Privacy Policy
Last updated: 25 September 2026
1. Controller
The controller responsible for processing your data on railwail.com is:
Philipp Schmid
Steinenberg 10
88339 Bad Waldsee
Germany
Email: info@railwail.com
This privacy policy covers the Railwail website, web app, API, MCP server and training (fine-tuning).
2. Summary
⢠The website, web app, API and database run on our server at Hetzner in Falkenstein, Germany. Cloudflare sits in front of the website; our email mailbox is hosted at OVH (sections 3 and 15).
⢠When you run a model, your input goes to the AI service that runs that model, currently mainly Replicate, OpenAI, Anthropic or DeepSeek (section 9).
⢠Your runs (inputs, settings, results) stay in your history. There is currently no automatic deletion period for them; you can ask for deletion at any time.
⢠Stored results and uploaded files can be opened via their link without signing in.
⢠We delete voice samples for voice cloning automatically, at the latest about 25 hours after upload.
⢠Our own analytics runs without consent; you can object to it. In the EU, the EEA, the United Kingdom and Switzerland, Google Analytics, Google Ads, the X pixel and Google One Tap load only after you consent; in other countries they are on by default and you can object (section 6).
⢠A program evaluates emails to info@railwail.com with the help of AI services (section 15).
⢠We do not train AI models on your inputs or results ourselves.
The details follow in the sections below.
3. Hosting and Delivery of the Website
The website, web app, API, database, sign-in, file storage and our background services run on a server we rent from Hetzner Online GmbH (Germany) in its Falkenstein data centre. We run sign-in and file storage there ourselves, using open-source software from Supabase; the company Supabase receives no data.
Cloudflare sits in front of railwail.com, www.railwail.com and supabase.railwail.com as a network and protection service (reverse proxy and CDN). Every request to these addresses passes through a Cloudflare data centre. Which one depends on your location; it may be outside the EU. Cloudflare decrypts the connection and processes the whole request: your IP address, the requested address, browser data and everything you send, including inputs, files, sign-in data and API keys. Cloudflare tells us the country a request comes from. We use it for the cookie banner region, the display currency and our own analytics.
Two more Cloudflare features are active: on connection errors your browser sends an error report to Cloudflare (Network Error Logging). And Cloudflare obscures email addresses on our pages with a small script so that spam bots cannot read them.
We serve fonts and blog images from our own server; we do not use Google Fonts. Your browser loads content from other providers in these cases:
⢠Stripe's scripts in the billing area (section 11),
⢠scripts from Google and X, depending on your cookie choice (section 6),
⢠your profile picture in the dashboard, directly from Google or GitHub, if you signed in with Google or GitHub (section 7),
⢠some results directly from Replicate (section 9).
The provider concerned receives your IP address and browser data.
Purpose: providing, protecting and quickly delivering the website. Legal basis: Art. 6(1)(b) GDPR (use of our service) and Art. 6(1)(f) GDPR (legitimate interest in secure and fast operation). Hetzner and Cloudflare process this data on our behalf (Art. 28 GDPR): Hetzner Online GmbH, IndustriestraĆe 25, 91710 Gunzenhausen, Germany, and Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. For Cloudflare, Cloudflare's Data Processing Addendum applies as part of its terms of service; it bases transfers to the United States on Cloudflare's certification under the EU-US Data Privacy Framework and on the European Commission's standard contractual clauses (section 17).
4. Server Logs and Error Reports
Access log: our server logs every request with IP address, time, requested address including URL parameters, method, status code, referring page and browser identifier (user agent). The log files are rotated by size, not after a fixed period; how far back they go depends on the traffic of all websites on this server, currently about two weeks.
Service logs: our services (app, sign-in, file storage, AI gateway) write technical logs. If we refuse a trial run under our abuse rules, the log contains the account ID and, where applicable, the IP network (section 5). These logs are also rotated by size; logs of replaced program versions remain until we remove those versions.
Error reports from your browser: every page contains a small script that reports JavaScript errors and files that failed to load, at most 10 per browser session; the app's error pages also report there. It sends the error text, the technical trace (stack trace), the full page address including URL parameters and the browser identifier to our own error service at admin.webgantic.com. This service runs on our Hetzner server but is called directly, without Cloudflare. It stores your IP address as a hash without a secret component; for IPv4 addresses this hash can be reversed by trying all addresses. In the access log your IP address appears as with any request. We delete error reports after 180 days. The script keeps track of how often it has reported or reloaded the page in your browser's session storage (_oe_n, _oe_cr).
Purpose: operation, troubleshooting and defence against attacks. Legal basis: Art. 6(1)(f) GDPR. For the entries in session storage we rely on § 25(2) No. 2 TDDDG. On your device the error script only accesses these two counters; they are needed so that it does not report or reload endlessly. Log limits: the access log rotates at 500 MB, and at most 30 older files are kept; service logs keep at most five files of 50 MB per service, older entries are overwritten.
5. Security and Abuse Prevention
To stop anyone from overloading our service or using it at others' expense, we limit requests:
⢠We count sign-in, sign-up and āforgot passwordā attempts per IP address and email address.
⢠We additionally count trial runs of accounts without a purchase per IP network (IPv4 address or IPv6 /64 network): at most 8 per 24 hours across all accounts.
⢠We limit uploads, API calls, MCP calls without a key and clicks on referral links per account, key or IP address.
These counters are kept in a cache (Redis) on our server and expire with their time window, after 24 hours at the latest. For the free run without an account we count runs per browser (cookie rw_anon, 60 days) and per IP address; for this we keep the IP address only as a hash with a secret key in memory (time window 6 hours).
Purpose: protection against abuse, fraud and overload. Legal basis: Art. 6(1)(f) GDPR. The rules for trial runs are described in section 20.
6. Cookies, Local Storage and Analytics
We set cookies and use your browser's local storage and session storage for these purposes:
⢠Operation: sign-in, language, the region for the cookie banner, your cookie choice and the free run without an account (section 5). Legal basis: § 25(2) No. 2 TDDDG, because these entries are strictly necessary for the service you use; for the further processing Art. 6(1)(b) GDPR (sign-in, language, free run) or Art. 6(1)(f) GDPR (region and cookie choice: our interest in respecting your choice and the rules that apply in your country).
⢠Interface: entries that stay in your browser and are not sent to us. In local storage, until you delete them in your browser: the colour scheme in the dashboard (theme), a collapsed sidebar (sidebar_collapsed_v1), the sign-in method you used last (rw:lastAuthMethod), the number of failed sign-in attempts (rw:signinFails), whether you have already seen the dashboard introduction (onboarding_completed_v1) or used the free run on the home page (rw:heroFreeUsed), and the language of the code examples in the documentation (railwail-docs-lang). In session storage, until you close the tab: the exchange rates for the display currency (rw_fx) and your playground inputs if you sign in before the run (rw_try_draft:ā¦). Legal basis: § 25(2) No. 2 TDDDG and Art. 6(1)(b) GDPR.
⢠Display currency and referrals: the cookie rw_ccy remembers for 30 days the currency in which we additionally show prices; the cookies rw_ref and referral remember a referral link for 30 days (section 12). The cookie rw_ref_owner (1 year) holds your own referral code when you open your referral page, so that your own link is not counted as a referral. The cookies rw_ccy, rw_ref and referral contain no identifier of you, only the currency or the code of the link you opened; we set these cookies without consent and read them only for this function. Legal basis: § 25(2) No. 2 TDDDG (showing prices in your country's currency and attributing the referral link you opened) and Art. 6(1)(f) GDPR (our interest in showing prices clearly and rewarding referrals).
⢠Our own analytics: it runs without consent, and you can object at any time. What we record, on which legal basis and for how long is described in the box below.
⢠Analytics and marketing: Google Analytics 4 (analytics category) as well as Google Ads, the X pixel and sign-in with Google One Tap (marketing category). For these, your browser loads scripts from Google or X and sends them, among other things, your IP address, the pages you view and browser data. We also report sign-up, start of checkout and purchase (with amount and the ID of the Stripe checkout) to Google Analytics, and sign-up and purchase to Google Ads. We currently do not report a purchase event to X; no event ID is set up for it. Google Analytics keeps event and user data with identifiers for 2 or 14 months, depending on the setting in our account; aggregated standard reports are not affected.
In the EU, the EEA, the United Kingdom, Switzerland and when your country cannot be determined, analytics and marketing services load only after you consent in the cookie banner; the legal basis is then your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). In all other countries both categories are on by default, and you can object in the cookie settings. There, the legal basis is our legitimate interest in audience measurement and advertising (Art. 6(1)(f) GDPR); after you object, we no longer load the scripts and delete the cookies they set.
Roles: for Google Analytics, Google processes the data as our processor; the basis is Google's Google Ads Data Processing Terms. For Google Ads and the X pixel, Google and X are independently responsible for processing the transmitted data (Google Ads Controller-Controller Data Protection Terms; X's Controller-to-Controller Data Protection Addendum); we are responsible for loading their scripts on our website only after your consent or with the option to object. For Google One Tap, Google processes your data as an independent controller under its privacy policy. The contracting parties for users in the EEA are Google Ireland Limited (Dublin) and X Internet Unlimited Company (Dublin); the US parent companies Google LLC and X Corp. are certified under the EU-US Data Privacy Framework (section 17).
More about the individual cookies and storage entries, with name, purpose and duration, is in our Cookie Policy. You can change or withdraw your consent at any time in the cookie settings (via the āCookie settingsā link in the footer of our public pages or on the Cookie Policy page); that is also where you object where the categories are on by default.
Our own analytics
We measure ourselves how railwail is used: which pages and models are viewed, where errors occur, where visitors come from and whether a visit leads to a sign-up or a purchase. We need these numbers to run the service, fix errors and improve what we offer, for example which models we provide.
We process the data in our own database on a server we rent from Hetzner in Falkenstein, Germany; like all requests to our website, the requests pass through our CDN provider Cloudflare. We do not pass the data on to third parties for advertising or analytics. This analytics runs regardless of your cookie choice; we store the state of your choice with every event.
What we record
- Pages viewed: the path without URL parameters (we replace IDs in the path with placeholders), the language of the page and the time.
- Where you came from on entry: only the domain name of the referring page, campaign parameters (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and whether an ad click parameter was present (only its type, e.g. āgclidā, never its value).
- Use of the page, for example models and categories viewed, search terms (we discard searches containing an email address or a long number), filters, clicks on buttons and on links to other websites, copied code examples, start, result or error of a playground run (of the prompt only the number of characters, never the content), the start of a payment with its amount, scroll depth and active time per page, and technical error messages of the page.
- The country (from the header of our CDN provider Cloudflare), the device class (desktop, mobile, tablet) and the browser and operating system family without version number. We do not store the full browser identifier (user agent).
- Whether you are signed in and, if so, the internal ID of your account.
- Pseudonymous identifiers: a visitor ID (from the cookie rw_vid, stored by us only as a hash with a secret key), a session ID (rw_sid) and a day ID that we calculate from IP address and browser identifier with a secret key and a random value that changes daily.
- Whether an access looks automated (bot). We mark such accesses instead of discarding them.
- The state of your cookie choice (none, analytics, or analytics and marketing) and whether consent is expected in your region.
We do not store IP addresses in this analytics. We only use them briefly in memory to calculate the day ID, to throttle excessive requests and to recognise our own visits. We delete the daily random value on the day after next; after that the day ID can no longer be recalculated.
Sign-ups, purchases and API keys
When you create an account, buy credits or create an API key, we store an event with the ID of your account, for purchases with amount, currency and credits. For sign-ups we add, where available, the entry source from the cookie rw_utm or from your earlier page views (domain of the referring page, campaign parameters, landing page, type of ad click). When you open a referral link (?ref=ā¦), we also store an event without an account ID: whether the referral code exists, the landing page, the domain of the referring page and the referral code as campaign parameter. For sign-ups and purchases we note whether the account came through a referral link.
Cookies of this analytics
| Name | Purpose | Duration |
|---|---|---|
| rw_vid | Recognises your browser on later visits (random ID, stored by us only as a hash). | 13 months |
| rw_sid | Groups the page views of one visit into a session (random ID). | 30 minutes after the last activity |
| rw_utm | Remembers the first entry source (campaign parameters, domain of the referring page, type of ad click, landing page) so that we can attribute a later sign-up. Only set if there is such a source. | 30 days |
| rw_optout | Stores your objection to this analytics. | 13 months |
Legal basis
We consider this analytics necessary to operate our service. We therefore base setting and reading the cookies rw_vid, rw_sid and rw_utm on Section 25(2) No. 2 TDDDG, and the further processing on our legitimate interest (Art. 6(1)(f) GDPR) in running the service reliably and developing it according to demand. We do not ask for consent for this; you can object at any time.
Retention
We delete individual events after 25 months so that year-on-year comparisons are possible. We remove visitor, session and day IDs as well as the account ID on page events after 180 days already. Events for sign-ups, purchases and API keys keep the account ID until we delete them after 25 months.
Objection
You can object to this analytics at any time without giving reasons. The āObject to analyticsā button below sets the cookie rw_optout in this browser. After that your browser no longer sends analytics data, the cookies rw_vid, rw_sid and rw_utm are deleted, and our server discards analytics data from browsers with this cookie. We still store sign-ups, purchases and API keys as contract data, but without any link to your page views.
The objection applies to this browser. If you delete your cookies, you need to declare it again.
Ā
Third-party trackers from Google and X
We load Google Analytics, Google Ads and the X pixel only when the respective category (analytics or marketing) is active. In the EU, the EEA, the United Kingdom including Gibraltar, Jersey, Guernsey and the Isle of Man, Switzerland, and whenever your country cannot be determined, it becomes active only after you agree in the cookie banner; the legal basis is then your consent (Art. 6(1)(a) GDPR, Section 25(1) TDDDG), which you can withdraw at any time. In all other countries both categories are on by default and you can object. You do both in the cookie settings, which you open with the āCookie settingsā entry in the footer or on the Cookie Policy page.
7. Account and Sign-in
For your account we store your email address, your credit balance and spending limit, and optional profile details (first name, last name, country, time zone, notification preferences). If you sign in with email and password, the sign-in service manages your password; it is never stored in plain text. You can also sign up and sign in without a password, using a sign-in link sent by email.
If you sign in with Google or GitHub, we receive your name, email address, your ID there and the address of your profile picture from them, and from GitHub also your username. Google or GitHub learn that you are signing in to our service. We show your profile picture in the dashboard; your browser loads it directly from Google or GitHub, which receive your IP address and browser data. We show Google One Tap according to your cookie choice (section 6).
For every sign-in session, the sign-in service stores the IP address and browser identifier; old sessions are currently not cleaned up automatically. If you switch on two-factor authentication, we store the recovery codes only as hashes. We log switching on two-factor authentication, new recovery codes, changes to your spending limit and changes to the credit limits of your API keys with IP address and browser identifier.
Emails: the only emails we send you automatically are for signing in (sign-in links, password reset links), a confirmation of the contract after every purchase of balance and an acknowledgement of receipt after a withdrawal with the withdrawal function (both section 11) and, where applicable, an automatic reply to your email to us (section 15). We write to you by hand when your request requires it, for example about a payout request (section 12). We store the notification preferences from your settings. Warnings about your API key limits and a low balance appear as notifications in your dashboard; we currently do not send them by email, and we do not send newsletters or promotional emails. Sign-in emails, contract confirmations, acknowledgements of receipt and our notices about incoming withdrawals to our own mailbox (section 11) are sent by the delivery service Resend: it accepts them on servers in the United States (Amazon Web Services, region us-east-1) and sends them through Amazon Web Services in the Ireland region.
Stripe: if you sign up with email and password in the sign-up form, we immediately create a customer record at Stripe (your email address and the internal IDs of your account). If you sign in with Google, GitHub or a sign-in link, this only happens when you save a card or open the customer portal; when you buy credits, Stripe receives your email address and the details from the checkout (section 11). The legal basis for this is Art. 6(1)(b) GDPR: the customer record is part of the billing of your account, through which you can buy credits; Stripe does not receive any payment details at this point.
Purpose: running your account, signing you in, managing your credits. Legal basis: Art. 6(1)(b) GDPR; for session and security logs Art. 6(1)(f) GDPR (protecting your account). Retention: account data until your account is deleted (section 18).
8. Using Models: Inputs, Results, History
We store every model run, whether it comes from the website, the API, the MCP server or a flow: your input (prompt, for chat requests the whole message history, settings, links to uploaded files), the result (full text, or a link for files), error messages from the AI service, token count, cost and duration. This lets you find your runs in your history and lets us bill them.
Files: we store uploaded images, audio files for transcription and generated images, audio and videos in our file storage on our server, in a folder for your account; we add a machine-readable AI label to generated images. This also applies to speech generated via the API: we return it in the response and store a copy in your history. If copying a result fails or a file is larger than our storage accepts, only the AI service's link remains (section 9).
The files in our file storage can be opened via their address without signing in: anyone who has the link can open the file. The address consists of your account ID and a timestamp. Your account ID is not public, but the address is not a secret like a password. So do not upload or generate anything that nobody but you may see; you can ask us to delete individual files at any time (section 21).
Retention: we currently do not delete runs and files automatically; we have not yet set a period. They remain until you ask for deletion or your account is deleted. Voice samples are the exception (section 10).
Free run without an account: where the website offers it, for example on the home page, you can try an inexpensive model once without an account. We store this run in the same way, but under a shared system account instead of an account of your own; we currently do not delete these runs automatically either.
We do not train AI models on your inputs or results ourselves. What the AI services do with the data is described in section 9.
Purpose: running and billing your runs, your history. Legal basis: Art. 6(1)(b) GDPR.
9. AI Services
The models do not run on our server but at external AI services. When you run a model, we send your input to the service that runs that model: prompt or messages, settings and uploaded files, or their address from which the service fetches them itself. We do not pass on your name or email address. However, the addresses of uploaded files contain the internal ID of your account. The user field you can set in the API is not passed on to the services.
Which service receives which data:
⢠Replicate: most of our catalogue, including image, video, audio, speech, transcription and voice cloning models as well as some text and code models. Replicate receives the prompt, settings and the addresses of uploaded images and audio files and fetches these files itself. Many of these models come from other developers, for example Black Forest Labs, Google, ByteDance, Kling, Runway, MiniMax, OpenAI or xAI, but run via Replicate. Whether and in which cases Replicate passes your input on to a model's developer is not expressly regulated in Replicate's terms; according to Replicate's documentation, predictions are visible only to the account that created them (here our account at Replicate).
⢠OpenAI: GPT and o models for chat (text and images), image generation (DALL-E 3), transcription (Whisper), speech output (TTS) and embeddings.
⢠Anthropic: Claude models for chat; for models that support it, also images and files.
⢠DeepSeek: DeepSeek models for chat, text only; we remove images beforehand.
Requests to OpenAI, Anthropic and DeepSeek pass through our own AI gateway on our server in Falkenstein. For each request it stores the model, token count, cost, time, technical error messages and the internal network address of our program that makes the request; no inputs or responses and not your IP address. No deletion period is configured for these entries; they contain no reference to your account. If a model is unavailable or the service rejects the request, the gateway can pass it on to a fallback model; the configured order is Anthropic (Claude Haiku), xAI (Grok) and DeepSeek. For the requests of your runs to OpenAI, Anthropic and DeepSeek we switch this off on every request, including streamed answers and requests for images, speech output, transcription and embeddings. The gateway therefore passes them only to the provider of the model you chose; if that provider fails, the run ends with an error and we refund the credits reserved for it. If an answer nevertheless comes from a fallback model and we can recognise it, the run also fails and we refund it. We connect to Replicate directly.
We copy results from Replicate (images, videos and audio) into our storage. If that fails, or if a file is larger than our storage accepts (currently 50 MB), we show Replicate's link, and your browser loads the result directly from Replicate; Replicate then sees your IP address.
Other services such as Google (Gemini), Hugging Face, ElevenLabs, Mistral or Together appear in the catalogue but are not connected at the moment; no runs are sent to them. The model page names who developed a model; that is not always the service that runs it.
How long the services keep inputs and outputs and whether they use them for their own purposes is governed by their terms. In detail:
⢠Replicate, LLC, 101 Townsend Street, San Francisco, CA 94107, USA: for runs via the API, Replicate deletes inputs, outputs and logs after one hour by default; output files on replicate.delivery expire after one hour. Under Replicate's terms, Replicate may use inputs only to provide the service, not to train its own models. Replicate is not certified under the EU-US Data Privacy Framework and does not name standard contractual clauses in its terms; the transfer currently takes place without an adequacy decision (section 17).
⢠OpenAI: the contracting party for customers in the EEA is OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland; the data is processed in the United States by OpenAI OpCo, LLC, 1455 3rd Street, San Francisco. According to OpenAI, API data is not used to train its models; for abuse monitoring OpenAI retains inputs and outputs for up to 30 days. OpenAI's Data Processing Addendum bases transfers to the United States on the European Commission's standard contractual clauses.
⢠Anthropic: the contracting party for customers in the EEA is Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland; the parent company is Anthropic, PBC, 548 Market Street, San Francisco, USA. According to Anthropic, API data is not used for training, and inputs and outputs are deleted within 30 days (retained for up to two years in case of violations of its usage policy). Anthropic's Data Processing Addendum bases transfers to the United States on the standard contractual clauses.
⢠DeepSeek: Hangzhou DeepSeek Artificial Intelligence Co., Ltd., People's Republic of China. DeepSeek processes and stores the data in the People's Republic of China and, under its privacy policy, may use it to train its models. There is no adequacy decision of the European Commission for China, and DeepSeek does not name standard contractual clauses in its terms. Therefore do not use DeepSeek models for personal or confidential inputs.
Purpose: running the model you chose. Legal basis: Art. 6(1)(b) GDPR.
10. Voice Cloning
For voice cloning you upload a voice sample to our server (MP3, WAV, WebM or Ogg, at most 10 MB and 60 seconds); this also applies to a sample you record in the browser. You also enter a text, which a model then speaks in that voice.
Confirmation: you may only use your own voice or the voice of a person who has expressly agreed to it (see the Terms of Service). You confirm this for every sample; without this confirmation we do not start a run. We store the confirmation with the run; it is not sent to the AI service.
Storage: we store the sample in our file storage under an address that contains your account ID and a random part that cannot be guessed. The AI service fetches it from there. We delete it automatically after 24 hours; because the deletion job runs hourly, after about 25 hours at the latest. The stored run keeps only the address of the sample, not the audio. We store the result, your text in the cloned voice, on the website and via the API like other results without an automatic deletion period (section 8).
AI service: all voice cloning models currently run via Replicate (section 9).
Legal basis: a voice sample can be biometric data (Art. 9 GDPR). We therefore process it only with explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR) and only for the run you start. For your own voice you give this consent with the confirmation before the run; you can withdraw it at any time by asking for deletion (we delete the sample itself after 24 hours anyway). For another person's voice, you obtain that person's explicit consent before uploading the sample, point them to this privacy policy and confirm to us with the checkbox that the consent exists; we cannot inform that person ourselves because we do not know them (Art. 14(5)(b) GDPR). You must be able to prove that person's consent to us on request; without it, the run is not permitted.
If your voice was used here without your permission, write to info@railwail.com. You have the rights set out in sections 21 and 22 even if you do not have an account with us.
11. Payments
You buy credits via Stripe. We show the checkout either embedded on our billing page or on a Stripe page; your browser loads Stripe's scripts only in the billing area. You enter your card details directly at Stripe; we do not see or store them. Stripe asks for what the card payment needs, for example the name on the card, the country and, depending on the country, the postal code. Stripe asks for your full billing address only if we issue an invoice for your purchase, because only the invoice needs it. We do not ask for a tax ID, and there is no automatic tax calculation: no VAT is charged under the German small business rule, § 19 UStG.
We store: the ID of your customer record at Stripe, every booking (amount, credits, checkout ID) and the messages Stripe sends us about purchases and other payment events (for example a failed payment, a refund or a dispute), each with Stripe's complete record. Depending on the message, they contain name, email address, billing address, company name and tax ID if given, and card details such as the card brand, the last four digits and the expiry date, never the full card number. If you save a card for later purchases, Stripe stores it; we only store an ID for it. With every purchase we pass the internal IDs of your account and the purchased amount to Stripe. Depending on your cookie choice we report the purchase to Google (section 6). Before every purchase you declare that provision of the balance is to begin immediately; we pass the time of this declaration to Stripe with the checkout, so it is also contained in the Stripe message we store. After the purchase we send you a confirmation of the contract to the email address from the checkout (balance, price, time, reference, your declaration with its time, right of withdrawal notice, Terms of Service). As proof we store, for every contract confirmation, its details (balance, price, times, reference, recipient address, language), whether and when it was sent and the ID assigned by the delivery service; if sending fails, we automatically try again. If you switch on automatic top-up, you give the declaration on immediate provision for every automatic top-up; we store its time with the setting and pass it to Stripe with every charge, and after every automatic top-up we send you a confirmation of the contract to the address of your account.
Purpose: processing your purchases and meeting legal obligations. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (retention under tax and commercial law). Retention: we keep bookings and booking records for the statutory period (§ 147 AO, § 257 HGB: eight years for booking records, ten years for books and records, in each case from the end of the calendar year) and delete them afterwards. We currently do not delete the other Stripe messages automatically; you can ask us to delete them insofar as they are not records.
Withdrawal: if you withdraw from a purchase with the withdrawal function on the page of the right of withdrawal notice, we store your name, the email address for the acknowledgement of receipt, your details of the purchase (if you are signed in, also the chosen top-up and your account), the time of receipt, the language of the page and a hash of your IP address that we compute with a secret key (not the address itself). We send you the acknowledgement of receipt by email and a notice with these details to our mailbox info@railwail.com. We store with the declaration whether and when both emails were sent. If sending fails, we automatically try again; what cannot be sent automatically we report to our mailbox with the reference number only, without name and address, and confirm it by hand. The program that evaluates emails to us with AI services (section 15) leaves this notice and this report out: neither goes to an AI service. Both arrive in our mailbox, the mail server forwards them from there to the operator's Gmail mailbox, and another program stores a copy in our administration database, as with other incoming messages (section 15). Purpose: processing your withdrawal and proving that it was received and that we acknowledged it. Legal basis: Art. 6(1)(c) GDPR (§ 356a BGB); for the hash of the IP address Art. 6(1)(f) GDPR (protecting the withdrawal function against abuse). Retention: for the details stored with the declaration, like booking records (see above); for the copies in our mailbox, the Gmail mailbox and the administration database, the retention in section 15 applies.
12. Referral Programme
If you refer users, you get a personal referral link. When someone opens it, we set the cookie rw_ref with your code (30 days; only the first link opened counts). If that person creates a new account within this time, we link it to your account. We rule out self-referrals by comparing email addresses and by not counting accounts created in a browser in which you opened your own referral page; sign-ups with addresses of disposable email services are not attributed.
As a referrer you only see a shortened ID for each referred person (for example āuserā¦1a2bā) and the commission per purchase with its date. The commission is 10% of the net purchase amount, so the time and amount of each purchase can be derived from it. It applies to purchases in the first 365 days after the referred person signed up. We base this per-purchase display on Art. 6(1)(f) GDPR: the referrer must be able to verify their commission but sees neither the name nor the email address of the referred person. As a referred user you can object to this display (section 22).
For a payout you provide a PayPal address or an IBAN and account holder. We review the request and transfer the money by hand; PayPal or the banks involved receive the necessary data. If you convert commission into credits, we need no payment details.
Older referral links of the form /ref/⦠set the cookie referral (30 days) instead, and we store the link's ID as the source of the new account.
Purpose: running the referral programme. Legal basis: for referrers Art. 6(1)(b) GDPR, for referred users Art. 6(1)(f) GDPR (legitimate interest in attributing and rewarding referrals). Retention: commissions and payouts are bookings; we keep them like booking records for the statutory period (section 11). The link between a referred account and yours remains until one of the two accounts is deleted.
13. API Keys and MCP
You create API keys for the API and the MCP server. Of each key we store only a hash (SHA-256) and its first characters, plus name, permissions, expiry date, request limit, the daily and monthly credit limits you set with warning threshold and email setting, the time of last use and of the last warning and, if you enter them, allowed IP addresses. For each key we record the credits used and the number of requests per UTC day, and for each run the key it was made with. When usage reaches your warning threshold or a limit, we create a notification in your dashboard with the key name, usage, limit and reset time. A revoked key is disabled; the entry remains in your account.
We store calls via the API and MCP like runs on the website (section 8) and send them to the model's AI service (section 9). We limit MCP calls without a key per IP address (section 5).
Legal basis: Art. 6(1)(b) GDPR; for limits Art. 6(1)(f) GDPR.
14. Fine-Tuning and Robotics Training
For training you name a public dataset on Hugging Face (in the form owner/name); you do not upload your own files for this. We check the dataset at Hugging Face without signing in; our server transmits the dataset's name and pins the checked version.
Training is to run on rented GPU machines from vast.ai. We prefer offers in the EU; if there are none, the machine may be outside the EU. The results (checkpoints) are to be stored in Hetzner object storage in Falkenstein; download links are valid for one hour. For every training job we store your account, the dataset, the settings, the progress and the cost.
The training service is currently in a test phase: no real training jobs run yet, and vast.ai does not receive any data yet. Once it starts, the rented machine receives only a job ID, a time-limited job token, the name of the public dataset, the settings and pick-up links for weights and result, not your account ID and not your email address. The provider is Vast.ai Inc., 1100 Glendon Ave #1840, Los Angeles, CA 90024, USA; vast.ai is not certified under the EU-US Data Privacy Framework, and under its terms data is processed in the United States. We have not yet set a deletion period for training results; they remain until you ask for deletion.
Legal basis: Art. 6(1)(b) GDPR.
15. Contacting Us by Email
If you write to info@railwail.com, we process your message and contact details to handle your request.
Our mailbox is on a virtual server we rent from OVHcloud. Its IP address is registered to OVH Sp. z o.o., ul. Swobodna 1, WrocÅaw, Poland; according to the network designation the server is located in Warsaw (Poland), i.e. in the EU.
A program on our Hetzner server reads new messages every five minutes. It sends sender name, sender address, subject and the first 4,000 characters of the text to an AI service, which classifies the message and drafts a reply. It tries OpenAI (via our AI gateway), Anthropic, DeepSeek, Google (Gemini) and xAI in this order until one answers. Then:
⢠The program answers simple standard cases automatically with the AI draft. The reply is labelled as AI-assisted and is sent to you via Resend.
⢠It forwards legally sensitive messages with the AI assessment and unclear ones with the AI draft, each with the full text; this also applies if the classification fails. The forwarding goes via Resend to a Gmail mailbox of the operator at Google.
The program can also classify a request about your data protection rights as a standard case and answer it automatically; such a reply does not replace our handling under section 21, which takes place within one month in any case. The Gmail mailbox is a Google account of the operator (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland); Google processes the messages stored there under its privacy policy. Messages to our mailbox can also be forwarded directly by the mail server to this Gmail mailbox, except messages it classifies as spam. The program leaves out the notices that our own system sends to this mailbox from noreply@railwail.com, for example about withdrawals (section 11); they reach the Gmail mailbox only through this forwarding.
In addition, another program on our server stores a copy of incoming messages (sender, subject, text) in the database of our internal administration area. Sender address and subject also appear in the program's log and, for automatic replies, in our administration database.
If you do not want your message processed this way, write to us by post at the address in section 1.
Legal basis: Art. 6(1)(b) GDPR if your request concerns your account or a contract, otherwise Art. 6(1)(f) GDPR (legitimate interest in handling requests quickly); for requests about your data protection rights Art. 6(1)(c) GDPR. Retention: no automatic deletion is currently set up for the emails in the mailbox, the forwarded copies in the Gmail mailbox, the copy in our administration database and the program's log; we delete them at your request insofar as no retention obligation applies.
16. Backups
We back up our databases every night. The backups are kept on a storage volume of our server (daily backups about two days, weekly backups 14 days) and as a copy in Hetzner object storage in Falkenstein, Germany. Our backup program does not delete these copies; the oldest date from 3 August 2026. Deleted data remains in the backups for as long as they exist. We have not yet set a period for these copies. Files from our file storage (section 8) are not part of this backup.
Purpose: protection against data loss. Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 32 GDPR.
17. Recipients and Transfers to Third Countries
These recipients receive data from us or via your browser. For each we name the company, its seat, its role and, where processing takes place outside the EU and the EEA, the basis for the transfer.
⢠Hetzner Online GmbH, IndustriestraĆe 25, 91710 Gunzenhausen, Germany: server, database, file storage, backups, storage for training results (sections 3, 14 and 16). Processor; processing in Germany.
⢠Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA: delivery and protection of the website (section 3). Processor; data centre depending on your location, also outside the EU. Basis: certification under the EU-US Data Privacy Framework and standard contractual clauses in Cloudflare's Data Processing Addendum.
⢠Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA): sending sign-in emails (section 7), contract confirmations, acknowledgements of receipt and notices about withdrawals to our mailbox (section 11), automatic replies and forwarded emails (section 15). Processor; emails are accepted in the United States. Basis: certification under the EU-US Data Privacy Framework and standard contractual clauses in Resend's Data Processing Addendum.
⢠OVHcloud (server registered to OVH Sp. z o.o., ul. Swobodna 1, WrocÅaw, Poland): our mail server (section 15). Processor; processing in Poland.
⢠OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, Ireland; processing by OpenAI OpCo, LLC, 1455 3rd Street, San Francisco, USA: GPT, o, image, speech and embedding models (section 9), classification of emails (section 15). Processor. Basis: standard contractual clauses in OpenAI's Data Processing Addendum.
⢠Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland; parent company Anthropic, PBC, 548 Market Street, San Francisco, USA: Claude models (section 9), classification of emails (section 15). Processor. Basis: standard contractual clauses in Anthropic's Data Processing Addendum.
⢠Replicate, LLC, 101 Townsend Street, San Francisco, CA 94107, USA: most models, including voice cloning (sections 9 and 10). Service provider that may use inputs only to provide the service under its terms. Not certified under the EU-US Data Privacy Framework, no standard contractual clauses in its terms; transfer currently without an adequacy decision.
⢠DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd., People's Republic of China): DeepSeek models (section 9), classification of emails (section 15). Processing and storage in China, use for training possible under its privacy policy; no adequacy decision, no standard contractual clauses in DeepSeek's terms.
⢠xAI (SpaceXAI LLC, USA): classification of emails (section 15). Not certified under the EU-US Data Privacy Framework; transfer currently without an adequacy decision.
⢠Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company Google LLC, Mountain View, USA, certified under the EU-US Data Privacy Framework): Google Analytics as processor; sign-in with Google, profile picture, Google One Tap and Google Ads as independent controller (sections 6 and 7); the operator's Gmail mailbox and Gemini for emails to us (section 15). Privacy policy: policies.google.com/privacy
⢠GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA, for users in the EEA GitHub B.V., Prins Bernhardplein 200, 1097 JB Amsterdam, Netherlands: sign-in and profile picture (section 7). Independent controller; certified under the EU-US Data Privacy Framework.
⢠X Internet Unlimited Company, One Cumberland Place, Fenian Street, Dublin 2, Ireland (parent company X Corp., Bastrop, Texas, USA, certified under the EU-US Data Privacy Framework): X pixel according to your cookie choice (section 6). Independent controller. Privacy policy: x.com/privacy
⢠Stripe Payments Europe, Limited, Dublin, Ireland (parent company Stripe, LLC, South San Francisco, USA, certified under the EU-US Data Privacy Framework): payments (section 11). Processor for the processing of payments, independent controller for fraud prevention and its own legal obligations; basis for transfers: Data Privacy Framework and standard contractual clauses in Stripe's Data Processing Agreement. Privacy policy: stripe.com/privacy
⢠Hugging Face, SAS, 9 rue des Colonnes, 75002 Paris, France (servers in the United States): checking public datasets for training (section 14); receives only the name of the dataset and the address of our server, no data of yours.
⢠Vast.ai Inc., 1100 Glendon Ave #1840, Los Angeles, CA 90024, USA: GPU machines for training once it starts (section 14). Not certified under the EU-US Data Privacy Framework; currently no data goes there.
⢠PayPal (Europe) S.à r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, or your bank: payouts in the referral programme (section 12), only with the details you provide for it. Independent controller.
Standard contractual clauses are the model contracts adopted by the European Commission (Implementing Decision (EU) 2021/914); where we name them, they are contained in the provider's data processing terms, and you can request a copy from us. The EU-US Data Privacy Framework is an adequacy decision of the European Commission; whether a company is certified can be checked at dataprivacyframework.gov. For Replicate, DeepSeek, xAI and vast.ai none of these bases currently exists. Whether your input goes to Replicate or DeepSeek is determined by your choice of model (section 9); the classification of emails (section 15) runs without your choice.
18. Retention and Account Deletion
As a rule, we delete data as soon as we no longer need it for its purpose and no retention obligation applies. For some data, however, there is currently no automatic deletion yet; this is noted for each item below:
⢠Account: until your account is deleted.
⢠Sign-in sessions with IP address and browser identifier: currently not cleaned up automatically.
⢠Security log (two-factor authentication, spending limit, API key limits): currently not deleted automatically.
⢠History and files: currently no automatic period; until you ask for deletion or your account is deleted.
⢠Key usage per day and notifications: currently no automatic period; until your account is deleted.
⢠Free runs without an account: currently no automatic period.
⢠Voice samples: 24 hours (about 25 hours at the latest).
⢠Bookings and payment data: for the statutory retention period (section 11); the other Stripe messages currently not deleted automatically.
⢠Referral payout details and commissions: for the statutory retention period like booking records (section 11).
⢠Withdrawal declarations: for the statutory retention period like booking records (section 11).
⢠Records of contract confirmations: for the statutory retention period like booking records (section 11).
⢠Our own analytics: IDs on page views 180 days, events 25 months (details in section 6).
⢠Google Analytics: 2 or 14 months, depending on the setting in our account (section 6).
⢠Access and service logs: rotated by size, currently about two weeks for the access log.
⢠Browser error reports: 180 days.
⢠AI gateway logs: currently not deleted automatically.
⢠Rate-limit counters: until the end of their time window, at most 24 hours.
⢠Emails to us: currently no set period (section 15).
⢠Backups: locally up to 14 days; copies in object storage currently not deleted automatically.
Deleting your account: there is no button for this yet. Write to info@railwail.com; we will delete your account and the related data within one month. Data we must keep, such as booking records, we restrict until the retention period ends instead of deleting it. We then delete your account in the sign-in service, your account record with history, files, API keys, flows and training jobs, and the account ID on analytics data; bookings and records remain stored, restricted, until the retention period ends. Copies in backups remain until those are deleted (section 16). What Stripe, Google, GitHub or an AI service stores about you is deleted by them under their own rules.
19. Do You Have to Provide Data?
You are not legally required to give us any data. We do need some data to provide the service:
⢠Without the technical data of your request (such as your IP address) we cannot deliver the website.
⢠For an account we need an email address (with a password or a sign-in link) or a sign-in via Google or GitHub.
⢠For a purchase, Stripe requires payment details, name and billing address.
⢠For a referral payout we need a PayPal address or bank details.
⢠A model can only work with an input.
Details such as first name, last name or country in your profile are optional.
20. Automated Decisions
We do not make decisions that have legal effects on you or similarly significantly affect you based solely on automated processing (Art. 22 GDPR). Our system does apply some rules automatically:
⢠Free credits: new accounts that sign in with Google receive 10 credits (USD 0.10), except for addresses of disposable or alias email services. Accounts that sign up with email or GitHub receive none.
⢠Trial rules for accounts without a purchase: the account must be at least 24 hours old; at most 5 runs per 24 hours and 2 credits per run; after 3 failures in a row no more trial runs; at most 8 trial runs per IP network and 24 hours across all accounts. These rules no longer apply after a purchase.
⢠Limits: request limits (section 5), your balance, the spending limit you set yourself and the credit limits you set for individual API keys.
These rules only affect free use and technical limits. We do not suspend accounts automatically, and a person reviews referral payouts. These rules reject at most a single trial run; they do not suspend any account, and you can buy credits at any time or write to us at info@railwail.com. In our assessment this is not a decision with legal effect or a similarly significant impact within the meaning of Art. 22 GDPR.
21. Your Rights
You have the right to:
⢠access your stored data (Art. 15 GDPR)
⢠rectification of inaccurate data (Art. 16)
⢠erasure of your data (Art. 17)
⢠restriction of processing (Art. 18)
⢠data portability (Art. 20)
⢠object to processing (Art. 21, see section 22)
⢠withdraw consent with effect for the future (Art. 7(3))
To exercise these rights, write to info@railwail.com or by post (section 1). There is no button for export or deletion yet. We reply within one month (Art. 12(3) GDPR). Please note that we process emails to us as described in section 15; by post you reach us without this evaluation.
22. Objection and Withdrawal of Consent
Right to object (Art. 21 GDPR): where we process data on the basis of our legitimate interest (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims. You can object to our own analytics without giving reasons, using the button in section 6.
Withdrawal: you can withdraw consent at any time; this does not affect the lawfulness of processing before the withdrawal. You change your consent for analytics and marketing in the cookie settings (section 6).
Send an objection or withdrawal to info@railwail.com or by post (section 1).
23. Right to Lodge a Complaint
You can lodge a complaint with a data protection supervisory authority, for example the authority where you live or work. The authority responsible for us is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
LautenschlagerstraĆe 20
70173 Stuttgart
https://www.baden-wuerttemberg.datenschutz.de
24. Changes
We update this privacy policy when our service or the law changes. The current version is always on this page; the date at the top shows when it was last updated.
See also: Cookie Policy Ā· Terms of Service Ā· Impressum