Last updated: 27 August 2026
1. Who is responsible
Controller under Article 4(7) GDPR:
NeoRebels GmbH, Dreiherrnsteinplatz 11, 63263 Neu-Isenburg, Germany Managing Director: Ufuk Ören · Amtsgericht Offenbach am Main, HRB 56637 · VAT ID DE 366959310 support@sqemes.com · +49 155 66067795
No data protection officer is appointed. For any question about your data, write to support@sqemes.com and it reaches the controller directly.
2. What this policy covers, and where to look
One page, two situations. Reading our website and entrusting a product with your team’s knowledge are different things, so they are kept apart here rather than blended into paragraphs that fit neither.
| If you are… | Read |
|---|---|
| just visiting sqemes.com | Part 1 — it is short, because almost nothing happens |
| using Sqemes — the app, the browser extension, the MCP server | Part 2 |
Sections 5 onwards apply to both.
Not covered: self-hosted installations. The Sqemes source is public and anyone may run their own instance. If you use somebody else’s, that operator is the controller, not us. We have no access to it and receive no data from it.
Part 1 — Visiting sqemes.com
3. What happens when you simply visit
Every visit produces a server log entry at our hosting provider: your IP address, the date and time, the page requested, the referring page if there was one, and your browser and operating system as your browser reports them.
Why: to deliver the page, keep the site working, and recognise attacks. A website cannot be operated without this. Legal basis: Article 6(1)(f) GDPR — our legitimate interest in a site that is available and secure. How long: kept briefly for security purposes, then deleted. Not combined with anything else and not used to build a profile of you.
This site loads nothing from third parties. No web analytics — no Google Analytics, no Matomo, no Fathom. No tracking pixel, no advertising network, no embedded widgets. Nobody counts you, and no outside company learns that you were here.
Cookies
Two, both strictly necessary, both set without asking because § 25(2) TDDDG allows exactly that:
| Cookie | What it does | Lifetime | |
|---|---|---|---|
wp-wpml_current_language | remembers which language you chose | 1 day | |
| our consent record | remembers what you decided, so you are not asked again | as shown in the banner |
The second one is worth a sentence: we have to store your decision somewhere, and storing it is the only way to honour it.
Where this site is hosted: Hostinger, on servers in Germany, under a data processing agreement in accordance with Article 28 GDPR.
Links that lead away from here
We link to GitHub, the Chrome Web Store and the Sqemes app. These are ordinary links — nothing is transmitted until you click one. Then you are on somebody else’s site and their policy applies.
Part 2 — Using Sqemes
4. What we process, and why
Your account. Email address, name, password (stored only as a hash), workspace membership and role, last sign-in. To give you an account and control who sees what. Article 6(1)(b) GDPR — performing the contract you entered into by registering.
What you put into your workspace. Templates (prompts, assistants, skills), context files you upload, brand settings, tags, marketplace listings. This is the substance of the service and some of it may be sensitive — it is where a team keeps the knowledge it works with. We store it, show it to the people you granted access to, and deliver it to the surfaces you use. Article 6(1)(b).
Chat. If you use the chat inside Sqemes we store the conversation so you can return to it: your messages, the responses, and which model produced them. Delete a conversation and it is gone from our database. Article 6(1)(b).
Billing. Plan, subscription status, billing period, and the identifiers our payment provider assigns. We never see or store your card details — those go directly to Stripe. Article 6(1)(b) for the subscription, Article 6(1)(c) for the retention obligations under German commercial and tax law.
AI credit usage. If your plan includes Sqemes-funded credits we count how many you used, to enforce the monthly allowance. We count tokens, not content. Article 6(1)(b).
Technical logs and error reports. When something breaks, our error monitoring records the error, a stack trace and technical context about the browser. Configured narrowly and deliberately: error reporting only — no session replay, no performance tracing. Nothing records what you see on screen or what you type. Article 6(1)(f) — our legitimate interest in a product that works and in noticing when it does not.
We do not use your content to train models. Where a request runs on Sqemes-funded credits the text of that request reaches Mistral AI, because producing an answer requires it — and we have opted out of Mistral using it for training. Requests on your own provider key are governed by your contract with that provider.
Both parts
5. What leaves only because you tell it to
This is separate from the section above on purpose, because the difference is real: the following does not happen unless you set it up, and it goes to services you chose and hold the account for.
AI providers on your own key. Connect your own OpenAI, Anthropic, Google, xAI, DeepSeek or OpenRouter key and your requests go to that provider under your contract. What they do with it is governed by their terms, not ours. We pass the request on and store your key encrypted.
Connectors. Connect Google Drive, Docs, Sheets, Calendar or Gmail, Microsoft Outlook or OneDrive, Notion, or GitHub, and Sqemes reads from those accounts on your instruction, at the scope you granted. Disconnect and that access ends.
Importing a skill from a public URL. Fetches the archive from that address, for example GitHub.
The browser extension. Runs on the AI sites you enable it for and inserts your templates there. It also keeps one history across those sites so you can find a conversation again: which platform it was, the conversation’s title, its link, and when you last saw it — not the messages. We never receive the content of your conversations on ChatGPT, Claude or Gemini.
6. How long we keep it
| Website server logs | briefly, for security, then deleted | |
| Account and workspace content | until you delete it | |
| Chat conversations | until you delete them | |
| Billing records | up to ten years — § 147 AO and § 257 HGB. This one is not a choice | |
| Error reports | 30 days | |
| Contact enquiries | while the matter is open and a reasonable period after |
If your subscription ends: you can still sign in and download everything for 30 days; the data is then kept for a further 60 days and deleted 90 days after the subscription ended. Deleting your account deletes the workspace content immediately.
Abandoned workspaces: a workspace created but never used is warned by email after about 23 days and deleted after 30. The warning comes first and is a separate email — nothing is deleted without one.
7. Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection to processing based on legitimate interests (Art. 21). Where processing rests on consent you may withdraw it at any time with effect for the future.
Two of these you can exercise without asking us: export all your data from the app, and delete your account in the settings. Both remain available after a subscription ends.
Where you are a consumer you also have a right of withdrawal from the contract itself — separate from these rights, and set out in our Terms.
We do not use automated decision-making that produces legal effects for you (Art. 22). What the AI generates is a suggestion; nothing here decides anything about a person on its own.
You may complain to a supervisory authority — where you live, where you work, or where you believe the infringement happened. Ours, by our registered seat, is Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden.
8. Security
Transport encryption throughout. Passwords stored only as hashes. Provider keys encrypted at rest. Access to workspace content is enforced in the database by row-level rules tied to workspace membership, not by application code alone — so a defect in the interface does not by itself expose another workspace’s data. A content security policy prevents foreign scripts from running.
9. Who processes data on our behalf
See Subprocessors for the current list, locations and transfer bases. It is updated at least 30 days before a provider changes.
In short: the website is hosted by Hostinger in Germany; database, files and backend are in the EU; payments through Stripe Payments Europe in Ireland; funded AI through Mistral in France; error monitoring in the EU; and transactional email through Resend in the United States, covered by the Standard Contractual Clauses.
10. Changes to this policy
We update it when the site or the product changes and record the date at the top. Material changes to providers or purposes are announced before they take effect. If we ever add something to the website that processes your data in a new way, it goes behind the consent banner first and into this text before it goes live — not afterwards.
11. If you think we got this wrong
Write to support@sqemes.com first — most questions are answered faster that way. You do not have to, and it does not affect your right to complain to a supervisory authority.
12. Subprocessors
We use the following providers to run Sqemes Cloud. They process data on our instructions and are bound by a data processing agreement.
| Provider | What it does | Location | Transfer basis |
|---|---|---|---|
| Supabase | Database, authentication, file storage, backend functions | European Union (Frankfurt) | — |
| Vercel | Delivery of the web application | Global CDN. The application is static — no personal data is stored there. Vercel processes IP addresses in access logs | Standard Contractual Clauses |
| Stripe Payments Europe Ltd., Ireland | Payments and subscriptions | European Union | — |
| Mistral AI, Paris, France | The model behind Sqemes-funded AI credits | European Union | — |
| Sentry | Error monitoring, 30-day retention | European Union | — |
| Plus Five Five, Inc. (“Resend”), San Francisco, USA | Transactional email — invitations, password resets, notices | United States | Standard Contractual Clauses (EU Module Two, and the UK addendum) |
| Hostinger | Hosting of the website at sqemes.com (server logs only) | Germany |
One provider is outside the EU, and we would rather say so than bury it. Transactional email is sent through Resend in the United States. What reaches it is what an email needs — a name, an address and the message itself. Never your templates, your files or your chats.
Stripe acts in two capacities. Processing your payment on our behalf, it is our processor. For fraud prevention, anti-money-laundering checks and its own regulatory duties, Stripe is an independent controller — that processing is not on our instructions, and we can neither direct nor prevent it.
Sqemes-funded AI credits run on Mistral in the EU, and we have opted out of Mistral using that content for model training. Requests made on your own provider key go to that provider under your contract with them, not ours.
Changes. We update this page at least 30 days before adding or replacing a provider, so that customers with a data processing agreement can object in time.
Not on this list: the AI providers you connect with your own key, and any connector you link (Google, Microsoft, Notion, GitHub). Those are not our processors — you grant that access and you can revoke it.
