LEGAL
Privacy policy
Information under Art. 13 GDPR · Last updated 16 September 2026
Aken has no accounts, cookies, or analytics. This website stores nothing on your device. The hosted relay stores the content you share only in encrypted form, cannot decrypt it, and deletes it when the session expires. It does keep request logs, including IP addresses, for security and abuse handling.
Who is responsible
Haylee Schäfer, Wiesenstraße 7, 78112 St. Georgen, Germany · mail@inventivetalent.org. Full details are in the imprint.
This website
aken.dev runs on Cloudflare Workers and is delivered through Cloudflare's network (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Serving a page requires processing connection data: your IP address, the time of the request, the page requested, the referring page, and your browser's user agent. Cloudflare processes this data to deliver the site and to protect it from attacks, and may keep it briefly in security logs.
The legal basis is Art. 6 (1) (f) GDPR: the legitimate interest in providing a working and reasonably secure website. Cloudflare acts as a processor under Art. 28 GDPR.
The site sets no cookies and writes nothing to your browser's storage. It has no analytics, advertising, social media embeds, or contact forms. Fonts and scripts are served from aken.dev itself, so opening the site sends no requests to any other domain. Your browser may report failed connections to Cloudflare's network error logging endpoint (a.nel.cloudflare.com).
The installer addresses aken.dev/install.sh, aken.dev/run.sh, and aken.dev/install-mcp.sh redirect to release downloads on GitHub. The request to aken.dev is handled as described above. The download itself is served by GitHub under GitHub's privacy statement.
The Aken tools
The collector (aken) and the local MCP (aken-mcp) run on your own machines. They send no telemetry and do not check for updates. The only service they contact is the relay you configure, which is relay.aken.dev by default. If you point them at a relay you run yourself, nothing described below applies to you.
The collector keeps a local record of what it sent, including the placeholder mapping. That record stays on your server, and you control its retention with --retention. It is never transmitted to the relay or to anyone else.
The hosted relay
The hosted relay at relay.aken.dev passes content between your server and your machine. It runs on a virtual server in Germany rented from netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. Traffic reaches it through Cloudflare, and stored content is kept in Cloudflare R2 object storage.
Content you share
Log excerpts, command results, and your agent's requests are redacted and encrypted on your server or your machine before they are uploaded. The keys are derived from your session token, which never reaches the relay. The relay stores and forwards only ciphertext and cannot read it.
That content can still include personal data, for example about the users of the service whose logs you share, because redaction can miss sensitive values. You decide what is uploaded, and you are responsible for having a legal basis to share it. The relay does not analyse, index, or use the content for any purpose other than delivering it.
Session metadata
To deliver content, the relay stores a random session identifier, a hash of the session credential, the public keys and message authentication codes used by the protocol, creation and expiry times, and the number and size of uploaded chunks. For live sessions, it also holds sequence numbers, message types, sizes, timing, and whether the join came from the command line or from agent chat. Live-session state is kept in memory only.
Request logs and rate limiting
For each request, the relay logs the time, the HTTP method and route, the session identifier, the response status and size, the duration, and the client IP address. It does not log request or response bodies, headers, credentials, or user agents. The IP address is also used to enforce per-address rate limits. That counter is kept in memory and discarded after an hour without requests.
These logs are used to keep the service running, to investigate errors, and to handle abuse. When a report reaches abuse@aken.dev, the relevant session may be deleted, the associated IP address may be blocked, and a record of the report and the action taken is kept.
Legal basis
Delivering the sessions you open is necessary to provide the service you request (Art. 6 (1) (b) GDPR). Request logs, rate limiting, and abuse handling rely on Art. 6 (1) (f) GDPR: the legitimate interest in operating a free public service securely and preventing its misuse. Cloudflare and netcup act as processors under Art. 28 GDPR.
How long data is kept
- Shared content and session metadata: until the session expires or you end it. Snapshots expire after 4 hours by default and live sessions after 8 hours; neither can last longer than 24 hours. Expired sessions are deleted within minutes, and a storage rule removes anything left over after 2 days at the latest.
- Live-session state: in memory until the session ends or the relay restarts.
- Request logs: 30 days, then deleted.
- Abuse reports and blocked IP addresses: as long as needed to handle the report and prevent repeated abuse.
- Emails you send: as long as needed to answer them.
Content that your agent has already fetched stays on your machine, and anything your agent read has been sent to its model provider. Neither can be recalled by the relay.
Transfers outside the EU
Cloudflare is a US company and may process data outside the EU. It is certified under the EU–US Data Privacy Framework and also relies on the European Commission's Standard Contractual Clauses, which are the basis for these transfers under Art. 44 ff. GDPR.
Emails
If you write to one of the addresses on this site, your address and message are used to answer you (Art. 6 (1) (b) or (f) GDPR) and are not shared with anyone else.
Other services
The source code, releases, and documentation are hosted on GitHub, and aken-mcp can be installed from npm. Those services have their own privacy policies. Your coding agent and its model provider are also outside Aken's control: whatever your agent reads through Aken is processed under your agreement with that provider.
Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), and data portability (Art. 20), and the right to object at any time to processing based on legitimate interests (Art. 21). To exercise them, write to mail@inventivetalent.org.
The relay does not link its data to names or accounts. To find records that concern you, it usually needs the session identifier or the IP address and the approximate time. Without them, it may not be able to identify your data (Art. 11 GDPR).
You can also complain to a supervisory authority. The authority responsible for Aken is the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.
No automated decisions
Aken does not use your data for profiling, advertising, or automated decision-making under Art. 22 GDPR, and does not sell it.
Changes
This policy will be updated when Aken's handling of data changes, for example if accounts or paid plans are introduced. The date at the top shows the current version.