Privacy Policy
Last updated: 11 September 2026
This English text is a convenience translation. The German version of this policy („Datenschutzerklärung“) is the binding one; in case of any discrepancy, the German wording prevails.
1. At a glance
DearWho is a free reference tool for first names. You type a first name, we estimate from open datasets whether that name is usually given to men, to women, to either, or whether it depends on the country, and we suggest a suitable salutation.
The essentials:
- There are no user accounts, no sign-up, no payments and no contact form.
- This website sets no cookies and stores nothing in your browser's local storage. No consent banner is therefore required (see section 5).
- Names you type are processed only to answer your request. We keep no database of queries and no search history.
- The optional AI feature runs only when you explicitly click it. Only then is the name you typed sent to OpenAI.
- No third-party content is embedded: no social media plugins, no videos, no reCAPTCHA, no advertising, no map services.
- Fonts are served from our own server. Your browser never contacts Google.
2. Controller
The controller within the meaning of Art. 4 (7) GDPR is:
Niels Erselius
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-mail: nielserselius@yahoo.de
No data protection officer has been appointed. The conditions of Art. 37 GDPR and § 38 BDSG are not met for this service: fewer than 20 people are permanently engaged in automated processing of personal data, and the core activity is neither large-scale processing of special categories of data nor large-scale regular monitoring of individuals.
3. Hosting
This website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes personal data on our behalf (in particular your IP address and technical details about your browser) in order to deliver the pages and API responses.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest lies in providing this service in a technically secure, performant and low-maintenance way.
A data processing agreement under Art. 28 GDPR is in place with Vercel (Data Processing Addendum, available at https://vercel.com/legal/dpa). Vercel uses its own sub-processors; the current list is published at https://security.vercel.com. Vercel's own privacy notice is available at https://vercel.com/legal/privacy-notice.
Regions and third-country aspects:
- Static content (HTML, CSS, JavaScript, font files, images) is delivered through a global content delivery network, from whichever location is closest to your device. That location may be outside the EU.
- Responses of the public lookup endpoint (GET /api/check) are held in that network's cache for up to 24 hours so that frequently requested names do not have to be recomputed each time. What is cached is the requested URL, including the name contained in it, and the corresponding response — not your IP address.
- Server function execution (the API routes /api/check, /api/greeting and /api/ai, and dynamically rendered pages) currently takes place in the provider's default region in the USA (Washington, D.C., region code “iad1”). Once execution is pinned to the Frankfurt am Main region (region code “fra1”), this paragraph will be amended accordingly. Regardless of the execution region, Vercel Inc. remains a US company able to access the data processed.
For transfers to the USA we rely on the European Commission's Standard Contractual Clauses, which form part of the data processing agreement referred to above (Art. 46 (2) (c) GDPR). Vercel further states that it is certified under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR). Despite these safeguards, it cannot be ruled out that US authorities may access data on the basis of US law.
Server log files
The host automatically collects and stores information in server log files, which your browser transmits automatically. These are:
- IP address of the requesting device
- date and time of the request
- requested URL and HTTP method
- volume of data transferred and HTTP status code
- referrer URL, where transmitted
- browser type, browser version and operating system
This data is not merged with other data sources. It is collected on the basis of Art. 6 (1) (f) GDPR; our legitimate interest is the technically error-free operation and the security of this website.
Important for you: when you look up a name, that name appears in the URL requested (for example /name/alex or /api/check?name=Alex) and is therefore part of this log data. We do not store these logs ourselves on a lasting basis, do not routinely analyse them and do not archive them. The host retains them according to its own default for the plan we use, and then deletes them automatically: Vercel documents these retention periods as one hour on the Hobby plan, one day on Pro, three days on Enterprise, and 30 days on any plan with the Observability Plus add-on (https://vercel.com/docs/logs/runtime, as of 11 September 2026). No log drain — a lasting export of these logs to another system — is configured; the logs stay with Vercel for no longer than the period stated above. We have not agreed any longer retention.
4. General information and mandatory disclosures
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Postfach 1349
91504 Ansbach
Germany
(visiting address: Promenade 18, 91522 Ansbach)
Phone: +49 981 180093-0
E-mail: poststelle@lda.bayern.de
Web: https://www.lda.bayern.de
Legal bases
We process personal data on the following bases:
- Art. 6 (1) (a) GDPR (consent): for the optional AI feature, which you trigger by an explicit click.
- Art. 6 (1) (f) GDPR (legitimate interests): for hosting, server log files, audience measurement, abuse protection of the AI feature, and answering e-mail enquiries.
- Art. 6 (1) (b) GDPR: where an e-mail enquiry concerns the initiation or performance of a contract.
There is no statutory or contractual obligation to provide us with personal data. You can use this website without filling in any field; if you enter no name, you simply get no result.
Withdrawing consent
Where processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of processing carried out before withdrawal is unaffected. In practice, for the AI feature, this means simply not triggering it again. A request already sent to OpenAI cannot be recalled; please contact OpenAI regarding its deletion.
Right to object under Art. 21 GDPR
WHERE PROCESSING IS BASED ON ART. 6 (1) (E) OR (F) GDPR, YOU HAVE THE RIGHT AT ANY TIME TO OBJECT, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RESPECTIVE LEGAL BASIS IS SET OUT IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ART. 21 (1) GDPR).
To object, simply write to nielserselius@yahoo.de.
No processing for direct marketing takes place on this website, so an objection under Art. 21 (2) GDPR has no subject matter here.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work or the place of the alleged infringement (Art. 77 GDPR).
The authority competent for us is:
Your other rights
- Access (Art. 15 GDPR): you may request information about the personal data we process.
- Rectification (Art. 16 GDPR): you may request correction of inaccurate data or completion of incomplete data.
- Erasure (Art. 17 GDPR): you may request deletion of your data, unless a statutory retention obligation applies.
- Restriction of processing (Art. 18 GDPR): you may request restriction, for example while the accuracy of data you contest is being verified. Restricted data is — apart from being stored — processed only with your consent or for the establishment, exercise or defence of legal claims.
- Data portability (Art. 20 GDPR): data we process automatically on the basis of your consent or in performance of a contract will be handed over to you or to a third party in a common, machine-readable format, as far as technically feasible.
Please note: because we do not store name lookups and operate no accounts, we normally hold no data that could be linked to you, so a request for access will come back empty. If you have written to us, a request for access will in practice concern your e-mail correspondence.
An informal e-mail to nielserselius@yahoo.de is enough for any of these requests.
No automated decision-making
There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. The results on this website are statistical information. They produce no legal effect and do not similarly significantly affect anyone; whether and how you use a result is entirely your decision.
SSL/TLS encryption
For security reasons this site uses SSL/TLS encryption. You can recognise an encrypted connection by the browser address bar changing from “http://” to “https://” and by the lock symbol. When encryption is active, the data you transmit to us cannot be read by third parties.
5. Data collected on this website
No cookies, no consent banner
This website sets no cookies — neither strictly necessary nor analytics or marketing cookies. It stores no other information on your device either, and reads no information stored there (no local storage, no session storage, no IndexedDB, no fingerprinting). We therefore treat the cookieless audience measurement (see section 6) as not requiring consent under § 25 (1) TDDDG, and we use no consent banner.
We note that the European Data Protection Board, in its Guidelines 2/2023 on the technical scope of Art. 5 (3) of the ePrivacy Directive — which § 25 TDDDG transposes — also brings the evaluation of IP addresses and request headers within that scope. The question is not conclusively settled. You may object to the audience measurement under Art. 21 (1) GDPR (see section 4); we will then switch the measurement off for this service.
Your language follows solely from the address you open (/ for English, /de/ for German) and is not stored.
E-mail enquiries
If you contact us by e-mail, your message including the contact details you provide there is stored by us in order to handle the enquiry and in case of follow-up questions. We do not pass this data on without your consent.
Processing is based on Art. 6 (1) (f) GDPR (legitimate interest in answering enquiries) or Art. 6 (1) (b) GDPR where your enquiry concerns the initiation or performance of a contract. The data stays with us until the purpose for storing it no longer applies (as a rule, once your matter has been dealt with), until you ask us to delete it, or until a statutory retention period ends.
For clarity: the contact address is the operator's personal mailbox with a free e-mail provider (yahoo.de). There is no data processing agreement with that provider for this mailbox; the provider's own terms and privacy policy apply. Please do not send us particularly sensitive content by e-mail.
No contact form, no accounts, no payment data
This website has no contact form, no newsletter sign-up, no registration and no payment processing. The pricing page merely offers an e-mail link for expressions of interest; no data is entered into a form.
6. Audience measurement: Vercel Web Analytics
We use Vercel Web Analytics, a service of Vercel Inc. (address as in section 3), to understand which pages are visited and whether the service works technically.
Vercel Web Analytics works without cookies. Instead of an identifier stored on your device, a hash is derived from the details of the incoming request and is discarded after 24 hours. According to the provider, the following is recorded per event:
- time of the page view
- URL requested and the dynamic path
- referrer
- filtered query parameters
- approximate location (country, region, city), derived from the IP address
- operating system and its version
- browser and its version
- device type
- version of the analytics script
The IP address itself is not stored, no cross-site profiles are built, and no recognition across different websites or applications takes place. We receive aggregated reports only and cannot identify any individual from them.
The legal basis is Art. 6 (1) (f) GDPR. Our legitimate interest is a data-minimising analysis of usage in order to improve this service. Because no information is stored on or read from your device, we treat this as not requiring consent under § 25 (1) TDDDG; the European Data Protection Board's position described in section 5 applies here too. We do not rely on the “strictly necessary” exception in § 25 (2) no. 2 TDDDG for audience measurement.
This service offers no individual opt-out switch for visitors. Because the measurement works without any recognition attribute, an objection cannot be applied to an individual visitor. On a reasoned objection under Art. 21 (1) GDPR (see section 4) we will switch the audience measurement off for this service as a whole. The provider's privacy information for this service is available at https://vercel.com/docs/analytics/privacy-policy. Transfers to the USA and the safeguards in place are described in section 3 and apply here accordingly.
7. Name lookups, public API and MCP server
What happens to a name you enter
When you enter a name — a first name in the search, as a rule the full name including the surname in the salutation generator, up to 200 names in the bulk check — that input is transmitted to our server, matched against the stored datasets, and the result is returned to your browser. The bulk check sends up to 200 names in one request (POST /api/check).
We build no database of your queries, keep no search history and link queries to no person. Processing is limited to answering the request in question. Beyond that, what is described in section 3 applies: names in the URL appear in the host's server log files, and responses of the lookup endpoint are held in the delivery network's cache for up to 24 hours. Names you submit by POST in the bulk check or the salutation generator do not appear in the URL and are not cached.
Names of third parties
A name may relate to another identifiable person — typically the person you are writing to. In that case we process that third party's data.
The salutation generator processes the full name you enter, which as a rule includes the surname; the bulk check processes up to 200 names entered by you. These details are used solely to compute the answer; they are not stored, not logged and not linked into profiles. Names transmitted by POST appear neither in the URL nor in the delivery network's cache. Please do not enter any further details about a person (such as address, date of birth or contact details); the input fields are not intended for that.
The legal basis is Art. 6 (1) (f) GDPR; the legitimate interest is enabling you to use the correct form of address. What is decisive for the balancing is that the processing is purely transient, ends with the response, results in no storage and no profiling, and that the details are not enriched with any further data.
Informing the third party concerned under Art. 14 GDPR is impossible for us: we know neither their identity nor their contact details, and we store nothing from which either could be derived. This information is therefore made publicly available in this privacy policy in accordance with Art. 14 (5) (b) GDPR.
Public API
DearWho offers a public, keyless JSON interface (including /api/check and /api/greeting). No account and no access key is required to use it. Only the name or country string sent by the calling party is transmitted; we keep no personal request logs and build no per-caller histories. The host's technically necessary logs are covered by section 3.
Anyone who embeds this interface in their own application is responsible for the data processed there and must inform their own users about the transmission to DearWho.
If you use the bulk check or the interface commercially and thereby process names for which you are the controller yourself, we act as a processor in that respect. We will provide a data processing agreement under Art. 28 GDPR on request at nielserselius@yahoo.de.
MCP server
The MCP server for DearWho, published as a separate package, is read-only. It stores nothing itself, contains no telemetry and requires no account. It forwards the name or country string passed to it to the same public interface a browser would call, and returns the answer. Everything said above about the public API therefore applies to it.
8. AI feature (OpenAI)
Name pages may offer an optional AI feature (“Ask AI about this name”). It is available only if the operator has enabled it by configuring an API key; otherwise it is not shown.
What happens:
- The feature runs only when you actively click the button. There is no automatic execution when the page loads.
- What is sent to OpenAI: the name you entered and whether the answer should be written in German or English, together with our fixed instruction to the model. What is not sent: your IP address, any browser identifier, the referrer or any other details about you — the request is made by our server, not by your browser.
- The answer (gender guess, confidence, origin, meaning, pronunciation, a note) is returned to your browser and is not stored by us.
The recipient is OpenAI. The contracting entity for customers in the European Economic Area is OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. Processing also takes place at affiliated companies in the USA. A data processing agreement is in place with OpenAI. For transfers outside the EEA, OpenAI relies on the European Commission's Standard Contractual Clauses (Art. 46 (2) (c) GDPR). OpenAI's privacy policy for the European Economic Area is available at https://openai.com/policies/eu-privacy-policy.
According to OpenAI, the following applies to API use:
- Data sent through the API is not used to train or improve the models unless this is explicitly opted into. We have not opted in.
- Abuse-monitoring logs are retained for up to 30 days and then deleted, unless longer retention is required by law or is necessary to protect against harm.
- OpenAI offers processing in European regions for certain accounts. That option is not configured for this service at present, so processing is not confined to the EU.
The legal basis for the processing is your consent under Art. 6 (1) (a) GDPR, which you give by clicking the button; the notice about the transmission to OpenAI appears directly at the button and is visible before you click. The transfer outside the EEA is safeguarded by the European Commission's Standard Contractual Clauses (Art. 46 (2) (c) GDPR); we do not rely on the derogations in Art. 49 GDPR. You may withdraw your consent at any time with effect for the future by not triggering the feature again. The website is fully usable without it.
Abuse protection: to protect the feature against automated mass use, we count requests per IP address and calendar day and cap them (default: five requests per day). A counter is held in the memory of the executing server instance, keyed by IP address and date. It is not written to a database or persisted; it is lost as soon as the server instance stops or restarts. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in preventing abuse and limiting cost).
Transparency under Art. 50 of the AI Act: the output of this feature is generated by an AI system. It is labelled as AI-generated, and the notice appears before you trigger the feature. AI-generated statements can be factually wrong. They are an estimate about the name, not a statement about any particular person.
9. Fonts
This website uses the typefaces Fraunces and Inter. They are integrated via the framework's next/font function: the font files are downloaded once at build time and then served as our own files from our server.
Your browser therefore establishes no connection to Google servers. In particular, no requests are made to fonts.googleapis.com or fonts.gstatic.com, and no IP address is transmitted to Google.
The icons used (lucide-react) are likewise part of the application and are served from our server.
10. External links
In a few places this website links to external services, for example to the sources of the datasets used. These are plain links; no third-party content is embedded, and your browser contacts those providers only once you click a link. From that point the respective provider's privacy policy applies; we have no influence over their processing.
11. Search engines and IndexNow
This website publishes XML sitemaps and a robots.txt so that search engines and assistant systems can find the content. The addresses of name pages contain the respective first name.
In addition, new or changed addresses may be submitted to Microsoft Bing via the IndexNow protocol so that they are indexed faster. Only the addresses of the pages concerned and this website's public IndexNow key are transmitted. No visitor data is transmitted — in particular no IP addresses and no information about who opened which page or looked up which name. The legal basis is Art. 6 (1) (f) GDPR (legitimate interest in the discoverability of the service).
12. Transfers to third countries — overview
In summary, data is transferred to the following recipients outside the EU, or to companies established outside the EU:
| Recipient | Purpose | Data transferred | Basis |
|---|---|---|---|
| Vercel Inc., USA | hosting, delivery, audience measurement | IP address, technical request data, URL requested including names looked up | data processing agreement with Standard Contractual Clauses; EU-US Data Privacy Framework |
| OpenAI (OpenAI Ireland Limited, Ireland; processing also in the USA) | optional AI feature | the name entered and the desired answer language | consent; data processing agreement with Standard Contractual Clauses |
| Microsoft (Bing/IndexNow) | faster indexing | page addresses, IndexNow key | legitimate interest; no personal visitor data |
Despite these safeguards, access by state authorities to data processed in the USA cannot be entirely ruled out.
13. Retention — overview
- Name lookups: not stored by us; processing ends with the response. Cached responses in the delivery network are refreshed or discarded after at most 24 hours.
- Server log files: stored by the host according to its own default for the plan we use — per Vercel's documentation, one hour on Hobby, one day on Pro, three days on Enterprise, 30 days with Observability Plus (see section 3); deleted automatically thereafter, not archived by us, and no log drains configured.
- Audience measurement: the visitor-identifying hash is discarded after 24 hours; beyond that we hold aggregated figures only.
- AI feature: not stored by us; abuse-monitoring logs at OpenAI for up to 30 days. The daily-limit counter exists only in the server instance's memory.
- E-mail correspondence: until your matter has been dealt with, and beyond that only where statutory retention obligations apply.
14. Changes to this privacy policy
We update this privacy policy whenever the actual processing or the legal situation changes — for example when a feature is added or removed, or a provider changes. We additionally re-verify the statements about cookies and storage techniques (section 5) after every update of the framework used and of the audience-measurement script. The version published here, bearing the date above, is the applicable one.