Ginius Hub
Imprint & privacy
Imprint
Giner Aaron, reachable at contact@gineraaron.com. This is a privately operated service offered without charge.
1. Controller
The controller for this processing is Giner Aaron, at the address above. The same controller operates Ginius Hub and every app it signs you in to.
2. What Ginius Hub stores
The Hub holds your identity, and nothing else:
- Account: the username you choose and your password. The password is never stored in the clear. It is kept as an scrypt hash with a per-account salt and a server-side pepper, and the stored value cannot be turned back into your password.
- Sessions: which browsers are currently signed in, when each session was opened and last used, and the browser's self-reported user agent.
- Sign-in attempts: the username tried and whether it worked, kept for seven days so that repeated guessing can be slowed down.
- Which apps you have used: the fact that an account has signed in to an app, so that deleting the account knows which apps to clear.
What you actually do inside an app — in Tracktivity, your workspaces, activities and time entries — is stored by that app, in its own database, and is covered by that app's own privacy policy. The Hub never sees it.
Nothing is collected automatically: no location, no device sensors, no contacts, no analytics or tracking services, no advertising networks, no profiling and no automated decision-making.
3. Access logs and IP addresses
Every request is logged on the server, including the IP address of the device making it, the time, the address requested, the method and the response status. They exist for running the service, for finding faults and for fending off abuse. The legal basis is the legitimate interest in a secure and functioning service (Art. 6(1)(f) GDPR). The logs are not joined with your account and expire with the usual system rotation.
4. Cookies
Ginius Hub sets one cookie per app you sign in to, plus one for this account page. Each holds a random value that means nothing on its own and expires after thirty days or when you sign out of that app. A separate short-lived token protects the sign-in form against being submitted from somewhere else. All are sent over HTTPS only and none is readable by scripts.
The cookies are deliberately kept apart rather than combined into one. Signing in to an app signs you in to that app and nothing else, so signing out of it leaves the others alone — and a device left unlocked on one app is not a device left unlocked on all of them. Signing out everywhere is offered on the sign-out page, but it has to be asked for.
Each app additionally sets its own cookie on its own address, described in its own privacy policy.
5. No third-party content
The page loads nothing from outside servers. Even the typefaces are served from this server rather than fetched from Google or anyone else. Opening the page therefore creates no connection to a third party, and your IP address is passed to no one.
6. Purposes and legal bases
Your account is processed for one purpose: to let you sign in to the apps you signed up for, which is performance of that arrangement (Art. 6(1)(b) GDPR). For log data and for the sign-in attempt counter, the legitimate interest set out in section 3 applies.
7. Retention and deletion
Your data is kept for as long as your account exists. You can delete the account yourself at any time from your account page here, which asks for your password again first. Deleting it removes your identity and instructs every app you have used to remove everything it holds for you — in Tracktivity, that is every workspace, activity and time entry. There is no recovery. If an app cannot be reached at that moment, nothing is deleted anywhere and you are asked to try again, so that your data can never be left behind with no account attached to it. Access logs are not covered, as they are not tied to an account.
8. Sharing with third parties
There is none. The data sits on a self-operated server. There are no processors, nothing is sold, and nothing is transferred to a third country. The apps you sign in to are operated by the same controller and are not third parties.
9. Security
The connection is encrypted with HTTPS throughout. Passwords are protected with scrypt, a deliberately slow algorithm built for the purpose, over a value that is additionally combined with a secret held outside the database. An app is never given your password; it receives only a single-use code, redeemed once, over a connection that never leaves the server.
10. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. A message to the contact address above is enough. You also have the right to lodge a complaint with your competent data protection supervisory authority.