Skip to content

Privacy Policy

Privacy policy and information on data processing

1. Controller

Tobias Kneidl
Johanneck 24
85307 Paunzhausen
Germany

Email: tobias@homelabdiary.dev

This privacy policy applies to homelabdiary.dev (Homelab Diary) and nia-todo.homelabdiary.dev (the official nia-todo product website and documentation), including their respective subpages.

2. Hosting and Server Logs

These websites run on a dedicated server administered by me in a data center operated by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO provides the server and network infrastructure and processes data as a processor in accordance with Art. 28 GDPR.

When the websites are accessed, the upstream web server processes technically necessary access data and stores it in server log files. This includes, in particular, the IP address, date and time, requested URL, HTTP method and status code, referrer URL, and browser and operating system information (user agent).

Processing is necessary to provide the websites and ensure their stability and security and is based on Art. 6(1)(f) GDPR. The legitimate interest is the secure and reliable operation of the websites. Regular access logs are retained for up to four days and then deleted automatically. Data relating to a specific security incident may be retained for longer until the incident has been fully investigated and mitigated.

For more information: STRATO Privacy Policy

Protection Against Abusive Access

CrowdSec is used to detect and prevent attacks automatically. If an access attempt is identified as security-relevant, the IP address, time, and type of detected attack may be transmitted to CrowdSec SAS, 20 rue Maurice Arnoux, 92120 Montrouge, France, and access may be blocked temporarily. Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is protecting the websites and server infrastructure against abuse and attacks.

CrowdSec may engage additional processors to provide its services. According to CrowdSec, any processing outside the European Economic Area is subject to appropriate safeguards, in particular EU Standard Contractual Clauses. For more information: CrowdSec Privacy Policy

3. Web Analytics

Both websites use Umami Analytics, a privacy-friendly open-source analytics tool hosted on the privately operated server infrastructure in Germany. Each website is recorded under a separate website identifier. Umami does not set cookies and does not enable cross-site tracking. No names, email addresses, or other directly identifying information are collected.

The data processed includes, in particular, pages visited, referrer, time of access, browser, operating system, device type, screen resolution, language, approximate country of origin, and technical performance metrics. The IP address and user agent are processed technically to generate a pseudonymous, regularly changing session identifier and determine the country of origin; the full IP address is not stored in the Umami database.

Processing is based on Art. 6(1)(f) GDPR. The legitimate interest is the data-minimizing measurement of reach and technical performance and the improvement of this website. Analytics data is not used for advertising, combined with data from other websites, or shared with third parties. Event and session data is retained for twelve months.

For more information: umami.is

4. Cookies and Local Storage

Homelab Diary sets the technically necessary locale cookie to retain the selected language for 30 days. On both websites, the selected appearance (system setting, light, or dark color scheme) is stored locally in the browser’s Local Storage until it is deleted or changed there. Neither storage mechanism is used for tracking or advertising.

No analytics, advertising, or third-party cookies are set.

5. RSS Feed

Homelab Diary provides an RSS feed. Requests for the feed are subject to the same technically necessary server logging as other page requests (see section 2). No additional analysis takes place.

The websites contain links to external websites, including GitHub (GitHub, Inc., 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA). When you click an external link, you leave the respective website. The operators of linked sites are solely responsible for their content and privacy practices. The respective privacy policies of those services apply.

7. Comments

No comment functionality is currently active on either website. No user-related data is processed in connection with comments.

8. Self-hosted nia-todo Instances

This privacy policy applies only to the official nia-todo product website and documentation at nia-todo.homelabdiary.dev. It does not apply to nia-todo instances operated by third parties or self-hosted by users. The respective operator of such an instance is solely responsible for processing account, todo, attachment, location, voice, or other data within that instance. The official product website does not receive such application data from self-hosted instances.

9. Your Rights

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR), where applicable
  • Objection (Art. 21 GDPR)
  • Complaint to a supervisory authority (Art. 77 GDPR)

Competent supervisory authority: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach, Germany.

For inquiries: tobias@homelabdiary.dev

Last updated: August 24, 2026