Cookies to run the site. Analytics and ads only with your consent. Privacy policy
Version of 19 August 2026
Wagner, Wunderlich & Lorenz GbR, Hohenbergstedt 18b, 22359 Hamburg, Germany. Email: contact@addpencil.com. We have not appointed a data protection officer, as we are not required to.
Each time the site is accessed, our server records the IP address, the time, the page requested, the referring page, and the browser and operating system. This is necessary to deliver the site and to detect attacks. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in an operable, secure service. A device identifier is stored in your browser so that the free monthly allowance cannot simply be reset. Same legal basis.
We process the description you type and any image you upload in order to produce the model. This happens on our own service at service.addpencil.de. Legal basis: Art. 6 (1) (b) GDPR, performance of the contract or of pre-contractual steps at your request. Please do not upload photographs of other people without their consent. An uploaded image stays on that service for 30 days after the model is made, so that we can spot-check whether anyone is misusing it; after that it is deleted automatically. Legal basis for keeping it: Art. 6 (1) (f) GDPR, our legitimate interest in preventing abuse.
For an account we process your email address and, if you set one, a password we never see in plain text, plus your generation history. If you sign in with Google we receive your name and email address from Google. Google runs that sign-in under its own responsibility; Google's privacy policy applies. Legal basis: Art. 6 (1) (b) GDPR.
For a paid order we process the data needed for the contract and for accounting. Card details are entered directly with our payment provider; we do not receive them. Legal basis: Art. 6 (1) (b) GDPR, and Art. 6 (1) (c) GDPR for retention required by commercial and tax law.
If you write to us we process your message and your contact details in order to answer. Legal basis: Art. 6 (1) (b) or (f) GDPR.
Your designs appear in the gallery only after you choose to publish them. Model and preview files from the generation service are accessible through their direct links without signing in. Do not use confidential source material and share these links deliberately. If you release one to the gallery, the display name you chose, your description, the preview image and the date become publicly visible — to every visitor and to search engines. Your email address never appears there; the display name is the only name we publish, and you pick it yourself. When you like a design we record that it was you, so you can take the like back and nobody is counted twice; what is public is the total, not who gave it. If you report a published design we store that it was you and the reason you typed, so we can look at it and so one account cannot file the same report twice. The report itself is not shown in the gallery. You may add a photograph of your own to an entry — of the printed part or the finished bake — entirely at your option. It is not a requirement; without one your entry keeps showing the rendered view of the model. If you upload one, we re-encode it on our server and store only the result, which removes every piece of metadata embedded in the shot, in particular the GPS coordinates many cameras and phones record. A photograph added after approval goes back for review before it becomes visible. You can withdraw a published design or a photograph from your account at any time, after which they no longer appear in the gallery. Previously shared model links are not revoked by this. Legal basis: Art. 6 (1) (a) GDPR for publication — none of that happens without your explicit decision, and withdrawing the design is how you revoke it. Legal basis for likes and reports: Art. 6 (1) (f) GDPR, our interest in a gallery that can be moderated and is not counted twice. Saved Studio orders contain the order name, model identifiers, sizes, save date and your finished ZIP. They are held in private storage and accessed through your signed-in account. You can delete them from your account. Legal basis: Art. 6(1)(b) GDPR to provide this feature.
We use Google reCAPTCHA to tell humans from automated requests. Its script loads on every page, not only on the ones with a form, because the version we use scores behaviour continuously rather than posing a puzzle. This transmits your IP address, interaction data and browser information to Google, which also loads a font from its own servers as part of that. Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in keeping forms free of abuse.
We use service providers who process data strictly on our instructions under a data processing agreement (Art. 28 GDPR): Supabase (database, authentication and file storage), Stripe (payments), Resend (transactional email), Google (reCAPTCHA and AdSense), PostHog (usage statistics, European instance), and our hosting provider DeinServerHost. Model generation runs on our own infrastructure at service.addpencil.de.
We do not sell your data. Beyond the processors named above we pass data on only where we are legally obliged to, or where you have consented.
Some of these providers are based in the United States or process data there. Transfers are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on standard contractual clauses under Art. 46 (2) (c) GDPR. You can request a copy of those safeguards from us.
We store information on your device, or read it from there, only where this is strictly necessary to provide the service you asked for, or where you have consented (§ 25 TDDDG). You give and withdraw that consent in our cookie banner, which you can reopen at any time via “Cookie settings” in the footer.
Session and login cookies, your language and theme choice, your cookie decision itself, and the device identifier for the free allowance. These are set without consent because the service does not work without them.
We use PostHog to understand how the site is used — for instance how many visits lead to a finished design. The provider is PostHog, Inc.; we use their European instance, so processing takes place in the EU. Only events we named ourselves are recorded: prompt started, generation started, completed or failed, file downloaded, sign-up completed, purchase completed, size package prepared, package downloaded, order saved or downloaded. The properties attached to them are coarse: which kind of object was chosen, whether you are signed in, and how long a generation took. The text of your prompts, your email address and your model identifiers are never transmitted, and addresses are stripped of their parameters before anything is sent. We do not record sessions and do not capture clicks automatically. No cookie is set; your browser's local storage holds a random identifier so a returning visit is not counted twice. PostHog is loaded only after you consent — before that nothing is fetched, stored or transmitted, not even buffered for later. The event data is deleted after 30 days. Legal basis: Art. 6(1)(a) GDPR and § 25(1) TDDDG.
Google AdSense may show ads and, for that purpose, set cookies and use similar technologies, including for personalised advertising. AdSense is loaded only after you consent. Legal basis: Art. 6 (1) (a) GDPR and § 25 (1) TDDDG. You can also object to personalised advertising in your Google ad settings. Google explains how it uses data from partner sites and apps on the linked help page.
For as long as your account exists. You can delete it yourself, under "Account" in your account settings. Doing so cancels a running subscription, removes your saved sets and their files, your gallery entries and photographs, your history and your credits, and finally your sign-in. What we must keep by law is not deleted: invoices and payment records, and your withdrawal and cancellation declarations. An image you uploaded within the last 30 days may still be held for the abuse check until that period ends, and is then deleted automatically. You can also download a copy of your data as a file there at any time.
Normally 7 days; longer only where a specific incident needs investigating.
10 years, as required by § 147 AO and § 257 HGB.
10 years, for the same reason, see section 7.
Up to 3 years after the matter is closed, so we can answer follow-up questions and defend claims.
You have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it erased (Art. 17), to restrict its processing (Art. 18), to receive it in a portable format (Art. 20), and to object to processing based on our legitimate interests (Art. 21). Where processing rests on your consent, you can withdraw that consent at any time with effect for the future.
Write to contact@addpencil.com. We will answer without undue delay and at the latest within one month.
You can lodge a complaint with a data protection supervisory authority, in particular in the EU state where you live, work, or where you believe an infringement occurred (Art. 77 GDPR). The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.
If you use our online withdrawal form, we process your name, your email address, your order or contract reference, optionally the product and your reason, the date and time of submission, and your IP address.
To process your withdrawal and to be able to prove that we did. Legal basis: Art. 6 (1) (c) GDPR together with §§ 355, 356 BGB, and Art. 6 (1) (f) GDPR for the IP address, our legitimate interest in preventing abuse.
Kept for 10 years under § 147 AO and § 257 HGB. Passed on only as far as processing your request requires, for example to cancel your subscription with our payment provider.
Your description or image is processed by an automated, AI-supported procedure to produce the model. This is not automated decision-making producing legal effects concerning you within the meaning of Art. 22 GDPR, and there is no profiling.
The site is delivered over an encrypted TLS connection. We take technical and organisational measures appropriate to the risk to protect your data against loss and against unauthorised access, and we review them as our service changes.
We update this policy when our service or the legal position changes. The current version is always the one on this page; the date at the top tells you which version you are reading.
For any question about this policy or about your data: contact@addpencil.com.