Privacy
How we handle information
There isn't much to tell. We don't sell anything on, we don't track you around the web, and we don't keep more than we need in order to reply to you.
- Who we are
- komplai ApS, CVR DK40351981, Copenhagen. We are the data controller for what is described here. Write to hej@komplai.dk if you want something corrected or deleted.
- The contact form
- You have to give us an email address. The message is optional. What you write is sent as an ordinary email to our inbox, and you get a receipt at the address you entered. We don't put it in a database, and we don't use it to train models. The basis is our legitimate interest in answering an enquiry you sent us yourself. We keep the email for as long as it is relevant to what we are corresponding about, and delete it if you ask us to.
- Statistics
- We run our own statistics on our own servers. We count page views, where you came from, and whether the form was sent. To tell two visits apart, a code is derived from your IP address and your browser, and that code is replaced every day. The IP address itself is not stored.
- Cookies
- There are none. Neither ours nor anyone else's. There is no login on this site either.
- Where it runs
- The site and the statistics run on our own servers at Hetzner in Falkenstein, Germany. We send email through Resend, which is an American company. The sending itself happens on their servers in Ireland, but because the company is American, US law may apply to them. They see your email address and what you wrote. The typefaces are loaded from Google Fonts, which sees your IP address when the page loads.
- Your rights
- You can find out what we hold about you, have it corrected or deleted, and object to us processing it. Write to hej@komplai.dk. If you are not happy with the answer, you can complain to the Danish Data Protection Agency at datatilsynet.dk.
The free tools
The tools do not work the same way, and the difference matters. In lens the document never leaves your browser. In redact the text is sent to us, because the detection runs at our end. So each one is described on its own here.
lens Your PDF stays in the browser.
- The document
- The file is read and examined inside your browser. There is no upload, and there is no server to upload it to. Close the tab and it is gone, along with its text and everything found in it.
- What we can see
- That the page was visited, and that a document was opened. Not which document, not how big it is, and not what it says.
- Anyone other than us
- The typefaces are loaded from Google Fonts, which therefore sees your IP address. Otherwise no one.
redact The text is sent to us and processed in Germany.
- The text
- To find CPR numbers, names and addresses, we send what you wrote to our own server. Up to 50,000 characters at a time. It is not stored, neither in a database nor on disk, and the response is not cached.
- Where it is processed
- On our own servers at Hetzner in Falkenstein, Germany. The text is passed on to the name recognition we run in the same place, which uses the first 16,000 characters. That does not store anything either, and the text does not leave those machines.
- What stays in the browser
- The substitution itself with [CPR-1] and the like, the list of what was swapped for what, and putting the real values back into the AI's answer afterwards. That list never leaves the page, and it disappears when you refresh.
- PDFs
- The PDF file stays in the browser, and the new file is built there too. Only the text from the document is sent to us.
- Anyone other than us
- The typefaces are loaded from Google Fonts, which therefore sees your IP address.
docs Documents and impact assessments are stored with us in Germany. Without signing in, they are deleted after 30 days without activity.
- The documents
- What you write is stored in our database on our own servers at Hetzner in Falkenstein, Germany, along with comments and earlier versions. If you share a link, anyone with the link can open the document. If you invite someone, we store their email address with the document.
- Impact assessments (DPIA)
- An impact assessment is a document here like any other, only starting from Datatilsynet's template: you pick that template when you create the document on docs.komplai.dk. Everything above applies to it too — risks, comments and earlier versions included. We do not redistribute Datatilsynet's spreadsheet; we use the structure, meaning the questions, scales, risks and measures.
- Without signing in
- You can write without signing in. A cookie in your browser then shows that the documents are yours, and we only store a fingerprint of it. A document without a sign-in is deleted once there has been no activity in it for 30 days. If you clear your cookies, we can no longer tell that the documents are yours.
- Signed in
- If you sign in, we send a link to your email address. The email goes through Resend. We store the address, and the documents you made without signing in, in the same browser, move to your account. Documents on an account are kept until you delete them or the whole account. If you delete the account, we delete its documents with it.
- Backups
- We take an encrypted backup of the database every night. When you delete a document or your account, or a document is deleted after 30 days, it can remain in older backups for up to 12 months before they expire.
- Cookies
- None of them are used for tracking. A visitor cookie remembers for a year which documents are yours. A sign-in cookie keeps you signed in on docs.komplai.dk. While you sign in, the form also uses two technical cookies: one against forged forms and one that remembers where to send you afterwards.
- AI
- If you ask the AI for help, the request goes to our own GPU server in Denmark first. If it cannot answer, you are told and given a choice, and we do not pass anything on ourselves. A free third-party model is only used if you choose it in a dialog that names the model, and only for that one request. The answer is inserted as a suggestion that you accept or reject yourself.
- Anyone other than us
- Resend is an American company. The sending happens on their servers in Ireland, but US law may apply to them, and they see your email address. If you choose a free model, the request goes through OpenRouter to the provider that runs the model. We cannot say in advance which country that happens in, and the provider may train on what you send, so that route is not suitable for personal data. The typefaces are loaded from Google Fonts, which therefore sees your IP address.
secret We cannot read what you send.
- The content
- It is encrypted in your browser before anything at all is sent. The key sits in the part of the link after the # character, and browsers never send that part to the server. So all we hold is an encrypted blob we cannot open.
- What we hold
- The encrypted text and an expiry time. Not who created it, not who it is for, and not what it is about.
- Once only
- When the link is opened, the row is deleted in the same operation. That is a real delete in the database, not a flag being set.
- What we can see
- Your IP address is used to limit how many can be created from the same place. It is not stored alongside the secret.
mcp bridge No account, and none of your keys with us.
- Keys
- The connectors that need a credential run on your own machine. The hosted set cannot accept keys at all, and the server refuses to start if anyone tries to put one in it.
- What the server sees
- The requests your AI assistant sends. A log is kept of which tools were called, and whether they were denied.
- Where the requests end up
- The connectors look things up in Danish public registers. If you use them, your query goes on to the CVR register, DAWA, Retsinformation, Statistics Denmark or the Danish Parliament's open data, depending on what you ask for.
- The config generator
- What you click together on the page to get a configuration out stays in the browser. Nothing is sent, and nothing is stored.
townhall townhall has its own privacy policy.
- Privacy policy
- townhall has its own privacy policy, in Danish, at townhall.komplai.dk/privatliv. It describes what is stored, why, who can see it and for how long. If you have questions about townhall, write to townhall@komplai.dk.
decide Text is processed on local infrastructure in Denmark. Jev with your own key is processed in the US.
- Text and questions
- Text, questions and results pass through our encrypted queue on local infrastructure. Input is deleted when processing finishes; results are encrypted and retained for one hour by default, then deleted during periodic cleanup; operational metadata is used for capacity and troubleshooting. Use synthetic data when trying the experimental d1 model.
- Your own Jev key
- Selecting Jev sends your text to TypeSafe in the US. The key stays in the open page’s memory. Laya, Claes and d1 do not send text to the model publisher.
Last updated:
Back to the front page