Privacy Policy for the shiver App
This is a translation for convenience only. The German version of this privacy policy is the legally binding one.
Last updated: 13 August 2026
This privacy policy applies to the mobile application shiver
(iOS and Android, package identifier jetzt.zest.shiver) and to
the server services accessible through the app. It describes which personal
data we process, for which purpose, on which legal basis and for how long. The
website zest.jetzt itself is covered by the separate
privacy policy for the website.
1. Controller
The controller within the meaning of Art. 4 no. 7 GDPR is:
Zest UG (haftungsbeschränkt)
Stadtplatz 39
84529 Tittmoning
Germany
Represented by the managing director Justin Brandon Pratt
Register court (Registergericht): Amtsgericht Traunstein
Commercial register number (Handelsregisternummer): HRB 35020
Email: info@offline-events.de
Phone: +49 1512 9786245
For all questions concerning data protection and for exercising your rights as a data subject, you can reach us at the email address given above. No data protection officer has been appointed; the conditions of Art. 37 GDPR and § 38 BDSG (German Federal Data Protection Act) currently do not apply to us, as we do not permanently employ at least 20 people in the automated processing of personal data, and neither large-scale processing of special categories of data nor a core activity requiring extensive regular and systematic monitoring takes place.
2. Principles and scope
shiver is a platform for short, horizontally recorded videos that are created and published by the users themselves. Operating the platform is not possible without processing certain personal data: an account needs an identifier, a video needs an author, a comment needs a sender. In doing so we process exclusively data that is necessary for the operation, the security and the legally required moderation of the platform.
We use no analytics SDK, use no advertising identifiers (no IDFA, no Android Advertising ID), integrate no third-party advertising networks or trackers and do not access the GPS location of your device. We do not sell data and do not disclose it for advertising purposes.
3. Your rights as a data subject
You have the following rights vis-à-vis us:
- Access (Art. 15 GDPR), you may request information as to whether and which personal data we process about you, and receive a copy of that data.
- Rectification (Art. 16 GDPR), you may request the correction of inaccurate data and the completion of incomplete data. You can change your display name, username, biography and profile picture yourself in the app at any time.
- Erasure (Art. 17 GDPR), you may request the erasure of your data, unless a statutory retention obligation or an overriding legitimate interest (such as the investigation of a reported legal violation) stands in the way. The app contains a self-service function for this purpose, see section 12.
- Restriction of processing (Art. 18 GDPR), you may request that we restrict the processing of your data, for example while the accuracy of the data is being verified. We point out openly that the app has no technical state for this: we implement a restriction organisationally, by excluding the records concerned internally from further use. Where a restriction cannot be implemented technically, we instead offer you the erasure of the data concerned.
- Data portability (Art. 20 GDPR), you may receive the data you have provided in a structured, commonly used and machine-readable format, or request its transmission to another controller, insofar as this is technically feasible.
- Withdrawal of consent (Art. 7(3) GDPR), insofar as processing is based on your consent, you may withdraw it at any time with effect for the future. The lawfulness of the processing carried out up to the withdrawal remains unaffected.
Right to object under Art. 21 GDPR: you have the right, on grounds relating to your particular situation, to object at any time to the processing of personal data concerning you which is carried out on the basis of a legitimate interest (Art. 6(1)(f) GDPR). We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims. Please address your objection informally to info@offline-events.de.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other legal remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your residence, your place of work or the place of the alleged infringement. The supervisory authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany
Phone: +49 981 180093-0
Email: poststelle@lda.bayern.de
4. Overview of all processing activities
The following table lists every processing activity that takes place when operating shiver. The subsequent sections explain the most important points in detail.
| Purpose | Categories of data | Legal basis | Storage period |
|---|---|---|---|
| Registration, sign-in and management of the user account | Email address, password (only as a cryptographic hash), username, display name, profile picture, biography, time of registration and of the last sign-in; when signing in via "Sign in with Apple" additionally the identity token transmitted by Apple, the (where applicable anonymised) relay address provided by Apple and, only at the first sign-in, the name, as well as a one-time authorization code which we store in order to be able to revoke access when an account is deleted; when signing in via Google additionally the Google account identifier, the email address together with its verification status, the display name and the link to the Google profile picture (details in section 11) | Art. 6(1)(b) GDPR (performance of the user contract) | Until the account is deleted by you or by us |
| Publication of uploaded videos, their transcoding and their delivery to other users | Video file, thumbnail, title or description, hashtags, technical metadata (resolution, duration, file size, format), time of upload, link to your account; optionally a coarse location in the form of the coordinates of a city selected by you (section 6); when a video is retrieved, the IP address and the technical connection data of the retrieving device vis-à-vis our streaming service provider Mux (section 11) | Art. 6(1)(b) GDPR | Until the video is deleted by you, until removal following a moderation decision, or until account deletion |
| Interactions: likes, comments, follows | Comment text, reference to the video, like and follow relationships, timestamps, link to your account | Art. 6(1)(b) GDPR | Until deleted by you, until the referenced object is deleted, or until account deletion |
| Direct messages between users | Message content, sender and recipient account, timestamp, read status | Art. 6(1)(b) GDPR | Until deleted by the participants or until account deletion; the copy held by the other conversation participant remains |
| Feed ordering and recommendations (feed_score) | Usage events relating to videos: playback duration and completion rate, like, comment and follow events, time of publication and of interaction | Art. 6(1)(b) GDPR (provision of the contractually owed feed function) | Individual events are stored linked to your account and are deleted at the latest when the account or the video is deleted; they feed into the score only in aggregated form per video |
| Delivery and billing of promoted clips | For a promoted clip: the fact of a qualified view (it increments a plain counter on the campaign), and, per campaign, clip and account, an event for a tap on the promotion button or a visit to the promoted profile. Whether you already follow an advertiser, or have already tapped, decides whether the advert is still delivered to you at all | Art. 6(1)(b) GDPR (provision of the service) and Art. 6(1)(f) GDPR (billing the advertiser and capping frequency) | Deleted at the latest when your account is deleted; the advertiser learns totals only, never who reacted |
| Handling of reports (notice and action procedure under Art. 16 DSA) | Identifier of the reported content or account, reason for the report, free-text report, identifier of the reporting person, time, moderation decision and its statement of reasons | Art. 6(1)(c) GDPR in conjunction with Regulation (EU) 2022/2065 (DSA); additionally Art. 6(1)(f) GDPR (platform security) | Until the review is concluded; beyond that, for as long as required to fulfil the record-keeping, statement-of-reasons and reporting obligations under the DSA and to defend against legal claims |
| Automated pre-screening of content at upload | Description or title, hashtags and comment text as well as individual frames from the uploaded video, both are transmitted to the moderation interface of OpenAI in the USA (section 11), screening result (approved, flagged for manual review, rejected) | Art. 6(1)(c) GDPR (obligations under the DSA and the JMStV, the German Interstate Treaty on the Protection of Minors in the Media); additionally Art. 6(1)(f) GDPR | The screening result is stored with the content and deleted with it |
| Delivery of push notifications about events concerning your account | Push token, operating system, the device's language and time-zone offset, notification settings, time of consent, time sent and time opened | Art. 6(1)(a) GDPR (consent) | Until consent is withdrawn, until the app is uninstalled, after 90 days without contact between the device and the app, and at the latest on account deletion |
| Processing and verification of the shiver Premium subscription | Identifier of the product purchased, the transaction or purchase
identifier issued by the store (Apple: originalTransactionId,
Google: purchaseToken), status of the subscription, start and
end of the current period, link to your account. No payment
data, card and account details remain with Apple and Google
respectively (section 13) |
Art. 6(1)(b) GDPR (performance of the subscription contract); Art. 6(1)(c) GDPR where commercial and tax retention obligations apply | Until the end of the subscription and the erasure of the account; where retention obligations apply, until they expire |
| Operational and security logs of the backend infrastructure (prevention of abuse, troubleshooting) | IP address, time, endpoint called, HTTP status code, user agent or app version | Art. 6(1)(f) GDPR (legitimate interest in secure and trouble-free operation) | Short-term; deleted as soon as the purpose ceases to apply, at the latest in accordance with the specifications of our processor |
| Storage of the sign-in session on your device | Session and refresh token in the protected app storage | § 25(2) no. 2 TDDDG (strictly necessary) in conjunction with Art. 6(1)(b) GDPR | Until sign-out, expiry of the session, or uninstallation of the app |
5. Registration and account
Using shiver requires an account. When registering with an email address we require a valid email address, a password and a username. The email address is used for signing in, for resetting the password and for messages relating to the operation of the service (such as security notices or notifications about moderation decisions). After registration we send a confirmation email; the account only becomes usable once you have opened the link it contains. We do not send advertising to this address. These account emails, confirmation and password reset, are sent via Twilio SendGrid (section 11).
Alternatively you can create an account and sign in via Google; on iOS "Sign in with Apple" is additionally available. In this case we receive the data that the respective provider transmits to us, from Google the account identifier, the email address, the display name and the link to the profile picture; from Apple the identity token, the email address (at your choice an anonymised relay address) and, at the first sign-in, your name. Details and the associated transmission are described in section 11. You then choose a username in the app.
Your password is never known to us in plain text; it is stored exclusively as a salted cryptographic hash. Display name, profile picture and biography are optional. Please note that username, display name, profile picture and biography are publicly visible, including to people without an account, insofar as content is shared outside the app. Your email address is not visible to other users.
The legal basis is Art. 6(1)(b) GDPR: without this data the user contract cannot be performed.
6. Uploaded content and its visibility
When you upload a video, we store the video file, a thumbnail generated from it, the title or description you have provided, hashtags as well as technical metadata such as resolution, duration, file size and format. This data is linked to your account. The video file is then handed over to our service provider Mux in the USA, which converts it into a streaming format suitable for playback and later delivers it to the end devices; details are set out in section 11.
Coarse location for a video
A video can carry a coarse location. It originates exclusively from a city that you select yourself from a fixed list in the "Nearby" feed (currently Berlin, London, New York, Tokyo and São Paulo); what is stored are the coordinates of the city centre and the name of the city. No location sensor of your device is read out, neither GPS nor Wi-Fi or cell tower positioning, and no information more precise than the city you selected is created. Like the video itself, the location is publicly retrievable and serves solely to assign the video to the selected city in the "Nearby" feed. It is deleted together with the video. The legal basis is Art. 6(1)(b) GDPR.
Published videos are public: they appear in the feed, in hashtag search and on your profile, and can be accessed by all users. Please do not upload recordings containing personal data of third parties unless you are entitled to do so. For content in which other people are identifiable, you share responsibility under data protection law; as a rule you need their consent.
We do not evaluate the content of your videos for profiling or advertising purposes. Automated screening takes place exclusively for the purpose of moderation (section 9). If you delete a video, it is removed from the database and from file storage including the thumbnail, the location, comments, likes and the associated playback and ranking events; for the transcoded version held at Mux we place an order for deletion (section 12). We cannot remove copies already made by third parties outside the app.
7. Comments, likes and follows
We store comments together with the text, the time, the reference to the commented video and the link to your account. Comments are public and are displayed under your username. We store likes as a relationship between your account and the video; the number of likes is publicly visible. We store follows as a relationship between two accounts; follower and following counts are publicly visible.
This processing is necessary in order to provide the social functions you have requested (Art. 6(1)(b) GDPR). You can withdraw your own comments, likes and follows in the app at any time; they are then deleted.
8. Direct messages
Direct messages are stored on our servers so that they can be delivered and read on multiple devices. We store the message content, sender and recipient account, timestamp and read status.
Important: direct messages are not end-to-end encrypted. Transmission is encrypted in transit (TLS) and the data is stored encrypted on the servers of our processor, but technically we are able to access it. We do not read direct messages routinely and do not evaluate them for recommendations or statistics. Access only takes place if a message is reported or if we are legally obliged to do so. Do not transmit particularly sensitive information via direct messages.
If you delete a message or your account, your copy is removed. The copy of an already delivered conversation held by the recipient remains, because it is at the same time their communication data.
9. Reports and moderation
shiver provides a reporting procedure in the app with which videos, comments and accounts can be reported (Art. 16 of Regulation (EU) 2022/2065, Digital Services Act, DSA). Incoming reports are stored and reviewed by us. In doing so we store the identifier of the reported content, the reason selected, any free text, the identifier of the reporting person, the time as well as the decision taken and its statement of reasons. The reporting person is not disclosed to the reported person.
This storage is necessary in order to process reports, to detect repeated reports and abuse of the reporting system, to produce the statement of reasons for moderation decisions required under the DSA, and to be able to demonstrate the course of events in the event of a dispute. The legal basis is Art. 6(1)(c) GDPR in conjunction with the DSA as well as Art. 6(1)(f) GDPR (security of the platform and protection of the other users).
Automated pre-screening at upload
An automated pre-screening already runs at upload: title, description and comment texts are checked against a word list, and videos go through a technical check before they appear in the feed. Content may be automatically rejected, flagged for manual review or approved. While the screening is running, a video is visible only to you.
The description and the hashtags of an upload are in addition transmitted to the moderation interface of OpenAI in the USA and checked there automatically for prohibited content. Once transcoding has finished, individual still frames from the video are additionally transmitted to the same interface and checked there for prohibited image content. Both screenings are active; details and the basis for the transfer to the USA are set out in section 11. A screening of individual frames from the video by an external image recognition service (Hive) is technically prepared but not activated: no video content is currently transmitted to Hive.
If content is automatically rejected or not published, we inform you of the decision and its reason. You can object to the decision and request a review by a human; to do so, contact info@offline-events.de.
Contractually we reserve the right to suspend an account temporarily pending clarification (section 3.2 of the Terms of Use). Technically, only deletion is currently available to us, the app does not yet have a "temporarily suspended" state. Before a deletion we therefore primarily take content-related measures (removal of the content concerned, notice to the person concerned).
10. Ranking and recommendations
The order of the videos in the feeds results from a score which we
internally call feed_score. Only the following signals feed into
it:
- Completion, the proportion of a video that is watched on average before scrolling on. Videos that are frequently watched to the end receive a higher value.
- Engagement, likes, comments and follows that a video has triggered, in relation to the number of views.
- Velocity, the speed at which a video receives reactions, i.e. engagement per unit of time since publication.
- Freshness, the age of the video; older content continuously loses weight through a time decay so that new posts get a chance.
The value is calculated per video, not per person. We do not create interest or personality profiles, do not buy in additional data and do not use signals from outside the app. Your playback events are stored linked to your account: for every video watched, a record is created containing the identifier of your account, the time and the proportion of the video watched. These individual events are therefore personal data and not anonymous. They feed into the score exclusively in aggregated form, that is as a metric of the respective video and not as a characteristic of a person. There is a second purpose: if you watch a promoted clip qualifiedly, the same report additionally increments the view counter of the associated campaign so that the advertiser can be billed; see section 4. They are not evaluated for any purpose beyond these two. When your account is deleted, these individual events are deleted as well (section 12). These statements also serve as information on the main parameters of our recommender system within the meaning of Art. 27 DSA.
No automated decision in an individual case: the ordering of the feed is not an automated decision in an individual case within the meaning of Art. 22(1) GDPR. It has no legal effect on you and does not similarly significantly affect you; it determines solely the order in which publicly accessible videos are displayed. No profiling for advertising or scoring purposes takes place.
11. Processors and third-country transfers
We use carefully selected service providers who process personal data on our instructions; we conclude data processing agreements under Art. 28 GDPR with them. In addition, there are recipients that are independently responsible (eigenverantwortlich) for their part of the processing (such as Google and Apple in the case of the sign-in procedures). The following section names all recipients and states whether and where data is transferred.
Supabase (backend, database, authentication, storage)
The backend of shiver, database, sign-in and file storage for videos and
images, is operated via Supabase (project identifier
ofhlepxizdoktdhpbaab). The data is held in the AWS region
eu-west-1 (Ireland) and thus within the European Union. In
this respect no transfer to a third country takes place. All
data listed in section 4 is processed. The legal basis for the processing is
Art. 6(1)(b) GDPR. Account emails are not sent via the mail
service integrated in Supabase but via Twilio SendGrid (see below).
Important, data storage is not entirely limited to the EU: database, sign-in and the original file storage are located in Ireland. The video files and the entire playback traffic additionally run via Mux, Inc. in the USA (see below). Anyone watching a video thereby establishes a direct connection to servers in the USA.
Twilio SendGrid (delivery of account emails), active
The emails concerning your account, the confirmation of registration and the password reset, are sent via SendGrid. Our contracting party and processor is Twilio Ireland Limited, 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland; for technical operation it engages Twilio Inc., 101 Spear Street, San Francisco, CA 94105, USA, as a sub-processor. Transmitted are your email address, the subject and content of the respective message and technical delivery data (time, delivery status). Your videos, comments, direct messages and your usage behaviour are not transmitted. The legal basis is Art. 6(1)(b) GDPR (performance of the usage contract). This function is active.
The processing takes place in the USA. The basis for the transfer to the USA is a certification of the recipient under the EU-US Data Privacy Framework on the basis of the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR) and, insofar as the recipient is not or is no longer certified, the conclusion of the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914, Art. 46(2)(c) GDPR) together with supplementary safeguards. We point out that, despite these guarantees, access by state authorities to transmitted data cannot be completely ruled out in the USA and that the level of protection does not in every respect correspond to that of the European Union.
Mux (transcoding, thumbnails and delivery of the videos)
We hand over every published video to Mux, Inc. based in
San Francisco, California, USA (full address:
88 Stevenson Street, San Francisco, CA 94105, USA). Mux transcodes the
uploaded file into an adaptive streaming format suitable for mobile playback,
generates thumbnails from it and subsequently delivers the video to the end
devices. Processed in this context are
the video file itself together with its technical metadata
(resolution, duration, file size, format) and, on every playback, the
IP address and the technical connection data of the retrieving
device, because the video stream and the thumbnails are loaded
directly from the servers of Mux (stream.mux.com,
image.mux.com). This does not only concern the uploading person:
the IP address of every device on which a video is played is transmitted to
Mux on every retrieval. The legal basis is Art. 6(1)(b) GDPR, without
transcoding and delivery, the contractually owed playback of videos cannot be
provided.
Mux processes this data in the USA; a transfer to a third country therefore takes place. The basis for the transfer is a certification of the recipient under the EU-US Data Privacy Framework on the basis of the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR) and, insofar as the recipient is not or is no longer certified, the conclusion of the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914, Art. 46(2)(c) GDPR) together with supplementary safeguards. Here too it applies that access by state authorities in the USA cannot be completely ruled out despite these guarantees. The basis for processing on our behalf under Art. 28 GDPR is Mux's Data Processing Addendum in its version of 1 April 2025, available at www.mux.com/dpa; it forms part of the contractual terms concluded with Mux.
Netlify (delivery of these legal texts)
The website zest.jetzt, on which this policy, the imprint (Impressum), the terms of use and the support page are hosted, is delivered by Netlify. When a page is retrieved, Netlify processes the technically necessary connection data (in particular IP address, time, requested file, user agent) in server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and reliable provision of the pages). Details are set out in the privacy policy for the website.
OpenAI (text and image moderation), active
When a video is uploaded, we transmit the description and the hashtags to the moderation interface of OpenAI (OpenAI Ireland Ltd., Dublin, Ireland; processing via OpenAI OpCo, LLC, San Francisco, USA), which checks the text automatically for prohibited content and returns a screening result. Once transcoding has finished we additionally transmit up to four still frames from the video to the same interface, which checks them for prohibited image content. Only this text and these still frames are transmitted; the complete video file, your name, your email address and your account identifier are not transmitted in this process. This function is active.
Hive (image moderation), prepared, not activated
The app is technically prepared to additionally have individual frames from uploaded videos screened by the image recognition service Hive (Hive AI, Inc., USA). This function is not activated: no video content is currently transmitted to Hive. We will update this policy and announce the activation in the app before the function is switched on.
The processing by OpenAI takes place in the USA; the same would apply to Hive after an activation. The legal basis is Art. 6(1)(c) GDPR (fulfilment of the moderation obligations under the DSA and the JMStV) as well as Art. 6(1)(f) GDPR (protection of users from unlawful content). The basis for the transfer to the USA is a certification of the recipient under the EU-US Data Privacy Framework on the basis of the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR) and, insofar as a recipient is not or is no longer certified, the conclusion of the Standard Contractual Clauses of the European Commission (Implementing Decision (EU) 2021/914, Art. 46(2)(c) GDPR) together with supplementary safeguards. We point out that, despite these guarantees, access by state authorities to transmitted data cannot be completely ruled out in the USA and that the level of protection does not in every respect correspond to that of the European Union.
Sign-in via Apple and Google
On iOS the app offers "Sign in with Apple". If you use this procedure, a sign-in process takes place between your device and Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (for users in the EEA regularly Apple Distribution International Ltd., Ireland): Apple receives the information that you are signing in to shiver, and subsequently transmits to us an identity token, your email address, at your choice as an anonymised relay address ("private relay"), and, at the first sign-in, your name. In addition we store the one-time authorization code issued by Apple in order to be able to revoke the link with your Apple ID when an account is deleted. Apple is independently responsible (eigenverantwortlich) for the processing on its side; Apple's privacy policy applies in that respect. The legal basis on our side is Art. 6(1)(b) GDPR. If you do not use the procedure, no transmission takes place either.
The app also offers sign-in via Google (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; for processing outside the EEA Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). This function is active. If you use it, Google receives the information that you are signing in to shiver and issues us an identity token for your Google account. From that token our authentication service stores, attached to your account:
- the Google account identifier (the values
subandprovider_id) and the issuer of the token (accounts.google.com), - your email address together with its verification status,
- your display name,
- the link (URL) to your Google profile picture. The image itself is not stored by us, and we do not automatically adopt it as your shiver profile picture.
No access or refresh token for Google services is stored. We therefore have no access to your data at Google beyond this sign-in process; in particular we do not read contacts, calendars, photos or emails. Google is independently responsible (eigenverantwortlich) for the processing on its side; Google's privacy policy applies in that respect. The legal basis on our side is Art. 6(1)(b) GDPR. If you do not use the procedure, signing in with an email address and password is available as an equivalent alternative, no transmission to Google takes place.
Push notifications
If you have given your consent, we send you push notifications about events concerning your account, new messages, comments or replies to your posts, new followers, moderation decisions about your content, and notices about payments and payouts. Delivery runs through Firebase Cloud Messaging (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; outside the EEA Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA); on iOS devices Google forwards the message through the Apple Push Notification service (Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA).
For this we process a device identifier generated by your device (push token), the operating system, your device's language and time-zone offset, your notification settings, and the time of your consent. We also record which notification was sent when and whether it was opened. That record serves one purpose only: to cap how many notifications you receive, apart from direct messages and account-related notices, at most three a day, and to switch off a category you evidently do not need. It is not evaluated for advertising or profiling.
What is transmitted to Google per notification is the push token and the title and text shown. Where a notification carries the text of a direct message or a comment, that text is transmitted too; you can switch off the display of message text in the app's settings. Your account identifier, e-mail address and location data are not transmitted.
The legal basis is your consent, Art. 6(1)(a) GDPR. You may withdraw it at any time with effect for the future, in the app under Settings → Notifications, or in your operating system's settings. On withdrawal we delete the push tokens stored for your account. The above statements on the transfer bases (Data Privacy Framework or Standard Contractual Clauses) apply accordingly to the transmission to the USA involved in delivery.
We delete push tokens on withdrawal, on uninstallation of the app, when a device has had no contact with the app for 90 days, and at the latest when your account is deleted.
Other recipients
Beyond the recipients named in this section, we do not pass on your data. In particular, we do not sell any data and do not transmit any data to advertising networks, data brokers, analytics or tracking providers. Any disclosure beyond this only takes place if we are legally obliged or entitled to do so, for example by order of law enforcement authorities or courts, or to enforce our terms of use and to defend legal claims. The app stores of Apple and Google are independently responsible for the distribution of the app; we have no influence on the data collected there (such as purchase history, device data, crash reports), and the privacy notices of the respective providers apply.
12. Storage period and erasure
We store personal data only for as long as is necessary for the purposes set out in section 4. As a general rule: account data and the content linked to it are stored until the account is deleted.
You can delete your account yourself in the app at any time: Settings → Account → Delete account. After a security prompt the deletion is executed server-side and takes effect cascadingly. In particular, the following are deleted:
- the sign-in record including email address and password hash,
- the profile with username, display name, biography and profile picture,
- all videos uploaded by you including thumbnails, locations and metadata, the files are removed from all three storage areas (videos, thumbnails and profile pictures),
- your comments, likes and follow relationships in both directions,
- your copies of direct messages,
- your playback events (the individual view records from section 10) and the share events triggered by you, these records are deleted and not merely detached from your account,
- any stored authorization code from "Sign in with Apple", after it has been used to revoke the link,
- reports submitted by you, insofar as they do not exceptionally remain necessary for evidentiary purposes.
For the transcoded version of your videos stored at Mux, we place an order for deletion with the service provider: if you delete a video or your account, the asset held there is instructed for deletion via Mux's interface. The execution lies with Mux; we cannot bring about the time of the deletion there ourselves and therefore do not guarantee it. Mux does not publish a general retention period; the company states only that it keeps data for as long as it deems necessary for its business purposes. Until Mux has confirmed the deletion to us, the transcoded version may continue to exist there for a transitional period. We have therefore refrained from naming a period here that we cannot substantiate.
The deletion is final and cannot be undone. Alternatively you can request deletion informally by email to info@offline-events.de. Data may continue to be contained in technical backups for a short transitional period until the respective backup is overwritten in the regular cycle; this data is not actively used.
Excluded from deletion is data for which a statutory retention obligation exists, as well as information that we continue to need in order to fulfil our obligations under the DSA, to prevent abuse or for the establishment, exercise or defence of legal claims. This essentially concerns the report and moderation records (reason for the report, report text, decision and statement of reasons); only these are retained in a form relating to a person and are deleted once the purpose ceases to apply. We limit their use organisationally to the stated purpose; the system does not have a technical restriction state (Sperrzustand) for individual records. All remaining residual data is no longer attributable to a person, this concerns purely numerical counters on other people's videos (such as view and share counters) which no longer contain any identifier of your account.
13. shiver Premium (subscription)
Using shiver is free of charge. Anyone who takes out the optional shiver Premium subscription (section 13 of the terms of use) thereby triggers an additional processing operation, which is described here. Without a subscription it does not take place.
What we store. The identifier of the product purchased
(shiver_premium_monthly or shiver_premium_yearly),
the transaction or purchase identifier issued by the store (Apple: the
originalTransactionId, Google: the purchaseToken),
the status of the subscription (active, cancelled, expired, refunded), the
start and end of the current period, and the link to your account. Nothing
more is needed in order to grant Premium and to withdraw it again.
What we do not receive. Payment data. Card and account details, the billing address and the name of the payment method holder remain exclusively with Apple and Google respectively; they are never transmitted to us. Nor do we learn which payment method was used.
Why the data reaches the server. A purchase has to be verified server-side against the systems of the respective provider, otherwise any device could grant itself Premium. The app transmits the receipt issued by the operating system to our server, which verifies it with Apple's App Store Server API or with the Google Play Developer API and stores the result. Subsequent status changes, renewal, cancellation, refund, are reported to us by both providers on their own initiative via a server notification (Apple: App Store Server Notifications, Google: Real-time Developer Notifications).
Recipients. Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) and Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) as operators of the purchase systems. They are separate controllers for the payment processing; their own privacy notices apply. Details on third-country transfers are set out in section 11.
Legal basis. Art. 6(1)(b) GDPR, without the verification the subscription contract cannot be performed. Where the data forms part of a record subject to retention, Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB applies in addition.
Storage period. Until the end of the subscription and the erasure of your account. Where retention obligations apply, the data covered by them remains stored until those obligations expire and is used for nothing else (section 12).
Cancellation and erasure. You manage and cancel the subscription itself in the subscription settings of your Apple or Google Play account; we cannot terminate it there. If you delete your account, we erase the data listed above in accordance with section 12, a running subscription in the store does not, however, end by itself as a result.
14. Data security
We take technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access. These include in particular:
- end-to-end transport encryption (TLS) between app and servers,
- encryption of data at rest at the processor,
- storage of passwords exclusively as a salted cryptographic hash,
- access restrictions at database level (Row Level Security), so that an account can in principle only access its own data and publicly released content,
- storage of the sign-in tokens in the protected storage of the operating system on your device,
- limitation of administrative access to the necessary group of people.
Despite these measures, absolute security of data transmission over the internet cannot be guaranteed.
15. No advertising IDs, no tracking, no analytics SDK
We expressly confirm: shiver contains no analytics SDK (no Firebase Analytics, no Google Analytics, no Amplitude, no Mixpanel or comparable services), no advertising SDK and no tracking pixels. We do not read out advertising identifiers (neither the IDFA on iOS, which is why no App Tracking Transparency dialog appears, nor the Android Advertising ID), create no cross-device profiles and carry out no fingerprinting. We do not access the GPS location, the address book, the calendar or the telephony functions of your device. Access to camera, microphone and photo library only takes place if you grant it, and only in order to record or select a video or profile picture.
The usage data collected are the playback and interaction events described in section 10 together with the events relating to promoted clips described in section 4. They serve to order the feed and to bill promoted clips, and they do not leave the app, except for storage in our own database. A promoted clip is itself content of this platform: there is still no ad network, no advertising identifier and no disclosure to third parties.
16. Storage on your device (§ 25 TDDDG)
§ 25(1) TDDDG (German Telecommunications Digital Services Data Protection Act) requires consent before information is stored on or read from a terminal device. Under § 25(2) no. 2 TDDDG this requirement does not apply if the storage is strictly necessary in order to provide a service expressly requested by the user.
shiver stores on your device exclusively information that is strictly necessary in this sense: the session and refresh token of your sign-in as well as simple app settings (such as the feed view last selected) and a technical cache for videos and images that have already been loaded. Without this storage you would have to sign in again on every start; the service would not be usable. A consent banner is therefore not required, and we deliberately do not display one.
This assessment applies for exactly as long as storage remains purely necessary. As soon as we introduce analytics, reach measurement or advertising functions that store information on or read information from the terminal device, this is no longer covered by § 25(2) TDDDG. In that case we would obtain express, granular consent that can be withdrawn at any time beforehand, and amend this policy accordingly.
17. Children and young people
shiver is directed neither at children nor at adolescents. Use is permitted only from the age of 18; the service comprises user-generated content and a direct messaging feature and is not intended for minors (section 3.2 of the Terms of Use). By registering you confirm that you are at least 18 years old.
The age limit in Art. 8(1) GDPR, 16 in Germany, because the legislator has not used the option to lower it, concerns the capacity to consent and is a different matter from the contractual minimum age. As our minimum age lies above it, the question of capacity to consent does not arise in lawful use.
If we become aware of, or if there are concrete indications that, an account is being run by a minor, we delete the account and the associated data without undue delay; the temporary suspension reserved in section 3.2 of the Terms of Use is not yet technically available in the app, which is why we delete directly until it is. Legal guardians can contact info@offline-events.de at any time in this regard. To protect minors we additionally use the pre-screening described in section 9 as well as the reporting procedure; details on the protection of minors under the JMStV and the JuSchG (German Youth Protection Act) are set out in the terms of use.
18. Changes to this privacy policy
We adapt this privacy policy when the functions of the app, the service providers used or the legal situation change. The version published on this page is always the authoritative one; you will find the date of the last change above under "Last updated". We will additionally inform you about material changes, such as the activation of image moderation by Hive or a new category of data, in the app or by email before the change takes effect. If processing is based on your consent, we will obtain it separately before the processing begins.