Privacy policy

What we collect, why we collect it, and how you stay in control of your data.

We believe in being transparent about your data. This privacy policy shows you what information we collect from you, what we need it for and who we share it with. We update this policy regularly so that you are always up to date and know exactly what happens with your data.

Disclaimer

To make things easier to understand, we have summarised each section of the legal text in plain language. These explanations are provided for orientation and readability only. They are not legally binding.

The sole authoritative legal basis is the text of the privacy policy as presented in the original version marked as such.

Please note that the legally binding wording always takes precedence.

What data we collect

What services we use

This service is operated by Loggd UG (haftungsbeschränkt), registered at Eislebener Straße 29, 99086 Erfurt, Germany. In the following, terms such as 'we' refer to that company.

Through our app and our website, we offer a platform to track, rate and organise all of your different media, such as films, games and TV series. Our goal is to streamline your media tracking experience and make it as easy as possible to keep track of everything you are interested in.

The protection of your personal data is very important to us. In this privacy policy, we inform you in a simple and transparent manner about what data we process in our app and on our website and how we do so.

1. Controller and contact

The controller responsible for processing your personal data within the meaning of Art. 4(7) GDPR is:

Loggd UG (haftungsbeschränkt)
Eislebener Straße 29
99086 Erfurt
Germany

If you have questions or comments about this privacy policy, or if you would like to exercise your rights, you can reach us by email at privacy@loggd.me or by post at the address above.

Contact person for data protection:
Tobias Kärst
Email: privacy@loggd.me

We are not required to appoint a data protection officer under Art. 37 GDPR in conjunction with § 38 BDSG and have not appointed one. The person named above is your internal point of contact for all data protection matters.

2. Principles of data processing

We process your personal data only in accordance with the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This privacy policy transparently informs you about:

  • What data we collect and for what purposes

  • The legal basis on which the processing takes place

  • How long we store your data

  • Who data is disclosed to

  • Whether data is transferred to countries outside the European Union

  • What rights you have and how you can object to the processing

As a matter of principle, we only process the data required for the respective purpose. Features that are not necessary for operating the platform, in particular error diagnostics and usage analytics, are switched off by default and are only activated after your explicit consent.

3. Definitions

3.1 What is personal data?

Personal data is any information through which a natural person can be identified directly or indirectly. This includes names, address details, dates of birth, digital contact methods such as email addresses or phone numbers, as well as technical identifiers such as IP addresses or device identifiers.

3.2 What does processing mean?

Processing is any form of handling or working with personal data, regardless of the method or means used. This includes, for example: collecting, storing, adapting, transmitting, archiving and erasing personal data.

3.3 What does disclosure mean?

This means that personal data is transmitted to third parties or made accessible to them in any way, whether through deliberate sharing, publication or inspection.

3.4 What are third parties?

Third parties are all those who are neither the data subject themselves nor part of the controlling bodies or their appointed representatives. This includes individuals as well as companies, authorities or other organisations that fall outside the direct area of responsibility or work and are not authorised to handle the personal information concerned on their own account.

3.5 When is consent given?

Consent exists where a person, of their own accord and in clear awareness of the significance of their decision, agrees explicitly or through a clearly identifiable action that their personal data may be processed for a previously defined purpose. This consent must be unambiguous and must not be influenced by coercion or a lack of clarity.

3.6 When is data considered pseudonymised?

Pseudonymisation refers to a process in which personal information is modified or encrypted in such a way that it can no longer be attributed directly to a specific person without the use of additional, separately secured information. This additional data is kept separately and protected by technical and organisational measures to ensure that identification of the data subject is prevented.

3.7 What is a third-country transfer?

A third-country transfer occurs when personal data is transmitted to, or processed in, a country outside the European Union and the European Economic Area. Under Chapter V GDPR, such a transfer is only permitted if an adequate level of data protection is ensured, for example through an adequacy decision of the European Commission or through appropriate safeguards such as the standard contractual clauses.

4. Data security

We store your data securely and take all reasonable precautions to protect it against loss, unauthorised access, misuse or alteration.

This includes, for example, the following measures:

  • SSL/TLS encryption for all data transmissions

  • Encryption of stored data

  • Regular security updates

  • Access controls and permission concepts

  • Protection of our interfaces against automated attacks

  • Regular, encrypted backups

Our business partners and staff who have access to your data are obliged to comply with the applicable data protection provisions. We have concluded a data processing agreement pursuant to Art. 28 GDPR with every service provider that processes data on our behalf.

Despite all precautions, the security of data during transmission over the internet cannot be guaranteed one hundred per cent.

5. Your rights

As a data subject under the GDPR you have various rights, which arise in particular from Articles 15 to 21 GDPR

5.1 Right to object and withdraw consent

You can withdraw consent given for the processing of your personal data at any time without stating reasons. The withdrawal takes effect from the moment you notify us and does not affect the lawfulness of processing carried out up to that point.

Consent you have given in the app, in particular for error diagnostics and usage analytics, can be withdrawn at any time using a toggle in the app's privacy settings. Withdrawing is just as easy as giving consent.

Where we base the processing of your data on a balancing of interests, you may object at any time. Please tell us the reasons why you object to the processing. We will then examine whether compelling grounds on our side prevail or whether we must stop the processing.

In addition, you have the right to object to the processing of your data for advertising purposes and for data analysis. You can inform us of this at any time using the contact details provided in this privacy policy.

To exercise your right of withdrawal or objection, please contact us using the contact details given at the beginning of this policy.

What this means

You can withdraw your consent at any time without giving reasons. This applies from the moment you tell us.

For error diagnostics and usage analytics you can do this directly in the app's privacy settings, with a toggle.

If we use your data on the basis of legitimate interests, you can object. Just tell us the reason. We will then review it and stop the processing where appropriate and possible.

You can object to advertising and data analysis purposes at any time.

Simply send us a message using the contact details at the beginning of this policy.

5.2 Right of access

You have the right to request information about the personal data we hold about you at any time. This information is provided free of charge in written or electronic form within one month of the request.

Where necessary, we may extend the response period by two further months if the complexity or number of requests requires this. You will be informed of any extension in good time. In most cases, however, the information is automated and available immediately.

In the case of manifestly unfounded or excessive requests, we reserve the right to refuse the request or to charge a fee. The right of access does not apply insofar as it would adversely affect the rights and freedoms of other persons.

To exercise your right of access, you can choose one of the following routes. In both cases you will receive the information in a commonly used electronic format:

  • An email with valid proof of identity to privacy@loggd.me

  • A direct download of your data through the application (Profile > Account > Download personal data)

What this means

You can find out free of charge at any time what data we hold about you. You will normally receive the information within one month.

If it gets complicated or we receive too many requests, we can extend the deadline by two months. In that case we will inform you in good time. Usually, though, it is automatic and immediate.

For manifestly pointless or excessive requests we can refuse or charge a fee.

To get your data, simply send an email to privacy@loggd.me or download it directly from your profile.

5.3 Rectification

You have the right, in accordance with statutory requirements, to request the completion of data concerning you or the rectification of inaccurate data concerning you.

You can change many details yourself at any time in your profile settings, in particular your username and your profile information.

To exercise your right to rectification, please contact us using the contact details provided in this privacy policy.

What this means

You can ask us to correct incorrect data about you or complete incomplete data. You can also change much of it directly in your profile.

5.4 Erasure and restriction

You have the right to request the erasure of your personal data. However, this does not apply insofar as statutory retention obligations or other legal grounds prevent erasure. Please note that erasing your data may affect the performance of existing contracts.

To exercise your right to erasure, you can choose one of the following routes:

  • An email with valid proof of identity to privacy@loggd.me

  • A direct erasure request through the application (Profile > Account > Delete account)

Please note that an existing subscription you took out through Apple or Google is not automatically cancelled when you delete your account. You must cancel it in the subscription settings of your app store.

Alternatively, you can request that the processing of your data be restricted. This is possible in particular if you contest the accuracy of the data, if the processing is unlawful, if you no longer need the data or if you have objected to the processing.

While a restriction applies, your data is only stored. Further processing is only permitted with your consent, for the establishment of legal claims, for the protection of the rights of others or for reasons of important public interest. You will be notified before the restriction is lifted.

To exercise your right to restriction, please contact us using the contact details provided in this privacy policy.

What this means

You can ask us to erase your data. Exception: where we have to keep it for legal reasons. Note: erasure may affect ongoing contracts.

To erase your data, simply send an email to privacy@loggd.me or delete your account directly in the app.

Important: you cancel your subscription in the Apple or Google app store, not with us. Deleting your account does not automatically end the subscription.

Instead of erasure you can also ask us to restrict the processing.

With a restriction we only store your data and no longer process it. Exceptions: you agree, we need it for legal claims, to protect others or for important public interest. We will inform you before lifting the restriction.

Write to us if you would like a restriction, using the contact details in this privacy policy.

5.5 Data portability

You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format. This applies in particular where the processing is based on your consent or on a contract with us and is carried out by automated means.

You can request that we transmit this data directly to another controller, where technically feasible. We will not obstruct you in doing so.

Please note that the right to data portability does not apply to data we process on other legal grounds (for example, on the basis of statutory obligations).

To exercise your right to data portability, please contact us using the contact details provided in this privacy policy.

What this means

You can receive your data in a machine-readable format, for example through the download in your profile.

You can also ask us to send your data directly to another provider, where this is technically possible.

This does not apply to data we have to process for legal reasons.

Write to us if you would like your data transferred, using the contact details in this privacy policy.

5.6 Complaint to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the General Data Protection Regulation. The competent authority is in particular the supervisory authority in the country in which you habitually reside, in which you work or in which the alleged infringement took place.

The authority responsible for us is the Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit, Häßlerstraße 8, 99096 Erfurt, Germany.

What this means

If you think we are breaching data protection rules, you can lodge a complaint with a data protection supervisory authority. The authority in the country where you live, work or where the infringement took place is competent.

The supervisory authority responsible for us is the one in Thuringia, Germany.

6. Individual processing activities

6.1 Use of website and app - hosting with Hetzner

When you visit our website or when the app establishes a connection to our servers, technical data that your device transmits to our server is recorded automatically. This is necessary for operation.

List of data processed

  • IP address and internet service provider

  • Date and time of the request

  • Page accessed or interface requested

  • Technical data (browser type and version or app version, operating system, volume of data transferred, status code)

  • Referrer URL (previously visited page)

Purpose of processing this data

The processing is technically necessary in order to deliver the website and the functions of the app to you. In addition, we use the log data to ensure the stability of our systems and to detect and defend against attacks or misuse.

Legal basis for the processing

The legal basis for this processing is Art. 6(1)(f) GDPR. We have a legitimate interest in ensuring the functionality and security of our services. These interests outweigh your data protection interests, as the processing is technically indispensable for operation and the data is only stored for a short time.

Disclosure of data

We host our entire infrastructure with Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). Hetzner operates the server infrastructure in German data centres as our processor. All servers are located exclusively in Germany, so your data does not leave the Federal Republic of Germany. We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR.

Preventing the processing

The processing of this data is technically indispensable for operation. Storing log files is necessary for the technical operation and security of our services. Because this processing is technically necessary, you cannot object to it without refraining from using our services.

Storage period

Server log data is deleted automatically after 30 days at the latest. Longer storage only takes place where this is necessary to investigate a specific security-related incident; in that case, the data concerned is stored until the investigation is complete.

What this means

When you visit our website or the app talks to our servers, technical data is recorded automatically. This is necessary for operation.

What data: IP address, date and time, page accessed, browser or app and device information, previous page.

Why: so that everything works and stays secure, and so that we can detect attacks.

Where: all servers are with Hetzner in Germany. Your data stays in Germany.

Storage period: log data is deleted after 30 days at the latest.

This processing is technically necessary; you cannot object to it without refraining from using the services.

6.2 Content delivery, attack protection and DNS - Bunny

We use Bunny for several technical tasks: as a content delivery network for delivering images and files, for hosting static content, for protecting our interfaces against bots and automated attacks, and for resolving the DNS records of our domains.

List of data processed

  • IP address and internet service provider

  • Date and time of the request

  • Content and files requested

  • Technical data (browser type and version, operating system, volume of data transferred)

  • Referrer URL (previously visited page)

  • Characteristics of the request used to detect automated access

  • Domain names requested as part of DNS resolution

Purpose of processing this data

The content delivery network distributes our content across servers worldwide so that it can be loaded from a location near you. This significantly improves loading speed and reduces the load on our main servers. Bot and attack protection serves to protect our interfaces against overload, automated scraping of content and attacks. DNS resolution is necessary so that your requests can reach our servers at all.

Legal basis for the processing

The legal basis for this processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing our services quickly, securely and reliably and in protecting them against misuse.

Disclosure of data

The data is transmitted to Bunny (BunnyWay d.o.o., Cesta komandanta Staneta 4A, 1215 Medvode, Slovenia) as our processor. Bunny is established in the European Union but operates a global server network with locations including North America and Asia. Your requests may therefore also be processed outside the European Union. For these cases, Bunny has concluded the standard contractual clauses of the European Commission with its sub-processors (Art. 46(2)(c) GDPR). Further information can be found in section 7.

Preventing the processing

Processing by Bunny is technically indispensable in order to provide our services. Without DNS resolution and content delivery you cannot use our website and app. If you do not want this processing, you must refrain from using our services.

Storage period

Data is stored by Bunny only for as long as is technically necessary for delivering content and defending against attacks. Log data is deleted at short notice in accordance with Bunny's retention rules.

What this means

We use Bunny so that images and files load quickly, so that our interfaces are protected against bots and attacks, and so that our domains are reachable at all.

What data: IP address, date and time, content requested, browser and device information, previous page and the domain names requested.

Why: faster loading times, better protection against attacks, reliable availability.

Where: Bunny is based in Slovenia (EU) but operates servers worldwide. Your request may also be processed outside the EU. The standard contractual clauses apply to this.

The processing is technically necessary; without it you cannot use the services. Data is only stored briefly.

6.3 Data storage and database hosting

All personal data collected through the app and the website is stored in a central database that we use to operate our services.

List of data processed

All personal data described in the preceding or following sections of this privacy policy. Including, among others, the following.

  • Account data (email address, username, login provider and the user identifier held there)

  • Authentication data (password hash, encrypted key and hashed recovery codes for two-factor authentication)

  • Session information

  • Technical metadata (creation and modification timestamps)

  • Content you have created (reviews, ratings, lists, watchlists)

  • Social connections (friendships, blocks)

  • Subscription status and associated identifiers

  • Your settings, including your privacy settings

Purpose of processing this data

The database forms the technical foundation for all of our services. It allows us to store and retrieve your account information, to verify your subscription status, to recognise and sign you in on each visit, to store your content and settings and to provide all functions. Central data storage ensures the consistency and integrity of your data and enables us to implement your rights to access, rectification and erasure efficiently.

Legal basis for the processing

The legal bases for data storage correspond to the respective legal bases of the individual processing activities explained in this privacy policy. Storage takes place in particular for the performance of a contract (Art. 6(1)(b) GDPR), on the basis of your consent (Art. 6(1)(a) GDPR), for compliance with legal obligations (Art. 6(1)(c) GDPR) and on the basis of our legitimate interests in the proper operation of our services (Art. 6(1)(f) GDPR).

Disclosure of data

We host and manage our database ourselves on our own infrastructure with Hetzner within Germany. There is no disclosure to third-party providers for database hosting. The data stored in our database does not leave Germany.

Preventing the processing

Storing your data in our database is technically indispensable in order to provide our services to you. Without this data storage you cannot create an account, create content or use any functions. However, you have the right to delete your account, and with it all stored data, at any time (see section 5.4).

Storage period

The storage period depends on the specific retention rules for individual data types as described in the respective sections of this privacy policy. In general: account data and content you have created are stored until you delete your account, temporary session data is deleted at the end of the session, and data without specific retention obligations is deleted when the purpose of processing ceases to apply or when you request erasure.

Data security

The database is protected by several layers of security. All data is encrypted both in transit and at rest. Access is strictly controlled and only possible for authenticated systems and authorised persons. Automatic backups are created and stored in encrypted form to prevent data loss. The infrastructure is monitored continuously so that anomalies or security incidents are detected early.

What this means

All your data (account, content, settings, subscription status) is stored in our central database.

What data: email, username, login provider, your reviews and lists, friendships, subscription status, settings.

Why: so that the platform works, for your account, your content, your login and all functions.

Where: our own database on servers in Germany. This data does not leave Germany.

Security: everything encrypted, access strictly controlled, encrypted automatic backups.

Storage period: until you delete your account. Session data only for the duration of the session.

You can delete your account at any time, and your data will then be removed.

6.4 Strictly necessary cookies and local storage

We use cookies on our website and comparable local storage technologies in our app to ensure functionality. Most of the cookies we use are so-called session cookies. These are deleted automatically as soon as you leave our website. Other information remains stored on your device until you delete it manually, uninstall the app or its validity period expires.

List of data processed

  • Session and sign-in information (to maintain your login)

  • Language and region settings

  • Your privacy settings, in particular whether you have consented to error diagnostics and usage analytics

  • Interactions already completed (onboarding completed, notices seen once)

  • Local caches to speed up display

Purpose of processing this data

This information serves to maintain your login so that you do not have to enter your credentials again on every page. We store your privacy settings in order to respect your decision and not ask you again on every start. Language and region settings allow us to display the interface in your preferred language.

Legal basis for the processing

Storing information on your terminal equipment and accessing it is permitted without consent under § 25(2) no. 2 TDDDG because it is strictly necessary for us to provide the service you have expressly requested. We base the subsequent processing of the data on Art. 6(1)(b) GDPR (performance of a contract) and on Art. 6(1)(f) GDPR (legitimate interest in the technical operation of our services).

Disclosure of data

This information is set exclusively by us and is not disclosed to third parties. We do not use cookies or similar technologies for advertising purposes and do not integrate any advertising networks.

Preventing the processing

You can block or delete cookies in your browser settings and remove the app's local storage by uninstalling it. However, this may significantly restrict functionality. In particular, signing in is not possible without session information and your settings cannot be saved.

Storage period

Session cookies are deleted at the end of your browser session. Persistently stored information such as language preference and privacy settings remains stored until you delete it or uninstall the app.

What this means

We use cookies on the website and local storage in the app so that everything works properly.

What data: session information for your login, language and region, your privacy settings, whether you have seen the onboarding.

Why: so that you stay signed in, your language is saved and we do not have to keep asking you again.

We do not use advertising cookies and do not integrate advertising networks.

Disclosure: none, only we use this information.

You can block cookies in your browser, but then things like signing in will no longer work.

Storage period: session cookies until you close the browser, others until you delete them or uninstall the app.

6.5 Registration, sign-in and account security

You need an account to use the platform. You can either register with your email address and a password of your choice, or use one of the login providers we support: Discord, Google, Apple or Twitch. In both cases, your verified email address serves as the identifier of your account.

List of data processed

When you register with an email address and password, we process:

  • Email address

  • Password, exclusively as a cryptographic hash using a modern algorithm suitable for passwords; we never store your password in plain text and cannot view it

  • Verification status of the email address

  • One-time tokens for verifying the email address and resetting the password, together with their validity period

When you sign in via a login provider, we read out only the following details. We do not retrieve or store any other information from your profile with that provider.

  • Email address

  • Verification status of the email address

  • User identifier with the respective login provider

  • Username, where available with the login provider

Regardless of the method you choose, we additionally store in our own system:

  • Time of registration and of the last sign-in

  • IP address at the time of registration

  • Number and time of failed sign-in attempts

  • Active sessions and the associated device and session identifiers

  • Profile details and settings you have chosen

Two-factor authentication

You can additionally protect your account with two-factor authentication. Setting it up is voluntary. If you activate it, we additionally process the secret key of your authentication method, which we store encrypted, the time of activation and of the last successful verification, your recovery codes exclusively in hashed form, and, if you choose this, the identifiers of the devices you have marked as trusted. This data serves exclusively to secure your account and is not evaluated for any other purpose. You can deactivate two-factor authentication at any time in your account settings; the associated data is then deleted.

Purpose of processing this data

We process this data in order to create and manage your account and to authenticate you when you sign in. We need the verified email address because it is the unique identifier of your account and because we contact you through it on matters relevant to your contract. Storing the password hash, failed sign-in attempts and the two-factor authentication data serves to protect your account against unauthorised access, in particular against automated sign-in attempts and account takeover. Storing the time of registration and the IP address serves to prevent misuse and fraud.

Legal basis for the processing

The legal basis for creating and managing your account is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of the user agreement and for taking pre-contractual steps. We base the processing for securing access, in particular storing the IP address at registration, failed sign-in attempts and session data, on Art. 6(1)(f) GDPR; our legitimate interest lies in preventing misuse, automated mass registrations and account takeover. At the same time, we thereby fulfil our obligation to ensure an appropriate level of security of processing under Art. 32 GDPR. You set up two-factor authentication voluntarily; the processing of the data required for it is based on Art. 6(1)(a) GDPR and can be withdrawn at any time by deactivating the feature.

Disclosure of data

When you sign in via a login provider, we communicate with the provider you selected in order to verify your identity. The login providers process the data arising in this context under their own responsibility and in accordance with their own privacy policies. These are Discord Netherlands BV or Discord Inc., Google Ireland Limited, Apple Distribution International Ltd. and Twitch Interactive, Inc. We do not transmit any information about your use of the platform to these providers. When you register with an email address and password, no disclosure to third parties takes place; only the sending of verification and security emails is carried out through our email service provider.

Preventing the processing

You cannot use the platform without an account. You are free to choose whether you register with an email address and password or through one of the four login providers. If you later sign in through a different login provider or with a different email address, this is treated as a new account; matching takes place exclusively via the combination of email address and the user identifier of the login provider. You can delete your account completely at any time under Profile > Account > Delete account, and you can additionally revoke the connection to a login provider in that provider's settings.

Storage period

We store your account data, including the password hash and the two-factor authentication data, until you delete your account. Tokens for verifying your email address and resetting your password are deleted immediately after their short validity period expires or after use. Logs of failed sign-in attempts are deleted after 30 days at the latest. Session data is deleted at the end of the respective session or when you sign out.

What this means

You need an account to use the platform. You can register with an email address and password or sign in via Discord, Google, Apple or Twitch.

We store your password only as a hash, never in plain text. We cannot view it.

What we read from the login provider: email address, whether it is verified, your user identifier there and, where available, your username. Nothing more.

We additionally store: time of registration and last sign-in, IP address at registration, failed sign-in attempts, active sessions and your profile settings.

Two-factor authentication is voluntary. If you activate it, we store the secret key encrypted and your recovery codes only as hashes. You can deactivate it at any time, and this data is then deleted.

Why: for your account, signing in, communication about your contract and protection against misuse and account takeover.

Your verified email address is the identifier of your account. If you sign in with a different provider or a different email address, a new account is created.

We do not send the login providers any information about what you do on the platform.

You can delete your account at any time under Profile > Account > Delete account.

Storage period: account data until you delete your account. Failed sign-in attempts for a maximum of 30 days, verification tokens only briefly.

6.6 User-generated content, lists and friendships

You can create your own content on our platform. This includes reviews and ratings of media, lists and watchlists, and friendships with other users.

List of data processed

  • The content of your reviews and ratings

  • Lists and watchlists you have created, together with their visibility setting

  • The link between the content and your profile (username, profile details)

  • Creation and modification timestamps

  • Friend requests, existing friendships and blocks

Purpose of processing this data

The processing serves to provide you with the core functions of the platform: rating and commenting on media, organising your media in lists, and interacting with other users.

Legal basis for the processing

The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of the user agreement. You decide yourself whether and what content you create and how visible it is.

Disclosure of data

Content you set to public is visible to other users of the platform and is linked to your profile. Please note that you decide yourself what information about you becomes visible to others. Published content can be read, copied or further distributed by other people without us being able to prevent this. We therefore recommend that you do not include sensitive personal information in reviews, list names or profile details. We do not disclose this content to third parties outside the platform.

Preventing the processing

Creating content is voluntary. You can change the visibility of your lists at any time and edit or delete individual items yourself at any time. You can end friendships and blocks at any time.

Storage period

Your content is stored until you delete it or delete your account. When you delete your account, your content is removed or separated from your profile. Copies or quotations of your content already made by other people lie outside our sphere of influence.

What this means

You can write reviews and ratings, create lists and watchlists, and become friends with other users.

What data: the content of your reviews, your lists and their visibility, the link to your profile, timestamps, friendships and blocks.

Why: so that the core functions of the platform work.

Important: anything you make public can be read, copied and redistributed by others. So do not put sensitive personal information in reviews, list names or your profile.

You decide yourself what you create and how visible it is. You can change or delete anything at any time.

Storage period: until you delete the content or your account.

6.7 Reports, blocking and moderation

Users can report other people's content if it infringes applicable law or our terms of use. Reported content is reviewed by us and removed or blocked where appropriate.

List of data processed

  • The reported content and its identifier

  • The account of the reporting person

  • The account of the person whose content was reported

  • The reason for the report and, where applicable, a description

  • Time of the report

  • Outcome of the review and the measure taken

Purpose of processing this data

We process this data in order to review reported content, remove unlawful content or content infringing our terms, and detect repeat infringements. Documenting the decision serves to make our measures traceable and to justify them to those affected and to authorities.

Legal basis for the processing

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in operating a safe and legally compliant platform and in protecting the rights of other users and of third parties. Insofar as we are legally obliged to act against unlawful content or to provide information, the legal basis is Art. 6(1)(c) GDPR.

Disclosure of data

As a matter of principle, we do not disclose the identity of the reporting person to the reported person. Disclosure to third parties only takes place where we are legally obliged to do so, for example on the basis of an official or judicial order, or where this is necessary for the establishment, exercise or defence of legal claims.

Preventing the processing

Reporting content is voluntary. If your content has been reported, you can object to the processing under Art. 21 GDPR; we will then examine whether our legitimate interests in the safety of the platform prevail. You can contest a decision about the removal of your content at any time by writing to contact@loggd.me.

Storage period

We store reports and the associated decision for 12 months after the review has been completed, in order to be able to detect repeat infringements. Longer storage only takes place insofar as this is necessary for the establishment, exercise or defence of legal claims or for compliance with legal obligations.

What this means

You can report other people's content if it infringes the law or our terms. We review every report.

What data: the reported content, who reported it, whose content was reported, the reason, the time and our outcome.

Why: so that the platform stays safe and legally compliant and so that we can detect repeat infringements.

We do not tell the reported person who reported them.

If your content was removed, you can contact us and have the decision reviewed.

Storage period: 12 months after the review is completed, longer only in the event of legal disputes.

6.8 Subscriptions and purchase processing via Apple, Google and RevenueCat

Paid subscriptions are processed exclusively as in-app purchases through the Apple App Store or through Google Play. Apple and Google are the contracting parties for the payment transaction and process your payment data under their own responsibility and in accordance with their own privacy policies. We never receive your payment data, in particular no card numbers, bank details or billing addresses. To verify and manage your subscription status we use the service RevenueCat.

List of data processed

The following data is processed through RevenueCat in connection with your subscription:

  • A pseudonymous user identifier that we associate with your account

  • Identifier of the purchased product and of the subscription

  • Purchase and renewal times, expiry date, cancellation and refund status

  • Status of the purchase receipt of the respective app store

  • Platform (iOS or Android), app version and operating system version

  • Country or region of the app store account and currency

  • Transaction amount

Payment data such as card numbers or bank details is transmitted neither to RevenueCat nor to us. It remains exclusively with Apple or Google.

Purpose of processing this data

The processing serves to verify the purchase receipt of your app store, to unlock the features belonging to your subscription, to reflect renewals, cancellations and refunds correctly, and to make your subscription available across devices. In addition, we need this information for our own accounting and to answer support enquiries about your subscription.

Legal basis for the processing

The legal basis is Art. 6(1)(b) GDPR, as the processing is necessary for the performance of the subscription agreement with us. Insofar as we store transaction data to comply with commercial and tax retention obligations, the legal basis is Art. 6(1)(c) GDPR.

Disclosure of data

The purchase is processed by Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) or Google Commerce Limited (Gordon House, Barrow Street, Dublin 4, Ireland). These companies are independently responsible for the payment processing. The subscription status is managed by RevenueCat, Inc., established in San Francisco, California, USA, as our processor. We have concluded a data processing agreement with RevenueCat pursuant to Art. 28 GDPR. As RevenueCat processes data in the United States, this constitutes a third-country transfer; details can be found in section 7.

Preventing the processing

Without this processing we cannot provide you with a paid subscription. If you do not want this processing, you can use the free features of the platform and refrain from subscribing. You can cancel your subscription at any time in the subscription settings of your app store; you carry out the cancellation directly with Apple or Google.

Storage period

We store your current subscription status for as long as your account exists. Transaction data forming part of our accounting records is retained for 10 years in accordance with the statutory retention obligations under § 147 AO and § 257 HGB. The retention periods of the respective providers apply to the payment data stored by Apple and Google.

What this means

You buy subscriptions as an in-app purchase through the Apple App Store or Google Play. They process the payment, not us.

We never see your payment data: no card number, no bank details, no billing address.

We use RevenueCat to check whether your subscription is active and to unlock your features.

What data: a pseudonymous identifier, which product you bought, purchase and renewal times, status, platform, country and amount.

Where: Apple and Google in Ireland, RevenueCat in the United States. For the transfer to the US see section 7.

You can cancel your subscription at any time in the settings of your app store, not with us.

Storage period: subscription status for as long as your account exists, accounting-relevant data for 10 years (required by law).

6.9 Error diagnostics with GlitchTip (only with your consent)

We run our own instance of the software GlitchTip in order to detect and fix crashes and technical errors in our app. This feature is switched off by default. It is only activated if you explicitly consent during onboarding or in the privacy settings.

List of data processed

  • A pseudonymous installation or device identifier with no link to your account

  • Error message and technical call history (stack trace)

  • Time of the error

  • App version and build

  • Operating system and its version

  • Device model and basic device information

  • Language setting of the device

  • Technical context of the last actions before the error

We deliberately do not transmit any account data, email address or content you have created to the error diagnostics.

Purpose of processing this data

The processing serves exclusively to detect crashes and malfunctions, determine their cause and fix them. We need the technical details about the device and operating system in order to reproduce errors that only occur on certain devices or system versions.

Legal basis for the processing

Access to information on your terminal equipment takes place on the basis of your consent under § 25(1) TDDDG. We base the subsequent processing of the data on your consent under Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future.

Disclosure of data

We run GlitchTip ourselves on our own infrastructure with Hetzner in Germany. No disclosure to third parties takes place. The data does not leave Germany.

Preventing the processing

The feature is switched off by default. It is only activated with your explicit consent. You can withdraw your consent at any time in the app's privacy settings; from the moment of withdrawal, no further error reports are transmitted. The lawfulness of processing carried out before the withdrawal remains unaffected.

Storage period

Error reports are deleted automatically after 90 days.

What this means

We use our own GlitchTip to find and fix crashes and errors in the app.

Off by default: this feature is deactivated and only becomes active if you explicitly consent during onboarding or in the settings.

What data: a pseudonymous device identifier with no link to your account, the error message with technical call history, app and system version, device model and time.

Not transmitted: your account, your email address and your content.

Where: on our own servers in Germany. No disclosure to third parties.

You can withdraw your consent at any time in the privacy settings.

Storage period: 90 days, then deleted automatically.

6.10 App updates and usage analytics with Expo

Our app is built on the Expo platform. We use Expo for two separate purposes, to which different rules apply: first, for delivering app updates, and second, for optional, pseudonymous analysis of app usage.

Delivery of app updates

Through the EAS Update service we can deliver improvements and bug fixes directly to the installed app without you having to install a full update from the app store. In doing so, your app asks Expo whether a new version is available. The data processed in this context is your IP address, the installed app and runtime version, the platform, and the time and result of the request. This processing is necessary so that we can provide you with a functional and secure app and takes place on the basis of Art. 6(1)(b) GDPR in conjunction with Art. 6(1)(f) GDPR.

Usage analytics (only with your consent)

In addition, we can analyse how the app is used through Expo Insights and Expo Observe. This feature is switched off by default and is only activated if you explicitly consent during onboarding or in the privacy settings.

List of data processed

  • A pseudonymous installation or session identifier with no link to your account

  • Events triggered in the app and views accessed

  • Technical performance data such as app start time (cold start) and response times

  • App version, runtime version and platform

  • Operating system and its version, device model

  • A coarse regional assignment derived from the IP address

No link to your account takes place. We do not use advertising identifiers such as IDFA or GAID and do not carry out any cross-provider tracking. A request under Apple's App Tracking Transparency is therefore not required.

Purpose of processing this data

The analysis helps us understand which features are used, where users drop off and where the app is too slow. On this basis we improve usability, stability and speed.

Legal basis for the processing

Access to information on your terminal equipment for the usage analytics takes place on the basis of your consent under § 25(1) TDDDG. We base the subsequent processing on your consent under Art. 6(1)(a) GDPR. You can withdraw this consent at any time with effect for the future. The separate legal basis stated above applies to the delivery of app updates.

Disclosure of data

The provider is 650 Industries, Inc. (Expo), established in the United States. Expo processes the data as our processor on the basis of a data processing agreement pursuant to Art. 28 GDPR. As processing takes place in the United States, this constitutes a third-country transfer; details can be found in section 7.

Preventing the processing

The usage analytics is switched off by default and is only activated with your explicit consent. You can withdraw your consent at any time in the app's privacy settings. You cannot object to the check for app updates, as it is necessary for providing the app securely.

Storage period

Analytics data is stored by Expo for a maximum of 12 months and then deleted. Request data arising from update delivery is retained only briefly for operational and security purposes.

What this means

Our app is built on Expo. We use Expo for two things, to which different rules apply.

App updates: we can deliver improvements directly to the app without you needing a store update. This is technically necessary and cannot be switched off.

Usage analytics: off by default. Only becomes active if you explicitly consent during onboarding or in the settings.

What data for the analytics: a pseudonymous identifier with no link to your account, events triggered, app start time, app and system version, device model and a coarse region.

No advertising identifiers, no cross-provider tracking, no link to your account.

Where: Expo is based in the United States. For the transfer to the US see section 7.

You can withdraw your consent at any time in the privacy settings.

Storage period: analytics data for a maximum of 12 months.

6.11 Contact

If you contact us by email, through our contact form or through a support function in the app, we process your data in order to handle your enquiry.

List of data processed

  • Username or the name you provide

  • Email address

  • Content of your message

  • Time of contact

  • When using the contact form: IP address as protection against misuse

Purpose of processing this data

We process your contact details in order to answer your enquiry and provide you with support. Documenting the communication protects both sides and allows us to refer back to earlier correspondence if you follow up.

Legal basis for the processing

The legal basis is generally Art. 6(1)(f) GDPR, as we have a legitimate interest in answering enquiries. If your enquiry concerns an existing or future contractual relationship, the legal basis is Art. 6(1)(b) GDPR.

Disclosure of data

We do not disclose your contact details to third parties. Disclosure only takes place where this is strictly necessary in order to answer your enquiry or where we are legally obliged to do so.

Preventing the processing

Without your contact details we cannot answer your enquiry. If you do not want this processing, you must refrain from contacting us. Once the communication has been concluded you can request erasure of your data, provided no retention obligations apply.

Storage period

We delete general enquiries no later than 6 months after they have been finally dealt with. Insofar as the correspondence qualifies as a commercial letter, we retain it for 6 years in accordance with § 257(4) HGB and § 147 AO; documents of accounting relevance are retained for 10 years.

What this means

If you write to us by email, contact form or support, we store your data so that we can reply to you.

What data: name or username, email, your message, timestamp. With the contact form also the IP address as protection against misuse.

Why: to answer your enquiry and provide support. The documentation protects both sides.

Disclosure: as a matter of principle, none.

Storage period: general enquiries no later than 6 months after conclusion. Business correspondence 6 years, accounting documents 10 years (required by law).

Once the communication has ended you can request erasure, provided no statutory retention obligation applies.

6.12 Newsletter via Brevo

We offer you the option of subscribing to our newsletter in order to be informed about new features, offers and news.

List of data processed

  • Email address (required)

  • Username

  • Time of registration

  • IP address at the time of registration (to document the registration process)

  • Time of confirmation (double opt-in)

  • Open rate (whether and when you open newsletters)

  • Click behaviour (which links you click in the newsletter)

  • Device information (device type, operating system, email client)

  • Time of unsubscription (where applicable)

Purpose of processing this data

We process your data in order to send you our newsletter with information about new features, special offers and news about Loggd on a regular basis. Recording open and click rates serves to measure the success of our campaigns and helps us understand which content is most relevant to our subscribers. Storing your IP address and the registration and unsubscription times serves as evidence that you subscribed legitimately and protects us against abusive registrations by third parties.

Legal basis for the processing

The legal basis for sending the newsletter and for the success measurement it contains is Art. 6(1)(a) GDPR, based on your explicit consent. You give this consent through the double opt-in procedure: after registering you receive an email with a confirmation link. Only if you click this link is your registration activated. The processing for documenting the registration is based on Art. 6(1)(f) GDPR, as we have a legitimate interest in being able to demonstrate the legitimacy of the registration.

Disclosure of data

To send our newsletter we use the service Brevo (Brevo GmbH, formerly Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; parent company: Brevo SAS, Paris, France). Brevo processes your data as our processor on the basis of an agreement pursuant to Art. 28 GDPR. All newsletter data is stored and processed on servers within the European Union.

Preventing the processing

You can withdraw your consent to receiving the newsletter at any time free of charge. At the end of every newsletter you will find an unsubscribe link that lets you unsubscribe with one click. Alternatively you can send us an email to privacy@loggd.me or withdraw your consent directly in your profile settings under Privacy. After unsubscribing you are removed from our distribution list immediately. Withdrawing your consent does not affect the lawfulness of processing carried out before the withdrawal.

Storage period

We store your newsletter data for as long as you are subscribed. After you unsubscribe, your data is deleted from the active distribution list. We store the documentation data (IP address, time of registration and unsubscription) for 3 years so that we can demonstrate in the event of a dispute that the registration was legitimate. This storage is based on our legitimate interest under Art. 6(1)(f) GDPR.

Tracking in the newsletter

Our newsletters contain so-called tracking pixels (web beacons). A tracking pixel is a small graphic file embedded in emails that allows us to see whether and when you opened a newsletter. The links contained in the newsletter carry parameters so that we can track which links were clicked. This information is used exclusively for statistical purposes. It is not combined with other personal data and is not disclosed to third parties. If you do not want this tracking, you can disable the display of images in your email program or reject HTML emails in general. However, this may affect how the newsletter is displayed.

What this means

You can subscribe to our newsletter to receive information about new features and offers.

What data: email (required), username, registration time, IP address, whether and when you open newsletters, which links you click, device information.

Why: to send you newsletters and to see which content interests you, so that we can improve them.

Double opt-in: you have to confirm your registration via a link in an email; only then will you receive newsletters.

Where: we use Brevo, based in Berlin. All data stays in the EU.

Tracking: we can see whether and when you open newsletters and which links you click. You can prevent this by disabling images in your email program.

Unsubscribing: at any time free of charge, via the link in the newsletter, by email to privacy@loggd.me or in your profile settings.

Storage period: for as long as you are subscribed. After unsubscribing the data is deleted; the documentation (IP, timestamp) is kept for 3 years as evidence.

7. Transfers to countries outside the EU

The vast majority of our processing takes place in Germany. Our servers, our database and our error diagnostics are operated exclusively in German data centres. In the following cases, however, processing outside the European Union may occur:

  • RevenueCat, Inc. (USA) - management of your subscription status, see section 6.8

  • 650 Industries, Inc. / Expo (USA) - delivery of app updates and, only with your consent, usage analytics, see section 6.10

  • Bunny (global server network) - content delivery and attack protection, see section 6.2

We ensure an adequate level of protection for these transfers in accordance with Chapter V GDPR. No adequacy decision of the European Commission applies to the providers concerned; in particular, they are not certified under the EU-US Data Privacy Framework. We therefore base the transfer on the standard contractual clauses of the European Commission (Implementing Decision (EU) 2021/914, Module Two: controller to processor) pursuant to Art. 46(2)(c) GDPR.

In addition, we have assessed the level of protection in the respective recipient country and taken supplementary technical and organisational measures. These include in particular encryption in transit and at rest, strict data minimisation and the use of pseudonymous identifiers with no link to your real name. We transmit neither the content you have created nor your contact details to the providers named, with the exception of the pseudonymous user identifier required for subscription management.

You can request a copy of the relevant safeguards from us at privacy@loggd.me.

Please note that despite these measures a residual risk remains: in third countries the level of data protection may differ from that in the European Union, in particular with regard to the access powers of state authorities and the legal remedies available to data subjects.

8. Minors

Our services are not directed at children. A minimum age of 16 is required to use our platform.

Insofar as we base processing on your consent and you have not yet reached the age of 16, that consent is only valid under Art. 8(1) GDPR if it is given or authorised by the holder of parental responsibility.

We do not knowingly collect personal data from persons under the age of 16. If we become aware that an account has been created contrary to this requirement, we will delete it and the associated data. If you believe that a child has created an account without the required authorisation, please contact us at privacy@loggd.me.

9. Changes to this privacy policy

We adapt this privacy policy when our services, the providers we use or the legal requirements change. The current version published on our website and in our app applies in each case.

In the case of material changes, in particular where these require new consent or significantly alter the purposes of processing, we will inform you in an appropriate form in good time before they take effect, for example by email or through a prominent notice in the app.