Skip to content
Hey it's Sara
  • Products
  • MakerWorld
  • Patreon
  • About
DEDeutschContact

Legal

Privacy policy

Last updated: October 3, 2026·Deutsche Fassung

  • Legal notice
  • Privacy policy
  • Terms of use
  • Data deletion

Contents

  1. Controller
  2. Summary
  3. Hosting and server logs
  4. Cookies, fonts and tracking
  5. Contacting us by email
  6. MakerWorld, Patreon and Instagram
  7. Instagram messaging with Echo Studio
  8. Your rights
  9. Security and changes

This is an English translation of our Datenschutzerklärung. In case of doubt, the German version applies.

1. Controller

The controller responsible for data processing within the meaning of the GDPR is:

Hey it's Sara
Owner: Sara Kammerlocher
Anhaltsweg 17
38547 Calberlah
Germany

Email: kontakt@heyitssara.de
Phone: +49 171 7529378

This privacy policy applies to this website, to our profiles on MakerWorld, Patreon, Instagram and to communication via our own Instagram accounts using our software Echo Studio. Our apps (for example Dough it yourself and Cupcaker) have their own privacy notices, which we refer to within each app.

2. Summary

  • This website uses no analytics, tracking or advertising services and no cookies for such purposes.
  • Fonts and graphics are served from our own web space. No content is loaded from Google or other third parties.
  • When you visit the website, technically necessary server logs are created by our hosting provider Cloudflare.
  • When you interact with our Instagram accounts, we process the data needed to reply to you and automatically delete message content after 30 days.
  • You can request information at any time and ask us to delete your data.

3. Hosting and server logs

This website is provided via the platform of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA ("Cloudflare"). Cloudflare delivers the pages through a worldwide network of data centres (content delivery network) and protects them against attacks. When you access the website, Cloudflare automatically processes information transmitted by your browser:

  • IP address,
  • date and time of access,
  • requested page or file, HTTP status code and amount of data transferred,
  • referrer URL (the previously visited page),
  • browser type and version as well as operating system.

This data is technically necessary to deliver the website and to ensure its stability and security, for example to fend off attacks and bots. The legal basis is Art. 6 (1) (f) GDPR; our legitimate interest lies in providing the website securely and reliably. We do not combine this data with other data and do not use it to analyse your behaviour.

Cloudflare processes the data on our behalf as a processor (Art. 28 GDPR) on the basis of Cloudflare's Data Processing Addendum. Data may be transferred to the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework, for which an adequacy decision of the European Commission exists (Art. 45 GDPR). Log data is only stored for as long as necessary for these purposes and is then deleted automatically.

4. Cookies, fonts and tracking

We ourselves do not set cookies, we do not store any information in your browser and we do not use analytics, tracking or advertising services. The fonts used (Fredoka and Nunito) are hosted locally on our web space, so visiting this website does not establish a connection to servers of Google or other font providers.

To protect against attacks and automated access, Cloudflare may set technically necessary, short-lived security cookies (for example "__cf_bm"). They serve exclusively to keep the website secure and are not used for analytics or advertising. The legal basis is Section 25 (2) no. 2 of the German Telecommunications Digital Services Data Protection Act (TDDDG) in conjunction with Art. 6 (1) (f) GDPR.

5. Contacting us by email

If you email us, we process your email address, your name (if provided) and the content of your message in order to answer your request. The legal basis is Art. 6 (1) (b) GDPR if your request relates to a contract or its preparation, and otherwise Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries). We delete the data as soon as it is no longer required and no statutory retention obligations, for example under commercial or tax law, apply.

6. MakerWorld, Patreon and Instagram

We maintain profiles on MakerWorld, Patreon, Instagram. On this website we only link to these platforms with plain links; no content or scripts from the platforms are embedded. Data is only transferred once you click such a link and visit the platform.

When you visit our profiles or interact with us there, for example by downloading a model, becoming a member, commenting or messaging us, the platform operators process your data under their own responsibility in accordance with their privacy policies. We only see the information the platform shows us, for example your public profile name, your comments and messages or, on Patreon, details of your membership. We use this information to communicate with you and to manage our offerings (Art. 6 (1) (b) and (f) GDPR).

Instagram is operated by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland ("Meta"). Insofar as Instagram provides us with statistics about the use of our profiles (Insights), we are jointly responsible with Meta for this (Art. 26 GDPR). We only receive these statistics in aggregated form, without being able to identify individuals. Meta may also transfer data to the USA; Meta Platforms, Inc. is certified under the EU-U.S. Data Privacy Framework.

7. Instagram messaging with Echo Studio

For our own Instagram professional accounts we use Echo Studio, software that we develop and operate ourselves. Echo Studio is connected to our accounts via Meta's official interface (the "Instagram API with Instagram Login"). We use it to plan and publish our own posts and to reply to comments, story replies and messages, partly automatically.

Which data we process

When you comment on one of our posts or reels, reply to one of our stories, send us a direct message or tap a button in one of our messages, Meta sends us the following data:

  • your Instagram-scoped ID (a pseudonymous identifier that Instagram issues specifically for our account) and, where provided by Meta, your Instagram username,
  • the text of your comment, story reply or message and the related identifiers, for example of the comment, post or story,
  • timestamps and the technical status of our replies, for example "sent" or "awaiting confirmation".

If we send a link with click counting in a message, we only store the date and time and the host name of the referring site (for example instagram.com) when the link is opened. We do not store IP addresses, full referrer URLs, browser identifiers or device identifiers.

What we use the data for

  • to respond to your comment with a short public reply,
  • to send you information you requested with a keyword via direct message. We only send the actual content, for example a link, after you have explicitly confirmed in the conversation that you want to receive it,
  • to ensure that you receive each automation only once and do not get duplicate messages,
  • to detect technical errors and to evaluate the number of link visits.

We do not send unsolicited messages, we do not sell data, we do not use it for advertising and we do not use AI services. No automated decision-making within the meaning of Art. 22 GDPR takes place.

Legal basis

Art. 6 (1) (f) GDPR. Our legitimate interest lies in answering requests from our community quickly and reliably and in managing our accounts efficiently. You only receive further content after your explicit confirmation.

Storage location and security

Echo Studio runs on a server that we operate ourselves; no external service providers for hosting or analytics are involved. Access tokens and the person identifiers required for ongoing conversations are stored encrypted (AES-256-GCM). To prevent duplicate messages, we use pseudonymous check values (HMAC). Only persons authorised by us have access, and the connection to Meta is always encrypted.

Retention

  • We automatically delete the content of incoming comments and messages as well as the encrypted person identifier of completed conversations after 30 days.
  • We delete individual link visits after 30 days; afterwards only a total count without personal reference remains.
  • We keep open or unresolved cases until they have been resolved.
  • We keep pseudonymous check values, event identifiers and the technical status so that nobody receives the same automation twice. They are deleted when you request deletion or when we no longer need them for this purpose.

Recipients

Messages and public replies are sent via Meta's interface. Meta processes the data of your interactions with Instagram under its own responsibility; Instagram's privacy policy applies. There are no other recipients.

Connected Instagram accounts

We only connect our own Instagram accounts to Echo Studio. In doing so, we process the account ID, the username, the permissions granted, an access token stored in encrypted form and information about the posts and stories of these accounts (for example caption, media link and publication time). For our team members to sign in to Echo Studio, we store their email address, role and a password hash. The connection to an Instagram account can be removed at any time, as described in our data deletion instructions.

8. Your rights

You have the following rights regarding your personal data:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR),
  • withdrawal of consent with effect for the future (Art. 7 (3) GDPR).

Right to object (Art. 21 GDPR)

Where we process your data on the basis of Art. 6 (1) (f) GDPR, you may object to this processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.

To exercise your rights, simply send an informal message to kontakt@heyitssara.de. Our page on data deletion explains step by step how to request the deletion of your Instagram data.

You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement (Art. 77 GDPR).

You are not obliged to provide us with personal data. However, the website cannot be delivered without server logs, and we cannot reply to you on Instagram without the data of your interaction.

9. Security and changes

For security reasons, this website uses TLS encryption. You can recognise an encrypted connection by "https://" in your browser's address bar.

We update this privacy policy when our offerings or the legal situation change. The current version published on this page applies.

Hey it's Sara

3D print designs, apps and software – made with love.

Explore

  • Products
  • MakerWorld(opens an external site)
  • Patreon(opens an external site)
  • Instagram(opens an external site)
  • About

Legal

  • Legal notice
  • Privacy policy
  • Terms of use
  • Data deletion

Contact

  • kontakt@heyitssara.de
  • Deutsch

© 2026 Hey it's Sara. All rights reserved.

Owner: Sara Kammerlocher · Calberlah