Legal Β· Privacy

Privacy Policy

How we collect, use, and protect your data β€” in plain English.

Last updated: 28 June 2026

πŸ‡©πŸ‡ͺ Diese Seite auf Deutsch lesen

1. Who we are

The websites and services of Christian Albert Mueller β€” lps.world (including all subdirectories under /k/, /claw/, /christianalbertmueller/) and aros.ai with its subdomains β€” are operated by Christian Albert Mueller, an individual based in Munich, Germany. We are the "data controller" under the EU General Data Protection Regulation (GDPR) and equivalent laws.

Controller / Verantwortlicher Christian Albert Mueller
Schwanseestr. 47
81549 MΓΌnchen, Germany
USt-IdNr.: DE298983586
Email: hello@christianalbertmueller.com

Full contact details are in our Imprint.

Data Protection Officer

We have appointed an external Data Protection Officer (Datenschutzbeauftragter) you can contact directly with any privacy questions:

Prof. Dr. h.c. Heiko Jonny Maniero LL.B., LL.M. mult., M.L.E.
DG Datenschutz
Franz-Joseph-Str. 11
80801 MΓΌnchen, Germany
Tel: +49 (0)800 – 6264376
Email: info@dg-datenschutz.de
Web: dg-datenschutz.de

2. What personal data we collect

Data you give us directly

Data collected automatically

Data we do NOT collect

3. Why we collect it (legal bases)

Under GDPR, we rely on these legal bases:

4. How we collect it

5. Who we share data with

We use third-party processors β€” they only get the minimum needed to deliver their service:

We never share data with advertisers or data brokers.

5b. Where our emails come from

We send via Amazon SES from these verified domains:

The From address per send is chosen by us when composing (e.g. support@aros.ai, chris@lps.world). The Reply-To header matches the From. Mails sent to any @aros.ai address are forwarded by Namecheap to a single human inbox.

5c. Bounce & complaint handling

Amazon SES notifies us automatically when an address bounces (hard or soft) or someone clicks "spam". Both events:

6. Cookies & tracking

We use the absolute minimum cookies needed for the site to work:

You can disable cookies in your browser settings. Most of the site works fine without them.

How we count visits (cookieless analytics)

We measure page views and unique visitors on our own server β€” no Google Analytics, no Facebook Pixel, no third-party analytics service. For this we store nothing on your device: no cookie, no local-storage identifier.

To count a unique visitor without identifying you, our server derives a short, one-way hash from your IP address combined with a secret salt that rotates every month. Your raw IP address is never stored in our analytics, the hash cannot be reversed back to your IP, and it changes each month so you cannot be tracked over time. We also use Cloudflare's own country signal for rough, country-level geography β€” so your IP is not sent to any separate location-lookup service. None of this analytics data is shared with third parties.

We do not use a cookie consent banner because we don't set non-essential cookies and we don't store any tracking identifier on your device. If that ever changes, we'll add one.

Affiliate links

Some links on our site and in our newsletters are affiliate links β€” for example via Digistore24, ClickBank, Impact.com, or directly with a brand. If you click one and make a purchase, we may earn a commission at no extra cost to you.

When you click an affiliate link, the partner network may set its own cookie in your browser to attribute a possible sale to us. We do not receive your payment details or your individual purchase data β€” only aggregate, anonymised commission reports (e.g. "3 sales this month"). The partner network is the data controller for whatever happens after you leave our site; please see their own privacy policy. We only feature products we'd genuinely recommend, and a recommendation is our opinion, not professional advice.

7. How long we keep your data

8. Your rights

Under GDPR, CCPA, and similar laws, you have the right to:

To exercise any right, email us at the address below. We respond within 30 days.

9. International data transfers

Most of our infrastructure is in the EU (eu-central-1). Where data is processed outside the EU/EEA (e.g. by AWS US-based parent, or Google for YouTube embeds), the transfer relies on Standard Contractual Clauses (SCCs) and adequacy decisions where available.

10. Children's privacy

Our content is intended for adults. We do not knowingly collect data from children under 16. If you believe a child has subscribed, contact us and we'll delete their data immediately.

11. Security

We use TLS (HTTPS) for all traffic. Subscriber email addresses in our primary database (MongoDB) and in our send-logs (SQLite) are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256), with the encryption key wrapped by AWS KMS so a leaked database snapshot alone does not expose any addresses. Admin access is via SSH key authentication only (no password login). We rotate API credentials when we suspect exposure, when team members change, or at minimum annually. No system is 100% secure β€” we'll notify affected users if a breach occurs that is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR).

12. Changes to this policy

We may update this page when our practices or the law changes. Material changes will be announced in our newsletter. The "Last updated" date at the top always reflects the current version.

13. Contact us

Christian Albert Mueller (Controller) Schwanseestr. 47, 81549 MΓΌnchen, Germany
Email: hello@christianalbertmueller.com
Privacy questions: privacy@christianalbertmueller.com
Data Protection Officer Prof. Dr. h.c. Heiko Jonny Maniero Β· DG Datenschutz
Franz-Joseph-Str. 11, 80801 MΓΌnchen Β· +49 (0)800 – 6264376
info@dg-datenschutz.de

We are a small independent operation. If you write us about your data, you'll get a personal reply β€” usually within 48 hours.