EO Funding FinderSign in
← Back

Privacy policy

As of: 23 August 2026

This translation is provided for convenience. The German version is the binding one.

This policy describes which personal data is processed when using EO Funding Finder, and on what basis.

1. Controller

David Pogorzelski, Geisbergstraße 18, 10777 Berlin, Germany. Email: support@dpogoda.dev.

2. Which data we process

Account data. When you sign in via Google, Apple or an email code, we store your email address and a user ID. We do not receive a password.

Your input. The project description or proposal you paste in for a research run is stored in your account together with the generated report, the matches found and the sources used, so you can call runs up again later. More on this in section 3.

Uploaded files. Images, PDFs and text files you attach to a research run are stored alongside the run, so you can look up later what went in. They sit in private storage that only our server can reach. They are deleted along with your account; files you pick but never submit are removed automatically after 24 hours.

Usage data. For every run we record technical figures (status, timestamps, number of searches and pages read, tokens consumed), for billing, troubleshooting and abuse prevention.

Balance. Purchases and consumption of credits are stored as ledger entries (timestamp, amount, reason, Paddle reference).

Payment data. Purchases are handled by Paddle as merchant of record. Paddle collects your payment data under its own privacy policy; we receive only the transaction reference, the pack bought and the billing country. We never see your full payment details.

Server logs. Our infrastructure logs IP addresses, request metadata and errors for a short period, in order to operate and secure the service.

Cookies. We set only technically necessary cookies for the sign-in session. No advertising cookies, no cross-site tracking, no analytics tools.

3. Your project description and your proposal

The text you paste in is transmitted to Anthropic to carry out the research and processed there. Anthropic is our processor and does not use the content to train its models. As part of the research, search queries derived from your text are sent to search engines and public web pages are fetched; this happens on Anthropic's infrastructure. The same applies to attached files: images, PDFs and text files are transmitted to Anthropic to be read.

Please note: proposals often contain trade secrets, consortium details or names of people involved. Only paste in content you are allowed to. If your text contains personal data of third parties, it is your responsibility that a legal basis exists. If you need a data processing agreement under Art. 28 GDPR, contact support@dpogoda.dev.

4. Purposes and legal bases

To provide the service and manage your account (Art. 6 (1) (b) GDPR), to secure the service, prevent abuse and handle billing (Art. 6 (1) (b) and (f) GDPR), and to comply with legal obligations such as commercial and tax retention duties (Art. 6 (1) (c) GDPR).

5. Recipients and processors

We use the following service providers on the basis of data processing agreements:

  • Vercel Inc.: hosting and running the application
  • Supabase Inc.: database and sign-in
  • Anthropic PBC: carrying out the research, including web search and page retrieval

Paddle (Paddle.com Market Limited or Paddle Payments Limited) processes payment data as an independent controller and merchant of record, not as our processor.

6. Transfers to third countries

Some of these providers process data in the United States. Where data is processed outside the EU/EEA, we rely on the EU standard contractual clauses and, where available, on the EU-US Data Privacy Framework.

7. Retention and deletion

We store account data, runs (including your input texts and reports) and ledger entries for as long as your account exists. On the account page you can delete all of it yourself at any time: profile, all runs and all ledger entries. Unused credits are forfeited in the process.

The invoice records for your purchases are held by Paddle, which issues the invoices as merchant of record and is subject to commercial and tax retention duties. Our own ledger entries are internal operating data and are removed on deletion.

Your login remains. Sign-in is shared across several Overfly applications; we do not delete it along with the rest, because that would remove your access to other applications. If you sign in here again later, you start with an empty account.

Server logs are deleted after a short time.

8. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests (Art. 15–21 GDPR).

Access, portability and erasure you can exercise yourself, without going through us: on the account page you download a complete copy of your data as JSON, or delete it. For anything else, contact support@dpogoda.dev.

You can also lodge a complaint with a supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information.

9. No automated decision-making in individual cases

The research itself is carried out automatically by a language model. There is, however, no automated decision within the meaning of Art. 22 GDPR: the results are research findings without legal effect on you, and no profiling takes place.

10. Changes to this policy

We adapt this policy when the service or the legal situation changes. The current version is always on this page. See also our terms.