Zum Inhalt springen

Trust & security

What NEXEARTH stores, where it lives and which rules apply. Only what can be checked in the code or at the website itself is listed here. NEXEARTH is an open preview without accounts or payments; the name is a working title.

As of: 28.09.2026

At a glance

  • No account, no sign-in.
  • No own cookies, no third-party analytics or tracking tools; only our own count without identifier.
  • No camera: the browser is not even allowed to switch it on for this website.
  • Settings and demo bookings stay in your browser – only a paired screen keeps its settings with us.
  • AI only receives public texts – never data about you.

What data exists – and where it lives

WhatWhereHow long
Studio and Explorer settingsonly in your browser (localStorage)How long: until you delete them
Spot demo bookings and noticesonly in your browser – none of it is sent to usHow long: until you or the operator delete them
Technical access data (IP address, time, address, browser)server logs of our host VercelHow long: briefly, per Vercel's retention periods
Abuse counters (requests per IP address)only in the server's memoryHow long: usually a few minutes
Shared cache: translations of public headlines, the world map's learning stateprivate Vercel Blob store in Frankfurt (fra1) – no data about visitorsHow long: until the next update
Paired screen (/tv, /koppeln): studio settings without PIN, random device ID, hashes, last seen and running programprivate Vercel Blob store in Frankfurt (fra1) – no name, no email, no IP address; name and edit key only on your phoneHow long: until you remove the device; the pairing code expires after 15 minutes
Proof of play (Spot): screen ID, time, ad on air, covered minutes and plays per day – nothing about viewerspaired screens: private Vercel Blob store in Frankfurt (fra1), no IP address; demo in working memory onlyHow long: 13 months (billing), demo only briefly

The website is hosted by Vercel Inc. (USA) and delivered through its worldwide network. The server functions currently run in Vercel's Washington, D.C. region (iad1) – the response header “x-vercel-id” shows it. Transfers to the USA rely on the EU-US Data Privacy Framework and, in addition, standard contractual clauses.

The privacy policy lists every storage key and service.

What there is not

Cookies
NEXEARTH sets none of its own. Only when you start a live webcam with a click can YouTube (in privacy-enhanced mode) set cookies.
Tracking
No third-party analytics, advertising or tracking tools, no profiles, no ad network; only our own count of the steps reached, without cookies, identifier or storing the IP address.
Camera
No face recognition, no audience measurement. The rule “Permissions-Policy: camera=()” blocks the camera for the whole website.
Microphone
Only in the Bar & club program and only when the operator switches on “React to the room”. Sound becomes loudness and frequency values on the device; nothing is recorded or sent.

AI – what for and with which data

Classification and filters
Public texts such as headlines go to a classification model that additionally detects war, violence and unsuitable content. It can sort out more, but never release anything our rules have blocked.
Translation
Only the public text of a headline is translated; translated headlines are labelled “machine-translated”.
Ads in Spot
Before ad text reaches an AI, our server removes email addresses, phone numbers and IBANs. Booking and contact data are never sent. AI suggestions are labelled and editable; nothing is ever rejected automatically.

Providers and legal bases: privacy policy, sections 8 and 11.

Security rules in the browser

Every page sends these headers. Check for yourself: in the browser's developer tools under “Network”, or with curl -I https://www.nexearth.de

HeaderWhat it does
Content-Security-Policyscript-src 'self' 'unsafe-inline'; object-src 'none'; form-action 'self'; base-uri 'self'; frame-ancestors 'self' …Scripts only from our own address (plus inline scripts for now, see “What is still missing”), no plugins, forms only to us. Enforced since 27.09.2026.
Strict-Transport-Securitymax-age=63072000; includeSubDomainsEncrypted connections (HTTPS) only, for two years, including subdomains.
X-Frame-OptionsSAMEORIGINNo embedding in other sites – protection against clickjacking (plus “frame-ancestors 'self'” in the CSP).
X-Content-Type-OptionsnosniffThe browser does not guess file types we have not declared.
Referrer-Policystrict-origin-when-cross-originWhen you follow a link, other websites see only our domain, not the full address.
Permissions-Policycamera=(), payment=(), usb=(), bluetooth=(), display-capture=(), geolocation=(self), microphone=(self) …Camera, payment, USB, Bluetooth and screen capture are off; location and microphone at most for this website itself and only after you allow it.
Cross-Origin-Opener-Policysame-originSeparates our page from windows opened by other websites.

Also: no public source maps, no “X-Powered-By” header.

Rules for advertising (Spot)

Political advertising, gambling, weapons, tobacco and adult content are excluded; health and alcohol get extra rules per industry. The rule check always runs, also without AI – the AI can only add further warnings. By default the operator approves every ad and can stop any running ad at once.

Booking terms (draft, not yet in force)

Found a security issue?

Write to a.joltea@me.com – in German or English. Please describe how to reproduce the problem, and publish details only once it is fixed.

There is no bug bounty and we do not promise a fixed response time – we will get back to you as soon as we can.

Machine-readable: /.well-known/security.txt

What is still missing

Listed honestly – so you know what you can rely on today and what not yet.

  • No certification (such as ISO 27001 or SOC 2) and no promised availability.
  • No public status page.
  • The server functions run in the USA (iad1), not in the EU; only the cache is in Frankfurt.
  • The script rule still allows inline scripts (“'unsafe-inline'”) until Next.js is set up with nonces.
  • No accounts and no contracts – so no roles, logs or billing yet either.
  • Smart TV browsers are not yet tested on real hardware. Device list