DanceRep.Back to home

Last updated: 17 September 2026

Privacy policy

This policy explains how personal data is processed when you visit dancerep.app, use the DanceRep app or take part in the voluntary private beta.

1. Controller


Sole proprietor
Schertlinstraße 29
86159 Augsburg
Germany

You can also use our protected contact form.

2. Website hosting

The website is provided through Cloudflare Pages by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. When you visit, Cloudflare processes connection data needed to deliver the site. This may include your IP address, the time and destination of the request, the amount of data transferred, browser and system information, and traffic management information.

We process this data to provide a secure and reliable website and prevent abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the website. Cloudflare processes some data on our behalf and, according to its own information, acts as an independent controller in some cases.

Processing may take place outside the European Economic Area, especially in the United States. Cloudflare provides safeguards including EU standard contractual clauses. See Cloudflare's privacy policy.

Data is deleted when it is no longer needed for these purposes, unless legal retention duties or legitimate security interests require otherwise. We do not fully control retention periods set by Cloudflare in its own capacity.

We use Cloudflare Turnstile on contact and deletion forms and before displaying the controller's name and email address. Turnstile evaluates technical connection, browser and interaction signals to distinguish people from automated requests. We receive only the verification result; the legal basis is Article 6(1)(f) GDPR and our legitimate interest in preventing scraping, spam and abuse. A failed or unavailable verification can prevent the protected form or contact details from being displayed.

3. Confirmation links and Supabase

The /auth/ page helps confirm registration, sign-in, invitations, email changes and password recovery. The one-time token in the link is first read locally from the URL fragment in your browser and removed from the visible address. The website does not verify it automatically.

Only when you choose “Continue in DanceRep” are the token hash, confirmation type and intended redirect destination sent to Supabase, Inc., 970 Toa Payoh North #07-04, Singapore 318992. Supabase also processes connection data needed to complete the requested authentication step.

The legal basis is Article 6(1)(b) GDPR where processing is needed to provide the account or take pre-contractual steps. Otherwise it is Article 6(1)(f) GDPR: our legitimate interest is secure confirmation that resists automated email-link scanners. Supabase processes data on our behalf and provides safeguards for transfers to third countries, including EU standard contractual clauses.

Authentication data is kept for the life of the account and otherwise only as long as needed for the stated purposes or legal duties. One-time confirmation links expire.

4. DanceRep app and user account

Account data also includes your chosen username, an available profile photo, role and permissions, Free/Plus plan, any trial period, additional move slots, and creation and update timestamps. Provider sign-in can retain the provider identifier, name and photo URL in authentication records even though the app does not ask for a separate display name. Your plan and permissions determine available features and capacity.

We process the data necessary for sign-in, account management and the features you request to perform our contract (Article 6(1)(b) GDPR). Without that information, the relevant features, such as account access or cloud synchronization, cannot be provided. Acceptance of the content rules is not blanket consent to personal data processing. Additional analysis during the ongoing beta is described separately in section 5.

Synced content also includes ordering and practice stage, recording dates, creation and update timestamps, and technical media information: file size, duration, format, dimensions, frame rate, checksum, storage reference and backup status. Clips can include audio, and preview images may be stored with them. Local working copies and downloaded caches are also held on your device.

Blocking, reviewing reports and preventing abuse protect users and the sharing service. Where no specific legal obligation applies, we rely on our legitimate interest in the security of the service for this necessary processing (Article 6(1)(f) GDPR).

You can create an account with an email address and password, or through Google or Apple. We process your email address, internal user ID, sign-in and confirmation data, and the session data needed for access. With Google or Apple sign-in, we receive the account information you choose to share; authentication itself takes place with that provider. The legal basis is Article 6(1)(b) GDPR.

When you first sign in with Google, we use the profile photo supplied by Google as your initial DanceRep photo, if available. We retrieve it from Google and store a copy in our private Supabase storage. You can replace or remove it in Settings; a removed or chosen photo is not automatically overwritten on later sign-ins. Recipients of your shared moves can see your username and profile photo. This provides the account and sharing features under Article 6(1)(b) GDPR.

The app first stores your boards, moves, practice stages, tags, notes and settings on your device. With an account, board data and finished, compressed clips are privately synchronized through Supabase so they can be available on other devices. A video selected from your photo library is processed locally; the original is not uploaded to our servers. The app accesses your library only after your selection or permission. This processing and synchronization provide the app features you request under Article 6(1)(b) GDPR.

When you share a move, its name, notes, selected tags, recording date and clip become available to signed-in people with the link. Share links expire after seven days and can be revoked earlier. If someone imports the move, an independent copy is created in their account. Deleting your link or account later does not delete that copy.

For safe sharing, we store your chosen username, the accepted version of the terms and time of acceptance, import relationships and blocks. For a report, we store the reason, any description you provide and a snapshot of the shared content. Authorized administrators can inspect that snapshot and its clip. Moderation decisions and media access are logged. Email notifications to moderators contain only a case ID and a link to the protected dashboard.

Open reports are kept until they are handled. Closed reports and associated moderation notes are removed after 30 days at the next administrative review. Account deletion removes linked reports as described below. See the terms of use for the content rules.

The app uses Sentry for operation and error analysis. Technical device, app and crash data may be processed. Touch logs are discarded and network details are reduced to the method, status and broad service endpoint. Email addresses, move names, request bodies, tokens and private storage paths are intended to be excluded from error reports. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is a secure and reliable app. Supabase processes synchronization and authentication data on our behalf. The providers offer safeguards for possible transfers outside the EEA, including EU standard contractual clauses.

To delete your entire account: You can delete your account in the app under Settings → Privacy and deletion, or request deletion without the app on our account deletion page. This removes account access, private boards and moves, stored clips, shares and attributable beta data. Original videos in your device's photo library remain untouched. Independent copies already imported into other accounts remain. Records required by law or technical security logs may be retained only for as long as necessary for those purposes.

4a. Deletion requests and recovery backups

Account data is retained for the life of the account. Content is retained while you use it in DanceRep unless you arrange for its earlier deletion. You can remove individual moves and your profile photo in the app. You can also request deletion of selected data without deleting your account. Information needed to operate the remaining account is retained.

To recover from technical failures, we also create encrypted database and private-file backups on a separate server. They can contain the same account data and content as the active system.

Encrypted recovery backups may still contain older copies after deletion from active systems. They leave those backups through the daily, weekly and monthly retention rotation. Backup deletion is therefore not immediate. We explain the applicable backup retention and remaining deletion date when handling your request; any restoration must take completed deletion requests into account.

We handle requests manually and respond without undue delay, normally within one month of receipt. If a complex request requires an extension, we explain why within that first month; the legal extension can be up to two additional months. We tell you when deletion is complete and which data, if any, must still be retained.

To handle a request, we process your contact address, the data you identify, necessary identity verification information and the processing history. The legal basis is compliance with our data protection obligations (Article 6(1)(c) GDPR). After completion, we retain only evidence necessary to demonstrate fulfilment of these obligations or establish, exercise or defend legal claims. Its scope and retention depend on that purpose and the applicable periods. You can ask us for the period applicable to your case.

Copies already imported by other people are not automatically removed when the source account deletes content. This does not exclude statutory erasure or other data protection rights concerning those copies; please identify affected content in your request.

5. Additional processing in the ongoing beta

The /beta/ portal is intended for personally invited testers. When you accept, we store your email address, a neutral tester code, and the time and version of the beta notices you accepted. Your email address also determines whether you may later create an account.

Events are linked to your account through an internal user ID and are therefore not anonymous. During the beta, the app records selected product and diagnostic events. These include app starts, onboarding completion, creating and moving figures, the extent of tag use, opening practice mode, video processing and backup, and creating, opening and importing QR shares. Event properties do not include email addresses, move names, notes, specific tag names, share tokens or local file paths.

For quality checks, the sole authorized beta administrator can also see synchronized move names, notes, tag names and the compressed clip made by DanceRep. The original video from your library is not uploaded. Clip previews use short-lived private links.

After beta access is granted, we email your tester code and available installation and questionnaire links. We use Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as a processor for these transactional emails. It processes the recipient address, tester code, message content and delivery data. This is necessary for the beta under Article 6(1)(b) GDPR. Resend also processes and stores data in the United States using safeguards including EU standard contractual clauses. See Resend's privacy policy.

Testers who already have access can request a fresh link to the current download page. We check the entered email against beta access and send an encrypted link through Resend, valid for 30 minutes. The form returns the same response whether or not the address is approved. When the link is deliberately opened, access is checked again; the access value is not passed in the server URL or referrer information.

Additional beta analysis is based on consent under Article 6(1)(a) GDPR. You can withdraw it at any time for the future in the app under Settings → Privacy and deletion → Leave beta or through our protected contact form. Direct withdrawal deletes beta usage events, hides account content from the beta dashboard and signs the device out. Your private account, board and clips remain until account deletion. Beta participation also ends. Personal beta analysis is deleted or aggregated so it can no longer be linked to a tester no later than 30 days after the beta ends, unless a higher-ranking legal duty applies.

Technical crashes are processed by Sentry. Touch logs are discarded and network details are limited to method, status and a broad service endpoint. Visible email addresses, move names, request bodies, tokens and private storage paths are intended to be excluded from error reports.

6. Optional Google questionnaires

After access is granted, the beta page may link to optional Google Forms questionnaires. A connection to Google is made only when you open one of those links. The forms ask for the neutral tester code and are prepared not to collect email addresses. Please do not submit videos, passwords or confidential move content. Google's privacy information shown there also applies.

7. Cookies, analytics and external content

This website does not use analytics or marketing cookies. We do not run general website audience measurement or load external fonts. After sign-in, the beta administrator dashboard uses only a short-lived, technically necessary session cookie protected by HttpOnly. Private beta clips are loaded directly from private Supabase storage only after a deliberate administrator action. The language selector stores your chosen language in a preference cookie.

8. Your rights

Subject to the legal requirements, you may request access, rectification, erasure, restriction of processing and data portability. You may also object to processing under Article 6(1)(f) GDPR for reasons relating to your particular situation.

You may lodge a complaint with a data protection supervisory authority, in particular in the place where you normally live, work or believe an infringement occurred.

9. Updates

We update this policy when the website, services or legal requirements change.

DanceRep

Terms of useLegal noticePrivacy policyDelete accountDelete data