Privacy policy
As of: 04/25/2026
1. Controller
Christian Prehl
Drachenfelsstr. 5
50939 Köln
E-mail: webmaster@prehl.de
2. Access data and server log files
When this website is accessed, technically necessary access data is processed. This may include in particular the IP address, time of access, requested URL, referrer, user agent, HTTP status, and technical connection data. The processing serves the secure and stable operation of the website, error analysis, and protection against misuse.
Legal basis is our legitimate interest in the secure and stable operation of the website and in error analysis (Art. 6(1)(f) GDPR).
3. User account and sign-in
Signing in is required to submit jokes and for moderation features. In doing so, the data necessary for sign-in, assignment, and permission checks is processed, in particular the user identifier, e-mail address, and technical session data.
Legal basis is the provision of the sign-in–dependent features you use (Art. 6(1)(b) GDPR) and our legitimate interest in secure authentication (Art. 6(1)(f) GDPR).
4. Sign-in via Google
Sign-in can take place via Google. Google is integrated as an external identity provider. As part of the authentication, the data required for sign-in is processed, in particular the user identifier provided by Google as well as profile and e-mail data.
The provider is Google (Google Ireland Ltd. and Google LLC, USA); a transfer of personal data to the USA may occur, which Google safeguards via Standard Contractual Clauses and its certification under the EU-US Data Privacy Framework. Legal basis is the provision of the sign-in you chose (Art. 6(1)(b) GDPR) and our legitimate interest in secure authentication (Art. 6(1)(f) GDPR).
5. Submission and moderation of jokes
When you submit a joke, we store the entered text, language, time of submission, the associated user account, the processing status, and technical review data. The submission is processed for moderation, misuse prevention, duplicate detection, and possible publication.
Legal basis is our legitimate interest in moderation, misuse prevention, and publication (Art. 6(1)(f) GDPR).
5a. Ratings and favorite jokes
Signed-in users can rate published jokes with a thumbs up or thumbs down. We store which user rated which joke, the value of the rating, and the time of creation and last change.
Upvotes are used to show the user their favorite jokes. Ratings may also be used in aggregated form to evaluate the quality and popularity of jokes, prepare rankings, and improve the platform. Currently only the total number of upvotes is shown publicly. Downvotes are not shown as a public count and are not publicly attributed to individual users.
The processing serves to provide the rating and favorite-joke feature as well as to improve the platform and prevent misuse. Users can remove a rating by clicking the same rating again or change it by selecting the other rating.
If a user account is deleted, the ratings associated with that account are also deleted, unless legal retention obligations prevent this.
6. AI-supported analysis and joke explanation
To support moderation and to create or prepare joke explanations, joke texts and associated working data may be transmitted to an AI service provider. In particular, the joke text, existing categories, humor types, and joke patterns are processed. The results are stored in the platform and used editorially.
The AI service provider is OpenAI (OpenAI Ireland Ltd. and OpenAI OpCo, LLC, USA); the joke text and associated working data are transmitted there as a processor on the basis of a data processing agreement. Insofar as a transfer to the USA occurs, OpenAI safeguards it through its certification under the EU-US Data Privacy Framework and, in addition, the EU Standard Contractual Clauses incorporated into the data processing agreement; the transmitted content is not used to train the models. Legal basis is our legitimate interest in efficient moderation and in preparing the joke explanations (Art. 6(1)(f) GDPR).
No confidential or third-party personal data should be entered into joke texts.
7. Misuse protection and rate limits
To limit abusive use, technical characteristics are processed. The IP address is used for rate limits and stored as a hash. The hash serves to detect repeated submissions within a short time without storing the IP address in plain text in the submission.
The IP hashes are automatically deleted after the misuse-protection purpose no longer applies, by default after 7 days. Legal basis is our legitimate interest in protection against abusive use (Art. 6(1)(f) GDPR).
8. Cookies
This website uses technically necessary cookies. These include in particular cookies for sign-in, session management, and security features such as CSRF protection. These cookies are required for the operation of the website.
No additional rating cookies are set for rating jokes. Ratings are only attributed server-side to signed-in user accounts.
No cookies requiring consent under § 25(1) TTDSG are set, so a cookie banner is not required. In detail:
| Cookie | Purpose | Storage period |
|---|---|---|
sessionid |
Session management after sign-in | Session |
csrftoken |
Protection against cross-site request forgery | 1 year |
django_language |
Stores the selected language | 1 year |
Legal basis for technically necessary cookies is our legitimate interest in secure operation (Art. 6(1)(f) GDPR) in conjunction with § 25(2)(2) TTDSG.
9. Recipients and processors
Personal data may be transmitted to technical service providers insofar as this is necessary for operation, sign-in, hosting, misuse protection, or AI-supported processing. This may include in particular hosting providers, Google as the login provider, and the AI service provider used.
Recipients are in particular the hosting provider, Google as the login provider (USA), and OpenAI as the AI processor (USA). Transfers to the USA are safeguarded by Standard Contractual Clauses or corresponding certifications (see sections 4 and 6).
10. Storage period
Personal data is only stored for as long as necessary for the respective purposes. Server logs are stored for a limited time. User accounts, submissions, ratings, favorite-joke assignments, moderation data, and published content are stored as long as they are required for platform operation, user features, moderation, documentation, or publication. IP hashes for rate limits should be deleted or anonymized after the misuse-protection purpose has expired.
In particular, IP hashes for rate limits are deleted after 7 days by default.
11. Rights of data subjects
Data subjects have in particular the right to information, rectification, erasure, restriction of processing, data portability, and objection. There is also a right to lodge a complaint with a data protection supervisory authority.
To exercise these rights — including deletion of your account and associated data — an informal message to the contact address stated in the imprint is sufficient. We process requests without undue delay, at the latest within the statutory period of one month.
12. Obligation to provide data
Use of the publicly available content is generally possible without signing in. For submissions, ratings, favorite jokes, and moderation features, the required sign-in, session, rating, and content data is necessary. Without this data, the respective features cannot be provided.