Skip to content
KRPUSCOMING SOON

COMING SOON

Korpus is in early development and sign-up is not open yet.

What this page shows is built and running on our test system. Features, limits and prices may still change before launch.

Want early access or a demo? Write to me@till-it-works.de.

LEGAL

Privacy Policy

Effective September 23, 2026

1. Controller

Tilman Krauß
Tillitworks - IT Dienstleistungen
Bismarckstraße 17a
42799 Leichlingen
Germany

Email: me@till-it-works.de · Phone: +49 1577 5976707

2. Overview

This policy has one part for each: Part A covers the website korpus.cloud. Part B covers the Korpus app: the web app at fra.korpus.cloud, its REST API at api.fra.korpus.cloud and its MCP server at mcp.fra.korpus.cloud. What applies to both, such as contact, your rights and changes, is in Part C.

In short:

Part A · The website korpus.cloud

A.1 Hosting

The website is a static site, served from Amazon S3 through Amazon CloudFront by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. To deliver a page, CloudFront has to process your IP address, the requested address, time, browser type and data volume. We have not switched on access logs, so we do not keep these data.

The site is stored in Frankfurt. CloudFront may deliver it from an edge location in Europe or North America; see C.4 on transfers. We have a data processing agreement with AWS under Art. 28 GDPR.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to deliver the website securely and reliably.

A.2 Fonts

The fonts are served from our own domain, on the website and in the app. No request goes to Google or any other third party.

A.3 Cookies and local storage

The website sets no cookies. If you choose a light or dark theme, the choice is saved in your browser's local storage and never leaves your device. This is needed for the function you ask for (§ 25(2) no. 2 TDDDG).

A.4 Links

The website links to the Korpus app (Part B) and to external sites, whose operators are responsible for their own privacy practices.

Part B · The Korpus app

B.1 Your account

To use Korpus you create an account. We store:

Sign-in runs through Amazon Cognito, with a passkey or with a one-time code sent to your email address. For a passkey, Cognito stores only its public key. The codes and other account emails (sign-up, change of email address) are sent through Amazon SES from no-reply@fra.korpus.cloud. We send no newsletters or marketing email.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract).

B.2 Content you store

In a bundle you store concepts (markdown documents), data-table rows, files (assets), relations and their revisions. Korpus records who made each change, so every write carries:

The bundle's members can see this attribution. Changes are also listed in the bundle's activity log. When someone @mentions you, a notification is stored for you.

Files are stored in Amazon S3 and encrypted at rest. They can be downloaded only through short-lived signed links.

Personal data of other people in your content. If you store personal data of other people in Korpus, for example names in a runbook or notes from a customer call, you decide why and how it is processed. For that content we act as your processor under Art. 28 GDPR. A data processing agreement (AVV) is available on request.

Legal basis for your own data: Art. 6(1)(b) GDPR.

B.3 Sharing, invitations and publishing

You can invite people to a bundle by username or email address. If the address has no account yet, the invitation stores that email address until it is accepted, declined or withdrawn. Invitations are shown in the app; we send no invitation email. Members of a bundle see its content and who wrote what.

If you publish a bundle to the Korpus catalog, each version is a copy of the bundle's current content. The copy carries no author email addresses and no earlier revisions. Our reviewers read each version before it appears. Published versions are visible only to signed-in Korpus users, not to the public internet.

Other users can follow a published version or clone it. A clone is the other user's own bundle from then on. It stays with them when you remove the version or delete your account.

Legal basis: Art. 6(1)(b) GDPR.

B.4 Agents and connected AI apps

You can create agents in Korpus and connect AI apps to them over MCP or REST, for example Claude, ChatGPT or Cursor. Each connection signs in through our own OAuth server. For agents and connections we store:

An access token is valid for 1 hour. A refresh token is valid for 30 days and changes on every use. An app registration that is never used expires after 90 days.

What the AI app does with your content. A connected app reads and writes your content within the rules you set for its agent. What the app and its provider do with that content is governed by your own agreement with that provider. That provider is not our processor, and you decide which apps you connect. You can revoke a connection at any time.

Legal basis: Art. 6(1)(b) GDPR.

B.5 Payments (Plus)

Plus is sold through Stripe Managed Payments. The merchant of record is Sold through Link, LLC (link.com), a Stripe company. It sells you the subscription, takes the payment, issues receipts and invoices, and handles taxes. For that sale it is a controller of its own; its privacy policy applies. Payments are processed by Stripe Payments Company or Stripe Technology Europe, Limited.

When you start a checkout, we give Stripe your email address and your account ID, so the subscription can be matched to your account. Your card or other payment details go to Stripe directly and never reach us. We store:

Legal basis: Art. 6(1)(b) GDPR.

B.6 Cancellation and withdrawal

You can cancel or withdraw from Plus without signing in, on the page Cancel or withdraw contracts here. The form asks for your name, your email address, whether you cancel, withdraw or cancel for cause, and, for a cancellation for cause, your reason.

We use these data to find the subscription and carry out your declaration. A withdrawal within 14 days refunds you in full and ends Plus at once. We confirm receipt by email to the address you gave, sent through Amazon SES, and send a copy to our own inbox. The declaration is recorded in the audit trail (B.8). To stop the page from being used to flood a mailbox, we remember the address for 15 minutes and send one confirmation per address in that time.

Legal basis: Art. 6(1)(c) GDPR, together with § 312k and § 356a BGB, which require this page and the confirmation.

B.7 Operation and moderation

Korpus is run by the controller named in section 1, the operator. To support you, keep the service secure, act on abuse or illegal content, meet legal duties, or review a submitted publication, the operator can open any bundle, read only. Every such opening is logged in the audit trail (B.8).

The operator can block an account. A block stores when it was made, by whom, and an optional note about the reason. For good cause, the operator can also delete an account; see sections 8 and 11 of the Terms of Service.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to run the service securely and lawfully.

B.8 Audit trail

A few events are written to an audit trail, so we can tell later who did what and when:

Each entry holds the account ID, the time, the event and, where it applies, the username at sign-up or rename, the agent and the surface used (web, REST or MCP). It holds no email address and no content.

The audit trail is kept for 2 years, also after an account is deleted. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to keep the service secure and to be able to explain changes and resolve disputes.

B.9 Usage metering

Every plan has usage limits. To apply them, we keep counters per account: short-term read and write rates, and how much of a session and a weekly allowance you have used. They are kept until you delete your account. Legal basis: Art. 6(1)(b) GDPR.

B.10 Security and technical data

IP addresses. Amazon's services process your IP address for as long as it takes to deliver a request and to apply request limits. We do not store it.

Signed-in browsers. For each browser you sign in with, we store its device description (the user agent) and when it was first and last used. This lets you see your sign-ins and end them. Each record is deleted 30 days after it was last used.

Error logs. Our servers log errors without request contents and keep them for 30 days.

Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is to run the service securely and reliably.

B.11 How long we keep data

When you delete your account, we end any Plus subscription at once, delete the bundles you own alone, with their files, and remove you from all other bundles. We also revoke your connections and delete your agents, sessions and account records.

Content you wrote in bundles that other people own stays there, because it is part of their record. It keeps your former account ID, which from then on shows as "deleted user". It also keeps the email address stored with each revision until the owners delete that content or the revision expires.

Receipts and invoices for Plus are issued and kept by Sold through Link, LLC (B.5), under the retention periods that apply to it.

B.12 Cookies and local storage

Korpus sets no cookies. The app keeps a few entries in your browser's local or session storage:

These entries are needed to provide the service you ask for (§ 25(2) no. 2 TDDDG) and never leave your device, except the sign-in token, which is sent with each request. No consent banner is required.

B.13 Processors and recipients

ServiceProviderPurposeLocation
Hosting, database, file storage, sign-in, emailAmazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 LuxembourgDynamoDB, S3, Lambda, API Gateway, Cognito, SES, CloudFrontEU (Frankfurt); CloudFront edge locations in Europe and North America
Sale and payment of PlusSold through Link, LLC; payments processed by Stripe Payments Company or Stripe Technology Europe, LimitedMerchant of record, a controller of its own (B.5)USA and EU

We have a data processing agreement with AWS under Art. 28 GDPR (the AWS Data Processing Addendum). We use no other processors.

Part C · Both

C.1 Contact by email

If you write to us, we process your email address and your message to answer it.

Legal basis: Art. 6(1)(b) GDPR where your request concerns a contract, otherwise Art. 6(1)(f) GDPR. Our legitimate interest is to answer requests. We delete the message once it is dealt with, unless we must keep it by law.

C.2 Your rights

You have the right to:

You can read out all your content at any time through the web app, the REST API or MCP, and you can delete your account in the app. For anything else, write to me@till-it-works.de.

You need to give us an email address to have an account; without one we cannot provide the service. We make no automated decisions under Art. 22 GDPR.

C.3 Right to lodge a complaint

You can complain to a data protection supervisory authority. The authority responsible for us is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf, Germany
www.ldi.nrw.de

C.4 Transfers to third countries

The website, your account and your content are stored in the EU (Frankfurt). AWS is part of Amazon.com, Inc., a US company. CloudFront may deliver a response from an edge location outside the EU. Sold through Link, LLC and Stripe Payments Company are US companies. Such transfers rest on the EU-US Data Privacy Framework (an adequacy decision under Art. 45 GDPR) and on standard contractual clauses.

C.5 Changes

We update this policy when the service or the law changes. We tell account holders about material changes by email or in the app. The current version is always at korpus.cloud/privacy.