1. Who is responsible for your data
Abrum UG (haftungsbeschränkt) in Gründung (in formation), Hauptstraße 27, 55278 Friesenheim, Germany, is responsible for your ABRUM account, the operation of our services and handling your data protection requests. You can contact us at hello@abrum.ai.
Hue Ventures GmbH, Hauptstraße 27, 55278 Friesenheim, Germany, handles only the commercial processing as the seller and invoice issuer. It is independently responsible for processing order, payment and invoice data for these purposes and retaining them as required by law. You can contact it at info@hueventures.de. ABRUM remains your central contact for data protection requests and coordinates billing-related matters with Hue Ventures.
2. Your content stays under your control
ABRUM Station runs locally on your devices. The software processes and stores your working content there, such as documents, conversations and work results. ABRUM does not provide a central storage service for this local working content. Local processing by the software is not the same as processing that content by the company ABRUM.
You control the local use and sharing of your content. When you link Stations or share rooms, shared content may also be stored on other participating users' devices. ABRUM provides the software for this; that alone does not make ABRUM responsible for your choice of content and recipients.
“On your Station” therefore does not automatically mean “only on this one device”. If you end a share, this cannot recall copies already received by a recipient. Deleting a local view does not necessarily remove copies that have already been transferred either.
Connections to operated services need to be considered separately from local storage. Examples include sign-in, billing and AI requests from functions you use or automations you set up. The following sections describe these processes; they do not turn the local Station into cloud storage operated by ABRUM.
When sharing, the software uses direct connections and, where necessary, an intermediary service (relay). Transferred content is encrypted between the endpoints. The relay cannot read application content and does not keep a collection of files for later retrieval; it forwards data packets using limited in-memory buffers. In doing so, it processes technical endpoint identifiers and routing information. The native Station also uses an external address directory service from Number 0 (n0/Iroh). Depending on the client and configuration, public Iroh relays may be used instead of the ABRUM relay.
Technical operational and error logs are generated to operate and secure the connection service. These are distinct from your stored content. We describe their retention separately in section 9.
3. Account and contract data
We process your ABRUM ID, linked wallet addresses, public keys and information about your configured sign-in methods and connected devices. These data are used to manage your account, verify your access rights and protect against unauthorised access.
Sign-in data include technical identifiers, authorisation status and timestamps. For active sessions, we store a verification value derived from the session key, its association with your account and, where applicable, device, and the expiry time.
To document our contractual relationship, we store your declarations regarding the terms of use, together with the relevant document version, account and device references and timestamps, in a signed record stored in encrypted form. A copy, including our acknowledgement of receipt, is also stored on your Station.
4. What happens during an AI request
When you use an AI function, the Station sends the inputs assembled for the request and the attached context to the configured AI endpoint. This may include text, conversation excerpts, document content, tool descriptions and results from connected tools. It is therefore not always just the last sentence you entered. An automation you set up can also trigger these requests. When you use relevant voice and meeting functions, voice data and transcripts may also be processed and stored in participating rooms.
For a request through the ABRUM AI gateway, the request content passes through our server. The server forwards it to the AI provider configured for the model and returns the provider's response. In doing so, the gateway processes the content in readable form in working memory. Unlike encrypted file transport through the relay, the gateway is not a content-blind intermediary here. The reviewed gateway billing path does not store complete inputs or responses as a conversation archive; this is not a promise that no parts of the content are stored by any participating service or in any error situation.
For usage records, however, we store the association with your access account, the model and provider route used, request identifiers, timestamps and status information, usage quantities, costs and the remaining budget. These data enable billing and limit usage to your purchased allowance.
Section 8 describes the participating AI providers, processing locations and possible fallback routes.
The information above describes the current AI data flows. We describe planned local AI operation separately in the outlook under “Service providers and data recipients”.
5. Purchases, subscriptions and invoices
For paid services, we process your name, email address, billing address and, where applicable, tax identifiers. We also process information about your order, selected plan, payments, subscription periods, cancellations and refunds. These data are used to fulfil your purchase, manage your subscription, assign your entitlement to use the service and issue invoices.
The seller and invoice issuer is Hue Ventures GmbH. Payments are processed through Stripe, which processes the information required for your chosen payment method. Order and billing data, as well as issued invoices, are also stored in the ABRUM application.
When invoices are sent through Resend, your email address, the message text and the invoice attachment are sent to the email delivery service. Activation messages contain the information needed to associate your licence and are sent through the configured email service.
6. Wallets and blockchain
For wallet payments, we process the association with your account, wallet addresses, recipients, amounts and digital signatures. We store payment instructions, technical transaction identifiers and status information in the ABRUM application. These data are used to prepare payments, verify their authorisation, submit them to the network and track their processing status.
The transaction data required for a payment are sent to the integrated blockchain service providers, in some cases already during preparation. Confirmed payments on the Base network are publicly traceable through sender and recipient addresses, amounts and timestamps. Wallet addresses can be linked to an individual when combined with other information. ABRUM cannot subsequently remove these public entries. Your rights regarding the data stored by us are unaffected.
For recurring wallet payments, we also store the payment authorisation you grant, including the amount, interval, validity and signature, as well as information about completed debits. Payments can be executed automatically within the scope of that authorisation.
7. Operations, security and technical storage
When you connect to our services, we process technical information about the connection and the handling of your request. Depending on the service, this includes IP addresses, requested service URLs, request identifiers, timestamps and status information, and error and diagnostic data. We use this information to provide the services, detect and resolve faults, and prevent unauthorised access and abuse.
To keep you signed in in your browser, we store a technically necessary sign-in cookie there. It associates your requests with your session. To protect the purchase process and the sending of activation messages, we also use verification values derived from IP or email addresses to limit repeated requests.
Operational and error logs are stored on our servers. Errors from external AI services may also result in parts of the provider's error message being included in these logs. Section 9 describes the retention of technical data.
Visiting our website
When you visit our website, the technical connection and security data described in this section are processed. We use them to provide and protect the website reliably, based on our legitimate interest under Article 6(1)(f) GDPR. Fonts and images are served through our website.
We store your selected language in a cookie for up to one year. Your website analytics choice is stored in your browser's local storage until you change it or clear that storage. These settings allow us to respect your choices; they do not constitute consent to this privacy notice. Where storage is strictly necessary for these functions you have selected, section 25(2), point 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) applies.
Signing up for launch updates
If you sign up on our website for news about the ABRUM launch, we process your email address, the signup time, form source, selected language and transmitted IP address. The information is stored in application logs and, where available, in a local signup list. We use it to manage your signup and inform you about the ABRUM launch. The legal basis is your consent under Article 6(1)(a) GDPR.
We use Resend to send the confirmation and internal notification of your signup. Your email address and the respective message contents are transmitted to the delivery service; the internal message also includes the form source, language and signup time. The information about the provider and international transfers in section 8 also applies here.
You can withdraw this consent at any time by contacting hello@abrum.ai. We delete signup data when the purpose no longer applies or you withdraw consent, unless statutory retention obligations or necessary record-keeping requirements apply. The periods in section 9 also apply to technical logs.
Optional website analytics
With your separate consent, we use the self-hosted service Umami at analytics.abrum.ai. It helps us understand website use in aggregate form, such as page views, referring websites, browsers, operating systems, device types and countries of origin. Umami does not set analytics cookies. IP addresses are processed to derive technical metrics but are not stored as IP addresses in the analytics data. Analysis takes place on our own infrastructure.
Where additionally configured, we load Google Analytics 4, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, following the same consent. This may involve analytics cookies and information about page views, interactions, browser, device and approximate location. Data may also be processed by Google in the United States. Further information is available in Google's privacy policy.
The legal basis for analytics is Article 6(1)(a) GDPR; where information is stored on or accessed from your device, section 25(1) TDDDG also applies. Without your consent, we do not load analytics code. You can change your choice and withdraw consent at any time through “Analytics settings” at the bottom of the website. Withdrawal does not affect the lawfulness of processing before withdrawal. The website can also be used without consenting to analytics.
8. Purposes, legal bases and recipients
The legal bases for processing
We process the personal data necessary to perform your contract. This includes, in particular, managing your account and access entitlement, providing purchased services, billing for usage and handling contract-related support requests. Requests you make in preparation for entering into a contract are also covered. The legal basis is Article 6(1)(b) GDPR; it applies when you are, or wish to become, a party to the contract yourself.
To protect our services against unauthorised access and abuse, we process the necessary technical connection and security data. We handle general questions and suggestions for improvement to respond to your concern or assess the improvement you suggest. We may also retain necessary contract and case records to establish or defend legal claims. For these purposes, we rely on legitimate interests under Article 6(1)(f) GDPR. In each case, the processing must be necessary and must not be overridden by your interests and fundamental rights. You can find your right to object in the section “Your rights”.
Where we must process data to fulfil your data protection rights, the legal basis is Article 6(1)(c), together with Articles 12 to 22 GDPR. For the legally required retention of invoices, Hue Ventures GmbH, as the invoice issuer, processes the relevant data under Article 6(1)(c) GDPR in conjunction with section 14b of the German Value Added Tax Act (UStG).
Service providers and data recipients
We use external infrastructure and specialist providers to operate our services. The data they receive depend on the relevant function:
- Hosting: We use the server and network infrastructure of Hetzner Online GmbH, based in Germany, to operate our services. The data required for each service are processed there as described in this privacy notice.
- Payments: Stripe processes the payment, contact and billing details required for the selected payment method, along with order and transaction data. Stripe acts as a processor for payment processing; for certain purposes of its own, particularly fraud prevention and compliance with statutory verification obligations, it acts as an independent controller. Data are also transferred to Stripe, LLC in the United States. Further information about this processing is available in Stripe's privacy policy.
- Email delivery: For delivery through Resend, we use the service provided by Plus Five Five, Inc., United States. The provider receives the recipient address, message content and technical information required for delivery. Invoice messages also include the invoice as a PDF attachment. Resend processes and stores these data in the United States; selecting a European sending region does not change the storage location. Activation messages may alternatively be sent through the configured SMTP service.
- Connection services: To enable Stations to discover and connect to one another, the software uses the Iroh address directory service operated by N0, Inc. (Number 0). It processes technical Station identifiers and their associated relay addresses. Depending on the application and configuration, public Iroh relays operated by this provider are also used. This involves technical connection data such as IP addresses, connection times and the volume of data transferred. Content transmitted through the relay is encrypted between the participating Stations and cannot be read by the relay operator.
- Wallet payments: The integrated blockchain infrastructure services receive the transaction data required for preparation and submission. Confirmed transactions are processed on the public network.
AI functions: providers and processing locations
We use OpenRouter, Nebius and IONOS for AI requests through the ABRUM gateway. The service processing your request depends on the model you select and the connection route configured for it. The service receives the assembled inputs and context to process your request. OpenRouter routes requests to the respective AI model operators.
Depending on the connection route, data may be processed within or outside the European Union. This applies both to routing a request and to its processing by the AI model. Operating a model in an EU data centre therefore does not automatically mean that the entire connection route is restricted to the EU. Where fallback routes are configured, another provider may receive the same request if a service is disrupted.
Planned: local AI on your device or your own infrastructure
For a future version, we are planning offline AI that runs on your device or within your own infrastructure. The goal: your inputs, the context used and the responses stay where you work – with you.
With this fully local AI operation, the transfer to external AI providers described under “AI functions” would no longer take place; the ABRUM AI gateway would not be involved either. This requires that no external AI services or online tools are integrated. The described data flows remain unchanged for online functions you continue to use, such as your account, payments or sharing outside your own network.
Processing outside the European Economic Area
When you use our services, personal data may also be processed outside the European Economic Area. The data involved and the providers receiving them depend on the relevant function.
Additional data protection requirements apply to these transfers. We rely on an adequacy decision of the European Commission applicable to the recipient or on appropriate safeguards, in particular the EU Standard Contractual Clauses. Where necessary, supplementary protective measures are added. You can obtain information about the safeguards used and a copy through our data protection contact.
9. How long data are kept
We do not set a central ABRUM retention period for working content stored exclusively on users' devices: ABRUM does not manage a server-side store of that content. A request to delete your ABRUM account is not automatically an instruction to destroy your local documents or copies held by other users. Local deletion and sharing functions are distinct from deleting data held in systems operated by ABRUM.
Account, contract and usage data
We store your account and access entitlement data for as long as you use your account and the information is needed to operate it. When you close your account, we delete the data no longer needed for this purpose. Cancelling a paid subscription alone does not close your account.
We need usage information for billing and to resolve billing questions. Afterwards, we retain only the information required by law or necessary to establish or defend legal claims. The same applies to records of your contractual relationship and the terms of use you have accepted.
Where records are necessary for potential claims, we retain them until the applicable limitation period expires. This is generally three years. It generally starts at the end of the year in which the claim arose and the relevant circumstances and the other party were known or should have been known. Special statutory provisions or ongoing litigation may require longer retention. Once the reason for retention no longer applies, we delete the data concerned.
For invoices, the company subject to the retention obligation is generally required by law to keep them for eight years from the end of the year in which they were issued. Statutorily required extensions remain possible. This obligation applies regardless of whether your subscription is still active.
Operational and error data
We delete technical error and security logs that can be associated with an individual or device as soon as they are no longer required for error analysis or the protection of our services, and no later than seven days after they are recorded. We limit these logs to the information needed for those purposes.
To identify recurring faults and changes in load, we store aggregated technical operational metrics for no more than 30 days from each measurement. These include, for example, error frequencies and response times per service. These evaluations contain neither working content nor IP addresses, account, wallet or device identifiers and are not used to create personal usage profiles. They are automatically deleted when the period expires.
Where there are concrete indications of a security incident, we may separately retain the log excerpts needed for that incident for longer. We restrict access to the people handling the incident, document the reason and review at least every 30 days whether storage remains necessary. As soon as the preservation purpose no longer applies, we delete those excerpts.
Help and feedback
We process the information in reports you submit through “Help & Feedback” to answer questions, handle reported problems and receive feedback. This includes the category and content of your report, together with the basic diagnostic data you choose to send: product version, where applicable the public identifier of the software revision, operating system family and processor architecture.
The report is stored in encrypted form in our access-controlled support system. To handle it, we also record a case number, receipt time, status and, where applicable, our response and the time the case was closed. You receive the response through your Station; an email address is not required.
The handling and retrieval period ends 90 days after receipt or 30 days after the case is closed, whichever is earlier. After that, the case can no longer be retrieved and is automatically deleted from the active support database together with its associated notification job. Deletion is performed by the regularly scheduled cleanup.
Our support team receives only an email notification that a new report has arrived. The report content and diagnostic data are not forwarded by email.
Backups
Backups of the services we operate are used to restore data after a technical failure. They are not an additional storage service for working content stored exclusively on your local devices.
After deletion from the live system, affected data may remain temporarily in existing backups. These copies are kept outside live operations. The affected data are removed from them no later than 45 days after deletion from the live system. Where shorter maximum periods apply to particular data, those periods remain applicable. The remaining data are not reused for other purposes.
If we restore a backup, we take account of deletions made in the meantime before the data are used in live operations again.
10. Your rights
You can request information about the personal data we process about you and receive a copy of those data. You can have inaccurate information corrected and incomplete information completed. Subject to the applicable legal conditions, you can also request deletion of your data or restriction of their processing.
Subject to the applicable legal conditions, you have the right to receive the data you have provided in a commonly used, machine-readable format and to have them transferred to another provider.
Your right to object: Where we process data on the basis of legitimate interests, you can object to that processing at any time on grounds relating to your particular situation.
To exercise your rights, you can contact hello@abrum.ai. Requests are generally handled free of charge. You will generally receive a response within one month of receipt of your request. If an extension permitted by law is necessary, we will inform you within that month of the reasons and the extended period.
If we are legally required to retain certain data, we cannot yet delete them. We will explain which data are affected and why.
If you suspect a data protection infringement, you can lodge a complaint with a data protection supervisory authority, in particular in the place of your habitual residence, place of work or the alleged infringement. For our registered office in Rhineland-Palatinate, the competent authority is the State Commissioner for Data Protection and Freedom of Information of Rhineland-Palatinate. You do not have to contact us first.
11. Changes to this privacy notice
We keep this privacy notice up to date. You can identify the version by its stated date.
If the processing of your data changes, we will inform you in good time before the change takes effect. For significant changes, we will expressly draw your attention to them and explain what changes for you and when. Examples include new processing purposes, additional recipients or changes to retention periods.
Document reference
bafyreicwmysiy4tyxdb5h4jviqhhhofwwtwt6qb3c5dx4blymiypjfjot4