Privacy
Last updated: September 2026
1. Controller
needful-apps, owner: Stefan Reinhardt, Am Wahlebach 6, 34253 Lohfelden, Germany
Email: backoffice@needful-apps.de, telephone: 0561 2207 6342
No data protection officer has been appointed, as the statutory requirements for such an
appointment are not met.
2. What this service is
Greedy Snacks is a Git server. It stores source code repositories, their history and
publications (releases) including files. Public repositories can be read without signing in,
all others only by authorised persons.
3. Accessing the pages (server log data)
When the pages are accessed, technical data transmitted by your browser is processed:
IP address, date and time, the address accessed, HTTP status, volume of data transferred,
browser identification (user agent) and – if you are signed in – the user name.
- Purpose: provision and stability of the service, detection and investigation of misuse.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
- Storage period: web server log data is deleted after 14 days at the latest.
No analysis of usage behaviour, tracking, profiling or advertising takes place.
4. Cookies
Only technically necessary cookies are set. Consent is not required for this under
§ 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act); this is
why there is also no cookie banner.
| Cookie | Purpose | Duration |
|---|---|---|
gs_session |
sign-in (session identifier) | 14 days |
gs_csrf |
protection against cross-site request forgery | 14 days |
gs_flash |
one-off status message after an action | 60 seconds |
gs_lang |
selected language of the interface | 1 year |
No third-party cookies are set and no external resources are embedded (no fonts, maps or
scripts from third-party servers).
5. Signing in via Authentik (single sign-on)
Signing in takes place via our own identity provider (Authentik, operated at
auth.needful-apps.de). In this process the following are transmitted and stored: unique
identifier (subject), user name, display name, email address and the group memberships that
determine access rights.
- Purpose: signing in, assignment of rights, traceability of changes.
- Legal basis: Art. 6(1)(b) GDPR (usage relationship) or Art. 6(1)(f) GDPR, and in the case
of employees § 26 BDSG (German Federal Data Protection Act). - Storage period: until the account is deleted.
6. Repository content
For each commit, Git stores the name, the email address and the time of the author. This
information comes from the users' local Git configuration and is part of the version history.
In the case of public repositories, it is visible without signing in.
- Legal basis: Art. 6(1)(b) and (f) GDPR.
- Storage period: for as long as the repository exists. Subsequently changing the version
history is technically possible only for the authorised persons themselves
(rewriting the history and pushing it again).
Anyone who does not wish to publish a private email address should configure a neutral address
in Git (git config user.email).
7. Access credentials
Personal access tokens are stored exclusively as a SHA-256 hash value; the plain text is
displayed exactly once and is not logged anywhere. Of the SSH keys deposited, the public key
and its fingerprint are stored.
8. Recipients
The service runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen,
located in Germany (processing on behalf of the controller pursuant to Art. 28 GDPR). No
transfer to third countries takes place. Beyond this, data is not passed on to third parties
unless we are legally obliged to do so.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17),
restriction of processing (Art. 18), data portability (Art. 20) as well as a right to
object to processing based on Art. 6(1)(f) GDPR (Art. 21). To exercise these rights, please
contact backoffice@needful-apps.de.
You also have the right to lodge a complaint with a supervisory authority; the authority
responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian data protection authority),
Postfach 3163, 65021 Wiesbaden, poststelle@datenschutz.hessen.de
10. Obligation to provide data
Providing the data referred to above is technically necessary in order to use the service.
Without signing in, only public content is accessible.