Privacy policy
Version: 28 July 2026
This is a courtesy translation for readers who do not speak German. Only the German version is legally binding. Where the two texts differ, the German wording prevails. Article references are to the EU General Data Protection Regulation (GDPR); DDG, MStV and TDDDG are German acts.
1. Controller
iMild LLC
2648 International Blvd Ste 301 #285
Oakland, CA 94601
USA
Email: s@smejj.com
2. Overview
smejj.com is deliberately built to collect as little data as possible. No analytics or tracking services are used, no advertising is shown, and no data is processed for marketing purposes. Project data, settings and working data are stored locally in your browser wherever possible (IndexedDB/OPFS) and do not leave your device unless you switch on a sync feature.
3. Hosting (GitHub Pages)
This website is delivered via GitHub Pages, a service of GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. When you open the site, GitHub processes technically necessary connection data (e.g. your IP address) in order to provide and secure the service.
Further information: GitHub privacy statement.
4. Signing in with Google (Google Sign-In)
Google Sign-In, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is used for logging in. When you sign in, smejj.com receives a signed ID token from Google containing your email address and your name. This data is used solely for authentication. The legal basis is Art. 6(1)(b) GDPR (providing the user account). Further information: Google privacy policy.
5. Cookies and session data
smejj.com does not set any cookies. After a successful login, an access token is stored in your browser's local storage (localStorage) and secures your session; it is used solely for requests to our own services and is removed when you log out. No tracking takes place. This local storage is technically necessary for signed-in operation, so no consent is required for it (section 25(2) no. 2 TDDDG). For that reason no cookie banner is shown.
6. Local storage in the browser
Projects, files, settings and notes are stored locally in your browser (IndexedDB/OPFS). This data stays on your device and is not transmitted to us. You can delete it at any time in the app or through your browser settings.
7. Your own API keys (BYOK)
If you store your own API keys for AI services (Bring Your Own Key), they are kept locally in your browser and used directly for requests to the provider you have chosen. Your keys are not transmitted to us. The privacy policy of the AI provider you have chosen applies to that provider's processing of your data.
8. Cloud storage (IDrive e2)
If sync or storage features are enabled, project data is stored in an S3-compatible object store (IDrive e2). Access is exclusively via short-lived signed URLs. The legal basis is Art. 6(1)(b) GDPR. Further information: IDrive privacy notice.
9. Server infrastructure (Zeabur and Salad)
When you use signed-in features (chat, voice mode, coding jobs, account management), our own services process your requests on rented infrastructure:
Zeabur (Zeabur Pte. Ltd.) runs the chat and voice bridge of smejj.com on a permanently rented server (Tencent Cloud infrastructure, located in the USA). The contents of your chat and voice requests are processed, together with technically necessary connection data.
Salad Technologies, Inc. (USA) runs the control server (login, account data retrieval, job management) and, for coding jobs, short-lived stateless compute nodes that are shut down once the task is finished. Request contents, job data and technically necessary connection data are processed.
To generate AI responses, these services transmit the contents of the respective request to the connected inference provider of the model you selected; where you use your own API keys (BYOK), section 7 applies. The legal basis for all of this is Art. 6(1)(b) GDPR (providing the feature you requested). Some of this processing takes place in the USA.
10. Training data for smejj 1.0 (only with consent)
smejj.com is developing its own AI model (smejj 1.0). To improve this model, selected work results (e.g. verified task results and your own corrections) may be used as training data — only with your prior, explicit consent (Art. 6(1)(a) GDPR). Without consent, nothing whatsoever is collected for training purposes; the feature is switched off by default.
Consent is voluntary and split three ways: (1) collection and review of the data, (2) use for model training, (3) confirmation that you hold the necessary rights to the content. You can use smejj.com without restriction and without giving consent.
Before anything is stored, the data is cleaned automatically: credentials, API keys and personal details are removed (sanitization). The cleaned data is encrypted (AES-256-GCM) and stored immutably in the IDrive e2 object store. It is not passed on to third parties; data from third-party model APIs is not used for training.
You can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR), directly in the app or by email to s@smejj.com. After withdrawal, your data will no longer be used for future training, and stored training data will be deleted or blocked unless statutory retention obligations prevent this.
11. Retention period
Personal data is stored only for as long as it is needed for the purposes described above. Session data expires automatically. Account-related data is removed when the account is deleted, unless statutory retention obligations apply.
12. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You may also lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). An email to s@smejj.com is enough to exercise your rights.
13. Changes to this policy
This privacy policy is updated whenever features or legal bases change. The version published here applies in each case.