Privacy Policy
This Privacy Policy explains what personal data CrucibleMark collects, why, where, and for how long, and how you can exercise your rights. It is written for an international audience and is intended to satisfy, in particular, the EU General Data Protection Regulation (GDPR), the UK GDPR, the Swiss FADP, the California Online Privacy Protection Act (CalOPPA), the California Consumer Privacy Act (CCPA), the federal Children's Online Privacy Protection Act (COPPA), and Canada's PIPEDA.
In brief
CrucibleMark is a non-commercial editorial website that ranks and reviews publicly described language models. It runs without user accounts, comments, payments, advertisements, or social-media embeds.
- No cookies are set on your device for analytics, advertising, or preferences. We do not store any client-side state.
- No third-party trackers, advertising networks, or external CDNs are loaded when you visit a page.
- What we do receive when you open a page: your IP address, the page you requested, your browser type, your operating system, the referring page (if any), and the time of the request. This is recorded by our hosting provider as standard server logs, and partly as aggregated, cookie-free statistics by a self-hosted Matomo instance.
- What we do not do: we do not sell, rent, lease, or trade personal data; we do not share it with advertising networks; we do not profile individuals; and we do not make any automated decisions that affect you.
The full notice follows below.
1. Controller and contact
The data controller for this website is:
Kay BeißertMedia-Garage
Großbeerenstraße 71
14482 Potsdam
Germany
E-mail: kontakt@media-garage.de
The controller is the natural person who determines the purposes and means of processing personal data on this website.
A data protection officer (DPO) has not been appointed. Under Article 37 of the GDPR, a DPO is mandatory only for public authorities, organisations whose core activities consist of large-scale monitoring of individuals, or organisations that process special categories of data on a large scale. None of these apply to CrucibleMark.
An EU representative under Article 27 GDPR is not required, because the controller is established in the European Union.
A UK representative under Article 27 UK GDPR is not required for the same reason.
2. Scope of this notice
This notice applies to the website at https://www.cruciblemark.com/ and its subdomains (for example, the analytics subdomain described in Section 7).
It does not apply to external websites we link to from articles, models, reports, or magazine pieces. Each linked site has its own privacy practices.
It does not apply to language-model providers, cloud platforms, or other third parties whose models are merely described on this site. We are not the controller for any data those third parties process on their own infrastructure.
3. The information we collect, and why
| What we collect | When | Why we collect it | Legal basis (EU/UK GDPR) |
|---|---|---|---|
| Server log data: IP address, date and time, requested URL, HTTP status, byte count, referrer URL, browser type and version, operating system, hostname | Every page request, automatically | To deliver the website, keep it stable, and detect or prevent abuse and attacks | Article 6(1)(f) GDPR — legitimate interest in operating a secure website |
| Aggregated, cookie-free usage statistics (page viewed, anonymised IP, screen-resolution class, document referrer) | Every page request, automatically, by self-hosted Matomo | To understand which content is read and how the site is used, so we can improve it | Article 6(1)(f) GDPR — legitimate interest in editorial improvement |
| Your name, e-mail address, message contents, and any other details you volunteer | When you write to us | To respond to your enquiry | Article 6(1)(b) GDPR if your request relates to a contract; otherwise Article 6(1)(f) GDPR |
| Comments, corrections, or tips you choose to send by e-mail | When you send them | To consider publication or correction of our editorial content | Article 6(1)(f) GDPR |
We do not collect:
- Names, addresses, phone numbers, or e-mail addresses unless you provide them yourself.
- Cookies, including analytics, advertising, authentication, or preference cookies.
- Persistent identifiers that can be used to recognise you across websites (no fingerprinting, no advertising IDs).
- Geolocation data precise enough to identify your street.
- Financial, health, biometric, or other "sensitive" categories of data.
- Special categories of data within the meaning of Article 9 GDPR (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data, data concerning health, data concerning a natural person's sex life or sexual orientation).
- Personal data relating to criminal convictions or offences (Article 10 GDPR).
4. Automated decision-making and profiling (Article 22 GDPR)
CrucibleMark does not make any decision based solely on automated processing, including profiling, that produces legal effects concerning you or that otherwise significantly affects you.
In particular:
- We do not use your personal data to evaluate, score, or categorise you.
- We do not infer interests, preferences, or behaviour patterns at the individual level.
- The aggregated statistics from Matomo cannot be traced back to you.
5. Hosting, processors, and international transfers
Hosting provider
The website is hosted by:
All-Inkl.com — Neue Medien Münnich Hauptstraße 68 02742 Friedersdorf Germany
All-Inkl.com stores server log files and serves the website from servers located in Germany. We have concluded a data processing agreement with All-Inkl.com under Article 28 GDPR. The server log files are retained by All-Inkl.com only for as long as necessary for the technical operation and security of the website.
Analytics provider (Matomo, self-hosted)
We use Matomo, an open-source web analytics platform, self-hosted on
the operator's own infrastructure at analytics.media-garage.de (a
subdomain operated by the same controller, also located in Germany). The
subdomain processes only truncated, anonymised IP addresses and uses no
cookies at all.
Other recipients
We do not transfer your personal data to advertising networks, social-media platforms, data brokers, marketing services, payment processors, or analytics vendors. We do not sell, rent, lease, or otherwise trade personal data.
International transfers
No transfer of personal data to a third country (a country outside the European Economic Area, the United Kingdom, or a country covered by an adequacy decision) takes place in the ordinary operation of this website:
- The hosting server is in Germany (EEA).
- The Matomo instance is on the controller's own infrastructure in Germany (EEA).
- All assets — fonts, stylesheets, JavaScript, charts, mathematics — are served from the controller's own web server in Germany.
- No third-party scripts, beacons, fonts, or analytics services are loaded at page render.
For the limited case in which you actively follow an external link (for example, to a research paper, a vendor's page, or a model's repository), your browser may transmit data (in particular your IP address and referrer) to the destination server. Whether that destination is in a third country depends on the operator of the linked site. The legal basis for such a transfer on your click is Article 6(1)(a) GDPR — your consent by clicking the link. Once you are on the linked site, the privacy policy of that site applies.
For completeness: the EU–U.S. Data Privacy Framework (an adequacy decision of the European Commission, in force since 10 July 2023) provides a lawful basis for transfers from the EU to certified U.S. recipients. The framework is not relied on here, because we do not transfer data to U.S. recipients in the normal operation of this website.
6. Cookies and client-side storage
This website does not use cookies. It also does not use
localStorage, sessionStorage, IndexedDB, WebSQL, or any comparable
client-side storage technology. It does not use a service worker.
Because no cookies or comparable technologies are used, no consent banner is required under the German Telecommunications-Telemedia Data Protection Act (which implements Article 5(3) of the EU ePrivacy Directive 2002/58/EC).
7. Matomo: privacy-friendly analytics
We use Matomo to count how many visitors read which articles, so we can prioritise future editorial work. Matomo is operated on the controller's own infrastructure in Germany. Specifically:
- No cookies. Matomo is configured with
disableCookies(). No tracking cookie is set on your device. - IP addresses are anonymised. The last two octets of IPv4 addresses (and an equivalent portion of IPv6 addresses) are truncated before storage. The stored data cannot be used to identify you.
- No profiling. No user profile is created, no events are correlated across visits, and no identifiers are tied to other data sources.
- No fingerprints. No canvas fingerprint, no font fingerprint, no audio-context fingerprint, no hardware fingerprint, and no IP-based pseudo-ID is used.
- Retention is short. Raw page-view records are aggregated and discarded after 30 days; aggregated reports are kept for up to 24 months.
You can object to Matomo's collection of your visit at any time by contacting kontakt@media-garage.de. We will record your objection against the hash of your anonymised IP address so that future visits from the same network are not counted.
Response to "Do Not Track" and Global Privacy Control signals
We honour the Do Not Track (DNT) header and the Global Privacy Control (GPC) signal. When either signal is sent by your browser, Matomo does not record the visit.
8. Newsletters and marketing
We do not operate a newsletter, mailing list, or push-notification service. We do not send you any e-mail unless you have first written to us. We do not run remarketing campaigns. We do not embed third-party marketing pixels.
9. Contact enquiries
When you write to kontakt@media-garage.de, we receive the personal data you include in your message: typically your name (if you sign your e-mail), your e-mail address, the time and date of your message, and the contents of your message and any attachments.
We use this data only to read and respond to your enquiry, and we delete it when the enquiry is closed. We do not add you to any mailing list. We do not enrich the data with information from third-party sources.
If your enquiry relates to the conclusion or performance of a contract (for example, a request for a quotation or a service), the legal basis is Article 6(1)(b) GDPR. Otherwise, the legal basis is Article 6(1)(f) GDPR (legitimate interest in handling correspondence).
10. Children
CrucibleMark is an editorial service intended for a professional and technical audience. It is not directed at children under the age of 16 (the default age of consent under Article 8 GDPR), and it does not knowingly collect personal data from anyone under 16.
We also do not direct the service at children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA), and we do not knowingly collect personal information online from children under 13. Because the service does not target children and does not collect personal information from visitors in the ordinary course, the COPPA Rule's verifiable-parental-consent requirements do not apply.
If you believe that a child under 13 has provided personal information to us, please write to kontakt@media-garage.de so that we can delete the information.
11. How long we keep your data
| Data | Retention period |
|---|---|
| Server log files (hosting provider) | Generally 7 to 30 days, then deleted or anonymised; longer only if required for incident analysis or to comply with a statutory retention obligation |
| Matomo aggregated statistics (controller's own infrastructure) | Raw hits discarded after 30 days; aggregated reports up to 24 months |
| E-mail correspondence | Deleted once the matter is closed and any statutory retention period has expired; commercial correspondence is retained for 6 or 10 years as required by the German Commercial Code and the German Fiscal Code |
12. Your rights
If you are in the European Economic Area, the United Kingdom, or Switzerland
You have the following rights with respect to your personal data:
- Right of access (Article 15 GDPR) — to obtain confirmation of whether we process your data and to receive a copy.
- Right to rectification (Article 16 GDPR) — to correct inaccurate or incomplete data.
- Right to erasure (Article 17 GDPR) — also called the "right to be forgotten", with the exceptions in Article 17(3).
- Right to restriction of processing (Article 18 GDPR) — to limit how we use your data while a dispute is resolved.
- Right to data portability (Article 20 GDPR) — for data you have provided to us in a structured, commonly used electronic format.
- Right to object (Article 21 GDPR) — to object to processing based on Article 6(1)(e) or (f), including profiling.
- Right to withdraw consent (Article 7(3) GDPR) — where the legal basis is consent, you can withdraw it at any time, without affecting prior lawful processing.
- Right to lodge a complaint (Article 77 GDPR) — with a supervisory authority.
- Right to an effective judicial remedy (Articles 78 and 79 GDPR).
- Right not to be subject to automated decision-making (Article 22 GDPR) — see Section 4.
You can exercise these rights by writing to kontakt@media-garage.de. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. We will not charge you for responding, unless your request is manifestly unfounded or excessive (Article 12(5) GDPR). We may need to verify your identity to prevent unauthorised disclosure.
You may lodge a complaint with:
- The supervisory authority of your habitual residence, place of work, or place of the alleged infringement (Article 77(1) GDPR). For most users in Germany, this is the Landesbeauftragte für den Datenschutz und für das Recht auf Akteneinsicht Brandenburg (the State Commissioner for Data Protection and the Right to Inspect Files for Brandenburg), Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany. A list of all EEA supervisory authorities is available on the European Data Protection Board's website.
- If you are in the United Kingdom, the Information Commissioner's Office (ICO).
- If you are in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
If you are in California (United States)
The California Online Privacy Protection Act (CalOPPA, California Business and Professions Code, Sections 22575–22579) applies to commercial websites and online services that collect personally identifiable information from California residents. This notice is intended to satisfy CalOPPA's disclosure requirements. The categories of personally identifiable information collected are listed in Section 3. We do not allow third parties to collect personally identifiable information about your online activities over time and across different websites when you use this site. The effective date of this notice is shown in Section 15.
California residents may also have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA). However, the CCPA applies only to for-profit businesses that (i) have gross annual revenue above USD 25 million, (ii) buy, sell, or share the personal information of 100,000 or more California residents or households, or (iii) derive 50 % or more of their annual revenue from selling California residents' personal information. CrucibleMark is a non-commercial personal project and is below each of these thresholds, so the CCPA does not apply. Out of courtesy, however, California residents may write to kontakt@media-garage.de to request access to or deletion of any personal information we may hold about them; we will respond on a best-effort basis as if the CCPA applied.
CrucibleMark honours the Global Privacy Control (GPC) signal that California residents can enable in supported browsers. When GPC is active, we treat the request as a valid opt-out from the "sale or sharing" of personal information (which we do not perform in any case).
If you are in the United States outside California
CrucibleMark does not knowingly collect personal information from U.S. residents for commercial purposes. If you write to us, we will treat your personal data with the same care as for EU/UK residents.
If you are in Canada
CrucibleMark is operated from Germany. The Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) applies to the collection, use, and disclosure of personal information in the course of commercial activities in Canada. CrucibleMark does not direct commercial activities at Canada; however, PIPEDA's fair-information principles (accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance) reflect good privacy practice. If you write to us from Canada, we will apply these principles to your data. You may also contact the Office of the Privacy Commissioner of Canada.
If you are elsewhere
If you are outside the EEA, the United Kingdom, Switzerland, the United States, and Canada, the privacy and data-protection laws of your country may still grant you rights. Where this notice grants stronger rights than your local law, we will honour the stronger rights. You may write to kontakt@media-garage.de at any time.
13. Security
We take appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage. In particular:
- Transport encryption. All pages are served over HTTPS using TLS 1.2 or TLS 1.3.
- No third-party scripts. Because we do not load any third-party scripts, fonts, or trackers, we eliminate a common source of supply-chain compromise.
- Limited recipients. Personal data is processed only by the controller and by processors bound by an Article 28 GDPR agreement.
- No public user data. There are no user accounts, no comments, no posts, and no uploaded content that could leak personal data through this site.
No method of transmission over the Internet, however, is 100 % secure. If you have reason to believe that your interaction with us is no longer secure, please notify us at kontakt@media-garage.de.
14. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices, technologies, or the law. The "effective date" at the top of this notice will change when we do so. Material changes will be highlighted on the homepage for at least 30 days.
You can find the version history of this policy on GitHub.
15. Effective date
This Privacy Policy is effective as of .
Previous versions are kept on request.