Privacy Policy

Last updated: 20 July 2026

This policy explains how we process personal data on kreiso.app. It is written to meet Articles 13 and 14 GDPR.

Also available in German.


1. Controller

Nikita Konstantinovskiy Görresstraße 11 80798 Munich, Germany support@kreiso.app

We have not appointed a Data Protection Officer. See section 12 on why this may change.


2. Where your data is stored

Our primary databases and file storage are located inside the European Union: Firestore in the eur3 multi-region (Belgium and the Netherlands) and Cloud Storage in the EU multi-region. Application services run in europe-west1.

Some processors operate outside the EU. Those transfers are covered in section 7.


3. What we process, and why

3.1 Waitlist

Data: name, email address and/or phone number. Purpose: to tell you when we launch or when a place opens. Legal basis: Art. 6(1)(b) GDPR — delivering the notification service you signed up for.

3.2 Event applications (/apply)

Data: name, email, phone, age, gender, country of origin, languages spoken, life stage, city, time in the city, the events you select, and a campaign identifier if you arrived through a tracked link. Purpose: to review applications, decide which events to invite you to, and contact you about them. Review is carried out by a person; we do not make invitation decisions by automated means alone. Legal basis: Art. 6(1)(b) GDPR — steps taken at your request before a possible contract. The demographic details, which we use for statistics, rest on Art. 6(1)(f) — our legitimate interest in understanding who applies and building balanced groups.

3.3 Paid events (/specials)

Data: name, email, phone, age, gender, country of origin, number of seats, any note you write, and payment status. Purpose: to review your booking, allocate places, and run the event. Legal basis: Art. 6(1)(b) GDPR — steps taken at your request prior to a contract, and performance of that contract once concluded. Payment records: Art. 6(1)(c) — legal retention obligations.

Card details are entered on Stripe's own checkout page. We never see or store your card number.

3.4 Vibe test and card decks (/vibe-test, /cards)

Data: your answers, a generated result, and a name if you enter one. Purpose: to produce and display your result, and to let you compare with friends who have a share link. Legal basis: Art. 6(1)(b) — providing the feature you asked for.

3.5 Group composition

Data: the answers you gave when applying, including the languages you speak. Purpose: to put together groups for an event where people are likely to get on and share a language everyone can talk in. Legal basis: Art. 6(1)(b) GDPR. Groups are put together by a person, not by an automated system.

3.6 Communications

We send four different kinds of message, and they rest on different bases:

Kind Example Legal basis
Transactional Invitations, reminders, confirmations and feedback requests for an event you applied for or booked Art. 6(1)(b) GDPR — performing our agreement with you
Waitlist notifications Telling you that we have launched, or that a place has opened Art. 6(1)(b) GDPR — this is the service you signed up for, not advertising
Similar events, to past guests If you have booked an event, news about comparable future events Art. 6(1)(f) GDPR together with § 7(3) UWG. You may object at any time, free of charge, using the link in every message.
General promotional email Anything not covered above Art. 6(1)(a) GDPR — your separate consent

We do not send marketing SMS. Text messages are only ever transactional — invitations, reminders and details for an event you applied for or booked.

Every message carries a one-click way to stop receiving that kind of message. Opting out of marketing does not stop transactional messages about an event you have booked — you will still get the address and the reminder.

You can withdraw consent or object at any time via the link in any message, or by writing to support@kreiso.app.

3.7 Security and abuse prevention

We use Firebase App Check with reCAPTCHA Enterprise to verify that requests come from our genuine website rather than automated tooling. This reads technical characteristics of your device and browser. Our API rejects requests without a valid token, so the service cannot function without it.

Legal basis: Art. 6(1)(f) — our legitimate interest in preventing abuse, spam and fraud. Because this is strictly necessary to deliver the service you requested, it falls within the exemption in § 25(2) no. 2 TDDDG and is not subject to consent.

reCAPTCHA Enterprise is provided by Google as our processor under the Google Cloud Data Processing Addendum. It is not the free consumer reCAPTCHA product, and your data is not used for Google's own purposes.

3.8 Analytics

We use Google Analytics 4 to understand how the site is used and where people drop out of our signup flow.

This runs only if you consent. Analytics cookies are not set, and no data is sent to Google, until you click "Accept" on our cookie banner. You can change or withdraw your choice at any time via "Cookie settings" in the footer.

Legal basis: § 25(1) TDDDG and Art. 6(1)(a) GDPR — consent. Transfer: data is processed by Google in the United States. See section 7.

3.9 Storage on your device

Beyond analytics, we store a small amount of information on your device:

What Purpose Consent needed?
Flow identifier (/apply, /interest, /specials, /vibe-test) Lets you return and resume without re-entering everything No — strictly necessary
Language preference Remembers whether you chose English or German No — strictly necessary
App Check token Security (see 3.7) No — strictly necessary
Google Analytics cookies (_ga, _ga_*) Analytics (see 3.8) Yes

The items marked "strictly necessary" are exempt under § 25(2) no. 2 TDDDG because the service you asked for cannot be delivered without them.


4. Special categories of data (Art. 9 GDPR)

We ask for your country of origin and the languages you speak. We use these two things for statistics — understanding who applies and how our audience is made up — and to make sure everyone in a group can talk to each other.

We do not use them to infer, record or match on ethnic or cultural background. Nationality and language are not in themselves special categories under Art. 9 GDPR, and we do not process them for any purpose that would make them so.

We do not process data about your health, religion, political opinions, trade union membership, sexual orientation or sex life. If a free-text field invites you to describe yourself, please do not enter such information — we do not need it.

Should we later introduce matching that weighs shared cultural background, we will ask for your explicit consent under Art. 9(2)(a) GDPR separately and in advance. You would be able to decline and still use Kreiso.


5. Automated decision-making

We do not make automated decisions about you. Applications are reviewed and groups are put together by a person. Nothing on this website takes a decision producing legal effects or similarly significant effects on you by automated means within the meaning of Art. 22 GDPR.


6. Who we share data with

We do not sell, rent or trade personal data. We use the following processors, each under a data processing agreement pursuant to Art. 28 GDPR:

Processor Purpose Location
Google Cloud / Firebase (Firestore, Storage, Hosting, Cloud Functions, App Check) Databases, file storage, hosting, application logic, security EU (eur3 / EU / europe-west1)
Google Ireland Ltd. — Google Analytics 4 Analytics, only with your consent EU/US
Stripe Payments Europe Ltd. Payment processing for paid events EU/US
Resend Transactional and marketing email US
Twilio SMS delivery US

Stripe acts as an independent controller for parts of the payment process under its own privacy policy.

We may also disclose data where required by law, or to establish, exercise or defend legal claims.


7. International transfers

Where a processor handles data outside the EU or EEA, the transfer is protected by one of:

  • an adequacy decision of the European Commission — this covers transfers to certified organisations in the United States under the EU-U.S. Data Privacy Framework; or
  • the European Commission's Standard Contractual Clauses, together with supplementary technical measures such as encryption in transit and at rest.

You can request a copy of the relevant safeguards by writing to support@kreiso.app.


8. How long we keep data

Data Retention
Waitlist entries Until you unsubscribe, or 36 months without any interaction from you
Event applications Until you ask us to delete them, or 36 months without any interaction
Group composition data For as long as the application it belongs to
Paid booking records (accounting) Up to 10 years, as required by § 147 AO and § 257 HGB
Contract data, for legal claims 3 years from the end of the year in which the contract was concluded (§§ 195, 199 BGB)
Consent records 3 years from the end of the year in which consent was withdrawn, as evidence under Art. 7(1) GDPR
Analytics data 14 months — the maximum Google Analytics permits
Server and error logs 90 days

Where a period runs from inactivity, the clock restarts each time you interact with us.

After these periods data is deleted or irreversibly anonymised.


9. Your rights

You have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time with effect for the future.

Where we rely on legitimate interest (section 3.7), you may object under Art. 21 GDPR on grounds relating to your particular situation.

To exercise any of these, write to support@kreiso.app. We respond within one month; if a request is complex we may extend this by two further months and will tell you why.

You may also lodge a complaint with a supervisory authority. The one responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27, 91522 Ansbach, Germany https://www.lda.bayern.de

You may also complain to the authority where you live or work.


10. Age

Kreiso is not intended for children under 16, and we do not knowingly collect their data. Some events carry an 18+ requirement, shown on the event itself. If you believe a child has given us personal data, write to support@kreiso.app and we will delete it.


11. Security

We protect data with encryption in transit and at rest, authenticated access controls, request attestation via App Check, and access limited to what operations require.

No system is perfectly secure. If you find a vulnerability, please report it to support@kreiso.app.


12. Data Protection Officer

We have not appointed a Data Protection Officer. Under § 38(1) sentence 2 BDSG, one becomes mandatory regardless of headcount if our processing requires a Data Protection Impact Assessment under Art. 35 GDPR. We are assessing this, and will appoint and publish a DPO if it applies.


13. Changes

We may update this policy. If changes are material we will tell you by email or by a prominent notice on the site before they take effect. The date at the top always reflects the current version.


14. Contact

Nikita Konstantinovskiy Görresstraße 11 80798 Munich, Germany support@kreiso.app