Transparent & concrete
Privacy policy
As at: 7 September 2026
The German version of this page is the binding one. This English translation is provided for understanding only. Read the German version
1. Controller
CLUSTER ONE GmbH, Grüner Winkel 21, 41065 Mönchengladbach, Deutschland, represented by its managing director Marlon Meuters.
Email: [email protected]
Phone: +49 2161 27298 40
2. What data the application processes
Depending on the features you use, we process:
- technical connection and security data, such as IP address, time, browser/app information and server logs,
- sign-in and account information, where access is protected by the platform sign-in,
- training configurations (including an optionally stored training focus), product knowledge, website URLs and uploaded text or PDF content,
- pasted conversation transcripts and the training assessments produced from them,
- when the reporting function is used — in the app as well as on this website: the reported AI content, the reason for the report, an optional comment, the origin (web, iOS or Android) and the time,
- saved conversation partners: the person invented by the AI (name, role, background, way of speaking, typical objections), the situation it grew out of, a title you gave it yourself and the chosen voice — so that the same person can be called again in the app and on the web,
- training histories and settings stored locally on the device.
Please do not enter special categories of personal data, trade secrets or information about third parties where this is not necessary for the training and not legally covered.
3. Purposes and legal bases
We process data in order to provide the service, to build sales scenarios, to assess pasted conversation transcripts, to prevent misuse and to ensure technical security. Depending on the use, the legal bases are Art. 6(1)(b) GDPR (contract or pre-contractual measures) and Art. 6(1)(f) GDPR (secure and economical operation). For the voluntary spoken conversations — the role play and the preliminary talk in which you describe your situation — Art. 6(1)(a) GDPR applies in addition: you give your consent by starting them and allowing microphone access (section 5). Without such a conversation no microphone processing takes place.
4. Hosting, delivery and access protection
The web application and the interface run on a server operated by us in a data centre in Germany. Delivery goes through the network of Cloudflare (Cloudflare Germany GmbH, Rosental 7, 80331 München, as the contracting party for the EU; parent company Cloudflare, Inc., USA), which acts as a reverse proxy and protects against attacks. In doing so, IP address, time, requested address, browser identification and technical status data are processed.
To protect against misuse we limit the number of requests per IP address and for that purpose store the IP address together with a counter in our database for at most ten minutes. In addition the server issues a short-lived access token bound to the IP address, which is kept in the browser only for the current session and in the app only in memory. The legal basis is Art. 6(1)(f) GDPR (provision and security of the service).
Further information: Cloudflare privacy policy.
5. AI processing by OpenAI
For offer analysis, scenario preparation and the assessment of a conversation transcript, the inputs needed for this are transmitted to the OpenAI API. The responsible contracting party for customers in the EEA is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117‑126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland.
Spoken conversations (voluntary). If you start a role play under “Jetzt live sprechen” or a preliminary talk under “Mit dem Coach besprechen”, your browser asks for access to your microphone. A direct WebRTC connection is established between your device and OpenAI; in the process your microphone signal and your IP address are transmitted to OpenAI and processed there for the duration of the conversation. We set up the connection — we send the instructions for it from our server — and do not receive the other side’s audio ourselves. So that your own sentences also appear in the feedback, during the role play your device additionally sends short pieces of your microphone signal (about five seconds each) to our server, which passes them on to OpenAI’s transcription and returns only the text to you. We store neither the pieces nor the text; it appears in your history only together with your feedback. The same applies to the preliminary talk with the coach; only what the coach says is written down there, and that text reaches our server only when you have a scenario built from it.
Trial conversation without an account. On the home page a predefined conversation can be held without signing in. No user account is created, and we store neither the conversation nor its transcript. For the duration of the conversation the same is processed as described above — microphone signal and IP address at OpenAI. In addition we store your IP address in the form described in section 4, in order to limit the number of trial conversations per caller; without that limit the offer could not be free of charge. The legal basis for the conversation is your consent (Art. 6(1)(a) GDPR), for the limit our legitimate interest in protection against misuse and cost (Art. 6(1)(f) GDPR).
We make no audio recording. No audio recording is created here and none is stored anywhere. What is written down as text during the conversation stays in your browser; it leaves the browser only when you send it yourself under “Auswerten”. The legal basis is your consent (Art. 6(1)(a) GDPR), which you give by starting the conversation and allowing microphone access; you can withdraw it at any time by hanging up.
The live conversation is one of two routes. Instead you can take the scenario to ChatGPT or Claude and hold it there in your own account — then no voice connection is established here. Section 8 describes what is transmitted in that case.
We send Responses requests with store: false set. According to OpenAI, API content is by default not used to train the models. Security and abuse logs can, under the API data controls applicable at the time, generally be retained for up to 30 days, unless different data controls have been agreed.
The legal basis is Art. 6(1)(b) GDPR. The basis for the processing on our behalf and for any transfers to third countries is the OpenAI data processing agreement and the standard contractual clauses it provides for.
6. Product knowledge, files and external websites
Uploaded PDFs and text files are read out on the server and handed to the AI for the requested analysis. Files are not kept by the application as permanent file storage. When a product URL you have given is fetched, the operator of the target website necessarily receives a server request including IP address and user agent. Only fetch websites whose use is permitted for this purpose.
7. Local storage on the device
Training history, saved conversations and temporary session settings are kept in the local storage of the browser or the app. This data generally stays on the device used until it is deleted in the application or through the browser/app data. If you are signed in, saved conversations and your offers are additionally stored in your account (section 11) so that you see them on other devices; deleting them in the application removes them there as well. With every AI assessment, your current contribution, the last ten conversation contributions, the structured offer fields (product, price, benefit, target customers, conversation goal, evidence, needs questions, objections) and an extract of up to 3,000 characters of your product knowledge are transmitted to our server and then to OpenAI.
8. Handover to ChatGPT or Claude
Only when you choose the corresponding button do we put the generated prompt into your clipboard and open the page of the chosen provider. Nothing is transmitted from us: only when you paste the text there does it reach ChatGPT (OpenAI) or Claude (Anthropic). The prompt contains the invented conversation partner and the scenario data you entered (industry, role and, where the module provides for it, the product name).
Important: this processing takes place in your own account with the respective provider. There is no data processing agreement with us for it and no joint controllership; the provider’s terms alone apply – including the question of whether it uses the content to improve its models. That differs from our own use of the OpenAI interface (section 5). The handover is optional.
9. Assessment of conversations held elsewhere
If you have held a conversation at ChatGPT or Claude, you can paste the transcript here and have it assessed. The pasted text is then transmitted to OpenAI together with the offer fields of your scenario (as described in section 5) and the result is stored in your account under “Trainings” – marked as held elsewhere. The legal basis is Art. 6(1)(b) and (f) GDPR; this entry is deleted along with your account.
Please do not paste personal data of third parties. You are responsible for the content you transmit.
10. Reporting AI content
In the app and on this website, AI replies and training assessments can be reported immediately. We process the selected content, the reason for the report, an optional comment, the platform and the time, in order to examine safety problems, inappropriate content and errors. Reports are stored in our database, used only for security, fault fixing and improvement of the service, and deleted at the latest 90 days after the examination is closed.
11. Account, sign-in and history
A free account is needed for the AI features. We store your email address, the time of your sign-ins, sessions per device (browser or device identification as free text, times), the trainings stored in the account (configuration without product knowledge, transcript, assessments, duration), your saved offers and daily usage counters for the quotas. If you switch on reminders in the app, we additionally store your device’s push token, the chosen time, your time zone and your weekly goal; the message goes through the push service of Expo (Expo, Inc., USA) to Apple or Google – one sentence about your last conversation, never more than once a day. Switching it off deletes the token. An offer contains the fields you enter yourself – industry, product, price, benefit, target customers, conversation goal, evidence, needs questions, expected objections, URL and source name – and, unlike the trainings, your product knowledge as well. We store offers so that the same offer is available in the app and on the web; you can delete each one individually and at any time. Sign-in links are valid for 15 minutes, work once and are stored only as a hash. The session sits in the browser in an HttpOnly cookie (sct_session, 90 days rolling) or in the app in the device’s keychain. The legal basis is Art. 6(1)(b) GDPR.
The sign-in link is sent by an SMTP mail server operated by us. Under “Konto” you can export all account data as JSON (Art. 15 GDPR) and delete your account (Art. 17 GDPR); the deletion permanently removes sessions, trainings and counters.
12. Cookies, audience measurement and advertising
We currently use no audience measurement of our own, no personalised advertising and no marketing trackers. Technically necessary are the session cookie sct_session after sign-in (section 11), a cookie valid for 20 minutes sct_login_nonce, which binds a requested sign-in link to this browser, and possible security cookies from Cloudflare; the access token from section 4 sits in the browser’s session storage and is not a cookie.
13. Retention period
We store personal data only for as long as it is necessary for the respective purpose or for legal obligations. Locally stored training data remains until the user deletes it. Account data remains until the account is deleted; expired sessions and sign-in links are removed after one day at the latest, usage counters after 90 days. Counters for request limiting are overwritten after ten minutes, content reports deleted at the latest 90 days after they have been handled. For data held by processors, the contractual deletion and retention rules of the respective services apply.
14. Automated assessments
AI-generated scores and hints serve the training alone. They can be inaccurate and have no legal or similarly significant effect. No automated decision within the meaning of Art. 22 GDPR takes place.
15. Your rights
Subject to the statutory conditions, data subjects have in particular rights to information, rectification, erasure, restriction of processing, data portability and objection. Consent can be withdrawn with effect for the future. There is also a right to lodge a complaint with a data protection supervisory authority, in particular at the place of habitual residence, place of work or place of the alleged infringement.
16. Security and updates
We use appropriate technical and organisational measures to protect data. This policy is adjusted when features, service providers or legal requirements change.