Skip to content
Greedy Snacks

Privacy

Last updated: September 2026

1. Controller

needful-apps, owner: Stefan Reinhardt, Am Wahlebach 6, 34253 Lohfelden, Germany
Email: backoffice@needful-apps.de, telephone: 0561 2207 6342

No data protection officer has been appointed, as the statutory requirements for such an
appointment are not met.

2. What this service is

Greedy Snacks is a Git server. It stores source code repositories, their history and
publications (releases) including files. Public repositories can be read without signing in,
all others only by authorised persons.

3. Accessing the pages (server log data)

When the pages are accessed, technical data transmitted by your browser is processed:
IP address, date and time, the address accessed, HTTP status, volume of data transferred,
browser identification (user agent) and – if you are signed in – the user name.

No analysis of usage behaviour, tracking, profiling or advertising takes place.

4. Cookies

Only technically necessary cookies are set. Consent is not required for this under
§ 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act); this is
why there is also no cookie banner.

Cookie Purpose Duration
gs_session sign-in (session identifier) 14 days
gs_csrf protection against cross-site request forgery 14 days
gs_flash one-off status message after an action 60 seconds
gs_lang selected language of the interface 1 year

No third-party cookies are set and no external resources are embedded (no fonts, maps or
scripts from third-party servers).

5. Signing in via Authentik (single sign-on)

Signing in takes place via our own identity provider (Authentik, operated at
auth.needful-apps.de). In this process the following are transmitted and stored: unique
identifier (subject), user name, display name, email address and the group memberships that
determine access rights.

6. Repository content

For each commit, Git stores the name, the email address and the time of the author. This
information comes from the users' local Git configuration and is part of the version history.
In the case of public repositories, it is visible without signing in.

Anyone who does not wish to publish a private email address should configure a neutral address
in Git (git config user.email).

7. Access credentials

Personal access tokens are stored exclusively as a SHA-256 hash value; the plain text is
displayed exactly once and is not logged anywhere. Of the SSH keys deposited, the public key
and its fingerprint are stored.

8. Recipients

The service runs on a server of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen,
located in Germany (processing on behalf of the controller pursuant to Art. 28 GDPR). No
transfer to third countries takes place. Beyond this, data is not passed on to third parties
unless we are legally obliged to do so.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17),
restriction of processing (Art. 18), data portability (Art. 20) as well as a right to
object
to processing based on Art. 6(1)(f) GDPR (Art. 21). To exercise these rights, please
contact backoffice@needful-apps.de.

You also have the right to lodge a complaint with a supervisory authority; the authority
responsible for us is: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian data protection authority),
Postfach 3163, 65021 Wiesbaden, poststelle@datenschutz.hessen.de

10. Obligation to provide data

Providing the data referred to above is technically necessary in order to use the service.
Without signing in, only public content is accessible.