Datenschutzerklärung

Stand: Juli 2026

1. Verantwortlicher

Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) ist Tobias Ens (Kontaktdaten siehe Impressum).

2. Welche Daten wir erheben

3. Hosting

Unsere Backend-Infrastruktur (Datenbank, Authentifizierung, Speicher) wird von Supabase in einer EU-Region gehostet. Deine Daten verbleiben damit im Geltungsbereich der DSGVO, soweit nicht unten abweichend beschrieben.

4. Auftragsverarbeiter und Drittanbieter

Wir verwenden keine Werbe-SDKs und keine Drittanbieter-Analyse- Tools, und wir verkaufen deine Daten nicht an Dritte.

5. Deine Rechte

Du hast jederzeit das Recht auf Auskunft über die zu dir gespeicherten Daten (Art. 15 DSGVO) und auf Löschung deines Kontos und der damit verbundenen Daten (Art. 17 DSGVO). Die Löschung entfernt dein Profil, deine Gerätschaften/Push-Token, deine Plex-Verbindung inklusive des verschlüsselten Tokens, deine Gruppenmitgliedschaften und deine Swipe-Historie. Deine Teilnahme an bereits entstandenen Gruppen-Matches wird anonymisiert (dein Bezug zum Match wird entfernt), der Match-Eintrag selbst bleibt für die übrigen Gruppenmitglieder bestehen.

Ausnahme bei gemeinsam genutzten Plex-Servern: Wenn du Zugriff auf einen Plex-Server hattest, den auch eine andere SofaSoGood-Nutzerin oder ein anderer Nutzer verwendet (etwa weil euch dieselbe Bibliothek freigegeben wurde), und diese Person weiterhin verbunden bleibt, dann werden dein Plex-Konto, dein Zugriffstoken und deine Zugriffsberechtigung vollständig gelöscht — die technischen Metadaten des Servers selbst (Kennung, Name, Netzwerkadresse, Bibliotheksabschnitte und die abgeglichenen Titel) bleiben jedoch erhalten, weil die verbleibende Person sie für ihre eigene Nutzung benötigt. Ein etwaiger Verweis auf dich als Eigentümer:in wird dabei entfernt. Diese Server-Metadaten werden erst gelöscht, wenn die letzte zugriffsberechtigte Person ihr Konto löscht oder Plex trennt.

Du kannst dein Konto direkt in der App löschen, oder öffentlich und ohne Login über unsere Löschseite.

Um Missbrauch dieser öffentlichen Löschseite zu verhindern (z. B. automatisierte Massenanfragen), speichern wir dort vorübergehend einen kryptografischen Hash (SHA-256) deiner E-Mail-Adresse und einen Hash der anfragenden IP-Adresse, jeweils für ca. einen Tag. Beide Hashes dienen ausschließlich der Ratenbegrenzung dieser einen Funktion; weder die E-Mail-Adresse noch die IP-Adresse werden dabei im Klartext gespeichert.

6. Speicherdauer

Wir speichern deine Daten, solange dein Konto besteht. Nach einer Löschanfrage werden dein Konto und die zugehörigen Daten unmittelbar gelöscht; die vollständige Entfernung aus Backups kann bis zu 30 Tage dauern.

7. Kontakt

Fragen zum Datenschutz richtest du bitte an die im Impressum genannte E-Mail-Adresse.

English summary

We collect your email address; profile details (display name, a two-letter region code used to show country-appropriate availability, your notification preference, and which streaming services — currently Netflix — you mark as available to you); which group(s) you belong to and whether you're the owner, together with the free-text group name you choose when you create a group (it is shown to every member of that group and is attributed to your account as its owner); your swipe decisions and resulting group matches; a push-notification device token together with your device's operating system; and — if you choose to set one — an avatar image you pick from your device's photo library. Avatar images are stored in an access-restricted bucket: they can be viewed by signed-in users of the app (for example your group members) but cannot be fetched or listed without signing in. If you connect Plex, we store your Plex username in plaintext and your access token encrypted in Supabase Vault (the token itself is never stored in plaintext); we also store technical metadata about your Plex setup — your server's id, name, and network address, your library section titles (e.g. "Movies", "Shows"), the individual titles held in each section (matched against the TMDB catalog so we can mark them "available via Plex" in your deck), and the time of the last sync. For the Plex sign-in handshake and every subsequent library call we transmit an app-generated random identifier (the X-Plex-Client-Identifier header), together with your access token, to plex.tv (Plex Inc., USA); we also store that identifier. It is not a hardware or device identifier, but Plex is a recipient of it within the meaning of Art. 13(1)(e) GDPR. Our backend is hosted by Supabase in an EU region. We use Firebase Cloud Messaging (Google) for push delivery, which may transfer device tokens to the US under the EU-US Data Privacy Framework and Standard Contractual Clauses. TMDB provides title metadata; JustWatch provides streaming-availability data. We do not use any advertising SDK or third-party analytics, and we do not sell your data. You may request access to or erasure (deletion) of your data at any time, in-app or via our public account deletion page — no login required. To prevent abuse of that public deletion page, we temporarily store a SHA-256 hash of your email address and a SHA-256 hash of the requesting IP address, each for about a day, solely to rate-limit that one endpoint — neither is ever stored in plaintext.

One exception to deletion, for shared Plex servers: if you had access to a Plex server that another SofaSoGood user also uses (for example because the same library was shared with both of you) and that person stays connected, then your Plex account, your access token and your access grant are all deleted in full — but the server's own technical metadata (its id, name, network address, library sections and the matched titles) is retained, because the remaining user needs it for their own use. Any reference to you as that server's owner is removed. Those server records are only deleted once the last user with access deletes their account or disconnects Plex.