Privacy Policy
1. Controller
Alexander Lojewski, Raiffeisenstraße 13, 86513 Mindelzell, Germany.
Privacy requests by email: support@film35.de.
2. Core principle: end-to-end encryption
Film35 is built for data minimisation and end-to-end encryption. Photos, guest names and event titles are encrypted on the device before they are transmitted to our servers. We have no access to the content – the key required for decryption is stored only in the invite link and on users' devices and is never transmitted to us.
3. Data processed
| Data | Purpose | Legal basis |
|---|---|---|
| Anonymous user ID (random) | Associating photos with a guest inside an event | Art. 6(1)(b) GDPR |
| Encrypted photos & metadata | Providing the service | Art. 6(1)(b) GDPR |
| Encrypted names / event titles | Display within the event | Art. 6(1)(b) GDPR |
| Timestamps (creation, event end, deletion) | Automatic deletion | Art. 6(1)(b)/(f) GDPR |
We do not collect email addresses, real names or contact details of guests. Sign-in is anonymous.
4. Hosting / processors
- Server: Hetzner Online GmbH, Germany – hosting of the encrypted data.
- Backend: Supabase – database and storage for the encrypted content (servers in the EU).
Data processing agreements (DPA) under Art. 28 GDPR are in place with these providers.
5. Retention / deletion
Encrypted event data is automatically and irreversibly deleted no later than 30 days after the event ends. The host can delete an event manually at any time, which removes all associated data immediately.
6. Purchases via Apple
In-app purchases are handled by Apple. Apple processes payment data under its own responsibility; we only receive confirmation of a purchase, no payment data.
7. Your rights
You have the right to access, rectification, erasure, restriction, data portability and objection (Art. 15–21 GDPR), as well as the right to lodge a complaint with a supervisory authority. As the content is end-to-end encrypted, we cannot access it ourselves; deletion is ensured by deleting the event or by automatic expiry.
8. Contact
Privacy requests: support@film35.de.
9. Encryption used
We use only recognised standard algorithms:
- Photos & metadata: AES-256 (authenticated, AES-GCM).
- "Host only" mode: additional asymmetric encryption with Curve25519 (ECIES), so only the host's key can open the photos.
- Implementation: Apple CryptoKit / Apple's swift-crypto — no proprietary crypto.
- Keys: live only locally on users' devices (iOS keychain) and are never transmitted to our servers. We do not hold the keys and have no access. There is no backup: delete means delete for good.
10. Website, cookies & tracking
This website sets no tracking cookies and embeds no analytics, advertising or other third-party services (no Google Analytics, no social plug-ins, no third-party fonts). We deliberately collect no personal data via the website.
Only a technically necessary local flag in your browser (local storage) remembers that you dismissed the "no data collection" notice — it is never sent to us and serves no tracking purpose.
When you visit, the server (or the reverse proxy in front of it) processes automatically transmitted connection data (e.g. IP address, time, requested page) in server logs solely to operate the site securely and prevent abuse (Art. 6(1)(f) GDPR). These logs are kept briefly and not combined with other data.
Last updated: 27 July 2026.