Privacy Policy
Last updated: 13 July 2026
1. General Information
The protection of your personal data is very important to us. This website is operated for informational purposes only and does not use advertising networks, tracking technologies, or profiling tools beyond those explicitly described herein. It complies with applicable data protection laws, including the Swiss Federal Act on Data Protection (nFADP/DSG) effective September 1, 2023, and the EU General Data Protection Regulation (GDPR).
Data controller: Florian Follonier, operator of AI Use Case Hub. Privacy and data-protection requests can be sent to [email protected]. Further legal information is available in the Impressum.
Please note that this website is publicly accessible and its pages may be indexed by search engines (such as Google). As a result, publicly available content may appear in search engine results.
2. Data Collection and Usage
This website automatically collects certain technical information, such as your IP address and browser type, solely for security, error detection, hosting, and operational logging purposes. This data is not used for advertising or behavioral profiling. It may be processed by our hosting, security, and reliability service providers only as needed to operate and protect the website. It is retained only as long as necessary for those purposes.
Publicly available content on this website may be discoverable via search engines, which may collect and display such content in their search results according to their own privacy policies.
- Internal user ID - generated from your Google or Microsoft account identifier
- Name, email address, and profile picture URL - as provided by your authentication provider, if available
- Authentication provider - whether you logged in via Google or Microsoft
- Account creation date, last login time, and active status
- Account activity metadata - successful backend sign-in count and the date counting began, search count and last search metadata, saved/followed item counts, comments and questions by moderation state, and the most recent recorded account activity
- User role - for access control (user, moderator, or admin)
- Credit and access information - monthly credit allocation, credits used, credit reset date, account tier, and API/MCP request counters used to enforce daily and per-minute limits
- Optional API key metadata - if an API key is issued for your account, the key and its last update timestamp are stored
- Session token records - hashed session-token identifiers, provider, user ID, creation/update time, expiry time, and automatic time-to-live data
We use this information to:
- Verify your identity and maintain your login session
- Personalize your experience on the website
- Enable features such as saving cases, following customers or partners, alerts, API access, and submitting content
- Operate account limits, credit usage, and admin/moderator permissions
- Produce administrator-only, first-party activity summaries for service operation, moderation, support, and understanding which account features are used
- Communicate with you about your account if necessary
When a new account is created, a limited notification email may be sent to the maintainer for operational awareness. This notification can include your name, email address, authentication provider, internal user ID, and account creation time.
We do not receive your password from Google or Microsoft. OAuth tokens and our own session tokens are used only to authenticate requests and keep you signed in. Your account data is retained until you request deletion, unless a longer retention period is required for security, legal, or abuse-prevention purposes. Third-party providers may process your data in jurisdictions outside Switzerland; we use appropriate safeguards (e.g., Standard Contractual Clauses) to protect your personal information.
3. User-Generated Content
- Saved cases - use cases you have saved, including the date saved and any alert frequency you choose
- Followed customers and partners - entity names you follow and the date you followed them
- Alert and newsletter preferences - entity alerts, in-app alert state, newsletter filters, frequency, and unsubscribe metadata
- Submitted URLs - any URLs and descriptions you submit for inclusion in our database
- Feedback and ratings - Any feedback or ratings you provide on use cases
- Comments and questions - comment or question text, page context, moderation status, edit/delete history, submission time, internal user ID, account display name, and email address
- Search activity - for logged-in users, search queries, search type, source, filters, result counts, timestamps, and summary counters such as total searches and last search metadata
- Contact messages - if you use the contact form, your email address, optional name, message, and submission time are sent to the maintainer by email
Comments are reviewed before publication. If a comment is approved, its text, your account display name, publication date, and edited status may be displayed publicly on the relevant company or success-story page and may be indexed by search engines. Your email address and internal user ID are not displayed publicly. Administrators can see them for moderation, abuse prevention, and responding to your submission.
We may send operational email and in-app notifications when a comment is submitted, edited, approved, or rejected. You can edit or delete your own comments. Editing a published comment removes it from public display until it is reviewed again. Deleting a comment removes it from public display immediately; a limited moderation record may remain for a reasonable period for audit, security, dispute handling, and abuse prevention, subject to applicable deletion rights.
4. Legal Bases and Moderation
- Contract and requested services (Art. 6(1)(b) GDPR) - account authentication, saved content, user-requested alerts, data export, account deletion, and publishing a comment or question you ask us to review
- Legitimate interests (Art. 6(1)(f) GDPR) - securing and operating the service, preventing abuse, maintaining audit trails, moderating submissions, correcting data, diagnosing errors, and notifying administrators or authors about moderation events
- Consent (Art. 6(1)(a) GDPR) - optional processing where we explicitly request consent, including marketing communications where applicable; consent can be withdrawn at any time without affecting earlier lawful processing
- Legal obligations (Art. 6(1)(c) GDPR) - records or disclosures required by applicable law
5. Cookies and Tracking
- A strictly necessary cookie to store your cookie consent preference.
- Local storage and session storage entries for login state, selected authentication provider, provider profile data, our session token, and token expiry time.
- Microsoft authentication cache data stored in session storage when you sign in with Microsoft.
- Local or session storage entries for user interface preferences, such as theme, navigation visibility, search state, and explorer settings.
- Application Insights telemetry is configured without cookie usage and is limited to sampled page views and critical errors when a production connection string is configured. No cookies are used for advertising or marketing purposes.
Consent and Personal Data Use: We may ask for your consent to use cookies or browser storage for site functionality, preferences, and service development. Your personal data, unique identifiers, or device data may be stored on or accessed from your device where necessary for these purposes.
Vendors and Partners: Information from your device may be processed by third-party service providers described in this policy, including authentication and hosting/telemetry providers. You can object to processing based on legitimate interests by adjusting your settings where available.
Manage or Withdraw Consent: You can manage or withdraw your consent at any time. Click the button below or at the bottom of this page to update your cookie and privacy preferences.
Manage Your Cookie Preferences
6. Data Storage, Recipients, and Retention
- Encryption at rest and in transit
- Access controls and authentication requirements
- Regular security updates and patches
- Secure backup and recovery procedures
We retain account data while the account is active or as needed to provide requested services. Reader submissions and moderation notifications are included in account export and the account-erasure cascade. Session token records are time-limited and expire automatically. A deleted comment is removed from public display immediately; limited moderation, security, email, backup, or abuse-prevention records may remain for the period reasonably required for those purposes or by law. Retention is determined by account status, the purpose of the record, security and dispute needs, backup cycles, and applicable legal obligations. When data is no longer needed, it is deleted or anonymized.
7. Your Rights
- Access - You can request a copy of the personal data we hold about you
- Correction - You can request correction of inaccurate personal data
- Deletion - You can request deletion of your account and associated data
- Portability - You can request your data in a machine-readable format
- Restriction - You can ask us to restrict processing in circumstances provided by law
- Objection - You can object to certain processing of your data
- Withdraw consent - Where processing relies on consent, you may withdraw it at any time
- Complaint - You may lodge a complaint with the competent data-protection supervisory authority
8. Third-Party Services and Authentication
Fonts: Website fonts are bundled with and served by our application. Visiting a page does not require a request to Google Fonts.
Login with Google and Microsoft: Our website offers authentication via Google LLC and Microsoft Corporation using OAuth 2.0. When you log in through these providers, we receive limited profile information such as your provider account ID, name, email address, and profile picture URL where available. We use this information to authenticate you, maintain your account, apply access controls, and personalize your browsing experience. We do not receive your password. These providers may process data in the United States or other jurisdictions. Where required, international transfers are protected through recognized safeguards such as an adequacy decision or Standard Contractual Clauses.
AI search (Microsoft Azure OpenAI): When you run a search, your search query text is sent to Microsoft Azure OpenAI, hosted in the EU (Sweden Central region), to compute a semantic embedding that powers our search ranking. This happens for every search, whether or not you are logged in. Microsoft acts as our data processor and does not use this data to train its models. Because the service is hosted within the EU/EEA, your query text is not transferred outside the EEA for this processing. Legal basis: our legitimate interest in providing and improving the search functionality (Art. 6(1)(f) GDPR).
Payments and email delivery: If you start a paid subscription, payment and subscription data is processed through Stripe. Transactional, alert, moderation, contact, and confirmation emails are delivered through the email service configured by the operator. These providers receive only the data needed for the relevant transaction or message, such as account identifiers, billing status, recipient address, and message content. International transfers, where applicable, are protected through the provider's applicable contractual and data-transfer safeguards.
9. Analytics & User Tracking
This website uses Microsoft Azure Application Insights to monitor reliability and critical errors. Telemetry is configured with sampling, cookie usage disabled, automatic AJAX/fetch tracking disabled, and minimized user/device context. Application Insights may receive sampled page views and exception details, but it is not used for advertising or profiling.
Separately, if you are logged in, we maintain a limited first-party account activity summary as described above. Login counting is forward-only from the date tracking begins for an account; historic login totals cannot be reconstructed. Session refreshes and ordinary authenticated page requests are not counted as sign-ins. Community summaries contain counts and moderation states; the admin user directory does not include comment or question text. We do not maintain a general per-user page-view or clickstream history for this dashboard.
10. External Links
This website may contain links to external websites. We have no influence over the content or privacy practices of these third-party websites and therefore assume no responsibility or liability for them. We recommend reviewing their respective privacy policies.
11. Data Breach Notification
If a personal-data breach is likely to create a risk to individuals, we will notify the competent supervisory authority where required and, where feasible, within the applicable statutory deadline. If the breach is likely to create a high risk, we will also inform affected individuals without undue delay, unless a legal exception applies.
12. Changes to This Policy
We may update this privacy policy from time to time to reflect legal or functional changes. The latest version will always be available on this page. Significant changes will be communicated to registered users via email.
13. Contact
If you have questions regarding this privacy policy or wish to exercise your data protection rights, feel free to contact us using the details provided on the Impressum page or through the contact form on the About page. If you use the contact form, your message is delivered by email to the maintainer so it can be answered.
Last updated: 13 July 2026