Privacy Policy

1. Controller

Miklós Hegybíró · c/o IP-Management #11238 · Ludwig-Erhard-Str. 18 · 20459 Hamburg, Germany

Email: support@feedfocus.app

No data protection officer has been appointed, as fewer than 20 persons are constantly engaged in the automated processing of personal data (§ 38 (1) BDSG).

2. Overview of data processing

FeedFocus processes personal data solely to provide the app's functions. We do not sell data, do not display advertising and do not carry out tracking.

3. Data collected and purpose

3.1 Google OAuth authentication

When signing in with Google OAuth, we receive:

Purpose: user authentication and provision of the feed from subscribed channels. No write access to the YouTube account (e.g. likes, comments) takes place. The OAuth token is stored and used exclusively server-side; it does not leave our backend. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.2 YouTube data (feed)

To provide the distraction-free feed, the following data is retrieved:

This data is used exclusively to display the feed and for notifications about new videos. Legal basis: Art. 6(1)(b) GDPR.

3.3 Video transcripts

Video transcripts required for AI summaries are obtained via an external service provider: Supadata (Dumpling Software UG (haftungsbeschränkt), Berlin, Germany). Only the public YouTube video ID is transmitted to this provider — no personal data, no user identifier and no OAuth token.

Video transcripts are processed only transiently (read, process, discard): they are held in a temporary technical cache and automatically deleted after 24 hours at the latest. Permanent storage of full video texts does not take place. Legal basis: Art. 6(1)(b) GDPR.

3.4 User data stored in the app

The following data is stored in our database (Supabase, hosted at AWS, region eu-central-1):

To prevent circumvention of usage limits (e.g. by deleting and recreating an account), usage quotas are additionally tied to a pseudonymized identifier: a cryptographic hash (HMAC-SHA256) of the Google account ID. The plaintext identifier is not stored for this purpose; the hash cannot be reversed to the person. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in abuse prevention).

3.5 AI processing by third-party providers

To create AI summaries, podcast scripts and AI perspectives, video transcripts and metadata (title, channel name) are transmitted to the following AI providers:

a) Server-side processing (via Supabase Edge Functions, API keys stored with the provider):

The respective current model versions are used; the specific models used are disclosed in the AI Transparency Statement.

b) Optional user-side processing (user's API keys, encrypted in the iOS Keychain via SecureStore): Users can store their own API keys for supported AI providers in the settings. In this case, the data is transmitted directly from the device to the respective provider. By entering their own key, the user actively consents to this transmission.

No personal data of the user is transmitted to the AI providers — only video transcripts and metadata. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.6 Text-to-Speech (audio)

The speech output (MP3) for digests and briefings is generated primarily by xAI (Grok TTS, five synthetic voices). As a technical fallback if the primary service fails, ElevenLabs Inc. (UK/USA) may be used. Only the texts to be voiced (summaries, podcast scripts) are transmitted, no personal data. Processing takes place server-side via Supabase Edge Functions.

3.7 Payment processing

In-app purchases are processed via Apple StoreKit and managed by RevenueCat Inc. (USA). From RevenueCat we receive:

RevenueCat stores the Supabase User ID as the App User ID for mapping. Legal basis: Art. 6(1)(b) GDPR.

3.8 Newsletter

When you sign up for the newsletter, we store the email address in our database. Dispatch takes place via Resend Inc. (USA). Double opt-in is implemented: dispatch only begins after confirmation via the link sent. Unsubscribing is possible at any time via the link in every email. Legal basis: Art. 6(1)(a) GDPR (consent).

3.9 Crash reporting and diagnostics

Sentry (Functional Software Inc., USA) records crash reports of the app as well as server-side error events of our Edge Functions for troubleshooting. These events contain technical context data (e.g. error codes, video IDs), but no plaintext data such as name or email address. In the development environment, Sentry is disabled. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability of the app).

3.10 Push notifications

When push notifications are activated, an Expo Push Token is generated on the device and stored in our database. Dispatch takes place via the Expo Push Service (650 Industries Inc., USA). Legal basis: Art. 6(1)(a) GDPR (consent).

3.11 Data stored on the device

FeedFocus stores the following data locally on the user's iOS device:

4. Processors and third-country transfers

The following services process data on our behalf or receive data to provide their services:

ServiceProviderLocationPurposeSafeguardLegal basis
SupabaseSupabase Inc.USA (hosting: AWS eu-central-1)Database, auth, storage, Edge FunctionsEU SCCs, DPFArt. 6(1)(b)
SupadataDumpling Software UG (haftungsbeschränkt)Germany (EU)Sourcing of video transcripts (only public video IDs transmitted)no third-country transferArt. 6(1)(b)
Anthropic ClaudeAnthropic PBCUSAAI summaries, podcast scripts, AI perspectiveEU SCCs, DPFArt. 6(1)(b)
Google (YouTube)Google LLCUSA/EUOAuth, YouTube Data API (read-only), RSS feedsEU SCCs, DPFArt. 6(1)(b)
Google GeminiGoogle LLCUSA/EUAI summaries, AI perspective, video fallbackEU SCCs, DPFArt. 6(1)(b)
xAI GrokxAI Corp.USAAI perspective, text-to-speech (Grok TTS)EU SCCsArt. 6(1)(b)
ElevenLabsElevenLabs Inc.UK/USAText-to-speech (technical fallback only)EU SCCs, UK AdequacyArt. 6(1)(b)
RevenueCatRevenueCat Inc.USASubscription management, entitlement checkEU SCCs, DPFArt. 6(1)(b)
ResendResend Inc.USANewsletter dispatch, double opt-inEU SCCsArt. 6(1)(a)
SentryFunctional Software Inc.USACrash reporting, error monitoring (app + server)EU SCCs, DPFArt. 6(1)(f)
Expo650 Industries Inc.USAPush notifications, build serviceEU SCCsArt. 6(1)(a)
AppleApple Inc.USA/EUIn-app purchase, app distributionEU SCCs, DPFArt. 6(1)(b)

For transfers to the USA, we rely on EU Standard Contractual Clauses (SCCs) and, insofar as the respective provider is certified, the EU-US Data Privacy Framework (DPF). Details of the individual safeguards can be requested from the controller.

Note: When users use their own API keys, a direct contractual relationship exists between the user and the respective AI provider. The privacy policy of the respective provider then applies additionally.

5. Storage period

6. Your rights

You have the following rights vis-à-vis us under the GDPR:

To exercise your rights, contact us at: support@feedfocus.app

You have the right to lodge a complaint with a data protection supervisory authority. Competent supervisory authority: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, poststelle@lfd.niedersachsen.de

7. Changes

We reserve the right to adapt this privacy policy in the event of changes to the app's functions or the legal situation. The current version is always available at feedfocus.app/privacy.