Privacy Policy
Last updated: 16 July 2026
This policy explains what personal data 128KB collects, why, and what rights you have. It is written for the GDPR (DSGVO).
1. Who is responsible
The controller for data processing on this website is:
Tim Rodenbröker
Consell de Cent 394 4-2
08009 Barcelona
Espana
Email: post@timrodenbroeker.de
This must match the details in our Imprint.
2. What we collect, and why
2.1 When you create an account
To register as a creator you provide:
| Data | Required? | Why |
|---|---|---|
| Username | Yes | Identifies your account and appears publicly next to your work |
| Email address | Yes | Account approval, password resets, service messages |
| Password | Yes | Stored only as a salted hash — we never see it |
| Bio | No | Shown publicly on your creator page |
| Website | No | Shown publicly on your creator page |
| Profile picture | No | Shown publicly next to your name |
We also record the date you accepted these terms, as evidence that consent was obtained.
New accounts are held in a pending state until reviewed manually. We do this to prevent spam. Your email address is used to tell you the outcome.
Legal basis: Art. 6(1)(b) GDPR — performance of a contract (your membership). The record of terms acceptance rests on Art. 6(1)(f) — our legitimate interest in evidencing agreement.
2.2 When you submit a GIF
Submitted GIFs are stored on our server and reviewed before publication. Once approved, the GIF is published publicly and attributed to your creator name.
Legal basis: Art. 6(1)(b) GDPR. You decide what to submit and what to write in your profile.
2.3 What is public
Please be aware that the following are visible to anyone on the internet, including search engines:
- Your creator name
- Your bio, website link, and profile picture
- Every GIF of yours we have published
Your email address is never shown publicly.
2.4 Contact forms
If you write to us through a form on this site, the data you enter is transmitted by email to us and retained so we can handle your enquiry.
Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR.
2.5 Server log files
Our hosting provider automatically records technical data each time the site is accessed: IP address, date and time, page requested, referrer, browser and operating system. This is necessary to operate the site securely and is not combined with other data or used to identify you.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in a secure, functioning website.
Hosting provider: [[HOSTING COMPANY, ADDRESS]] — we have a data processing agreement (AVV) in place.
2.6 Cookies
We use only what the site needs to work. We do not use tracking, advertising, or analytics cookies.
| Cookie | Purpose | Duration |
|---|---|---|
| WordPress session/login cookies | Keep you logged in | Session, or up to 14 days if you tick “remember me” |
| Comment cookies | Remember your name and email if you leave a comment | Up to 1 year |
Because these are strictly necessary for a service you actively requested, no cookie banner is required for them.
3. Third parties
Gravatar. [[DECIDE — see note below]] If you have not uploaded a profile picture, WordPress requests a default avatar from Gravatar, a service of Automattic Inc. (USA). To do this, a hash of your email address is transmitted to Gravatar, which may allow them to recognise you. Automattic is certified under the EU-US Data Privacy Framework. Privacy policy: https://automattic.com/privacy/
You can remove this entirely by unticking “Show Avatars” under Settings → Discussion, in which case delete this paragraph.
Email delivery. Outgoing mail (account approvals, password resets) is sent via our SMTP provider [[SMTP PROVIDER NAME AND ADDRESS]]. They process the recipient address and message content solely to deliver it.
Embedded tools. Some pages embed interactive tools from tools.128kb.eu in an iframe. This is our own subdomain; no third party receives your data through it.
Fonts. All fonts are served from our own server. No connection is made to Google Fonts.
Analytics. We do not use Google Analytics or any comparable tracking service.
4. How long we keep your data
- Account data: for as long as your account exists.
- Published GIFs: until you delete your account or ask us to remove them.
- Server logs: [[usually 7–30 days — confirm with your host]].
- Contact enquiries: until the matter is resolved, subject to statutory retention periods.
5. Deleting your account
You can delete your account yourself at any time: open the user menu, choose Edit Profile, then Delete my profile.
This is immediate and permanent. It deletes your account and every GIF you have submitted. It cannot be undone. If you would like your GIFs to remain published under a different attribution, contact us before deleting.
6. Your rights
Under the GDPR you have the right to:
- Access (Art. 15) — ask what data we hold about you
- Rectification (Art. 16) — correct inaccurate data
- Erasure (Art. 17) — have your data deleted
- Restriction (Art. 18) — limit how we process your data
- Data portability (Art. 20) — receive your data in a machine-readable format
- Object (Art. 21) — object to processing based on legitimate interest
To exercise any of these, email post@timrodenbroeker.de.
You also have the right to complain to a supervisory authority. The authority responsible for us is [[YOUR STATE’S DATA PROTECTION AUTHORITY — e.g. Berliner Beauftragte für Datenschutz und Informationsfreiheit]].
7. Data security
This site is served over HTTPS. Passwords are stored only as salted hashes.
8. Changes to this policy
We may update this policy as the site changes. The date at the top shows the current version.