Version 2026-08-02
Privacy information
This notice describes the public information pages and the first-party Lebensatlas access path selected for the pilot. The login origin and the web pilot itself remain sealed and accept no personal Atlas content.
1. Responsibility and contact
- Responsible person
- Christian Seiwald
- Privacy contact
- christian.seiwald.at@gmail.com
2. Public information pages
Delivering a web page technically requires connection data such as IP address, time, requested path, transfer protocol and TLS information to be processed so that the page can be served securely.
The Lebensatlas web server is configured not to retain access logs for these pages. The pages do not set cookies, use browser storage or load third-party analytics, advertising, font or script services. Technical network and security metadata may arise at the hosting, DNS and TLS services involved under their respective policies.
3. First-party Lebensatlas access
The prepared access path is intended for exactly one personally invited, separately activated adult pilot participant. There is no public self-registration. These information pages trigger neither an invitation nor sign-in.
The sign-in service at
https://login.lebensatlas01.grabenplaner.eu uses a
random neutral sign-in name generated by the operator, a short-lived
single-use invitation code and a password set by the invited person.
No email address, display name or other profile information is
required.
The sign-in name is stored by the server only as a peppered HMAC lookup value. The password is not stored in plain text; it is protected with an individual random salt, Argon2id and a separately held server-side pepper. Abuse protection processes tightly time-limited, peppered HMAC values for the identifier and connection address together with counters and blocking times.
After successful sign-in, the product platform maps a random technical subject, the issuer and the authentication time to the internal product account. Invitation and authorization codes are short-lived and single-use. The sign-in service receives no Atlas content, vault keys, device containers, exports or health-related information. No external sign-in provider is active for this pilot path.
Password recovery and vault recovery are strictly separate. The Lebensatlas recovery code only opens the encrypted vault and does not reset a sign-in password. A later password reset must not open a vault and requires its own reviewed and audited process.
4. Sharing and additional purposes
These information pages contain no advertising, telemetry or audience measurement. Sign-in and security data is not used for advertising, research, profiling or AI analysis. Necessary infrastructure operators process only metadata required for connection and operation.
Any later processing of personal or health-related Atlas content requires separate, legally and professionally reviewed information and an activation decision. Invitation, activation and sign-in are not consent to such processing.
5. Storage and deletion
These information pages create no user account and store no form submissions. Transient connection data is processed only for technical delivery. For a later activated access path, invitations, abandoned sign-in transactions, authorization codes and abuse limits are tightly time-limited. The identifier HMAC, password hash, random technical subject and required security timestamps remain only while the product account or a documented security or deletion obligation requires them.
Specific account, content, backup and deletion information will be published and reviewed separately before any real-data release. The pilot remains blocked until credential reset, complete deletion propagation and restoration without reappearance of deleted access credentials have also been accepted.
6. Questions and rights
Questions about this notice and requests for access, correction or deletion can be sent to christian.seiwald.at@gmail.com. You may also complain to a competent data protection authority; in Austria this is the Austrian Data Protection Authority.
Changes to sign-in data, recipients or pilot conditions will be identified in a newly dated version before they are used.