Legal Information for the Public Beta
This page contains the terms of use and the privacy policy for evaluating and using Hansestack during the Public Beta phase.
Terms of Use (Beta Phase)
1. Status as Test Operation (Public Beta)
Hansestack is currently provided as a free test operation (Public Beta) by a private individual (see Legal Notice). It is not a commercial offer. The service is intended for developers who wish to evaluate the system and provide feedback.
2. Disclaimer & Availability
Since the service is offered free of charge and in a testing phase, the following applies:
- Use at your own risk: The use of the API and the developer portal is strictly at the user's own risk.
- No guarantees: We make no representations or warranties regarding availability (uptime), accuracy, speed, or the completeness of the leak database. There is no Service Level Agreement (SLA).
- Limitation of liability: The operator shall not be liable for any damages, data loss, business interruptions, or lost profits arising from the use or failure of the service (except in cases of intent and gross negligence, as required by law).
3. Rate Limiting & Modifications
The operator reserves the right to modify, restrict, or completely discontinue the API, the portal, or rate limits at any time without prior notice.
Privacy Policy
We take the protection of your data seriously. As a service operated in Germany, we fully comply with the European General Data Protection Regulation (GDPR).
1. Data Minimization & k-Anonymity (Our Core Promise)
Hansestack is built on the principle of "Privacy by Design".
- No plaintext data: We never process plaintext passwords when you use our leak check API.
- Technical implementation: You only transmit the first 5 characters of a hash value (k-Anonymity concept). These prefixes do not allow us to identify your users or reverse-engineer their full passwords. We do not infer or store sensitive end-user data.
2. Processing of Account Data
To provide the developer portal and issue API keys, we process the following data belonging to you (the developer):
- Registration: Email address and, if applicable, name for account management.
- Usage data: IP address, access times, and API request volumes to prevent abuse (rate limiting) and analyze technical errors.
3. Technologies & Service Providers
We utilize the following services and infrastructure to provide our platform. All core systems are hosted in Europe (Zero Cloud Act):
- Hetzner Online GmbH (Germany): All servers (API, Portal, Reverse Proxy via Caddy) and databases operate on dedicated infrastructure in ISO 27001 certified data centers in Germany (Nuremberg/Falkenstein).
- Zitadel (Switzerland): We use Zitadel for secure Identity & Access Management (login, token generation). The servers are located in Switzerland (recognized by the EU Commission as providing an adequate level of data protection).
- Umami (Self-Hosted on Hetzner): We use Umami for strictly anonymized analytics of the portal. No cookies are set, and the data never leaves our Hetzner servers.
4. Data Processing Agreement (DPA)
During the current free Public Beta phase operated as a private project, we do not enter into formal Data Processing Agreements (DPA) pursuant to Art. 28 GDPR. We recommend using the API solely for technical evaluation purposes during this phase.
5. Your Rights
You have the right to request access to, correction of, deletion of, and portability of your personal data stored by us. To exercise these rights, please contact the email address provided in the Legal Notice.
Data Sources & Licenses
Our Leak Check API relies on aggregated databases for validation. A significant portion of our dataset is based on the Pwned Passwords database provided by Have I Been Pwned (Troy Hunt).
This data is used under the Creative Commons Attribution 4.0 International License (CC BY 4.0). We thank the HIBP community for their invaluable contribution to global IT security.