Legal notice & privacy

Updated 14 September 2026. This notice covers zippergen.io, its interactive demo and demo-api.zippergen.io.

This website is a personal academic project.

Editor and data controller

Benedikt Bollig
LMF – CNRS & ENS Paris-Saclay
4, avenue des Sciences
91190 Gif-sur-Yvette, France
Office: 2S60
Email: bollig@lmf.cnrs.fr
Phone: +33 (0)1 81 87 54 32

Hosting

The website is served through Cloudflare Pages.

Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107, USA

The live demo backend runs on a server provided by:

netcup GmbH
Emmy-Noether-Straße 10
76131 Karlsruhe, Germany
Phone: +49 721 7540755 0
Netcup legal notice

Privacy in the demo

The simulated walkthrough runs in your browser. It does not call a model, send email or contact Telegram. The optional live step creates a temporary workflow on the demo server and asks for your approval through a Telegram bot. It uses a fixed example reply. You can use the simulation without connecting Telegram.

Data used by the live step

Your browser also sends ordinary connection information, such as its IP address, to the hosting providers. Please use the bot's Start and approval controls rather than sending personal or confidential messages. The live step needs the session and Telegram identifiers to work. No model provider receives these demo interactions.

Purpose and legal basis

These data are used to provide the demonstration you request, save its progress, associate your answer with the right workflow and protect the service from abuse. The legal basis is legitimate interests under Article 6(1)(f) GDPR: operating a small public demonstration and keeping it reliable and secure. We do not use these data for advertising, profiling or model training.

Retention

A live session expires 30 minutes after creation. During normal operation, the service then deletes its session record and saved workflow files, including the associated Telegram identifiers and decision. Completed runs use the same expiry time. Incoming Telegram updates are removed from the processing queue after they have been handled. Failed processing may delay removal until a retry succeeds.

The application retains hashed IP addresses and start times for the rolling one-hour limit, then removes them during maintenance. If the server is stopped, cleanup resumes when it starts again. These periods describe the demo's application data, not messages kept by Telegram or connection and security records managed by the hosting providers.

Demo usage counts

When enabled, we count the steps reached in the walkthrough to understand where it is difficult to follow. The browser sends only a fixed milestone name and a random identifier for the current demo attempt to our Netcup server. It sends no command text, message content, page address, referrer, live-session token or Telegram identifier to the counting endpoint.

The attempt identifier and sent milestones stay in session storage for up to 24 hours or until the tab is closed. Start over creates a new attempt. The server retains event-specific hashes for duplicate detection for up to 24 hours. These temporary identifiers are not treated as anonymous data. The long-term report contains only daily totals, kept for 90 days. Counts describe attempts, not distinct people. Reloads within an attempt do not intentionally count a milestone again.

For the live path, the server counts session creation, connection through the bot's Start button and the final approval or rejection. This works even if the webpage is closed. Duplicate-count flags stay with the live session and expire with it. Refused live requests are counted separately. Existing sessions from before measurement was enabled are not counted.

These counts are used only by the editor to improve this demo and plan server capacity, on the basis of legitimate interests under Article 6(1)(f) GDPR. They are not used for advertising, cross-site tracking or model training. You can turn them off using “Usage counts” in the demo footer. The browser's Do Not Track and Global Privacy Control signals also disable measurement. Turning counts off stops further browser events and, when the page can reach the server, counting of the current live session. Already aggregated totals cannot be attributed back to you and are not removed.

To limit abuse of the counting endpoint, the server temporarily keeps a hash of the source IP address in memory for up to one minute. This address is not written to the usage tables. Ordinary hosting connection records follow the hosting providers' policies. Cleanup runs during normal service operation and resumes after a stopped service starts again.

Browser storage

The demo uses local storage to remember your progress, your current live-session link and which completion animations have already played. This information can remain after a server session expires. Start over resets the walkthrough and forgets the current live session. Clear this site's data in your browser settings to remove all locally saved information, including your usage-count preference. Blocking local storage does not prevent the basic walkthrough, but progress may not survive a reload.

The demo code does not set advertising or analytics cookies. Hosting providers may use technical or security mechanisms under their own policies. QR codes are generated in your browser. The session link is not sent to an external QR-code service. Keep live-session links private, as they provide access to the run.

Providers and international processing

The editor administers the demo. Cloudflare serves the website, Netcup hosts the backend, and Telegram delivers bot messages when you choose the live step. Telegram also processes your use of its service under its own privacy policy. Deleting a demo session does not delete the conversation from Telegram.

Cloudflare and Telegram operate internationally, so their processing may occur outside the European Economic Area. Their policies describe processing locations, retention and transfer safeguards. You can contact the editor above for further information about the providers used by this demo.

Your rights and contact

You can ask for access, correction or deletion of your personal data, request a restriction of processing, or object to processing based on legitimate interests. These rights apply subject to the conditions in data-protection law. Contact bollig@lmf.cnrs.fr. You can also lodge a complaint with the CNIL or your local supervisory authority.