Legal

Legal notice & privacy

This page contains the core legal notice and privacy information for GroupMixer as a private, non-commercial website operated by a natural person in Austria.

Legal notice under Austrian media law

GroupMixer is structured as a small, private and non-commercial website. The following information is provided in a permanently easy and direct form.

Owner / content responsibility
Guido Witt-Dörring
Place of residence
Mühlgasse 3, 2322 Zwölfaxing, Austria
Purpose of the website
Private, non-commercial website for browser-based creation and optimisation of groups, teams and session plans.
Editorial direction
Provision of a private, non-commercial web tool together with accompanying information about the use and capabilities of GroupMixer.
Contact
guwidoe [at] gmail.com

Privacy information

1. Controller

The controller for this website is Guido Witt-Dörring, Mühlgasse 3, 2322 Zwölfaxing, Austria. For privacy-related questions or to exercise your rights, you can contact us at guwidoe [at] gmail.com.

2. Hosting and technical server data

This website is provided through Vercel; the separate public solver API is additionally delivered through Cloudflare and hosted on Render. When the website or API is accessed, technically required connection data such as IP address, access time, requested URL, referrer information, browser/device data and similar log data may be processed to deliver the service, ensure security and detect misuse.

Where personal data is processed in this context, the legal basis is our legitimate interest in the secure and stable operation of the website (Art. 6(1)(f) GDPR).

3. Scenario data and feedback form

The browser-based GroupMixer tool does not automatically transmit entered participant names or result data. When a signed-in person expressly enables remote synchronization for a specific scenario, its scenario and result documents are encrypted in transit and stored by Cloudflare so they can be recovered on another device using the same account. The separate public solver API does process scenario JSON that API users intentionally submit; callers should use non-identifying technical IDs where possible. API telemetry does not retain scenario payloads. Product telemetry sends coarse usage events; when solver failures occur it may also send an anonymized scenario structure in which people, groups, attribute names and attribute values are replaced with technical placeholders. The solution-rating form can transmit an expressly selected 1–5-star rating, an optional comment, and coarse scenario or solver size categories. Rating count and average may be displayed publicly in aggregate; comments remain private unless separate explicit publication consent is provided. The full feedback form can also transmit the message you enter, optional contact details and optional browser diagnostics. Non-anonymized browser-tool scenarios are not sent automatically outside expressly enabled remote synchronization.

4. Public community, accounts, and private contact

Community threads and replies publish immediately after submission and can be indexed by search engines. Your displayed name, post text, authored language, status, and timestamps may remain discoverable on the public internet. Your email address, Google identity, sign-in provider, and internal account identifier are not displayed publicly. A GroupMixer account is optional, provides a product-wide sign-in identity, and can be used for community features; the grouping workspace remains available without an account. For password sign-in, Convex stores only the Scrypt-derived password verifier, not the plaintext password.

Guest posts are controlled by a secret editing capability stored only in the originating browser profile. Clearing site data or changing devices loses that capability, and later signing in does not claim guest posts. GroupMixer share links may encode scenario data. Publish them or other material only when you have authority to do so and they contain no confidential or identifying data. Private contact submissions are stored separately and are never converted into public threads. Signed-in people may voluntarily enable per-discussion emails about public replies, status changes, accepted answers, and related GroupMixer updates. This processing relies on consent (Art. 6(1)(a) GDPR); consent can be withdrawn at any time in the discussion or account area or through every message’s unsubscribe link, with effect for the future. Other requested community, account, and contact functions rely on Art. 6(1)(b) GDPR; abuse prevention, moderation, security, and legal defence rely on legitimate interests under Art. 6(1)(f) GDPR.

Community rules and content license

You retain your rights in submitted content and grant GroupMixer a non-exclusive, worldwide, royalty-free license to store, reproduce, display, index, back up, and moderate it for operating the community. Do not submit unlawful, abusive, harassing, deceptive, rights-infringing content or unnecessary sensitive personal data. Content may be reported, hidden, locked, or removed for legal, privacy, safety, or policy reasons. Public removal erases the post text and author snapshot; necessary audit evidence may be retained separately.

5. Web analytics

Regardless of your choice, this website temporarily uses Vercel Web Analytics, Cloudflare Web Analytics, and PostHog Cloud EU cookieless baseline mode for privacy-preserving reach, coarse interaction measurement, and comparison. They may process page views, page leaves, the prior page-view duration bounded in seconds, content-sanitized click signals, timestamps, referrer host, browser, operating system, device type, and country information. Click signals contain no element text, input values, links, labels, or selected/copied text. PostHog receives only a controlled route label, sanitized referrer hostname, release metadata, expressly registered campaign labels, and the bounded analytics decision (accepted or declined) with its consent-notice version; raw query parameters, hashes, dynamic result IDs, and unknown campaign values are discarded. In cookieless baseline mode PostHog transiently processes the IP address, hostname, and raw User-Agent to derive a salted identifier that rotates daily, then removes those inputs before storing the event; it uses no cookies, person profiles, or persistent cross-browser identifier. Cloudflare Web Analytics is a managed cookieless reach provider used particularly for country, technical, and aggregate Core Web Vitals measurements. Vercel creates a server-side request hash that is discarded after 24 hours for aggregate statistics and may derive country, region, and city.

Regardless of your consent choice, Convex processes privacy-safe coarse product and operational telemetry, including generate, solver, example, export, navigation, help, embed, and PWA events plus coarse size, runtime, failure, release, and anonymous-session metadata. Convex also receives best-effort online reliability outcomes for local scenario storage and migration, verified durability, account-session coordination, and expressly enabled remote synchronization. These outcomes use closed status, phase, error-code, and duration categories, contain no scenario, document, workspace, or account identifiers, Automerge heads or hashes, credentials, raw errors, or stacks, and are retained indefinitely for now. This semantic event stream does not contain input values, participant names, group assignments, constraint text, raw scenario/result content, copied text, raw URL parameters, or free text. Separate solver-failure reports may contain a documented anonymized scenario structure in which people, groups, attribute names, and attribute values are replaced with technical placeholders; raw or non-anonymized scenario content is not sent. After you consent, PostHog additionally extends the cookieless baseline with page navigation, clicks, form changes, dead/rage-click signals, and coarse locale, release, and scenario-size categories using a random sessionStorage-based session identifier; session replay remains disabled. PostHog events and daily privacy-canonicalized Vercel and Cloudflare reach aggregates are retained for up to three years in the private Cloudflare R2 archive in Western Europe. You can withdraw or grant consent for richer PostHog product analytics at any time using the setting directly below this paragraph; this does not change consent-independent Convex telemetry. Data-minimised baseline measurement and Convex telemetry rely on legitimate interests (Art. 6(1)(f) GDPR); richer PostHog product analytics relies on your consent (Art. 6(1)(a) GDPR).

6. Browser-local storage and offline functions

GroupMixer stores drafts, scenarios, results, UI state and similar functional data locally in the browser (for example via IndexedDB, localStorage, sessionStorage and the service worker cache) so that the app works as intended. This data generally remains on the user’s device and is not used for server-side collection of tool content.

This browser-local storage supports scenario editing, draft recovery and offline use. Quick Setup and the scenario editor use the same saved scenario, and advanced settings not shown in Quick Setup remain intact. Isolated guide examples become saved scenarios only after an explicit handoff. For ratings, the browser stores a random rating identifier so a later rating from the same browser profile replaces the previous response instead of increasing the public count. Convex stores only a hash of that identifier, which is not used for other analytics.

7. Retention of community and account data

Public posts are retained until deleted by an authorized owner or removed through moderation. Remotely synchronized scenario and result documents remain until confirmed cloud deletion, account removal, or a necessary operational removal. Deleted cloud documents remain in active encrypted backup history for 30 days. Personal OneDrive may then retain the removed encrypted files in its provider recycle bin for ordinarily up to 30 further days; operational outages, account restrictions, or legal retention duties can delay final removal. Account deletion invalidates sessions, removes stored password verifiers, and labels remaining public contributions as “Deleted user.” Notification consent is stored until withdrawal; after withdrawal, pending deliveries are cancelled and necessary consent, withdrawal, and delivery evidence is retained only as long as needed for accountability, reconciliation, abuse prevention, or legal obligations. Private contact submissions, other delivery state, and moderation, security, and removal audit records are likewise kept only as long as needed; their continued necessity is reviewed regularly. Short-lived sign-in, verification, and password-reset codes expire within minutes; providers may keep their own necessary delivery and security logs. Browser-local guest capabilities remain until site data is cleared.

8. Recipients and storage periods

The main external technical recipients are Vercel for website hosting, Convex for community, account, password-verifier, telemetry, and remote-synchronization control data, Google when you expressly choose Google sign-in, Mailjet for email sign-in, account-verification, and password-reset codes and expressly enabled community notifications, Cloudflare for Turnstile, web analytics, the public API, and expressly synchronized scenario/result documents, Microsoft OneDrive for exclusively client-side-encrypted backup copies of those cloud documents, Render for the public API, PostHog for analytics, and potentially GitHub for internal delivery of private contact submissions. Google sign-in shares the provider-confirmed identity and profile data with us. For sign-in, verification, and reset codes, Mailjet receives the destination address and code but never the password; for community notifications, Mailjet receives the destination address, the relevant discussion title, the discussion or related-update title and URL, a public reply/status/accepted-answer or related-update notice, and a non-public delivery/unsubscribe identifier. Where we control retention, the periods above apply; otherwise each provider’s necessary retention and deletion rules apply.

9. Data protection rights

Where personal data is processed in connection with community, accounts, contact submissions, hosting, logs, or reach measurement, statutory data protection rights apply, including access, rectification, erasure, restriction, portability, and objection. Signed-in people can export account data and delete their account in the GroupMixer account area; use the contact above for guest content or further privacy requests. You also have the right to lodge a complaint with the Austrian Data Protection Authority.