Privacy
What SciStack records, and why
Reading SciStack sets no cookies and loads nothing from other companies. The site counts its visitors without tracking them, and it keeps an email address only for a reader who creates an account.
Last changed 2026-10-07.
Who is responsible
The controller under the General Data Protection Regulation (GDPR) is
Matthias Baer
Email: privacy@scistack.dev
Write to this email address for anything on this page, including the rights listed at the end.
Where the data lives
The site, its database, and its logs run on one server rented from DigitalOcean, LLC (101 Avenue of the Americas, New York, USA) in its data center in Frankfurt, Germany. DigitalOcean processes the data on behalf of the operator under a data processing agreement (Art. 28 GDPR). DigitalOcean is a US company; transfers to the USA that may occur in its support and operations are covered by the standard contractual clauses in that agreement.
Fonts, the formula renderer, figures, and notebooks are all served by the site itself. No page loads anything from another company's servers.
When you read the site
Your browser sends every request with your IP address, the page it asks for, the time, and the browser's self-description (user agent). The site uses them in three ways, all on the basis of the operator's legitimate interest in running the site safely and knowing which tutorials are read (Art. 6(1)(f) GDPR).
Server log
The web server (nginx) writes every request to its log: IP address, time, request, status, referring page, and user agent. The log protects the server against attacks and helps fix errors. It is kept for 14 days. Errors and warnings of the site itself go to the server's system journal, also kept for 14 days; a warning may name a network when it is blocked.
Request records
The site records each request that reaches it: IP address and its network, time, method, page, status, user agent, the country looked up from the IP address in the free DB-IP database on the server itself, whether the request came from a bot, and whether it was a failed sign-in. These records serve abuse detection only and are deleted after 7 days.
Usage statistics
For a page view or a notebook download, the site also keeps a statistics row: the page, the time, the country, the host name of an external page that linked to it, and the text of a site search with the number of results. Instead of the IP address the row holds a short hash of IP address and user agent, computed with a random value that changes every day and is deleted when the day is over. A visitor can therefore be counted once per day, and the next day nothing leads back from the row to a person. These rows are kept for 365 days. Bots are not counted. Please do not type personal information into the search box: the search text is kept with the statistics.
Blocking
5 failed sign-ins within 15 minutes close sign-in for the sending network for a while, and a flood of requests closes the whole site to it for an hour or a day. A block records the network (an IPv4 address or an IPv6 /64 range), the reason, and its duration, and is deleted 30 days after it ends.
Cookies
Reading the site sets no cookie. Three cookies exist, all technically necessary for a function you start yourself (§ 25(2) TDDDG), so no consent is asked:
csrftoken, set when a page with a form opens (sign-in, sign-up, password reset), protects the form against forgery from other sites. It holds a random value and lasts a year.sessionid, set when you sign in, keeps you signed in. It is deleted when you sign out and expires after 14 days.messagescarries a short notice such as "Your password is changed" to the next page and is removed when it has been shown.
If you create an account
An account is optional and serves to save tutorials to a list. It holds your email address, a hash of your password (the password itself is never stored), the dates you joined, confirmed the address, and last signed in, and the tutorials you saved. The legal basis is the contract of use you enter by signing up (Art. 6(1)(b) GDPR). Everything is kept until you delete the account on your account page, which removes it and your list at once. An account whose address is not confirmed is deleted after 7 days.
The site sends two kinds of email: the confirmation of a new account and a link to set a new password, each only when you ask for it. No newsletter, no advertising. To stay within its sending limits, the site records each email for 30 days with its time, kind, the sending network, and a keyed hash of the address, from which the address cannot be read back (Art. 6(1)(f) GDPR).
The emails are sent through Brevo, a service of Sendinblue SAS (106 boulevard Haussmann, 75008 Paris, France), which processes the address and the message on behalf of the operator under a data processing agreement (Art. 28 GDPR). Brevo keeps a log of each email's delivery, such as sent, delivered, or bounced, and may note when an email is opened.
Links to GitHub
"Report a problem" and "Source on GitHub" lead to GitHub, a service of GitHub, Inc. (USA). The site sends nothing to GitHub; what GitHub records once you follow such a link is described in GitHub's own privacy statement.
Your rights
You may ask what the site has recorded about you (Art. 15 GDPR) and have it corrected (Art. 16), deleted (Art. 17), or its use restricted (Art. 18), and receive the data of your account in a common format (Art. 20). You may object at any time to the processing based on legitimate interest (Art. 21). Note that most records on this page hold no name and no address, so the operator can only find them if you give the IP address and the time, and the statistics rows cannot be found at all.
You also have the right to complain to a data protection authority (Art. 77 GDPR), for example the one responsible for the operator:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
https://www.lda.bayern.de