This page describes how CreateMaps currently handles API keys, browser storage, query logging, and server-side debugging data.
Harald Körtge Softwareentwicklung
Eldenaer Str. 7
10247 Berlin
Germany
Contact: info@hekosoft.de
The current web frontend does not need tracking cookies. It stores the API key and local UI state in browser storage, for example editor content, panel state, custom route profiles, or REST test settings. The API key is stored locally so you do not need to enter it repeatedly. Remove it through the browser’s site data settings or by clearing the API key field.
The current purpose is internal debugging, operational analysis, and troubleshooting of the CreateMaps prototype. API access request data is used to review requests, confirm email addresses, issue or disable API keys, contact applicants about their access, and send occasional alpha update emails when the applicant explicitly opted in. Feedback data is used to reproduce issues, improve the product, and follow up when an email address was provided.
At the current prototype stage, processing is based on providing the requested preview service, protecting and operating the service, and consent where you explicitly opt in to optional alpha update emails or provide optional feedback contact details.
Submitted search queries and natural-language requests are written to append-only structured server log files together with timestamps, result size information, request/session IDs, and the remote IP address. Do not submit confidential, personal, or regulated data in queries or feedback while the service is in alpha testing.
Natural-language query translation may use a configured OpenAI-compatible model endpoint or local/remote model service. Prompts sent to that feature can include the natural-language request and relevant query context. The endpoint used can change during the alpha phase.
During the alpha, query/debug logs are intended to be reviewed and pruned regularly and should normally not be kept longer than 90 days unless needed to investigate abuse, security issues, billing/credit disputes, or a specific bug report. Feedback is normally kept for up to 24 months so it can inform product decisions. API access requests, API-key records, credit counters, approval/revocation events, and alpha update opt-in status are kept while the key or request remains active and for up to 24 months afterwards. These periods may be shortened as the service matures.
You can remove the locally stored API key via your browser’s site data settings. Already created server-side log entries are not automatically deleted. For API access, feedback, or alpha update emails, contact info@hekosoft.de.
Depending on the applicable law and the specific processing context, you may have rights of access, rectification, erasure, restriction, objection, and withdrawal of consent with future effect.