Privacy Policy
Last updated: July 19, 2026
1. Controller
petuja.tools is operated by petuja Systems UG (haftungsbeschränkt). Full provider and contact details are available in the central imprint.
2. Principles
We process personal data only where necessary for secure website operation, communication or a tool function requested by you. Many converters, calculators and generators run entirely in your browser. Server-side functions process only the data required for the respective request.
3. Website access and server logs
When you access the website, technically required data such as IP address, date and time, requested URL, referrer, browser information and HTTP status may be processed. This supports delivery, error analysis, attack prevention and abuse protection. The legal basis is Art. 6(1)(f) GDPR. Server logs are retained only as long as required for operation and security or where legal obligations require longer retention.
4. Local storage
The website uses local browser storage for language, color mode and optional clock-tool settings. These values remain on your device and are not sent to us. Certain forms and security-sensitive functions use technically necessary session cookies for CSRF protection, session management and form limits; they expire when you close the browser. This storage is not used for tracking. We do not load advertising, analytics or social-media tracking services.
5. Visit counts and request limits
For individual tool view counts and abuse protection, we use pseudonymous IP identifiers. For IPv4, only the /24 network prefix is used before HMAC generation; for IPv6, the address is protected with HMAC. View-count identifiers are deleted after 60 minutes, and QuickAI request-limit identifiers after no more than three hours through regular technical cleanup. This processing supports secure, proportionate operation and is based on Art. 6(1)(f) GDPR.
6. DNS and IP tools
For DNS, MX, BIMI, reverse-DNS and similar network tools, the entered domain or IP address is passed to the server DNS resolver. The tools do not open an HTTP connection to the submitted domain; in particular, the BIMI checker does not download referenced logos or certificates. Inputs are not stored as a separate tool history.
7. Contact forms
If you contact us through a form, we process the content you enter, the related page URL, your optional email address and technical security data. The message is transmitted to our mailbox using TLS transport encryption and is not stored in the website database. We use the data only to handle your request and retain it in the mailbox only as long as needed for processing, evidence and legal obligations.
8. Cloudflare Turnstile
Our contact forms use Cloudflare Turnstile to detect automated spam and abuse. Cloudflare may process, in particular, IP address, browser and device information, interaction data, the page URL and a verification token. The legal basis is Art. 6(1)(f) GDPR. More information is available in the Cloudflare Privacy Policy.
9. QuickAI, AI SVG Generator and Google Gemini API
When you actively use QuickAI or the AI SVG Generator, the text or prompt you enter and the requested AI action are sent server-side to the Google Gemini API; the response is returned to your browser. We do not store prompts or responses in the website database. Google’s processing is governed by the Gemini API Additional Terms; do not enter sensitive or confidential data.
10. Recipients and international transfers
Recipients of personal data may include hosting and email providers, Cloudflare and, for functions you actively request, their technical providers. The exact hosting and email providers and applicable safeguards for transfers outside the EU or EEA are determined by the contracts and provider documentation in use. External links are only opened when you select them; their respective providers are responsible for their content and privacy practices.
11. Your rights
Subject to the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. You also have the right to lodge a complaint with a data protection supervisory authority.
12. Updates
We update this privacy policy when functions, providers or legal bases change.
1. Controller
petuja.tools is operated by petuja Systems UG (haftungsbeschränkt). Full provider and contact details are available in the central imprint.
2. Principles
We process personal data only where necessary for secure website operation, communication or a tool function requested by you. Many converters, calculators and generators run entirely in your browser. Server-side functions process only the data required for the respective request.
3. Website access and server logs
When you access the website, technically required data such as IP address, date and time, requested URL, referrer, browser information and HTTP status may be processed. This supports delivery, error analysis, attack prevention and abuse protection. The legal basis is Art. 6(1)(f) GDPR. Server logs are retained only as long as required for operation and security or where legal obligations require longer retention.
4. Local storage
The website uses local browser storage for language, color mode and optional clock-tool settings. These values remain on your device and are not sent to us. Certain forms and security-sensitive functions use technically necessary session cookies for CSRF protection, session management and form limits; they expire when you close the browser. This storage is not used for tracking. We do not load advertising, analytics or social-media tracking services.
5. Visit counts and request limits
For individual tool view counts and abuse protection, we use pseudonymous IP identifiers. For IPv4, only the /24 network prefix is used before HMAC generation; for IPv6, the address is protected with HMAC. View-count identifiers are deleted after 60 minutes, and QuickAI request-limit identifiers after no more than three hours through regular technical cleanup. This processing supports secure, proportionate operation and is based on Art. 6(1)(f) GDPR.
6. DNS and IP tools
For DNS, MX, BIMI, reverse-DNS and similar network tools, the entered domain or IP address is passed to the server DNS resolver. The tools do not open an HTTP connection to the submitted domain; in particular, the BIMI checker does not download referenced logos or certificates. Inputs are not stored as a separate tool history.
7. Contact forms
If you contact us through a form, we process the content you enter, the related page URL, your optional email address and technical security data. The message is transmitted to our mailbox using TLS transport encryption and is not stored in the website database. We use the data only to handle your request and retain it in the mailbox only as long as needed for processing, evidence and legal obligations.
8. Cloudflare Turnstile
Our contact forms use Cloudflare Turnstile to detect automated spam and abuse. Cloudflare may process, in particular, IP address, browser and device information, interaction data, the page URL and a verification token. The legal basis is Art. 6(1)(f) GDPR. More information is available in the Cloudflare Privacy Policy.
9. QuickAI, AI SVG Generator and Google Gemini API
When you actively use QuickAI or the AI SVG Generator, the text or prompt you enter and the requested AI action are sent server-side to the Google Gemini API; the response is returned to your browser. We do not store prompts or responses in the website database. Google’s processing is governed by the Gemini API Additional Terms; do not enter sensitive or confidential data.
10. Recipients and international transfers
Recipients of personal data may include hosting and email providers, Cloudflare and, for functions you actively request, their technical providers. The exact hosting and email providers and applicable safeguards for transfers outside the EU or EEA are determined by the contracts and provider documentation in use. External links are only opened when you select them; their respective providers are responsible for their content and privacy practices.
11. Your rights
Subject to the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. You also have the right to lodge a complaint with a data protection supervisory authority.
12. Updates
We update this privacy policy when functions, providers or legal bases change.