Privacy & Cookies
Last updated: 2026-08-17
This page is pending legal review before the EU launch (launch gate G3/G4).
Dlubal CALC processes personal data in three strictly separated flows: product analytics (only with your consent), abuse protection for the free quota (necessary), and your account including the customer record in our CRM (contract). No identifier is shared between these flows.
Controller & contact
The controller within the meaning of the GDPR is Dlubal Software GmbH, Am Zellweg 2, 93464 Tiefenbach, Germany. For any privacy request — access, rectification, erasure, objection — contact our data protection officer at [email protected]. The competent supervisory authority is the Bavarian State Office for Data Protection Supervision (BayLDA), Ansbach.
Necessary cookies & storage
We use cookies that are required to operate the app: sign-in session cookies, the cookie that stores your consent decision (12 months), an anonymous session id, and a random device token (up to 400 days) used solely to enforce the free quota. These are first-party cookies, contain no tracking identifiers and are not shared with third parties. Legal basis: §25(2) TDDDG and Art. 6(1)(b), (f) GDPR.
Abuse protection for the free plan
To keep the free plan available, we enforce the free quota per device, not per email address. Primary mechanism: the random device token above. Only when concrete risk signals appear (e.g. the free quota is nearly exhausted, an account switch on a known device, or a deleted device token with prior usage) we additionally compute a device fingerprint. The raw fingerprint never leaves the processing step: we store only a keyed pseudonym (HMAC), delete it after 180 days of inactivity, and never use it for analytics, advertising or marketing. A match never blocks you automatically — it can only trigger an additional verification step. Legal basis: legitimate interest, Art. 6(1)(f) GDPR; the necessity assessment under §25(2) TDDDG is documented internally.
Product analytics (Microsoft Clarity)
Only if you consent, we load Microsoft Clarity to understand how the app is used (session replays, heatmaps). All text and media content — chats, project and file names, profile data — is masked in recordings. We do not pass your email, account id or any device identifier to Clarity; advertising storage is permanently disabled. Recipient: Microsoft Ireland Operations Ltd.; transfers to the USA are safeguarded by the EU standard contractual clauses and Microsoft’s EU Data Boundary commitments. Retention at Microsoft is up to 30 days for recordings and up to 13 months for aggregated usage data. Legal basis: consent, Art. 6(1)(a) GDPR — you can withdraw it at any time in the cookie settings; the app then stops all Clarity processing and reloads. Note: cookies that Clarity set under the clarity.ms domain can technically not be deleted by us; the withdrawal signal stops their use.
Account & CRM record
After you sign in with a verified email address, we link your CALC account server-side to a contact record in our customer-relationship system, or create one, so that licensing, support and billing reference one consistent record. This happens exclusively between our servers; the email address used for it is never part of analytics or abuse identifiers. Account management and possible marketing communication are separate processing activities — marketing, if any, has its own legal basis and opt-out. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(f) GDPR (consistent customer management).
AI analysis of your chats
When a chat session has finished, we have it analysed automatically by an AI model in order to find answers that did not hold up technically and places where the product got in the way. Analysed are the text of the messages, your ratings and written feedback, and which tools were used; uploaded files, images and drawings are not analysed. The results contain verbatim quotes from your messages. They are visible only to administrators at Dlubal Software and are passed neither to third parties nor into our CRM. The analysis is carried out by the same AI provider that already processes your chats (currently DeepSeek; alternatively z.ai or Anthropic) — it opens no new transfer path, but it is a separate purpose. An analysis is deleted together with the chat it belongs to; there is no separate retention period. Mood analysis — how your mood developed over the course of a session, and whether frustration was directed at the product or at the task — is a separate purpose and is switched off: it runs only if you switch it on yourself under Settings → Personalisation. Switching it off again ends it and deletes the frustration signals already derived from your sessions. A commercial evaluation (indications of need and interest for our sales team) is covered by the same switch, has its own legal basis, and is currently not active. Legal basis: Art. 6(1)(f) GDPR (improving our product and its answers); for the mood analysis, your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time. You can object at any time under Settings → Personalisation: the analysis then stops for the future and the analyses already created for your sessions, including the stored quotes, are deleted.
Bot protection (Cloudflare Turnstile)
The registration form uses Cloudflare Turnstile to block automated sign-ups. Turnstile evaluates technical browser signals; we receive only a pass/fail token. Recipient: Cloudflare, Inc. under EU standard contractual clauses. Legal basis: legitimate interest, Art. 6(1)(f) GDPR.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to withdraw any consent at any time with effect for the future. You can lodge a complaint with a supervisory authority, in particular in the member state of your residence.