Privacy Notice
Information pursuant to Articles 13 and 14 GDPR · Updated July 30, 2026
1. Controller
The controller within the meaning of the GDPR is:
Lukas Elias Rehfus
Derfflingerstraße 21, 10785 Berlin
Email: support@reconstrura.com
2. Key facts
- Your recordings never leave your device. Frame extraction, masking, reconstruction, and training all run locally on your GPU. No video or image material is uploaded.
- This website uses no cookies, employs no third-party analytics or tracking services, and loads no content from third-party servers (including CDN fonts or embeds). Installer-link starts are counted only as anonymous daily totals without a visitor identifier. The website therefore does not need a cookie banner.
- The software makes narrowly scoped network requests for trials, licensing, updates, the benchmark catalogue and optional benchmark captures, and—only if you enable it in Settings—product analytics. On first launch it may download the GPU runtime, managed Python, dependencies, and core models once (approximately 2.4–4.0 GB, depending on the operating system and GPU compatibility tier); the unpacked runtime uses approximately 6–7 GB. Segmentation models are downloaded when masking is first used. These downloads may connect directly to GitHub, PyPI/Fastly, download.pytorch.org, and Hugging Face. Sections 3 and 7 provide details.
- EULA acceptance in an installer or the desktop app is recorded locally with the EULA version and exact content hash. That receipt is not sent to us. Checkout acceptance is separately recorded by Polar as part of the order.
3. Processing activities
| Processing | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Raw server logs (website, downloads, API) | IP address, time, requested resource, user agent | Operational security and the prevention of faults and abuse | Article 6(1)(f) GDPR (legitimate interests) | Approximately 14 days, then deleted |
| Installer download counter | UTC date, requested distribution channel, and an integer counter. No cookie, visitor ID, or IP address is stored with the counter. | Measuring release demand and the relative use of the available distribution formats | The counter is anonymous aggregate data. The technically separate raw request log is processed under Article 6(1)(f) GDPR as described above. | Aggregate counters may be retained for long-term release comparisons; raw request logs are deleted after approximately 14 days |
| Optional product analytics | A pseudonymous token derived from a random local installation UUID and re-HMACed on the server; consent version; first and latest contact; app version and install channel; broad operating system family; exact selected NVIDIA GPU product model; and total VRAM and system-RAM capacities, rounded on the device to the nearest GiB. Daily activity uses a day-specific token. GPU serial numbers and UUIDs, CPU names, and other raw hardware IDs are never sent. Project data, filenames, photos, videos, names, and email addresses are never included. Request access logging is disabled for this endpoint end-to-end. | Understanding active installations, platform and hardware support needs, and release adoption | Your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. The setting is off by default and is not required to use the software. | No more than 13 months after the latest heartbeat. Turning the setting off requests immediate deletion of that installation's active and daily analytics rows; if offline, the request is retried later and on the next launch. Backup expiry is described below. |
| Application security log | Event type and time; a pseudonymized HMAC hash of the IP address for network requests; depending on the event, the associated trial, license, activation, or order ID and limited event details. For manually issued support keys, this may include the supplied email address. | Detecting and investigating abuse, failed activations, invalid webhooks, and security-relevant events, and handling support cases. Ambiguous device matches create a random support reference with the already-hashed evidence and candidate record IDs; they do not change a trial or activation automatically. | Article 6(1)(f) GDPR (operational and abuse prevention); Article 6(1)(b) GDPR for contract-related events | 90 days, then automatically deleted |
| Free trial | Pseudonymized, purpose-separated HMAC hashes of the firmware system UUID (when available), Windows MachineGuid or Linux machine-id, and a random Reconstrura installation UUID. On Windows, the system-volume serial is also hashed and used only as a weak collision warning, never by itself to identify a device. Raw identifiers never leave the device. Until 1 December 2026, a migration bridge also sends the older hashes. Those bridge hashes are identical in trial and paid-license requests, so the two records can temporarily be linked. The server stops accepting and deletes paid-license copies at that cutoff. A trial-only lookup remains through November 2028 solely so a pre-cutoff expired trial cannot reset after an update; it is not stored for new trials, cannot be joined to a paid record, and is then deleted. We also process platform, app version, and trial period. | Providing the free trial and enforcing one trial per device, including after reinstallation. The usage conditions are stated in the EULA. | Article 6(1)(f) GDPR; the trial starts only after active confirmation accompanied by an in-app notice. Access to device information is strictly necessary to provide the expressly requested trial (Section 25(2)(2) TDDDG). | 24 months from trial start, then automatically deleted |
| Purchase and license activation | License key, order number, email address supplied by Polar, the versioned EULA checkbox value made available with the Polar order, hashed identifiers for activated devices (maximum three), and device label. The temporary legacy-hash migration bridge and its 1 December 2026 deletion described under “Free trial” also applies to activation. On the purchase-success page, the fresh, high-entropy Polar checkout ID is used in memory as a short-lived key-recovery capability; it is removed from the address bar and is neither stored in application data nor written to our standard website access log. | Providing and managing the purchased license, including documenting EULA acceptance, activation, device limits, key recovery, and refund matching | Article 6(1)(b) GDPR (performance of a contract); Article 6(1)(f) GDPR for establishing, exercising, or defending legal claims concerning the acceptance record | For the duration of the license plus statutory retention periods |
| Refund request form | Name, Polar purchase email, order or license identification, a keyed hash of the short-lived verification code, pseudonymous IP hash, the withdrawal declaration and timestamp, refund amount/status/identifier, delivery status, and case reference | Proving that the requester controls the email address on the Polar order when automatic refund processing is requested, recording declarations even without that optional proof, submitting only verified eligible refunds through Polar's API, sending the required receipt, handling exceptions, and documenting receipt | Article 6(1)(b) and (c) GDPR (contract and legal obligation); Article 6(1)(f) GDPR for establishing, exercising, or defending legal claims | Verification-challenge records: no more than 7 days. The declaration and refund record: until resolved and thereafter only for applicable statutory retention and limitation periods |
| Contributed datasets | The image, video, and capture files you choose to upload through a personal invite link, together with their file names and sizes, the time of upload, any note you write, the accepted contribution-terms revision, and a hashed IP address. Captures can themselves contain personal data — recognizable people, vehicles, premises, and embedded GPS coordinates or device identifiers — which is why uploading is never automatic and only ever happens on a link you were sent and a set you selected | Reproducing and diagnosing a reconstruction defect you reported, and regression-testing the fix. Contributed datasets are never published, never used in marketing without separate written permission, and never shared with a third party or any external service | Article 6(1)(f) GDPR (our legitimate interest, and yours, in fixing a defect you encountered), on the basis of your explicit decision to send the material | Normally days: a set is copied to a workstation and deleted from the server as soon as it has been verified. In any case no more than 60 days, and an upload that was started but never completed is discarded after 7 days. You can request deletion at any time, for any reason or none, by quoting the upload reference shown when the transfer finished |
| Support correspondence | Email address, addressing data, message content, attachments, and the technical delivery metadata generated by email | Answering support, licensing, privacy, and purchase questions | Article 6(1)(b) GDPR for contract-related support; Article 6(1)(f) GDPR for other correspondence and for establishing, exercising, or defending legal claims; Article 6(1)(c) where a legal obligation applies | Until the request is resolved, then only as long as needed for follow-up and applicable statutory retention or limitation periods |
| License revalidation | License ID, hashed device identifier, and IP address as technically required | Periodic license-status checks, such as revocation after a refund | Article 6(1)(b) GDPR | Raw server log: approximately 14 days; pseudonymized security event: 90 days |
| Update check | IP address, app version, and platform when retrieving a static feed file | Notifying you about available updates | Article 6(1)(f) GDPR | Raw server log: approximately 14 days |
| Benchmark catalogue and capture | IP address, time, user agent, and requested catalogue or capture file. Benchmark results, projects, and hardware measurements remain local and are not uploaded. | Showing the current catalogue when the Benchmark settings are opened and, only after your confirmation, downloading the selected benchmark capture | Article 6(1)(b) GDPR (providing a requested software feature); Article 6(1)(f) GDPR for a secure, current download service | Our raw request log is deleted after approximately 14 days. The downloaded capture and local results remain on your device until you delete them. |
| Debian/Ubuntu APT updates | IP address, time, requested repository file, and HTTP user agent, which can include package-manager, platform, and architecture information | The .deb registers our signed APT source. Your
package manager later contacts it during its normal refreshes so
Reconstrura can receive security and product updates. The source
can be disabled in /etc/default/reconstrura or
removed by the system administrator. |
Article 6(1)(b) GDPR (maintaining the software); Article 6(1)(f) GDPR (secure and reliable update delivery) | Raw request log: approximately 14 days |
| Runtime and model downloads (once per component) | IP address, user agent, and requested file, as technically required. Depending on the component, the recipient is GitHub, PyPI and its Fastly delivery infrastructure, download.pytorch.org, or Hugging Face. | Downloading managed Python, the GPU runtime, dependencies, and core model/code assets on first launch (approximately 2.4–4.0 GB, depending on the operating system and GPU compatibility tier), and segmentation models when masking is first used | Article 6(1)(b) GDPR (provision of the software) | Not stored by us; third-party log data is governed by each provider's privacy notice |
Backups: The license database is backed up daily. Backups are retained for no more than 30 days and are used solely for recovery after a failure. Data deleted from the active system may therefore remain in an access-restricted backup until that period expires. Before a restored database returns to service, the deletion periods above are applied again.
Local desktop storage: Reconstrura stores settings, licensing/trial state, caches, and an EULA receipt containing the agreement version, content hash, acceptance channel, and normally the acceptance time. This information remains on your device except for the network processing expressly described above. Storage needed to provide the software you request relies on Section 25(2)(2) TDDDG. Any use of the random local installation identifier for optional analytics occurs only with your consent under Section 25(1) TDDDG. The same identifier can be used separately for strictly necessary trial and licensing functions. Deleting the EULA receipt causes Reconstrura to ask for acceptance again.
4. Payment processing by Polar (independent controller)
Purchases are processed by Polar Software Inc. as the Merchant of Record. The purchase button on this website is a plain link to Polar's hosted checkout. Polar begins processing your data—such as your name, email address, payment and billing details, and VAT calculation—only when you open that page, acting as an independent controller. See Polar's privacy notice. Polar also stores the required checkout checkbox under a version-and-content-specific field key. We can view that boolean with the order to document which EULA was accepted. We receive the other data required to manage your license: order number, email address, license key, and refund status. If you use the refund request form, we compare the address you enter with Polar's order record. The code is optional for submitting a declaration, but an automatic refund is attempted only after a valid code proves control of the address on the order. A declaration without that proof is recorded, marked for manual ownership review, and cannot trigger Polar's Refunds API. Reconstrura support receives a private operational email copy only for manual-review cases and decides whether further action is needed.
5. Article 11 GDPR notice for pseudonymous identifiers
We cannot associate hashed trial or optional analytics identifiers with a natural person; we store no name, email address, or raw hardware identifier for those purposes. We therefore generally cannot link your identity to such a record when responding to access or other data-subject requests (Article 11(2) GDPR). Optional analytics can be erased directly by switching the setting off on the relevant installation.
6. No website cookies, tracking, or third-party page content
This website neither stores nor reads cookies or comparable identifiers on your device, so no consent banner is required under Section 25 TDDDG. Our own server delivers every page resource, including fonts, scripts, and graphics. Links to Polar, Discord, and other external sites make no request to those providers unless you choose to open them. Optional analytics in the installed desktop software is separate from the website and runs only after the in-app consent setting is enabled.
7. Recipients and international transfers
- netcup GmbH hosts the website, API, downloads, and database in Germany under a data-processing agreement pursuant to Article 28 GDPR.
- Zoho Mail hosts our support mailbox and processes addressing, correspondence, verification codes, and receipts. The account uses Zoho's EU service region. Zoho describes limited international access and its Standard Contractual Clause safeguards in its privacy policy.
- Polar Software Inc. processes checkout, payment, EULA-checkbox, and refund data as an independent controller and may transfer data to third countries, particularly the United States. Its privacy notice describes its recipients and safeguards. The refund form submits refund and case metadata to Polar because Polar is the seller; it never emails Polar support automatically.
- For runtime and model retrieval, your device connects directly to GitHub, PyPI and Fastly, the PyTorch/Linux Foundation infrastructure, and Hugging Face. Those providers receive the connection data needed to deliver the requested files and govern their own logs under the linked notices.
- Discord is optional and is contacted only if you open the community link. Discord then acts under its own privacy policy.
Several of these independent providers are based in, or may process data in, countries outside the EEA, especially the United States. The linked notices explain the relevant provider's transfer locations and mechanisms. No recording, image, project, benchmark result, or filename is included in these download requests.
8. Your rights
You have the following rights regarding your personal data:
- Access (Article 15 GDPR), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), and data portability (Article 20);
- Objection (Article 21 GDPR): You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR;
- You may withdraw product-analytics consent at any time in Settings, without affecting the lawfulness of processing before withdrawal;
- Lodging a complaint with a data-protection supervisory authority, such as our competent state authority, the Berlin Commissioner for Data Protection and Freedom of Information.
Contact for all privacy matters: support@reconstrura.com
9. Requirement to provide data
Neither law nor contract requires you to provide optional product analytics, and refusing it has no effect on the software. A trial cannot start without the hashed device identifier, and a license cannot be provided without the order and activation data. Purchasing requires the checkout data requested by Polar and acceptance of the linked EULA. Benchmark use, Discord, and direct support contact are optional. Runtime and model connection data is technically necessary only when the required component is not already bundled or cached.
10. Automated licensing and access decisions
Trial and license access is decided automatically by deterministic checks: signed trial or license status, expiry, the pseudonymous device match, the three-device limit, and any refund or revocation status. The result can allow or block use of the software; it is not used to profile you and never examines your recordings or projects. Contract-related automation is necessary to provide and enforce the purchased license (Article 22(2)(a) GDPR where Article 22 applies); trial-abuse prevention relies on the legitimate interest described above. You may contact support@reconstrura.com to contest a result, explain your circumstances, and request human review.