set/registry

Privacy Notice

Version 2026.09.18.2-stealth.1 · Effective September 18, 2026

Controller

The controller under the General Data Protection Regulation (“GDPR”) is:

set/registry Media Postfach 12 34 55001 Mainz, Germany Email: [email protected] Direct contact: Email: [email protected]

Data Protection Officer: No data protection officer has been appointed.

Scope

This Privacy Notice explains how we process personal data when you browse the Portal, register, use a passkey, upload files, maintain a profile, download sets, create a basket, save favourites, follow uploaders, subscribe to notifications, submit a report or appeal, communicate with us, or trigger security controls.

Public uploads and public profiles are intentionally available worldwide. Search engines, archives, other users, and third parties may copy public information. Use a pseudonymous username and do not publish information that you do not want to be public.

Categories of data

Depending on use, we process:

Account and authentication data

  • email address and verification status;
  • public username and internal user identifier;
  • password hash, never the plain password;
  • passkey credential identifier, public key, authenticator and security metadata;
  • account status, roles, settings, language, and accepted legal-text versions;
  • recovery, login, session, and security events.

Public profile and community data

  • public username, profile text and image;
  • published sets, version relationships, descriptions, tags, and public upload history;
  • aggregate counted downloads and other public counters;
  • favourites and follows where configured as private; public status only if expressly introduced and disclosed;
  • reports submitted about content and resulting public status labels where applicable.

Upload and report data

  • .set files and parsed parameters;
  • report files, screenshots, ZIP files, filenames, file sizes, hashes, and technical metadata;
  • symbol, timeframe, broker, in-sample and out-of-sample periods or explicit unknown-period designation, descriptions, and associations;
  • extracted report context, orders, deals, trades, metrics, history quality, charts, parser logs, conflicts, and derived scores;
  • malware, secret, and privacy-scan results;
  • publication, quarantine, moderation, and version history.

Reports or screenshots may contain account numbers, names, broker identifiers, computer paths, or other personal data. Uploaders are required to remove unnecessary personal data. We may automatically detect and redact or reject suspected personal or secret data, but detection is not guaranteed.

Download and usage data

  • requested page, set version, download or basket event, time, response status, and generated archive manifest;
  • short-lived download-acceptance token and accepted policy version;
  • rate-limit and abuse-control identifiers;
  • browser, device, operating-system, referrer, and network information contained in standard server or security logs;
  • IP address or a shortened, keyed, or pseudonymised representation where appropriate;
  • cookie, local-storage, and session identifiers used for requested functions.

We do not require an account for downloads and do not intentionally build a cross-site advertising profile from anonymous downloads.

Notification data

  • email address;
  • subscription confirmation, consent text and version, time, source, and withdrawal history;
  • selected symbols, timeframes, brokers, uploaders, evidence criteria, score ranges, and risk flags;
  • delivery, bounce, complaint, open, and click data only to the extent actually used and disclosed. Configure the email provider to minimise tracking; do not use tracking pixels by default.

Communication, moderation, and legal data

  • messages, support requests, notices, reports, good-faith declarations, evidence, appeals, decisions, statements of reasons, authority requests, and related correspondence;
  • reporter and affected-user contact information;
  • legal claims, rights-holder evidence, sanctions and compliance records;
  • audit logs showing who performed an administrative action and when.

We process data for the following purposes:

1. Account creation and service performance — to register users, authenticate, provide profiles, uploads, favourites, follows, notifications settings, baskets, downloads, and support. Legal basis: Article 6(1)(b) GDPR where processing is necessary to perform or take steps concerning the user agreement. 2. Publication at the user’s request — to publish the username, profile, set files, metadata, reports or sanitised report extracts, metrics, scores, flags, and version history. Legal basis: Article 6(1)(b) GDPR and, where applicable, our legitimate interest under Article 6(1)(f) GDPR in operating a transparent community library. 3. Parsing and analytics — to extract parameters and report data, reconstruct metrics, compare reports, create risk flags, and calculate scores. Legal basis: Article 6(1)(b) GDPR for uploader-requested processing and Article 6(1)(f) GDPR for consistent, secure, and transparent presentation. 4. Security and abuse prevention — to prevent unauthorised access, malware, spam, scraping, count manipulation, credential abuse, and denial of service; apply rate limits or CAPTCHA; investigate incidents; and preserve evidence. Legal basis: Article 6(1)(f) GDPR. Our interests are service security, fraud prevention, availability, and protection of users and rights holders. 5. Moderation and legal compliance — to receive and decide notices, restrict unlawful or prohibited content, issue reasons, handle appeals, comply with orders, and defend claims. Legal basis: Article 6(1)(c) GDPR where a legal obligation applies and Article 6(1)(f) GDPR for enforcement of rules, rights protection, and legal defence. 6. Necessary communications — to send verification, security, password/passkey, moderation, legal, and material service messages. Legal basis: Article 6(1)(b), Article 6(1)(c), or Article 6(1)(f) GDPR, depending on the message. 7. Daily email notifications — to send the optional tailored digest. Legal basis: consent under Article 6(1)(a) GDPR and applicable electronic-marketing law. Consent can be withdrawn at any time without affecting prior processing. 8. Service measurement and improvement — to create privacy-minimised aggregate statistics, diagnose parser failures, improve accessibility, and plan capacity. Legal basis: Article 6(1)(f) GDPR. Optional analytics or cross-context tracking is used only with consent where required. 9. Corporate and statutory records — to meet accounting, tax, company, litigation-hold, and documentation obligations. Legal basis: Article 6(1)(c) GDPR and Article 6(1)(f) GDPR for legal defence.

Where we rely on legitimate interests, you may request information about the balancing assessment and may object as described below.

Required and optional data

Data marked as mandatory is required to provide the requested account, upload, report, download, security, or notice function. Without it, that function may not be available. Profile biography, image, out-of-sample period, supporting report, screenshots, favourites, follows, and daily notifications are optional unless the interface states otherwise for a specific action.

Passkeys

When you register a passkey, the Portal receives a credential identifier, public key, sign counter or comparable security information, and technical metadata needed for WebAuthn authentication. Your private key remains in the authenticator. Biometric templates or the device PIN used to unlock the authenticator are not sent to the Portal by the WebAuthn authentication process.

Public disclosure

The following may be disclosed publicly and globally: public username, profile text/image, published set file, description, symbol, timeframe, broker reference, in-sample/out-of-sample periods or explicit unknown-period designation, version history, uploader relationship, public report extracts, reconstructed metrics, scores, flags, counted downloads, and publication/moderation status.

Original report files should be private by default unless a separate public-report option is deliberately activated. Active HTML is never served. The Portal may publish sanitised tables or rendered images. Search engines may index public pages. Once another person has lawfully downloaded or copied public content, we may be unable to retrieve every copy.

Recipients and processors

We disclose data only where necessary to:

  • hosting, object-storage, database, backup, content-delivery, DDoS-protection, CAPTCHA, email, monitoring, and support providers acting under contract;
  • authorised employees, administrators, moderators, and contractors subject to confidentiality and role restrictions;
  • downloaders and the public for intentionally published content;
  • an uploader, reporter, or rights holder where disclosure is necessary for fair notice-and-action handling and lawful;
  • courts, authorities, law enforcement, regulators, legal advisers, insurers, auditors, or transaction counterparties where required or permitted by law.

Service providers:

  • Hosting: set/registry Media, self-hosted application server, European Union
  • Object storage: set/registry Media, self-hosted MinIO object storage, European Union
  • Email: A contracted e-mail delivery provider, European Union
  • Security/CDN/CAPTCHA: Cloudflare, Inc., reverse proxy/CDN and DDoS protection; Europe and United States
  • Monitoring: self-hosted OpenTelemetry
  • Analytics: none

We do not sell personal data.

International transfers

Public content is available worldwide by design. Cloudflare may process limited network metadata in Europe and the United States; its Data Processing Addendum provides the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses where applicable.

Cloudflare and security challenges

> We use Cloudflare, Inc. for reverse-proxy/CDN and DDoS-protection services to deliver content, mitigate denial-of-service attacks, and apply network security rules. Cloudflare may process IP address, request headers, device/browser signals, timestamps, and security identifiers for these purposes. If a security challenge is enabled, Cloudflare may also process challenge results and related signals. We use these functions to protect the Portal and its users. Legal basis under the GDPR is Article 6(1)(f); terminal storage or access is used without consent only to the extent strictly necessary for the expressly requested service or security function. Any optional or non-essential Cloudflare function is activated only with consent where required. Details of processing locations and transfer safeguards: Europe and the United States; EU-U.S. Data Privacy Framework and, where applicable, EU Standard Contractual Clauses under Cloudflare’s Data Processing Addendum.

Retention

We retain data only for as long as needed for the stated purpose, legal duties, security, dispute handling, or defence of claims. Current retention periods are:

| Data | Default retention target | |---|---| | Unverified registration | 7 days | | Login/session tokens | Session duration or configured security lifetime | | Anonymous legal-acceptance/browser token | Up to 24 hours unless a longer duration is necessary to avoid repeatedly presenting the same current acknowledgement | | Active account/profile | Duration of account agreement | | Public upload and set version | While published; then removed from public access without undue delay | | Deleted/unpublished primary object | Operational deletion normally within 30 days, unless legal hold or security preservation applies | | Encrypted backups | Rolling deletion normally within 35 days; not restored to public state solely because the backup exists | | Standard web/security logs | Normally 14 days | | Escalated abuse/security evidence | Normally up to 90 days, longer where an incident, claim, or authority process remains open | | Raw download events | Normally 30 days for deduplication and abuse detection | | Aggregate non-identifying download counts | May be retained indefinitely | | Legal-text acceptance records | Account duration plus normally 3 years, longer if a claim or statutory period requires it | | Moderation notices, decisions, and appeals | Normally 3 years after closure, adjusted to DSA and limitation requirements | | Newsletter consent/withdrawal evidence | Subscription duration plus normally 3 years after withdrawal or last use for defence of claims | | Rejected ordinary uploads | Normally 14 days after final rejection | | Malware or serious-abuse sample/hash | Normally up to 90 days, or longer where required for evidence or prevention; access strictly limited | | Support communication | Normally 3 years after closure, shorter where no longer needed, longer for an open claim |

When a legal retention duty, preservation order, pending dispute, rights claim, or security incident applies, the affected data may be isolated and retained until the reason ends. Data is then deleted or irreversibly anonymised.

Account deletion and unpublishing

Account deletion removes access and starts deletion or anonymisation of account-bound data. Public uploads are unpublished or handled according to the user’s lawful request, the Upload Licence, existing downloader licences, legal obligations, rights disputes, and security needs. Public attribution may be replaced with a neutral deleted-user label where retention of the set page is legally justified.

We cannot delete copies already lawfully downloaded by third parties. Aggregated statistics that no longer identify a person may remain.

Automated processing

The Portal automatically parses reports, classifies set parameters, calculates metrics and scores, detects duplicates or suspicious activity, and may quarantine content. These outputs concern files and Portal integrity. They are not used to make a decision producing legal effects or similarly significant effects about a natural person within the meaning of Article 22 GDPR.

Contested account or content restrictions are eligible for human review as described in the moderation policy. Permanent account termination is not based solely on automated processing.

Your rights

Subject to statutory conditions, you have the right to:

  • obtain access to your personal data and a copy;
  • correct inaccurate data;
  • request deletion;
  • request restriction of processing;
  • receive data you provided in a structured, commonly used, machine-readable format and transmit it where data portability applies;
  • object to processing based on Article 6(1)(e) or (f) GDPR, including profiling based on those grounds;
  • withdraw consent at any time for future processing;
  • lodge a complaint with a data-protection supervisory authority;
  • not be subject to a solely automated decision with legal or similarly significant effect where Article 22 GDPR applies.

For direct marketing, you may object at any time without giving reasons. We will then stop using your data for that purpose.

To exercise rights, contact [email protected]. We may need information to verify identity. Do not send identity documents unless specifically and lawfully requested through a secure channel.

Competent supervisory authority: The State Commissioner for Data Protection and Information Freedom of Rhineland-Palatinate, Postfach 30 40, 55020 Mainz, https://www.datenschutz.rlp.de. You may also contact the supervisory authority of your habitual residence, place of work, or the alleged infringement.

You may withdraw daily-notification consent through the unsubscribe link or account settings. Withdrawal is free and does not affect processing before withdrawal. We retain a minimal suppression record where necessary to respect the withdrawal and evidence compliance.

Objection to legitimate-interest processing

You may object, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will stop unless compelling legitimate grounds override your interests, rights, and freedoms, or processing is needed to establish, exercise, or defend legal claims.

Data sources

We receive data directly from you, your browser/device, uploaded files, generated Portal events, security providers, email-delivery providers, other users submitting notices, and competent authorities or rights holders. Broker records may be submitted by users and later normalised by administrators.

No obligation to provide sensitive data

Do not upload special-category data, government identifiers, financial-account credentials, private keys, or information about another person. The Portal is not designed to process such data. If detected, it may be redacted, quarantined, or deleted.

Changes to this Privacy Notice

We update this notice when processing, vendors, law, or service functions change. Material changes will be communicated appropriately. Where a new purpose requires consent, we will request consent before the processing starts.

Version: 1.0 — 1 September 2026 Effective from: 3 September 2026