Skip to content

Privacy policy

Applies to 2mi.dev as well as brbjournal.2mi.dev, huedown.2mi.dev and yonder.2mi.dev

1. Privacy at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data by which you can be personally identified. For detailed information on data protection, please refer to the privacy policy set out below this text.

Scope

This privacy policy applies centrally to the overview page 2mi.dev and to all services we operate on subdomains — currently brbJournal (brbjournal.2mi.dev), huedown (huedown.2mi.dev) and Yonder (yonder.2mi.dev). Because the individual services differ in what they do, section 5 sets out separately which data is processed in which app.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the section "Information on the controller" in this privacy policy.

How do we collect your data?

Some of your data is collected because you provide it to us. This may, for example, be data you enter when registering a user account or into a form.

Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. internet browser, operating system, or time of the page view). This data is collected automatically as soon as you enter this website.

What do we use your data for?

Part of the data is collected to ensure the website is provided without errors. Other data may be processed in order to provide the functions you use.

What rights do you have regarding your data?

You have the right at any time to obtain information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given consent to data processing, you can withdraw this consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of the processing of your personal data. Furthermore, you have the right to lodge a complaint with the competent supervisory authority.

You can contact us at any time regarding this and any other questions on the subject of data protection.

2. Hosting

Our applications, the database and the storage for uploaded images run on our own hardware in Germany. No external cloud or storage provider receives your content.

The only component in front of this is a reverse proxy with the following provider, which receives requests from the internet and forwards them to our own systems in encrypted form:

Hetzner

The provider is Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (hereinafter Hetzner).

For details, please see Hetzner's privacy policy: https://www.hetzner.com/de/legal/privacy-policy/.

There, IP addresses are processed for abuse prevention (e.g. rate limiting) and are not stored persistently. Hetzner is used on the basis of Art. 6 (1) (f) GDPR. We have a legitimate interest in presenting our website as reliably as possible. Where corresponding consent has been requested, processing takes place exclusively on the basis of Art. 6 (1) (a) GDPR and § 25 (1) TDDDG, insofar as the consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent can be withdrawn at any time.

Data processing agreement

We have concluded a data processing agreement (DPA) for the use of the service named above. This is a contract required by data protection law which ensures that the provider processes our website visitors' personal data only in accordance with our instructions and in compliance with the GDPR.

3. General notes and mandatory information

Data protection

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.

When you use this website, various personal data is collected. Personal data is data by which you can be personally identified. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens.

We would like to point out that data transmission over the internet (e.g. when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

Information on the controller

The controller responsible for data processing on this website is:

Moritz Mikus
c/o Christian Jahnke
Gulisastraße 93
56072 Koblenz, Germany

Email: contact@2mi.dev

The controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

Storage period

Unless a more specific storage period is stated within this privacy policy, your personal data will remain with us until the purpose for processing it no longer applies. If you assert a justified request for deletion or withdraw your consent to data processing, your data will be deleted unless we have other legally permissible reasons for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, deletion takes place once those reasons cease to apply.

General information on the legal bases for data processing

If you have consented to data processing, we process your personal data on the basis of Art. 6 (1) (a) GDPR or Art. 9 (2) (a) GDPR where special categories of data under Art. 9 (1) GDPR are processed. In the case of explicit consent to the transfer of personal data to third countries, processing also takes place on the basis of Art. 49 (1) (a) GDPR. If you have consented to the storage of cookies or to access to information on your device (e.g. via device fingerprinting), processing additionally takes place on the basis of § 25 (1) TDDDG. Consent can be withdrawn at any time. If your data is required for the performance of a contract or for pre-contractual measures, we process your data on the basis of Art. 6 (1) (b) GDPR. Furthermore, we process your data where required to fulfil a legal obligation on the basis of Art. 6 (1) (c) GDPR. Data processing may also take place on the basis of our legitimate interest under Art. 6 (1) (f) GDPR. The relevant legal bases in each individual case are set out in the following paragraphs of this privacy policy.

Recipients of personal data

We only pass personal data to external parties where this is necessary for the performance of a contract, where we are legally obliged to do so, where we have a legitimate interest under Art. 6 (1) (f) GDPR in doing so, or where another legal basis permits it. When using processors, we pass on our users' personal data only on the basis of a valid data processing agreement. In the case of joint processing, a joint controllership agreement is concluded.

Withdrawal of your consent to data processing

Many data processing operations are only possible with your express consent. You can withdraw consent you have already given at any time. The lawfulness of the data processing carried out up until the withdrawal remains unaffected by the withdrawal.

Right to object to data collection in special cases and to direct marketing (Art. 21 GDPR)

IF DATA PROCESSING IS CARRIED OUT ON THE BASIS OF ART. 6 (1) (E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION; THIS ALSO APPLIES TO PROFILING BASED ON THESE PROVISIONS. THE RESPECTIVE LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21 (1) GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR THE PURPOSE OF DIRECT MARKETING, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR THE PURPOSE OF SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS CONNECTED WITH SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR THE PURPOSE OF DIRECT MARKETING (OBJECTION UNDER ART. 21 (2) GDPR).

Right to lodge a complaint with the competent supervisory authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work or the place of the alleged violation. This right to complain exists without prejudice to any other administrative or judicial remedies. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate (Landesbeauftragter für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz).

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in performance of a contract handed over to you or to a third party in a common, machine-readable format. If you request the direct transfer of the data to another controller, this will only be done insofar as it is technically feasible.

Access, rectification and erasure

Within the framework of the applicable statutory provisions, you have the right at any time to free information about your stored personal data, its origin and recipients and the purpose of the data processing and, if applicable, a right to rectification or erasure of this data. You can contact us at any time regarding this and any other questions on the subject of personal data.

Right to restriction of processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time to do so. The right to restriction of processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored by us, we generally need time to verify this. For the duration of the review, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of erasure.
  • If we no longer need your personal data but you need it to exercise, defend or establish legal claims, you have the right to request the restriction of the processing of your personal data instead of erasure.
  • If you have lodged an objection under Art. 21 (1) GDPR, a balance must be struck between your interests and ours. As long as it has not been determined whose interests prevail, you have the right to request the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, this data may — apart from being stored — only be processed with your consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a member state.

No automated decision-making

No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place in our services.

Minimum age

Our services are intended for people aged 16 and over. People under the age of 16 may only use our services with the consent of the holder of parental responsibility and may not transmit personal data to us without that consent. We do not carry out active age verification. If we become aware that personal data of a person under 16 has been transmitted to us without the required consent, we delete that data.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser's address line changing from "http://" to "https://" and by the lock symbol in your browser bar.

When SSL or TLS encryption is activated, the data you transmit to us cannot be read by third parties.

Objection to advertising emails

The use of contact data published under the imprint obligation to send unsolicited advertising and information material is hereby objected to. The operators of the pages expressly reserve the right to take legal action in the event of the unsolicited sending of advertising information, for example through spam emails.

4. Data collection on this website

Cookies

Our web pages partly use so-called "cookies". Cookies are small data packets and do no harm to your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain stored on your device until you delete them yourself or your web browser deletes them automatically.

Cookies have various functions. Many cookies are technically necessary because certain website functions would not work without them (e.g. keeping you signed in). Cookies required to carry out the electronic communication process or to provide certain functions you have requested (necessary cookies) are stored on the basis of Art. 6 (1) (f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies for the technically error-free and optimised provision of its services. Where consent to the storage of cookies and comparable recognition technologies has been requested, processing takes place exclusively on the basis of that consent (Art. 6 (1) (a) GDPR and § 25 (1) TDDDG); consent can be withdrawn at any time.

You can set your browser so that you are informed about the setting of cookies and only allow cookies in individual cases, exclude the acceptance of cookies for certain cases or in general, and activate the automatic deletion of cookies when closing the browser. If cookies are deactivated, the functionality of this website may be limited.

Which of our services use cookies and which do not is set out in detail in section 5. We ourselves do not use any cookies for analytics or advertising purposes. In addition, cookies or comparable recognition technologies may be set by the map service embedded in Yonder; for details, see section 6.

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Host name of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources.

This data is collected on the basis of Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in the technically error-free presentation and optimisation of its website — for this, the server log files must be recorded.

Enquiries by email or in-app form

If you send us a message by email or via a form within one of our apps (e.g. a bug report, feature request or other enquiry), your details including the contact data you provide there will be stored by us for the purpose of processing the enquiry and in case of follow-up questions. We do not pass on this data without your consent.

This data is processed on the basis of Art. 6 (1) (b) GDPR if your enquiry is connected with the performance of a contract or is necessary for pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of enquiries addressed to us (Art. 6 (1) (f) GDPR) or on your consent (Art. 6 (1) (a) GDPR) where this has been requested; consent can be withdrawn at any time.

The data you send us remains with us until you request its deletion, withdraw your consent to storage, or the purpose for storing the data no longer applies (e.g. after your enquiry has been dealt with). Mandatory statutory provisions — in particular statutory retention periods — remain unaffected.

5. Our services in detail

The following sections describe which data is processed in each of our services. The general sections 2 to 4 of this policy apply to all of them in addition.

2mi.dev (overview page)

The overview page is a purely static page. It sets no cookies, embeds no external resources, uses no analytics and has no user accounts. Only the server log data described above is processed.

brbJournal (brbjournal.2mi.dev)

Registration and user account

Using brbJournal requires a user account. On registration we collect your email address and a password of your choosing. The password is stored exclusively as a cryptographic hash and is never visible to us in plain text. Processing takes place on the basis of Art. 6 (1) (b) GDPR for the performance of the usage relationship.

To keep you signed in, we set a technically necessary session cookie. This cookie serves session management only, not analytics or tracking; consent under § 25 (1) TDDDG is not required for it, as it is strictly necessary for the service you have expressly requested. When you sign out, the session is ended and the cookie is removed.

Entries and uploaded photos

We store the journal entries you create and the photos you upload with them. On upload, image metadata (EXIF), including any GPS location data, is automatically stripped before the image is stored. The image files reside in the self-hosted object storage described above. The legal basis is Art. 6 (1) (b) GDPR.

Share links

You can share an individual entry via a link. Anyone holding that link can view the entry without an account of their own. A share link automatically expires after 7 days; you can revoke it yourself at any time before then. Sharing takes place on the basis of your decision (Art. 6 (1) (a) GDPR).

Deleting your account

You can delete your account yourself, in full, at any time within the app. Doing so permanently removes your entries, the associated photos, your sessions and your messages.

huedown (huedown.2mi.dev)

huedown requires no account with an email address or password. On first launch, a device token is stored locally in your browser (not a cookie) so the app recognises you next time. In addition, you provide a freely chosen display name, which is not verified.

Photos you take during a round are stored and shown to the participants of your round. Here too, all image metadata including GPS location is stripped before a photo is shown to another person. Rounds are not public and are only accessible via an invite code.

Your IP address is processed only briefly, to limit how many new devices can be created from one address, and is not stored. huedown uses no cookies, no analytics and no third-party scripts.

All data in a round — photos, collages and the round itself — is deleted automatically 7 days after the round ends. A device that is neither hosting nor playing in a round and has not been active for some time is also deleted automatically. The legal basis is Art. 6 (1) (b) GDPR.

Yonder (yonder.2mi.dev)

Yonder creates no user accounts, sets no cookies and has no application server of its own — the app runs entirely in your browser. Your location is determined via your device's geolocation API, and only after you have expressly granted access in your browser. Your location is never transmitted to us and we do not store it.

To display the map and determine a destination, map tiles are loaded from an external map service and coordinates are transmitted to its servers. The legal basis for this is Art. 6 (1) (f) GDPR; for details and the balancing of interests, see "OpenStreetMap" in section 6 below.

6. Plugins and tools

Fonts

All fonts used in our services are delivered from our own servers or embedded at build time into the respective application. Where a font originally comes from the Google Fonts catalogue, it is embedded locally only — your browser does not establish a connection to Google's servers and no IP address is transmitted to Google.

OpenStreetMap

We use the OpenStreetMap (OSM) map service in Yonder.

We embed map material from OpenStreetMap hosted on the servers of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS, United Kingdom. The United Kingdom is considered a safe third country under data protection law. This means that the United Kingdom has a level of data protection that corresponds to the level of data protection in the European Union. When using the OpenStreetMap maps, a connection to the servers of the OpenStreetMap Foundation is established. In doing so, your IP address and further information about your behaviour on this website may, among other things, be forwarded to the OSMF. OpenStreetMap may store cookies in your browser for this purpose or use comparable recognition technologies.

To select a destination, Yonder additionally transmits your approximate location (coordinates) to one of the following Overpass API servers operated by third parties: overpass-api.de, overpass.kumi.systems, overpass.private.coffee. We have no influence on the data processing carried out by these providers; their own privacy policies apply.

Displaying the map and finding a destination are Yonder's core function and cannot be provided without external map data; hosting the world's map material ourselves is not feasible for us. This constitutes our legitimate interest within the meaning of Art. 6 (1) (f) GDPR. Access to information on your device is, to that extent, strictly necessary under § 25 (2) no. 2 TDDDG in order to provide the service you have expressly requested; consent is not required for this. You may object to this processing under Art. 21 GDPR — since the map is indispensable to Yonder, an objection means Yonder cannot be used.

Last updated: August 2026. The German version is the authoritative one; this translation is provided for convenience. Template source: https://www.e-recht24.de