Privacy Policy

Called Datenschutzerklärung under German law. The site is run from Germany, so the GDPR applies.

1. Controller

Jonas Franke
Satisfished Poker
Kölnische Straße 128
34119 Kassel
Germany
Email: support@satisfishedpoker.com

2. The short version

This site uses no third-party analytics service, no advertising trackers and no tracking cookies. We do run one small measurement script of our own, described in section 4: it records how long a page was used and which parts of a tool were opened. It stores nothing on your device unless you ask it to stop counting you, and it identifies you only by a pseudonym that our server derives for one day and that cannot be traced back to you or carried into the next day. The calculators run entirely inside your browser. Nothing you type into a calculator ever reaches us. If you make an account, the ranges you keep are also stored on our server, and one further value is stored in your browser: the cookie that keeps you signed in. Both are described in section 6. Beyond that we evaluate the server access log locally and in aggregate, as explained below, and process information you deliberately submit by email or through the feedback form.

3. Hosting and server log files

The site runs on a server that we administer ourselves. The underlying infrastructure is provided by netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany, which acts as a processor for us on the basis of a data processing agreement under Art. 28 GDPR. The server itself stands in netcup's data centre in Nuremberg, Germany, so your data never leaves the European Union.

When you open a page, the web server processes the connection data it needs to answer the request. That can include your IP address, the date and time, the file requested, the amount of data transferred, the referring page, and your browser and operating system.

We use GoAccess on the same server to turn those short-lived logs into a private, aggregate report about visitor numbers, requested pages, referring sites, browsers and technical errors. The report is not public, the host/IP panel is disabled and network addresses are anonymised before the report is created. This does not set or read anything in your browser and sends no data to GoAccess or any other analytics provider.

We process this to deliver the site, keep it stable and secure, investigate abuse, understand which public pages are useful and find technical problems. The legal basis is Art. 6(1)(f) GDPR, and our legitimate interest is running and improving the site reliably. Raw log entries are deleted after 7 days, unless a specific security incident means we have to keep them longer. The private report is rebuilt from the logs available at that time and does not extend their raw-data retention period.

4. Usage measurement

Server logs cannot show how long a page was actually used or which parts of a calculator someone opened, because a page of this site is a single request and everything after it happens in your browser. To learn which of our own tools are worth developing further, a small script of ours measures that and sends one short summary when you leave a page.

That summary contains the file name of the page, the number of seconds the page was actively in use, a coarse screen size category (phone, tablet or desktop), the website that referred you if your browser supplies one, counts from a fixed list of actions inside the page, for example which analysis tab was opened or whether a link to a spot was copied, and how those seconds were divided between the parts of the page, for example which of the calculators on a page you had in front of you and for how long. Only the name of an action or of a part of the page is counted, never its content.

To tell one person from one page opening, our server works out a pseudonym for you: a non-reversible value calculated from your IP address and your browser's user agent together with a random secret. That secret is replaced every night and the previous one is destroyed, so the pseudonym holds for a single day and cannot be recalculated afterwards by anyone, including us. Within one day it lets us see that someone opened three of our calculators rather than three unrelated pages; across two days nothing can be joined, a return visit cannot be recognised, and none of these records can be traced back to you. Neither your IP address nor your user agent is stored; both are used to calculate the pseudonym and are then discarded. The IP address is additionally used to limit the request rate, again only as a keyed, non-reversible value that exists in the service's working memory and disappears when the service restarts.

While a page of ours is open in front of you, the script sends a short sign of life roughly every ninety seconds so that we can see how many people are on the site at this moment. It carries the page name and nothing else, it is never written to the database, and it is forgotten five minutes after the last one arrives.

Apart from one case you ask for yourself, nothing is stored on your device and nothing is read from it: no cookie, no tracking identifier, no fingerprint held in your browser. The exception is the off switch described below, which has to be remembered in your browser in order to work at all. Nothing you type is recorded, in particular no ranges, no boards and no addresses you build yourself; the part of a link after the "#" sign, where a shared position is kept, is never transmitted.

The measurement runs on the same self-administered server described in section 3. It is not passed to anyone else and no analytics provider is involved. The legal basis is Art. 6(1)(f) GDPR, and our legitimate interest is understanding the use of our own tools in order to improve them. Records are deleted after 400 days at the latest. Because the pseudonym cannot be recalculated once the day's secret has been destroyed, we are unable to connect these records to you, which also means the rights in section 10 cannot be exercised against this particular data set: there is nothing in it we could find, correct or delete for you specifically. Under Art. 11 GDPR we are not required to keep additional information for the sole purpose of identifying you.

Section 25 TDDDG does not apply to the measurement itself, because it stores nothing in your terminal equipment and reads nothing already stored there, so no consent is required for it. The one thing that is written to your browser is the off switch, and Section 25(2) TDDDG covers it because it exists solely to carry out something you explicitly asked for.

If you would rather not be counted, open any page of this site with ?insight=aus appended to its address, for example https://satisfishedpoker.com/?insight=aus. A short confirmation appears and that browser is left out from then on; ?insight=an switches it back. This works by storing one value in your browser and nothing else, which is also why clearing your browser data undoes it. Any content blocker that stops the script, or a browser setting that blocks it, prevents the measurement entirely as well; the site keeps working exactly as before either way.

5. Local storage in your browser

The calculators, chart views and other interactive parts of the site can keep your inputs, settings, saved comparisons and any ranges you save in your browser's localStorage or sessionStorage. That happens purely so the features you asked for work and so your work survives a reload on your own device. These values are never sent to us and we cannot see them, with one exception you choose yourself: with an account, your saved ranges are also kept on our server, as described in section 6.

A range or a folder of ranges that you share as a link travels inside the link itself, in the part after the "#" sign. Browsers do not send that part to any server, so opening such a link transmits none of its content to us, and nothing of it is stored anywhere except in the browser of whoever adds it to their ranges.

Because this storage is either technically necessary or something you explicitly asked for, it rests on Section 25(2) TDDDG and needs no consent. You can clear it at any time in your browser settings. We set no analytics, advertising or tracking cookies.

6. Accounts

You can use everything on this site without an account, and nothing on it asks you to make one. An account exists for a single purpose: the ranges you build are otherwise kept in the browser you built them in, and an account lets the same collection follow you to your other devices and survive a browser whose data you clear.

To make one you give us an email address, and that is the only thing we ask for. There is no password: you type your address, we send a one-time link and a six digit code, and either of them signs you in. That is also why there is no password reset, and why we hold nothing that could be stolen and used to sign in as you elsewhere.

What we store for an account: your email address, when the account was created, when it was last used, the ranges you chose to keep, and whether you asked us for news by email, as described below. Sign-in links and codes are stored only as non-reversible hashes, are valid for fifteen minutes, and can be used once. The session that keeps you signed in is a cookie holding a random value; on our side only a hash of it is stored, so a copy of our database would not let anybody sign in as you. That cookie is technically necessary for a function you asked for by signing in, which is why it needs no consent under Section 25(2) TDDDG. It lasts 90 days from your last visit: every visit starts the 90 days again, so you stay signed in on a device as long as you come back to it at least once in that time.

Your ranges are stored as you built them, with their names, folders and colours, and we do not read them, analyse them or pass them on. The email address is used to sign you in and, if we ever had to write to you about your account, to reach you. Anything beyond that we send only if you asked for it, as described below.

The legal basis is Art. 6(1)(b) GDPR, because keeping your collection available is the service you asked us for when you made the account, and Art. 6(1)(f) GDPR for the limited request-rate protection that stops the sign-in mail being used to flood somebody's mailbox. That protection works on a keyed, non-reversible value derived from the requesting IP address, which exists only in the service's working memory.

When you make an account there is a box you can tick, "Inform me when there is something new to discover": new tools, features and offers on this site, now and then by email. The box starts empty, and the account works exactly the same without it. If you tick it, the sign-in mail says so, and your consent takes effect only when you use the code or the link from that mail, which confirms that the address is yours. You can also tick the same box later in your account menu. The legal basis is your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time and without giving a reason, with the same box in your account menu, and every such mail carries a way to stop them; withdrawing does not affect what was lawful before it. To be able to show that you agreed, and that we respected it when you withdrew (Art. 7(1) and Art. 5(2) GDPR), we store the exact words you agreed to, when you gave or withdrew your consent, and whether that happened with the code, the link or in your account menu. These records are kept as long as the account exists and are deleted with it.

You can delete the account yourself, at any time, from the account menu at the top of every page: it removes the address, the sessions and the copy of your ranges on our server, immediately and without asking us. What is stored in your own browser stays yours and is untouched by that. An account you stop using is deleted after two years without a sign-in. Our backups, kept on the server and on one encrypted computer of ours, still hold a deleted account for up to 60 days, after which they are overwritten; they are used for nothing but restoring the service after a failure.

The account runs on the same self-administered server described in section 3. The sign-in mail is delivered by STRATO, the same provider described in section 7.

7. Getting in touch

If you email us or submit the feedback form in the footer, we process your message, the page it refers to, the selected topic, any optional reply address and whatever else you tell us in order to read and, where requested, answer it. When the form is submitted, this information travels over an encrypted connection to our server at netcup and is immediately relayed to our support mailbox through STRATO. The feedback service has no message database and does not write the form contents or reply address to its application log.

For protection against automated abuse, the feedback service temporarily compares a keyed, non-reversible value derived from the requesting IP address. That value exists only in the service's working memory and disappears when its short rate-limit window expires or the service restarts. The regular web-server log described in section 3 still records the request and is deleted after 7 days.

The legal basis is Art. 6(1)(b) GDPR where your message concerns a contract or the run-up to one, and otherwise Art. 6(1)(f) GDPR, our legitimate interest being to receive feedback, reply to genuine enquiries and prevent abuse. We delete the correspondence once the matter is settled and no statutory retention period stands in the way.

Email is provided by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO processes the addressing, transport and storage of messages for us under a data processing agreement pursuant to Art. 28 GDPR.

8. External links

This site links out to other places, for example Discord, booking services or partner offerings. You only leave this site when you click such a link, and from that point the other provider's privacy policy applies. We do not embed external content automatically. Partner or affiliate links are labelled as advertising.

9. Recipients and transfers outside the EU

The recipients used to operate this site are netcup for hosting, as described in section 3, and STRATO for email, as described in sections 6 and 7. Apart from these processors, we do not disclose personal data. The website itself does not initiate transfers outside the European Union or the European Economic Area; any subprocessors used by our providers are governed by their data processing agreements and the safeguards required by the GDPR.

10. Your rights

An informal email to the address above is enough to exercise any of them.

The supervisory authority responsible for us:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
Wilhelmstraße 7
65185 Wiesbaden, Germany
datenschutz.hessen.de

11. Changes to this policy

We update this policy whenever the features, the service providers behind them or the legal basis change. Before any new analytics, advertising, payment, booking or external communication service goes live here, this policy is extended accordingly and we check whether consent is needed first.

Last updated: September 2026