Skip to content
Künstlerfinanzen Sign in Deutsch

Security and data processing

You are trusting this application with your income figures. This page says what happens technically, who apart from you gets to see anything — and what is not yet provided here. The last part is the most important.

What can be verified in the code

These statements can be checked in the open source code:

ItemImplementation
PasswordsStored as a bcrypt hash, never in plain text.
Sign-inJSON Web Token, valid for 30 days.
Password changeInvalidates all older tokens immediately — anyone still signed in is signed out.
Forgotten passwordAt most three requests per email address per hour. The token is stored in the database only as a SHA-256 hash.
TransportHTTPS enforced, HSTS for one year including subdomains.
HeadersX-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin, no identifier of the application or of the storage — only Server: CloudFront, which the delivery service sets itself.
Database and backupsStored encrypted. Backups are made automatically every day, kept for 14 days and are encrypted as well.
ReachabilityThe database has no access to the internet. The application can only be reached through the address of this website, not directly.
CookiesNone. Neither on this site nor in the application — the sign-in is kept in your browser's localStorage.
Statistics and trackingNone. No analytics service, no tracking pixel, no fonts embedded from third-party servers.

Because no cookies are set and no data is passed to third parties, there is no consent banner here either. That is not a sacrifice, but the consequence of loading nothing that would need consent.

What is stated openly here instead of being kept quiet

Hosting and service providers

PurposeService providerLocation
Application and databaseAmazon Web ServicesFrankfurt am Main
BackupsAmazon Web ServicesFrankfurt am Main, copy in Ireland (EU)
Sending emailAmazon Simple Email ServiceFrankfurt am Main
Email to info@kuenstlerfinanzen.deAmazon Simple Email Service, forwarded to Google (Gmail)Ireland (EU); Google also outside the EU
Delivery of this websiteAmazon CloudFrontCaches in Europe and North America
Payment processingStripe (Stripe Payments Europe, Limited)Dublin, Ireland

Only if you use the one-time fetch from Lexware Office or sevDesk: Künstlerfinanzen uses the API key you paste for it to fetch your paid vouchers from your own account there. The key is used for that one fetch only and is neither stored nor logged; nothing is taken over until you confirm it in the preview.

Data processing agreements under Art. 28 GDPR (DSGVO) are in place with Amazon Web Services and Stripe as part of their terms. Which data goes where is set out in the privacy policy (Datenschutzerklärung, in German).

What this application does not do

Found something?

If you notice a vulnerability, please report it to info@kuenstlerfinanzen.de. We confirm receipt and get back to you, even if the report turns out not to be confirmed.

Page last checked: 2026-10-03.