Lange Labs

Privacy notice

Last updated: August 8, 2026

1. Controller

Robert Lange
Bahnhofstraße 20
12555 Berlin
Email: [email protected]

2. Hosting and server logs

The services run on infrastructure hosted by Hetzner Online GmbH in Germany. When a service is accessed, the participating servers process connection data that is technically necessary. This may include the IP address, date and time, requested address, amount of data transferred, referrer, browser or user agent, and status or error messages.

This processing is used to deliver the services, maintain stability, diagnose errors, and prevent abusive access. The legal basis is Article 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of these private research projects. Container logs are rotated automatically and are limited to three files of no more than 10 MB per service. Their retention period therefore depends on the actual volume of logs.

3. Contacting us

If you contact us by email, the information you provide is processed to handle your request. The legal basis is Article 6(1)(b) GDPR where the communication concerns pre-contractual or contractual matters, and otherwise Article 6(1)(f) GDPR. The information is deleted once the request has been fully handled and no statutory retention obligations prevent deletion.

4. Audience measurement with Umami

After you give consent, the self-hosted Umami software is used to measure audience reach. Data processed may include pages visited, time, referrer, language, screen size, browser and device type, operating system, and a session value derived from the IP address, user agent, and project identifier. Umami does not set its own analytics cookies and runs on the same German Hetzner infrastructure.

The legal basis is your consent under Article 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. Analytics are activated only after consent. Consent is voluntary and can be withdrawn at any time for the future through the privacy settings. Raw analytics data is deleted after 180 days; only aggregated statistics may be retained for longer. Umami features are not used to associate signed-in Mesh users with analytics profiles.

5. Mesh closed beta

To operate the closed beta, Mesh processes in particular names, usernames, password hashes, session and CSRF information, project and workflow configurations, and content entered by invited users. Technically necessary session and CSRF cookies are used for sign-in and to secure write requests. They are required for the service explicitly requested; § 25(2) no. 2 TDDDG applies.

The legal basis is Article 6(1)(b) GDPR for performing the beta usage agreement and Article 6(1)(f) GDPR for security and error analysis. Accounts and associated project data are stored until the account is deleted, the beta ends, or the processing purpose ceases to apply. Users may not enter personal data of third parties unless they have their own legal basis for doing so.

6. AI services

When an invited Mesh user explicitly runs an AI component, the designated inputs may be transmitted through the self-hosted LiteLLM interface to the selected provider, such as OpenAI or OpenRouter. The specific provider is displayed before activation. Transfers to third countries may occur. The selected provider's privacy information and contractual safeguards also apply. Project content is not transmitted to an AI provider without a user running such a component.

7. Backups

Database content is stored in access-restricted local backups. Seven daily, four weekly, and six monthly restore points are retained. Following deletion, data may therefore remain in a backup until the applicable backup cycle expires. Backups are used only to restore data after loss or corruption.

8. Recipients and processors

Hetzner processes hosting data as a processor. Umami, PostgreSQL, Redis, and LiteLLM are self-hosted. Other recipients receive data only where this is necessary for an expressly selected function, required by law, or covered by valid consent.

9. Your rights

Subject to the GDPR, data subjects have rights of access, rectification, erasure, restriction of processing, data portability, and objection. Consent can be withdrawn at any time for the future. Requests can be sent to [email protected].

You also have the right to lodge a complaint with a data protection supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information.

10. Automated decision-making

No solely automated decisions with legal or similarly significant effects within the meaning of Article 22 GDPR take place.