Privacy Policy
1. Controller
The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is the operator of this site — an individual in Germany running the project privately and non-commercially. The operator participates anonymously; postal contact and legal service are handled through a contact channel listed in the site footer.
There is no designated data protection officer; the project does not meet the thresholds of Art. 37 GDPR / § 38 BDSG.
2. Summary
This site has no user accounts, no analytics, no advertising, no tracking pixels, no third-party embeds and no profiling. It collects the minimum needed to run a shared canvas fairly and keep bots out. Concretely: an anonymous session cookie, your IP address held only in memory for rate-limiting, a Cloudflare bot check, and your text prompt.
Important: your prompt text is public. Every submission
that passes automated content moderation is stored and displayed to all visitors in a live
feed on this site, attributed to a short anonymous session handle such as
anon-x4f2. Prompts rejected by moderation are not stored and never shown.
Whatever you type into the prompt box is published as written, so
never enter personal information about yourself or anyone else. The
handle is a random identifier — it carries no name, account or contact detail — but any
personal data you put into the prompt yourself will be visible to everyone.
Because no analytics or marketing cookies are used, there is no cookie consent banner.
3. What is processed, why, and on what legal basis
3.1 Anonymous session cookie
When you first interact with the canvas, a cookie is set containing a randomly generated, signed session identifier. It contains no name, no email address, no account and no profile — it exists solely to enforce “one submission per session per round” and to show you the result of your own submission.
- Purpose: fairness of the round lottery, abuse prevention, delivering the function you requested.
- Legal basis: § 25(2) no. 2 TDDDG (TTDSG) — strictly necessary to provide the service you explicitly requested; therefore no consent is required. For the processing of the identifier itself: Art. 6(1)(f) GDPR (legitimate interest in a functioning, non-manipulable art experiment), and Art. 6(1)(b) GDPR where you actively participate.
- Storage duration: 4 days (the event window plus a short buffer).
3.2 IP address (transient, never stored)
Your IP address is visible to the server when your browser makes a request, as with any website. It is used only in volatile memory, for the duration of a round, to count submissions per network and block flooding. It is never written to a database, never written to a log file, and never persisted in any form; the in-memory counters are discarded each round.
- Purpose: abuse prevention, rate-limiting, protecting a fixed generation budget from being drained.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in the security, integrity and availability of the service.
- Storage duration: none (transient, cleared per round).
Note that the hosting provider (see section 4) processes connection data, including IP addresses, independently at the network level for delivery and security purposes.
3.3 Cloudflare Turnstile (bot check)
Before a submission is accepted, a Cloudflare Turnstile challenge runs in your browser. Turnstile is a privacy-oriented alternative to a CAPTCHA: it evaluates signals from the browser environment (such as browser characteristics and interaction behaviour) to decide whether the request comes from a human, and issues a single-use token that the server verifies. It usually requires no interaction from you. According to Cloudflare, Turnstile does not use the data for advertising or cross-site tracking. Loading the widget transmits your IP address and browser data to Cloudflare.
- Purpose: blocking automated submissions and scripted abuse.
- Legal basis: Art. 6(1)(f) GDPR — legitimate interest in preventing abuse; § 25(2) no. 2 TDDDG for any strictly necessary access to your device.
- Recipient: Cloudflare, Inc. / Cloudflare Germany GmbH, as processor (see section 4).
3.4 Your prompt text — stored and published
The text prompt you submit (maximum 500 characters) is first checked by automated content
moderation. If it is rejected, it is discarded immediately and is neither stored nor shown
to anyone. If it passes, it is stored and published: displayed to all
visitors in the live submission feed on this site, next to a short anonymous session handle
such as anon-x4f2. This applies to every accepted submission,
not only to those that win a round. If your submission wins the round lottery, the prompt
is additionally sent to the AI provider to generate the image (see section 4).
- Purpose: the feed is part of the artwork — it makes the collective process of the experiment visible in real time and preserves it in the record used for the timelapse film. The stored text also serves deduplication and abuse detection.
- Legal basis: Art. 6(1)(b) GDPR (carrying out the participation you initiated — publication of the prompt is the service you requested by submitting it) and Art. 6(1)(f) GDPR (the operator's legitimate interest in running, documenting and archiving the experiment and in preventing abuse). By submitting, you accept the Terms of Use, which set out the publication expressly.
- Storage duration: for the duration of the project and thereafter for archival and timelapse purposes — the same as for the generated images.
- Visibility: the feed is public and unauthenticated. Prompts can be read, copied, screenshotted, quoted and archived by anyone, including search engines and third-party archives, and the operator cannot recall copies made in that way.
- Please do not put personal data in your prompt. Prompts are free text, published verbatim and also sent to a third-party AI provider. Do not include your name, anyone else's name, contact details, or any information about identifiable people.
Only the anonymous session handle is shown with a prompt. It is derived from the random session identifier in your cookie and contains no name, email address or account. It does, however, group together the prompts submitted from the same browser session during the event, so avoid writing anything across several prompts that could identify you in combination.
3.5 Shapes and generated images
The shape you draw and the image the AI generates inside it are — like the prompts — public by design. They are painted onto a shared canvas that anyone can view, screenshot and share, they form part of a collective artwork, and they are recorded in an event log so that a timelapse film and other derivative works can be produced after the event. They are not linked to any name and cannot be traced back to you by visitors; the anonymous session handle described in section 3.4 may be shown alongside them, for example in the result notification.
- Legal basis: Art. 6(1)(b) and Art. 6(1)(f) GDPR — realising the artwork you chose to contribute to, and the operator's interest in documenting and archiving the experiment.
3.6 What is not done
- No analytics or statistics tools (no Google Analytics, no self-hosted alternative).
- No advertising, no ad networks, no remarketing.
- No cross-site tracking, fingerprinting for tracking purposes, or profiling.
- No user accounts, registration, newsletter or email collection.
- No automated decision-making with legal effect within the meaning of Art. 22 GDPR (the round lottery is a random draw and has no legal or similarly significant effect).
- No sale or commercial sharing of personal data.
- No attempt to link a session handle to a real identity, and no de-anonymisation of participants.
- No storage or publication of prompts that automated moderation rejects — those are discarded on the spot.
This list is about tracking and marketing, not about secrecy of your submission: the prompts, shapes and images you contribute are published, as described in sections 3.4 and 3.5.
4. Recipients and processors
| Recipient | Role & data |
|---|---|
| Cloudflare (Workers, R2, D1, Turnstile) |
Hosting, edge delivery, object and database storage, and the bot check. Processes connection data (including IP address), the session cookie, stored images, stored prompt texts and event-log entries. Acts as processor under Art. 28 GDPR on the basis of Cloudflare's data processing addendum. |
| OpenAI (image generation & moderation) |
Receives the prompt text together with a fixed system prompt and the shape mask, in order to run moderation and generate the image. Receives no cookie, no session identifier and no direct identifier of you. Established in the USA (OpenAI, L.P. / OpenAI Ireland Ltd. for EEA users). |
| Google (Gemini image models — testing only) |
May be used as an alternative image-generation provider during testing or as a fallback. Same data as above: prompt text and shape mask only. |
No other recipients in the sense of contracted processing. Data is disclosed to public authorities only where legally required. Beyond this, note that the prompt feed and the canvas are public: everyone on the internet can read the prompts you submit — that is the point of the project, not a transfer to a processor.
5. Transfers to third countries
Processing may involve transfers to the United States, in particular to Cloudflare, Inc. and to the AI provider used for generation. These transfers are safeguarded by the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures (transport encryption, data minimisation), and — where the recipient is certified — by the EU–US Data Privacy Framework adequacy decision under Art. 45 GDPR.
Despite these safeguards, a residual risk remains that US authorities may access data. Because the only content transferred to the AI provider is your prompt text and the shape you drew — the same prompt text that is in any case published openly on this site — you can eliminate this risk for yourself simply by not including personal information in your prompt.
6. Retention
| Data | Retained |
|---|---|
| Session cookie / session identifier | 4 days |
| IP address | Not retained — in memory only, cleared each round |
| Prompt text — rejected by moderation | Not retained — discarded immediately, never stored or shown |
| Prompt text — accepted, published in the feed | Duration of the project and thereafter for archival and timelapse purposes, as part of the artwork |
| Anonymous session handle shown with a prompt | Same as the published prompt it belongs to |
| Generated images, shapes, event log | Duration of the project and thereafter for archival and timelapse purposes, as part of the artwork |
| Turnstile token hashes | Duration of the current round only |
Because the prompts, images, shapes and event log constitute the artwork itself and the source material for the timelapse film, they are kept indefinitely for archival and artistic purposes. They contain no identifiers assigned by the operator beyond the random session handle — but a published prompt contains whatever text its author typed, which is why you are asked not to put personal data there.
7. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — confirmation of whether data about you is processed and a copy of it;
- Rectification (Art. 16) — correction of inaccurate data;
- Erasure (Art. 17) — deletion of your data;
- Restriction of processing (Art. 18);
- Data portability (Art. 20) — receipt of data you provided in a machine-readable format;
- Objection (Art. 21) — to object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR;
- Withdrawal of consent (Art. 7(3)) — where processing exceptionally rests on consent, with effect for the future;
- Complaint to a supervisory authority (Art. 77) — in particular in the EU Member State of your residence, place of work or the place of the alleged infringement.
Requests can be sent via the contact channel listed in the site footer.
An important practical limitation: the project deliberately stores almost nothing that could identify you. There is no account, and IP addresses are never persisted. What is stored — the prompt text, the shape, the image and the random session handle — normally cannot be linked to you as an individual, so under Art. 11 GDPR the operator is not obliged to obtain additional information solely in order to identify you. If you want to exercise a right in relation to a specific submission, please identify it precisely: the session handle shown with it and the approximate time, or the exact wording of the prompt. You can delete the session cookie yourself at any time through your browser settings; it expires on its own after 4 days.
Removing a published prompt. If a prompt in the feed contains personal data — yours or someone else's — or should not be there for any other reason, report it via the contact channel listed in the site footer and it will be reviewed and, where appropriate, deleted. The same applies to a generated area on the canvas: describe where and when it was drawn. Note two limits: the Terms of Use reserve the right to remove or overpaint any content in any case, and content that was publicly visible may already have been copied, quoted or archived by third parties, which the operator cannot reverse.
8. Security
All traffic is served exclusively over HTTPS. The session identifier is cryptographically signed to prevent tampering, and only a short derived handle — never the full identifier — is shown publicly. Prompts pass automated content moderation before they are stored or displayed. The service runs on Cloudflare's edge platform with its standard technical and organisational protections. Please keep in mind that the prompt feed is intentionally public: security measures protect the system, they do not make your submission private.
9. Changes
This policy may be updated if the technical setup changes — for example if the image provider changes. The version published on this page is the current one.
10. Contact
For privacy questions, rights requests and data protection matters, please use the contact channel listed in the site footer.