This Privacy Policy explains how oglimmer.com / Oliver Zimpasser ("we", "our", "us") processes personal data when you use Renovate Initializr (the "Service"). It applies to all visitors and to signed‑in users of the dashboard.
Controller within the meaning of Art. 4(7) GDPR:
Oliver Zimpasser, Berliner Str. 39a, 63110 Rodgau, Germany
Email: oglimmer@gmail.com
We have not appointed a Data Protection Officer because we are not required to do so under Art. 37 GDPR.
We process the following categories of personal data, depending on how you use the Service:
renovate.json happen entirely in your browser and do not require an account or send personal data to us. renovate.json is not normally personal data, but you control what you paste in. repo and read:org scopes, or the GitLab read_api scope. These tokens may technically grant broader access than the Service uses; the Service only reads repository metadata and Renovate configuration files and never creates, modifies or deletes anything in your repositories. The token is held only for the duration of your session (refreshed where your provider issues short‑lived tokens) and is not stored in our database. owner/repo) of the repositories you choose to track on the dashboard. You are not under any statutory or contractual obligation to provide personal data. You can use the configuration builder, preview, download and REST API without an account. Signing in is only necessary if you want to use the dashboard to compare your repositories' configuration; if you do not sign in, that feature is simply unavailable to you.
We do not carry out any automated decision‑making, including profiling, that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR.
The "AI feedback" feature and the REST API call a third‑party AI provider, DeepSeek (operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., People's Republic of China), to analyse a configuration. Only the configuration text you submit for that single request is transmitted. No account data, access tokens, tracked‑repository lists or server logs are sent. This feature is only active when the operator of the instance has configured an AI provider API key.
We disclose personal data only to the following categories of recipients:
When you use the AI review feature, the configuration text you submit is transferred to DeepSeek in the People's Republic of China, for which the European Commission has not issued an adequacy decision. Because the review is carried out only at your explicit request and is necessary to provide the feature you asked for, we rely on the derogations in Art. 49(1)(a) and (b) GDPR for this transfer. The transfer carries the risks generally associated with transfers to countries without an adequacy decision; if you do not wish your configuration to be transferred, simply do not use the AI review feature. You can request more information by contacting us (see Section 11).
When you sign in to the dashboard, we set the following strictly necessary cookies:
XSRF-TOKEN — a cross‑site request forgery (CSRF) protection token that the frontend reads and echoes back on state‑changing requests. The Service also uses your browser's sessionStorage to hand a configuration over from the dashboard to the editor ("Open in editor"); this stays in your browser and is not sent to us.
These items are strictly necessary to provide the functionality you have requested and therefore do not require consent under § 25 (2) Nr. 2 TDDDG. We do not use analytics, advertising or cross‑site tracking cookies of any kind.
We implement appropriate technical and organisational measures within the meaning of Art. 32 GDPR to protect your data, including transport encryption (HTTPS), authenticated sessions, CSRF protection and minimisation of the data we collect. No online service can guarantee absolute security.
Under the GDPR you have the following rights regarding your personal data:
Right to object (Art. 21 GDPR). You have the right to object, on grounds relating to your particular situation, to processing of your personal data that is based on our legitimate interests (Art. 6(1)(f) GDPR), in particular the technical‑log processing described in Sections 2 and 4. If you object, we will stop processing the data in question unless we can demonstrate compelling legitimate grounds that override your interests or the processing is needed to establish, exercise or defend legal claims.
To exercise any of these rights, contact us at oglimmer@gmail.com. You also have the right to lodge a complaint with a supervisory authority. The competent authority for the controller is the Hessischer Beauftragter für Datenschutz und Informationsfreiheit, Wiesbaden, Germany; you may also lodge a complaint with the supervisory authority of your habitual residence or place of work.
The Service is not intended for children under 16. Do not sign in or submit content if you are under 16.
We may update this Privacy Policy to reflect changes in our practices or legal requirements. The "Last updated" date at the top of this page reflects the effective date of the current version.
For privacy questions or requests, contact: oglimmer@gmail.com.