Skip to content

Privacy policy

There is not much being processed here, and this page says exactly what it is. No analytics, no ad networks, no fonts loaded from someone else's server.

Controller

The controller under the General Data Protection Regulation is:

Phillipp Jäger Karl-Liebknecht-Ring 2 06679 Hohenmölsen Email: info@citexnode.de

Data protection officer: None has been appointed. The conditions in Art. 37 GDPR and § 38 BDSG do not apply; privacy requests go to the address above

Appointing a data protection officer only becomes mandatory above a certain size or for certain kinds of processing.

What data we collect

All of the following exists because you have an account and run instances. None of it is bought in and none of it comes from third parties.

  • Account data: email address, display name, your password as an Argon2id hash, language preference, your referral code and, if you enable it, your two-factor configuration.
  • Instance metadata: name, plan, template, node, allocated ports, expiry date and the start and stop times of your servers and bots.
  • Usage metrics: CPU share, memory, disk, network traffic and uptime of your instances, stored in time buckets.
  • Credits: your balance and every transaction with amount, reason and timestamp.
  • Support: tickets, messages and attachments you send us.
  • Server logs: IP address, timestamp, requested path, status code and user agent.
  • Content on your instances: files, worlds, configuration and console output live on our nodes. We only look at them where it is necessary to operate the platform, to deal with abuse, or to answer a support request you opened yourself.

What we use it for

  • So you can log in and your account stays yours.
  • So instances can be created, started, renewed and deleted.
  • So the meters, usage figures and the status page show real numbers instead of estimates.
  • So we can spot abuse: mining, attacks launched from our addresses, multiple accounts routing around the limit.
  • So we can plan capacity and know when a node is full.
  • So we can answer your support requests.

Legal bases

  • Art. 6 (1) (b) GDPR: account, instances, credits and support, in other words everything needed to perform the usage contract.
  • Art. 6 (1) (f) GDPR: server logs, rate limits, abuse and attack prevention, and capacity planning. Our legitimate interest is a stable platform that is not being abused.
  • Art. 6 (1) (c) GDPR: statutory retention and disclosure obligations.
  • Art. 6 (1) (a) GDPR: anything you explicitly consent to, for example There are none. No newsletter, no marketing mail, and so nothing to consent to. You can withdraw consent at any time with effect for the future.

How long we keep it

The operator sets the concrete retention periods and fills them in here. They have to match what the systems actually do.

  • Account data: for as long as your account exists.
  • After account deletion: immediately. Account, instances, databases and tickets go in the same operation
  • Server logs: rolling, at most around 30 MB per instance. It is a size rather than a period: older lines drop off the end as new ones arrive
  • Usage metrics: 8 days. Raw samples are never stored, only 5-minute and hourly averages, and those are deleted afterwards
  • Tickets: until you delete your account. A closed ticket is not removed automatically, because the history helps the next time something happens on the same server
  • Backups: as long as you keep them. Backups live on the node, count against your plan's backup slots and are deleted with the instance
  • Deleted instances: the files go with the instance, immediately after the grace period ends. The container, the directory and the backups go together

Recipients and processors

We do not sell data and we do not pass on anything that is not needed to run the service. Involved are:

  • Data centre and server provider: Amazon Web Services, region eu-central-1 (Frankfurt am Main, Germany)
  • Second location: Eygelshoven data centre, Netherlands (Skylink). Servers created there keep their files and worlds on that machine. Which node carries your instance is shown in the dashboard next to its name.
  • Email delivery for confirmations and notifications: none. Mail leaves our own server; no sending service is involved
  • Payment provider: none. CitexNode does not take money, so there is no payment data and nobody processing it
  • Authorities, where we are legally obliged to disclose.
  • Bot protection on sign-in, registration and the two forms that send an email: Cloudflare Turnstile, Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA

There is a processing agreement under Art. 28 GDPR with every processor.

Transfers to third countries: your content and your account stay on servers in Germany. There is one exception: opening sign-in, registration, forgot password or resend confirmation makes your browser load the Turnstile widget from Cloudflare, and your IP address along with browser and device details reach Cloudflare, including in the United States. The basis for that is the standard contractual clauses under Art. 46 GDPR.

Cookies, browser storage and tracking

This section is short, and that is the point.

  • Two strictly necessary session cookies: cn_at and cn_rt. They are set when you log in and they are httpOnly, so JavaScript in the browser cannot read them. Without them there is no login.
  • Two entries in your browser's local storage: cn-theme remembers whether you chose light or dark, cn-cookie-notice remembers that you dismissed the notice. Both stay on your device and are never sent to us.
  • No analytics, no tracking pixels, no ad network, no third-party cookies, no profiling.
  • The fonts are served from our own server. No request goes to a font CDN, so no font provider ever sees your IP address.

That is why there is a notice here rather than a consent wall: there is nothing you could say no to without also logging yourself out. The bot protection on the four public forms sets no cookies on your device; it has a section of its own further down, because data still reaches a third party.

Bot protection on the public forms

Four forms are open without anybody being signed in: sign-in, registration, forgot password and resend confirmation. Those are precisely the ones a script wants, and a counter per IP address only helps for as long as the script uses one address.

So those four forms run Cloudflare Turnstile. It is a puzzle almost nobody has to solve: the widget decides from browser signals whether to let you through.

What reaches Cloudflare in the process is not ours to decide and not ours to limit. By Cloudflare's own description it is essentially your IP address, browser and device details, and how the page was used during the check.

The legal basis is our legitimate interest under Art. 6(1)(f) GDPR in protecting the public forms from automated abuse. Without it, mass registration and using our form to flood somebody else's inbox would both be possible.

The widget is loaded on those four pages only. On the rest of the site, in the dashboard and on the console, Cloudflare is not involved.

Cloudflare's privacy policy

Access by support

Staff with admin rights can open the console and the file manager of somebody else's instance. That is what makes it possible to answer a ticket like "my server will not start" without asking you for your password.

Three rules apply, and the third is the one you can check yourself:

  • It only happens for operations, to work on your support request, or to deal with abuse.
  • The access reaches as far as that of a person you share your server with: console, files, backups, databases, on and off. Deleting, renaming, reinstalling, renewing and the sharing list stay yours alone.
  • Every single one of these accesses is logged and appears in your own activity log under the instance. You can see that somebody from the team was in there, when, and what they opened.

You can generate an eight-digit support PIN in your settings to prove who you are. It is valid for 24 hours, replaces the previous one and can be withdrawn at any time. We store it encrypted rather than in plain text, and staff never see it: they type in what you read out and get back a yes or a no. It is proof that you belong to your account, not a precondition for us being allowed to look into abuse.

We do not go browsing servers without a reason. If you find an access in the log you cannot explain, open a ticket and we will tell you who it was and why.

Your rights

You have the following rights under the GDPR, and we answer requests within the statutory deadline:

  • Access to what we have stored about you (Art. 15).
  • Rectification of incorrect data (Art. 16).
  • Erasure (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability, meaning your data in a machine-readable format (Art. 20).
  • Objection to processing based on our legitimate interest (Art. 21).
  • Withdrawal of consent with effect for the future (Art. 7 (3)).

You can also lodge a complaint with a supervisory authority under Art. 77 GDPR. The competent authority is: Landesbeauftragter für den Datenschutz Sachsen-Anhalt, Leiterstraße 9, 39104 Magdeburg, Germany

Data export and account deletion

Two of those rights you can exercise yourself, without writing to us and without waiting for a reply.

Export your data or delete your account

The export contains your account, your instances, your credit transactions and your tickets as JSON. Deleting your account removes the account and every instance including its files. Both are final, so download the export before you delete.

Security

Access runs over HTTPS. Passwords are stored only as an Argon2id hash, never in clear text, which also means we cannot read them. Session tokens live in httpOnly cookies so a script in the browser cannot take them.

Changes to this policy

If the processing changes, this page changes. For material changes we tell you in the dashboard rather than doing it quietly.

Last updated: 21 August 2026