Trust & security
What NEXEARTH stores, where it lives and which rules apply. Only what can be checked in the code or at the website itself is listed here. NEXEARTH is an open preview without accounts or payments; the name is a working title.
As of: 28.09.2026
At a glance
- No account, no sign-in.
- No own cookies, no third-party analytics or tracking tools; only our own count without identifier.
- No camera: the browser is not even allowed to switch it on for this website.
- Settings and demo bookings stay in your browser – only a paired screen keeps its settings with us.
- AI only receives public texts – never data about you.
What data exists – and where it lives
| What | Where | How long |
|---|---|---|
| Studio and Explorer settings | only in your browser (localStorage) | How long: until you delete them |
| Spot demo bookings and notices | only in your browser – none of it is sent to us | How long: until you or the operator delete them |
| Technical access data (IP address, time, address, browser) | server logs of our host Vercel | How long: briefly, per Vercel's retention periods |
| Abuse counters (requests per IP address) | only in the server's memory | How long: usually a few minutes |
| Shared cache: translations of public headlines, the world map's learning state | private Vercel Blob store in Frankfurt (fra1) – no data about visitors | How long: until the next update |
| Paired screen (/tv, /koppeln): studio settings without PIN, random device ID, hashes, last seen and running program | private Vercel Blob store in Frankfurt (fra1) – no name, no email, no IP address; name and edit key only on your phone | How long: until you remove the device; the pairing code expires after 15 minutes |
| Proof of play (Spot): screen ID, time, ad on air, covered minutes and plays per day – nothing about viewers | paired screens: private Vercel Blob store in Frankfurt (fra1), no IP address; demo in working memory only | How long: 13 months (billing), demo only briefly |
The website is hosted by Vercel Inc. (USA) and delivered through its worldwide network. The server functions currently run in Vercel's Washington, D.C. region (iad1) – the response header “x-vercel-id” shows it. Transfers to the USA rely on the EU-US Data Privacy Framework and, in addition, standard contractual clauses.
What there is not
- Cookies
- NEXEARTH sets none of its own. Only when you start a live webcam with a click can YouTube (in privacy-enhanced mode) set cookies.
- Tracking
- No third-party analytics, advertising or tracking tools, no profiles, no ad network; only our own count of the steps reached, without cookies, identifier or storing the IP address.
- Camera
- No face recognition, no audience measurement. The rule “Permissions-Policy: camera=()” blocks the camera for the whole website.
- Microphone
- Only in the Bar & club program and only when the operator switches on “React to the room”. Sound becomes loudness and frequency values on the device; nothing is recorded or sent.
AI – what for and with which data
- Classification and filters
- Public texts such as headlines go to a classification model that additionally detects war, violence and unsuitable content. It can sort out more, but never release anything our rules have blocked.
- Translation
- Only the public text of a headline is translated; translated headlines are labelled “machine-translated”.
- Ads in Spot
- Before ad text reaches an AI, our server removes email addresses, phone numbers and IBANs. Booking and contact data are never sent. AI suggestions are labelled and editable; nothing is ever rejected automatically.
Providers and legal bases: privacy policy, sections 8 and 11.
Security rules in the browser
Every page sends these headers. Check for yourself: in the browser's developer tools under “Network”, or with curl -I https://www.nexearth.de
| Header | What it does |
|---|---|
Content-Security-Policyscript-src 'self' 'unsafe-inline'; object-src 'none'; form-action 'self'; base-uri 'self'; frame-ancestors 'self' … | Scripts only from our own address (plus inline scripts for now, see “What is still missing”), no plugins, forms only to us. Enforced since 27.09.2026. |
Strict-Transport-Securitymax-age=63072000; includeSubDomains | Encrypted connections (HTTPS) only, for two years, including subdomains. |
X-Frame-OptionsSAMEORIGIN | No embedding in other sites – protection against clickjacking (plus “frame-ancestors 'self'” in the CSP). |
X-Content-Type-Optionsnosniff | The browser does not guess file types we have not declared. |
Referrer-Policystrict-origin-when-cross-origin | When you follow a link, other websites see only our domain, not the full address. |
Permissions-Policycamera=(), payment=(), usb=(), bluetooth=(), display-capture=(), geolocation=(self), microphone=(self) … | Camera, payment, USB, Bluetooth and screen capture are off; location and microphone at most for this website itself and only after you allow it. |
Cross-Origin-Opener-Policysame-origin | Separates our page from windows opened by other websites. |
Also: no public source maps, no “X-Powered-By” header.
Rules for advertising (Spot)
Political advertising, gambling, weapons, tobacco and adult content are excluded; health and alcohol get extra rules per industry. The rule check always runs, also without AI – the AI can only add further warnings. By default the operator approves every ad and can stop any running ad at once.
Found a security issue?
Write to a.joltea@me.com – in German or English. Please describe how to reproduce the problem, and publish details only once it is fixed.
There is no bug bounty and we do not promise a fixed response time – we will get back to you as soon as we can.
Machine-readable: /.well-known/security.txt
What is still missing
Listed honestly – so you know what you can rely on today and what not yet.
- No certification (such as ISO 27001 or SOC 2) and no promised availability.
- No public status page.
- The server functions run in the USA (iad1), not in the EU; only the cache is in Frankfurt.
- The script rule still allows inline scripts (“'unsafe-inline'”) until Next.js is set up with nonces.
- No accounts and no contracts – so no roles, logs or billing yet either.
- Smart TV browsers are not yet tested on real hardware. Device list