Skip to content

Privacy

This notice explains how Powerbeat processes personal data across the public website, account registration, the Powerbeat app, cloud services, the local Satellite, connected devices, automation, AI features, analytics, diagnostics, and correspondence.

Powerbeat and the controller

Powerbeat is the service covered by this notice. Manuel Gruber is its legal operator and controller. This notice covers the public website, account registration, the authenticated Powerbeat app, cloud services, the local Satellite, connected devices, Power and Energy data, automation, AI features, analytics, diagnostics, and correspondence. Contact Powerbeat at pilot@powerbeat.ai.

Accounts and access

Powerbeat processes account identifiers, name, email address, verification and pilot-approval status, role, timestamps, password credentials or linked-account tokens, session tokens, IP address, user agent, sign-in activity, and site memberships. This is necessary to register, authenticate, secure, administer, and provide Powerbeat under Article 6(1)(b) GDPR. Security, abuse prevention, access review, and audit records also rely on legitimate interests under Article 6(1)(f) GDPR.

Homes, devices, and Energy data

Powerbeat processes site names, timezone, optional coordinates, system and battery characteristics, tariffs and emissions settings, membership roles, device names and locations, vendor identifiers, connector configuration, local network addresses, and supported credentials or tokens. Declared cloud connector secrets are encrypted before database storage. The local Satellite stores pairing and connector state on equipment controlled by the home. Powerbeat processes timestamped solar, grid, battery, consumption, device Power, cumulative Energy, state, forecasts, topology, and connectivity data to provide the service under Article 6(1)(b) GDPR.

Controls, automation, and AI

Powerbeat records device commands and payloads, acting user or automation source, command status, manual overrides, rules, conditions, actions, Agent runs, tool arguments and results, approvals, errors, insight questions, generated answers, charts, and LLM usage metadata. Relevant questions, home and device context, readings, forecasts, tariffs, reports, and tool results can be sent to the selected AI provider to deliver requested features under Article 6(1)(b) GDPR. Per-site provider keys are encrypted. Audit and safety records rely additionally on Article 6(1)(f) GDPR.

Product analytics and diagnostics

When configured, the Powerbeat app and cloud API use PostHog for product and server analytics. Server events can contain user, site, device, feature, model, usage, cost, latency, request, and error identifiers. Sentry can receive browser and server errors, traces, logs, metrics, and session replay around errors. Axiom can receive API logs. Better Auth Cloud can receive authentication activity. Langfuse can receive model traces including prompts and responses. The public-website analytics choice does not apply to these product services. Powerbeat is completing the legal-basis, consent, masking, retention, and processor assessment before optional persistent product analytics, replay, or raw AI tracing are approved for pilot use.

Hosting, delivery, and security

Cloudflare serves the Powerbeat website and app and processes request data such as IP address, time, requested path, HTTP headers, browser or user-agent information, security signals, and network-error telemetry. Render and Tiger Cloud host Powerbeat cloud services and databases in the EU. Processing is necessary to provide Powerbeat under Article 6(1)(b) GDPR and to protect, observe, and diagnose the service under Article 6(1)(f) GDPR.

Necessary browser storage

The host-only pb_consent cookie stores your analytics choice, a generated consent ID, timestamps, the consent revision, and the current host for one year. If you explicitly select a language, pb-locale stores that choice in localStorage until you clear it. A bounded pb_site_event_queue_v1 entry can carry only allowlisted interaction fields in sessionStorage across one same-origin navigation; it is removed on the next page load and ignored after five minutes. These operations provide settings you explicitly request and use the exception in § 25(2)(2) TDDDG.

Cookieless measurement before consent

Before analytics acceptance, PostHog runs in memory-only cookieless mode. It receives a page view and limited request, page, locale, device, and browser metadata, including the IP address used by the service. It creates no analytics cookie or localStorage identifier, person profile, persistent attribution, heatmap, performance capture, or session replay. We rely on Article 6(1)(f) GDPR and our legitimate interest in basic, privacy-reduced audience measurement. You may object for reasons arising from your situation by contacting us.

Analytics after consent

If you accept public-website analytics, PostHog uses host-only ph_* and _ph_* persistence for up to one year. It can process pseudonymous profiles, page and allowlisted interaction events, approved campaign and referrer origins, browser and device data, performance and network timings, heatmaps, autocapture of clicks, changes and submits, and masked session replay when recording is enabled. Input values, request and response bodies, headers, arbitrary URLs, and private text are excluded or sanitized by the website configuration. The legal bases are your consent under Article 6(1)(a) GDPR and § 25(1) TDDDG.

Choices, withdrawal, and retention

Use Cookie settings in the footer to accept or withdraw public-website analytics. Withdrawal resets that PostHog client, removes accessible persistence, and reloads into cookieless mode. Public-website session recordings, if enabled, are retained for 30 days. Authentication sessions expire after seven days. Raw home and device readings are normally retained for 45 days; hourly device rollups for 25 months; rule events, report runs, and notification logs normally for 90 days. Daily device ledgers and 15-minute site-flow ledgers are retained without an automatic expiry. Several account, insight, command, Agent, audit, LLM, and configuration records currently have no automatic retention rule and are kept until deletion, a rights request, or an applicable operational or legal need requires another outcome.

Email correspondence

Opening a mailto link does not send data to Powerbeat. If you send a message to pilot@powerbeat.ai, we process the sender, recipients, message, attachments, and delivery metadata in Google Workspace to answer the request, prepare possible pilot access, secure correspondence, and keep necessary records. The legal bases are Article 6(1)(b) GDPR for pre-contractual requests and Article 6(1)(f) GDPR for other correspondence and record protection. Messages are kept until the request is resolved and then only for applicable evidence, defense, and statutory retention periods.

Processors and international transfers

Powerbeat uses Cloudflare for web delivery and security, Render and Tiger Cloud for cloud hosting and databases, Google Workspace for email, Better Auth Cloud for authentication activity when enabled, PostHog for analytics, Sentry for diagnostics, Axiom for logs, and Langfuse for AI tracing and evaluation. AI requests can go to Z.ai or a selected Anthropic, OpenAI, or DeepSeek account. Connected services can include Tesla, Easee, Solcast, aWATTar, and user-selected command proxies. Providers can use subprocessors and can be subject to access from outside the EEA. Where required, transfers rely on applicable processing terms, adequacy decisions, or standard contractual clauses. Powerbeat does not state unverified vendor-specific retention or transfer details as fact.

Your rights and complaints

Subject to the legal conditions, you can request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier processing. Contact pilot@powerbeat.ai. You may also complain to a data-protection authority, in particular the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, at https://www.lda.bayern.de/.

Contact

Powerbeat
Manuel Gruber
Am Anger 9a 84140 Gangkofen GermanyEmail: pilot@powerbeat.ai
Phone: +49 8721 - 1289833