Privacy Policy

Version 1.0 · 27 July 2026 · Deutsche Fassung weiter unten

Send a Scratch is built so that the contents of a card cannot be read by the people running it. That is not a promise about our conduct; it is how the software is put together, and the two places where it does not hold are named explicitly below.

1. Who is responsible

DonkeyCat GmbH, Lindengasse 43/19, A-1070 Vienna, Austria, is the controller within the meaning of Art. 4(7) GDPR. Full company details are in the imprint. For any question about this policy or to exercise a right listed in section 8, write to office@donkeycat.com.

We have not appointed a data protection officer; the thresholds in Art. 37 GDPR are not met.

2. How the encryption changes what we hold

When you build a card, your browser assembles the image, the message and any calendar event and encrypts them with AES-256-GCM before anything is uploaded. The key is generated in your browser, is never sent to us, and ends up in the fragment of the link — the part after the #. Browsers do not transmit that part of a URL to servers, so the key cannot appear in a request, a log file or a backup, even accidentally.

The practical consequence: we hold a block of bytes we cannot decrypt. We cannot tell you what a card contains, we cannot produce it in response to a request, and we cannot hand it to anyone else in a readable form. We can delete it.

The two exceptions, stated plainly

A link preview in WhatsApp is rendered by a crawler that holds no key and runs no JavaScript. For a preview to exist at all, some things must be readable by us. Those are:

These are stored unencrypted and are visible to anyone who receives the link, before they scratch anything. The builder says so at the point where you enter them. Nothing else about a card is readable.

3. What is stored, and why

DataPurposeLegal basis
Encrypted card contents Delivering the card you asked us to host Art. 6(1)(b) — performance of the service you requested
Occasion, custom preview image and wording Rendering the link preview Art. 6(1)(b)
Language, size in bytes, creation and expiry time Serving the card and deleting it on schedule Art. 6(1)(b)
Unlock time and time zone, when you set one Refusing to release the card before that moment Art. 6(1)(b)
First and last open time, number of opens Answering “has it been scratched yet?” for the sender Art. 6(1)(b)
A hash of your five-character management code Checking the code without being able to reconstruct it Art. 6(1)(b)
A hash of the requesting IP address, plus an hourly counter Rate limiting; stopping bulk abuse and code guessing Art. 6(1)(f) — our legitimate interest in keeping the service usable

The IP address is used as a hash and is not stored in readable form. We do not know who created a card, and there is nothing in the record that identifies you.

What is not collected

No accounts, names or email addresses. No cookies, no localStorage, no sessionStorage. No analytics, no tracking pixels, no advertising, no profiling, no automated decision-making within the meaning of Art. 22 GDPR. Web fonts are served from this domain, so loading a page makes no request to any third party.

4. Retention

5. Hosting and processors

The service runs on Google Cloud Run with Google Cloud Firestore, operated by Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland, as our processor under Art. 28 GDPR. Compute is in region europe-west1 (Belgium) and storage in the EU multi-region eur3. Google's Data Processing Addendum and the EU Standard Contractual Clauses apply. No other processor is involved, and no data is sold, rented or shared for advertising.

6. Recipients

Anyone you send the link to can open the card — that is the point of it. We do not disclose data to anyone else, except where we are legally obliged to. Note that even under a legal obligation we could only produce ciphertext and the metadata in section 3, because we hold no key.

7. What you put in a card is your call

You choose what goes behind the foil, including whether it contains personal data about someone else. If it does, you are the one deciding that, and the same rules apply to you as to anyone handling another person's data. Please do not use a scratch card as a way of moving sensitive information around — it is a gift, not a vault, and the terms list what may not be uploaded.

8. Your rights

Under Art. 15–21 GDPR you have the right of access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests. Write to office@donkeycat.com.

Two honest limits. First, a card record contains nothing that identifies you, so in most cases we cannot connect a request to a specific record — please include the card id from your link. Second, we cannot give you the contents of a card, because we cannot decrypt them; you already hold the only key, in your own link.

You may also complain to a supervisory authority, in Austria the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

9. Children

The service is not directed at children and asks for no age information. It also asks for no personal data at all, so there is nothing to verify.

10. Changes

Material changes are published here with a new version number and date. The current version is shown at the top of this page.


Datenschutz­erklärung

Fassung 1.0 · 27. Juli 2026

Send a Scratch ist so gebaut, dass die Betreiber den Inhalt einer Karte nicht lesen können. Das ist kein Versprechen über unser Verhalten, sondern eine Eigenschaft der Software — und die beiden Stellen, an denen es nicht gilt, sind unten ausdrücklich benannt.

1. Verantwortlicher

DonkeyCat GmbH, Lindengasse 43/19, A-1070 Wien, Österreich, ist Verantwortlicher im Sinne des Art. 4 Z 7 DSGVO. Die vollständigen Unternehmensdaten stehen im Impressum. Für Fragen zu dieser Erklärung oder zur Ausübung eines Rechts aus Punkt 8: office@donkeycat.com.

Ein Datenschutzbeauftragter wurde nicht bestellt; die Schwellen des Art. 37 DSGVO sind nicht erreicht.

2. Was die Verschlüsselung ändert

Beim Bauen einer Karte setzt dein Browser Bild, Text und einen allfälligen Termin zusammen und verschlüsselt das Ganze mit AES-256-GCM, bevor irgendetwas hochgeladen wird. Der Schlüssel entsteht in deinem Browser, wird nie an uns gesendet und landet im Fragment des Links — dem Teil nach dem #. Diesen Teil einer Adresse übertragen Browser grundsätzlich nicht an Server; er kann also weder in einer Anfrage noch in einem Logfile oder einem Backup auftauchen.

Praktische Folge: Wir haben einen Block Bytes, den wir nicht entschlüsseln können. Wir können dir nicht sagen, was in einer Karte steht, können sie auf Anfrage nicht herausgeben und niemandem in lesbarer Form weitergeben. Löschen können wir sie.

Die zwei Ausnahmen, deutlich gesagt

Die Linkvorschau in WhatsApp wird von einem Programm erzeugt, das keinen Schlüssel hat und kein JavaScript ausführt. Damit es überhaupt eine Vorschau geben kann, muss etwas für uns lesbar sein. Das sind:

  • der gewählte Anlass (etwa birthday) und
  • ein eigenes Vorschaubild samt Vorschautext, falls du eines hinterlegst.

Beides wird unverschlüsselt gespeichert und ist für alle sichtbar, die den Link bekommen — bevor gerubbelt wird. Im Baukasten steht das direkt bei den Eingabefeldern. Sonst ist an einer Karte nichts lesbar.

3. Was gespeichert wird und wozu

DatenZweckRechtsgrundlage
Verschlüsselter KarteninhaltBereitstellung der Karte, die du hosten lassen wolltestArt. 6 Abs. 1 lit. b — Erbringung der gewünschten Leistung
Anlass, eigenes Vorschaubild und VorschautextErzeugung der LinkvorschauArt. 6 Abs. 1 lit. b
Sprache, Größe in Bytes, Erstellungs- und AblaufzeitpunktAusliefern und fristgerechtes LöschenArt. 6 Abs. 1 lit. b
Öffnungszeitpunkt und Zeitzone, falls gesetztVerweigerung der Herausgabe vor diesem MomentArt. 6 Abs. 1 lit. b
Erstes und letztes Öffnen, Anzahl der ÖffnungenBeantwortung der Frage „schon gerubbelt?“ für den AbsenderArt. 6 Abs. 1 lit. b
Prüfsumme des fünfstelligen CodesPrüfung des Codes, ohne ihn rekonstruieren zu könnenArt. 6 Abs. 1 lit. b
Hashwert der IP-Adresse samt StundenzählerRatenbegrenzung gegen Massenmissbrauch und Code-RatenArt. 6 Abs. 1 lit. f — berechtigtes Interesse an einem benutzbaren Dienst

Die IP-Adresse wird nur als Hashwert verwendet und nicht im Klartext gespeichert. Wir wissen nicht, wer eine Karte erstellt hat; im Datensatz steht nichts, was dich identifiziert.

Was nicht erhoben wird

Keine Konten, Namen oder E-Mail-Adressen. Keine Cookies, kein localStorage, kein sessionStorage. Keine Analyse, keine Tracking-Pixel, keine Werbung, kein Profiling, keine automatisierte Entscheidungsfindung im Sinne des Art. 22 DSGVO. Schriftarten liegen auf dieser Domain — beim Aufruf einer Seite geht keine Anfrage an Dritte.

4. Speicherdauer

5. Hosting und Auftragsverarbeiter

Der Dienst läuft auf Google Cloud Run mit Google Cloud Firestore, betrieben von Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Irland, als Auftragsverarbeiter gemäß Art. 28 DSGVO. Die Verarbeitung erfolgt in der Region europe-west1 (Belgien), die Speicherung in der EU-Mehrfachregion eur3. Es gelten der Datenverarbeitungszusatz von Google und die EU-Standardvertragsklauseln. Weitere Auftragsverarbeiter gibt es nicht; Daten werden weder verkauft noch vermietet noch für Werbung weitergegeben.

6. Empfänger

Wer den Link bekommt, kann die Karte öffnen — das ist ihr Zweck. Darüber hinaus geben wir nichts weiter, außer wir sind gesetzlich dazu verpflichtet. Auch dann könnten wir nur den Geheimtext und die Metadaten aus Punkt 3 herausgeben, weil wir keinen Schlüssel haben.

7. Was du in eine Karte legst, entscheidest du

Du wählst, was hinter der Folie steckt — auch, ob darin personenbezogene Daten anderer Personen vorkommen. Wenn ja, ist das deine Entscheidung, und es gelten für dich dieselben Regeln wie für jeden, der fremde Daten verarbeitet. Bitte benutze ein Rubbellos nicht, um heikle Informationen zu transportieren — es ist ein Geschenk, kein Tresor. Was nicht hochgeladen werden darf, steht in den AGB.

8. Deine Rechte

Nach Art. 15–21 DSGVO hast du das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit und Widerspruch gegen eine Verarbeitung auf Grundlage berechtigter Interessen. Wende dich an office@donkeycat.com.

Zwei ehrliche Einschränkungen. Erstens enthält ein Kartendatensatz nichts, was dich identifiziert — wir können eine Anfrage meist keinem Datensatz zuordnen. Bitte gib die Karten-ID aus deinem Link an. Zweitens können wir dir den Inhalt einer Karte nicht geben, weil wir ihn nicht entschlüsseln können; den einzigen Schlüssel hast du selbst, in deinem Link.

Du kannst dich auch bei einer Aufsichtsbehörde beschweren, in Österreich bei der Datenschutzbehörde, Barichgasse 40–42, 1030 Wien, www.dsb.gv.at.

9. Kinder

Der Dienst richtet sich nicht an Kinder und fragt kein Alter ab. Er fragt überhaupt keine personenbezogenen Daten ab, es gibt also nichts zu prüfen.

10. Änderungen

Wesentliche Änderungen werden hier mit neuer Fassungsnummer und neuem Datum veröffentlicht. Die aktuelle Fassung steht oben auf dieser Seite.