Back | Deutsch

Privacy notice for Wilhelm

1. Controller

The controller is Dominik Ewers Solutions, owner Dominik Ewers. The address is in the imprint. Contact for privacy questions: info@de-solutions.net

2. What Wilhelm is

Wilhelm is an AI. Answers are generated by a language model and can be wrong. The model runs on the controller's own servers. Your input does not go to an external AI provider. The exception is web search, described in section 7. The site uses no external services, no third-party fonts and no analytics or advertising. The servers are located in Germany.

3. What data we process

Account. Email address, name, password (only as a hash, never in plain text), language, plan, account status and your choice about learning from chats. Purpose: providing Wilhelm (Art. 6(1)(b) GDPR). Duration: until you delete your account.

Stored chats. Title, messages, times, the model that wrote an answer, and your ratings (thumbs up or down). Purpose: you see your history and can continue it (Art. 6(1)(b)). Duration: until you delete the chat. A deleted chat disappears from your view at once and is permanently removed after 30 days. If you delete your account, all chats are deleted. Exception: section 6. Ratings help us judge the quality of answers. If you agreed to learning from chats, they can be considered when suitable chats are selected. A chat with a thumbs down is not used for learning.

Private chats. A private chat is not stored, not evaluated and not used for learning. It exists only in your browser until you close the page. While Wilhelm answers, the text is briefly processed by the model. Only the usage is counted (next item).

Usage. Number of generated tokens, time and model. Purpose: calculating your quota (Art. 6(1)(b)). Duration: 90 days, then the data is deleted.

Login and security. Login attempts are counted per email address and per IP address to fend off attacks (Art. 6(1)(f)). This also applies to redeeming invitations and resetting passwords. The data is deleted after one day at the latest. Invitations and password reset codes (with the email address) are deleted 30 days after use or expiry. After too many failed attempts the account address receives a warning email.

Server logs. The web server stores a shortened IP address (the last part is removed), time, requested address and status to keep operations secure (Art. 6(1)(f)). The application server briefly stores the full IP address in its operating logs and uses it to count failed sign-ins to prevent abuse. Duration: at most 7 days, the counters for sign-in attempts at most 1 day. A proxy in front of the web server stores the full IP address, time, requested address and status for at most 7 days as well (see section 7).

Cookie and browser storage. We set a single cookie (session, only for login, up to 7 days, only for this site). It is technically necessary (section 25(2) no. 2 TDDDG), so no consent is needed. Your browser also remembers whether the sidebar is open or closed. This contains no personal data.

Memory. Short entries that you create yourself or that Wilhelm saves when you ask for it in a chat (for example "Remember that I am vegetarian"). How many entries are possible depends on your plan, and each entry has at most 200 characters. Purpose: Wilhelm takes your wishes and details into account (Art. 6(1)(b) GDPR). The entries are sent to the model with every request, including in private chats, but nothing new is saved in private chats. The entries are never training data, and chats in which you have something saved are not used for learning. Duration: until you delete the entry or your account. Please do not enter sensitive data. If the model picks up an entry in an answer, that can appear in a chat you released for learning.

4. Learning from chats (optional)

If you choose Yes, we may use your stored chats to improve Wilhelm (consent, Art. 6(1)(a)). You are asked during setup and can change your choice at any time in your account settings. Wilhelm is fully usable with No. Withdrawal applies for the future.

How it works: chats get a random ID, without name and email. Contact details such as phone numbers, email addresses, links and account numbers, as well as your account name, are blurred automatically. What a program does not recognise, for example names of third parties or details in the text, stays visible. This is therefore pseudonymisation, not anonymisation. A person on our team sees these cleaned chats and selects what is suitable for learning. Only selected chats are used. Training runs on our own computers. We do not sell data and do not pass it on to third parties. The cleaned copies stay in the review system only for a limited time: unreviewed ones for 60 days at most, approved but not exported ones for 120 days at most, rejected ones for only 7 days (the rejection can be reversed until then) and reported chats for 30 days. An export file stays available for download for 14 days.

If you delete the chat, close your account or withdraw your consent, the chat is removed from this selection. A model that has already been trained with it cannot unlearn individual items. A withdrawal only works for the future: what was lawfully used before stays lawful. Your chat is removed from data sets that have not yet been used for training. We keep the collected training data set for at most 3 years and delete it afterwards.

Proof of consent. When you close your account, we keep a record of your consents (time, text version, yes or no) for another 3 years, without name and without chats. It can only be matched through a pseudonym derived from your e-mail address that cannot be reversed. The basis is our legitimate interest in being able to prove a consent (Art. 6(1)(f), Art. 7(1)).

If the reviewing person finds signs of a concrete danger to life or safety, the chat can be linked to the account and examined as described in section 5. In all other cases the selection has no consequences for you. This linking is not based on your consent but on the legal reporting duty and our legitimate interest (section 5, Art. 6(1)(c) and (f) GDPR, section 24 BDSG).

5. Protection against misuse and legal reporting duties

We do not read chats routinely. A stored chat is only opened if there is a concrete reason, for example a report, a notice from an authority, an anomaly or a report from the training selection. Every opening is logged with time, person and reason. The log is protected against later changes and checked automatically. We cannot read private chats because they are not stored. The log is kept for 12 months, after that older entries are deleted automatically.

A suspicious flag never leads to a block or other consequences automatically. A person decides. There are no automated decisions in the sense of Art. 22 GDPR.

If we learn of a suspicion of a criminal offence that poses a threat to the life or safety of persons, we must inform the competent authorities (Art. 18 of Regulation (EU) 2022/2065, legal basis Art. 6(1)(c) GDPR). We do not search for such content actively, the duty only arises when we learn of it. The report contains only the information that is available. A disclosure on request of an authority is based on Art. 6(1)(c) and (f) GDPR in connection with section 24 BDSG.

6. Preserving individual chats

A chat can be preserved for a limited time if an authority requests data, if we must report under section 5 or if we must secure our own legal claims (Art. 6(1)(c) and (f), Art. 17(3)(e) GDPR). A preserved chat is kept until the period ends, even if you delete it or close your account. The period is 90 days by default, 365 days at most. After that it is deleted automatically. Every preservation is logged with its reason. We only hand over data if there is a legal basis, and only what is requested. This is logged too. If you request access, we also tell you whether and to which authority data about you was passed on, with the date. This does not apply if an authority has lawfully forbidden us to tell you. We then record that internally with the reason.

7. Recipients and third countries

Your data is processed on our own servers. We send emails (for example the warning email) through our own mail server. Authorities only receive data as described in section 6.

Web search. If a question needs current information, for example news, prices or who currently holds an office, Wilhelm can search the internet. The model turns your question into a short search term and sends it to the controller's own search engine (SearXNG), which runs on our own server in Germany. It forwards the search term to public search engines without an account, without cookies and without any reference to you. The search engines see the IP address of our server and the search term, but not who asked. We do not store the search term, only how often searches happen. Questions about sensitive or private topics and about private individuals are not searched. The results (title, excerpt, address) exist only for that one answer. The chat shows the addresses of the sources under the answer and stores them with the message so you can open them later. Purpose: current and sourced answers (Art. 6(1)(b) GDPR). Please do not write personal data in questions where Wilhelm might search the internet, because parts of your question can end up in the search term.

Protection against attacks (CrowdSec). A proxy in front of the web server analyses requests with CrowdSec. CrowdSec runs on our own server. If an IP address behaves like an attacker, for example through many failed sign-ins, we report it with the time and type of attack to CrowdSec (CrowdSec SAS, France) and receive a list of known attacker addresses in return (Art. 6(1)(f) GDPR, recital 49). Normal visits are not reported. According to its own privacy policy CrowdSec uses cloud providers. Processing outside the EU takes place there on the basis of standard contractual clauses. Otherwise no data is transferred outside the EU, except for web search: the public search engines used there can be based outside the EU and only receive the search term without any reference to you.

Backups. The whole system is backed up and the backups are kept for 2 days. Deleted data can remain there for up to 2 days longer and is only used for restoring.

8. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time (Art. 7(3)). You manage chats, account and learning choice directly in Wilhelm. For everything else write to info@de-solutions.net. We answer within one month. You can also complain to the supervisory authority. In North Rhine-Westphalia this is the State Commissioner for Data Protection and Freedom of Information.

9. Obligation and voluntariness

We need the account details so that Wilhelm works. Learning from chats is optional.

10. Please do not enter sensitive data

Please do not enter passwords, health data or other particularly sensitive details into the chat. We cannot rule out that such details still end up in a chat. You can write anything in the chat. Particularly protected information, for example about health or religion, is stored if you explicitly agree to this during setup (Art. 9(2)(a) GDPR). You can end this agreement at any time by deleting chats or your account. Nothing is stored in a private chat. We do not use chats with such information for learning.

11. Version

Draft of 03.10.2026.