Privacy Policy
What we store, why we store it, and for how long. No sugarcoating: IXIOM measures website usage and binds licences to devices. All of it is documented here.
Last updated: August 2026
1. Data Controller and Contact
The controller for the processing of personal data on the website ixiom.de and in the IXIOM desktop app is Felix Schumann (IXIOM), Germany. You can reach us by email at [email protected]. The full postal address is listed in the Imprint. A data protection officer is not legally required and has not been appointed.
2. Legal Bases at a Glance
We only process data where a legal basis applies. Each section below refers to one of the following:
- Art. 6(1)(b) GDPRPerformance of a contract: account, licence, subscription, delivery of the software, support.
- Art. 6(1)(f) GDPRLegitimate interest: technical operation, security, abuse prevention, audience measurement.
- Art. 6(1)(c) GDPRLegal obligations, in particular commercial and tax law retention of payment records.
- Art. 6(1)(a) GDPRConsent, where we explicitly ask you for it in an individual case. You can withdraw it at any time with effect for the future.
3. Server Logs
When you visit ixiom.de, our web server automatically processes access data transmitted by your browser: the address requested, date and time, amount of data transferred, HTTP status code, referring page, browser type and version, operating system, and your IP address. This data is technically necessary to deliver the site, detect faults, and repel attacks. It is not merged with other data sources and is deleted regularly. Legal basis: Art. 6(1)(f) GDPR. Our server is operated at Hostinger International Ltd., located in Germany.
4. Cookies and Browser Storage
We use no advertising cookies, run no retargeting, and pass nothing on to ad networks. The following is stored:
- Login cookiesWhen you sign in, our authentication layer (Auth.js) sets technically necessary cookies, including a session cookie (authjs.session-token) plus CSRF and callback cookies. They are httpOnly, set over HTTPS, and expire after 30 days. Legal basis: Art. 6(1)(b) GDPR.
- ixiom_site_visitor_id_v1 (localStorage)A randomly generated visitor identifier without any name reference, stored permanently in your browser and used for audience measurement. Details in the next section.
- ixiom_site_session_id_v1 (sessionStorage)A random identifier that groups a single visit and expires when you close the tab.
- ixiom_token (localStorage)Your login token while you are signed in. It is required for the web games and for syncing with your account, and is valid for 30 days.
- Deleting themYou can remove all of the above at any time via your browser's site data or cookie settings. You will then have to sign in again.
5. Audience Measurement on ixiom.de
We measure how the website is used. This runs over two paths, both of which we operate ourselves. We use neither Google Analytics nor any ad network, and no cross-device profiling takes place.
- Our own measurementOn every page view your browser sends to our server: the random visitor identifier, the session identifier, the address requested including query parameters, the page title, the referring page, the site language setting, your time zone, and the width, height and pixel density of your screen. On the server we add: your IP address, the country code reported by Cloudflare, your browser identifier (user agent), and the language list your browser sends. This is stored in our database.
- Analytics scriptIn addition, the website loads the script laisie-analytics.js from dashboard.laisie.de and reports page views there. That server is also operated by us and located in Germany, so the data does not go to an outside provider. For technical reasons, loading the script transmits your IP address and browser identifier to that server.
- Purpose and legal basisWe want to know which content is used, whether pages work, and where visitors come from. The legal basis is our legitimate interest in a needs-based design and improvement of our offering under Art. 6(1)(f) GDPR.
- ObjectionYou can object to the measurement at any time: delete the site data for ixiom.de in your browser, block dashboard.laisie.de with a script or tracking blocker, or write to us at [email protected]. On request we delete the events stored under your visitor identifier.
6. Account and Login Data
We process the following data for an IXIOM account. The legal basis is Art. 6(1)(b) GDPR, because neither licence nor subscription works without an account.
- RegistrationEmail address, a display name of your choosing, and the registration date. Your password is stored exclusively as a hash (bcrypt, cost factor 12). We do not know your password in plain text and cannot recover it.
- VerificationTo confirm your email address we generate a six-digit code. It is also stored only as a hash, is valid for 15 minutes, and is deleted after successful confirmation.
- Account statusVerification status, role (user or administrator), and any block flag together with its reason.
- Licence and subscriptionType and status of your licence, the plan booked, start and end of the billing period, whether a cancellation at period end is scheduled, and the Stripe identifiers (customer, subscription, payment, checkout session).
7. IP Address and Device Identifier
You should read this section particularly carefully, because it goes beyond an ordinary website. IXIOM is paid desktop software. We bind licences to devices and protect the free trial against repeated use.
- What the device identifier isThe desktop app computes a 32-character HMAC hash from the Windows MachineGuid, the hard disk serial number, and the processor identifier. Only this hash value is transmitted to us. It cannot be reversed back into the source values. We do not read any files, documents, program lists, or other content from your computer.
- Licence bound to a maximum of 2 devicesYour licence is bound to at most two device identifiers. During a licence check we store the identifier on your licence together with the time of the last check. Once the limit is reached, the server reports a device block. Write to [email protected] if you have replaced a machine.
- Protecting the free trialWhen a trial starts we store the device identifier, IP address, email address and a timestamp in a separate record. One device gets one trial. In addition we limit new trial accounts per IP address to three within 30 days, so that connections shared by many people (offices, universities, mobile networks) are not blocked outright.
- Login historyOn every registration and sign-in we store on your account: IP address, device identifier, timestamp, country, network provider, and whether the connection was detected as a VPN, proxy, or data centre. The last 50 sign-ins are retained, older entries drop off automatically. We also keep the most recently used IP address and device identifier.
- Blocks in case of abuseWhere abuse has been established, individual IP addresses or device identifiers can be blocked, with the reason recorded.
- Legal basis and objectionArt. 6(1)(b) GDPR, because licence and subscription checks are part of the contract, and Art. 6(1)(f) GDPR based on our legitimate interest in preventing licence abuse and repeated exploitation of the free trial. You may object under Art. 21 GDPR. Without the device check, however, we cannot provide the software.
8. VPN and Location Check via ip-api.com
On every registration and sign-in we send your IP address to the external service ip-api.com in order to detect whether the connection runs through a VPN, a proxy, or a data centre, and to determine country and network provider. Only the IP address is transmitted, no other account data. The service returns proxy, hosting, country and provider information. We store the result in your login history and keep it in memory for five minutes to avoid repeated lookups. The sole purpose is abuse detection; legal basis Art. 6(1)(f) GDPR. This is a free third-party service with which no data processing agreement exists, which is why the transfer is deliberately limited to the IP address.
9. Payment Processing via Stripe
Payments for the IXIOM subscription and for Image Studio credits are handled by Stripe (Stripe Payments Europe Ltd., Ireland, with parent company Stripe, Inc., USA).
- What Stripe holdsCard details, bank details, billing address, cardholder name, payment history and receipts. This data is collected directly by Stripe and stays with Stripe, not with us. We neither see nor store it.
- What we storeYour Stripe customer number, your subscription identifier, the payment status, the plan booked, the end of the current billing period, and whether a cancellation at period end is scheduled. For credit purchases we additionally store a ledger entry with time, amount and transaction reference.
- Legal basisArt. 6(1)(b) GDPR for performing the contract and Art. 6(1)(c) GDPR for the statutory retention of payment records. Stripe's own privacy policy applies in addition.
10. Signing in with Google
As an alternative you can sign in with your Google account (Google Ireland Limited, Ireland). Google then transmits your email address, your name, and a unique Google identifier to us. Of this information we only use the email address, name and identifier; a profile picture is neither evaluated nor displayed by us. As part of the sign-in process, Google learns that you are signing in to IXIOM. Using Google is voluntary, registration with email and password is available as an equivalent alternative. Legal basis: Art. 6(1)(b) GDPR.
11. Email Delivery
For sending email we use an SMTP server at Hostinger International Ltd. Transmitted are the recipient address, display name, and the content of the message. We send only two kinds of email: the verification code on registration, and a confirmation after an Image Studio credit purchase. Invoices and payment receipts are sent by Stripe. We send no newsletters and no promotional email, and our messages contain no tracking pixels. Legal basis: Art. 6(1)(b) GDPR.
12. Cloudflare
ixiom.de runs behind Cloudflare (Cloudflare, Inc., USA) as a content delivery network and protection against denial-of-service attacks. All traffic to our website is routed through Cloudflare, which processes your IP address and connection data for that purpose. From Cloudflare we take the forwarded IP address and the detected country code, which feed into server logs and audience measurement. The purpose is the secure and fast operation of the website, legal basis Art. 6(1)(f) GDPR.
13. Data in the IXIOM Desktop App
By far the largest part of what you do in IXIOM stays on your machine. What is actually transmitted to us is listed here in full.
- What stays localSessions, terminal output, source code, project paths, chat histories, settings and buddy data are kept in your user profile under ~/.ixiom/. Credentials and API keys are stored there encrypted and bound to the device, on Windows via the system interface DPAPI, complemented by AES encryption. We do not transmit this content.
- What is synced to your accountWhile you are signed in, the app can back up certain areas to your account so they are available on your second device. These are exclusively the following eleven areas: tool calls, usage, gamification, activity, productivity, settings, and the save states of Ship It, Deploy Defense, Swarm IO, Code Duel and Galaxy IO. Each area is capped at 200 kilobytes and stored under your user identifier. Source code, files, terminal output and chat histories are explicitly not included.
- Game progressFor the built-in games we store a profile containing the chosen character, zone, equipment, gold and gems, level and experience, per-zone progress, and statistics such as number of runs, hits, best scores and best times. In addition we keep a running ledger of in-game currency granted and spent.
- Licence checkThe app validates your licence on startup. Section 7 describes which data this involves.
- Bug reportsIf you report a problem through the app, we store the report type, subject, description, app version and operating system together with your email address and display name.
14. Public Leaderboards
The leaderboards on ixiom.de are visible to anyone without signing in. That is intentional, but you should know what appears there.
- What is publishedYour display name, level, experience points, and usage statistics such as tokens consumed, costs incurred, number of messages and tool calls. On the buddy leaderboard additionally the species, title, rarity and level of your buddy. For cooperative runs the names of your fellow players are stored and displayed.
- Important note on the display nameIf you have not set a display name, we fall back to the part of your email address before the @ sign. On the games leaderboard other users are additionally shown a shortened form of your email address: the first three characters plus the full domain. Set a display name in your account settings if you do not want this.
- Legal basis and objectionArt. 6(1)(f) GDPR, legitimate interest in playful comparison within the community. On request to [email protected] we remove you from all leaderboards.
15. Image Studio and AI Services
When you use Image Studio, your prompts and any images you upload are transmitted for processing to the provider you selected: OpenAI, xAI (Grok), fal.ai, Google (Gemini) or OpenRouter. These providers are mostly based in the USA and process the content under their own terms. We store neither your prompts nor the generated images in our database. All that remains with us is your credit balance and a ledger entry with the time, the model used, and the number of credits deducted. Please do not upload personal or confidential content there that you would not want to hand to a US provider. Legal basis: Art. 6(1)(b) GDPR, the transfer is strictly necessary to provide the feature.
16. Collab and Multiplayer
For real-time collaboration the app connects to our own signalling server at collab.ixiom.de. Connection data and your user identifier are transmitted so that the participants of a session can find each other. The actual transmission runs directly between participants wherever possible; where restrictive networks prevent that, it is routed through our relay server. For this relay we issue short-lived credentials that are valid for one hour and contain your user identifier. The servers are located in Germany and operated by us. Legal basis: Art. 6(1)(b) GDPR.
17. Recipients and Processors
We do not sell data and pass nothing on for advertising purposes. Beyond the purposes described, data is received only by:
- Hostinger International Ltd.Server hosting in Germany and delivery of our email via SMTP.
- Stripe Payments Europe Ltd.Payment processing, subscription management and invoicing.
- Google Ireland LimitedSign-in with a Google account, only if you choose that option.
- Cloudflare, Inc.Content delivery network and protection against denial-of-service attacks.
- ip-api.comChecking the IP address for VPN, proxy and data centre use, and determining country and network provider.
- OpenAI, xAI, fal.ai, Google, OpenRouterProcessing of prompts and images, exclusively when you actively use Image Studio.
- Public authoritiesWhere we are legally obliged to provide information.
18. Transfers to Third Countries
Some of the recipients listed process data in the USA or can access it from there, in particular Stripe, Google, Cloudflare, OpenAI, xAI, fal.ai and OpenRouter. The basis for this is the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR and, where the providers are certified under it, the EU-US Data Privacy Framework under Art. 45 GDPR. Despite these measures, a level of protection fully equivalent to European standards cannot be guaranteed in every individual case. In particular, access by US authorities cannot be entirely ruled out.
19. Retention Periods
We store personal data only for as long as it is needed for the respective purpose or as long as statutory periods require.
- Account dataUntil your account is deleted.
- Login historyOnly the last 50 sign-ins are retained, older entries are overwritten automatically.
- Verification codes15 minutes, after which they expire. They are deleted immediately after successful confirmation.
- Device login codes5 minutes, after which they are automatically removed from the database.
- Trial identifiersFor as long as required to prevent repeated use of the free trial. Without this storage the protection would be ineffective.
- Licence and subscription dataFor the duration of the contract and afterwards until the statutory limitation periods expire.
- Payment records10 years under commercial and tax law retention obligations (section 147 AO, section 257 HGB).
- Audience measurementUntil the purpose no longer applies or until you object. Automatic deletion after twelve months is planned.
- Server logsShort term, solely for fault and attack detection.
- Leaderboards, save states, synced areasUntil your account is deleted or until you object.
- Block recordsWhere abuse has been established, for as long as needed to enforce the block.
20. Data Security
The website and all interfaces are reachable exclusively over encrypted HTTPS connections. Passwords and verification codes exist only as hashes, device identifiers only as an irreversible HMAC value. Sensitive local data of the desktop app is encrypted and bound to the device. Access to the database is restricted to the operator. Even so, nobody can guarantee complete security for data transmission over the internet.
21. Your Rights
You have the following rights under the GDPR. An informal message to [email protected] is enough, and we respond within one month.
- Access (Art. 15)You can find out which data we hold about you, for what purpose, and to whom we pass it on.
- Rectification (Art. 16)We correct incorrect or incomplete entries; you can change your display name yourself in the account settings.
- Erasure (Art. 17)On request we delete your account, your licence, your synced areas, your save states, your leaderboard entries and your analytics events. Self-service deletion in the dashboard is not currently available. Excluded are data we are legally required to retain, as well as block records where abuse has been established.
- Restriction (Art. 18)You can require that we only store data and no longer process it further.
- Data portability (Art. 20)We provide the data you supplied in a common, machine-readable format.
- Objection (Art. 21)You can object at any time to processing based on legitimate interests, in particular audience measurement and leaderboards.
- Withdrawal (Art. 7(3))You can withdraw any consent given at any time with effect for the future.
22. Right to Lodge a Complaint
Independently of the above, under Art. 77 GDPR you have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence, your place of work, or the place of the alleged infringement. The competent authority for us is the data protection supervisory authority of the federal state in which we are based; the address stated in the Imprint is decisive.
23. Changes to This Privacy Policy
We adapt this policy when IXIOM features, the services we use, or the legal situation change. The version published on this page is always the applicable one. Last updated: August 2026.
Questions about privacy? Write to [email protected].