MietKorrekt

Privacy

This page describes what MietKorrekt does with your documents and case data, who they are transmitted to and how long they exist. It describes what the application actually does.

Controller

The controller for the processing described on this page is:

  • Lucas Pennewiss
  • Bahnhofstrasse 57
  • 6312 Steinhausen
  • Schweiz
  • kontakt@mietkorrekt.ch

What data is processed

MietKorrekt requires neither an account nor registration, and asks for neither a name nor an e-mail address nor a telephone number. What is processed is what you upload yourself, and what is derived from it.

  • Uploaded documents: the final settlement bill, the move-out inspection report and any other documents you choose. They regularly contain names, addresses, amounts, details about the flat and signatures.
  • Extracted details: charges, rooms, objects, amounts, dates and passages of text read out of the documents.
  • Case data: a random case number, the processing status, timestamps, the charges assigned to the case and the assessment.
  • Origin details of the case: source, medium and campaign, where applicable a click identifier, and the attribution to a partner through whose link you came — see “Where your case came from”.
  • Technical logs: event names, case and document numbers, counts, durations and error codes.
  • Payment data for the case: amount, currency, payment status, the time of confirmation and the reference numbers under which the payment is held at Stripe. No card details — those never reach this service.

Why the data is processed

The documents are read in order to compare the charges on the final settlement bill with the other documents, to produce an assessment, and to derive a draft letter from it. They are not used for any other purpose.

There is no advertising, no profiling, no analysis across cases and no further use for training purposes.

Uploaded documents and case data

The uploaded files are held in non-public storage. There is no public link and no read link to a file; they are read exclusively on the server, for the extraction within your case.

Case data, extracted details, charges, source references and assessments are held in a database and are reachable through your case's access key.

Reading the documents through Anthropic

To read them, an uploaded file is transmitted to Anthropic's programming interface — one file per request, together with the extraction instruction. What comes back are the structured details, which are then stored. Anthropic processes the documents as a processor.

Inputs and outputs of the commercial API are, by default, not used to train Anthropic's models unless this is expressly agreed to.

Inputs and outputs of the standard API are generally deleted from Anthropic's systems within 30 days. Exceptions are possible, for example where a different retention has been agreed, for the enforcement of the usage policies, or because of legal obligations. That period is a statement by Anthropic about its own interface. It is not the period after which a case is no longer accessible at MietKorrekt — for that, see “How long a case exists” below.

Optional wording improvement for the letter

You can have the wording of the draft letter improved. This step is voluntary; without it, the text of the letter does not leave your browser.

What is transmitted in that case is only the introduction and the closing of the letter, plus one heading for each of the charges included and the tone you asked for.

What is not transmitted: sender and recipient with names and addresses, the address of the rental property, reference and invoice numbers, the amounts and reasons for the individual charges, source references, and the extracted raw data.

Payment (Stripe)

Checking a case is subject to a charge. The payment is handled by Stripe; MietKorrekt operates no payment processing of its own.

Only what is needed to set up the payment is transmitted to Stripe: the amount and currency, the product description, an internal payment reference, and the two return addresses Stripe uses to bring you back after completion or cancellation.

Those return addresses lead to your case and therefore contain its number — so Stripe receives the case number with them. It is assigned at random and has no connection to your name, your address or your documents: not anonymous, but a pseudonymous technical identifier. On its own it does not open the case. Access depends on a separate access key in the case link, which is not transmitted to Stripe and is held in the database only as a hash.

What is not transmitted: the uploaded documents, the details read from them, the charges on the final settlement bill, the assessment, the draft letter and the address of the rental property.

What you enter directly at Stripe

To pay, you are taken to a page operated by Stripe. The payment details — a card number, for example — and the details Stripe needs for the payment, such as an e-mail address for the receipt, are entered there, directly at Stripe.

Those details do not reach MietKorrekt: the payment page is not embedded in this application, no payment field of this application is displayed, and no e-mail address is received or stored. What Stripe reports back is only that payment was made, and for how much.

Stripe's own privacy policy applies to the details you provide there.

Operation of the application (Vercel)

The application is operated at Vercel. Its server functions are set to the fra1 region (Frankfurt, Germany). Vercel is therefore a processor for the operation; the uploaded documents pass through the server functions on their way to the extraction, and the case data on its way to being displayed.

The application's server functions are set to the Frankfurt (fra1) region. Static files are delivered over Vercel's worldwide network; the region setting governs where the server functions are executed.

Database and file storage (Supabase)

The database and the file storage are operated by Supabase. Supabase is therefore a processor for keeping the case data and the uploaded documents.

The production project runs in the eu-central-2 region (Central EU, Zurich, Switzerland). That is where the case data and the uploaded documents are kept.

The letter and the PDF are produced in your browser

The text of the letter is produced in your browser from the results already displayed. The PDF is likewise produced entirely in your browser and is not uploaded.

The name and addresses you enter for the letter are not stored. A downloaded PDF is on your own device; deleting the case does not reach it.

How long a case exists

A case is no longer accessible 30 days after it was created. That period is a decision by MietKorrekt and not a legal requirement.

With “Delete case”, the uploaded files are removed from storage and all case data in the database is deleted: the extracted details, the charges, the source references and the assessment. This cannot be undone, not even with the case link.

Expired cases are additionally removed on a schedule: a daily deletion run removes them from the database and from storage. Until one of the next runs removes it, an expired case may still exist — accessible it is not, from the moment it expires. If you do not want to wait for that, use “Delete case”.

A deletion takes effect in the live application. The production Supabase plan is “Pro”. The provider backs the database up automatically every day and, according to its plan description, keeps those backups for seven days. Deleted entries may therefore still exist in a provider backup for that period. The backups serve only to restore service after a failure and are not searched. Objects in Supabase storage are not part of the database backups. Your documents are therefore not part of them, and MietKorrekt keeps no additional copy of them. This page makes no statement about technical processes at the providers that MietKorrekt cannot inspect.

Who data is transmitted to

Data is transmitted exclusively to the following processors:

  • Vercel — operation of the application: execution of the server functions and technical runtime logs.
  • Supabase — database for the case data and private storage for the uploaded documents.
  • Anthropic — reading the uploaded documents and the optional wording improvement for the letter.
  • Stripe — handling the payment for checking a case.
  • Beyond that there is no disclosure: no sale and no analytics services. The only further transmission is the advertising measurement to Google, and it happens only after express consent — see “Advertising measurement (Google Ads)”. Disclosure to authorities takes place only where there is a legal obligation to do so.

Processing abroad

The processing does not take place in Switzerland only.

Anthropic may process commercial customers' data in several geographic regions. For storage, Anthropic names the United States by default unless something else has been agreed. When you upload documents and have them read, they may therefore be processed abroad and, in particular, in the United States.

As the contractual basis for this, Anthropic provides a data processing agreement with standard contractual clauses. Further assurances — an agreed processing without retention, for example — do not exist for this deployment.

Stripe is an internationally active payment service provider. No assurance is given that processing takes place in Switzerland only. The payment details named above may therefore also be processed outside Switzerland. As the contractual basis, Stripe provides terms with standard contractual clauses.

Case data and uploaded documents are kept at Supabase in Switzerland, and the server functions run in Germany. Access by the providers from other countries is therefore not excluded, and for the reading through Anthropic what is said above continues to apply: processing exclusively in Switzerland or in the European Economic Area is not assured.

Logs and security

Technical logs are produced for operation and troubleshooting. They contain event names, case and document numbers, counts, durations and status and error codes. Content from documents, access keys and quoted passages are removed before a log entry is written.

These logs are produced while the application runs and are collected there: Vercel runtime logs, in the standard scope of the Pro plan. They are kept for 1 day. They can be read by members of the Vercel project; there is no log drain, no Observability Plus and no disclosure to third parties.

A case is accessed through a random access key in the case link; the database holds only a hash of it. Whoever has the link can reach the case — do not pass it on.

Cookies

MietKorrekt sets two cookies. Both are technically necessary, both come from this site itself, and neither can be read by scripts in the browser.

  • The access key for your case. Restricted to your case's path, it expires with the case at the latest. Without it the case cannot be used.
  • Your privacy setting. It stores only your answer about the advertising measurement (“Advertising measurement (Google Ads)” below), the version of the question and the time — no identifier, no case number, no advertising or click identifier. It expires after 6 months; after that you are asked again.
  • Nothing else: no cookies for statistics, reach measurement or advertising, no cookies from Google, and no embedded third-party services on these pages.

Advertising measurement (Google Ads)

MietKorrekt advertises through Google Ads and would like to be able to measure whether a click on an advertisement led to a paid case. This measurement is voluntary, and we ask beforehand.

If you agree, our server transmits a report to Google after a paid check. That happens only if you have expressly agreed.

Four details are transmitted: the click identifier from your advertisement click, the time of the payment, the amount of CHF 49.– and a randomly generated transaction number. That number is not a case number and cannot be linked to any transaction outside MietKorrekt.

Even with your consent the following still holds: no Google scripts, no Google cookies, and none of this happens in your browser. These limits apply:

  • Only minimal details about a conversion, server-side from our server — not through a script in your browser.
  • No content from your documents, no amounts or defects from them, no results of the check, no letter and no assessment report.
  • No contact details: no e-mail address, no telephone number, no name, no address.
  • Without current consent no transmission takes place — not even if you agreed at some earlier time.

Recipient of the advertising measurement

The recipient of the report described above is Google. Google is an internationally active company; processing exclusively in Switzerland or in the European Economic Area is not assured, and the processing also takes place in the United States. Without consent nothing is transmitted.

    Where your case came from

    If you arrive through an advertising, campaign or partner link, the address carries details about where you came from. If you start a case, MietKorrekt takes at most the following details from it and stores them with the case:

    • Source, medium and campaign — “google”, “cpc” and a campaign name, for example. Those are labels for advertising material, not details about you.
    • A click identifier from Google (“gclid”) — but only if you have consented to the advertising measurement.
    • A partner code — if you arrived through the referral link of a MietKorrekt partner. It is public and identifies the partner, not you: no details about you, no contents of your documents and no assessment; it grants no access to a case and does not change the price. MietKorrekt checks the code on the server when the case is started, discards an unknown or no longer active code, and records with the case only which partner it is to be attributed to. It is no part of the advertising measurement and is not transmitted to Google; your choice about the advertising measurement is neither required nor changed for it.
    • Nothing more: no search terms, no advertisement variant, not the page you came from, and no identifier from other advertising networks.
    • In addition, MietKorrekt records which of its own pages you started the case from — the remaining-value calculator, for example. That is a single word from a fixed, short list of our own pages. It is not a history: what pages you looked at before, for how long or in what order is not stored.
    • Nothing is stored in your browser for this: no cookie, no “localStorage”, no identifier that recognises you — not for the partner code either. The details are read from the address when the case is started; anyone who navigates to another page first loses them. A referral link therefore counts only for the visit in which you opened it; a later visit without the link is attributed to no partner.
    • A partner receives no data about you through this: no documents, no extracted details, no assessment, no letter, no details about your person and no payment data. The attribution serves MietKorrekt solely to know through which partner a case came about.
    • They are transmitted to nobody and are deleted with the case. That applies to the attribution to a partner as well; the partner's own record is independent of it and contains nothing about you.

    Counting at the remaining-value calculator

    The remaining-value calculator computes entirely in your browser. Your entries are not transmitted to MietKorrekt and are not stored anywhere.

    When a calculation is produced, we count it — and as sparingly as possible:

    • What is stored is one entry with three details: that a calculation took place, on which of our pages, and when (by our server's clock).
    • What is not stored is everything else: not the object chosen, not the age, not the amount, not the result, not the percentage, and not whether you stated “replacement” or “repair”.
    • The entry contains no identifier: no case number, no cookie, no visitor or session identifier, no IP address, no device identifier and no browser identification string.
    • Because the entry is connected to no case and no person, it cannot be attributed to one either — and it is therefore not deleted together with a case. There is nothing in it that could be deleted.
    • This is to be distinguished from the usual access logs of our hosting provider, which arise with every page view. They are described elsewhere in this notice and are not part of this counting.

    Changing your choice

    You can change your answer at any time under “Privacy settings” at the bottom of every page. A withdrawal takes effect immediately.

    If you withdraw inside your case, a click identifier stored there is removed in the process. On a general page your withdrawal likewise applies immediately, but an identifier held with an earlier case cannot be removed from there. Either way it is not used: without current consent no measurement takes place.

    Declining has no disadvantages: the check works fully without consent — uploading, reading, assessment, letter, assessment report and payment are unaffected. If you do not answer, that counts as declining.

    Applying to the affiliate programme

    On the “Affiliate programme” page, creators, blogs, newsletters and communities can apply to become MietKorrekt partners. The form is separate from your case: it belongs to no case, uses no case key and reads nothing from your browser.

    • What is stored: the name given (a person, a creator or a company), the e-mail address, the chosen channel, the profile or website address given, an optional short note and the language of the form.
    • What for: to review the application and to contact the applicant. For nothing else – not for advertising, not as customer data, not for the processing of a case.
    • Who has access: exclusively the operator, internally. Applications are transmitted to nobody and published nowhere.
    • What does not happen: an application activates nothing automatically. No account and no referral link is created; whether somebody becomes a partner is decided by the operator, by hand.
    • On acceptance: the name, e-mail address, channel and profile or website address move into the partner's record, which the operator keeps for the partnership. From the application itself, the name, the e-mail address, the address and the note are removed in the same step; the note is copied nowhere and not archived. What remains of the application is when it came in, when it was accepted, in which language, for which channel and which partner it became.
    • What is not collected: no postal address, no phone number, no bank details, no tax data, no identity documents, no access credentials, no IP address.
    • How long: open applications are kept until they are decided. Rejected applications are deleted by the operator as part of routine cleanup; there is currently no automatic deletion period, and rejected applications are not kept in order to prevent a later application. You can request deletion of your application at any time through the address given in the legal notice.

    Your rights and how to get in touch

    You can request information about the data processed about you, ask for it to be corrected or deleted, and object to the processing.

    MietKorrekt does not know who you are: there is no account and no detail with which a case could be attributed to a person. For information about, or deletion of, a particular case, the case link is therefore needed. You can delete the case yourself at any time using “Delete case”.

    Address enquiries to the controller named above.

    Status of this page

    Last revised: 20. August 2026. The details about the processors were checked against their terms on 19. August 2026; the details about Stripe on 23. August 2026; the details about the deployment — providers, regions, plan and logs — were confirmed on 20. August 2026.

    This page is adjusted as soon as the processing changes.

    Privacy settings

    MietKorrekt can measure, with your consent, whether a click on a Google advertisement led to a paid case. If you agree, a report is transmitted to Google after a paid check. Without your consent this does not happen.

    What is transmitted – and what is not

    The check itself works fully regardless — uploading, assessment, letter and payment are unaffected. You can change your choice at any time under “Privacy settings” at the bottom of every page.

    More in the privacy notice