Privacy
In short: no account, no email address, no ads, no tracking. We store what a round needs, and only pass on what a feature you are using right now needs. This is a translation; the German privacy policy is binding.
Controller
Jarno Kyas, Überhöferfeld 13, 51503 Rösrath, email: jarnokyas@whu.edu
What we store
- Rounds: question, notes, the ideas (links, texts, titles, image addresses), your swipes, chat messages and the name you type when joining.
- Your device: a cookie
einig_kontoand the same random identifier in your browser’s local storage. This is how the app knows which rounds belong to this device. The app does not work without it; no consent is required for it (§ 25 (2) no. 2 TDDDG). The browser also stores the last opened round and your language locally. - Device pass: only if you request it, a code to move your rounds to another device.
- Abuse protection: when creating a round or redeeming a pass, a hash of your IP address, for ten minutes at most.
The app never shows anyone who added a card or how someone swiped. After the result, the group only sees the totals per idea.
Purpose and legal basis
To run the round you created or joined (Art. 6 (1) (b) GDPR), and to protect the app from abuse (Art. 6 (1) (f) GDPR). We don’t analyse anything for advertising and don’t sell anything.
Who gets to see data
- Cloudflare (Cloudflare, Inc., USA) runs the servers and the database and technically processes your IP address. Cloudflare is certified under the EU-US Data Privacy Framework.
- Anthropic (Anthropic, PBC, USA): typed ideas and titles of links without a photo are sent to the language model Claude so it can suggest a search term for a matching photo. If you tap “Find matching products?”, your keyword goes to Claude with web search. Without your name, without the round. Anthropic does not use these requests for training.
- Pexels (Pexels GmbH, Germany) receives the search term for a stock photo, with no link to you.
- OpenStreetMap / Overpass (overpass-api.de, overpass.kumi.systems): only when you search for places nearby, your location is sent there, rounded to about 100 m. We don’t store it. If the app shows “Places: Google”, the search comes from Google Places (Google Ireland Ltd.) instead of OpenStreetMap.
- TMDB (The Movie Database, TMDB Inc., USA): for a film link (IMDb, Netflix), our server sends the IMDb number or the film title to TMDB to find the poster and year – with no link to you. Your browser loads the poster from image.tmdb.org.
- Instagram (Meta Platforms Ireland Ltd.): only when you tap “View post” on an Instagram link does your browser load the post directly from Instagram. Meta then sees your IP address and may set cookies. Nothing from Meta loads before that.
- Linked shops and pages: your browser loads images on cards directly from there, so that server sees your IP address, like with any image on the web. When you tap a link, you leave group swipe.
How long
- Open rounds: deleted 60 days after the last activity.
- Decided rounds: deleted 365 days after the last activity.
- Device identifiers without a round and without a pass: deleted after 60 days.
- Whoever created a round can delete it for everyone at any time.
Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR). The fastest way to delete is yourself: on the home page under “Device pass & other device” → “Delete my data”. Rounds you created disappear completely; in other rounds your name is removed and your chat messages are deleted. For anything else, write to the address above. You can also lodge a complaint with a data protection supervisory authority.
