Privacy Policy
Note: The legally binding version of this Privacy Policy is the German text. This English translation is provided for convenience only, has not been reviewed by a lawyer, and may not reflect recent updates. German law (GDPR / DSGVO, TDDDG) applies.
Controller
The controller responsible for data processing on this website is:
TODO: Firmenname mit Rechtsformzusatz (oder Vor-/Nachname bei Einzelunternehmen)
TODO: Straße Hausnummer
TODOTODO: Ort
Phone: TODO: +49 ...
E-mail: TODO: kontakt@example.invalid
General information
We process personal data only to the extent necessary to provide a functional website and service. Legal bases are Art. 6(1) GDPR and, where terminal equipment is accessed, § 25 TDDDG. This website uses no marketing cookies and no profiling. Analytics are only activated if you have given your prior explicit consent (see below).
The service: data minimisation as a core principle
Our media/playlist player deliberately requires no user account and no name or e-mail address to use the app itself. Instead, a licence is bound to an internally derived device identifier:
-
The native platform identifier of your device is NEVER stored in plain text. It is
processed into an HMAC-SHA-256 value on the client and server; only that hash and a
derived 48-bit device code visible on-screen (displayed like a MAC address, e.g.
A7:3F:92:CD:81:4E) are stored — neither allows the original identifier to be reconstructed. -
Credentials for your own playlist source (Xtream credentials or M3U URLs containing
credentials) are stored exclusively using AES-256-GCM encryption. They are never logged
in plain text, included in error messages, or displayed on the website in plain text
(only masked, e.g.
s*****82). - The legal basis for these processing operations is performance of the contract (Art. 6(1)(b) GDPR) — licence verification is not possible without device binding.
Website session (technically necessary cookie)
After you enter your device code we set a single, technically necessary session cookie
(website_device_session) used solely for authentication during playlist
management (max. 15 minutes, HttpOnly, not readable via JavaScript). This cookie does not
require consent under § 25(2)(2) TDDDG as it is necessary to provide the function you
explicitly requested (playlist management). The legal basis for the related processing is
Art. 6(1)(b) GDPR.
Analytics (PostHog, only with your consent)
If you consent via the consent banner, we measure use of this website with PostHog. For
EU users the provider is PostHog BV, Netherlands; data are processed on the EU instance
(eu.i.posthog.com). PostHog is only loaded after you give consent — if you
decline or make no choice, no third-party script is executed and no cookie is set.
Data collected: pages visited, timestamp, approximate origin (derived from IP address), browser and device information, and a random identifier in a cookie grouping your visits into a session. Deliberately NOT collected:
- No automatic capture of clicks or form fields — your device code cannot enter the analytics this way.
- No session recording (no capture of your screen content).
- No personal profiles — we transmit no identifier that identifies you.
- In addition, strings matching the format of a device code are redacted before transmission.
The legal basis for accessing your terminal equipment is your consent under § 25(1) TDDDG; for subsequent processing it is Art. 6(1)(a) GDPR. You may withdraw your consent at any time with effect for the future by clearing website data (local storage and cookies) in your browser — you will then be asked again.
Hosting
This website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA (Cloudflare Pages). When you access the website, Cloudflare processes technically necessary connection data (IP address, date and time of access, page requested, User-Agent) to deliver the website and protect it from attacks. Legal basis: our legitimate interest in secure and performant operation (Art. 6(1)(f) GDPR). A data-processing agreement (Art. 28 GDPR) is in place. Cloudflare is certified under the EU-US Data Privacy Framework; EU Standard Contractual Clauses additionally apply as a transfer safeguard. Further information: cloudflare.com/privacypolicy.
Database and back-end service
For device registration, licence checking and encrypted playlist storage we use Supabase, operated in an EU data centre (region: TODO: EU-Region (z. B. Frankfurt) - noch nicht final eingerichtet). Provider: Supabase, Inc. A data-processing agreement (Art. 28 GDPR) is in place; Standard Contractual Clauses additionally cover any transfers to third countries. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Payment processing (Stripe)
For licence purchases we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The payment process takes place on a Stripe-hosted page (Stripe Checkout); you leave our website during this step.
What we send to Stripe: solely an internal purchase reference, the amount and the currency. We do not transmit your device code, name, address or e-mail address — we do not hold these.
What we receive back from Stripe: the payment identifier, amount paid with currency, payment timestamp, and — where determined by Stripe — the country code. We need the country code for tax allocation. No tax amount arises as no VAT is charged under § 19 German VAT Act. Payment data such as card numbers never reach us.
Stripe processes the payment data (card or account details) under its own responsibility. Stripe's privacy policy applies: stripe.com/privacy.
Legal basis: Art. 6(1)(b) GDPR (performance of the purchase contract) and for the retention of transaction data Art. 6(1)(c) GDPR in conjunction with statutory retention obligations under commercial and tax law.
Note: the description above accurately reflects what our software actually transmits and stores. The legal classification of the relationship with Stripe (data processor vs. independent controller), specific retention periods and transfer safeguards for third country transfers have not yet been reviewed by a lawyer and need to be addressed before further sales.
Withdrawal and e-mail dispatch (Resend)
If you declare a withdrawal at /widerruf, we store the timestamp, a reference number and the link to your device. Name, e-mail address and any note are voluntary — your withdrawal is valid without them.
If you provide an e-mail address, we send you the legally required confirmation of receipt (§ 356a(3) German Civil Code). For dispatch we use Resend (Plus Five Five, Inc., 2261 Market Street, San Francisco, CA 94114, USA). We transmit only your e-mail address plus the reference number and timestamp — not your name and not your note. The internal notification to us also contains only the reference number; anyone processing the case looks up the details in our database, not in an e-mail.
Legal basis for dispatch: Art. 6(1)(c) GDPR (compliance with § 356a(3) German Civil Code). If you provide no address, no dispatch takes place and no data are transmitted to Resend. Storage of the withdrawal declaration itself is based on Art. 6(1)(c) GDPR in conjunction with statutory retention obligations.
Note: Resend is based in the USA, making this a third-country transfer. A data-processing agreement and the required transfer safeguards (Standard Contractual Clauses, adequacy decision) have not yet been reviewed and need to be addressed before further operation. We mention the service here because a concealed recipient would be the more serious deficiency.
Encryption
This website uses TLS encryption for security reasons (indicated by "https://" and the padlock symbol in your browser's address bar).
Retention periods
We store personal data only for as long as necessary for the respective purpose or as required by statutory retention obligations. Deleted playlists are permanently deleted after a 48-hour recovery window.
Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
Consent given may be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), e.g. TODO: zuständige Landesdatenschutzbehörde (Bundesland Firmensitz) + URL.
Note: this page currently contains placeholder data (see src/data/impressum.ts, src/data/datenschutz.ts) and must be completed and reviewed by a lawyer before publication.
As of: August 2026