Privacy principles

Make information handling visible.

Privacy begins with clear boundaries: what a product reads, where work runs and what leaves the device must be understandable.

EisKaffee products are still in development. These principles describe the intended design direction and the current public website boundary; they are not a substitute for a product-specific privacy notice before release.

Prefer local understanding

The architecture should allow local files, local catalogues and local processing to remain local when the selected feature does not require a remote service.

Make every destination explicit

Storage and processing destinations should be named. Local disks, network storage and cloud providers can require different handling, but the product should explain the choice through one consistent interface.

Send only what the feature needs

Any feature that uses a remote service should define the minimum input, the purpose of the transfer, the retained result and the failure behaviour before it is enabled.

Current website and preview

The public website is informational. The Vanilla preview is view-only and uses invented sample data. It is not intended for uploading personal photo libraries or financial information.