Privacy Policy
Last updated: September 12, 2026
This Privacy Policy explains how Untether GbR ("we," "us," or "our") processes personal data when you use the HQ mobile application, website, dashboard, and related services (together, the "Service"). It is intended to provide the information required by the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable privacy laws.
1. Controller
Controller:
Untether Gesellschaft bürgerlichen Rechts (GbR) Partners: Fabian S. Klinke, Louis Köhler, Paul Vogler, Roger Nussbaum Represented jointly by its partners Uhlandstr. 171/172 10719 Berlin, Germany
Privacy contact:
2. Data We Process
Account and Authentication
- Email address, username, password hash, authentication provider, account and session identifiers
- Access and refresh tokens, sign-in events, device and app metadata used for authentication and security
- Purposes: Create and secure accounts, maintain sessions, prevent fraud, and provide support
- Legal basis: Performance of contract (Art. 6(1)(b) GDPR); legitimate interests in security and abuse prevention (Art. 6(1)(f))
Adult Eligibility and Policy Acceptance
HQ is for people aged 18 and older. We record your explicit adult declaration, the policy and confirmation-copy versions, the time of acceptance, the client (web or iOS), and app version. On supported Apple devices, we request an age range with an 18-year threshold. We retain only a coarse indication of an adult range and its declaration source, not your date of birth, identity documents, or the full range. An Apple Account declaration may be self-declared and is not proof of identity.
If Apple indicates that you are not at least 18, the app prevents you from continuing and directs you to correct inaccurate Apple Account information. Where Apple requires age-range sharing, a declined or unavailable required result does not permit access. Otherwise, self-declaration is available when sharing is declined or unavailable. Existing members without a record must make an explicit declaration; account creation is not treated as prior consent.
The iOS app also keeps a local, account-specific flag when Apple supplies an underage range. This prevents a later declined or unavailable response from overriding that result on the same installation. An adult Apple range clears the flag; it otherwise remains in the app's local data until that data is erased. This flag is not sent to HQ's servers and is separate from the server acceptance record.
We use these records to administer adult-only eligibility and document agreement to the Service's rules (Art. 6(1)(b) GDPR), and to maintain evidence of those declarations (Art. 6(1)(f) GDPR). Records are retained with your account and deleted when the authentication account is permanently deleted under the account-deletion process. Acknowledging this Privacy Policy is not consent to optional analytics or marketing.
Profile, Communities, and Content
- Display name, avatar, city, country, selected communities, roles, badges, and profile preferences
- Posts, comments, reactions, links, images, videos, audio, RSVP records, saved items, read state, XP, and leaderboard activity
- For media uploads: a temporary upload ID, object path, file size, media type, content digest, target community/audience, status, and expiry time
- For imported images and videos, the original file may be held temporarily for one advisory check of signed Content Credentials. This check does not delay or retry publication. We retain the check result, source digest, signer and claim metadata, and whether a trusted credential identifies the media as AI-generated or AI-edited. For images, we also retain whether the author marked the image as made with AI. We do not use visual AI classifiers for these labels.
- Images attached to posts can be analyzed to categorize their scenes and objects, including existing post images and new uploads. This does not include avatars, show artwork, or private conversation images. We retain broad scene and object labels, categories, confidence, text geometry and density (not the detected words), detector model and analysis versions, and a digest identifying the analyzed image. These observations let HQ apply display rules without analyzing the same image again. The records follow the source post and media deletion lifecycle. A separate public-gallery decision can include people, crowds, clubs, concerts, and nightlife scenes and exclude screenshots, documents, interface captures, text-heavy images, and unclear results. Classification does not grant permission to display a post publicly or change its audience. We do not identify people, recognize faces, infer sensitive traits, or use this analysis to hide the post inside HQ or determine whether it was made with AI.
- Purposes: Operate profiles, feeds, communities, shows, social features, rewards, content delivery, trustworthy media-origin labels, and curated public galleries
- Legal basis: Performance of contract; legitimate interests in operating and improving the Service
Direct Messages
- Message text, attachments, participants, replies, timestamps, delivery/read state, and conversation metadata
- Purposes: Deliver and synchronize conversations; investigate a conversation when a participant reports abuse or when legally required
- Legal basis: Performance of contract; legitimate interests in safety and legal compliance
Unreported conversations are not routinely reviewed. Direct-message content is not used for general promotion or included in moderation-training source data or model-training releases. Reported messages may be used to investigate the report, but remain outside the release pipeline.
When you report a direct message, we preserve the selected message, up to four nearby messages within a limited time window, attachment storage references, conversation-participant identifiers, report reason, and optional context. This evidence is access-restricted, audited through the moderation case workflow, and retained only for the investigation, appeal, legal-claim, or legal-hold period that applies.
Shows and Location
- City and country; optional coordinates, accuracy, timestamps, notification radius, and background-location preference
- Show, venue, artist, attendance, and booking-integration data
- Free-entry, half priced, and skip list eligibility, offers, responses, fulfillment status, check-in status, and related XP adjustments or temporary distribution restrictions
- The mandatory price and currency stored for a half priced offer, which HQ displays before acceptance but does not collect as payment
- The given name and family name that you provide when you accept an offer. We show this name to the relevant artist and, when needed for entry, the artist's promoter, venue, or ticket provider. The recipient depends on the artist's entry arrangements.
- The pool-level timestamp and account or staff actor recorded when the artist confirms that all finalized entry details have been sent
- IP-derived approximate city hints for the public shows catalog
- Purposes: Surface relevant shows, allocate artist-provided free-entry, half priced, and skip list places fairly, prepare entry lists or deliver tickets, verify attendance, support check-in and location features, import artist-authorized booking data, and send requested notifications
- Legal basis: Performance of contract; consent for precise or background location where required; legitimate interests in fair allocation, preventing unused places, and providing coarse city suggestions
Guest-list allocation uses RSVP status and the user's XP leaderboard rank in the relevant artist community. When one user is eligible for several artists at the same show, the allocation process also seeks to give a place to as many different people as possible. A half priced offer shows the amount payable and currency before the user accepts. A skip list offer provides full-price entry without queuing. HQ records its tier and capacity but does not store a separate skip list price. HQ displays this information but does not collect payment or provide an automated ticket-provider integration. An offer requires a separate confirmation. The confirmation screen explains the attendance commitment, the possible 500 XP deduction, and the three-calendar-month distribution restriction before the user accepts. A no-show consequence applies only when an offer is finalized and the artist has confirmed once that all finalized entry details were sent. HQ or an authorized administrator handles attendance corrections and disputes during the stated review period. Contact legal@untether.social if you want to contest an unresolved restriction or XP deduction.
Moderation, Legal Notices, and Safety
- Reports, reporter and target identifiers, categories, context, timestamps, weighting signals, moderator notes, decisions, appeals, and legal notices
- Temporary visibility restrictions, enforcement history, and repeat-violation records
- Purposes: Enforce our rules, process illegal-content and copyright notices, protect users, prevent abuse, and establish or defend legal claims
- Legal basis: Legitimate interests in safety and integrity; legal obligations (Art. 6(1)(c)); establishment, exercise, or defense of legal claims where applicable
Analytics, Diagnostics, and Security Logs
- Device model, operating system, app/browser version, preferred device language and regional locale at login, IP address, request timing and status, login and interaction events, session and device identifiers, online heartbeat events, crash traces, operational logs, and feedback-linked diagnostic identifiers
- Purposes: Maintain security and reliability, diagnose failures, measure feature usage, calculate aggregated product metrics, prioritize language support using aggregated device settings, and prevent abuse
- Legal basis: Legitimate interests in security, reliability, and service improvement; consent where required for non-essential device access or personalized third-party telemetry
HQ uses first-party product analytics and Sentry. First-party product analytics is enabled by default and records allowlisted, authenticated service-interaction events, including account, install, session, feature, view, and content references. We use it for product measurement based on our legitimate interests, not for advertising or sale. You may object to legitimate-interest processing as described in Section 9.
The iOS app offers Personalized, Anonymized, and Off modes for Sentry in Privacy settings. Personalized mode associates an HQ account identifier with diagnostics; Anonymized mode omits that identifier; Off disables Sentry. A current, timestamped choice is required before iOS Sentry starts. On the website and dashboard, minimized error reporting is enabled by default to maintain security and reliability. Browser Sentry is error-only: browser performance tracing, SDK logs, and breadcrumbs are disabled, and events are stripped of account data, request headers and bodies, cookies, query strings, URL fragments, and explicit extra data before transmission. We do not run Vercel client-side behavioral analytics. Server security, reliability, request, and aggregate product-measurement logs remain enabled where necessary or otherwise lawfully processed.
Email, Support, and Applications
- Email-delivery address and status, notification preferences, consent or opt-out records, support messages, feedback, access requests, and artist applications
- Purposes: Send essential service communications, send optional product emails where permitted, answer support requests, and review applications
- Legal basis: Performance of contract and legitimate interests for essential communications; consent or another applicable statutory permission for optional promotional email
New users receive a separate optional-email choice during onboarding. At the July 16, 2026 cutover, an existing account with no stored email-preference row can receive a legacy-enabled preference so that prior product behavior is not silently changed. That legacy preference is not a record of consent and does not by itself authorize a promotional message. Each optional campaign must still rely on valid consent or another applicable statutory permission, and every recipient can unsubscribe or change the canonical HQ preference.
Sources and Data We Derive
We receive personal data:
- Directly from you, including when you create an account, complete a profile, publish content, send a message, select a preference, report content, contact support, or submit an application
- Automatically from your device and use of the Service, including authentication, request, diagnostic, security, analytics, and location-permission data described above
- From other users, including messages sent to you, content that mentions or depicts you, reports, reactions, attendance information, and other social interactions
- From services you connect or ask us to use, including Sign in with Apple, artist-authorized ABOSS imports, and AI agents or other clients you authorize through OAuth
- From public or third-party sources, including public show, venue, link-preview, favicon, map, and YouTube metadata used to provide a requested feature
We also generate data from these sources, such as an approximate city derived locally from an IP address, aggregated product metrics, content-origin assessments, report-priority signals, moderation records, and personalized feed or show results. We do not use these results to infer special-category traits.
Fields identified as required, authentication proof, the adult-eligibility assertion, and the applicable policy acknowledgment are needed to create and secure an account. Data needed for an optional feature, such as precise location or an artist booking integration, is required only if you choose that feature. If you do not provide required data, we may be unable to create the account or provide the requested feature. Other profile, content, location, telemetry, and communication choices are optional unless we explain otherwise when collecting them.
3. Sensitive or Special-Category Data
We do not ask users to provide health, political, religious, sexual-orientation, biometric, or other special-category data. However, user-generated content, direct messages, reports, and media can reveal such information. We do not use that information to infer sensitive traits, target advertising, or build sensitive-trait profiles.
We do not use private messages, report narratives or evidence, or support content for promotion, personalization, general analytics, or model development. Diagnostics exclude message and content bodies and sensitive profile fields.
Every intentional special-category use requires a documented Art. 6 GDPR legal basis and Art. 9 condition. Explicit consent for a specific use, information manifestly made public by the data subject, and processing necessary for legal claims are assessed in their specific context; public availability or a report alone does not create a blanket permission. New intentional uses require privacy review and screening for a data protection impact assessment before implementation. Reported private content is accessed for the case by authorized staff, with access auditing and retention limited to the case or documented legal need.
4. How We Use Data
We use personal data to:
- Provide accounts, communities, feeds, messaging, shows, notifications, mini games, rewards, and support
- Personalize content based on communities, city, and user-controlled location settings
- Authenticate requests, secure the Service, detect fraud, and prevent abuse
- Moderate content and process Community Guidelines, DSA, copyright, and other legal notices
- Diagnose crashes and performance problems and measure product usage
- Train and evaluate spam, abuse-prevention, and safety tooling under the safeguards in Section 5
- Meet legal obligations and establish, exercise, or defend legal claims
We do not sell personal data or use it for third-party behavioral advertising.
5. Model Development and Anonymous Training Releases
Moderation source records and review datasets can contain pseudonymous identifiers and user-generated text. We treat those source records as personal data even when obvious identifiers have been removed.
We may retain a training release without a fixed end date only after we have documented that it is anonymous: it must contain no stable source, author, moderator, or account identifiers; no exact source timestamps or mapping table; and no text or context reasonably likely to identify, single out, or link a person to the source Service. Certified anonymous releases and models shown not to expose personal data are no longer personal data under the GDPR.
The release process excludes direct messages and does not copy source text verbatim. It replaces identifying details with semantic placeholders, quarantines text with unsafe identifying context, and releases generalized post/comment text with its complete safety-label combination only when at least five distinct contributors share that result. Contributor identifiers are used only during verification and are not written to the release. No source mapping is kept in the release store. Each release has a manifest and extraction/linkage risk assessment. Existing legacy exports are deleted before the anonymous backfill is generated. Canonical labels and label-review history remain in the personal staging corpus under the normal retention and deletion rules.
Until that standard is met, the source set and quarantined rows remain subject to this Policy, data-subject rights, purpose limitation, account deletion, and the retention criteria below. Consent does not create an irrevocable right to retain identifiable training data forever.
6. Providers and Other Recipients
The following list reflects integrations currently present in the Service. A provider may be our processor for some operations and an independent recipient for others.
| Provider | Role and purpose | Data involved |
|---|---|---|
| Supabase, Inc. | Authentication, Postgres database, Realtime, Storage, and related backend services | Account, profile, content, message, moderation, preference, and application data |
| Amazon Web Services EMEA SARL and affiliates (AWS) | API, queues, serverless processing, object storage, content delivery, stateless image analysis for public-gallery curation, operational logs, and analytics infrastructure | Requests, identifiers, content handled by backend jobs, image bytes and derived broad scene/text signals, raw analytics including source IP and derived city/country, delivery records, and logs |
| Functional Software, Inc. (Sentry) | Crash reporting, server performance and operational diagnostics, and user-submitted feedback | Device/app data, IP/network metadata, minimized diagnostic context, and account identifier or feedback email where deliberately supplied through iOS or feedback flows |
| Vercel Inc. | Website/dashboard hosting, content delivery, and platform operational logs | Web requests, IP/device metadata, requested routes, approximate geography, browser/device attributes, and operational logs |
| Plus Five Five, Inc. (Resend) | Essential and optional email delivery, including application-related email | Recipient email, names and application fields where included, message content, delivery status, and unsubscribe/suppression data |
| Apple | Sign in with Apple, APNs, MapKit, and Apple platform services | Apple account relay data, device tokens and notification payloads, map/search requests, IP/device metadata |
| Google LLC | Google Maps Platform place search, geocoding, time-zone lookup and embedded maps; YouTube oEmbed metadata | Search terms, addresses/coordinates, show or venue data, video IDs, API request metadata; browser IP/device data for embeds |
| KIKLIKO, Inc. (KLIPY) | GIF search, retrieval, and media delivery in chat | Search terms, locale, configured customer/device identifier, IP/device metadata |
| Duck Duck Go, Inc. | Website favicon retrieval | Requested domain and IP/device request metadata |
| Volentio JSD Limited (jsDelivr) and its CDN providers | Dashboard map data and PDF worker delivery | IP/device request metadata and requested asset |
| ABOSS B.V. | Artist-authorized booking/show import | Artist project identifier and token, public event/show data, and request metadata |
MaxMind supplies the GeoLite2 database used by our AWS backend for local IP-to-city lookup. Runtime visitor IP addresses are looked up in our copy of that database and are not sent to MaxMind for each lookup.
We may also disclose data to professional advisers, insurers, auditors, transaction counterparties, courts, regulators, or law-enforcement authorities where necessary and lawful. Where a provider acts as our processor, we require Art. 28 GDPR terms where applicable. Provider contracts, subprocessor lists, and transfer mechanisms are maintained separately and must be reviewed when integrations change.
When you authorize an AI agent or another third-party client through OAuth, that client can receive and change only the HQ data and actions available through the authorized integration. The current show integration permits draft show management and does not permit publishing. The client operator processes the data it receives under its own terms and privacy notice. You can deny the authorization or revoke the client’s access.
Profile information and content are visible to other HQ users or the public according to the feature, community, role, and audience you select. Public information can be copied, indexed, cached, or shared by others outside HQ. Direct messages are disclosed to their participants and, only in the limited cases described above, to authorized moderators or legal recipients.
When you open an external link, map, embed, GIF, favicon, or other remotely hosted media, your device can connect directly to that external operator. The operator receives the requested URL and ordinary network data, such as your IP address and device or browser information, under its own terms and privacy notice.
To keep scrolling smooth, HQ may preload nearby images and GIF previews before they enter the visible area. These requests use the same media providers and account access controls as displaying the media.
If Untether is involved in a proposed or completed reorganization, financing, merger, acquisition, insolvency, or transfer of all or part of the Service, we may disclose the minimum personal data needed to professional advisers and transaction parties, subject to confidentiality, purpose limitation, and applicable law. A successor that becomes controller must continue to protect the data under applicable law and provide any required notice.
7. International Transfers
We use EU regions where configured, including for core Supabase, AWS, and Sentry workloads. Some providers or their subprocessors may process data outside the EU/EEA. Where required, we rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another valid transfer safeguard, together with supplementary measures where appropriate. You may request information about the safeguard relevant to your data.
8. Retention
We apply the following periods or criteria:
- Active accounts and content: While the account is active and the data is needed to provide the Service.
- Account deletion: We schedule personal data for deletion or anonymization after the 30-day cooling-off period stated in the account-deletion flow, subject to legal holds, safety investigations, and records we must retain by law.
- Operational logs: AWS application logs are generally retained for 30 days. Other diagnostic-provider retention follows the configured project period and is reviewed against security and troubleshooting need.
- Guest-list records: We redact the accepted name snapshot 90 days after the show unless a live dispute, legal hold, or legal claim requires longer retention. We keep minimized offer, response, stored price and currency, fulfillment, attendance, pool-level sent timestamp and actor, restriction, and XP-adjustment records while they are needed to operate the feature, resolve a dispute, enforce the stated restriction, or establish or defend legal claims.
- Incomplete media uploads: Temporary upload records and unattached media expire after 24 hours and are removed by the hourly cleanup job. Untouched provenance source files are deleted after the advisory check attempt. A separate storage-cleanup ledger handles a failed deletion without retrying the post. The resulting Content Credentials assessment follows the completed post media and account-deletion rules above.
- Raw product analytics: Retained while reasonably necessary to calculate, validate, and improve product metrics. The criteria are continued analytical usefulness, identifiability, account status, security need, and the availability of aggregated or anonymous replacements.
- Moderation and legal records: Retained for the life of the case and as long as reasonably needed for appeals, repeat-violation enforcement, legal obligations, or legal claims.
- Moderation-training source and staging exports: Personal source rows follow the applicable content/account retention and deletion rules. Rebuildable staging exports expire after 30 days.
- Email and consent records: Retained while the preference is active and as needed to prove consent, opt-out, suppression, or delivery compliance.
- Personal data downloads: Generated download archives expire seven days after they are ready and are automatically deleted. We retain a minimized request and review record as needed to document our response and meet legal obligations.
- Backups: Deleted data can remain in encrypted rolling backups until those backups are overwritten under the ordinary backup schedule. Backups are isolated, are not used for ordinary product access, and deletion records must be reapplied if a backup is restored.
- Anonymous data: Aggregates, certified anonymous training releases, and anonymous model artifacts may be retained indefinitely because they can no longer be attributed to a person by means reasonably likely to be used.
This approach does not require editing each immutable log entry or backup in place. It does require bounded backup rotation, access restrictions, and a restore procedure that reapplies deletions.
9. Your Rights
Depending on applicable law, you may have rights to:
- Access, correct, or erase personal data
- Restrict processing or object to processing based on legitimate interests
- Receive portable data you provided to us
- Withdraw consent without affecting prior lawful processing
- Opt out of optional email and push notifications
- Lodge a complaint with a supervisory authority, including the Berliner Beauftragte für Datenschutz und Informationsfreiheit
Email privacy@untether.social to exercise a right. We may verify your identity and normally respond within one month. Rights do not apply to data that has already been irreversibly anonymized because we can no longer identify which records relate to you.
Where available in your version of HQ, Download my data in account settings lets you request a machine-readable copy of your personal data. Your signed-in account session is sufficient to request and download an export; no additional identity verification is required. We collect and prepare the data automatically in the background and email you a link when your private download is ready. Account settings show its status and expiry. The accompanying manifest explains the included categories and any omissions. Specific records may require additional collection or review to protect other people's rights or apply a valid legal restriction. You can use the privacy email above if you cannot sign in, need help, or want to follow up on an incomplete export; the self-service feature does not limit your rights.
10. Cookies, SDKs, and Similar Technology
We do not use advertising cookies, cross-site advertising identifiers, session replay, or Vercel client-side behavioral analytics. The website and dashboard use the following browser storage:
| Name or type | Where | Purpose | Duration |
|---|---|---|---|
sb-<project-ref>-auth-token and any numbered chunks | Website and dashboard cookie | Maintain and refresh the signed-in Supabase session and protect authenticated routes | Until the session expires, you sign out, or the cookie is cleared |
b90hq-theme | Website and dashboard local storage | Remember the light, dark, or system theme that you select | Until you change it or clear site data |
sidebar_state | Dashboard cookie | Remember whether you left the dashboard sidebar open | Seven days |
hq.shows.visitor-city-attempted.v1 | Website session storage | Avoid repeating the optional IP-derived city suggestion during the same browser session | Until the browser session ends |
These mechanisms provide authentication, security, or a setting or feature that you request. We do not use them to advertise to you or track you across unrelated services.
Minimized browser Sentry error reporting is enabled by default as described in Section 2. It does not set an HQ analytics preference or enable browser performance tracing, but its SDK can read technical runtime and error information when an error occurs. The iOS app uses secure device storage for authentication and stores the selected Sentry mode, decision version, and timestamp on the device. You can change the Sentry mode in Privacy settings. Device or browser controls can clear website storage, but clearing authentication storage signs you out and clearing a preference causes the default behavior to apply again.
11. Security
We use measures including encryption in transit, provider encryption at rest, role-based access, least-privilege controls, private storage, audit records, and security review. No system is completely secure. We follow applicable breach-assessment and notification duties if an incident occurs.
12. Adults Only
The Service is for people who are at least 18 years old. New iOS and web users must confirm that they are at least 18 during onboarding. Web onboarding also requires acceptance of the current Terms, Privacy Policy, and Community Guidelines before profile completion. If we learn that a user is under 18, we may restrict the account and request the information needed to delete or otherwise resolve it.
13. Automated Processing
We use rules and automated signals to detect spam, prioritize reports, calculate abuse-prevention signals, and temporarily limit content visibility. We label media as AI-generated or AI-edited when a trusted Content Credential identifies it as such. We also label an image as AI-generated when its author declares this. Separate automated image analysis decides whether a public post image is suitable for HQ's public marketing galleries. A negative or unclear gallery decision does not hide the image or post inside HQ and is not an account or moderation decision. Final content-removal and account-sanction decisions are intended to involve human review. Contact legal@untether.social to contest a moderation decision.
14. Changes
We may update this Policy when the Service, providers, or law changes. We will give appropriate notice of material changes. Where a change requires consent, continued use alone will not replace that consent.
15. Contact
For privacy questions or complaints, contact privacy@untether.social or write to the Controller at the address above.