Privacy Policy

Version of 30 September 2026. This policy covers the website coworking.live and the "Coworking" browser extension.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Mussie Haile
Lohmühlenstraße 65, 12435 Berlin, Germany
Email: contact@coworking.live · Phone: +49 176 87053245

We are not legally required to appoint a data protection officer. For all data protection matters, please contact us at the address above.

2. Overview

We process personal data only to the extent necessary to provide our website and extension, and in accordance with the GDPR, the German Federal Data Protection Act (BDSG) and the Telecommunications Digital Services Data Protection Act (TDDDG). We do not sell personal data. We currently do not use it for advertising and do not use analytics or tracking tools on this website or in the extension.

3. Visiting this website

Hosting and server log files

This website is hosted by Vercel Inc., USA ("Vercel"). When you access the website, the browser automatically transmits information that is stored in server log files: IP address, date and time of the request, requested page, referrer URL, browser type and version, and operating system. This data is not combined with other data sources.

Legal basis: Art. 6 (1)(f) GDPR. Our legitimate interest lies in the secure, stable and efficient delivery of the website and in detecting and defending against attacks. Vercel processes this data on our behalf under a data processing agreement (Art. 28 GDPR). For transfers to the USA, see section 8.

No cookies, no tracking, no external content

This website does not set cookies, does not store information on your device and does not load fonts, scripts or other content from third-party servers. Consent under § 25 TDDDG is therefore not required, and we don't show a consent banner. Links to external sites (such as the Chrome Web Store) only transmit data to the respective provider once you click them.

4. Using the extension

The "Coworking" extension lets you create and join rooms, share a pomodoro timer, see who is present and chat. Using the extension requires an account.

Data we process

Legal basis: Art. 6 (1)(b) GDPR (performance of the contract of use, see our Terms). For technical log data: Art. 6 (1)(f) GDPR, based on our legitimate interest in operating the service securely.

Visibility to other users

Your display name, presence, status, chat messages and timer actions are visible to the other members of the rooms you join. Please don't share information in rooms that you don't want other members to see.

Backend (Supabase)

Account and app data are stored and processed by Supabase, Inc. ("Supabase") as our processor under a data processing agreement (Art. 28 GDPR). The database is hosted in the EU (Frankfurt am Main, Germany). Supabase processes server logs, including IP addresses, to operate and secure the service. Support or maintenance access from outside the EU cannot be ruled out; see section 8.

Storage on your device

The extension stores your sign-in session and a few interface preferences (for example, tips you have dismissed) in the browser's extension storage. This is strictly necessary to provide the service you have expressly requested (§ 25 (2) no. 2 TDDDG). The session is removed when you sign out; preferences are removed when you uninstall the extension.

Browser permissions

The extension uses the Chrome permissions "storage" (sign-in session and preferences), "identity" (Google sign-in), "sidePanel" (display) and "notifications" (notice when a timer phase ends). It does not request access to the content of websites, your browsing history, camera or microphone.

Chrome Web Store

The extension is distributed through the Chrome Web Store, operated by Google. Google processes data in connection with the installation and updates under its own responsibility and privacy policy.

The use of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

5. Sign-in with Google

You sign in with your Google account. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). When you sign in, you are redirected to Google; Google then transmits your name, email address and a user identifier to us. We do not receive your Google password. Legal basis: Art. 6 (1)(b) GDPR. Google processes data in connection with the sign-in under its own responsibility; see Google's Privacy Policy.

6. Contacting us

If you contact us by email or phone, we process the data you provide (for example name, email address and the content of your message) to handle your request. Legal basis: Art. 6 (1)(b) GDPR if your request relates to the use of our services, otherwise Art. 6 (1)(f) GDPR (our legitimate interest in answering enquiries).

7. Recipients and processors

Personal data is only disclosed where this is necessary for the purposes described above:

8. Transfers to third countries

Some of our service providers are based in, or may access data from, countries outside the EU/EEA, in particular the USA. Where no adequacy decision exists, transfers are based on appropriate safeguards, in particular the EU Standard Contractual Clauses (Art. 46 (2)(c) GDPR). For providers certified under the EU-US Data Privacy Framework, transfers are based on the European Commission's adequacy decision (Art. 45 GDPR).

9. Storage period

We store personal data only as long as necessary for the purposes described, or as long as statutory retention obligations require. In particular:

Backups are overwritten in regular cycles; deleted data may remain in backups until they expire.

10. Security

We use appropriate technical and organisational measures to protect your data, including encrypted transmission (TLS) and access controls in the database. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Your rights

Under the GDPR you have the right to:

To exercise your rights, including deleting your account, contact us at contact@coworking.live. We may ask you to confirm your identity. The supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin, Germany. You can also contact the supervisory authority in your place of residence or work.

12. Right to object (Art. 21 GDPR)

Where we process your data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

13. Other information

Obligation to provide data

You are not legally or contractually obliged to provide personal data. However, the extension cannot be used without an account and the data described in section 4. The website can be used without providing any data beyond the technical data described in section 3.

No automated decision-making

We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.

Children

Our services are not intended for persons under 16. We do not knowingly process data of children under 16.

Former coworking.live web app

Until 2026, coworking.live offered a separate web app, which has been discontinued. If you had an account there and would like your data deleted or want to know what we store, contact us at contact@coworking.live.

Changes to this policy

We may amend this privacy policy to reflect changes in our services or the law. The version published on this page at the time of your visit applies.