Back to home

Legal

Privacy policy

This privacy policy explains what data Machinefixes processes when you use the service, why we process it, how it is stored and retained, and the rights you have under the EU General Data Protection Regulation (GDPR). The current service is purely anonymous — there are no user accounts, no profile data, no payment data, and no community attributions.

Effective August 11, 2026 · Version 2.1

Who is the controller

Machinefixes is the data controller for the personal information described in this policy. The service is operated from the European Union and the underlying database is hosted on EU-resident infrastructure, so the GDPR is our baseline — not a ceiling.

You can reach the data controller for any privacy question, request, or complaint at the address listed in the Contact section at the bottom of this page.

What we collect

The current service collects only what is needed to answer a symptom-search query and to keep the public knowledge graph running. There are no accounts to register, no sign-in, no payment, no per-user community contributions, and no per-user behaviour tracking.

  • Symptom-search queries — the symptom text, optional device pin, and optional observed-conditions you submit; the ranked result set you receive. Stored in an anonymous shape with no identifiers attached.
  • Knowledge-graph rows — Devices, Symptoms, Fixes, Steps, and Source citations, all populated from automated re-ingests of public YouTube walkthroughs, iFixit guides, and manufacturer manuals. None of these rows carry any personal data.
  • Server logs — the bare minimum required to operate the service (request status, response timing, IP address truncated to a /24 prefix for rate-limiting). Logs are rotated on a short rolling window and never joined with a user identity.

What we deliberately do not collect

The service no longer accepts an account, sign-in, payment, or per-user contribution of any kind — those surfaces were retired together with the user-identifying rows that backed them. The following categories are empty by design:

  • Account data — there is no User, Session, Account, or Verification table being populated. Sign-up and sign-in are not exposed anywhere in the current service.
  • Work-order data — work orders, failures, and repairs created by individual technicians. The static seeded corpus on the symptom-search side is the only data the ranker consults.
  • Community signals — votes and notes that would identify a specific contributor. The symptom-search response shape still exposes a community-notes counter for compatibility with earlier clients, but the counter is always zero for the current service.
  • Payment data — there is no checkout flow today. Card details, billing receipts, and Stripe account identifiers are not part of the current data model.

Why we process this, and our legal basis

Each category above has a purpose and a GDPR legal basis. The current service relies on only one of the six grounds the regulation recognises — legitimate interest — because anonymous symptom search is not a contract between us and a registered user.

  • Legitimate interest — operating the symptom search and serving the public knowledge graph. For each processing purpose we measure the interest against the visitor’s rights, and we have set up the service so the balance favours the operation a visitor implicitly opts into by using the page.
  • Contract — does not apply to the current service. There is no contract between the visitor and the controller beyond the act of submitting a query, which carries no obligation.
  • Consent — we do not place any consent-gated feature in front of today’s visitor. If a future consent-gated feature ships it will open with a consent prompt before any data is collected on that basis.

How we store and process it

The knowledge graph and the symptom-search log live in a single Postgres database hosted on EU-resident infrastructure managed by the Polsia platform. Backups are encrypted at rest and held in the same jurisdiction.

Automated cron jobs (the monthly re-ingest) read public YouTube, iFixit, and manufacturer-manual URLs, normalise the prose into Steps, and upsert Fix rows via the knowledge graph. No personal data is fetched, stored, or exposed by these jobs.

The web application itself is served through Cloudflare’s edge; we do not use any third-party analytics, advertising tracker, or session-recording tool. No cookies are set by the application code.

How long we keep it

Retention is per category. The windows are different for different data, and a single number would either over-retain or destroy records we operate on.

  • Knowledge-graph rows — held until the next re-ingest refreshes them. Effectively indefinite as long as the same source URL keeps resolving.
  • Symptom-search logs — 90 days from the query, after which only the aggregate rank-evaluation signal is retained.
  • Server logs — rotated on a short rolling window (typically 7 days) and never joined with a user identity.

Your rights

The GDPR grants a defined set of rights against any controller of personal data. The current service does not hold personal data tied to an identified visitor; if you believe a query you submitted does constitute personal data we should erase, get in touch at the address below and we will action the request within the statutory one-month window.

  • Access — request a copy of any personal data we hold about you, in a portable format.
  • Rectification — ask us to correct anything that is wrong or incomplete.
  • Erasure — ask us to delete your query record, or any personal data we hold.
  • Restriction — ask us to suspend processing while a dispute is resolved.
  • Portability — receive the data you gave us in a machine-readable form so you can move it elsewhere.
  • Objection — object to processing that runs on our legitimate-interest grounds; we will either stop the processing or demonstrate compelling legitimate grounds that override your interests.
  • Withdraw consent — for any future consent-based feature, at any time, without affecting the lawfulness of processing carried out before the withdrawal.

How to exercise your rights

Write to us at the contact address below. Include enough information for us to identify the request (the date and rough time of the query, the device family, and the symptom text are usually enough), and describe the right you would like to exercise. We will acknowledge within five working days and complete the request within the statutory one-month window.

If you are unhappy with our response, you have the right to lodge a complaint with your national data-protection authority. As the controller is established in the European Union, the lead supervisory authority will be the one in the controller’s country of establishment.

Copyright / DMCA Takedown contact

Notices of alleged copyright infringement and takedown/counter-notice correspondence for the service are handled by the designated DMCA agent for Machinefixes, Daniel Saeckl, reachable at saeckl.daniel@web.de. The full procedural notice (six required elements, counter-notice path) and the operator’s repeat-infringer policy are set out in the Terms of Service.

Changes to this policy

We will post material changes on this page and update the effective date and version number at the top. Non-material edits (typos, clarifications that do not change the substance) will not be announced individually. The current version is always the one displayed on this page; please check back before relying on a stale copy.

Contact

For any privacy question, request, or complaint, write to us at machinefixes@polsia.app. We acknowledge within five working days and complete valid requests within the statutory one-month window.

Back to home