Skip to content
Back to home

Privacy Policy

Data Controller

The party responsible for data processing on this website is AFTR.IO, Aleksa Petrovic, Vienna, Austria. For privacy inquiries, contact us at aftrparties.business@gmail.com.

What Data We Collect

What data we collect on this website depends on which feature you use: (1) Early Access sign-up — your email address and the time of registration, used to grant you access to the Early Access program (legal basis: your consent, Art. 6(1)(a) GDPR). (2) Contact form — your name, email address and message, used to process and answer your inquiry (legal basis: Art. 6(1)(b) GDPR where your inquiry relates to a contract, otherwise our legitimate interest in answering inquiries, Art. 6(1)(f) GDPR). (3) Host tier application — company name, legal form, VAT ID, tax ID, business address and contact details, used to review your application for a paid host tier and to verify business applicants (legal basis: pre-contractual measures, Art. 6(1)(b) GDPR, and our legitimate interest in verifying business applicants, Art. 6(1)(f) GDPR). All forms are protected against abuse by Cloudflare Turnstile bot protection (see 'Data Sharing with Third Parties').

Purpose of Data Collection

Your email is used exclusively to grant you access to the Early Access program of our app and to provide the Early Access bonus.

Legal Basis

The processing of your email is based on your consent pursuant to Art. 6(1)(a) GDPR.

Data Sharing with Third Parties

We do not sell your personal data. Data you enter on this website is shared only with the service providers listed under 'Third-Party Services' below, and only to the extent necessary to operate the site and process your request: Cloudflare (hosting, CDN and Turnstile bot protection on our forms), Cookiebot by Usercentrics (consent management), PostHog (website analytics, EU-hosted, only with your consent), Sentry (error tracking) and Crisp (support chat, only with your consent). Form submissions (Early Access, contact, tier application) are transmitted to our own backend and are not passed on to other recipients unless we are legally required to do so.

Storage & Deletion

Your email is stored for as long as the Early Access program is active. You can request deletion at any time by emailing aftrparties.business@gmail.com.

Security

We take appropriate technical and organizational measures to protect your data.

Your Rights

You have the right to access, rectify, delete your data, or withdraw your consent at any time. Contact us at aftrparties.business@gmail.com.

Note on the App

The use of the AFTR app is subject to separate privacy policies, which you can review within the app.

User-Generated Video Content (Clips)

When you upload a video clip via the AFTR app ('Clip'), the following processing applies: (1) The video file is uploaded to our content delivery network (Cloudflare R2, EU region) and assigned a unique URL. (2) The video is automatically scanned by automated content moderation systems for policy violations: text in the video metadata and extracted video frames are analyzed for harmful content and NSFW categories by our moderation providers — by default OpenAI (USA), with AWS Rekognition (EU region) and Cloudflare Workers AI (EU edge) as fallback providers — and frames may additionally be checked against Microsoft PhotoDNA (USA) hash-matching to detect known abusive material (see 'Content Moderation' for transfer safeguards). (3) Neither system performs facial recognition, biometric identification, or person matching. We do not extract biometric templates, we do not link faces to identities, and we do not maintain a database of facial features. (4) Clips are published as posts on your profile and remain stored until you delete them or your account is deleted; Stories, by contrast, expire automatically 24 hours after posting. (5) You can delete any Clip you have uploaded at any time. The legal basis is Art. 6(1)(b) GDPR (performance of the contract for Clip publishing) and Art. 6(1)(f) GDPR (legitimate interest in content moderation for safety). Because we do not perform biometric identification, Art. 9 GDPR does not apply.

Party and Event Data

When you join a party or purchase a ticket, we process: your user ID, ticket type, payment status, check-in time, and — if you enable it — your real-time location. Ticket QR codes contain a static, unique ticket identifier; reuse is prevented server-side because each ticket can be checked in only once. The separate Vibes identity QR code shown in the app for Vibes payments rotates every 60 seconds. Event hosts see attendee lists for their own events only.

Payment Processing

We use Stripe (Stripe Payments Europe Limited, Ireland) to process payments. Stripe receives your payment details directly; we do not store full card numbers. Stripe acts as an independent controller for fraud prevention and as our processor for transaction handling. See Stripe's privacy policy at stripe.com/privacy.

Location Data

When you enable location sharing during a party, your approximate location is shared in real-time with other guests at the same party via WebSocket. Location is not persisted after the party ends. Legal basis: Art. 6(1)(a) GDPR (your consent, revocable at any time in app settings).

Messaging and Chat

Direct messages and group party chat are encrypted in transit (TLS) and stored encrypted at rest on our servers so we can deliver them to recipients and keep the platform safe. Messages are not end-to-end encrypted: content may be processed by our automated content moderation (see 'Content Moderation'), and we can access it where necessary for safety reviews or where legally required. Chat messages are not automatically deleted after a fixed period: they are retained on our servers until you delete them or until your account is deleted.

Content Moderation

We use automated content moderation to enforce community guidelines. Text and images/video are analyzed by OpenAI (OpenAI, L.L.C., USA) as our default moderation provider; AWS Rekognition (Amazon Web Services, EU region) and Cloudflare Workers AI (EU edge) serve as fallback providers. Uploaded images and video frames may additionally be checked against Microsoft PhotoDNA (Microsoft Corporation, USA) hash-matching to detect known child sexual abuse material. Where content is transferred to providers in the USA, the transfer is safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR). Flagged content is reviewed by human moderators. You may appeal moderation decisions via the in-app appeal mechanism. Legal basis: Art. 6(1)(f) GDPR and DSA Art. 16.

Push Notifications

We use Firebase Cloud Messaging to deliver push notifications (order updates, party reminders, chat messages). You can disable notifications at any time in device settings. Notifications contain no personal data in the payload — display content is rendered locally.

Third-party services we use: Stripe (payments, EU + US), Firebase Cloud Messaging (push notifications, EU + US), Cloudflare R2 (content storage, EU), OpenAI (text + image moderation, US), AWS Rekognition (image moderation fallback, EU), Microsoft PhotoDNA (CSAM hash-matching, US), Cloudflare Workers AI (moderation fallback, EU edge), Sentry (error tracking, EU Frankfurt), Crisp (customer support chat, EU), Cloudflare Turnstile (bot protection on website forms, global edge), Cookiebot by Usercentrics (consent management, EU), PostHog (website analytics, EU — only with your consent). Transfers to US providers are safeguarded by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses.

Data Retention

Account data: retained while your account is active; after you request deletion, your account is deactivated and permanently deleted after a 7-day grace period. Payment records: 10 years (statutory accounting). Clips and posts: until you delete them or your account is deleted. Stories: deleted automatically 24 hours after posting. Chat messages: until you delete them or your account is deleted. Location: not persisted. Content rejected by moderation and its moderation records: 180 days (for appeals and legal obligations). Sentry error events: 90 days.