nopenix.de is a personal self-hosting project operated by a
private individual in Germany. It runs a small set of services
(including but not limited to an OpenID Connect identity provider)
primarily for the operator's own use and for a small,
pre-existing circle of friends who self-host. The operator is not
a company, business, or organisation in the legal sense, and
nopenix.de is not a commercial service.
When you sign in, the respective identity provider verifies your identity and shares a limited set of profile information with us via the OpenID Connect (OIDC) / OAuth 2.0 protocol. We currently support sign-in with the following providers:
Google — via Google Identity Services
GitHub — via GitHub OAuth Apps
Microsoft — via Microsoft Entra ID (formerly Azure AD), supporting both personal Microsoft accounts and work/school accounts
2.1 Data received from the provider
Depending on the provider and the scopes you approve, we may receive:
A stable, unique user identifier (OIDC sub / provider's user ID), used solely to recognise you on subsequent visits
Your email address (if you granted the email scope)
Your display name (if available)
Your profile picture URL (if available)
Your locale / preferred language
For Microsoft accounts only, an opaque tenant ID (tid) so we can distinguish between personal accounts and work/school accounts — we never see the organisation's name or any directory data
We only request the data we actually need to operate the service. We do not request access to your emails, contacts, repositories, files, calendars, OneDrive, Teams, or any other resource belonging to the providers.
2.2 Data generated by using the service
In addition to what the providers send, we store:
The timestamp of your last sign-in
IP address in our access logs (for abuse prevention; rotated regularly)
Basic session cookies necessary for the sign-in flow
3. What we use the data for
We use this data strictly to:
Create and manage your account on this service
Authenticate you when you return
Prevent abuse and secure the service
Communicate with you about the service (if needed)
We do not use your data for advertising, profiling, marketing, or any form of automated decision-making. We do not perform any cross-provider tracking.
4. Data storage and security
Your data is stored on servers operated by us in the EU.
We take reasonable technical measures to protect your data from unauthorized access (encrypted transport, least-privilege access on the server).
However, this is a private project run by a single person — see section 7.
5. Data sharing
We do not sell, rent, or share your data with third parties.
The only recipients are:
The identity provider itself, which technically re-receives requests as part of the sign-in flow
Our hosting provider, which stores the data on disk on our behalf (GDPR Art. 28 — processor relationship)
Law enforcement, only if we are legally compelled to do so
6. Data retention and deletion
Your data is kept only as long as your account exists and the service is running.
You can request deletion of your account and all associated data at any time by contacting us at the email address above.
We will process deletion requests within 30 days.
Backups are retained at most 30 days, after which your data is purged from them as well.
7. No warranty
This service is provided “as-is”, without any warranty of any kind — express or implied. We make no guarantees about:
Availability, uptime, or reliability
Correctness or completeness of results
Fitness for any particular purpose
We reserve the right to modify, suspend, or discontinue the service (in whole or in part, including any of the supported sign-in providers) at any time, with or without notice.
8. Your rights (GDPR / DSGVO)
Under the EU General Data Protection Regulation, you have the right to:
Access the data we hold about you (Art. 15)
Correct inaccurate data (Art. 16)
Request deletion of your data (Art. 17)
Restrict or object to processing (Art. 18, 21)
Data portability (Art. 20)
Withdraw consent and stop using the service at any time
Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at the email address above. We will respond within 30 days.
9. Changes to this policy
We may update this policy occasionally. The “Last updated” date at the top will reflect when changes were made. Continued use of the service after a change constitutes acceptance of the updated policy.
10. Governing law
This policy is governed by the laws of the Federal Republic of Germany. The court of jurisdiction is Nuremberg (Nürnberg), Germany.