Privacy
Privacy-first setup: this website uses a minimal first-party aggregate event counter, but no third-party analytics, advertising pixels or analytics cookies. The event counter stores aggregate counts only and does not create a persistent analytics user ID.
1. Controller
Unicorn Asset Management GmbH
Weidenbornstraße 8a
65189 Wiesbaden
Germany
Managing Director: Sebastian Diemer
Email: sebastian@unicorn.management
2. Hosting and server log files
This website is hosted on webspace provided by united-domains GmbH, Gautinger Straße 10, 82319 Starnberg, Germany. When you access the website, technical connection data may be processed in server log files. Depending on the technical configuration, this can include the requested page or file, date and time of access, transferred data volume, browser and operating system information, referrer information and the requesting IP address.
The processing is carried out to securely and reliably provide the website, detect technical errors and protect the systems against misuse. The legal basis is Art. 6(1)(f) GDPR (legitimate interests in secure and technically reliable website operation).
3. Cookies, local storage and aggregate analytics
This website uses aggregate first-party counters for page views and actions such as opening the prompt, creating a card image, publishing a share link and privacy-safe traffic source categories such as Instagram, search or direct/unknown. These counters contain event totals, not audit text, raw referrer URLs, image data, public card identifiers or deletion credentials. No third-party analytics service or persistent analytics visitor identifier is used.
The result page keeps your selected positive statements, traits, archetype and publishing state in browser session storage so a reload does not lose the result. This data is local to the browsing session; browser session restoration may retain it. If storage is blocked, the original result link in your chat remains usable. The website does not read the contents of your AI conversation.
Requests for a ChatGPT prompt source are recorded in a bounded diagnostic log: timestamp, audit ID, HTTP method/status, a shortened user-agent label, server processing time and a random request identifier. This log does not include your IP address, referrer, cookies, audit text or a persistent visitor ID. It holds up to 2 MB of recent entries. A source request does not establish that an audit started or completed; it is not linked to your ChatGPT session.
4. External links
The website links to external services, including Instagram, YouTube, ChatGPT and Claude. No social-media plugin or embedded third-party content is loaded on this website. A connection to the respective external provider occurs only after you actively follow an external link or open the service.
Email signup
Email signup data collected through earlier versions remains on this webspace for the purpose previously consented to. You may withdraw consent by contacting sebastian@unicorn.management. The current page does not offer email signup or a message submission form.
If a third-party newsletter provider, analytics service or advertising technology is added later, this privacy notice and any necessary consent mechanism will be updated before use.
Earlier message submissions
Messages and optional email addresses submitted through earlier versions remain on the webspace for the purpose previously consented to. You may request their deletion by contacting sebastian@unicorn.management. Creating or sharing an Audit Card does not send a personal message or sign you up for email updates.
You may withdraw your consent with effect for the future and request deletion of your submitted message by contacting sebastian@unicorn.management.
Audit Card images and public share pages
When you open a card link from your AI chat, the text after the # is read in your browser. That URL fragment is not sent in the HTTP request. The result page removes the fragment from the current address bar after reading it. The original link can still exist in your chat, browser history or any copies you share. A link containing personal text is not encrypted or access-controlled.
Story images are generated locally in your browser. Selecting “Publish my page” asks us to publish the displayed positive statements, traits, archetype and a preview image as a page anyone with its link can access. The legal basis is your consent under Art. 6(1)(a) GDPR. Only publish information you want to make public; omit names and sensitive information. The rest of your chat or audit is not uploaded. New summaries do not request your name. Published pages are automatically taken offline and their stored card data and preview image are deleted after approximately 7 days; creators may delete them earlier. Short public addresses are aliases; they are not passwords or access controls.
Public cards are stored on this webspace for approximately 7 days and are then automatically deleted when next accessed or during normal publishing activity. A secret deletion credential can be stored in this browser so you may remove a page earlier. If browser storage is unavailable or cleared, the page still expires automatically. You can also contact sebastian@unicorn.management to request earlier removal. Deletion removes the page and image from our service. We retain only an empty marker containing the public card identifier to prevent reuse of an old address; it contains no name, result text or image. This protects shared links against misuse. As before, other people’s copies and cached previews held by social platforms may remain.
To limit automated abuse of the publishing endpoint, we store short-lived request counters using a keyed hash of the requesting IP address. The publishing code does not store the raw IP address in these counters. Expired counters are removed on the next publishing request. Hosting access logs are handled as described above. Their purpose is secure website operation under Art. 6(1)(f) GDPR.
Selecting a system sharing option passes the image or link to the destination you choose. That app or platform then processes it under its own terms. Instagram Story posting and link stickers are controlled by Instagram; this website does not post to your account automatically.
YouTube thumbnails and links
The podcast preview images and Instagram photo backdrop are served locally by this website. Loading them does not connect to YouTube or Instagram. Clicking a podcast card or Instagram link opens the respective provider in a new tab.
5. Clipboard function
Compatibility mode uses your browser's local clipboard interface to copy the complete selected prompt when you continue to ChatGPT or press Copy prompt. The prompt is processed locally in your browser. The website does not transmit the copied text to us.
6. Your rights
Subject to the applicable legal requirements, you have rights including access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. You also have the right to lodge a complaint with a competent data protection supervisory authority.
7. Changes to this privacy notice
If new functions such as analytics, forms, newsletters, embedded media or advertising pixels are added later, this privacy notice and, where legally required, the consent mechanism must be updated before those functions go live.