Privacy policy

The German version of this policy is the authoritative one. Where the versions differ, the German text applies.

This is a private, access-restricted website. This page explains what personal data is processed when you visit it, why, and how long it is kept.

Who is responsible

The controller within the meaning of Art. 4(7) GDPR is:

Johann Tessarek
Anna-Wöbse-Straße 2
27283 Verden
Deutschland

For any question about your data, or to exercise the rights below, write to the postal address above.

Server logs

Every request to this site is recorded by the web server. The record contains a shortened IP address — the last part is removed before anything is written, so the address cannot be traced back to you — together with the time, the page requested and the response status. No browser identification and no referring page is stored. The legal basis is Art. 6(1)(f) GDPR, the legitimate interest in operating the site securely. These records are kept for a short period and then deleted.

Signing in, and cookies

Reading this site requires a personal account. Signing in is handled by an identity service the controller runs themselves (see the next section). Once you have signed in, a cookie is placed in your browser holding a random identifier, and the corresponding entry on the server records when the session began, which language you chose, an internal identifier for your account and the role assigned to you. Your name and email address are not stored there. A second cookie remembers your language so that pages open in it. Both are strictly necessary for an access-restricted site to work at all, so the legal basis is Art. 6(1)(f) GDPR. The session ends when you log out, or at the latest 14 days after it was last used. No analytics, tracking, advertising or third-party cookies are used anywhere on this site.

The contact form

If you use the contact form, the name, email address and message you enter are stored on the server so that your request can be answered. The legal basis is your consent under Art. 6(1)(a) GDPR, which you give with the checkbox on the form and may withdraw at any time. Your message is not forwarded by email to anyone; it is read on this site by the person who administers it. To limit misuse, the time the form page was opened and a shortened, irreversibly hashed form of your IP address are held briefly. Withdrawing consent does not affect processing that already took place.

Your message is deleted 30 days after it has been dealt with — that is, once access has been granted or declined. A message that nobody has dealt with is deleted 90 days after it arrived, whichever comes first. Deletion is automatic and permanent.

Named accounts

Everyone who uses this site has a personal account. Only a display name and an email address are collected; nothing further is asked for. Accounts are created by the administrator alone, and there is no way to register. This website keeps a local copy of the display name, email address and role only for people who are allowed to contribute; it is needed so that comments, changes and uploaded pictures can be attributed to a person. Anyone who only reads is not stored here. The legal basis is Art. 6(1)(f) GDPR.

The identity service, and passwords

Signing in is handled by software (Keycloak) that the controller runs on their own hardware. No single sign-on provider and no other third party is involved, and no sign-in data is passed to anyone. It stores a username, a display name, an email address, and the password only as a cryptographic hash. This website itself never stores a password and never checks one. To protect against automated guessing, failed sign-ins are counted for a time and the account is locked temporarily; it is never locked permanently. Sign-in sessions held by the identity service end at the latest seven days after they were last used, and in any case after 30 days. No log is kept of who signed in and when. Account data is stored for as long as the account exists. The legal basis is Art. 6(1)(f) GDPR.

The family tree

The tree holds names, dates and places for family members, including living ones. A living person who has not agreed to be shown appears by first name and initial only, with no year and no place — that is the default, and it applies until they say otherwise. The whole tree is reachable only after signing in, and no part of it is publicly reachable. The legal basis is Art. 6(1)(f) GDPR: the family's interest in its own history, weighed against the interests of the people recorded, which is what the access restriction and the default above are for.

Changes to the tree

The tree is maintained by the site administrator and is stored in a database rather than in the site's source code. Every change records which record was changed, what it then said, who changed it and when. Relatives with permission to contribute may propose a correction to a single field; a proposal records who made it, what they proposed and the reason they gave. Proposals are reviewed by the administrator before anything is published, which is deliberate: a proposal about a living person is a statement about that person, and accepting it shows it to every signed-in family member. This record of changes is kept for as long as the entry it belongs to.

Removal from the tree

Write to the address below and your entry will be removed, together with the record of changes to it. You may also ask for less than removal — that your entry be reduced to a first name and initial, which is what the site does by default for living people. One limitation has to be stated plainly rather than glossed over: until 2026 the tree was kept in the site's version control, and entries from that period remain in its history, which cannot be rewritten without discarding the project's entire record. Deleting an entry removes it from the site and from everything the site serves; it does not remove it from that archive. The archive is private, held by the controller, and is not published or shared.

The book

A family member is writing the family's history. Chapters are written and published by that person and can be read by every signed-in family member; drafts are visible to the author alone. Every saved version records who wrote it and when, and those versions are not deleted — the chapter's history rests on them. When an account is anonymized the version stays and the name attached to it is removed. Chapter texts are the author's own words and may mention living relatives; if something about you should not be there, write to the address below and it will be removed.

Pictures of people in the family tree

A person in the family tree may have a picture stored with their record. These are uploaded only by the person who operates this website and are held on storage inside the same infrastructure as the site itself — they are not passed to any third party and can only be retrieved after signing in. All embedded metadata is removed on upload, in particular the place and time a photograph was taken; the original file is not kept, only two reduced crops of it. No picture is shown or stored for a living person who has not explicitly agreed to be shown. The legal basis is Art. 6(1)(a) GDPR (consent), or for deceased relatives the legitimate interest in documenting the family under Art. 6(1)(f) GDPR. Consent may be withdrawn at any time, and the picture is then deleted.

Photographs and comments

Members with an account can upload photographs to the album and comment on them. A photograph is stored with a caption, a description for people who cannot see it, the name of the person who uploaded it, and the time. A comment is stored with its text, its author and the time. All of it is held on storage inside the same infrastructure as the site, is reachable only after signing in, and is passed to no third party. Embedded metadata is removed from every photograph on upload, in particular the place and time it was taken; the original file is not kept. The legal basis is Art. 6(1)(f) GDPR, the legitimate interest of a private circle in sharing its own family material. You can delete your own photographs and comments at any time and they are removed, not hidden; the person administering the site can remove any of them. If you appear in a photograph and do not wish to, ask via the contact form and it will be taken down.

Asking the archive (assistant)

On the “Ask the archive” page you can put a question in your own words and receive an answer assembled from the records on this website. What is processed is your question, the passages of the family tree and link list found for it, and the answer produced. All of this happens on servers the controller runs themselves; no cloud provider, no third-party programming interface and no other third party is involved, and no data whatsoever is passed to anyone. The language model is not trained, fine-tuned or otherwise adapted on this website's data. The legal basis is Art. 6(1)(f) GDPR.

Questions and answers are not stored. There is no conversation history, no database table for one and no retention period — each question stands alone and is gone once answered. Questions and answers are not written to log files either. The only thing recorded is how many questions have been asked in the current hour, so that one session cannot use up all the computing capacity; that counter is tied to a session identifier rather than to a person, and it expires after an hour.

The assistant sees the family tree only in the same reduced form in which it is displayed: for living people who have not explicitly consented, it does not know the surname, the years, the places or the notes. It therefore cannot name anything the site itself does not show.

An answer from the assistant is a machine's account of the archive and not part of the archive. It may be incomplete or wrong, it is stored nowhere, and it changes no record. Every answer names its sources so that the record itself can be read.

Chapters to listen to

Chapters of the book can be listened to as audio. The voice is synthetic and produced by software the controller runs on their own hardware; no speech provider, no cloud provider and no other third party is involved, and the text never leaves these servers at any point. The recording is made on the first request and then stored, so that it does not have to be computed again for every listener. It sits in the same object storage as the photographs, is likewise reachable only after signing in, and becomes obsolete as soon as the author changes the text — every version has its own recording. The legal basis is Art. 6(1)(f) GDPR.

No real person's voice is imitated. The voice used comes from a freely available speech model and belongs to nobody in the family; recordings of relatives, living or dead, are neither used nor stored for this.

Who receives your data

Your data is not sold, not shared with advertisers, and not transferred outside the European Union. The site runs on servers operated on behalf of the controller; the hosting provider acts as a processor under Art. 28 GDPR. Email that the site sends is delivered through an email provider acting as a processor, and never contains the content of your message.

Your rights

You have the right to obtain confirmation of whether your data is processed and to receive a copy of it (Art. 15), to have inaccurate data corrected (Art. 16), to have your data erased (Art. 17), to have processing restricted (Art. 18), to receive your data in a portable form (Art. 20), and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time. To exercise any of these, write to the address above.

Right to complain

If you believe your data is being processed unlawfully, you may complain to a data protection supervisory authority, in particular in the Member State of your residence, your place of work, or where the suspected infringement occurred.

Changes to this page

If what is processed here changes, this page changes with it. It carries the date it was last revised.

Last updated: August 4, 2026