Privacy policy
As of: 03.10.2026
Controller (Art. 4(7) GDPR)
Andreas JolteaSchmellerstr. 47
92655 Grafenwöhr
Deutschland
Email: a.joltea@me.com
1. Overview
NEXEARTH sets no cookies of its own except the access cookie for testers who enter an access code (section 7f), uses no third-party analytics, tracking or advertising tools and has no user account; it only runs its own cookie-free visit count without any identifier (section 2). Third parties can only set cookies on your device after you start an embedded webcam by clicking (section 10). We process personal data only as far as necessary to provide the website and the functions you use. You are not obliged to provide any personal data; without the technical access data, however, the website cannot be displayed.
2. Hosting, server logs and abuse protection
The website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. When you access it, Vercel processes technical access data (IP address, time, requested URL, referrer, browser/user agent) in server logs and in its delivery network in order to deliver the site and keep it secure. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure, working website). Vercel acts as our processor (Art. 28 GDPR, data processing addendum). Logs are kept only for a short time according to Vercel's retention periods; we do not use them to profile visitors.
Security reports (/api/csp-report): if your browser blocks a resource on our pages because of our security policy (CSP), it may send us a technical report. We keep only the rule concerned, the blocked origin (scheme and host) and the page path without parameters – no IP address, no browser details, no full address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a secure website).
Error reports (/api/client-error and server errors): if a page of ours fails, your browser sends us one short technical report per error – the type of error, its message cut to 300 characters with e-mail addresses, long numbers and address parameters removed, the script file and line, the page path without parameters, the time and the version of the website. We do not record or store an IP address, browser details or anything you typed for this (technically, your IP address reaches our host with every request, section 2); errors on our server are recorded in the same reduced form. We use the reports only to find and fix errors; they appear as a line in the server logs at Vercel and are deleted there after Vercel's retention period, a counter per error is held only in working memory. Nothing is stored on your device for this. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working website and screens).
Cookie-free visit count (/api/m): to see which steps in Studio and Spot are reached (such as “Studio opened”, “ad created”, “booking sent”) and which of our pages are visited, our page sends a list of fixed event names to our server when you leave or hide it (one request per page load, only from a fixed list, with the page name only for our own main pages and otherwise “other”). Nothing is stored on your device and nothing is read from it apart from one browser setting – whether the “Global Privacy Control” signal is on (no cookie, no local storage, no identifier). We do not record or store your IP address, browser identifier, address query parameters or anything you typed; the IP address only feeds the abuse brake briefly in working memory, and our host receives it technically like with every request (see above). Only daily counts per event are stored in non-public storage (Vercel Blob, Frankfurt); they cannot be linked to you or your device. The legal basis is our legitimate interest in improving the service and finding where it fails (Art. 6(1)(f) GDPR). In our view this is not an access to or storage of information on your device within the meaning of § 25(1) TDDDG, because only fixed event names that our page itself composes are sent and nothing is stored; supervisory authorities partly read this provision more broadly, which is why the count is deliberately minimal. If your browser sends the “Global Privacy Control” signal, we do not count at all. You can also object at any time (section 14); an email is enough.
Approximate location in kids mode: if no place and no country is set in the Studio, kids mode shows the distance to the stories from where the screen roughly is. For this our server reads the city and approximate coordinates that our host Vercel derives from the request's IP address (city level). We do not store this information or link it to anything; it is only returned to your browser. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in an understandable, place-related display). If you do not want this, set a place or a country in the Studio.
Transfers to the USA: Vercel Inc. is certified under the EU-US Data Privacy Framework; transfers are based on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR) and, in addition, on the standard contractual clauses in Vercel's data processing addendum (Art. 46(2)(c) GDPR).
To prevent misuse, our server endpoints (including translation, images, places, webcams, radio, AI briefs and the ad analysis in Spot) count requests per IP address. The address is only held in the server's working memory – usually for a few minutes, until the respective time window has passed and the counter is cleaned up – and is neither stored permanently nor linked to other data. Legal basis: Art. 6(1)(f) GDPR.
3. Fonts and globe data
Fonts (Sofia Sans, JetBrains Mono) are served from our own server (self-hosted via next/font); no connection is made to Google Fonts. The globe's textures and country shapes also come from our own server, as does the brand film on the home page; when it plays, your browser connects only to us, not to a video service.
4. Data retrieval via our server (no IP forwarding)
Live data, news, market and sport data, encyclopedia texts and Wikimedia images are fetched by our server from the following sources. Your IP address and browser data are not passed on to these providers; they only see a request from our server.
- /api/live: USGS (earthquakes), NASA EONET, GDACS, NOAA SWPC, Launch Library 2 (The Space Devs), wheretheiss.at, Energy-Charts (Fraunhofer ISE), Carbon Intensity API (UK), NOAA NHC (tropical storms), NASA FIRMS (fires), EMSC (earthquakes), Smithsonian GVP (volcanoes)
- /api/sats: CelesTrak (orbital elements of civil satellites); /api/aurora: NOAA SWPC OVATION (aurora forecast)
- /api/news: RSS feeds of news providers (incl. DW, heise, Spektrum, Phys.org; tagesschau, BBC and The Guardian only once their permission for commercial use exists, switched off until then); /api/local: Google News RSS – only the country, topics and, if chosen, the place name you picked are sent
- /api/markets: CNBC (stock indices; only when enabled, switched off until then), Frankfurter (ECB reference rates), CoinGecko (crypto prices); /api/sport: OpenLigaDB and openfootball/football.json from GitHub (raw.githubusercontent.com, CC0 – fixtures and kick-off times only, for Serie A, Ligue 1, Eredivisie, Primeira Liga); only when enabled: football-data.org, NHL, MLB, NBA, ESPN; /api/sport/news: kicker, Sky Sports, MLB.com (RSS); sportschau, tagesschau, BBC Sport and The Guardian only with their permission, switched off until then
- /api/translate and /api/local: machine translation of headlines (DeepL, language models at Groq or Cerebras, free language models via OpenRouter or a language model via the Vercel AI Gateway, section 8) – only the text of public headlines is sent
- /api/ai/brief and /api/ai/facts: “AI brief” on a headline and “AI quick facts” on a place via Groq, Cerebras or OpenRouter (section 8) – only the public headline or the introduction of the Wikipedia article, which our server fetches from Wikipedia itself, is sent
- /api/place: MET Norway / Norwegian Meteorological Institute (weather), Wikipedia (nearby article), World Bank (country indicators) – only the tapped point's coordinates, rounded to 0.01°, and the country code are sent; for the weather at a webcam (camera wall, cam panel) only MET Norway with the camera's coordinates rounded to 0.01° (about 1 km)
- /api/sights: Wikipedia (sights nearby, author and licence of the images from the file page) – only the map centre's coordinates, rounded to 0.01°, are sent
- /api/radio: radio-browser.info (station directory, also for the radio from a webcam's area) – only the country code, search term or rounded coordinates are sent; when you start a station, our server reports the play to Radio Browser (click counter) without your IP address
- /api/tv: iptv-org (channel directory) and availability checks of the channel streams by our server
- /api/geo: Photon (komoot) and OpenStreetMap Nominatim – only the place name you type is sent
- /api/roadtrip, /api/roadtrip/covers and /api/roadtrip/along: Wikipedia, Wikidata and Wikimedia Commons (pictures of the sights and photos along the road via Commons geosearch, each with author and licence) (the routes themselves are computed once and stored in the project, no route planner is asked) – only coordinates along the fixed route and article and file names are sent, never your location
- /api/learn, /api/onthisday and /api/wikicard: Wikipedia/Wikimedia (including the short descriptions in the city explorer, random trip and world quiz, and author and licence of the images), Simple English Wikipedia and Klexikon (ZUM e. V.) – only language, date, topics or article names are sent
- /api/dwd/warnings, /api/dwd/radar, /api/airsun: Deutscher Wetterdienst (German Meteorological Service, Offenbach) and Umweltbundesamt (German Environment Agency, Dessau-Roßlau) – our server fetches warnings, radar tiles (map mode only), pollen/UV and air-quality data; no viewer data is sent
- /api/warnings: Federal Office of Civil Protection and Disaster Assistance (BBK, Bonn) and Federal Agency for Cartography and Geodesy (BKG, Frankfurt am Main) – our server sends the coordinates of the place set in the studio, rounded to about 100 m, to the BKG to find its district, and fetches that district's official warnings from the BBK; no viewer data is sent and nothing is stored.
- /api/featured: Wikimedia Foundation (USA) – only language and date are sent
- /api/art: Art Institute of Chicago, The Metropolitan Museum of Art and Cleveland Museum of Art (USA) – no viewer data is sent
- /api/sky: calculated entirely on our server with the astronomy-engine library (MIT) (moon phase, visible planets, eclipses); nothing is fetched from third parties. Only the screen's place is sent, rounded to 0.1° (about 10 km)
- /api/apod: NASA (USA) – no viewer data is sent
- /api/img: images from Wikimedia Commons/Wikipedia (upload.wikimedia.org, thumb.wikimedia.org) – our server loads the image, your browser receives it from our address; images from the Art Institute of Chicago, The Metropolitan Museum of Art, the Cleveland Museum of Art and NASA are also loaded only via /api/img, your browser does not contact these providers
- /api/atlas: World Bank, Our World in Data (Ember), Wikidata
- /api/atlas (Europe maps): Eurostat (European Commission, Luxembourg); further world maps via Our World in Data with data from FAO, NCD-RisC and UN World Population Prospects – no viewer data is sent
- /api/atlas/discover (daily learning run, no viewers involved): language models at Groq or Cerebras or free language models via OpenRouter (section 8) receive only a list of public dataset names; our server checks suggested RSS addresses by fetching them – no viewer data; the result is stored with Vercel Blob if configured
- /api/images/generate and /api/images/ambient: AI symbol pictures for Spot ads and calm background pictures via Cloudflare Workers AI, alternatively Pollinations and – only if specially switched on – Google Gemini (section 8) – only a short picture description made from public ad content without contact data is sent; our server delivers the pictures (/api/images/file), your browser never connects to these providers
- /api/cams/img: the servers of the openly licensed cameras (Transport for London, Ayuntamiento de Madrid, Hong Kong Transport Department, Japan Meteorological Agency, GeoNet, USGS, National Park Service, Caltrans, DriveBC, NOAA, ESO) – our server fetches the latest picture; only the picture address is sent, no data about you; pictures stay in working memory for a few minutes at most and are not stored
- /api/venue/content (programme “Bar & club”): RSS feeds of music and lifestyle media (laut.de, Musikexpress, Rolling Stone, Groove, NME, Billboard, Pitchfork, Stereogum, Consequence, Clash, DJ Mag, Dancing Astronaut, XXL, The FADER, Dezeen, PUNCH, Eater – headline, source and link only), – only where the providers have permitted the use, both sources are switched off until then – the Apple Music charts (Apple Inc., rss.marketingtools.apple.com) and Ticketmaster (concerts within 30 km, in addition only with a key set up) – only the country, music genre and the screen's place rounded to about 10 km are sent, never viewer data; a language model may choose among the music items from the public headlines (section 8)
- /api/venue/events (programme “Bar & club”, only at the operator’s request): the server fetches the calendar link (https, .ics) the operator entered. The address is kept only in the operator’s browser (local storage) and sent to our server only for the fetch, by POST; it is not stored or logged (a short cache of up to 30 minutes under a hash). Only title, start and place of the next 14 days are read; none of it is stored. The calendar provider receives our server’s IP address, not the viewers’. The legal basis is the operator’s request (Art. 6(1)(b) GDPR); the operator is responsible for personal data in their own calendar.
- /api/webcams: YouTube (oEmbed and video page, only to check whether a webcam is live), the servers of the openly licensed cameras (only to check that a current picture exists) and – only if the operator has set up a Windy key (WINDY_KEY) – the Windy.com Webcams API – only video IDs or the map section's centre rounded to 0.01° are sent
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the information service) and, where you actively request a function (e.g. searching a place, translating headlines), Art. 6(1)(b) GDPR.
5. Direct connections from your browser
In the following cases your browser connects directly to a third party, which then receives your IP address and technical browser data (browser type, language, time, the requesting page) and is responsible for its own processing. This only happens when you use the function in question:
- Radio and TV: when you start a station, your browser connects directly to the broadcaster's streaming server or its delivery network (e.g. Akamai). In the Explorer this only happens after you click a station. In the Studio, the screen's operator switches TV and radio on, on Spot screens only after confirming they hold the licences for public performance; the device then plays without a further click.
- Live webcams, the camera wall and the radio from a webcam's area: see section 10.
- Maps: when you zoom in closely in the Explorer, open the city explorer or a road trip, the Studio shows a map (region map, map stage) or a Spot map is shown, your browser loads map tiles, fonts and symbols from OpenFreeMap (tiles.openfreemap.org) and terrain elevation from Mapterhorn (tiles.mapterhorn.com); in the “satellite” view also image tiles from EOX IT Services GmbH, Austria (tiles.maps.eox.at).
- Globe view “satellite image” or “night lights”: the tiles come directly from NASA GIBS (gibs.earthdata.nasa.gov, USA) – only once you choose that view.
- Spot: when booking, the preview shows logos and pictures loaded directly from the website whose link you entered; a Spot screen may load ad pictures directly from the advertiser's website.
- Links to external sites (e.g. publishers, broadcasters, data providers) are ordinary links; data only flows once you click them.
Legal basis: Art. 6(1)(b) GDPR (providing the function you asked for) and Art. 6(1)(f) GDPR (legitimate interest in showing broadcasts, maps and images without routing large data volumes through our server). Where a provider is located in the USA (NASA, Wikimedia Foundation), your data may be processed there; for providers not certified under the Data Privacy Framework the USA does not offer a level of data protection equivalent to the EU. You can avoid these connections by not using the respective function.
6. Location and microphone (only on request)
In the city explorer you can ask the app to use your current location. Your browser first asks for your permission. Your device only uses the coordinates to move the map there; they are not sent to us. When the app then looks up sights around the map centre, only the map centre rounded to about 100 m reaches our server (section 4). Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which you can withdraw at any time in your browser settings.
Webcams: if – and only if – you have already allowed this site to use your location, the webcam panel reads it to show the distance to the camera. It never asks for permission itself; the distance is calculated on your device and the location is not sent to us.
Microphone (programme "Bar & club", audio reactivity): only if the operator switches on "react to the room" does the browser ask for access to the microphone. The sound is analysed exclusively on this device into a few loudness and frequency values (bass, mids, highs) that move the visuals; speech is not recognised, nothing is recorded, stored or sent to us or anyone else. Without permission, or on a device without a microphone, the visuals run without it. Access can be withdrawn at any time in the browser settings or by switching the feature off. Legal basis: consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG); operators decide whether to use the feature in their venue.
7. Storage on your device
The app stores settings and favourites in your browser (localStorage/sessionStorage/IndexedDB) under the keys “nx-prefs” (Explorer settings), “nx-studio” and “nx-studio-coach” (Studio), “nx-unfiltered” (only the expiry time of the voluntarily enabled “Unfiltered news”), “oc-tour-seen” (tour seen), “nex.explorer.pass.v1” (explorer pass), “nexearth.radio.favs” and “nx-tv-favs” (favourite stations), “nexearth.kids.v1” (kids mode), “nx-spot-screens”, “nx-spot-bookings”, “nx-spot-board” (notice-board posts with the contact details given there), “nx-spot-health” (screen status), “nx-spot-operator” and “nx-spot-operator-party” (operator key and credit-note details, section 7d) (Spot), “nx-venue-cal” (only if the operator enters it: calendar link for the “Bar & club” programme; it can contain a secret access token and leaves the device only for the fetch, section 4), “nx-tv-subs” (subtitles on/off), “nx-camwall-presets” (saved camera walls; “nx-wall-autofill” remembers that the first wall was already pre-filled once; the webcam density on the map is kept as “camDensity” in “nx-prefs”, the camera wall's settings in “nx-studio”), and in sessionStorage “oc-launch”, “nx-kiosk-restart”, “nx-pin-wait” (number of wrong PIN attempts and the wait until the next try) and “nx-wall-consent” (the operator's consent for the camera wall, section 10); also “nx-pair-tv” and “nx-pair-screens” (pairing: device ID on the screen, your paired screens on the phone), “nx-offline-since”, “nx-wd-reloads” and “nx-wd-nightly” (24/7 operation: offline time and reload protection), “nx-quickstart-t0” (quick-start time, only to show how long it took), “nx-probe” (a test entry that checks whether storing is possible and is deleted at once), “nx-err-recover” (in localStorage: counter and time of the automatic recovery after a display error, so an unattended screen reloads at most six times a day), “spot-booking:…” (unfinished booking draft, this session only), “nx-screen” (which Spot screen belongs to this Studio and which ads you paused), “nx-studio-tv2” (one-off migration mark of the channel setting), “nexearth.atlasOwnerKey” (operator only: his admin key for source curation), in IndexedDB “nx-spotbg” (at most 16 recently generated map backgrounds for Spot ads so they also appear offline; no personal data) and “nx-spot-video” (videos you choose for a Spot booking; they stay on your device until you delete them in the Spot settings under “Stored videos”) and the app’s offline copies in the browser’s Cache Storage (“nx-…”: page shell at most 14 days, images and map tiles at most 30 days, program files at most 60 days, the last loaded reports and ad pictures at most 72 hours). This data stays on your device and is never sent to us. Storage is strictly necessary to provide the function you requested (§ 25(2) no. 2 TDDDG). You can delete it at any time via your browser settings.
7a. Pairing a screen without an account (/tv, /koppeln)
When you pair a screen, we store in our Vercel Blob store (Frankfurt region) the screen's studio settings (without the lock PIN), a random device ID, hashes of a device secret, of a QR pairing key (claim token) and of the edit keys (up to five phones per screen), a version number and the time the screen last reported in together with the programme it runs and whether its page was visible at that moment. We store no IP address, no name and no email address. To prevent abuse the server counts requests per IP address and per device ID briefly in memory; this count is not stored.
The pairing code expires after 15 minutes and is deleted once used; leftovers of unused codes are removed by a daily job after two hours at the latest. The screen's name and the edit key are stored only on your phone (localStorage), the device ID and secret only on the screen. "Remove device" deletes the data on the server at once; all that remains is a revocation mark (a random device ID and a time) so that the screen notices it was removed; it is deleted after 400 days. If the server hears nothing from a paired screen for 400 days (no report from the screen, no change from a phone), the daily job deletes the device with its data and play records in the same way; the revocation mark then also stays for 400 days. Legal basis: Art. 6(1)(b) GDPR (the feature you asked for).
7b. Sound & licences (licence confirmation)
If you choose “I hold a valid licence (GEMA/AKM/SUISA) for this location” for a screen, we store the time of your confirmation and – only if you enter one – the customer or venue number (at most 40 characters) together with that screen's settings: for the Studio in your browser under “nx-studio”, for Spot under “nx-spot-screens”; for a paired screen also with its studio settings in our Vercel Blob store (section 7a). A Spot setup link leaves the number and the confirmation out. We neither evaluate nor check the number and do not pass it on. It is deleted as soon as you choose another option or remove the screen. Legal basis: Art. 6(1)(b) GDPR (the feature you asked for).
The licence-free sounds by NEXEARTH are generated by your browser itself; nothing is downloaded and nothing is transmitted for them.
7c. Proof of play for advertisers (Spot)
So that advertisers can check that their ad actually ran, a Spot screen sends a short heartbeat to our server (/api/screen/heartbeat) every 30 seconds while its page is visible: the screen's ID, the device's time and time zone, the ad on air, the position in the loop, the ads shown in full since the last heartbeat (with start and end), the opening hours set for the screen and – for a paired screen – its random device ID with a signature. No data about viewers is collected: no camera, no microphone, no counting of people, no cookies. The IP address is not stored; to prevent abuse the server counts requests per IP address briefly in memory.
From this our server counts, per screen and day, the minutes covered without gaps and the complete plays of each ad within the opening hours. For paired screens these daily figures are stored in our Vercel Blob store (Frankfurt region); while the screen keeps reporting, figures older than 13 months are deleted. Heartbeats of unpaired screens and of the demo count as demo only and are kept briefly in working memory, never stored. A link to a person can at most exist indirectly via the screen's operator. Purpose: proof of play and billing towards advertisers. Legal basis: Art. 6(1)(b) GDPR (contract for showing the ad) or Art. 6(1)(f) GDPR (legitimate interest in verifiable proof).
7d. Screen operators: competitor protection, payouts and credit notes (Spot)
Competitor protection: when you publish the competitor protection of a Spot screen, we store in our Vercel Blob store (Frankfurt region) the screen ID, the blocked lines of business, the radius, the screen's industry and its location rounded to about 100 m, together with your random operator ID. When booking, the advertiser's browser sends the chosen line of business and – if the ad names one – the ad's location for the check (/api/spot/eligibility); we do not store them. Legal basis: Art. 6(1)(b) GDPR.
Operator profile: for payouts and credit notes we store under a random operator ID (no name, no email address): a hash of its key, your tax status (small business or standard VAT) with the time you chose it, the time and wording version of your consent to self-billing, the number series of your credit notes and – once you link a payout account – the Stripe account ID and its status. The key is kept only in your browser (localStorage “nx-spot-operator”). Name, address and tax number or VAT ID for the credit note stay in your browser (“nx-spot-operator-party”) and are transmitted to our server only to create a credit note; it is generated in working memory and not stored. Legal basis: Art. 6(1)(b) GDPR; once real payouts exist also Art. 6(1)(c) GDPR (retention of invoices and accounting records, § 14b UStG, § 147 AO).
Stripe (only once payouts are switched on): to link a payout account you are forwarded to Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland). Stripe collects the identity and bank details itself and processes them under its own responsibility, in particular for identity checks required by anti-money-laundering law; Stripe's privacy policy applies, including for any transfers to third countries. We send Stripe only the country, the requested capability and your operator ID; Stripe tells us the account ID and whether onboarding is complete and payouts are enabled. Today no connection to Stripe exists.
Storage period: published competitor protection until you clear it or remove the screen; the operator profile as long as you use payouts, credit notes and the related documents once live for the statutory retention periods; Stripe webhook event IDs (to process each event only once) without personal data.
7e. Play cards (quiz and “Where is it day right now?”)
In the Studio and on Spot screens, play cards appear now and then: a tap-to-answer quiz and a world map showing where it is day and night right now, with the local time in a few cities. The questions, map points and city list are built into the app; no data is fetched for them and none is sent to us or to third parties. Your answers and the number of right answers in a row stay in the page's working memory only and disappear when you close or reload it; there are no prizes and no leaderboard. Your device works out the sun's position and the local times from its own clock. If you do not want the cards, switch them off in the Studio under the modules (“Play cards”) or in the Spot settings under the programme modules; that choice is kept in “nx-studio” or “nx-spot-screens” (section 7).
7f. Access code for testers (cookie)
NEXEARTH is not released yet. Studio, Spot and the other features can only be used with an access code (/zugang). When you enter a correct code, we set the cookie “nx_access” in your browser: it contains a random identifier of the code (not the code itself), its expiry date and a signature, so our server recognises the access with each request. A second cookie “nx_ah” only contains the value 1, so the page can show “Test access active”. Both cookies expire after 30 days or when you click “Sign out”. A screen already paired with NEXEARTH receives the same cookie for 7 days without a code (renewed automatically while it is paired). We do not store which code was used by whom, and the cookie is not used to analyse or recognise you across visits. The code you enter is checked on our server and not stored; to brake guessing, attempts are counted per IP address in working memory only for a few minutes. Purpose: access to the test version you asked for. Legal basis: § 25(2) no. 2 TDDDG (strictly necessary for the service you requested) and Art. 6(1)(b) GDPR.
8. AI: classification, translation, briefs and Spot analysis
Classification: to keep war, violence, partisan politics and unsuitable material out of the programme, our server may send public texts (never data about you) to the AI model “Jev” (TypeSafe) via the Vercel AI Gateway: news headlines and teasers, encyclopedia snippets in the learning and kids areas, “on this day” events, names of nearby Wikipedia places, TV channel names with country, category and owner, and live-webcam stream titles. The model only returns probabilities (e.g. “conflict topic”, “suitable for children”, “clickbait”). We use them to hide additional items, to mark good news, to pick a children's age band and to rank clickbait lower; the model never releases anything our rules have blocked. If it is unavailable, our rule-based filters apply alone.
Translation: headlines in other languages are translated by the DeepL API (DeepL SE, Cologne, Germany), where set up, otherwise by a free language model via OpenRouter (see below) and, as a last resort, by a language model (Google Gemini, alternatively OpenAI GPT) via the Vercel AI Gateway. Only the public headline text is sent. Translated headlines are labelled “machine-translated” (Art. 50 EU AI Act).
Free AI models via OpenRouter: for translations, the “AI brief” under news headlines in the Studio (one or two sentences of background written from the headline alone – the outlet's teaser is never sent), the “AI quick facts” about a tapped place in the Explorer (picked from the introduction of the Wikipedia article) and, in kids mode, encyclopedia texts simplified for children together with suggested wrong quiz answers, our server sends public texts to OpenRouter (OpenRouter, Inc., USA), which passes them to a free language model (model providers currently include Google, Qwen/Alibaba Cloud, NVIDIA and Thinking Machines Lab; the current selection is shown at /api/ai-status). Only public content is sent – headlines (which can contain names of public figures), texts from Wikipedia or Klexikon and, for Spot, ad content as described in section 11 – never your IP address, your location, booking or contact data. Please note: according to OpenRouter's privacy policy, providers of free models may store inputs under their own terms and use them for training; OpenRouter itself states that it does not use inputs for training. We therefore first ask only endpoints that do not collect data (“data_collection: deny”) and use other free endpoints for public content only. According to OpenRouter's privacy policy, transfers to the USA are based on standard contractual clauses (Art. 46(2)(c) GDPR); we have not found a certification under the EU-US Data Privacy Framework. Legal basis, as far as personal data is involved at all: our legitimate interest in understandable, translated and child-friendly content (Art. 6(1)(f) GDPR). AI texts are labelled as such (“machine-translated”, “AI brief”, “AI quick facts”, “simplified by AI”; Art. 50 EU AI Act) and may contain mistakes; the numbers on our maps and panels are never written by an AI.
Cerebras (fast tier for text): the same text tasks as in the previous paragraph – text only, never pictures – may be sent by our server to Cerebras Inference (Cerebras Systems Inc., USA), if Groq (next paragraph) does not answer or its answer fails our checks. The same limits apply: only public content or, for Spot, ad texts with contact data removed; never your IP address, location, booking or contact data. If Cerebras does not answer or its quota is used up, OpenRouter takes over. Transfer to the USA: based on the provider's standard contractual clauses (Art. 46(2)(c) GDPR), where personal data is involved at all; legal basis as in the previous paragraph (Art. 6(1)(f) GDPR).
Groq (first tier for text and pictures, safety check): the same tasks as in the two previous paragraphs may first be sent by our server to GroqCloud (Groq LLC, USA; for customers in the EEA the contracting party is Groq UK Limited). The same limits apply: only public content or, for Spot, ad texts with contact data removed and the pictures of the ad that the advertiser uploaded or linked; never your IP address, location, booking or contact data. Groq also checks Spot ad texts and texts simplified for children with a safety model; its result can only add a warning or keep the original text, never remove a warning. According to Groq's terms, inputs and outputs are not used for training and are not retained by default. If Groq does not answer, its quota is used up or its answer fails our checks, Cerebras or OpenRouter take over. Transfer to the USA: based on the provider's standard contractual clauses (Art. 46(2)(c) GDPR), where personal data is involved at all; legal basis as in the previous paragraphs (Art. 6(1)(f) GDPR).
AI symbol pictures (image generation): for Spot ads, on the advertiser's request, and for calm background pictures of the screens, our server sends a short English picture description to an image model. It is written from public ad content only (industry, offer text, mood, time of day, weather) after e-mail addresses, phone numbers, IBANs, links and prices have been removed – never your IP address, location, booking or contact data, and never uploaded pictures. First tier: Cloudflare Workers AI (Cloudflare, Inc., USA) with the model FLUX.1 [schnell] (Black Forest Labs, licence Apache-2.0); if it does not answer, Pollinations (Myceli.AI OÜ, Tallinn, Estonia), which according to its terms may forward requests to further model providers; Google Gemini (Google LLC, USA) only if we switch it on separately. Before and after generation the description and the picture are checked by Groq's safety and vision models (paragraph above). The pictures are stored by us with Vercel Blob and are labelled “AI-generated illustrative image” on screen and in the file (Art. 50 EU AI Act). Transfer to the USA: based on the providers' standard contractual clauses (Art. 46(2)(c) GDPR), where personal data is involved at all; legal basis: our legitimate interest in illustrated ads and screens (Art. 6(1)(f) GDPR).
Music news (“AI one-liner”): in the “Bar & club” programme our server may send up to 20 public headlines of music media through the tiers named above (Groq, Cerebras, OpenRouter); the model picks suitable ones and writes a line of at most twelve words for each. It sees only the headline, never a teaser, never data about you. The line is labelled “AI one-liner” (Art. 50 EU AI Act); if the AI fails, the rule-based order applies. Legal basis, as far as personal data is involved at all (names of artists and public figures): Art. 6(1)(f) GDPR.
Providers: the Vercel AI Gateway (Vercel Inc., USA) forwards requests to the model providers (Anthropic PBC, Google, OpenAI, USA; TypeSafe). According to Vercel, the gateway does not retain prompts or outputs; according to Anthropic's commercial terms, inputs are not used to train models. OpenRouter: see the previous paragraph. For the Spot analysis, which may contain personal data, see section 11.
9. Kids mode, schools and businesses
Kids mode collects no data from children: there are no accounts, no input fields and no tracking; content comes from children's encyclopedias and is filtered twice. Institutions and businesses that show NEXEARTH on a screen decide which modules run and are themselves responsible for supervising children, for informing viewers and for licences for the public performance of radio and TV (e.g. GEMA, GVL, VG Media in Germany).
10. Live webcams, camera wall and webcam radio
Openly licensed cameras (marked “Publicly showable”): pictures from authorities, weather services, national parks and observatories whose licence allows public display. Your browser loads them only from our own server (/api/cams/img, section 4), which fetches the latest picture from the camera operator; the operator does not learn your IP address, and no cookies are set. The pictures are held in our server's working memory for a few minutes at most, never stored or archived, and shown uncropped with their source. These cameras therefore run without a consent click – they are the only ones the Studio's kiosk mode (public screens) shows. Exception: three live videos from Caltrans (California Department of Transportation) are streamed by your browser directly from Caltrans' server (wzmedia.dot.ca.gov, USA), which receives your IP address in the process; Caltrans sets no cookies there. Legal basis: our legitimate interest in showing live pictures of public places (Art. 6(1)(f) GDPR). Traffic cameras are wide shots at low resolution; we do not zoom in on people and remove cameras on which faces or number plates are recognisable.
YouTube: live webcams are embedded via YouTube in extended privacy mode (youtube-nocookie.com) of Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. Nothing is loaded from YouTube – not even a preview image – until you click “Load live picture”. Only then does your browser connect to YouTube/Google; your IP address and technical browser data are transmitted, YouTube may store cookies or similar identifiers on your device, and data may be transferred to Google LLC in the USA (certified under the EU-US Data Privacy Framework, Art. 45 GDPR). Legal basis: your consent by clicking (Art. 6(1)(a) GDPR, § 25(1) TDDDG); you can withdraw it at any time with effect for the future by leaving or reloading the page. Details: https://policies.google.com/privacy. YouTube webcams are intended for private viewing only: Spot screens and the Studio's kiosk mode leave them out. In the normal Studio they only appear after the operator has consented once per browser session; if the operator shows them publicly, the operator is responsible for the rights required (terms of use section 4).
Other webcams: webcams from Windy.com (Windyty SE, Czech Republic; only if the operator has set up a Windy key) and webcams streamed directly by their operators (HLS, except the openly licensed Caltrans videos above) are also loaded only after a click; with an HLS webcam your browser then connects to the operator's server, whose address is shown before the click. Some webcams are only linked; data flows only once you open the link.
Camera wall: in the Studio, the operator of a screen switches the webcam module or the camera wall on. For YouTube cameras on the camera wall, the operator consents once per browser session (openly licensed cameras need no consent, see above); this click is stored in sessionStorage (“nx-wall-consent”) until the tab is closed, and the players then load on that device without a further click. Saved walls stay on the device (“nx-camwall-presets”, section 7).
Radio from the webcam's area: the webcam panel and the camera wall can play a local station. The list of stations near the camera comes from Radio Browser through our server (section 4). Only after a click – on a station in the webcam panel, or the operator's start click on the camera wall for the tile chosen as the radio tile – does your browser connect directly to that station's streaming server, which receives your IP address (section 5).
Weather and snapshots: the weather shown at a webcam comes from MET Norway via our server, with the camera's coordinates rounded to about 1 km (section 4). A still image you save from a webcam is created in your browser and saved only on your device; it is not sent to us.
11. NEXEARTH Spot: booking ads, uploads and AI analysis
What is processed: when you book an ad on a Spot screen (via its QR code), you enter the ad content (texts, a link, optionally a photo) and optionally your name/company and an email address for the approval. In this demo version, the booking is stored only in your browser (localStorage key “nx-spot-bookings”) and is not transmitted to us (a chosen video clip is the one exception, see “Video ads”); screen settings stay on the device that shows them (“nx-spot-screens”). No payment data is collected.
Listing boost, notice board and “Who is advertising here?”: for a listing boost you paste the link to your own listing (e.g. Kleinanzeigen, eBay); our server reads title, picture and price from it like for any ad (see above). For private sales your name is not shown on the screen. On the notice board you enter a text and – voluntarily – a contact, which is shown on the screen at your express request; in this demo the post stays in your browser (“nx-spot-board”). The “Who is advertising here?” link carries the advertiser's name and provider details in the address; this address may appear in Vercel's server logs (section 2). Legal basis: Art. 6(1)(b) GDPR (post or booking), for showing a contact your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by deleting the post.
Video ads: if you choose a video for a booking, your browser opens the file itself (length, format, a still, colours) and first keeps it only on your device (IndexedDB “nx-spot-video”); the video file is not sent to us at that point. Only when you submit the booking and the server offers hosting does your browser cut out the booked part, re-encode it without an audio track and upload only that cut, through a short-lived address limited to that one file, into our non-public storage (Vercel Blob, Frankfurt region; Vercel Inc. as processor; for the transfer to the USA see section 2). The legal basis is the performance of your booking (Art. 6(1)(b) GDPR). The cut is played on the screens from a random, unguessable address on our domain, through our server. The video is deleted automatically after 90 days, earlier on request (contact in the imprint; please name the screen and the time of the booking); the delivery cache of our host may still serve a copy it has already fetched until that cache expires. To prevent abuse the server briefly counts uploads per address in working memory only; this count is not stored. If the upload fails, the video stays on your device. For the content check, a single still from the video – like an uploaded photo – goes to our server and is processed as described in this section and in section 8 (Groq, Cerebras, OpenRouter, Vercel AI Gateway; only the shrunk picture, no contact data); we do not store it. Whether a check succeeds does not change the approval by the screen's operator. The video runs on the screen without sound and without collecting any data about viewers. Please do not upload videos in which people can be recognised without their consent.
Analysis of links and photos: to build ad suggestions, the link, the text you typed and – if uploaded – the photo (shrunk in your browser beforehand) are sent to our server (/api/spot/ingest, hosted by Vercel, section 2). Our server fetches the linked page itself (your IP address is not forwarded) and reads its public data (title, description, Open Graph, schema.org, pictures). Uploaded photos are processed in memory only and not stored by us. Legal basis: Art. 6(1)(b) GDPR (steps prior to a contract at your request) and Art. 6(1)(f) GDPR (legitimate interest in checking ads for public space).
AI via Groq: if set up, the content (page text with e-mail addresses, phone numbers and IBANs removed and, where present, the ad's picture, shrunk beforehand) is first sent to a language/vision model at GroqCloud (Groq LLC, USA; section 8), and the ad text is checked by Groq's safety model; your booking and contact details are never sent. According to Groq's terms, inputs are not used for training and are not retained by default. Safety notes from Groq can only add warnings, never remove one. If Groq does not answer, Cerebras (text only) or OpenRouter take over.
AI via OpenRouter: if set up, the content is sent to a free language/vision model via OpenRouter (OpenRouter, Inc., USA; section 8) – and only to endpoints whose providers, according to OpenRouter, neither store inputs nor use them for training (“data_collection: deny”); if no such endpoint answers, OpenRouter passes the content to no model. Before that, our server removes e-mail addresses, phone numbers and IBANs from the page text; your booking and contact details are never sent. OpenRouter offers a data processing agreement only to enterprise customers; transfers to the USA are based on standard contractual clauses according to OpenRouter. Safety notes from the model can only add warnings, never remove one.
AI via the Vercel AI Gateway: if available, the content is additionally sent through the Vercel AI Gateway to a language/vision model (Anthropic Claude; Anthropic PBC, San Francisco, USA) and to the Jev classification model (TypeSafe) to understand what the ad is about, suggest headline, colours and formats and check it against the content rules (e.g. political, adult or gambling content). Vercel acts as our processor, Anthropic as Vercel's sub-processor. Transfers to the USA are based on the EU-US Data Privacy Framework (Vercel) and on standard contractual clauses (Art. 46(2)(c) GDPR; Anthropic is not certified under the Data Privacy Framework). According to the providers' terms, the gateway does not retain inputs and they are not used for model training. Please do not upload pictures showing identifiable people without their consent.
No automated decision: texts suggested by the AI are marked as such (Art. 50 EU AI Act) and can be changed before sending. By default the screen operator approves every ad personally. The operator can switch approval off; ads in which the automatic rule check finds nothing then go on air immediately. Ads with a finding are never rejected automatically but wait for the operator's decision, and the operator can stop any running ad at any time. There is therefore no rejection based solely on automated processing within the meaning of Art. 22 GDPR.
Storage period: demo bookings remain in your browser until you or the operator delete them (“Delete booking”) or you clear your browser data; a hosted video clip (see “Video ads”) is the exception and is deleted after 90 days at the latest. Before a live version with contracts and payments starts, this section will be completed (including storage for the duration of the booking and the statutory retention periods under § 257 HGB, § 147 AO).
Screens in shops: a Spot screen has no camera, no microphone and counts no viewers. The QR code only contains the address of the booking page for that screen.
12. Contact by email
If you email us, we process your email address, the content of your message and any details you provide in order to answer you. Legal basis: Art. 6(1)(b) GDPR where your message relates to a contract or steps prior to one, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries); for notices of illegal content also Art. 6(1)(c) GDPR in conjunction with Art. 16 DSA. We delete the correspondence once it is no longer needed, unless statutory retention periods apply. Our mailbox is provided by Apple (iCloud Mail).
12a. Applying for Gemeinwohl ads by email
When an organisation applies by email for a free Gemeinwohl ad (/gemeinwohl), we process the content of the email and its attachments: the contact person's name and contact details, details of the organisation, proof of charitable status, the ad's texts, images and links, region and period. Purpose: reviewing the application, coordinating with you, creating and showing the ad. Legal basis: Art. 6(1)(b) GDPR (steps towards and performance of the free-of-charge agreement to show the ad), or Art. 6(1)(f) GDPR (legitimate interest in reviewing charitable requests) where the contact person is not a party themselves.
There is no form; the application is stored only in our mailbox (Apple iCloud Mail, section 12), not on NEXEARTH's servers. Please do not send health data or other special categories of data (Art. 9 GDPR); any we receive unasked we delete. Images of people are used only with their consent, which the organisation obtains and confirms to us.
Only the content of an accepted ad (organisation name, text, link, region) becomes public – on the screens and via “Who is advertising here?”. Contact details never appear on screen. Rejected applications are deleted after 6 months, accepted ones 6 months after the ad stops showing, unless a statutory retention duty applies. Your rights under section 14 are unaffected.
13. Recipients and storage periods at a glance
Recipients are only the providers named above: Vercel (hosting, AI Gateway), Anthropic, Google, OpenAI, TypeSafe, DeepL, Groq, Cerebras, OpenRouter and the providers of the free models it forwards to (AI and translation; public texts or Spot content only), Cloudflare and Pollinations (Myceli.AI OÜ) for AI symbol pictures (picture descriptions from public ad content only), Apple (email) and – for the direct connections in sections 5 and 10 – the providers whose function you use. We do not sell data and do not pass it on for advertising. Storage periods: server logs according to Vercel's short retention periods; abuse protection one minute in working memory; proof-of-play daily figures of paired screens 13 months (section 7c); uploads and AI analyses in Spot are not stored by us, except video clips you book (at most 90 days, section 11, in Vercel Blob, Frankfurt); AI symbol pictures and their picture description stay in our Vercel Blob store so the same request is not generated again (they contain no personal data); data in your browser until you delete it; emails as described in section 12.
14. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw a consent at any time with effect for the future (Art. 7(3) GDPR). An email to the address above is sufficient to exercise your rights.
Right to object (Art. 21 GDPR): where we process data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
Right to lodge a complaint (Art. 77 GDPR): you can complain to a data protection supervisory authority, in particular in the member state of your residence or of the alleged infringement. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, https://www.lda.bayern.de.
15. Automated decisions, data protection officer, security
There is no automated decision-making including profiling within the meaning of Art. 22 GDPR (see sections 8 and 11). We have not appointed a data protection officer because there is no legal obligation to do so (Art. 37 GDPR, § 38 BDSG). All connections to NEXEARTH are encrypted (TLS/HTTPS).
16. Changes
Planned TV apps: we plan dedicated apps for Apple TV, Fire TV and Google TV. They do not exist yet; NEXEARTH runs only in the browser, and this policy applies to every device on which you open the website. Before an app is released, we will add here which data it and the respective app store process. We update this privacy policy when the website or the legal situation changes. The current version is always available here.