Legal
Privacy notice
What this site records, why, for how long, and what it refuses to. The German version is a translation; this page is the authoritative one.
No cookies, no advertising, no ad or social trackers. Page views of this site are counted with Plausible, without cookies or identifiers. Visiting this site leaves a server log line that is deleted after 14 days. An account is an email address. On customers' sites our script records what AI agents do, without addresses or identifiers, on the customer's behalf. Everything is stored on one server in Germany.
Controller
FINAL MASTER LLC, 7901 4th St N Ste 300, St. Petersburg, FL 33702, USA, hi@finalmaster.net. Questions about this notice go to hi@finalmaster.net.
The controller is a company in the United States. The server that stores all data described here stands in Germany, and the data stays there. The controller reaches it only over an encrypted administrative connection; nothing is copied to the United States apart from what an administrator looks at on screen.
Visiting this site
The web server writes one line per request: the requested path, the time, the status, the size of the answer, the referrer if the browser sends one, the user agent string and the network address. The lines are used to run the service, to find faults and abuse, and to count how often AI agents fetch our own pages; they are deleted after 14 days. The legal basis is our legitimate interest in a working and secure service (Art. 6 (1) (f) GDPR).
Fonts are served from this server. No font, image or style is loaded from anyone else's domain. The site carries its own tracking snippet, which records the same things on this site as it does on customers' sites, described below.
Page views of this site are counted with Plausible Analytics, loaded from analytics.polymarkt.de, an instance we operate ourselves on a server in Germany provided by netcup GmbH, Karlsruhe, Germany; nothing goes to Plausible Insights OÜ, the maker of the software. It sets no cookie, stores no network address and builds no fingerprint: it records the page, the referrer, the browser family and the country, derived from the address and then discarded, and rolls them into daily counts. The legal basis is our legitimate interest in knowing which pages are read (Art. 6 (1) (f) GDPR). It runs only on this site, never on a customer's.
Accounts and sign-in
An account consists of an email address, the plan, the language of the dashboard, the sites added to it and, if you create one, a hashed API token. There is no password: signing in means receiving a link by email, valid for 30 minutes and for one use, whose page sets a session cookie for 30 days. That cookie (at_session) is strictly necessary for the dashboard and needs no consent; it is the only cookie this site ever sets, and only after you sign in. We process this data to perform the contract with you (Art. 6 (1) (b) GDPR). Sign-in links are limited per address and day, and an address that receives too many is counted to enforce that limit.
Mail is sent through Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany), which processes the address and the message to deliver it. We send sign-in links, and, if you leave it on, a weekly digest of your sites' numbers with an unsubscribe link in every mail; the digest can be switched off in the dashboard at any time (Art. 6 (1) (b) and (f) GDPR).
Agent Tracking on customers' sites
Site owners place our script agent.js on their pages. For their visitors we then record, on their behalf: the page path without query string, whether the visit came from or was made by an AI assistant (matched from the referrer and the user agent against a published list), and for WebMCP tools the tool name, duration, success or failure, the error class and the names of the input keys, never their values. Each record carries a session id computed from a random daily salt, the site, a coarse browser class and the network address, hashed; the address itself is not stored, no cookie is set and nothing is written to the device. Raw records are deleted after 90 days; daily totals remain as long as the site is in the account.
Site owners may also upload their own server log. From each line the day, the agent name and the page path are taken; the network address is used while the upload is processed only to group one agent's fetches and to check the agent against its vendor's published address ranges, and is discarded when the request ends.
The site owner is the controller for these records and we process them as processor on their instruction; we do not use them for our own purposes and do not pass them to anyone else. The data processing agreement sets this out formally. Questions about the tracking on a particular site go to that site's owner; we help them answer.
Public stats pages
A site owner can publish a page of daily totals for their site. It shows counts and agent names, never sessions, paths or anything about an individual visitor.
Stats API and MCP endpoint
Requests with an API token are counted per address for rate limiting and answered from the same daily totals the dashboard shows. The token is stored as a hash; we cannot show it again.
Payment
Paid plans, once they open, are billed through Stripe, Inc. (354 Oyster Point Boulevard, South San Francisco, CA 94080, USA). Stripe receives your email address and the plan and handles the card itself; we never see card data. Stripe tells us the subscription state and a customer id, which we store with the account (Art. 6 (1) (b) GDPR). Stripe's own notice governs what it does with the payment data.
Recipients and international transfers
- NexoSystems IT-Solutions, Niederzier, Germany: provides and connects the server. No access to the contents of the data in regular operation.
- Brevo, Berlin: delivers our email.
- netcup GmbH, Karlsruhe, Germany: provides the server that runs our own Plausible instance for this site's page-view counts. No access to the contents in regular operation.
- GitHub, Inc., San Francisco, USA: holds a daily copy of the database, encrypted with AES-256 before it leaves the server. GitHub cannot read it. The transfer rests on the EU-US Data Privacy Framework, of which GitHub is a member.
- Stripe, Inc., USA: payment, only for paid plans, under the EU-US Data Privacy Framework and Stripe's standard contractual clauses.
- The controller itself is in the United States. Administrative access to the server from there is protected by encryption and keys. For customers in the EU and EEA the data processing agreement includes the standard contractual clauses of the European Commission.
Nobody else receives data. Nothing is sold, shared for advertising, or used to train models.
Backups
Once a day a consistent copy of the database is encrypted on the server and stored in a private repository (see above). Backups are kept for 30 days and are used only to restore the service after a fault. A record deleted from the live database can therefore survive in a backup for up to 30 days.
Your rights
Under the GDPR you have the right to access the data we hold about you, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable form (Art. 15 to 21). Where processing rests on legitimate interest, you may object for reasons arising from your particular situation. You also have the right to complain to a supervisory authority, for example the one of your member state of residence. To exercise any of these, write to hi@finalmaster.net; for the account data, removing a site or the account in the dashboard deletes it without asking us.
For visitors of customers' sites: the records contain no identifier through which a particular person could be found, and no network address. A request for access will therefore, honestly, return nothing that is about you; we say so rather than invent a match.
Residents of California and other US states with privacy statutes: we do not sell or share personal information and we do not use it for targeted advertising. The rights above apply to you in the same way.
Children
The service is for businesses and their websites. We do not knowingly create accounts for anyone under 16.
Changes
When the service changes, this notice changes with it, with a new date. Account holders are told by email about changes that affect them. Revised 2026-09-08.