Privacy Policy
Last updated: August 10, 2026
This Privacy Policy explains how Untether GbR ("we," "us," or "our") processes personal data when you use the HQ mobile application, website, dashboard, and related services (together, the "Service"). It is intended to provide the information required by the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable privacy laws.
1. Controller
Controller:
Untether Gesellschaft bürgerlichen Rechts (GbR) Partners: Fabian S. Klinke, Louis Köhler, Paul Vogler, Roger Nussbaum Represented jointly by its partners Uhlandstr. 171/172 10719 Berlin, Germany
Privacy contact:
2. Data We Process
Account and Authentication
- Email address, username, password hash, authentication provider, account and session identifiers
- Access and refresh tokens, sign-in events, device and app metadata used for authentication and security
- Purposes: Create and secure accounts, maintain sessions, prevent fraud, and provide support
- Legal basis: Performance of contract (Art. 6(1)(b) GDPR); legitimate interests in security and abuse prevention (Art. 6(1)(f))
Profile, Communities, and Content
- Display name, avatar, city, country, selected communities, roles, badges, and profile preferences
- Posts, comments, reactions, links, images, videos, audio, RSVP records, saved items, read state, XP, and leaderboard activity
- For media uploads: a temporary upload ID, object path, file size, media type, content digest, target community/audience, status, and expiry time
- For imported images and videos, the original file may be held temporarily to validate signed Content Credentials before a cropped or converted version is published. We retain the verification result, source digest, signer and claim metadata, and whether a trusted credential identifies the media as AI-generated or AI-edited; we do not use visual AI classifiers for this label.
- Purposes: Operate profiles, feeds, communities, shows, social features, rewards, content delivery, and trustworthy media-origin labels
- Legal basis: Performance of contract; legitimate interests in operating and improving the Service
Direct Messages
- Message text, attachments, participants, replies, timestamps, delivery/read state, and conversation metadata
- Purposes: Deliver and synchronize conversations; investigate a conversation when a participant reports abuse or when legally required
- Legal basis: Performance of contract; legitimate interests in safety and legal compliance
Unreported conversations are not routinely reviewed. Direct-message content is not used for general promotion or included in moderation-training source data or model-training releases. Reported messages may be used to investigate the report, but remain outside the release pipeline.
When you report a direct message, we preserve the selected message, up to four nearby messages within a limited time window, attachment storage references, conversation-participant identifiers, report reason, and optional context. This evidence is access-restricted, audited through the moderation case workflow, and retained only for the investigation, appeal, legal-claim, or legal-hold period that applies.
Shows and Location
- City and country; optional coordinates, accuracy, timestamps, notification radius, and background-location preference
- Show, venue, artist, attendance, and booking-integration data
- IP-derived approximate city hints for the public shows catalog
- Purposes: Surface relevant shows, support check-in and location features, import artist-authorized booking data, and send requested notifications
- Legal basis: Performance of contract; consent for precise or background location where required; legitimate interests for coarse city suggestions
Moderation, Legal Notices, and Safety
- Reports, reporter and target identifiers, categories, context, timestamps, weighting signals, moderator notes, decisions, appeals, and legal notices
- Temporary visibility restrictions, enforcement history, and repeat-violation records
- Purposes: Enforce our rules, process illegal-content and copyright notices, protect users, prevent abuse, and establish or defend legal claims
- Legal basis: Legitimate interests in safety and integrity; legal obligations (Art. 6(1)(c)); establishment, exercise, or defense of legal claims where applicable
Analytics, Diagnostics, and Security Logs
- Device model, operating system, app/browser version, IP address, request timing and status, login and interaction events, session and device identifiers, online heartbeat events, crash traces, operational logs, and feedback-linked diagnostic identifiers
- Purposes: Maintain security and reliability, diagnose failures, measure feature usage, calculate aggregated product metrics, and prevent abuse
- Legal basis: Legitimate interests in security, reliability, and service improvement; consent where required for non-essential device access or personalized third-party telemetry
HQ uses first-party product analytics and Sentry. First-party product analytics is enabled by default and records allowlisted, authenticated service-interaction events, including account, install, session, feature, view, and content references. We use it for product measurement based on our legitimate interests, not for advertising or sale. You may object to legitimate-interest processing as described in Section 9.
The iOS app offers Personalized, Anonymized, and Off modes for Sentry in Privacy settings. Personalized mode associates an HQ account identifier with diagnostics; Anonymized mode omits that identifier; Off disables Sentry. A current, timestamped choice is required before iOS Sentry starts. On the website and dashboard, minimized error reporting is enabled by default to maintain security and reliability. Browser Sentry is error-only: browser performance tracing, SDK logs, and breadcrumbs are disabled, and events are stripped of account data, request headers and bodies, cookies, query strings, URL fragments, and explicit extra data before transmission. We do not run Vercel client-side behavioral analytics. Server security, reliability, request, and aggregate product-measurement logs remain enabled where necessary or otherwise lawfully processed.
Email, Support, and Applications
- Email-delivery address and status, notification preferences, consent or opt-out records, support messages, feedback, access requests, and artist applications
- Purposes: Send essential service communications, send optional product emails where permitted, answer support requests, and review applications
- Legal basis: Performance of contract and legitimate interests for essential communications; consent or another applicable statutory permission for optional promotional email
New users receive a separate optional-email choice during onboarding. At the July 16, 2026 cutover, an existing account with no stored email-preference row can receive a legacy-enabled preference so that prior product behavior is not silently changed. That legacy preference is not a record of consent and does not by itself authorize a promotional message. Each optional campaign must still rely on valid consent or another applicable statutory permission, and every recipient can unsubscribe or change the canonical HQ preference.
3. Sensitive or Special-Category Data
We do not ask users to provide health, political, religious, sexual-orientation, biometric, or other special-category data. However, user-generated content, direct messages, reports, and media can reveal such information. We do not use that information to infer sensitive traits, target advertising, or build sensitive-trait profiles.
Where special-category data is present, the applicable Art. 9 GDPR condition depends on the context. This may include data the user has manifestly made public, explicit consent obtained for a specific use, or processing necessary to establish, exercise, or defend legal claims. Private or reported content is excluded from model-training releases unless the release passes an irreversible anonymization review. This area requires case-specific review when a new sensitive-data use is introduced.
4. How We Use Data
We use personal data to:
- Provide accounts, communities, feeds, messaging, shows, notifications, mini games, rewards, and support
- Personalize content based on communities, city, and user-controlled location settings
- Authenticate requests, secure the Service, detect fraud, and prevent abuse
- Moderate content and process Community Guidelines, DSA, copyright, and other legal notices
- Diagnose crashes and performance problems and measure product usage
- Train and evaluate spam, abuse-prevention, and safety tooling under the safeguards in Section 5
- Meet legal obligations and establish, exercise, or defend legal claims
We do not sell personal data or use it for third-party behavioral advertising.
5. Model Development and Anonymous Training Releases
Moderation source records and review datasets can contain pseudonymous identifiers and user-generated text. We treat those source records as personal data even when obvious identifiers have been removed.
We may retain a training release without a fixed end date only after we have documented that it is anonymous: it must contain no stable source, author, moderator, or account identifiers; no exact source timestamps or mapping table; and no text or context reasonably likely to identify, single out, or link a person to the source Service. Certified anonymous releases and models shown not to expose personal data are no longer personal data under the GDPR.
The release process excludes direct messages and does not copy source text verbatim. It replaces identifying details with semantic placeholders, quarantines text with unsafe identifying context, and releases generalized post/comment text with its complete safety-label combination only when at least five distinct contributors share that result. Contributor identifiers are used only during verification and are not written to the release. No source mapping is kept in the release store. Each release has a manifest and extraction/linkage risk assessment. Existing legacy exports are deleted before the anonymous backfill is generated. Canonical labels and label-review history remain in the personal staging corpus under the normal retention and deletion rules.
Until that standard is met, the source set and quarantined rows remain subject to this Policy, data-subject rights, purpose limitation, account deletion, and the retention criteria below. Consent does not create an irrevocable right to retain identifiable training data forever.
6. Providers and Other Recipients
The following list reflects integrations currently present in the Service. A provider may be our processor for some operations and an independent recipient for others.
| Provider | Role and purpose | Data involved |
|---|---|---|
| Supabase, Inc. | Authentication, Postgres database, Realtime, Storage, and related backend services | Account, profile, content, message, moderation, preference, and application data |
| Amazon Web Services EMEA SARL and affiliates (AWS) | API, queues, serverless processing, object storage, content delivery, operational logs, and analytics infrastructure | Requests, identifiers, content handled by backend jobs, raw analytics including source IP and derived city/country, delivery records, and logs |
| Functional Software, Inc. (Sentry) | Crash reporting, server performance and operational diagnostics, and user-submitted feedback | Device/app data, IP/network metadata, minimized diagnostic context, and account identifier or feedback email where deliberately supplied through iOS or feedback flows |
| Vercel Inc. | Website/dashboard hosting, content delivery, and platform operational logs | Web requests, IP/device metadata, requested routes, approximate geography, browser/device attributes, and operational logs |
| Plus Five Five, Inc. (Resend) | Essential and optional email delivery, including application-related email | Recipient email, names and application fields where included, message content, delivery status, and unsubscribe/suppression data |
| Apple | Sign in with Apple, APNs, MapKit, and Apple platform services | Apple account relay data, device tokens and notification payloads, map/search requests, IP/device metadata |
| Google LLC | Google Maps Platform place search, geocoding, time-zone lookup and embedded maps; YouTube oEmbed metadata | Search terms, addresses/coordinates, show or venue data, video IDs, API request metadata; browser IP/device data for embeds |
| KIKLIKO, Inc. (KLIPY) | GIF search, retrieval, and media delivery in chat | Search terms, locale, configured customer/device identifier, IP/device metadata |
| Duck Duck Go, Inc. | Website favicon retrieval | Requested domain and IP/device request metadata |
| Volentio JSD Limited (jsDelivr) and its CDN providers | Dashboard map data and PDF worker delivery | IP/device request metadata and requested asset |
| ABOSS B.V. | Artist-authorized booking/show import | Artist project identifier and token, public event/show data, and request metadata |
MaxMind supplies the GeoLite2 database used by our AWS backend for local IP-to-city lookup. Runtime visitor IP addresses are looked up in our copy of that database and are not sent to MaxMind for each lookup.
We may also disclose data to professional advisers, insurers, auditors, transaction counterparties, courts, regulators, or law-enforcement authorities where necessary and lawful. Where a provider acts as our processor, we require Art. 28 GDPR terms where applicable. Provider contracts, subprocessor lists, and transfer mechanisms are maintained separately and must be reviewed when integrations change.
7. International Transfers
We use EU regions where configured, including for core Supabase, AWS, and Sentry workloads. Some providers or their subprocessors may process data outside the EU/EEA. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another valid transfer safeguard, together with supplementary measures where appropriate. You may request information about the safeguard relevant to your data.
8. Retention
We apply the following periods or criteria:
- Active accounts and content: While the account is active and the data is needed to provide the Service.
- Account deletion: We schedule personal data for deletion or anonymization after the 30-day cooling-off period stated in the account-deletion flow, subject to legal holds, safety investigations, and records we must retain by law.
- Operational logs: AWS application logs are generally retained for 30 days. Other diagnostic-provider retention follows the configured project period and is reviewed against security and troubleshooting need.
- Incomplete media uploads: Temporary upload records and unattached media expire after 24 hours and are removed by the hourly cleanup job. Untouched provenance source files are deleted after verification, or by the same expiry cleanup if verification does not complete. The resulting Content Credentials assessment follows the completed post media and account-deletion rules above.
- Raw product analytics: Retained while reasonably necessary to calculate, validate, and improve product metrics. The criteria are continued analytical usefulness, identifiability, account status, security need, and the availability of aggregated or anonymous replacements.
- Moderation and legal records: Retained for the life of the case and as long as reasonably needed for appeals, repeat-violation enforcement, legal obligations, or legal claims.
- Moderation-training source and staging exports: Personal source rows follow the applicable content/account retention and deletion rules. Rebuildable staging exports expire after 30 days.
- Email and consent records: Retained while the preference is active and as needed to prove consent, opt-out, suppression, or delivery compliance.
- Backups: Deleted data can remain in encrypted rolling backups until those backups are overwritten under the ordinary backup schedule. Backups are isolated, are not used for ordinary product access, and deletion records must be reapplied if a backup is restored.
- Anonymous data: Aggregates, certified anonymous training releases, and anonymous model artifacts may be retained indefinitely because they can no longer be attributed to a person by means reasonably likely to be used.
This approach does not require editing each immutable log entry or backup in place. It does require bounded backup rotation, access restrictions, and a restore procedure that reapplies deletions.
9. Your Rights
Depending on applicable law, you may have rights to:
- Access, correct, or erase personal data
- Restrict processing or object to processing based on legitimate interests
- Receive portable data you provided to us
- Withdraw consent without affecting prior lawful processing
- Opt out of optional email and push notifications
- Lodge a complaint with a supervisory authority, including the Berliner Beauftragte für Datenschutz und Informationsfreiheit
Email privacy@untether.social to exercise a right. We may verify your identity and normally respond within one month. Rights do not apply to data that has already been irreversibly anonymized because we can no longer identify which records relate to you.
10. Cookies, SDKs, and Similar Technology
We do not use advertising cookies. Authentication can use cookies or secure device storage that are necessary to keep you signed in. The website and dashboard do not store a browser analytics preference or run Vercel client-side behavioral analytics. Minimized browser error reporting is enabled by default as described in Section 2. The iOS app stores the selected Sentry mode, decision version, and timestamp on the device. These tools may process technical information from a device even where no advertising cookie is set.
11. Security
We use measures including encryption in transit, provider encryption at rest, role-based access, least-privilege controls, private storage, audit records, and security review. No system is completely secure. We follow applicable breach-assessment and notification duties if an incident occurs.
12. Adults Only
The Service is for people who are at least 18 years old. New iOS and web users must confirm that they are at least 18 during onboarding. Web onboarding also requires acceptance of the current Terms, Privacy Policy, and Community Guidelines before profile completion. If we learn that a user is under 18, we may restrict the account and request the information needed to delete or otherwise resolve it.
13. Automated Processing
We use rules and automated signals to detect spam, prioritize reports, calculate abuse-prevention signals, and temporarily limit content visibility. We also validate cryptographically signed Content Credentials to label media that a trusted signer identifies as AI-generated or AI-edited; this label is informational and does not by itself remove or restrict content. Final content-removal and account-sanction decisions are intended to involve human review. Contact legal@untether.social to contest a moderation decision.
14. Changes
We may update this Policy when the Service, providers, or law changes. We will give appropriate notice of material changes. Where a change requires consent, continued use alone will not replace that consent.
15. Contact
For privacy questions or complaints, contact privacy@untether.social or write to the Controller at the address above.