Privacy Policy
Full legal entity details are set out in Section 1 below and mirror our Impressum.
Your privacy matters to us. It is Telekinesis's policy to respect your privacy and comply with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG), and any other applicable law regarding any personal information we may collect about you, including across our website, telekinesis.ai, and any related applications and services we own and operate.
Personal information is any information relating to an identified or identifiable natural person — for example your name, email address, IP address, or device data.
If our site links to third-party sites or services (including GitHub, Discord, and social platforms), please note that those third parties have their own privacy policies. This Privacy Policy does not apply to your activity on any site or service that is not ours.
This policy is effective as of 1 January 2026. Last updated: 1 September 2026.
1. Who Is Responsible (Data Controller)
The data controller responsible for processing your personal information under Art. 4(7) GDPR is:
- Telekinesis GmbH
- 4.1.08, Neckarstraße 464283 DarmstadtGermany
- Represented by
- Suman Pal, Arjun Vir Datta (Managing Directors)
- Commercial register
- Registration number: HRB 105059Registry court: Amtsgericht Darmstadt (Hesse District Court Darmstadt)
- VAT ID (USt-IdNr.)
- DE 00724601937
- Contact
- Phone: +49 157 5817 8477Email: suman.pal@telekinesis.ai
Note: full legal disclosure with the same details is also published at our Impressum, as required under § 5 TMG/DDG.
Data Protection Officer
We are not currently required to appoint a Data Protection Officer under § 38 BDSG. Privacy questions can be directed to suman.pal@telekinesis.ai.
2. Information We Collect
Information we collect falls into two categories: information you provide directly, and information collected automatically.
2.1 Information You Provide Directly
Newsletter / updates subscription. When you subscribe to receive updates from Telekinesis, we collect:
- Name
- Email address
Developer account / API key requests. When you request access to the Telekinesis platform or an API key, we collect:
- Email address
- Password (stored only as a salted cryptographic hash — we never store or can see your plaintext password), or
- If you choose "Sign in with Google," the basic profile information Google shares with us for authentication (typically your name, email address, and profile picture). We do not receive your Google password. See Section 6 on Google as a processor.
Contact and community. If you contact us by email, mention us on social media, or interact with us via GitHub or Discord, we may collect the information you choose to share in that context (e.g., name, email, message content, GitHub or Discord username).
2.2 Information Collected Automatically
Log data. When you visit our website, our servers or hosting provider automatically log standard technical data such as your IP address, browser type and version, referring/exit pages, the pages you visit, and the date and time of your visit. This is necessary for the technical delivery of the site and for security (Art. 6(1)(f) GDPR — see Section 4).
Error and diagnostic data. If you encounter an error while using our site or platform, we may automatically collect technical details about the error (e.g., device type, browser, what you were doing) to help us fix it.
Analytics. We use Plausible.io to understand how visitors use our site. Plausible is a privacy-focused analytics tool that does not use cookies, does not collect or store any personal information, and does not track or fingerprint individual visitors across websites or devices. It reports only aggregated, anonymous statistics (such as page views and referrers). Because it does not store or read any information on your device, it does not require cookie consent under § 25 TDDDG. Plausible's own EU-based infrastructure is described at plausible.io/data-policy.
We do not use any other tracking, fingerprinting, or session-recording script on this site.
3. Why We Collect and Use Your Information
We use personal information only for the following purposes, and we do not process it in ways incompatible with these purposes:
- To provide, operate, and maintain the Telekinesis platform, including issuing and managing API keys and authenticating your account
- To send you the updates, release notes, or newsletter content you subscribed to
- To respond to your enquiries and provide support
- For security purposes, such as detecting fraud, abuse, or unauthorized access
- For analytics and product improvement, to understand how our website and platform are used
- To consider your application if you apply for a role with us
We do not sell your personal information. We do not use your personal information, or any data you or your organization store in or process through the Telekinesis platform (including code, robot telemetry, or Skill configurations), to train artificial intelligence or machine-learning models, unless you explicitly opt in to a program that says otherwise.
4. Legal Bases for Processing (GDPR Art. 6)
Under the GDPR, we may only process your personal information where we have a valid legal basis. Depending on the activity, we rely on:
- Consent (Art. 6(1)(a) GDPR) — for example, when you subscribe to our newsletter. In line with German case law on email marketing, we use a double opt-in process: after you submit your email, we send a confirmation link, and you are only added to the list once you click it. This protects you from being subscribed by someone else using your address, and gives us a record of your consent. You may withdraw consent at any time via the unsubscribe link in any email or by contacting suman.pal@telekinesis.ai; this does not affect the lawfulness of processing before withdrawal.
- Performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR) — for example, creating and operating your developer account and API key so we can provide the service you requested.
- Legitimate interests (Art. 6(1)(f) GDPR) — for example, keeping logs for security and troubleshooting, and improving our website and product. Where we rely on legitimate interests, we have weighed our interests against your rights and freedoms and concluded ours do not override yours; you may object at any time (see Section 9).
- Legal obligation (Art. 6(1)(c) GDPR) — where we must retain or disclose information to comply with German or EU law (e.g., tax and commercial record-keeping obligations under the Abgabenordnung/HGB).
If you are under 16, we require the consent of a parent or legal guardian before processing your data based on consent, in line with Art. 8 GDPR and German practice.
5. How Long We Keep Your Information
We retain personal information only as long as necessary for the purpose it was collected for:
- Newsletter data (name, email): until you unsubscribe, plus a short period afterward to record that you unsubscribed and honor suppression.
- Account/API key data (email, password hash, or Google account link): for as long as your account is active, and for a limited period after deletion to prevent fraud and comply with legal obligations.
- Log and security data: typically deleted or anonymized after a short retention window (commonly 7–30 days), unless needed longer for an active security investigation.
- Correspondence: for as long as needed to resolve your enquiry and for a reasonable period afterward for our records.
Where German commercial or tax law (HGB, AO) requires longer retention of specific records (e.g., invoices), we retain only the legally required data for the legally required period (commonly 6 or 10 years), and restrict its use to that purpose.
6. Who We Share Information With
We disclose personal information only where necessary, to:
- Group companies or affiliates, if applicable
- Service providers acting as our data processors under Art. 28 GDPR data processing agreements, including hosting, cloud infrastructure, authentication, email delivery, and error-monitoring providers
- Courts, regulators, or law enforcement, where required by law or to establish, exercise, or defend legal claims
- A buyer or successor entity in the event of a merger, acquisition, or sale of assets, subject to this policy continuing to apply
Third parties we currently use:
- Alfahosting GmbH (Germany) — domain and/or web hosting
- Amazon Web Services (AWS Amplify) — application hosting and deployment infrastructure for our website
- GitLab Inc. — source control and CI/CD pipeline used to build and deploy our website (processes our codebase; not intended to process visitor personal data)
- Plausible Analytics OÜ — cookie-free, privacy-first website analytics (see above)
- Tally.so (Tally Labs) — powers our "Subscribe to Release Notes" form; collects the name and email you submit there on our behalf
- Google (Google Ireland Ltd. / Google LLC) — "Sign in with Google" authentication, if you choose that option when requesting an API key
- GitHub, Inc. — our open-source repositories and any GitHub-based sign-in or interaction
- Discord Inc. — our community server, if you choose to join it
We do not currently use a dedicated email/newsletter delivery provider — updates and release notes are not yet being sent on a recurring basis. This policy will be updated once one is in place, and any email sending will still be built on the double opt-in consent described in Section 4.
Sign-in with Google specifically
If you choose to authenticate using "Sign in with Google," Google acts as an independent controller for the authentication process itself (governed by Google's own privacy policy), while we act as a controller for the account data we subsequently store to operate your Telekinesis account. We only request the minimum profile scopes needed (name, email address) and do not request access to your other Google data.
International transfers
Some of our service providers — including Amazon Web Services (AWS Amplify), GitLab, Google (Sign in with Google), and Tally.so — are US-based companies and may process data outside the European Economic Area (EEA), including in the United States. Where this occurs, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses (SCCs), and, where relevant, supplementary measures required under the "Schrems II" ruling of the CJEU. Our hosting via Alfahosting is provided from within Germany. You can request more information about these safeguards at suman.pal@telekinesis.ai.
7. Security
We use appropriate technical and organizational measures (Art. 32 GDPR) to protect personal information against loss, misuse, and unauthorized access, disclosure, alteration, or destruction — including TLS/SSL encryption in transit and password hashing for account credentials. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for choosing a strong password and keeping your own credentials confidential.
8. Children's Privacy
Our website and platform are not directed at children, and we do not knowingly collect personal information from anyone under 16 years of age without parental or guardian consent, consistent with Art. 8 GDPR.
9. Your Rights Under the GDPR
As a data subject, you have the right to:
- Access (Art. 15) — request confirmation of whether we process your data, and a copy of it
- Rectification (Art. 16) — request correction of inaccurate or incomplete data
- Erasure (Art. 17) — request deletion of your data ("right to be forgotten"), subject to legal retention exceptions
- Restriction of processing (Art. 18) — request that we limit how we use your data in certain circumstances
- Data portability (Art. 20) — receive your data in a structured, machine-readable format, or have it transferred to another provider
- Object (Art. 21) — object to processing based on our legitimate interests or for direct marketing at any time, with no need to justify the objection for marketing
- Withdraw consent (Art. 7(3)) — at any time, without affecting prior lawful processing
- Lodge a complaint with a supervisory authority. You may contact your local EU data protection authority, or the German authority with jurisdiction over us:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)Gustav-Stresemann-Ring 165189 Wiesbaden, Germanydatenschutz.hessen.de
To exercise any of these rights, contact us at suman.pal@telekinesis.ai. We will respond within the timeframes required by the GDPR (generally one month).
10. Automated Decision-Making
We do not currently use your personal information for any decision that produces legal or similarly significant effects through fully automated means without human involvement (Art. 22 GDPR). If this changes, we will update this policy and provide the information required by law.
11. Cookies
Our website does not set any non-essential cookies, and does not run any analytics or tracking script that stores or reads information on your device. This includes Plausible (which is cookie-free by design), and also excludes Google Analytics, Google Tag Manager, Segment, Mixpanel, Hotjar, and Microsoft Clarity, none of which are used on this site.
Embedded third-party elements you actively choose to use — such as our Tally.so subscription form, or links to Discord, GitHub, or social media — are governed by those providers' own cookie and privacy practices once you interact with them.
If this changes in the future — for example, if we add a cookie-based tool — we will present a cookie consent banner before any non-essential cookie or similar technology is activated, and update this section accordingly.
12. Changes to This Policy
We may update this policy to reflect changes in our practices or in the law. We will post any changes on this page and update the "last updated" date above. Where required by law, we will seek your consent or give you the opportunity to opt out of any materially new use of your personal information.
13. Contact
Questions, requests, or concerns about this policy or your personal information: suman.pal@telekinesis.ai