Privacy Notice
As of 1 October 2026 · GDPR Art. 13/14 · The German version is the authoritative text.
1. Controller
Schübeler Consulting
Johann Jörgen Schübeler
Am Kreuzberg 10, 37688 Beverungen, Germany
Email: info@schuebeler-consulting.de
2. Data we process
- Account data: email address and the workspace name you choose. Legal basis: Art. 6(1)(b) GDPR (contract).
- Memories: the texts you upload or store through the interface. Held in an indexed database in a German data centre (Nuremberg). Legal basis: Art. 6(1)(b) GDPR.
- Your own AI keys: if you store provider keys, they are encrypted with a key specific to your workspace. Only your workspace can use them, and they are not kept in plain text on our servers.
- Access log: sign-in times, plan changes, creation and revocation of API tokens. When you retrieve knowledge through a connected AI or through the interface, we also record the first 80 characters of the query and its total length; searches in the web interface record the length only. We further record the units returned, at most 25 per retrieval, with identifier, kind, title (up to 120 characters) and match score (how well the hit fitted the query). Storing and uploading records the title (up to 200 characters), the length of the content, and its type, source and domain — never the content itself. Every entry also carries the IP address, the technical identifier of the requesting program, the name of the access used, and the name and version of the connected application. These entries can contain personal data as soon as you put such data into queries or titles. The log is visible in the audit area of your workspace and can be exported as JSON.
- Payment data: on paid plans, Stripe Payments Europe Ltd. (Ireland) handles payment and issues the invoices in our name. Your card details stay with Stripe. Stripe sends us the status of your subscription and every invoice. For each invoice we store, in our invoice archive, the invoice number, the recipient's name and email address, the amounts, the line items and the invoice file (section 9). Legal basis: Art. 6(1)(b) GDPR; for keeping the invoices, Art. 6(1)(c) GDPR together with § 14b of the German VAT Act (UStG) and § 147 of the German Fiscal Code (AO).
Legal basis for the access log: Art. 6(1)(f) GDPR. Our legitimate interest is being able to show who retrieved which knowledge and when. Without that record, no one can establish after a security incident which content was affected. We keep the intrusion small by storing extracts and metadata only, and by deleting each entry automatically once the retention period in section 9 has passed.
Your right to object: you may object to this processing under Art. 21 GDPR. The access log cannot be switched off while knowmind is in use, because it carries the evidential value. We examine every objection individually and tell you the outcome.
What remains after a deletion: if you delete a single memory, log entries about earlier access to it remain until the retention period in section 9 has passed, and they can contain the title of the deleted memory. Individual log entries can neither be changed nor removed before their retention period ends: the entries are linked into a chain, and that chain proves the log is complete. We delete log entries in two ways. Every day we delete the entries whose retention period has passed. When you delete your workspace, we delete its entire log (section 9).
3. Processors
- Hetzner Online GmbH, Gunzenhausen — server hosting in Nuremberg, Germany. Data processing agreement under Art. 28 GDPR in place.
- Stripe Payments Europe Ltd., Dublin — payment handling for paid plans.
- ALL-INKL.COM (Neue Medien Münnich), Friedersdorf, Germany — sending of sign-in links and billing notices.
4. AI providers (your own keys)
You may optionally store your own provider keys (Anthropic, OpenAI, Google, Mistral, local models). Inference requests then go from our server directly to the provider you chose. We recommend using a provider outside the EU only if you have your own data processing agreement with them.
Third-country note: choosing a provider outside the EU/EEA means inference transfers data to a third country. You initiate and are responsible for that transfer through your choice of provider; the legal basis for it (for example EU standard contractual clauses or an adequacy decision) has to exist between you and that provider. Schübeler Consulting does not cover this transfer with its own standard contractual clauses. If you use EU providers or local models only, content does not leave the EU through knowmind.
Indexing stays local: the vector indexing of your memories (embeddings) happens inside our server environment in Germany. No content is sent to external providers for indexing.
5. Connectors to your own systems
You can set up a connector through which a system you operate — Jira, for example — hands content to knowmind. knowmind retrieves nothing: it holds no credentials for your system and only receives what you have it send. Which events those are is decided in your system.
What that involves: the content itself plus whatever your system includes — for Jira that means issue key, summary, description, resolution and the names of the people involved, such as assignees or comment authors. These are stored like any other memory in your workspace, processed in Germany and not passed to third parties.
Your responsibility: since you decide which events your system sends, you also decide which personal data is handed over. Before setting a connector up, check whether the people concerned — employees or customers whose names appear in issues — may be included, and whether your works council has to be involved. We process this data solely on your instructions under Art. 28 GDPR.
Deletion: you delete content received through a connector like your other memories. Every intake through a connector is also recorded in your workspace's access log, and that entry can contain the name of the item received. It remains until the retention period in section 9 has passed or you delete your workspace. Together with the workspace we also delete the received content and its log entries (section 9).
6. Use through the ChatGPT app
If you use knowmind through the app directory of ChatGPT, OpenAI operates that surface. In that setting OpenAI and Schübeler Consulting are separate controllers: your conversation with ChatGPT is governed by OpenAI's terms and privacy notice, what you store in knowmind is governed by this notice. There is no data processing agreement between us and OpenAI, because neither of us processes on behalf of the other.
Practically this means: what our app returns to ChatGPT — the memories you retrieve — passes through OpenAI's systems and is subject to their developer terms, under which OpenAI may use app responses. Your stored content itself stays in Germany. If that separation matters to you, use knowmind through a client where you control the model, or through your own provider key.
7. Your rights
You have the right to:
- access (Art. 15 GDPR)
- rectification (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- objection (Art. 21)
You do not have to ask us for most of these. You can export your data yourself at any time (how that works). You delete single memories and documents in the dashboard, and your entire workspace including your account under “Arbeitsbereich löschen” (delete workspace) in the dashboard. What that deletes and what we keep is described in section 9. If you cannot trigger the deletion yourself, write to info@schuebeler-consulting.de; we handle your request without undue delay and within one month at the latest (Art. 12(3) GDPR). For anything else, write to info@schuebeler-consulting.de. You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
8. Cookies
Only what the service needs to work: cookies for signing in and, if you switch the language, a cookie with your language choice (valid for 1 year). No tracking, no advertising cookies, no consent banner — because there is nothing to consent to. The Stripe checkout sets its own cookies; Stripe's privacy notice describes them.
9. Retention
Memories, documents and account data stay stored for as long as your workspace exists. If a paid plan ends, your workspace continues on the free Private plan and your data is kept in full. If your data exceeds the limit of that plan, you can still read and retrieve it but cannot store anything new. If you terminate the contract as a whole, your data remains available for 30 days; after that we delete the workspace as described below. We delete access log entries after a period that depends on your plan: 1 month on Private, 3 months on Pro, 12 months on Team, 24 months on Business, 5 years on Enterprise. For other plans, the period is shown in the audit area of your dashboard.
Deleting your workspace: as soon as you delete your workspace in the dashboard, we block all access. You can no longer sign in, and your access keys stop working. From that moment the workspace can no longer be restored. In the same step we delete your entries in the knowledge graph, which stores the links between your memories. No earlier than 24 hours later we delete all remaining data of the workspace from our database; a deletion run that runs every hour does this. It deletes account data, memories, documents with all their parts, the access log, the change log (which records when memories were created, changed or deleted), and your plan and billing details except the invoices (see below). The retention periods of the access log end early as a result. If entries are left in the knowledge graph because deleting them there did not fully succeed, the deletion run waits until we have deleted them.
What remains after the deletion:
- Invoices: we keep your invoices for 8 years, counted from the end of the year in which each invoice was issued (§ 14b UStG, § 147 AO). Each invoice shows the recipient's name and email address, the amounts and the line items. We use the invoices only to meet this retention duty (Art. 6(1)(c), Art. 17(3)(b) GDPR) and delete them once the period has passed.
- Closing anchor: for the access log and for the change log, one closing anchor each remains permanently. It holds the internal identifier of the workspace and the position and checksum of the last entry; for the access log it also holds the number of deleted entries. It contains no names, addresses or content. The closing anchor proves that the log was complete up to the deletion.
- Backups: we keep backups of our database for up to 8 weeks and then delete them. Until then, data of a deleted workspace can still be contained in a backup. We do not delete it from backups individually. We only use a backup when we have to restore the database.
- Data held by Stripe: the deletion run does not delete the data Stripe stores about your subscription. We arrange its deletion at Stripe if you ask us to at info@schuebeler-consulting.de.
10. Personal data breaches
If we become aware of a breach — unauthorised access, loss or accidental disclosure — we follow a fixed procedure: analyse, contain, document, and assess the risk to the people affected.
- Where we are the controller for the data concerned (account, payment or email data) and the breach is likely to result in a risk to rights and freedoms, we notify the competent supervisory authority without undue delay, where feasible within 72 hours (Art. 33 GDPR). Where the risk is likely to be high, we inform the people affected without undue delay and in plain language (Art. 34 GDPR).
- For the content you process in knowmind as a business customer, you are normally the controller and we are your processor. In that case we do not notify the authority ourselves; we inform you without undue delay and within 48 hours at the latest, with the information available on nature, consequences and countermeasures, so that you can meet your own obligations under Art. 33 and 34 GDPR. The data processing agreement sets out the details.

