tellmelotellmelo.
ImprintPrivacyTerms of useReport copyrightContactAPIApps

Privacy policy

Last updated: 4 November 2026

This is a translation. The German version is authoritative. Where this text differs from it, the German text applies. You can switch language at the bottom of the page.

Overview

  • Controller
  • The essentials

When you visit

  • Server logs
  • Cookies and browser storage
  • Language
  • External links
  • Shared links and previews

Account

  • Account and sign-in
  • Signing in with Google
  • Age and parental consent
  • Invitations
  • Profile, place and organisation
  • Verification
  • Plans
  • Payment, invoices and cancellation

Content

  • Posts, replies and messages
  • Groups
  • “typing…” and online status
  • Findable by search engines

Feed and reach

  • Learned topics
  • Reach and highlighting
  • Lending your feed

Notifications

  • Push and apps
  • Recap by e-mail

Moderation and administration

  • Moderation and account standing
  • Contact requests and copyright reports
  • Audit log
  • API key

Periods and rights

  • How long data is kept
  • Recipients and third countries
  • No automated decisions
  • Your rights
  • Changes
Contents

Overview

  • Controller
  • The essentials

When you visit

  • Server logs
  • Cookies and browser storage
  • Language
  • External links
  • Shared links and previews

Account

  • Account and sign-in
  • Signing in with Google
  • Age and parental consent
  • Invitations
  • Profile, place and organisation
  • Verification
  • Plans
  • Payment, invoices and cancellation

Content

  • Posts, replies and messages
  • Groups
  • “typing…” and online status
  • Findable by search engines

Feed and reach

  • Learned topics
  • Reach and highlighting
  • Lending your feed

Notifications

  • Push and apps
  • Recap by e-mail

Moderation and administration

  • Moderation and account standing
  • Contact requests and copyright reports
  • Audit log
  • API key

Periods and rights

  • How long data is kept
  • Recipients and third countries
  • No automated decisions
  • Your rights
  • Changes

This policy describes which personal data tellmelo processes, for what purpose, on what legal basis and for how long.

Overview

Controller

Blackline Development Inh. Sebastian Ostermeier Gottesackerweg 11a85283 WolnzachBayern, Deutschland

No data protection officer has been appointed; the requirements of Section 38 BDSG are not met.

The essentials

  • No advertising, no sale. Data is not analysed for advertising, not sold and only passed to the recipients named here.
  • No analytics tools, no tracking pixels and no cross-site tracking.
  • No third parties when loading. Fonts, icons and program files come from this server. Other providers are only involved with “Continue with Google”, when paying for a plan and with push switched on.
  • Server located in Germany, run by the controller.
  • Learned topics only once switched on (learned topics).

When you visit

Server logs

The web server logs requests: IP address, time, requested address, amount of data and browser headers such as user agent and language. Excluded are the session cookie, the regular checks of signed-in members, images for signed-in members and unchanging program files.

Purpose: operation and defence against attacks. Legal basis: Art. 6(1)(f) GDPR. Retention: at most 14 days.

Cookies and browser storage

tellmelo sets two cookies and keeps three values in local storage, and in the Android app one more in session storage. With push a background script is added, with “Continue with Google” another cookie for ten minutes. The same list is shown by the shield button at the bottom of the page; after signing in on phones and tablets under Settings → App & data → What is on your device.

NamePurposeDurationLegal basis
tellmelo_session: cookieKeeps you signed in. Contains only a random token.7 days; deleted at once when you sign outSection 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR
tellmelo-language: cookieThe chosen language as a code, such as de.One year or until you choose againSection 25(2) no. 2 TDDDG
tellmelo-theme: local storageLight or dark. Not sent to the server.Until you delete itSection 25(2) no. 2 TDDDG
tellmelo-look: local storageThe app colour and pure black of a plan, so they apply while the page loads. The choice itself is kept with your settings.Until you delete it or the plan endsSection 25(2) no. 2 TDDDG
tellmelo-data-panel: local storageThat you have already opened the data panel.Until you delete itSection 25(2) no. 2 TDDDG
tellmelo-app: session storage (only in the Android app)That the page runs in the app, so the app’s tab bar and push question stay after a reload. Contains only 1. Not sent to the server.Until you close the appSection 25(2) no. 2 TDDDG
sw.js: background script (push only)Receives the push service’s signal and shows the notification. Stores nothing.Until you switch push offSection 25(1) TDDDG, Art. 6(1)(a) GDPR (push)
tellmelo_oauth: cookie (Google only)Links the return from Google to the sign-in started here. Random values only.10 minutes; deleted at once after the returnSection 25(2) no. 2 TDDDG

There is no consent banner: all seven entries are exempt from consent under Section 25(2) TDDDG. For the push script you are asked explicitly when you switch it on.

Language

tellmelo is available in six languages. The language comes from your account setting, otherwise the tellmelo-language cookie, otherwise the browser’s Accept-Language header, otherwise English. The header is only read when a page is requested, not stored. Legal basis: Art. 6(1)(f) GDPR, or (b) when you choose yourself.

The German version is authoritative. The translations of this policy and of the other legal texts are reading aids.

External links

Links in posts, messages and profiles first lead to a notice page. The target address sits after the #, which the browser does not send to the server; the notice page only asks whether the team has checked the target site. Which links you open is not stored. To prevent mass requests, the server counts requests for one minute, without an account under a non-reversible fingerprint of the IP address. The target site does not learn which page you come from.

Submitting sites for review: stored are your account ID, the address, your assessment, an optional reason, the time and the decision; the team sees your name. The ratings themselves apply until the team lifts them; blocked sites get no link preview, and texts naming them cannot be published. Legal basis: Art. 6(1)(f) GDPR (protection from harmful sites).

Shared links and previews

When someone pastes the link to a post into a messenger or another network, its server loads a preview: the author’s name, the first 200 or so characters and the first image. There is no preview for posts from non-public groups, from blocked accounts or accounts being deleted, and for removed posts. Search engines may only index this page if the author has switched on “Findable by search engines”. Legal basis: Art. 6(1)(f) GDPR.

Account

Account and sign-in

  • Username and display name: chosen by you, public.
  • Password: only as a scrypt hash with its own salt, never in plain text.
  • E-mail address: required, stored encrypted, with the key kept separately. Used for password links, messages from the operator, for example about changed legal texts, and the recap if you switch it on. Disposable addresses are rejected.
  • Two-factor sign-in: optional, mandatory for the team. The secret is stored encrypted, the ten recovery codes only as a hash. Switching it off under Settings → Account & security deletes both.
  • Sign-ins: time, last access (hourly) and a rough device description such as “Chrome on Windows”, no IP address. Under Settings → Account & security → Signed-in devices and signing out single or all other sign-ins can be ended.
  • Last use: when you last used tellmelo, to the hour. It drives the marking of new posts in the feed, the recap, “last online” in direct messages, the check of invitations and the end of unused organisation accounts.

Legal basis: Art. 6(1)(b) GDPR (contract of use).

Signing in with Google

With “Continue with Google” you sign in with Google and decide whether Google passes three details to us: the ID of your Google account, your e-mail address (only if Google has verified it) and your name. We do not receive your profile picture, contacts or password. The ID is stored to recognise you; if the verified address already belongs to a verified account, the two are linked. For a new account, address and name are kept encrypted until you finish signing up, for at most 30 minutes.

Legal basis: Art. 6(1)(b) GDPR. Unlink at any time under Settings → Account & security; the ID is then deleted. What Google itself processes is governed by Google’s privacy policy.

Age and parental consent

The date of birth is evaluated once when you sign up and not stored. Under 16, no account is created at first, but a request to the e-mail address of a parent or guardian (Art. 8(2) GDPR). Until the answer, the desired name and username, both e-mail addresses (encrypted) and the password as a hash are kept; without an answer they are deleted after 14 days, on refusal at once.

With the consent the account is created. As proof (Art. 5(2) GDPR), the time of the consent and the e-mail address it came from (encrypted) are stored until the account is deleted. Legal basis: Art. 6(1)(b) in conjunction with Art. 8 GDPR.

Invitations

Accounts prepared by the operator: The operator can prepare an account for someone. tellmelo then processes details that do not come from the invited person: the intended name and username, for organisation accounts industry, website, phone number and public e-mail address, and for an invitation by e-mail also their e-mail address (encrypted). Until the person opens the link and sets their own password, none of it is visible.

By e-mail, one invitation is sent naming sender, inviting person, purpose and validity, plus one reminder each after seven and thirteen days. For an invitation by link, tellmelo stores no address and sends no reminders; the link’s preview shows name, username and a prepared profile picture. Invitations not accepted are deleted after 14 days, or at once on request through the contact form. Legal basis: Art. 6(1)(f) GDPR.

Invitation links from members (/login?invite=username) contain only the username. Whoever signs up through one is asked once whether to follow that person; the page only shows the name for a public profile. For the rewards for inviting (terms of use), tellmelo stores which member invited, if the new account reports through the link within one day of signing up, and notes each night whether it has been used since, using the time of last use that is stored anyway. The inviting member only sees the number of counted and waiting invitations, not the people. The link is deleted as soon as it is clear the account does not count (after 30 days), otherwise 30 days after counting, at the latest after 60 days. “Don’t count me” in the notice after signing up deletes it at once, with no disadvantage to the account. For the inviting member, the number of invitations, the steps reached and credited plan time stay until the account is deleted. Legal basis: Art. 6(1)(f) GDPR (rewarding invitations fairly, keeping out fake accounts); for the inviting member Art. 6(1)(b) GDPR.

Profile, place and organisation

Place (optional): place, region, country, postcode, street, house number, coordinates of the centre and radius. From this tellmelo works out which posts come from your area. None of it is public at first; with “Show place in profile” only the place appears. The coordinates only go to your own browser. Legal basis: Art. 6(1)(a) GDPR; withdrawing under Settings → Profile → Your place deletes all location details.

Organisation accounts: businesses and associations show their full address, industry, phone number and a public e-mail address publicly, businesses also opening hours. These details are stored unencrypted because they are public; automated accounts have none. The account type ends when the team takes it back or after eighteen months without signing in (a message after one year, then at most a monthly reminder); account and posts remain. Legal basis: Art. 6(1)(b) GDPR.

Address search: while you type, the input goes to Photon (komoot GmbH, Potsdam). The request is made by this server; the service learns neither your IP address nor who searched. Answers are cached without any ID for 30 days.

Website: a website you enter appears publicly in your profile. When saving, on “Check now” and roughly weekly at night, the server fetches the page and looks for a link with rel=me to your profile; the website only sees the server’s IP address. Stored are the address, the result and the time, nothing of the content. Legal basis: Art. 6(1)(b) GDPR.

Verification

A person decides on every application for the verification mark. Stored are the application text, account type and time, for people and automated accounts also the figures when sending (followers as well as posts and received likes, replies and reposts of the last 30 days).

Businesses and associations upload an officially recognised document. It is kept encrypted and only until the decision; if the application is withdrawn it is deleted at once. Only administrators can open it, and every opening is logged. You may black out details that are not needed, with a reason. After the decision the application without the document, the decision and its reason are kept for 90 days. Legal basis: Art. 6(1)(b) and (f) GDPR (protection from accounts posing as someone else).

Plans

tellmelo offers two plans, “Supporter” and “Organization”. They can be bought or are granted by hand by the operator, for example to try them out. If your account has a plan, its kind, start and end are stored as long as the account exists. A plan changes nothing about how the feed is sorted. Legal basis for everything in this section, unless stated otherwise: Art. 6(1)(b) GDPR.

  • Badge and colours: your profile shows a badge with the plan’s name and start date; hide it under Settings → Profile. A chosen profile colour is seen by everyone who sees your profile. The app colour, saved feed mixes and stock replies are kept only with your settings.
  • Notes on saved posts are seen only by your account. They are deleted when you stop saving the post, when it is deleted, or with your account.
  • Your own emojis are public images: anyone who sees a text using them sees the image while your plan runs.
  • Insights: your year and the statistics of your posts are calculated from existing data and not stored separately; they show only totals, no names.
  • Link page: your link page at /<username> is public, also without signing in, and shows your name, profile picture, your text and your links. When the address is shared, the preview shows a card with your name, profile picture, your text and the first four links. Search engines may only list it if your profile is Findable in search engines. For each link we only count how often it was clicked, not by whom; when forwarding, the target site only learns that the visit comes from tellmelo. When the plan ends, the address leads to your profile.
  • Reminders and messages sent later: a reminder on a saved post stays with your account until the chosen time and is then deleted. A message you send later is stored encrypted on the server until then, like every message; the recipient only sees it once it is sent. If your plan has ended by then, it stays unsent until you send or delete it yourself.
  • Team access (Organization): up to five people act for the account. They see what the account sees, including the messages to the account, and write in its name; posts by editors wait for approval. What they do is kept in the log with person, action and time for 90 days; the account and its admins read it. Sign-in, security, keys, data export and deletion stay with whoever holds the password.
  • Team inbox (Organization): the organization and its team note for a conversation who takes care of it, whether it is done, and an encrypted internal note. The person in the conversation does not see this. It stays until the organization changes it or one of the two accounts is deleted. Legal basis towards the person in the conversation: Art. 6(1)(f) GDPR (handling requests as a team); the organization is responsible for the notes.
  • Events and locations (Organization) appear publicly in the profile; calendar files of public accounts can be fetched without signing in. Whoever signs up for an event appears with name and @name in the organization’s list of participants; others only see the number. Events and sign-ups are deleted one year after the event, a sign-up also when you sign off.
  • Profile additions (Organization): questions and answers and the description in further languages are public on the profile. Recurring posts appear at the chosen times like other posts of the account.
  • Website widget (Organization): it shows the name and the five latest public posts on another website, only for an account with a public profile page (Findable by search engines). The browser of that website’s visitors loads it from this server, which produces the server logs. The widget sets no cookies and runs no script. The operator of that website is responsible for it.
  • Webhooks (Organization): for new notifications, an https address that the organization enters receives the kind, the IDs of notification and post and the @name of whoever triggered it, never texts. The organization is responsible for receiving them and everything after. Undelivered deliveries are retried for at most one day and then deleted. Legal basis towards those who trigger them: Art. 6(1)(f) GDPR; the organization sees in its notifications anyway who reacted.
  • When a plan ends, these tools stop. What you set up with them is kept for six months, so that a new plan brings it back; you get an email two weeks before. After that it is deleted: link page, further pinned posts, reminders, messages not yet sent, recurring posts, profile additions, team access and team notes, events with sign-ups, locations, notes, own emojis, webhooks, profile and app colour, saved mixes and stock replies. Posts, messages and your account stay. Until then, what is stored stays readable and can be deleted.

Payment, invoices and cancellation

You pay for a plan on the checkout page of Stripe (in the EU: Stripe Payments Europe, Limited, Dublin, Ireland); your browser goes to Stripe for this. You enter payment details, email address and, where needed, your address only there; tellmelo does not receive them. tellmelo sends Stripe only the plan, term, price and an order number. tellmelo gets back whether, when and how much was paid, refunded or ended, with the IDs of the payment, plan and receipt at Stripe.

Depending on the operator’s setting, either tellmelo sells and Stripe only handles the payment, or Stripe sells through Link as merchant of record, calculates the VAT, sends the receipt and invoice and helps with questions about the payment; the checkout page shows which applies. For data Stripe processes for its own purposes, for example as merchant, against fraud or for legal obligations, Stripe itself is responsible; Stripe’s privacy policy (stripe.com/privacy) applies.

  • Stored at tellmelo: the order until it is completed (at most 14 days), every payment and refund with plan, period and amount and, when tellmelo sells itself, invoices and credit notes. Invoices to private persons name no one.
  • Billing address: businesses and clubs can store a name, address and VAT ID for their invoices under Settings → Plan → Invoices and payments. They are kept encrypted and deleted when you remove them or delete the account.
  • Cancellation and withdrawal work under Settings → Plan or without signing in on the page /cancel. The details from the form (name, @name, email address, reason) are stored encrypted; the confirmation comes by email.

Legal basis: Art. 6(1)(b) GDPR; for invoices, payments and cancellations as records Art. 6(1)(c) GDPR (Section 147 AO, Section 14b UStG). Retention: invoices and payments 8 full calendar years after the year they were issued, cancellations 6 full calendar years after the year they were received, both also after the account is deleted; the link to the account is then removed.

Content

Posts, replies and messages

Posts, replies, reactions, poll votes, drafts, collections, saved profiles and direct messages are stored as long as your account exists. Posts can be seen by anyone who opens tellmelo, direct messages only by those involved. Earlier versions of edited posts are kept with their time as long as the post exists and are visible to all readers. Legal basis: Art. 6(1)(b) GDPR.

Direct messages are access-protected, but not end-to-end encrypted. Anyone with access to the server can technically read them.

  • Images are scaled down in your browser; EXIF data including the GPS location is removed first. For this the Android app briefly keeps a chosen photo in its own storage on your device; it only leaves the device by being uploaded.
  • Link previews are loaded by the server, not your browser; the linked site does not learn who reads the post.
  • Message requests (if you want them): messages from people you do not follow and have never written to wait without a notification. Only whom you follow and have written to is evaluated for this.
  • Muting: stored until you undo it. The person learns nothing about it.
  • Slow mode: only your choice per post is stored. Whether many strangers are replying right now is counted afresh with every reply, not stored.

Groups

Applications: your text or answers are stored encrypted together with the questions word for word. They can be read by the group’s leaders and co-admins, not by the tellmelo team. Legal basis: Art. 6(1)(b) GDPR. Retention: 90 days after the decision; withdrawn ones are deleted at once.

Public group pages: the leaders of a public group can switch off “Findable by search engines” (on by default for open groups). The page /g/id shows name, description, pictures, topics, number of members and the newest posts, but only from members who are [findable](#search-engines) themselves. Legal basis: Art. 6(1)(f) GDPR, for the posts as under Findable by search engines.

“typing…” and online status

In direct messages tellmelo shows whether the other person is typing, is online (a tellmelo page visibly open in the last 90 seconds) and when they were last online (rounded to five minutes). Online status is only seen by people you have written to yourself; “typing…” only by the person you are writing to, and not across a block or a waiting request.

Nothing is stored for this: both are kept only in memory (typing 8 seconds, online time at most 24 hours), and only the fact that you type is sent, not what. If the online time is missing there, for example after a restart, “last online” shows your last use. Both displays are on and can be switched off under Settings → Privacy. Legal basis: Art. 6(1)(f) GDPR.

Findable by search engines

“Findable by search engines” is on by default, also when signing up, and can be switched off under Settings → Privacy. Accounts created with a parent’s consent stay off until they switch it on themselves. Profiles that were off when this default was introduced are switched on after an e-mail with 15 days’ notice, unless you choose “Keep off”; on the next visit tellmelo asks once. When on, your profile has the public page /u/username with name, description, profile picture, number of followers and newest public posts, for organisations also address, contact details and opening hours. Search engines may index it, it is listed in the sitemap, and visitors without an account see your public posts under shared posts at “More on tellmelo”. Excluded are posts from non-public groups, removed posts and blocked accounts or accounts being deleted.

Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is that the platform’s public content can be found. You object (Art. 21 GDPR) by switching it off. After that the page no longer exists; search engines remove what they already indexed by their own rules and on their own responsibility.

Feed and reach

Learned topics

If learning is switched on (off by default), searches, likes and shares earn 1, 3 or 5 points, split across the post’s #tags. “For you” uses this to weight your feed and to suggest groups. This is profiling within the meaning of Art. 4(4) GDPR, without an automated decision under Art. 22 GDPR.

Stored per topic are a score and a time, not what you read or searched for. Points halve after thirty days without a new reason and disappear below a threshold. Under Settings → Your feed you see and delete the topics; switching off deletes everything learned. Legal basis: Art. 6(1)(f) GDPR; you object (Art. 21 GDPR) with the switch.

Mirror: shows where the posts in “For you” come from and what your blocks and mutes filtered out in seven days. It is calculated when opened and not stored. It does not count posts by people who blocked you, so that it does not give that away.

Reach and highlighting

tellmelo counts how often a post was shown, once per person and day. For this the server stores no ID but a non-reversible fingerprint of day, person and post, which is deleted after 2 days; the counter stays as long as the post. The number is seen by the author, moderation and administration. Legal basis: Art. 6(1)(f) GDPR.

The team can highlight a post: it then weighs more in “For you” for a while, carries the mark “Highlighted by the team”, and the author is notified. Highlights cannot be bought.

Lending your feed

At your request tellmelo creates a link through which another person reads your “For you” list in your order for one hour. From it they learn which topics occupy you and whom you follow. Only the order is passed on: the person sees only what they may see anyway; messages, saved items, blocks and muted words stay with you.

Stored is one row with a random key, your ID and the time, for one hour. Take it back under Settings → Your feed. Legal basis: Art. 6(1)(a) GDPR.

Notifications

Push and apps

Push only exists if you switch it on on a device. Legal basis: Art. 6(1)(a) GDPR, Section 25(1) TDDDG. You can withdraw at any time in the settings, per device. A push service never receives the content of a notification, only the signal that there is something new; your device loads the text from this server.

  • In the browser: your browser creates an address at its maker’s push service (Chrome: Google, Firefox: Mozilla, Safari: Apple); it and two keys are stored here.
  • In the Android app with Google services push runs through Google’s Firebase Cloud Messaging. The app’s device ID and a fingerprint of its key are stored with your sign-in. Switching off deletes the ID here and at Google, signing out deletes it here.
  • On Android devices without Google services the app, with push switched on, asks here by itself about every 15 minutes whether there is anything new. It sends only its key and the time of the last notification it already knows; only the app stores that time. Nothing goes to third parties. When Android actually lets the app ask is up to the system; notifications may be delayed as a result. Switching off ends the asking. As with Firebase, only a fingerprint of its key is stored here, together with your sign-in.
  • In the desktop app for Windows and Linux there is no push service: while the app runs, the page checks here regularly, and the app shows anything new without content as a notification of your system. Nothing goes to third parties and nothing extra is stored here; whether the app keeps running after closing is stored only on your device. On Windows it uses Microsoft Edge WebView2; if it is missing, the installer downloads it from Microsoft.

Only one place notifies you: a notification and its sound come where you have tellmelo in front; otherwise in the desktop app if it runs, otherwise in the app on your phone, otherwise in the browser. For this, every open page reports with its regular check whether it is the desktop app, an app or a browser, whether it is in front, and its browser’s push address. This is kept in memory only and lapses 75 seconds after the last report; all that is stored is whether a push subscription belongs to an app or a browser. Legal basis: Art. 6(1)(b) GDPR.

Recap by e-mail

If you want it (off by default), after seven days away you receive an e-mail with what has happened since, as numbers only, without names or content, at most one until your next visit. Stored are the time of consent, of the last e-mail and a key for the unsubscribe link. Accounts created with parental consent cannot use it. Legal basis: Art. 6(1)(a) GDPR, Section 7(2) no. 2 UWG. Withdraw with one click through the link in every e-mail, in your e-mail program or in the settings; everything is then deleted.

Moderation and administration

Moderation and account standing

Reports, decisions, warnings and appeals are stored so that decisions can be traced and reviewed; you see your status under “Account standing”. If a profile breaks the rules, the team can remove pictures and description and ask for new names; until then you can only read tellmelo. You receive the reason as a notification and by e-mail; the affected details are kept until you have changed them. The team can also ask you to confirm your e-mail address again, for example if an account takeover is suspected. Legal basis: Art. 6(1)(b) and (f) GDPR.

Contact requests and copyright reports

In the contact form and the report form you give your name and e-mail address, for a copyright report also a postal address for service. Everything is kept encrypted, including the team’s replies; without an account you reply through a secret link that changes with every new reply.

Legal basis: Art. 6(1)(f) GDPR, for copyright reports also (c) (Section 10 DDG). Retention: contact requests until 6 months after completion, copyright reports at most 3 years as evidence. Earlier deletion is possible; for a copyright report only after explicit confirmation, recorded in the audit log.

Audit log

Every decision in the administration is logged with person, subject, time and a mandatory reason. The log is the only data that remains after your account is deleted, so that moderation stays verifiable; it contains no posts and no messages. Legal basis: Art. 6(1)(f) in conjunction with Art. 17(3)(e) GDPR. Retention: 3 years from the entry.

API key

You create a key for the API under Settings → App & data → API. It is shown once and not stored; what remains is a non-reversible fingerprint, the first characters, the time of last use and the number of calls, not what was fetched. Legal basis: Art. 6(1)(b) GDPR. Retention: until you reset or delete the key.

Periods and rights

How long data is kept

WhatHow long
Account, posts, messages, planUntil 30 days after the account is deleted
Server logsAt most 14 days
Fingerprints for counting reach2 days
Learned topicsHalve after 30 days without a new reason
Lent feedOne hour
Read notifications30 days
Cached link previews30 days
Cached address lookups30 days
Sessions7 days, at once when you sign out
Confirmation keysPassword 1 hour, address 24 hours; used ones at once
Sign-ups without a confirmed address1 hour; through Google 30 minutes
Second sign-in step5 minutes
Rate limit countersAt most 1 hour
Invitations14 days
Who invited whom (rewards)At most 60 days
Unconfirmed requests through the forms7 days
E-mails in the outboxAfter sending; undeliverable ones after 30 days
Browser view of an e-mail14 days
Contact requestsUntil 6 months after completion
Copyright reportsAt most 3 years
Applications to a group90 days after the decision; open ones without a limit
Submissions of external links for review90 days after the decision; open ones without a limit
Verification: documentUntil the decision or withdrawal
Verification: application without document90 days after the decision
Audit log3 years; outlasts the account deletion
Team access log90 days
Past eventsOne year after the event
Deliveries to webhooksAt most 1 day
Reminders on saved postsUntil the chosen time
Messages sent laterUntil they are sent or deleted
Event sign-upsUntil signing off, at most one year after the event
Data of plan features after the plan ends6 months; an email two weeks before
Plan ordersUntil completed, at most 14 days
Invoices and payments8 full calendar years; outlast the deletion of the account
Cancellations and withdrawals6 full calendar years; outlast the deletion of the account
Billing addressUntil you remove it or delete the account
Google link, two-factor sign-in, websiteUntil you remove them or delete the account
“typing…” and online statusOnly in memory, at most 24 hours
Database backups3 days
Backups of the encryption key30 days

Deleted data disappears from live operation at once but stays in the nightly backup for up to 3 days.

Recipients and third countries

  • A data centre operator in Germany runs the server, as a processor under Art. 28 GDPR with a contract. Name on request through the contact form.
  • An e-mail delivery provider in Germany sends confirmations, notices, password links and the recap, also as a processor. Name on request.
  • Photon (komoot GmbH, Potsdam) receives only the input when you type an address (profile).
  • Google (in the EU: Google Ireland Limited, Dublin) only with “Continue with Google”.
  • Stripe (in the EU: Stripe Payments Europe, Limited, Dublin) only when you buy a plan: plan, term, price and order number; you enter your payment details there yourself (Payment).
  • Your browser’s push service, in the Android app Google’s Firebase Cloud Messaging only with push switched on and only for the content-free signal (push).
  • An organization’s webhook servers receive the kind, IDs and @names of new notifications to that organization when it has entered webhooks (Plans); the organization itself is responsible for receiving them.

There are no other recipients. Third countries: all data stays in the EU, except with push switched on and when you buy a plan. With push switched on, the address of the delivery point and a signed, content-free signal go to the browser maker’s service (Chrome: Google, Safari: Apple, both USA; Firefox: Mozilla), in the Android app the device ID to Google (USA). The basis is your consent under Art. 49(1)(a) GDPR, alternatively the EU-US Data Privacy Framework. When you buy a plan, Stripe may transfer data to Stripe, Inc. in the USA; the basis is the EU-US Data Privacy Framework, which Stripe has joined. With “Continue with Google”, Google only learns that the sign-in is for tellmelo.

No automated decisions

There is no automated decision under Art. 22 GDPR. The feed sorts by a formula whose sliders you set; under every post it says why it appears. Moderation decisions are made by a person; restrictions follow from points in your account standing, each resting on a person’s decision, and you can appeal against every decision.

Your rights

  • Access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18) and data portability (Art. 20).
  • Objection (Art. 21 GDPR) to processing based on a legitimate interest.
  • Withdrawal of consent (Art. 7(3) GDPR) with effect for the future.

Do it yourself: under Settings → App & data you download your data and delete your account; it is blocked at once and finally deleted after 30 days, until then you undo it by signing in. For anything else write to kontakt@tellmelo.com or use the contact form.

You delete conversations on your side under Messages, your own messages for both sides up to 24 hours after sending, your own posts and replies through their menu.

Complaint: to a data protection supervisory authority (Art. 77 GDPR), for example where you live or where the controller is based; in Bavaria the Bavarian Data Protection Authority (BayLDA), Promenade 27, 91522 Ansbach.

Changes

If the processing changes, this text is updated; the date at the top names the version in force. Significant changes are announced by e-mail to your account’s address. Purely editorial changes without effect on the content are not announced separately.

Back to tellmelo