Privacy Policy
Effective Date: 2026. AUG. 21.
Service: Typen
1. Introduction
This Privacy Policy explains how Typen, operated by Martin Mátyás Binder, collects and processes personal data.
We aim to collect only information reasonably necessary to operate, secure, and improve the Service.
2. Controller
Controller: Martin Mátyás Binder
Country: Hungary
Privacy contact: support@typen.blog
3. Account Information
When you create or use an account, we may process:
- email address;
- username;
- profile image;
- authentication identifiers;
- settings;
- locale;
- account creation information;
- login and security information.
We do not normally collect your date of birth.
4. Authentication
Authentication may use:
- email;
- Google;
- GitHub.
When OAuth is used, we receive information necessary to identify and authenticate your account.
The OAuth provider independently processes information under its own terms and privacy policy.
5. Blog Content
We process information users publish or upload, including:
- blogs;
- posts;
- comments;
- images;
- attachments;
- tags;
- settings;
- themes;
- collaborator information.
Public blog content is publicly available.
6. Collaborators
Blog owners may invite collaborators.
Blog owners may see the email addresses of collaborators they invite.
A blog owner does not automatically receive the email address of someone merely because that person comments on the blog.
7. Comments
When you comment, we may process:
- your account identity;
- comment text;
- timestamps;
- technical information needed to operate and secure commenting.
Comments may be publicly visible.
8. Public Files
Uploaded files may be served through:
media.typen.blog
Unless a specific privacy or password feature says otherwise, uploaded files should be considered publicly accessible to anyone with the URL.
9. Built-In Blog Analytics
Typen provides blog owners with aggregated analytics.
These may include:
- page views;
- visitor counts;
- approximate country;
- timestamps;
- article or page identifiers;
- a random per-blog browser identifier;
- pseudonymised or hashed network-derived information.
The browser identifier is separate for each blog.
It is not designed to contain:
- your email;
- your Typen account ID;
- your name;
- raw IP address.
Blog owners receive aggregated information rather than individual visitor profiles.
Analytics records are generally deleted after 90 days.
Where applicable law requires consent for analytics-related browser storage, that storage will be subject to the appropriate consent mechanism.
10. IP Addresses
Our servers may temporarily process IP addresses for purposes including:
- serving requests;
- network security;
- rate limiting;
- abuse prevention;
- bot detection;
- troubleshooting;
- CrowdSec analysis;
- security investigations.
Raw security logs may be stored for:
90 days
Retention may depend on active attacks and legitimate security needs.
11. Country Detection
We may derive approximate country-level location from an IP address using a geolocation database such as an MMDB database.
The blog owner receives aggregate country statistics rather than raw IP addresses.
12. Umami
The main Typen application or dashboard may use Umami Cloud for analytics.
Where configured to require consent, Umami analytics runs only after consent has been provided.
Users can later withdraw analytics consent through Cookie Settings.
Umami used by Typen is separate from the built-in analytics provided to individual blog owners.
13. Browser Storage
Browser storage may be used for:
- authentication;
- language;
- theme;
- editor recovery;
- consent settings;
- analytics where applicable.
See the Cookie & Local Storage Policy.
14. Payments
Typen does not currently offer paid services or accept payments.
If paid services are introduced in the future, this Privacy Policy will be updated before payment processing becomes available.
15. Email
Transactional emails are sent using Mailjet.
These may include:
- authentication emails;
- account messages;
- security alerts;
- moderation notices;
- support communications;
- important Service notices.
Newsletter functionality for blog owners may be covered separately when released.
16. Infrastructure
Core Service infrastructure, databases, and media are hosted through Hetzner in Nuremberg, Germany.
Backups may use Backblaze B2 or compatible storage.
Backup retention:
30 days
17. Cloudflare
Cloudflare may be used for purposes including:
- DNS;
- CAPTCHA;
- bot protection;
- related security functionality.
18. Security Systems
Infrastructure and security systems may include:
- Caddy;
- Grafana;
- CrowdSec;
- application and server logs.
These systems are used to monitor, troubleshoot, protect, and operate Typen.
19. Cleo
Cleo is disabled by default.
If a blog owner enables Cleo, public article text may be sent to DeepSeek through its paid API.
We do not intentionally include unrelated personal data such as:
- blog-owner email addresses;
- reader IP addresses;
- reader analytics IDs.
See the Cleo & AI Policy.
20. Legal Bases
Depending on the processing activity, we may process personal data because:
- it is necessary to provide the Service;
- it is necessary to perform a contract;
- we have legitimate interests in security and Service operation;
- you gave consent;
- we must comply with a legal obligation.
Where processing is based on consent, consent may be withdrawn.
21. Sharing
We do not sell personal data.
We may provide necessary information to service providers for:
- hosting;
- backups;
- authentication;
- email;
- analytics;
- AI;
- CAPTCHA;
- security;
- DNS.
We may also disclose information where required by law or reasonably necessary to investigate serious abuse, fraud, attacks, or safety risks.
22. International Processing
Some service providers may process information outside Hungary or the European Economic Area.
Where legally required, appropriate transfer safeguards will be used.
23. Retention
Typical retention includes:
- built-in blog analytics: approximately 90 days;
- security logs:
90 days; - backups:
30 days; - active account information: while the account remains active.
24. Deletion
Account deletion can be requested through support.
We may verify the request before permanently deleting an account.
After confirmed deletion, active account data, blogs, posts, media, and related information are intended to be hard deleted.
There is no normal user-facing recovery period.
Backup copies are handled according to the backup lifecycle.
Third-party providers may independently retain information where they are legally required to do so.
25. Data Export
Users may request an export before deletion.
Exports may include blog content and other reasonably portable account information.
26. Your Rights
Depending on applicable law, you may have rights including:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent;
- submitting a complaint to a supervisory authority.
Contact:
support@typen.blog
27. Supervisory Authority
Users may have the right to complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or another competent European supervisory authority.
28. Children
We avoid collecting age information unless necessary.
Account eligibility is described in the Terms of Service.
If we discover that personal information was processed from a child where legally required authorization was missing, we may restrict or delete the relevant account or information.
29. Changes
We may update this Privacy Policy as the Service develops.
Material changes will be communicated appropriately.
30. Contact
support@typen.blog