Privacy Policy
Last updated: 2026-07-02
1. Who we are
Podshalocef, Inhaber Michael Sann, operating Mdkit (“we”), is the data controller for the personal data described here. Contact contact@podshalocef.com. The operator’s full name and address are in the Impressum.
2. Data we collect
- Account: email, name, and authentication data (managed by our auth provider).
- API keys: key name, prefix, creation and expiry — never the secret value.
- Content you submit: the files, documents, and text you send us to process, the results we produce from them, and any files you store with us. We process them only to give you your result — we never sell them, and we do not use them to train models.
- Usage & billing: request counts, credit usage, plan, and subscription status.
- Technical: IP address and request metadata, used for security and rate limiting.
3. Lawful basis (GDPR Art. 6)
- Contract: providing your account, the API/MCP service, and billing.
- Legitimate interest: security, abuse prevention, and rate limiting.
4. Retention
Account data is kept while your account is active and deleted on request. Billing records may be retained as required by law (in Germany currently 8–10 years for accounting records).
Content you submit is kept until you delete it — or, at the latest, until you delete your account, which erases your submitted content, the results we produced from it, and any files you stored, together with the job records that reference them. We apply no automatic expiry of our own, and requests we answer in a single round trip are processed in memory and not stored at all.
Encrypted backups are retained on a rolling schedule for up to ~13 months for disaster-recovery purposes. Data you delete is removed from live systems immediately and ages out of backups within that window; if we ever restore from a backup, any account already erased is re-deleted immediately after the restore.
5. Subprocessors
- Hetzner (EU) — hosting
- Polar — payments (merchant of record) & subscription billing
- Scaleway (EU) — transactional email
- Bunny.net — content delivery (CDN)
6. Cookies
We set first-party cookies only — three of them, and no more:
- your login session — strictly necessary: it keeps you signed in, and stays until it expires or you sign out
ak_land— the first page you landed on and the site that referred you, so we can see which pages bring people inak_ref— the referral or campaign link you arrived through, so a later signup can be credited to it
ak_land and ak_ref are session cookies:
they carry no expiry date, so your browser discards them when you close it. They hold only a page path, a
referring site, and a campaign code — never an identifier that follows you elsewhere. We set no
third-party, advertising, or cross-site tracking cookies, and we embed no third-party analytics script,
so we do not show a cookie consent banner.
7. Your rights
You can access, rectify, erase, export, and object to the processing of your data. From your account page you can export your data or delete your account, or email us.
8. International transfers
Our infrastructure is EU-based. Where a subprocessor transfers data outside the EU, it is covered by Standard Contractual Clauses or an adequacy decision.
9. AI features
Mdkit exposes an AI-agent (MCP) interface. Requests you make through it are processed only to provide the service; we do not use your request content to train models.
10. Changes & complaints
We may update this policy; material changes will be announced. You may lodge a complaint with your local data protection authority.