Privacy Policy
Scope
This privacy policy applies to the website at www.manasuite.com and the related application programming interface at api.manasuite.com (together, "Manasuite"). It explains, pursuant to Art. 13 GDPR, which personal data are collected, processed, and stored in that context.
Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is Jan-Hendrik Damerau. Full contact details are available in the Imprint.
Non-commercial offering
Manasuite is a private, non-commercial project. There is no newsletter and no contact form on this website. We do not use analytics tools, tracking or marketing pixels, or cookies for advertising or analytics. There is no profiling and no automated decision-making within the meaning of Art. 22 GDPR.
Encryption
This website and the API behind it are delivered exclusively over an encrypted HTTPS connection.
Server log files
When you visit this website and on every request to the API, technical access data transmitted by your browser or the Manasuite app are collected automatically. This includes in particular the IP address, the requested URL, and the user agent (browser or app identifier).
These data are technically required in order to deliver the website and the API correctly, and are processed solely to operate and secure the systems, for example to detect and fend off attacks and to keep the systems stable. The legal basis is our legitimate interest in a secure and functioning operation pursuant to Art. 6 para. 1 lit. f GDPR. Log files are retained only briefly and then deleted; they are not evaluated for marketing or profiling.
If the Manasuite app crashes, it may separately send a small, anonymous crash report - device identifier, app version, and stack trace - to this API on the next launch, so we can fix the bug.
Cookies
This website uses only technically necessary first-party cookies from our own server. Because these cookies are strictly necessary to provide functions you have expressly requested, no consent is required under Section 25 para. 2 TDDDG.
In detail:
manasuite-session - stores the login status, progress while scanning the QR code, passphrase-entry attempts, and a binding against cross-site request forgery (CSRF). After a successful sign-in you stay signed in until you log out. Lifetime: 2 hours of inactivity, renewed on each visit to this website; login status ends immediately on logout. Attributes: Secure, HttpOnly, SameSite=Lax.
XSRF-TOKEN - holds the CSRF token that protects form and API requests on this website against cross-site request forgery. Lifetime: identical to manasuite-session. Attributes: Secure, SameSite=Lax.
manasuite_browser_guid - a randomly generated, anonymous device identifier (UUID) with no name, email address, or other personal reference. It is set only when you actively open the login area at /user/login, not while browsing the rest of the website. Its only purpose is to recognise the same browser when the same QR code is scanned again, so that the app does not incorrectly add a second "Web" device to the linked-devices list. There is no evaluation, no cross-site tracking, and no profiling. Lifetime: technically persistent (up to 5 years). The legal basis is Art. 6 para. 1 lit. b GDPR in conjunction with Section 25 para. 2 TDDDG, because the cookie is strictly necessary to provide the login process you requested.
Login via the Manasuite app
Manasuite has no classic account. Login is deliberately not based on an Apple ID, an email address, or a real name. You prove on this website that you hold the anonymous identity already on your device, by scanning a QR code with the Manasuite app - that is the point of the flow, so the anonymity described above is guaranteed rather than optional. A short numeric code shown in the app and typed here is only a camera-free stand-in for the same scan; it does not collect a name or an email either.
With the QR code, the actual sign-in - redeeming the login hint - happens exclusively in the app; this website only shows progress. With the numeric code, this website checks the one-time, time-limited code itself and, on success, activates the session. In both cases a public user record (users_public) is created or retrieved only after a successful sign-in. That record is keyed to an anonymous identifier generated on the device. It does not contain an Apple ID, an email address, or a real name.
Manasuite does not store an Apple ID, an email address, or a real name anywhere - not in the app, not on this website, not at login, and not during any other use of the service. The only name that may exist is a username a user optionally chooses. Your iCloud data remain with Apple in your CloudKit container and are not transferred to our servers.
Recipients of your data
The recipient of your data is solely our hosting provider, who operates the servers on which this website and the API run. That hosting does not receive an Apple ID, an email address, or a real name, because Manasuite never collects those. For our own purposes, there is no transfer to recipients in third countries outside the EU or the EEA.
Your rights
Under Art. 15 to 21 GDPR you have the right of access to personal data stored about you, of rectification, of erasure, of restriction of processing, of data portability, and the right to object to processing. Please use the contact details given in the Imprint.
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The authority responsible for our establishment in Schleswig-Holstein is:
Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD)
Holstenstraße 98, 24103 Kiel, Germany