Privacy Policy

1. Privacy at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. Detailed information on the subject of data protection can be found in our privacy policy listed below this text.

Data Collection on This Website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. Their contact details can be found in the "Controller" section of this privacy policy.

How do we collect your data?

Some data is collected when you provide it to us — for example, data you enter into a contact form. Other data is automatically collected by our IT systems when you visit the website. This is mainly technical data (e.g., internet browser, operating system, or the time of the page access). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Some data is collected to ensure error-free provision of the website. Other data may be used to analyze your user behavior.

What rights do you have regarding your data?

You have the right to receive information about the origin, recipient, and purpose of your stored personal data free of charge at any time. You also have the right to request the correction, blocking, or deletion of this data. You can delete your account at any time from your profile page. For this and other questions about data protection, you can contact us at any time via our contact form.

2. General Information and Mandatory Disclosures

Data Protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this is done. Please note that data transmission over the internet may have security vulnerabilities. Complete protection of data from access by third parties is not possible.

Note on the Controller

The controller for data processing on this website is the Reasoned Project Team.

For questions about privacy, your data protection rights, or to exercise your rights, please use our contact form.

The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

3. Data Collection When Visiting the Website

Server Log Files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are: • Browser type and version
• Operating system used
• Referrer URL
• Hostname of the accessing computer
• Time of the server request
• IP address This data is not merged with other data sources. Collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimization of its website, for which server log files must be recorded.

4. What Data We Collect

We collect and store the following personal data to the extent that you voluntarily provide it or it is technically necessary:

On Registration

  • Email address (required)
  • Username (required)
  • Password (stored as bcrypt hash, never in plaintext)

Optional Profile Information

  • Biography
  • Location
  • Profile picture

Automatically Collected Usage Data

  • IP address (for security purposes: rate limiting, abuse prevention)
  • Timestamp of last login
  • Failed login attempts (for account lockouts during attacks)

Platform Activity

  • Debates and arguments created
  • Votes cast
  • Saved debates
  • Reputation points

Security Tokens (temporary)

  • Two-factor authentication codes (as hash, automatically deleted on expiry)
  • Password reset tokens (as hash, automatically deleted on expiry)
  • Email verification tokens (as hash, automatically deleted on expiry)

The legal basis for processing is Art. 6 para. 1 lit. b GDPR (contract performance) and Art. 6 para. 1 lit. f GDPR (legitimate interests: security and abuse prevention).

5. Third-Party Providers and Data Processing

We use the following third-party providers to operate the platform:

ProviderPurposeData Location
MongoDB AtlasDatabase hosting (all user data)EU (Frankfurt, AWS)
VercelWeb hosting and CDNEU / USA (SCCs)
Google OAuthOptional sign-in with Google accountUSA (SCCs)
ResendTransactional emails (verification, 2FA)USA (SCCs)

SCCs = EU Standard Contractual Clauses pursuant to Art. 46 para. 2 lit. c GDPR for data transfers to third countries.

6. Cookies

We use only technically necessary cookies (e.g., for authentication) and — with your consent — optional analytics cookies. You can reset your cookie preferences at any time via settings.

Essential Cookies

Authentication tokens (JWT session cookies) are set when you sign in. These are required for the platform to function and cannot be disabled.

7. Contact Form

When you use our contact form, your details (name, email, subject, message) are used to process your inquiry. The data is not passed on to third parties. The legal basis is Art. 6 para. 1 lit. f GDPR (legitimate interest: responding to inquiries).

8. Your Rights

You have the following rights:

  • Access (Art. 15 GDPR): What data we hold about you.
  • Rectification (Art. 16 GDPR): Correction of inaccurate data (via your profile settings).
  • Erasure (Art. 17 GDPR): Delete your account yourself at any time under Settings → Delete account. Published content will be anonymized.
  • Restriction (Art. 18 GDPR): Restriction of processing in certain cases.
  • Data portability (Art. 20 GDPR): Your data in machine-readable format — contact us.
  • Objection (Art. 21 GDPR): Object to processing based on legitimate interests.
  • Complaint (Art. 77 GDPR): Lodge a complaint with a data protection supervisory authority.

To exercise your rights, please use our contact form.

9. Security of Your Data

Passwords are stored exclusively as bcrypt hashes. Data transmission is encrypted via TLS/HTTPS. Security tokens (2FA, password reset) are hashed and expire automatically. We use rate limiting to detect and prevent attacks on user accounts.

We use necessary cookies for login/security and optional analytics only with your consent. See our Cookie Policy.