Privacy policy
This page explains what happens to data when you visit AWTRIX Hub, when you sign in, and when you publish a flow or an icon. It describes the site as it actually works — there is no tracking, no advertising, no analytics, and no third-party content embedded in these pages.
1. Who is responsible
Controller within the meaning of Art. 4 (7) GDPR:
Stephan Mühl Softwareentwicklung
Sole proprietor: Stephan Mühl
Weinbergstraße 10
63477 Maintal, Germany
admin@blueforcer.de
There is no statutory obligation to appoint a data protection officer for a service of this size, and none has been appointed.
2. Visiting the site
When you open a page, your browser sends technical data that the web server records in a log file:
- your IP address
- date and time of the request
- the page or file requested and the HTTP status
- the amount of data transferred
- the referring page, if your browser sends one
- browser and operating system identification (user agent)
Purpose: delivering the site, finding faults, and defending
against attacks and abuse.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is
operating a functioning and secure website.
Retention: application logs are deleted after 14 days. Web
server logs are rotated and overwritten continuously.
Your IP address is also used briefly to enforce rate limits — for example, a maximum of five flow submissions per hour. While you are signed in, that counter is kept per account instead of per IP address. These counters live in a temporary in-memory store and expire on their own within an hour. Legal basis: Art. 6 (1) (f) GDPR, interest in preventing spam and abuse.
3. No third-party content, no tracking
All fonts, stylesheets, scripts and images needed to display these pages are served from our own server. That includes the icon editor, which runs from our own server rather than being embedded from somewhere else, and the sign-in buttons, whose provider logos are served from here like everything else. We do not embed fonts, libraries or images from content delivery networks, and we use no analytics, no advertising, no social media plugins and no consent management platform. When you look at a page, your IP address is therefore not transmitted to any third party.
The pages do contain ordinary hyperlinks to other sites — the AWTRIX documentation, GitHub, Discord, Home Assistant and “Buy me a coffee”. Those sites receive data only if you actively click the link, and their own privacy policies apply from then on.
4. Cookies and data stored in your browser
We set only cookies that are strictly necessary to provide the functions you requested: keeping a session, protecting forms, and — once you sign in — keeping you signed in. Under § 25 (2) TDDDG these do not require consent, which is why this site shows no cookie banner. Three things have to be true for that, and they are: every cookie below is set by this site itself and does a job you asked for, nothing is stored before you do something that needs it, and no page here loads anything from a third party that could set a cookie of its own. There is no “stay signed in” cookie either; the session below simply lasts longer.
| Name | Purpose | Lifetime |
|---|---|---|
awtrix-flows-session |
Keeps your session, e.g. so form errors and one-time messages survive a page reload. Once you sign in, this is also what keeps you signed in, and it carries the one-time value that ties the detour to your identity provider back to your browser. | 30 days |
XSRF-TOKEN |
Protects forms against cross-site request forgery. | 30 days |
edit_token_… |
Set only when you open or save a flow with its secret edit link, so the page can show you that link again. One cookie per such flow; it is removed when the flow is attached to an account. | 30 days |
In addition, four values are stored in your browser's local storage. None of them is ever sent to our server:
-
flows-theme— remembers whether you chose the light or dark appearance. Written only when you use the toggle. -
awtrixDeviceAddress— the address of your own AWTRIX device, remembered so you do not have to type it again when uploading icons. Written only when you use that function. -
awtrixNgAddress— the address of your own AWTRIX NG device, remembered for the same reason when you install a script on it. Written only when you use that function. Both of these addresses stay in your browser: it talks to your device directly, and our server never learns the address. -
flows-notice-dismissed— remembers that you closed the notice about the switch to accounts, so it is not shown to you again. Written only when you close it.
You can delete cookies and local storage at any time in your browser settings,
and signing out ends your session immediately. Deleting the
edit_token_… cookie means the site can no longer show you your
edit link — keep the link itself if you want to come back to it.
5. Accounts and what you publish
5.1 Publishing a flow or an icon
Publishing requires an account (section 5.2); browsing, searching and downloading do not. What you enter in the form is stored and published:
- the name of the flow, a short summary and a longer description
- the flow itself (configuration or script text)
- the cover image and any icons you upload with a flow
- the author name you type in — you choose it freely, and a pseudonym is fine
- the system, topic and firmware you select
- for an icon: the file, the name you give it, and what we read out of the file itself — its dimensions, its number of frames, its size in bytes, a checksum of it, and which editor or client you sent it from
- which version of the terms of service you accepted for that contribution, and when. That is recorded on each contribution separately; flows published before accounts existed carry no such record, because there was nothing to accept at the time.
- internally, which account the contribution belongs to. That link is not shown next to it; what visitors see is the author name you typed.
All of this becomes publicly visible and can be read, downloaded and indexed by search engines. Please do not put personal data of yourself or others into these fields. If you enter your real name as the author name, that name is published.
Purpose: publishing the flow or the icon, which is the entire
point of the service you are using.
Legal basis: Art. 6 (1) (b) GDPR — you actively submit content
for publication, and we provide the publication.
Retention: until it is deleted. You can change or delete your
own contributions from your account page at any time, or ask us to.
Flows published before accounts existed are changed and deleted with a secret edit link instead. We store only a cryptographic hash (SHA-256) of that secret, never the secret itself, so nobody — including us — can reconstruct the link from the database. When such a flow is attached to an account, that hash is deleted and the link stops working.
We also count page views and downloads per flow and per icon. These are plain numbers with no connection to a person. Legal basis: Art. 6 (1) (f) GDPR, interest in knowing which contributions are useful.
5.2 Your account
An account comes into existence the first time you sign in with GitHub, Google or Discord. We never receive your password. From the provider we store:
- which provider you used and the user id it gives us — that pair is what recognises you when you come back
- the display name or user name the provider returns
- the e-mail address the provider returns, if it returns one. GitHub and Discord may withhold it; an account without an e-mail address works normally.
- the time of your last sign-in
We do not store your password, your profile picture or the access token the provider issues. We ask each provider only for your identity and, where it offers one, your e-mail address — nothing else. The token is used once during the sign-in and then discarded. No picture of yours is stored here or loaded from the provider, which is what keeps the promise in section 3 true. Your e-mail address is never published and never shown to other visitors.
You can connect more than one provider to the same account; a record of the kind above then exists for each of them. If you sign in with a second provider that reports the same e-mail address as an account you already have, and that provider confirms the address as verified, we attach the sign-in to the existing account instead of creating a second one.
Purpose: recognising you as the author of your contributions so
that only you can change them, and being able to reach you about them — for
example about a report under section 6.
Legal basis: Art. 6 (1) (b) GDPR — the account is what the
agreement between us consists of, and publishing is not possible without one.
For the security-related part, the time of the last sign-in and defending an
account against misuse, additionally Art. 6 (1) (f) GDPR.
Retention: as long as the account exists. Section 5.3 describes
deletion.
5.3 Deleting your account
You can delete your account yourself, at any time, from your account page. You do not have to give a reason and you do not have to ask us. Before it happens we ask what should become of what you published, and you choose one of two things:
- Delete everything. Your flows and icons are removed from the site, their files are deleted from the server, and any Home Assistant blueprint mirrored to GitHub is deleted there as well. What other people have already downloaded or installed, and the history of the public GitHub repository, cannot be recalled.
- Leave what I published online. Your contributions stay published exactly as they are, including the author name you chose for them, but they are detached from you: they are shown as belonging to a deleted account, and from then on nobody — including you — can change or delete them. Choose this only if you are content for them to stay.
Either way, the account itself and every connection to an identity provider are deleted immediately, and you are signed out. Two things survive on purpose: reports made through the reporting form, which are kept for three years under section 6 no matter who made them, and the server log entries described in section 2, which expire on their own within 14 days. Deleting your account here deletes nothing at GitHub, Google or Discord; only the connection between them and this site is removed.
6. Reporting content
If you report a flow or an icon using the reporting form, we store what you write, the content concerned, and — if you choose to provide it — your name and e-mail address, so we can come back to you. Providing them is voluntary; a report without contact details is still processed. A report is not connected to your account, even if you are signed in when you make it.
Legal basis: Art. 6 (1) (c) GDPR in conjunction with Art. 16 of
Regulation (EU) 2022/2065 (Digital Services Act) — we are legally required to
operate a reporting procedure — and Art. 6 (1) (f) GDPR for keeping a record of
how a report was handled.
Retention: reports and the decisions taken on them are kept for
three years so that we can demonstrate how we acted, then deleted.
7. Who else receives data
Hosting
The site runs on a server operated by Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. Contabo acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The server is located in Germany.
Discord — announcing new flows and icons
When a new flow is published, an automatic announcement is posted to our Discord server via a webhook. It contains the flow name, the author name you chose, the short summary, the link to the flow and its cover image — that is, content you submitted for publication anyway. A new icon is announced the same way, with its name, the author name you chose, the link to it and the icon image itself. No IP addresses, no account data and no data about visitors are sent. This happens whether or not you have a Discord account. The service is operated by Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, and Discord, Inc., 444 De Haro Street, San Francisco, CA 94107, United States.
GitHub — the blueprint mirror
Flows submitted for the “Home Assistant Blueprint” system are additionally mirrored into a public GitHub repository, because Home Assistant imports blueprints directly from there. The mirrored file contains the flow text you submitted, and no account data. The service is operated by GitHub B.V., Vijzelstraat 68-72, 1017 HL Amsterdam, Netherlands, and GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, United States (part of Microsoft).
Signing in: GitHub, Google and Discord
When you press one of the sign-in buttons, your browser is sent to the provider you chose. From that moment the provider knows that somebody is signing in to this site, and it sees your IP address, your browser and the time. That happens at the provider, not here, and their own privacy policy applies to it. Nothing reaches any of them unless you press the button: the buttons load no code and no images from them, and a visitor who never signs in is never in touch with them through this site. What we receive back is the data listed in section 5.2, and we send them nothing about you beyond what the sign-in itself requires. The providers are:
- GitHub B.V., Vijzelstraat 68-72, 1017 HL Amsterdam, Netherlands, and GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, United States (part of Microsoft).
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States.
- Discord Netherlands B.V., Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands, and Discord, Inc., 444 De Haro Street, San Francisco, CA 94107, United States.
GitHub and Discord appear twice on this page for unrelated reasons: above as recipients of content you published, here as a way to sign in. Signing in with one of them tells us nothing about the other role, and publishing a flow tells them nothing about your account.
Discord, GitHub and Google may process data in the United States. Transfers take place on the basis of the European Commission's adequacy decision for the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.
We do not sell data, and we pass nothing on to anybody else unless we are legally obliged to.
8. Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable form (Art. 20)
- object to processing based on legitimate interests (Art. 21) — this applies in particular to the log data described in section 2
A message to admin@blueforcer.de is enough. If you have an account, the account page is quicker: it shows everything the account holds, lets you download all of it as a file, and lets you delete it — that covers Art. 15, 16, 17 and 20 without waiting for us. If you write instead, please write from the e-mail address linked to your account, or tell us which provider you sign in with, so that we can tell which account you mean. For a flow published before accounts existed we hold no e-mail address at all and cannot connect it to a person; sending us the edit link or the address of the flow is then the only way to identify it.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7, 65185 Wiesbaden, Germany
datenschutz.hessen.de
9. Children
This service is aimed at people who own an AWTRIX display and is not directed at children. We do not knowingly process data of children. Where consent were ever required from a child, Art. 8 GDPR and the German age threshold apply. If you believe a child has published personal data here, please tell us and we will remove it.
10. No automated decisions
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Whether a flow or an icon is hidden or removed is always decided by a person.
11. Changes
We will update this policy when the service changes. The date below tells you which version you are reading.
Last updated: 11 August 2026