Privacy policy
This page explains what happens to data when you visit AWTRIX Flows and when you submit a flow. It describes the site as it actually works — there is no tracking, no advertising, no analytics, and no third-party content embedded in these pages.
1. Who is responsible
Controller within the meaning of Art. 4 (7) GDPR:
Stephan Mühl Softwareentwicklung
Sole proprietor: Stephan Mühl
Weinbergstraße 10
63477 Maintal, Germany
admin@blueforcer.de
There is no statutory obligation to appoint a data protection officer for a service of this size, and none has been appointed.
2. Visiting the site
When you open a page, your browser sends technical data that the web server records in a log file:
- your IP address
- date and time of the request
- the page or file requested and the HTTP status
- the amount of data transferred
- the referring page, if your browser sends one
- browser and operating system identification (user agent)
Purpose: delivering the site, finding faults, and defending
against attacks and abuse.
Legal basis: Art. 6 (1) (f) GDPR. Our legitimate interest is
operating a functioning and secure website.
Retention: application logs are deleted after 14 days. Web
server logs are rotated and overwritten continuously.
Your IP address is also used briefly to enforce rate limits — for example, a maximum of five flow submissions per hour. These counters live in a temporary in-memory store and expire on their own within an hour. Legal basis: Art. 6 (1) (f) GDPR, interest in preventing spam and abuse.
3. No third-party content, no tracking
All fonts, stylesheets, scripts and images needed to display these pages are served from our own server. We do not embed fonts, libraries or images from content delivery networks, and we use no analytics, no advertising, no social media plugins and no consent management platform. When you look at a page, your IP address is therefore not transmitted to any third party.
The pages do contain ordinary hyperlinks to other sites — the AWTRIX documentation, GitHub, Discord, Home Assistant and “Buy me a coffee”. Those sites receive data only if you actively click the link, and their own privacy policies apply from then on.
4. Cookies and data stored in your browser
We set only cookies that are strictly necessary to provide the functions you requested. Under § 25 (2) TDDDG these do not require consent, which is why this site shows no cookie banner.
| Name | Purpose | Lifetime |
|---|---|---|
awtrix-flows-session |
Keeps your session, e.g. so form errors and one-time messages survive a page reload. | 2 hours |
XSRF-TOKEN |
Protects forms against cross-site request forgery. | 2 hours |
edit_token_… |
Set only when you submit or edit a flow, so the page can show you your edit link again. One cookie per flow you submitted. | 30 days |
In addition, two values are stored in your browser's local storage. Neither is ever sent to our server:
-
flows-theme— remembers whether you chose the light or dark appearance. Written only when you use the toggle. -
awtrixDeviceAddress— the address of your own AWTRIX device, remembered so you do not have to type it again when uploading icons. Written only when you use that function.
You can delete cookies and local storage at any time in your browser settings.
Deleting the edit_token_… cookie means the site can no longer show
you your edit link — keep the link itself if you want to come back to it.
5. Submitting a flow
There are no user accounts on this site. Submitting a flow requires no registration and no e-mail address. What you enter in the form is stored and published:
- the name of the flow, a short summary and a longer description
- the flow itself (configuration or script text)
- the cover image and any icons you upload
- the author name you type in — you choose it freely, and a pseudonym is fine
- the system, topic and firmware you select
All of this becomes publicly visible and can be read, downloaded and indexed by search engines. Please do not put personal data of yourself or others into these fields. If you enter your real name as the author name, that name is published.
Purpose: publishing the flow, which is the entire point of the
service you are using.
Legal basis: Art. 6 (1) (b) GDPR — you actively submit content
for publication, and we provide the publication.
Retention: until the flow is deleted. You can delete or change
it yourself with your edit link, or ask us to.
When you submit a flow you receive a secret edit link. We store only a cryptographic hash (SHA-256) of that secret, never the secret itself, so nobody — including us — can reconstruct your link from the database.
We also count page views and downloads per flow. These are plain numbers with no connection to a person. Legal basis: Art. 6 (1) (f) GDPR, interest in knowing which flows are useful.
6. Reporting content
If you report a flow using the reporting form, we store what you write, the flow concerned, and — if you choose to provide it — your name and e-mail address, so we can come back to you. Providing them is voluntary; a report without contact details is still processed.
Legal basis: Art. 6 (1) (c) GDPR in conjunction with Art. 16 of
Regulation (EU) 2022/2065 (Digital Services Act) — we are legally required to
operate a reporting procedure — and Art. 6 (1) (f) GDPR for keeping a record of
how a report was handled.
Retention: reports and the decisions taken on them are kept for
three years so that we can demonstrate how we acted, then deleted.
7. Who else receives data
Hosting
The site runs on a server operated by Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany. Contabo acts as a processor on our behalf under a data processing agreement pursuant to Art. 28 GDPR. The server is located in Germany.
Discord
When a new flow is published, an automatic announcement is posted to our Discord server via a webhook. It contains the flow name, the author name you chose, the short summary, the link to the flow and its cover image — that is, content you submitted for publication anyway. No IP addresses and no data about visitors are sent. The service is operated by Discord Netherlands B.V. and Discord Inc. (United States).
GitHub
Flows submitted for the “Home Assistant Blueprint” system are additionally mirrored into a public GitHub repository, because Home Assistant imports blueprints directly from there. The mirrored file contains the flow text you submitted. The service is operated by GitHub B.V. and GitHub, Inc. (United States, part of Microsoft).
Both Discord and GitHub may process data in the United States. Transfers take place on the basis of the European Commission's adequacy decision for the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the basis of standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.
We do not sell data, and we pass nothing on to anybody else unless we are legally obliged to.
8. Your rights
Under the GDPR you have the right to:
- access the data we hold about you (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased (Art. 17)
- have processing restricted (Art. 18)
- receive your data in a portable form (Art. 20)
- object to processing based on legitimate interests (Art. 21) — this applies in particular to the log data described in section 2
A message to admin@blueforcer.de is enough. Because we deliberately store no e-mail addresses of submitters, we may be unable to identify which submission belongs to you; sending us the edit link or the address of the flow makes that straightforward.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7, 65185 Wiesbaden, Germany
datenschutz.hessen.de
9. Children
This service is aimed at people who own an AWTRIX display and is not directed at children. We do not knowingly process data of children. Where consent were ever required from a child, Art. 8 GDPR and the German age threshold apply. If you believe a child has published personal data here, please tell us and we will remove it.
10. No automated decisions
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Whether a flow is hidden or removed is always decided by a person.
11. Changes
We will update this policy when the service changes. The date below tells you which version you are reading.
Last updated: 30 July 2026