Legal
Cookies
English below, Deutsch weiter unten.
This website sets no cookies. It stores nothing in your browser — no cookies, no local storage, no session storage, no pixels, no fingerprinting. There is no analytics tool of any kind. That is why you are not being asked to accept anything.
1. Why there is no banner
Under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG, which implements the ePrivacy Directive), consent is needed before storing information on, or reading information from, your device — unless that storage is strictly necessary to deliver the service you asked for.
We store nothing at all, necessary or otherwise. With nothing to consent to, a consent banner would be theatre. A banner that asks permission for storage that never happens is not compliance; it just trains people to click through.
2. What actually happens when you load a page
Your browser asks our host for the files that make up the page, and the host sends them. To do that the host necessarily sees the request — your IP address, the time, the page requested, the referring page, and your browser and device type. That is connection data, not a cookie: it is not stored on your device and cannot be used to recognise you on a later visit.
The legal basis for that processing is Art. 6(1)(f) GDPR (operating and securing the site). It is covered in full in the privacy policy and the Datenschutzerklärung.
3. Everything the page loads
Every file the site needs comes from our own domain. No request leaves for a third party while you read a page:
- Fonts — Space Grotesk, IBM Plex Mono, and Archivo are served from
/fonts/on this domain. They were previously loaded from Google Fonts, which sent your IP address to Google on every visit; they are now self-hosted, so that no longer happens. - Images and drawings — the mark is an inline SVG, and the illustrations are drawn in the browser with code. Nothing is loaded from an image CDN.
- No embeds — there is no YouTube or Vimeo player, no map, no social widget, no comment system, no chat bubble, no A/B testing tool, no tag manager, no advertising script.
External links, such as the one to metiscale, only contact the other site once you click them. They carry rel="noreferrer", so the destination is not told which page you came from.
4. Things that are not cookies but are worth stating
- Our host (Google Firebase Hosting) serves the files. Static hosting of this kind sets no cookie. Firebase’s
__sessioncookie applies only to server-rendered or Cloud Function responses, which this site does not use. - The subscribe field on the home page opens your own email program. It stores nothing in your browser and sends nothing anywhere until you press send in your mail client. See privacy policy.
- The sign-in callback at
/overlap/auth/callbackforwards the parameters in the URL straight to the Overlap app and keeps nothing. - The Overlap app itself is not this website. Being an app, it stores a sign-in token on your phone so you do not have to log in each time. That is strictly necessary for a service you asked for, and it is described in the privacy policy.
5. If this ever changes
If we add analytics, embedded video, a hosted newsletter form, or anything else that writes to your device or calls a third party, then consent becomes necessary. In that case we will add a real consent banner — one that asks first, works without dark patterns, makes refusing exactly as easy as accepting, and loads nothing before you choose. We will update this page at the same time.
6. Contact
hello@heylabapp.com — postal address in the Impressum.
Last updated: 7 September 2026
Rechtliches
Cookies
Deutsche Fassung. English version above.
Diese Website setzt keine Cookies. Es wird nichts in Ihrem Browser gespeichert — keine Cookies, kein Local Storage, kein Session Storage, keine Zählpixel, kein Fingerprinting. Es ist keinerlei Analysewerkzeug im Einsatz. Deshalb werden Sie um keine Einwilligung gebeten.
1. Warum es kein Banner gibt
Nach § 25 TDDDG (Umsetzung der ePrivacy-Richtlinie) ist eine Einwilligung erforderlich, bevor Informationen auf Ihrem Endgerät gespeichert oder aus ihm ausgelesen werden — es sei denn, die Speicherung ist für den von Ihnen ausdrücklich gewünschten Dienst unbedingt erforderlich.
Wir speichern überhaupt nichts, weder erforderlich noch sonst. Wo es nichts einzuwilligen gibt, wäre ein Einwilligungsbanner reine Fassade. Ein Banner, das um Erlaubnis für eine Speicherung bittet, die nie stattfindet, ist keine Rechtstreue, sondern gewöhnt Menschen nur daran, wegzuklicken.
2. Was beim Seitenaufruf tatsächlich passiert
Ihr Browser fordert die Dateien der Seite bei unserem Hoster an, und dieser liefert sie aus. Dabei sieht der Hoster zwangsläufig die Anfrage: IP-Adresse, Zeitpunkt, aufgerufene Seite, Referrer sowie Browser- und Gerätetyp. Das sind Verbindungsdaten, kein Cookie — sie werden nicht auf Ihrem Gerät abgelegt und erlauben kein Wiedererkennen bei einem späteren Besuch.
Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (Betrieb und Sicherheit der Website). Einzelheiten in der Datenschutzerklärung.
3. Alles, was die Seite lädt
Sämtliche Dateien stammen von unserer eigenen Domain. Beim Lesen einer Seite geht keine Anfrage an Dritte:
- Schriften — Space Grotesk, IBM Plex Mono und Archivo werden unter
/fonts/von dieser Domain ausgeliefert. Früher wurden sie von Google Fonts geladen, wobei bei jedem Aufruf Ihre IP-Adresse an Google übermittelt wurde; sie sind nun selbst gehostet, sodass dies entfällt. - Bilder und Zeichnungen — die Marke ist ein eingebettetes SVG, die Illustrationen werden im Browser per Code gezeichnet. Es wird nichts von einem Bild-CDN geladen.
- Keine Einbettungen — kein YouTube- oder Vimeo-Player, keine Karte, kein Social-Widget, kein Kommentarsystem, kein Chat-Fenster, kein A/B-Testing, kein Tag-Manager, kein Werbeskript.
Externe Links, etwa zu metiscale, nehmen erst Kontakt auf, wenn Sie sie anklicken. Sie tragen rel="noreferrer", sodass dem Ziel nicht mitgeteilt wird, von welcher Seite Sie kommen.
4. Kein Cookie, aber erwähnenswert
- Unser Hoster (Google Firebase Hosting) liefert die Dateien aus. Statisches Hosting dieser Art setzt kein Cookie. Das Firebase-Cookie
__sessionbetrifft nur serverseitig gerenderte Antworten bzw. Cloud Functions, die hier nicht eingesetzt werden. - Das Abonnement-Feld auf der Startseite öffnet Ihr eigenes E-Mail-Programm. Es speichert nichts im Browser und übermittelt nichts, bevor Sie in Ihrem Mailprogramm auf Senden drücken.
- Die Anmelde-Weiterleitung unter
/overlap/auth/callbackreicht die Parameter aus der URL unmittelbar an die App weiter und behält nichts. - Die App Overlap ist nicht diese Website. Als App speichert sie ein Anmelde-Token auf Ihrem Telefon, damit Sie sich nicht jedes Mal neu anmelden müssen. Das ist für den von Ihnen gewünschten Dienst unbedingt erforderlich und in der Datenschutzerklärung beschrieben.
5. Falls sich das ändert
Sobald wir Analyse, eingebettete Videos, ein gehostetes Newsletter-Formular oder sonst etwas einsetzen, das auf Ihr Gerät schreibt oder Dritte aufruft, wird eine Einwilligung erforderlich. Dann ergänzen wir ein echtes Einwilligungsbanner — eines, das vorher fragt, ohne Dark Patterns auskommt, das Ablehnen genauso einfach macht wie das Annehmen und vor Ihrer Wahl nichts lädt. Diese Seite wird gleichzeitig aktualisiert.
6. Kontakt
hello@heylabapp.com — Postanschrift im Impressum.
Stand: 7. September 2026