Privacy

1. Controller

The controller responsible for data processing on bricoria.app is:
Thomas Harnisch, Königskinderweg 74f, 22457 Hamburg, Germany
Email: [email protected]

2. Overview

Bricoria is designed to collect as little data as possible. You can use all content and tools without an account. Photos you turn into a mosaic never leave your device: they are processed only in your browser and are never sent to our server.

3. Hosting and server log files

Our website is operated by a host with servers in Germany. When you visit the site, the server automatically collects information your browser transmits (server log files): browser type and version, operating system, referrer URL, host name of the accessing computer, time of the request and IP address. This data is used for technical delivery, security and stability and is deleted after 7 days at the latest. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).

4. Cloudflare (CDN and security)

To deliver, speed up and protect the site against attacks we use Cloudflare (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA), which processes your IP address among other things. Cloudflare is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). The legal basis is Art. 6(1)(f) GDPR.

5. SSL/TLS encryption

For security reasons this site uses SSL/TLS encryption (https). Transmitted data cannot be read by third parties.

7. Mosaic generator

The mosaic generator converts your photo into a brick grid entirely in your browser. The photo is neither uploaded nor stored by us. Settings you make in the tool may be saved locally in your browser so you can continue later. If you save a mosaic, only the brick grid is stored, never the photo (see “User account”).

9. Tracking, analytics and advertising

With your consent we may use services for audience measurement and advertising. Cookies and similar technologies may be used and device and usage data processed; depending on the service, data may be transferred to third parties, including in the USA, where the providers are certified under the EU-US Data Privacy Framework. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future.

A complete and always up-to-date list of the services used, each with the processing company, purpose, data collected, retention period, third-country transfers and a link to the provider's privacy policy, is available at any time under "Cookie settings" in the footer. Without your consent none of these services is loaded.

10. Catalogue data and images

Set and part data comes from Rebrickable's public data downloads and is stored on our server. No personal data is sent to Rebrickable when you view catalogue pages.

11. Fonts

We load fonts exclusively from our own server. There is no connection to third-party servers (e.g. Google Fonts).

12. Contacting us

If you write to us by email or via the contact form, we process your details (email address, optionally your name, topic and message) to handle your request. The form stores nothing on our server: the message is forwarded to us directly as an email. To prevent abuse we briefly count submissions per irreversible hash of your IP address (for at most one hour); the IP address itself is not stored. The legal basis is Art. 6(1)(b) GDPR (handling your request) or Art. 6(1)(f) GDPR (spam protection). Emails are deleted as soon as they are no longer needed.

13. User account

An account is optional; all tools work without one. If you create an account, we store your email address, your password (only as an irreversible hash), optionally your display name, your language and the time of registration and last sign-in. While you are signed in, we also store your collection (set numbers, quantities, “built” and when you added them) with your account so you can use it on all your devices; a collection you created in this browser before signing in is added to your account. Without signing in, the collection stays in your browser only. To confirm your address (double opt-in) we send you a link; when you click it, we store the time, an irreversible hash of your IP address, your browser identifier (user agent) and the version of the consent text as proof. Confirmation and password reset links are only stored as hashes; they are valid for 48 hours or 60 minutes respectively and work once. For signing in we set technically necessary cookies (session, "stay signed in"). To prevent abuse we briefly count sign-in attempts per hash of your IP address. The legal basis is Art. 6(1)(b) GDPR (user agreement) or Art. 6(1)(f) GDPR (security). Optionally you store an avatar that you put together from eight preset colours as a brick pattern (8 × 8 studs); no photo is uploaded for it. If you change your email address, we send a confirmation link to the new address (valid for 24 hours, stored only as a hash) and, after the change, a notice to your previous address. If the terms of use change materially, we inform you by email and record that and when we sent you this information. We keep the data until you delete your account.

Data export and account deletion: In your account under “Privacy & data” you can download all data stored for your account as a file at any time (machine-readable JSON, your collection also as CSV) and delete your account yourself. To confirm, you enter your password; if you only sign in with Google or Apple, we email you a link instead (valid for 60 minutes). On deletion we immediately remove your account with profile, collection, lists, mosaics and settings, the links to Google/Apple, open links, your sessions and the delivery events stored for your address, and send you a confirmation by email. You can also request deletion by emailing [email protected].

Sign-in security: You can also sign in with a passkey or a sign-in link by email and protect your account with two-step sign-in (authenticator app). For a passkey we only store the public key, an identifier of the key, the name you chose and when it was added and last used; the private key and your biometric data (fingerprint, face) stay on your device and never reach us. Sign-in links are stored only as a hash; they are valid for 15 minutes and work once. For two-step sign-in we store the secret key encrypted and the recovery codes only as a hash. So that you can see your signed-in devices and sign them out one by one, we set the technically necessary cookie bricoria_device (random identifier, up to 400 days) when you sign in and store a hash of this identifier, the browser identifier (user agent), when it was first and last used and a hash of this browser’s “stay signed in” key. We do not determine your location for this. If you sign in with a browser we don’t know for your account yet, we send you a notice email. The legal basis is Art. 6(1)(b) GDPR (user agreement) and Art. 6(1)(f) GDPR (security of your account). We delete this data with your account; you can remove a passkey or sign out a device yourself at any time, and devices not used for 400 days are deleted automatically.

Lists, saved mosaics and favourite themes. Without an account we store none of this: lists (wishlist, missing-parts lists, your own lists) stay in your browser’s local storage, saved mosaics in its database (IndexedDB). When you are signed in, we store your lists (set or part numbers, colour, quantity, time), your saved mosaics and your favourite themes with your account so you have them on all devices and later in the app; when you sign in, we take over what you saved in this browser without an account. Of a mosaic we only store the brick grid (the colour of every stud), size, palette, parts count, your settings in the tool and a preview image that our server creates itself from this grid. We never store your photo – it does not leave your device, not even with an account. The grid is a strongly coarsened, pixelated version of the image area; with large mosaics you may be able to tell what the photo showed. Only you can see your mosaics and previews (after signing in, not public and not in our CDN’s cache). If you turn on “New sets in my favourite themes”, we send you at most one email a day after the nightly catalogue update with new sets in your favourite themes (sent via Brevo, see below); for this we store when you gave your consent and when we last sent one. You can unsubscribe anytime in your account or with one click in every email. The legal basis is Art. 6(1)(b) GDPR (contract of use), for the emails Art. 6(1)(a) GDPR (consent). We delete the data when you delete it or your account; it is included in your account’s data export.

14. Signing in with Google or Apple

Instead of email and password you can also sign in with your Google or Apple account. This is optional. If you choose it, you are redirected to Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) or Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) and sign in there. The provider then sends us a unique identifier of your account, your email address as confirmed by the provider and, if available, your name. With Apple you can hide your address; we then receive a forwarding address created by Apple (…@privaterelay.appleid.com). We store the identifier, the provider and the email address with your account; no confirmation email is needed then. If a confirmed account with this address already exists, we link it. We do not receive passwords or any other data from your Google or Apple account. For the duration of the sign-in (at most 10 minutes) we set a technically necessary cookie (bricoria_oauth) to prevent abuse. What Google or Apple process during sign-in is governed by their privacy policies (Google, Apple); this may involve a transfer to the USA, and both providers are certified under the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(b) GDPR (user agreement). We delete the link together with your account.

15. Sending emails via Brevo

We send transactional emails (confirmation link, password reset, security notices, confirmation of a new address, account deletion, notices about changed terms of use) and messages from the contact form via Brevo (Brevo SAS, 106 boulevard Haussmann, 75008 Paris, France) as a processor. Brevo processes your email address, the content of the email and technical delivery data (e.g. time, delivery status). If Brevo reports that an email could not be delivered or was marked as spam, we store this event and send no further emails to this address. We do not send newsletters or advertising emails, and we do not transfer contact lists to Brevo. The legal basis is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR (reliable delivery).

16. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection at any time (Art. 15–21 GDPR). You can withdraw consent with effect for the future (Art. 7(3) GDPR). With an account you can also download your data and delete your account yourself (see section 13). Otherwise please contact [email protected].

17. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.

18. Changes

When we introduce new features (such as syncing your collection or the Bricoria app), we will update this privacy policy. The version published here applies.