Version 1.6
Privacy notice
- Effective
- 9/28/2026
- Updated
- 9/28/2026
1. Controller
The controller responsible for personal-data processing in connection with the public website and cliprio applications is:
Florian Leeser Softwareentwicklung
Proprietor: Florian Leeser
Eintrachtstraße 50
42655 Solingen
Germany
Email: privacy@coderave.dev
General support: support@coderave.dev
No data protection officer has been appointed because there is no statutory appointment requirement.
2. Scope of this notice
This notice describes processing when you use:
- the public website at https://cliprio.app, delivered through Vercel;
- the web application at https://web.cliprio.app, delivered through Firebase Hosting;
- the cliprio applications for Android, iOS, macOS, and web; and
- the related account, transfer, notification, support, and deletion functions.
cliprio does not use advertising trackers, usage analytics, advertising profiles, or tracking cookies. Content is not used for advertising or to train AI models. We do not use solely automated decisions with legal or similarly significant effects, and we do not profile users.
3. Visiting the websites
When you visit the public website or web application, the hosting providers process technically necessary connection data. This may include IP address, date and time, requested path, referrer, browser and operating-system details, transferred volume, and security or error data.
Processing is necessary to deliver, stabilize, troubleshoot, and protect the sites against misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable, and economical operation of our online services. Technical logs are deleted under the providers’ operational deletion schedules unless they are exceptionally required for longer to investigate a security incident or comply with law.
4. Account and authentication
To create and access an account, cliprio processes:
- email address, cryptographically processed password proof, and verification status;
- server-side user identifier and creation or modification timestamps;
- display name;
- authentication, verification, recovery, and session data; and
- accepted Terms version and acknowledged Privacy Notice version with a server timestamp.
We cannot view your password in plain text. Email confirmations, one-time codes, and account-security notices are generated through Supabase Auth and delivered by Plus Five Five, Inc. (Resend). Resend therefore processes the recipient address, subject, rendered message body, which can contain a one-time code or action URL, and delivery metadata.
Processing is necessary to create and authenticate the account, perform the usage contract, prevent misuse, and document agreement or acknowledgement. The legal bases are Article 6(1)(b) and (f) GDPR. Required data is necessary to create an account; without it, an account cannot be provided.
The application retains the authenticated session locally on your device so that you can remain signed in. Signing out removes session-related local data to the extent it is not retained by the operating system or browser under its own rules.
5. Device management and local app data
For each registered device, cliprio processes a random installation identifier, server-side device identifier, the device name you choose, platform, registration and last-seen timestamps, private eight-digit device code, and default content-retention selection. Known-device relationships and temporary receive-code sessions may also be processed.
A six-digit receive code is valid for no more than one hour. Failed attempts are rate-limited without retaining the submitted code; technical rate-limit records are cleaned up after the protection window.
Quick Receive lets a person without an account open https://web.cliprio.app/quick. The browser keeps a random receiver token only in that tab’s session storage; the displayed code and other receiver metadata remain in memory. The backend stores only a token hash, pseudonymous HMAC rate-limit keys, session state and, after delivery, independent content references. Access ends 24 hours after delivery; an hourly retryable cleanup then removes the expired references. Cloudflare Turnstile processes necessary connection and browser-integrity data to prevent automated abuse. Raw IP addresses, receiver tokens and submitted codes are not stored in cliprio’s application logs or rate-limit records. Explicit downloads use a five-minute private Storage authorization and a separate Quick Receive OPFS area; verified artifacts are removed after export, cancellation, failure, sharing or page disposal.
The app stores necessary preferences locally, including language, theme, installation identifier, and notification-prompt status. Native apps can hold unsent text and file drafts locally and prune them after no more than 24 hours. The web implementation keeps drafts in memory only.
When you explicitly open, copy, or download a file, the app streams the authenticated file into app-private temporary storage and verifies its size and checksum before making it available to that action. Native apps use their temporary app directory; the Web app uses the browser’s Origin Private File System (OPFS). These artifacts are isolated to the authenticated session and removed after export, cancellation, failure, expiry, page disposal, successful sign-out or account deletion, app startup, or an account switch. For a native Open or Copy action, the app schedules best-effort cleanup of the private artifact 24 hours after handing it to the selected operating-system consumer; successful sign-out, account deletion, an account switch, a later expired-artifact prune, or the next app startup removes it earlier. If the operating system suspends or terminates the app before scheduled cleanup runs, the app-private artifact may remain beyond 24 hours until one of those lifecycle cleanup boundaries executes.
Processing provides device, security, and transfer functions. The legal bases are Article 6(1)(b) and (f) GDPR.
6. Content and transfers
Depending on how you use cliprio, it processes:
- transferred text, images, and files;
- file name, file type, MIME type, size, and optional title;
- content, sender, recipient, and device identifiers;
- creation, modification, expiry, and deletion timestamps; and
- selected retention, share count, and technical operation status.
Files are stored in a private Supabase Storage bucket. Access is granted only for authenticated and authorized requests. Push notifications contain no content, file names, public links, device names, or display names.
Processing is limited to carrying out the storage, display, forwarding, and deletion instructions you choose. The legal basis is Article 6(1)(b) GDPR. If content contains another person’s personal data, you are responsible for transferring it only where lawful.
A transfer to another account creates an independent copy controlled by the recipient. That copy has its own retention and is not recalled if the sender later deletes their account. The sender identifier is removed or neutralized where possible after account deletion.
7. Notifications
If you enable push notifications, cliprio processes your setting, platform and language, a device-specific Firebase Cloud Messaging token, technical delivery information, and notification, read, and error status. The delivery message contains a random notification identifier, generic localized wording, and potentially an unread count, but no transferred content.
The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time for the future in the cliprio or operating-system settings. This does not affect prior lawful processing. Delivery tokens that have not been refreshed for 90 days are removed.
8. Billing and subscription administration
To sell, attribute, enforce, and reconcile Free, Personal, and Team access, cliprio processes the account or organization billing subject, plan and logical product, selected Team package and purchased seat capacity, billing interval, current or scheduled package change, entitlement and provider customer identifiers, subscription and purchase identifiers, status and event timestamps, renewal, expiry and cancellation state, refund or chargeback state, payment-failure and grace-period state, accepted Team memberships needed for capacity checks, and successful-delivery usage assigned to a UTC month. This data is separated from transferred content.
Personal and Team purchases on the Web use Stripe Managed Payments directly. After a Personal Web payment, RevenueCat mirrors subscription and entitlement information. RevenueCat also supplies native offerings and attributes native purchases. Apple or Google processes native Personal and Team purchases and supplies the localized storefront price. Those providers may process contact, country, tax, transaction, payment-instrument, fraud-prevention, device, and purchase data under their own notices. cliprio does not receive or store full card or bank-account details.
Processing is necessary to perform the paid subscription, allocate plan allowances, manage organization seats, prevent duplicate or unauthorized attribution, recover failed payments, reconcile provider events, comply with tax and accounting duties, and establish or defend legal claims. The legal bases are Article 6(1)(b), (c), and (f) GDPR. Our legitimate interests are secure billing, fraud prevention, reliable entitlement state, and auditable provider reconciliation.
A native store purchase is attributed to the cliprio account or organization selected at purchase or restoration and is not automatically moved to another billing subject. Team invitation and acceptance state is processed to check whether active members fit the purchased package. An invitation never triggers a purchase automatically; package upgrades require an explicit owner action, while eligible downgrades take effect at renewal.
9. Public account deletion
The public deletion page sends the normalized email address to Supabase Auth. If an account exists, a one-time code is delivered through Resend. After successful verification, the page creates a temporary in-memory session and uses it to invoke the existing self-deletion service.
The site disables session persistence and automatic token refresh. It does not log email addresses, one-time codes, access tokens, or deletion-session details. Temporary data is discarded after cancellation, success, or reload. Hosting and backend providers may still process connection data required for the network request.
The legal basis is Article 6(1)(b) GDPR and compliance with deletion obligations under Article 6(1)(c) in conjunction with Article 17 GDPR.
10. Support, privacy, and illegal-content notices
If you email us, we process the sender address, name, message, attachments, timestamps, and account or technical details needed to respond. Never send passwords or verification codes, and do not unnecessarily attach reported illegal content.
Processing is based on Article 6(1)(b) GDPR for contractual or pre-contractual requests, Article 6(1)(c) GDPR for legal obligations, and otherwise Article 6(1)(f) GDPR for our legitimate interests in effective communication, misuse prevention, and legal claims.
Correspondence is ordinarily deleted three years after the matter closes. Statutory retention duties or the establishment, exercise, or defense of legal claims may require longer retention.
11. Recipients and processors
We use the following providers in particular:
- Supabase, Inc. for authentication, database, private file storage, and Edge Functions. The main project is configured in the Frankfurt region (
eu-central-1). - Vercel Inc. to host and deliver the public website at https://cliprio.app.
- Cloudflare, Inc. for Turnstile bot and abuse protection on public Quick Receive session creation. Further information about Cloudflare’s processing of personal data is available in the Turnstile Privacy Addendum.
- Google Ireland Limited and related Google entities for Firebase Hosting, Firebase Cloud Messaging, and native Personal and Team purchases through Google Play.
- Stripe and its related entities for Stripe Managed Payments, Web checkout, payment processing, tax handling, fraud prevention, refunds, chargebacks, and billing events.
- RevenueCat, Inc. for native offerings and purchase attribution, and for post-payment Personal Web subscription and entitlement mirroring.
- Apple Distribution International Limited and related Apple entities for native Personal and Team purchases and Apple Push Notification Service delivery to Apple devices.
- Plus Five Five, Inc. (Resend) for delivery of account, verification, recovery, security-notification, and deletion-code emails.
- IONOS SE for coderave support, privacy, and general email mailboxes.
Data may also be disclosed to authorities, courts, or other bodies where required by law or necessary to pursue or defend legal claims. Required data-processing agreements apply to processors.
12. International transfers
Some providers and subprocessors are established or operate technical locations outside the European Economic Area, particularly in the United States. Even with the main Supabase project configured in Frankfurt, support, security operations, Edge Functions, or subprocessors may involve third countries. Firebase Cloud Messaging, Stripe, and RevenueCat may operate on international infrastructure. Resend stores account data, including email metadata, logs, and API records, in the United States regardless of the selected sending region.
Where necessary, transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses and supplementary protections. You can request information about applicable safeguards from privacy@coderave.dev.
13. Retention and deletion
The following criteria apply in particular:
- Account, profile, device, and contract-evidence data is generally processed until account deletion.
- Content is removed after your selected 24-hour, 3-day, 7-day, or 30-day period, or for permanent content after you delete it or delete your account.
- Independent recipient copies remain under the recipient’s settings and decisions.
- Billing subject, subscription, purchase-attribution, usage, and Team package and capacity records are retained while required to perform the subscription and afterward for statutory tax, accounting, fraud-prevention, dispute, refund, chargeback, and legal-claims periods. They are then deleted or anonymized where legally and technically possible.
- The technical provider-event inbox keeps opaque event identifiers, digests, and processing outcomes for no more than 30 days for secure webhook deduplication and replay defense. This short-lived inbox is separate from normalized billing and accounting records retained under the preceding rule.
- Notification records are removed when related content no longer exists. Delivery attempts run only within a 24-hour technical delivery window.
- Receive-code sessions remain valid for no more than one hour. Security rate limits are cleaned up after their protection periods.
- Push-delivery tokens not refreshed for 90 days are removed.
- Resend states that it retains email data for 30 days across its standard plans. You can direct a request concerning provider-held Auth-email data to us; we coordinate deletion with the processor subject to applicable legal retention requirements.
- Technical replay data for completed content operations is cleaned up after eight days. Interrupted legacy-client operations may be released after 30 minutes. Incomplete protocol-two direct-transfer reservations normally last up to 24 hours, may be renewed while work continues, and never remain valid beyond the 48-hour absolute limit; expiry releases unused quota and schedules temporary-object cleanup.
After the final logical copy is removed, file-object deletion runs through a retryable technical cleanup process. Deleted data may remain in providers’ rolling backups until scheduled overwrite. It is not restored for ordinary operations and, after disaster recovery, remains subject to the applicable deletion rules.
14. Security
cliprio uses measures including encrypted transport, private file storage, account- and device-bound authorization, Row Level Security, time-limited codes, input limits, and data-minimized push notifications. No internet service can guarantee absolute security.
15. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent at any time for the future. Where processing relies on Article 6(1)(f) GDPR, you may object for reasons arising from your particular situation.
Send requests to privacy@coderave.dev. We may request reasonable proof of identity to prevent unauthorized disclosure.
You also have the right to complain to a data-protection authority. Our competent authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
https://www.ldi.nrw.de
16. Changes
We update this Privacy Notice when cliprio, its providers, or applicable law materially changes. We will provide appropriate notice of material changes in the app, on the website, or by email.