Privacy policy
Last updated: 19 September 2026 · Version 2.0
This privacy policy provides information under Articles 13 and 14 GDPR about the processing of personal data on check-mine.com and in the MINE browser extension.
1. Controller
You can also contact us through the contact form.
2. Website, server logs and local storage
Provision of the website
When you access the website, the hosting server processes in particular your IP address, time of access, requested address, referrer, browser and operating-system information, transferred data volume and HTTP status. This is technically necessary to deliver the website, diagnose faults and prevent attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interests are secure and reliable operation. Server logs are rotated daily and deleted within 14 days.
The website is hosted by DomainFactory GmbH under a data processing agreement pursuant to Art. 28 GDPR.
Cookies, local storage and session storage
We use no analytics, marketing or social-media cookies. For functions you expressly request, your language choice is stored in a cookie for twelve months. Depending on your use, the browser's local or session storage contains the language choice, a random browser identifier for usage limits, your Things, check history, settings and temporary data for an ongoing check.
This storage and access is strictly necessary to provide the function you use (§ 25(2) no. 2 TDDDG). Where the data is personal, processing is based on Art. 6(1)(b) GDPR to provide the requested function and Art. 6(1)(f) GDPR to prevent abuse. Local data remains until you delete it through the browser or app function or uninstall the extension; session data ends with the browser session.
Product images
External product images are retrieved through our server. The image provider receives our server's IP address and the image address, not your IP address. The legal basis is Art. 6(1)(f) GDPR; our interest is a privacy-preserving and reliable display.
3. MINE check and use of AI
Data processed and purpose
When you start a check, we process the product-page address, details of your Thing, language, technical request data and the content of the product page. Our server retrieves the product page; the relevant page provider receives our server's IP address and the requested address, not your IP address. Do not submit personalised, private or access-restricted links.
Where product pages exceptionally contain personal data about third parties, this may include names or other identifiers contained in product titles, descriptions or technical details. The source is the product page submitted by you or product-related content transmitted by the browser extension from the displayed page. Such data is processed solely for product analysis, not to evaluate a person.
For a check initiated by you, the browser extension may additionally transmit a screenshot of the visible part of the page. It is processed only temporarily in server memory and is not written to the database. It ceases to be available through the application after two hours and is removed from memory on the next access to the store or when the application process restarts.
The purpose is to provide the compatibility check you requested. Processing of your data is based on Art. 6(1)(b) GDPR. The product address and details of your Thing are required for the check; no result can be generated without them. Personal data about third parties is processed under Art. 6(1)(f) GDPR; our legitimate interest is providing the requested product check. Individual notice is not provided where the person cannot be reliably identified or providing notice would involve disproportionate effort (Art. 14(5)(b) GDPR); this notice is made publicly available for that purpose.
AI service and retention
We transmit the details and product information required for the check to OpenAI Ireland Ltd.. Our API requests are configured so that the provider does not store regular application state for those requests. OpenAI does not use API inputs and outputs to train its models by default. Abuse-monitoring logs may nevertheless contain inputs, outputs and derived metadata and are retained for up to 30 days by default; longer retention is possible where required by law or necessary to protect the services or third parties. Depending on the model, encrypted prompt-cache data may be stored temporarily.
We store the result together with the product address, details of your Thing and pseudonymous security identifiers under a random result ID; it is removed in the next daily deletion run after 30 days. Database records of pseudonymous operational and usage logs (such as time, domain, status and token volumes) are removed in the next daily deletion run after 90 days; daily limit counters after no more than three days. Up to 2,000 recent log entries may additionally remain temporarily in volatile process memory until displaced or the application process restarts. The legal basis is Art. 6(1)(f) GDPR; our legitimate interests are abuse prevention, fault analysis and economically viable operation.
To accelerate later checks, we store the original product address, a version from which certain known tracking parameters have been removed, and derived details such as title, manufacturer, model, category, identifiers and technical characteristics. When the browser extension is used, these details may originate from the product page displayed in the browser. The transmitted page extract and screenshots are not stored in the product catalogue. Catalogue entries are removed in the next daily deletion run after 90 days have elapsed since their last update. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is avoiding repeated page retrievals and AI evaluations.
AI transparency notice
Check results are produced automatically with the help of an AI system and are not reviewed individually by a person. They may be incomplete or incorrect. The visible label informs you that AI is used when the result is displayed. It also serves transparency with regard to Art. 50 of Regulation (EU) 2024/1689. No solely automated decision with legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.
4. MINE browser extension
The extension has technical access to open HTTP and HTTPS pages. It evaluates page content locally to identify shop, product, cart and order pages relevant to its functions and to display the functions you select. It does not create a general browsing-history profile. Data is transmitted to our server when, in particular, you identify or save a Thing, use a check, order-assistance feature or partner link. The relevant sections of this policy explain the data processed in each case.
Things and check history are stored in chrome.storage.local and can be deleted in MINE; history is also limited to the most recent entries. Language and settings remain stored until changed or reset. The random browser identifier remains stored until the extension data is cleared through the browser or the extension is uninstalled. The legal bases are § 25(2) no. 2 TDDDG and, where personal data is processed, Art. 6(1)(b) and (f) GDPR.
Installation and updates are provided through the Chrome Web Store. Google Ireland Limited is independently responsible for the Store's processing. The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Order assistance
If you use order assistance, the extension transmits the order-page address, titles, image and product addresses of detected items and the details of your locally stored Things required for selection. This data is used only to transfer the purchased items you requested and is held solely in server memory. It ceases to be available after two hours and is removed on the next access to the store or when the application process restarts. The legal basis is Art. 6(1)(b) GDPR.
5. Contact
If you contact us by form or e-mail, we process your e-mail address, message, optional name and communication metadata to handle the enquiry and any follow-up. The form processes the IP address temporarily to prevent automated abuse and stores only a pseudonymous form of it with the message. Form data is stored on our hosting server or by our database provider; a working copy is delivered to hello@check-mine.com.
The legal basis is Art. 6(1)(b) GDPR where the enquiry concerns a contract or pre-contractual measures, and otherwise Art. 6(1)(f) GDPR. Our legitimate interests are handling enquiries and protecting the form. Records at the database provider are removed in the next daily deletion run after one year; older records in the file-backed fallback store are removed on the next access. We retain e-mail working copies until the enquiry has been dealt with and subsequently only where statutory retention duties or legal claims require this.
Where Turnstile is enabled, Cloudflare processes in particular the IP address, TLS and browser characteristics, interaction data, sitekey, origin and verification result. Cloudflare acts as our processor when protecting the form and as an independent controller when improving its bot-detection capabilities. Processing on our behalf is based on § 25(2) no. 2 TDDDG and Art. 6(1)(f) GDPR; our interest is protection against automated abuse. Cloudflare states its own legitimate interests for its independent processing. Turnstile is loaded only when this security feature is enabled.
6. Partner links and click measurement
MINE contains labelled partner links. As an Amazon Associate I earn from qualifying purchases. When you click a link, we record its destination, time, channel, link type, labelling and, where applicable, the result ID and the check result shown immediately before the click. For the click record, we derive a pseudonymous identifier from the IP address. Independently, the IP address is processed in server logs when the click is transmitted, as described in section 2. Database records are removed in the next daily deletion run after 90 days.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are attributing referrals, preventing abuse and funding the service. Only when you open the link does your browser connect to Amazon or the relevant retailer. The destination provider processes the resulting data under its own responsibility; MINE loads no Amazon cookies or direct Amazon embeds.
7. Recipients and international transfers
We use the following recipients where required for the purposes described:
- DomainFactory GmbH (company established in Germany): hosting and e-mail, processor;
- Supabase Pte. Ltd. (Singapore): database and operational data, processor. Where a German project region is selected, project data is stored and primarily processed there; this does not exclude processing by Supabase or subprocessors at other locations;
- OpenAI Ireland Ltd. (Ireland; affiliates and subprocessors, particularly in the United States): AI evaluation, processor;
- Cloudflare, Inc. (United States): only if the Turnstile security check is enabled;
- providers of the product pages and product images you submit: server-side retrieval;
- Google Ireland Limited: Chrome Web Store, independent controller;
- Amazon and other destination providers: only when external links are opened, independent controllers.
The transfer to Supabase Pte. Ltd. in Singapore is safeguarded by the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR. OpenAI Ireland Ltd. safeguards transfers to affiliates and subprocessors outside the EEA through Standard Contractual Clauses or an adequacy decision under Art. 45 GDPR. Transfers to Cloudflare in the United States rely on its EU-US Data Privacy Framework certification, with Standard Contractual Clauses as a fallback. Information about the safeguards and a copy of the applicable clauses are available on request. Following deletion, data may remain in access-restricted processor backups until they are overwritten in the ordinary backup cycle.
8. Your rights
Subject to the statutory conditions, you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20).
Where processing is based on Art. 6(1)(f) GDPR, you may object to processing at any time on grounds relating to your particular situation (Art. 21(1) GDPR). We will then no longer process the data concerned unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or processing is necessary for the establishment, exercise or defence of legal claims.
Under Art. 77 GDPR you may lodge a complaint with a data protection supervisory authority. The authority competent for us is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit (TLfDI). To exercise your rights, send a message to the e-mail address stated in section 1.