, Discord, Home Assistant and “Buy me a coffee”. Those sites receive data only if you actively click the link, and their own privacy policies apply from then on.

4. Cookies and data stored in your browser

We set only cookies that are strictly necessary to provide the functions you requested: keeping a session, protecting forms, and — once you sign in — keeping you signed in. Under § 25 (2) TDDDG these do not require consent, which is why this site shows no cookie banner. Three things have to be true for that, and they are: every cookie below is set by this site itself and does a job you asked for, nothing is stored before you do something that needs it, and no page here loads anything from a third party that could set a cookie of its own. There is no “stay signed in” cookie either; the session below simply lasts longer.

NamePurposeLifetime
awtrix-flows-session Keeps your session, e.g. so form errors and one-time messages survive a page reload. Once you sign in, this is also what keeps you signed in, and it carries the one-time value that ties the detour to your identity provider back to your browser. 30 days
XSRF-TOKEN Protects forms against cross-site request forgery. 30 days
edit_token_… Set only when you open or save a flow with its secret edit link, so the page can show you that link again. One cookie per such flow; it is removed when the flow is attached to an account. 30 days

In addition, four values are stored in your browser's local storage. None of them is ever sent to our server:

You can delete cookies and local storage at any time in your browser settings, and signing out ends your session immediately. Deleting the edit_token_… cookie means the site can no longer show you your edit link — keep the link itself if you want to come back to it.

5. Accounts and what you publish

5.1 Publishing a flow or an icon

Publishing requires an account (section 5.2); browsing, searching and downloading do not. What you enter in the form is stored and published:

All of this becomes publicly visible and can be read, downloaded and indexed by search engines. Please do not put personal data of yourself or others into these fields. If you enter your real name as the author name, that name is published.

Purpose: publishing the flow or the icon, which is the entire point of the service you are using.
Legal basis: Art. 6 (1) (b) GDPR — you actively submit content for publication, and we provide the publication.
Retention: until it is deleted. You can change or delete your own contributions from your account page at any time, or ask us to.

Flows published before accounts existed are changed and deleted with a secret edit link instead. We store only a cryptographic hash (SHA-256) of that secret, never the secret itself, so nobody — including us — can reconstruct the link from the database. When such a flow is attached to an account, that hash is deleted and the link stops working.

We also count page views and downloads per flow and per icon. These are plain numbers with no connection to a person. Legal basis: Art. 6 (1) (f) GDPR, interest in knowing which contributions are useful.

5.2 Your account

An account comes into existence the first time you sign in with GitHub, Google or Discord. We never receive your password. From the provider we store:

We do not store your password, your profile picture or the access token the provider issues. We ask each provider only for your identity and, where it offers one, your e-mail address — nothing else. The token is used once during the sign-in and then discarded. No picture of yours is stored here or loaded from the provider, which is what keeps the promise in section 3 true. Your e-mail address is never published and never shown to other visitors.

You can connect more than one provider to the same account; a record of the kind above then exists for each of them. If you sign in with a second provider that reports the same e-mail address as an account you already have, and that provider confirms the address as verified, we attach the sign-in to the existing account instead of creating a second one.

Purpose: recognising you as the author of your contributions so that only you can change them, and being able to reach you about them — for example about a report under section 6.
Legal basis: Art. 6 (1) (b) GDPR — the account is what the agreement between us consists of, and publishing is not possible without one. For the security-related part, the time of the last sign-in and defending an account against misuse, additionally Art. 6 (1) (f) GDPR.
Retention: as long as the account exists. Section 5.3 describes deletion.

5.3 Deleting your account

You can delete your account yourself, at any time, from your account page. You do not have to give a reason and you do not have to ask us. Before it happens we ask what should become of what you published, and you choose one of two things:

Either way, the account itself and every connection to an identity provider are deleted immediately, and you are signed out. Two things survive on purpose: reports made through the reporting form, which are kept for three years under section 6 no matter who made them, and the server log entries described in section 2, which expire on their own within 14 days. Deleting your account here deletes nothing at GitHub, Google or Discord; only the connection between them and this site is removed.

6. Reporting content

If you report a flow or an icon using the reporting form, we store what you write, the content concerned, and — if you choose to provide it — your name and e-mail address, so we can come back to you. Providing them is voluntary; a report without contact details is still processed. A report is not connected to your account, even if you are signed in when you make it.

Legal basis: Art. 6 (1) (c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065 (Digital Services Act) — we are legally required to operate a reporting procedure — and Art. 6 (1) (f) GDPR for keeping a record of how a report was handled.
Retention: reports and the decisions taken on them are kept for three years so that we can demonstrate how we acted, then deleted.

7. Who else receives data

Hosting

The site runs on a server operated by Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. Contabo acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The server is located in Germany.

Discord — announcing new flows and icons

When a new flow is published, an automatic announcement is posted to our Discord server via a webhook. It contains the flow name, the author name you chose, the short summary, the link to the flow and its cover image — that is, content you submitted for publication anyway. A new icon is announced the same way, with its name, the author name you chose, the link to it and the icon image itself. No IP addresses, no account data and no data about visitors are sent. This happens whether or not you have a Discord account. The service is operated by Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, and Discord, Inc., 444 De Haro Street, San Francisco, CA 94107, United States.

GitHub — the blueprint mirror

Flows submitted for the “Home Assistant Blueprint” system are additionally mirrored into a public GitHub repository, because Home Assistant imports blueprints directly from there. The mirrored file contains the flow text you submitted, and no account data. The service is operated by GitHub B.V., Vijzelstraat 68-72, 1017 HL Amsterdam, Netherlands, and GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, United States (part of Microsoft).

Signing in: GitHub, Google and Discord

When you press one of the sign-in buttons, your browser is sent to the provider you chose. From that moment the provider knows that somebody is signing in to this site, and it sees your IP address, your browser and the time. That happens at the provider, not here, and their own privacy policy applies to it. Nothing reaches any of them unless you press the button: the buttons load no code and no images from them, and a visitor who never signs in is never in touch with them through this site. What we receive back is the data listed in section 5.2, and we send them nothing about you beyond what the sign-in itself requires. The providers are:

GitHub and Discord appear twice on this page for unrelated reasons: above as recipients of content you published, here as a way to sign in. Signing in with one of them tells us nothing about the other role, and publishing a flow tells them nothing about your account.

Discord, GitHub and Google may process data in the United States. Transfers take place on the basis of the European Commission's adequacy decision for the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

We do not sell data, and we pass nothing on to anybody else unless we are legally obliged to.

8. Your rights

Under the GDPR you have the right to:

A message to admin@blueforcer.de is enough. If you have an account, the account page is quicker: it shows everything the account holds, lets you download all of it as a file, and lets you delete it — that covers Art. 15, 16, 17 and 20 without waiting for us. If you write instead, please write from the e-mail address linked to your account, or tell us which provider you sign in with, so that we can tell which account you mean. For a flow published before accounts existed we hold no e-mail address at all and cannot connect it to a person; sending us the edit link or the address of the flow is then the only way to identify it.

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7, 65185 Wiesbaden, Germany
datenschutz.hessen.de

9. Children

This service is aimed at people who own an AWTRIX display and is not directed at children. We do not knowingly process data of children. Where consent were ever required from a child, Art. 8 GDPR and the German age threshold apply. If you believe a child has published personal data here, please tell us and we will remove it.

10. No automated decisions

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Whether a flow or an icon is hidden or removed is always decided by a person.

11. Changes

We will update this policy when the service changes. The date below tells you which version you are reading.

Last updated: 11 August 2026