Version 1.0
Privacy notice
- Effective
- 7/20/2026
- Updated
- 7/20/2026
1. Controller
The controller responsible for personal-data processing in connection with the public website and cliprio applications is:
Florian Leeser Softwareentwicklung
Proprietor: Florian Leeser
Eintrachtstraße 50
42655 Solingen
Germany
Email: privacy@coderave.dev
General support: support@coderave.dev
No data protection officer has been appointed because there is no statutory appointment requirement.
2. Scope of this notice
This notice describes processing when you use:
- the public website at https://cliprio.app, delivered through Vercel;
- the web application at https://web.cliprio.app, delivered through Firebase Hosting;
- the cliprio applications for Android, iOS, macOS, Windows, and web; and
- the related account, transfer, notification, support, and deletion functions.
cliprio does not use advertising trackers, usage analytics, advertising profiles, or tracking cookies. Content is not used for advertising or to train AI models. We do not use solely automated decisions with legal or similarly significant effects, and we do not profile users.
3. Visiting the websites
When you visit the public website or web application, the hosting providers process technically necessary connection data. This may include IP address, date and time, requested path, referrer, browser and operating-system details, transferred volume, and security or error data.
Processing is necessary to deliver, stabilize, troubleshoot, and protect the sites against misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable, and economical operation of our online services. Technical logs are deleted under the providers’ operational deletion schedules unless they are exceptionally required for longer to investigate a security incident or comply with law.
4. Local website preference
The public site follows your system appearance by default. If you use the Light/Dark switch, it stores the cliprio-theme key with the selected appearance in your browser’s local storage. cliprio does not transmit this setting to a server.
Storage is required to provide the appearance you requested. It is permitted under section 25(2)(2) TDDDG and does not require consent or a cookie banner.
5. Account and authentication
To create and access an account, cliprio processes:
- email address, cryptographically processed password proof, and verification status;
- server-side user identifier and creation or modification timestamps;
- display name;
- authentication, verification, recovery, and session data; and
- accepted Terms version and acknowledged Privacy Notice version with a server timestamp.
We cannot view your password in plain text. Email confirmations and one-time codes are handled through Supabase Auth and the configured IONOS SMTP service.
Processing is necessary to create and authenticate the account, perform the usage contract, prevent misuse, and document agreement or acknowledgement. The legal bases are Article 6(1)(b) and (f) GDPR. Required data is necessary to create an account; without it, an account cannot be provided.
The application retains the authenticated session locally on your device so that you can remain signed in. Signing out removes session-related local data to the extent it is not retained by the operating system or browser under its own rules.
6. Device management and local app data
For each registered device, cliprio processes a random installation identifier, server-side device identifier, the device name you choose, platform, registration and last-seen timestamps, private eight-digit device code, and default content-retention selection. Known-device relationships and temporary receive-code sessions may also be processed.
A six-digit receive code is valid for no more than one hour. Failed attempts are rate-limited without retaining the submitted code; technical rate-limit records are cleaned up after the protection window.
The app stores necessary preferences locally, including language, theme, installation identifier, and notification-prompt status. Native apps can hold unsent text and file drafts locally and prune them after no more than 24 hours. The web implementation keeps drafts in memory only.
Processing provides device, security, and transfer functions. The legal bases are Article 6(1)(b) and (f) GDPR.
7. Content and transfers
Depending on how you use cliprio, it processes:
- transferred text, images, and files;
- file name, file type, MIME type, size, and optional title;
- content, sender, recipient, and device identifiers;
- creation, modification, expiry, and deletion timestamps; and
- selected retention, share count, and technical operation status.
Files are stored in a private Supabase Storage bucket. Access is granted only for authenticated and authorized requests. Push notifications contain no content, file names, public links, device names, or display names.
Processing is limited to carrying out the storage, display, forwarding, and deletion instructions you choose. The legal basis is Article 6(1)(b) GDPR. If content contains another person’s personal data, you are responsible for transferring it only where lawful.
A transfer to another account creates an independent copy controlled by the recipient. That copy has its own retention and is not recalled if the sender later deletes their account. The sender identifier is removed or neutralized where possible after account deletion.
8. Notifications
If you enable push notifications, cliprio processes your setting, platform and language, a device-specific Firebase Cloud Messaging token, technical delivery information, and notification, read, and error status. The delivery message contains a random notification identifier, generic localized wording, and potentially an unread count, but no transferred content.
The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time for the future in the cliprio or operating-system settings. This does not affect prior lawful processing. Delivery tokens that have not been refreshed for 90 days are removed.
9. Public account deletion
The public deletion page sends the normalized email address to Supabase Auth. If an account exists, a one-time code is delivered through IONOS. After successful verification, the page creates a temporary in-memory session and uses it to invoke the existing self-deletion service.
The site disables session persistence and automatic token refresh. It does not log email addresses, one-time codes, access tokens, or deletion-session details. Temporary data is discarded after cancellation, success, or reload. Hosting and backend providers may still process connection data required for the network request.
The legal basis is Article 6(1)(b) GDPR and compliance with deletion obligations under Article 6(1)(c) in conjunction with Article 17 GDPR.
10. Support, privacy, and illegal-content notices
If you email us, we process the sender address, name, message, attachments, timestamps, and account or technical details needed to respond. Never send passwords or verification codes, and do not unnecessarily attach reported illegal content.
Processing is based on Article 6(1)(b) GDPR for contractual or pre-contractual requests, Article 6(1)(c) GDPR for legal obligations, and otherwise Article 6(1)(f) GDPR for our legitimate interests in effective communication, misuse prevention, and legal claims.
Correspondence is ordinarily deleted three years after the matter closes. Statutory retention duties or the establishment, exercise, or defense of legal claims may require longer retention.
11. Recipients and processors
We use the following providers in particular:
- Supabase, Inc. for authentication, database, private file storage, and Edge Functions. The main project is configured in the Frankfurt region (
eu-central-1). - Vercel Inc. to host and deliver the public website at https://cliprio.app.
- Google Ireland Limited and related Google entities for Firebase Hosting and Firebase Cloud Messaging.
- Apple Distribution International Limited and related Apple entities where Apple Push Notification Service delivers notifications to Apple devices.
- IONOS SE for coderave email mailboxes and SMTP delivery of account and verification messages.
Data may also be disclosed to authorities, courts, or other bodies where required by law or necessary to pursue or defend legal claims. Required data-processing agreements apply to processors.
12. International transfers
Some providers and subprocessors are established or operate technical locations outside the European Economic Area, particularly in the United States. Even with the main Supabase project configured in Frankfurt, support, security operations, Edge Functions, or subprocessors may involve third countries. Firebase Cloud Messaging operates on global infrastructure.
Where necessary, transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified recipients, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses and supplementary protections. You can request information about applicable safeguards from privacy@coderave.dev.
13. Retention and deletion
The following criteria apply in particular:
- Account, profile, device, and contract-evidence data is generally processed until account deletion.
- Content is removed after your selected 24-hour, 3-day, or 7-day period, or for permanent content after you delete it or delete your account.
- Independent recipient copies remain under the recipient’s settings and decisions.
- Notification records are removed when related content no longer exists. Delivery attempts run only within a 24-hour technical delivery window.
- Receive-code sessions remain valid for no more than one hour. Security rate limits are cleaned up after their protection periods.
- Push-delivery tokens not refreshed for 90 days are removed.
- Technical replay data for completed content operations is cleaned up after eight days; abandoned processing can be released after 30 minutes.
After the final logical copy is removed, file-object deletion runs through a retryable technical cleanup process. Deleted data may remain in providers’ rolling backups until scheduled overwrite. It is not restored for ordinary operations and, after disaster recovery, remains subject to the applicable deletion rules.
14. Security
cliprio uses measures including encrypted transport, private file storage, account- and device-bound authorization, Row Level Security, time-limited codes, input limits, and data-minimized push notifications. No internet service can guarantee absolute security.
15. Your rights
Subject to statutory requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent at any time for the future. Where processing relies on Article 6(1)(f) GDPR, you may object for reasons arising from your particular situation.
Send requests to privacy@coderave.dev. We may request reasonable proof of identity to prevent unauthorized disclosure.
You also have the right to complain to a data-protection authority. Our competent authority is:
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
https://www.ldi.nrw.de
16. Changes
We update this Privacy Notice when cliprio, its providers, or applicable law materially changes. We will provide appropriate notice of material changes in the app, on the website, or by email.