Privacy Policy

1. An overview of data protection

General information

The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website or use the application at app.kistn.com. The term "personal data" comprises all data that can be used to personally identify you.

Data recording at Kistn

Who is the responsible party for the recording of data?

The data is processed by the operator of Kistn, whose contact information is available under section "Information about the responsible party" in this Privacy Policy.

How do we record your data?

We collect your data as a result of your sharing of your data with us — for instance, when you register an account, create a project, or contact us. Other data is recorded automatically by our IT systems when you visit the website or application, or when your client tools push inventory data.

Your rights

You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee. You also have the right to demand that your data be rectified or eradicated. If you have consented to data processing, you have the option to revoke this consent at any time.

2. Hosting

Hetzner

Our servers and the object storage used for uploaded files are provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Hetzner). Outbound email is sent via a mail server we operate ourselves, also hosted on Hetzner infrastructure. For details, please view the data privacy policy of Hetzner: https://www.hetzner.com/de/rechtliches/datenschutz.

3. General information and mandatory information

Data protection

The operators of Kistn take the protection of your personal data very seriously. We handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.

Information about the responsible party (controller)

The data processing controller is:

Christian Doebler Software Development & IT Services
Kientalstr. 3
82211 Herrsching
Germany

Phone: +49 8152 993 8198
E-mail: mail@christian-doebler.net

4. Data recording at Kistn

Cookies

This website (kistn.com) does not itself set cookies. When you sign in to the application at app.kistn.com, we use an essential session cookie to keep you logged in. This cookie is required for the application to function and is not used for tracking or advertising.

Registration and authentication

When you create an account, we store your name, email address, and a hashed password. If you use a passkey (WebAuthn) or two-factor authentication instead of or in addition to your password, we store the corresponding public key credential or an encrypted secret and recovery codes. We use this data solely to authenticate you and secure your account.

Projects and API tokens

Each project you create is assigned an API token that your local client tools (Composer plugin, WordPress plugin, JS collector) use to push inventory data. Tokens are stored in hashed form; the plaintext token cannot be recovered once issued. We record when a token was last used.

Uploaded package files

When enabled, your client tools may upload lock and manifest files (e.g. composer.lock, package-lock.json) so the server can independently verify or re-audit your project's dependencies. Uploaded files are stored twice: an untouched original (kept for audit and forensic purposes) and a sanitized working copy with executable script hooks removed before any server-side tool processes it. These files are stored in Hetzner Object Storage and are only accessible through your account.

Inventory and vulnerability data

We keep an append-only history of every package added, updated, or removed in your projects, so you can always see what changed and when. Vulnerability findings are stored per package, version, and advisory. For packages that are not marked private, a finding is shared automatically with every other project on the platform running the exact same package version — no personal data is exchanged in this process, only the fact that a given package version is affected. Packages you mark, or that we detect, as private are excluded from this sharing and remain visible only within your own projects.

Email notifications

Based on your notification settings, we send you emails about new vulnerability findings, discrepancies between client- and server-reported audits, and — if enabled — a periodic digest. Emails are delivered via a mail server we operate ourselves on Hetzner infrastructure.

Server log files

Our servers automatically collect and store information in server log files, which your browser or client communicates to us automatically. This comprises: browser or client type, operating system, referrer URL, time of the server inquiry, IP address. This data is not merged with other data sources.

Data retention and deletion

We retain your account, project, uploaded file, and inventory data for as long as your account exists. When you delete a project, its packages, uploaded files, event history, and associated vulnerability findings are deleted. When you delete your account, all projects and associated data are deleted, except where we are legally required to retain records (e.g. billing or tax records) for longer.

Request by e-mail or telephone

If you contact us by e-mail or telephone, your request, including all resulting personal data, will be stored and processed by us for the purpose of processing your request. We do not pass this data on without your consent.