Datenschutzerklärung

Stand: 2. September 2026

1. Verantwortlicher

Verantwortlicher im Sinne der Datenschutz-Grundverordnung (DSGVO) ist Tobias Ens, Manzingerweg 2, 81241 München, Deutschland, E-Mail: sofasogood-info@ensware.de (weitere Angaben siehe Impressum).

SofaSoGood richtet sich an Personen ab 16 Jahren (siehe Ziffer 3 der Nutzungsbedingungen); Daten von Kindern unter 16 Jahren erheben wir bewusst nicht.

2. Welche Daten wir erheben

Meldungen und Blockierungen

Meldungen. In der App selbst kannst du zwei Dinge melden: den Anzeigenamen eines Mitglieds (über das Menü neben seinem Namen in der Gruppe) und den Namen einer Gruppe (über das Menü der Gruppe). Alles andere — etwa ein Avatar-Bild — meldest du über den Eintrag „Send feedback“ oder an die im Impressum genannte Kontaktadresse; die Nutzungsbedingungen nennen dieselben Wege. Schickst du eine Meldung ab, speichern wir: dein Konto als meldende Person, das gemeldete Konto und die betroffene Gruppe (soweit vorhanden), die gemeldete Stelle (Anzeigename, Avatar-Bild, Gruppenname oder „Sonstiges“), deinen Meldetext (Freitext, bis 2.000 Zeichen) und den Zeitpunkt der Meldung. Hinzu kommt, wie wir die Meldung bearbeitet haben: der Bearbeitungsstand (offen, umgesetzt oder zurückgewiesen), der Zeitpunkt unserer Entscheidung, unsere Begründung und der Zeitpunkt, zu dem wir dich über die Entscheidung benachrichtigt haben. Diese Benachrichtigungen senden wir an die E-Mail-Adresse deines Kontos. Ergreifen wir eine Maßnahme zu deinem Konto oder zu Inhalten, die du eingestellt hast, schreiben wir dir ebenfalls an diese Adresse — auch dann, wenn die Maßnahme nicht auf deine eigene Meldung zurückgeht. Meldungen sind für andere Nutzer:innen nicht einsehbar — auch nicht für die gemeldete Person; sie werden ausschließlich von uns als Betreiber gelesen. Über den Eingang einer neuen Meldung werden wir automatisch benachrichtigt; diese Benachrichtigung enthält keinen Inhalt deiner Meldung und keine Angaben zu dir.

Wie lange wir Meldungen aufbewahren. Eine Meldung wird frühestens 12 Monate nach ihrem Eingang gelöscht, und auch dann nur, wenn wir sie entschieden und dich über die Entscheidung benachrichtigt haben; eine offene oder noch nicht beantwortete Meldung bleibt gespeichert, bis das erledigt ist. Löschst du dein Konto, werden die Meldungen, die du selbst abgeschickt hast, mit gelöscht. Meldungen über dich bleiben dagegen bestehen: die Verknüpfung mit deinem Konto wird dabei entfernt (das Kontokennzeichen wird geleert), der Meldetext und die Entscheidung bleiben jedoch unverändert erhalten und können weiterhin Angaben zu dir enthalten — begrenzt durch dieselbe 12-Monats-Frist. Rechtsgrundlage dafür ist Art. 17 Abs. 3 lit. e DSGVO (Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen) zusammen mit unserem berechtigten Interesse an einer nachvollziehbaren Moderation (Art. 6 Abs. 1 lit. f DSGVO).

Blockieren. Blockierst du ein Mitglied, speichern wir dein Konto, das blockierte Konto und den Zeitpunkt. Diese Liste ist nur für dich abrufbar; die blockierte Person erfährt nichts davon. Das Blockieren wirkt nur in deine Richtung: Anzeigename und Avatar-Bild der blockierten Person werden für dich ausgeblendet (an ihrer Stelle steht dann „Blocked member“ bzw. „a member“); umgekehrt ändert sich für die blockierte Person nichts. Was das Blockieren nicht tut: die Person bleibt in der Gruppe, ihre Swipes zählen weiterhin für die Matches der Gruppe, gemeinsame Matches entstehen weiter, Push-Benachrichtigungen über neue Matches nennen weiterhin den Namen der Gruppe, und ein von der blockierten Person vergebener Gruppenname bleibt sichtbar (dafür ist die Meldefunktion da). Willst du den Kontakt vollständig beenden, verlasse die Gruppe. Die Blockierung endet, sobald du sie im selben Menü aufhebst, und wird gelöscht, wenn du oder die blockierte Person das Konto löscht.

3. Besuch unserer Website und Nutzung der Web-App

Diese Website wird über Cloudflare Pages (Cloudflare, Inc., USA) ausgeliefert. Beim Aufruf verarbeitet Cloudflare die für die Auslieferung und den Schutz der Seite technisch erforderlichen Verbindungsdaten, insbesondere deine IP-Adresse. Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (sicherer und effizienter Betrieb der Website). Cloudflare ist unter dem EU-US Data Privacy Framework zertifiziert; ergänzend gelten Standardvertragsklauseln. Unsere Schriftarten sind lokal eingebunden; diese Website setzt keine Cookies und nutzt keine Analyse- oder Werbedienste. Die App-Schnittstelle (api.sofasogood.app) läuft nicht über das Cloudflare-Netzwerk.

Sprachwahl dieser Website: Wählst du auf dieser Website zwischen Deutsch und Englisch, speichern wir deine Auswahl unter dem Schlüssel „site_lang_v1“ lokal in deinem Browser (localStorage), damit die Seiten dir bei jedem weiteren Aufruf in der gewählten Sprache angezeigt werden; diese Speicherung ist für die Bereitstellung des von dir ausdrücklich gewünschten Dienstes unbedingt erforderlich (§ 25 Abs. 2 Nr. 2 TDDDG) und bedarf daher keiner Einwilligung.

Die Web-App im Browser (app.sofasogood.app)

Zusätzlich zur installierten App bieten wir SofaSoGood als Web-App unter app.sofasogood.app an. Sie läuft vollständig in deinem Browser und nutzt dieselbe Backend-Infrastruktur wie die installierte App (Punkt 4); es werden dort dieselben Konto-, Profil-, Gruppen- und Swipe-Daten verarbeitet, die in Punkt 2 beschrieben sind. Nicht verfügbar sind im Browser insbesondere zwei Funktionen der installierten App: Push-Benachrichtigungen und die Plex-Anbindung (siehe Punkt 2 und Punkt 5). Die Web-App wird über ein eigenes Cloudflare-Pages-Projekt ausgeliefert; für den Seitenaufruf gilt das im vorstehenden Absatz Beschriebene entsprechend.

Lokaler Speicher (localStorage): Die Web-App speichert in deinem Browser ausschließlich funktional notwendige Angaben — deine Sitzung (Anmelde-Token), den zuletzt geöffneten Tab, einen Hinweis-Merker für bereits gezeigte Neuigkeiten sowie einen noch nicht übertragenen Swipe. Diese Speicherung ist für die Bereitstellung des von dir ausdrücklich gewünschten Dienstes unbedingt erforderlich (§ 25 Abs. 2 Nr. 2 TDDDG); eine Einwilligung ist hierfür nicht erforderlich. Ein Einwilligungsbanner setzen wir daher nicht ein. Cookies oder Speicherzugriffe zu Werbe- oder Analysezwecken finden nicht statt.

Fehlerberichte der Web-App (Sentry): Tritt in der Web-App ein technischer Fehler auf, senden wir einen Fehlerbericht an unseren Auftragsverarbeiter Sentry (Punkt 5). Ein solcher Bericht enthält den technischen Fehlerablauf (Stacktrace), die aufgerufene Seiten-URL ohne Abfrageparameter und ohne Sprungmarke — Abfrageparameter und Sprungmarke entfernen wir bereits in deinem Browser, bevor der Bericht gesendet wird, damit etwa Einladungscodes aus einem Beitritts-Link nicht mitübermittelt werden —, Angaben zu Browser und Betriebssystem (Browserkennung/„User-Agent“), die Version der Web-App und den Zeitpunkt des Fehlers sowie einige technische Verlaufsvermerke (z. B. ein Wechsel des Online-Status oder der Hinweis auf eine erzwungene Abmeldung). Diese Verlaufsvermerke bestehen aus festen technischen Texten ohne Angaben zu deiner Person. Angaben zum Zustand deines Geräts — etwa Bildschirmgröße und -ausrichtung, Zeitzone, Spracheinstellung oder verfügbarer Speicher — entfernen wir bereits in deinem Browser aus dem Bericht, bevor er gesendet wird; sie werden nicht übermittelt. Aus dem Fehlertext und den Verlaufsvermerken entfernen wir außerdem E-Mail-Adressen und lange zufällige Zeichenfolgen (etwa Codes oder Token), bevor der Bericht deinen Browser verlässt. Die Berichte enthalten keine Konto- oder Nutzerkennung und sind nicht mit deinem Konto verknüpft. Eine IP-Adresse übermitteln wir nicht im Bericht; technisch bedingt sieht Sentry beim Empfang die IP-Adresse deiner Verbindung, speichert sie aber nicht (die Einstellung zum Nichtspeichern von IP-Adressen ist auf Ebene unserer Organisation aktiviert). Konsolenausgaben der App werden den Berichten nicht beigefügt. Diese Erfassung findet ausschließlich in der Web-App statt und dort nur in den von uns veröffentlichten Produktions-Builds — in Entwicklungs- und Testbuilds ist sie deaktiviert, und in der installierten App läuft Sentry nicht (dort erfasst Firebase Crashlytics Absturzberichte, Punkt 5). Rechtsgrundlage ist Art. 6 Abs. 1 lit. f DSGVO (unser berechtigtes Interesse an der Stabilität der Web-App). Einen Schalter zum Abschalten gibt es in der Web-App derzeit nicht; du kannst dieser Verarbeitung nach Art. 21 DSGVO widersprechen.

Anmeldung mit Google im Browser: Wenn du dich in der Web-App mit Google anmeldest, leiten wir dich dafür auf die Anmeldeseite von Google weiter und anschließend zurück auf app.sofasogood.app. Google erhält dabei die für den Anmeldevorgang erforderlichen Daten als eigenständiger Verantwortlicher (Punkt 5); zusätzlich erhält Google technisch bedingt deine IP-Adresse. Die Anmeldung per E-Mail-Code funktioniert ohne diese Weiterleitung.

Poster und Logos: Auch im Browser lädt die Web-App die Poster- und Logobilder direkt von image.tmdb.org, also unmittelbar von deinem Browser aus und nicht über unseren Server; TMDB erhält dabei technisch bedingt deine IP-Adresse und die Browserkennung (Punkt 5).

4. Hosting

Unsere Backend-Infrastruktur (Datenbank, Authentifizierung, Speicher) wird von Supabase in einer EU-Region gehostet (AWS-Region eu-central-1, Frankfurt am Main). Deine Daten verbleiben damit im Geltungsbereich der DSGVO, soweit nicht unten abweichend beschrieben.

5. Auftragsverarbeiter und Drittanbieter

Wir verwenden keine Werbe-SDKs und keine Drittanbieter-Analyse-Tools; zur Fehler- und Absturzdiagnose setzen wir ausschließlich die oben beschriebenen Dienste Firebase Crashlytics (installierte App) und Sentry (Web-App) ein. Deine Daten verkaufen wir nicht an Dritte.

6. Rechtsgrundlagen der Verarbeitung

Wir verarbeiten deine Daten auf folgenden Grundlagen: (a) Bereitstellung der App — Konto und Anmeldung, Profil, Gruppen und Gruppennamen, Swipes und Matches, deine persönliche Liste, Push- Zustellung bei aktivierter Benachrichtigung sowie die Plex-Anbindung, nachdem du sie hergestellt hast: Art. 6 Abs. 1 lit. b DSGVO (Erfüllung des Nutzungsverhältnisses). (b) Teilen deiner Likes mit einer Gruppe (Like-Import): deine Einwilligung, Art. 6 Abs. 1 lit. a DSGVO; du kannst sie jederzeit mit Wirkung für die Zukunft widerrufen (Art. 7 Abs. 3 DSGVO), indem du das Teilen in der Gruppe beendest — die Rechtmäßigkeit der bis dahin erfolgten Verarbeitung bleibt unberührt. (c) Absturz- und Fehlerberichte: für die installierte App (Firebase Crashlytics) deine Einwilligung, § 25 Abs. 1 TDDDG und Art. 6 Abs. 1 lit. a DSGVO, widerruflich mit Wirkung für die Zukunft (Art. 7 Abs. 3 DSGVO) über den Profil-Schalter „Absturzberichte“; für die Web-App im Browser (Sentry) unser berechtigtes Interesse an der Stabilität der Web-App (Art. 6 Abs. 1 lit. f DSGVO). (d) Missbrauchsvermeidung und Ratenbegrenzung (Hashes von E-Mail-Adresse, IP-Adresse und Konto-Kennung): Art. 6 Abs. 1 lit. f DSGVO — unser berechtigtes Interesse ist der Schutz des Dienstes vor automatisiertem Missbrauch. (e) Bearbeitung deines Feedbacks: Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO. (f) Nachweis deiner Zustimmung zu den Nutzungsbedingungen (Zeitpunkt, angenommene Fassung und die Bestätigung des Mindestalters): Art. 6 Abs. 1 lit. b DSGVO — der Eintrag belegt das Zustandekommen des Nutzungsverhältnisses, auf dessen Grundlage wir die App bereitstellen — er hält zugleich fest, welche Fassung für dein Nutzungsverhältnis gilt, und steuert, ob die App dich beim nächsten Mal erneut um deine Zustimmung bittet. (g) Bearbeitung von Meldungen — Entgegennahme, Prüfung, Entscheidung und die Benachrichtigung beider Seiten: Art. 6 Abs. 1 lit. c DSGVO (Erfüllung unserer Pflichten aus Art. 16 und Art. 17 der Verordnung (EU) 2022/2065 über digitale Dienste); die darüber hinausgehende Aufbewahrung nach Ziffer 2 zusätzlich auf Art. 6 Abs. 1 lit. f DSGVO. (h) Blockierfunktion — die Liste der von dir blockierten Konten: Art. 6 Abs. 1 lit. b DSGVO, da das Ausblenden auf deine eigene Anforderung hin Teil des Dienstes ist, den wir dir schulden. (i) Interne statistische Auswertung der Nutzung: Wir werten die nach (a) ohnehin vorhandenen Daten zusätzlich in zusammengefasster Form aus — etwa die Zahl der Konten, Gruppen, Swipes oder Matches pro Tag —, um zu verstehen, wie die App genutzt wird und was wir verbessern sollten; dafür erheben wir keine neuen Daten, es entstehen dabei keine Profile über einzelne Personen, und diese Auswertungen geben wir an niemanden weiter. Rechtsgrundlage ist die Weiterverarbeitung zu statistischen Zwecken, die mit dem ursprünglichen Zweck vereinbar ist (Art. 5 Abs. 1 lit. b Halbsatz 2 i. V. m. Art. 89 Abs. 1 DSGVO).

7. Deine Rechte

Du hast jederzeit das Recht auf Auskunft über die zu dir gespeicherten Daten (Art. 15 DSGVO) und auf Löschung deines Kontos und der damit verbundenen Daten (Art. 17 DSGVO). Die Löschung entfernt dein Profil, deine Gerätschaften/Push-Token, deine Plex-Verbindung inklusive des verschlüsselten Tokens, deine Gruppenmitgliedschaften und deine Swipe-Historie. Deine Teilnahme an bereits entstandenen Gruppen-Matches wird anonymisiert (dein Bezug zum Match wird entfernt), der Match-Eintrag selbst bleibt für die übrigen Gruppenmitglieder bestehen.

Darüber hinaus hast du das Recht auf Berichtigung (Art. 16 DSGVO), auf Einschränkung der Verarbeitung (Art. 18 DSGVO) und auf Datenübertragbarkeit (Art. 20 DSGVO). Eine erteilte Einwilligung — etwa in das Teilen deiner Likes mit einer Gruppe — kannst du jederzeit mit Wirkung für die Zukunft widerrufen (Art. 7 Abs. 3 DSGVO). Außerdem kannst du dich bei einer Datenschutz-Aufsichtsbehörde beschweren (Art. 77 DSGVO), zum Beispiel beim Bayerischen Landesamt für Datenschutzaufsicht (BayLDA), Ansbach — www.lda.bayern.de.

Soweit wir Daten auf Grundlage von Art. 6 Abs. 1 lit. f DSGVO verarbeiten, hast du das Recht, aus Gründen, die sich aus deiner besonderen Situation ergeben, jederzeit Widerspruch einzulegen (Art. 21 DSGVO).

Ausnahme bei gemeinsam genutzten Plex-Servern: Wenn du Zugriff auf einen Plex-Server hattest, den auch eine andere SofaSoGood-Nutzerin oder ein anderer Nutzer verwendet (etwa weil euch dieselbe Bibliothek freigegeben wurde), und diese Person weiterhin verbunden bleibt, dann werden dein Plex-Konto, dein Zugriffstoken und deine Zugriffsberechtigung vollständig gelöscht — die technischen Metadaten des Servers selbst (Kennung, Name, Bibliotheksabschnitte und die abgeglichenen Titel; eine Netzwerkadresse speichern wir ohnehin nicht) bleiben jedoch erhalten, weil die verbleibende Person sie für ihre eigene Nutzung benötigt. Ein etwaiger Verweis auf dich als Eigentümer:in wird dabei entfernt. Diese Server-Metadaten werden erst gelöscht, wenn die letzte zugriffsberechtigte Person ihr Konto löscht oder Plex trennt.

Ausnahme bei Meldungen über dich: Meldungen, die du selbst abgeschickt hast, werden zusammen mit deinem Konto gelöscht. Meldungen, die eine andere Person über dich abgeschickt hat, bleiben dagegen bestehen — ohne die Verknüpfung zu deinem Konto, aber mit unverändertem Meldetext und unveränderter Entscheidung, die weiterhin Angaben zu dir enthalten können. Grundlage ist Art. 17 Abs. 3 lit. e DSGVO (Geltendmachung, Ausübung oder Verteidigung von Rechtsansprüchen): andernfalls könnte ein Konto den Nachweis eines Verstoßes durch die eigene Löschung beseitigen. Die Einzelheiten und die Frist stehen unter Ziffer 2, „Meldungen und Blockierungen“.

Du kannst dein Konto direkt in der App löschen, oder öffentlich und ohne Login über unsere Löschseite.

Um Missbrauch dieser öffentlichen Löschseite zu verhindern (z. B. automatisierte Massenanfragen), speichern wir dort vorübergehend einen kryptografischen Hash (SHA-256) deiner E-Mail-Adresse und einen Hash der anfragenden IP-Adresse, jeweils für ca. einen Tag. Beide Hashes dienen ausschließlich der Ratenbegrenzung dieser einen Funktion; weder die E-Mail-Adresse noch die IP-Adresse werden dabei im Klartext gespeichert.

Aus dem gleichen Grund begrenzen wir auch, wie viele Import-Anfragen dein Gerät pro Stunde an unseren Plex-Import senden darf. Dazu speichern wir vorübergehend einen Zähler unter einem Schlüssel, der einen kryptografischen Hash (SHA-256) deiner Konto-Kennung enthält (plex-import:submit:<Hash>) — ebenfalls für ca. einen Tag und mit der gleichen automatischen Bereinigung wie die Hashes oben. Deine Konto-Kennung wird dabei nicht im Klartext gespeichert.

Auch fehlgeschlagene Versuche, einer Gruppe mit einem falschen Einladungscode beizutreten, begrenzen wir — pro Konto und pro Netzwerk. Dafür speichern wir vorübergehend (ca. einen Tag, mit der gleichen automatischen Bereinigung wie oben) einen kryptografischen Hash (SHA-256) der anfragenden IP-Adresse; die Adresse selbst wird nie im Klartext gespeichert. Erfolgreiche Beitritte werden nicht gezählt.

8. Speicherdauer

Wir speichern deine Daten, solange dein Konto besteht. Nach einer Löschanfrage werden dein Konto und die zugehörigen Daten unmittelbar gelöscht — ausgenommen sind Meldungen anderer Nutzer:innen über dich, die ohne die Verknüpfung zu deinem Konto erhalten bleiben (Ziffer 7 und Ziffer 2); Sicherungskopien (Backups) werden nach 7 Tagen automatisch überschrieben, die vollständige Entfernung aus Backups erfolgt daher innerhalb von 7 Tagen.

Abweichende, kürzere Fristen gelten für Absturz- und Fehlerberichte sowie für die unter Ziffer 6 und Ziffer 7 genannten Hashes zur Ratenbegrenzung; die jeweiligen Fristen stehen dort. Für Meldungen gilt eine eigene, längere Frist — sie steht unter Ziffer 2.

9. Kontakt

Fragen zum Datenschutz richtest du bitte an die im Impressum genannte E-Mail-Adresse.

The English section on this page is a summary; the complete and legally authoritative privacy policy is the German version.

Privacy policy (English summary)

Last updated: 2 September 2026

SofaSoGood is intended for people aged 16 and over (see section 3 of the Terms of Service); we do not knowingly collect data from children under 16. We collect your email address; profile details (display name, a two-letter region code used to show country-appropriate availability, your notification preference, and which streaming services — currently Netflix, Prime Video, Disney+, Apple TV+, Paramount+, WOW, RTL+, Joyn, and HBO Max — you mark as available to you; which services you have marked is visible to the members of your groups); the app separately shows regional free or rent-or-buy offers on some titles from providers you have not necessarily added as a service, such as Amazon Video, Apple TV, Google Play, or ARTE, or Joyn's free tier, once those sources go live — that is catalog data from JustWatch (see processors and third parties, below), not data we collect about you; watched marks (titles you mark as watched) — visible to the members of your groups, including groups you join later, and marking never hides or removes anything; your personal list (which titles you save for yourself, mark as watched, or pass on, with timestamps — filled from your solo swipes, from your likes in groups, and from the watched marks you set on your groups' matches; your existing likes and watched marks were carried over once when the feature launched), which is visible only to you and is shared with a group only with your explicit consent (Art. 6(1)(a) GDPR): if a group has like-sharing enabled and you agree to share there, the titles on your To watch list and your flagged rewatches flow into that group's shared deck and matching continuously. Passes always stay private. You can withdraw your consent per group at any time with effect for the future (the 'Sharing likes' switch in the group); no new titles flow in after that, and the lawfulness of sharing up to that point is unaffected. Matches that already happened remain, and titles already imported stay in that group's deck and matching — they can still produce new matches later. The continued use of already-imported titles — including matches that only arise after you stop sharing — rests on our and the other group members' legitimate interest in a reliable group function (Art. 6(1)(f) GDPR); you may object to this processing (Art. 21 GDPR). We store your per-group answer (agreed or declined) and a short-lived technical queue of likes being imported; coalesced match notifications are deleted after sending (an undeliverable notification's record is deleted after about 7 days); your personal swipe settings (movies, series, or both, plus an optional genre filter that determines which titles enter your own deck) are likewise readable only by you; your private lists (including Favorites) — list names you type and their genre tags are visible only to you, never to group members; which group(s) you belong to and whether you're the owner, together with the free-text group name you choose when you create a group (it is shown to every member of that group and is attributed to your account as its owner); An owner may also set an optional group genre filter, visible to the group's members, which limits which titles enter that group's deck; your swipe decisions and resulting group matches. We also use a group's likes to sort that group's shared deck, so titles the group is more likely to enjoy appear earlier. This affects order only — it never reveals who liked what, and passes are never used for it. We also store when you last viewed a group's matches (used only to badge new matches for you; never visible to other members) and, if you ask a group's owner for more suggestions, that request (visible to that group's owner by name; cleared when the group's settings change) — both are deleted when you leave the group or delete your account; a push-notification device token together with your device's operating system (Android or iOS — push notifications exist only in the installed app; the web app in your browser delivers none and registers no token); and — if you choose to set one — an avatar image you pick from your device's photo library. Avatar images are stored in an access-restricted bucket: they can be viewed only by you and by the members of a group you are in, and not even by those members if they have blocked you; they cannot be fetched or listed without signing in. If you connect Plex, we store your Plex username in plaintext and your access token encrypted in Supabase Vault (the token itself is never stored in plaintext). A second copy of the access token stays on your device, in operating-system-protected secure storage (Android Keystore / iOS Keychain); that device copy is the one used to read your library, and it is erased when you disconnect Plex, sign out, or delete your account. Plex is offered only in the installed app: you cannot connect Plex in the web app, and no copy of the access token is stored in your browser. We also store technical metadata about your Plex setup — your server's id and name, your library section titles (e.g. "Movies", "Shows"), the individual titles held in each section (matched against the TMDB catalog so we can mark them "available via Plex" in your deck), and the time of the last sync. We do not store your Plex server's network address — it is only cached locally on your own device. Your library is read by your device, over your local network, directly from your Plex server, not from our backend; your device then submits only the entries it found, and our backend matches those against the TMDB catalog and stores the result. For the Plex sign-in handshake and every subsequent library call we transmit an app-generated random identifier (the X-Plex-Client-Identifier header), together with your access token, to plex.tv (Plex, Inc., USA); we also store that identifier. It is not a hardware or device identifier, but Plex is a recipient of it within the meaning of Art. 13(1)(e) GDPR. Only you establish the connection; the processing rests on Art. 6(1)(b) GDPR, and the transfer to the US is necessary to provide the Plex feature you requested (Art. 49(1)(b) GDPR). Feedback: if you send us feedback from the app, we store your message and the screenshot you marked up, together with your account, the app version, and the platform, until you delete your account. Terms acceptance: when you accept the Terms of Service in the app, we store the time, the version you accepted (for example "15 August 2026"), and your confirmation that you are at least 16. That confirmation is a yes/no value — we collect no age and no date of birth. Accepting a later version adds a further record; existing records are never altered, and declining stores nothing. All of them are deleted with your account. This website is served via Cloudflare Pages (Cloudflare, Inc., USA), which processes the connection data technically required to deliver and protect the site, in particular your IP address (Art. 6(1)(f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses additionally apply. Our fonts are self-hosted; this site sets no cookies and uses no analytics or advertising. The app API (api.sofasogood.app) does not pass through Cloudflare's network. This site's language choice: if you switch this site between German and English, we store your choice locally in your browser (localStorage) under the key "site_lang_v1" so the pages appear in the language you chose on later visits; this storage is strictly necessary to provide the service you expressly requested (§ 25(2) no. 2 TDDDG) and therefore needs no consent. The web app in your browser (app.sofasogood.app): besides the installed app we offer SofaSoGood as a web app at app.sofasogood.app. It runs entirely in your browser and uses the same backend as the installed app, processing the same account, profile, group, and swipe data described above. Two features of the installed app are in particular not available in the browser: push notifications and the Plex connection. The web app is served from its own Cloudflare Pages project, so what is said about Cloudflare above applies to loading it as well. Local storage: the web app stores only functionally necessary items in your browser — your session (sign-in token), the last tab you opened, a marker for an already-shown hint, and a not-yet-submitted swipe. This storage is strictly necessary to provide the service you expressly requested (§ 25(2) no. 2 TDDDG) and needs no consent, so we show no consent banner. There are no cookies and no storage access for advertising or analytics. Error reports from the web app (Sentry): when a technical error occurs in the web app, we send an error report to our processor Sentry. Such a report contains the technical error trace (stack trace), the page URL without query parameters and without the fragment — we strip both in your browser before the report is sent, so that an invite code from a join link is never transmitted —, browser and operating-system details (the browser's user-agent string), the web app's version, and the time of the error, plus a few technical trail markers (for example an online-status change or a note that a forced sign-out occurred). Those trail markers are fixed technical texts with no details about you. Details about your device's state — such as screen size and orientation, time zone, language setting, or available memory — are removed from the report in your browser before it is sent; they are not transmitted. We also strip email addresses and long random strings (codes or tokens, for example) out of the error text and the trail markers before the report leaves your browser. The reports contain no account or user identifier and are not linked to your account. We send no IP address in the report; Sentry technically sees your connection's IP address on receipt but does not store it (the option to not store IP addresses is enabled for our organization). The app's console output is not attached to the reports. This collection happens only in the web app, and there only in the production builds we publish — it is disabled in development and test builds — and Sentry does not run in the installed app, where Firebase Crashlytics collects crash reports instead. The legal basis is Art. 6(1)(f) GDPR (our legitimate interest in the stability of the web app); there is currently no switch to turn it off in the web app, and you may object to this processing under Art. 21 GDPR. The provider is Functional Software, Inc. ("Sentry"), 45 Fremont Street, San Francisco, CA 94105, USA; error reports are received and stored in Sentry's EU region (data centre in Frankfurt, Germany), while administrative data about our own Sentry account (for example project and access data) is stored by Sentry in the US. The error reports themselves therefore never leave the EU; the safeguards that follow concern only the administrative data of our Sentry account stored in the US: for that transfer the same safeguards as for Firebase apply — Sentry is certified under the EU-US Data Privacy Framework, and Standard Contractual Clauses additionally apply. Error reports are deleted automatically after the retention period that applies to our Sentry account (currently 90 days); because they are not linked to your account, deleting your account does not delete them — they expire after that period instead. Because we store no identifier with these reports, we cannot attribute them to you (Art. 11(2) GDPR); access to or erasure of them is therefore technically impossible. Signing in with Google in the browser: if you sign in with Google in the web app, we redirect you to Google's sign-in page and then back to app.sofasogood.app; Google receives the data necessary for the sign-in as an independent controller and, as a technical necessity, your IP address. Signing in with an emailed code needs no such redirect. Posters and logos are loaded directly from image.tmdb.org in the browser too — fetched by your browser itself, not through our backend — so TMDB receives your IP address and user-agent string. Our backend is hosted by Supabase in an EU region (AWS region eu-central-1, Frankfurt). We use Firebase Cloud Messaging (Google) for push delivery, which may transfer device tokens to the US under the EU-US Data Privacy Framework and Standard Contractual Clauses. Firebase Crashlytics (Google) is off by default and only activates once you consent — in your profile (the "Crash reports" switch) or when the app asks you — and you can withdraw that consent at any time, with effect for the future, through the same switch. If you consent and the app crashes, Crashlytics collects a crash report — the stack trace, device model, OS version, app version, the time of the crash, technical device state such as free memory, and a Crashlytics installation identifier — so we can find and fix bugs; crash reports are not linked to your account, the same US-transfer safeguards as for push delivery apply. Crash reports are retained by Google for 90 days and then deleted automatically. Because they are not linked to your account, deleting your account does not delete them; they expire after that period instead. Crashlytics runs only in the installed app, never in the browser. TMDB provides title metadata; the app also loads poster and logo images directly from image.tmdb.org, so TMDB (USA) technically receives your IP address, as required to display the content you request. JustWatch provides streaming-availability data. Resend sends our system emails (sign-in codes and deletion codes) via send.sofasogood.app; processing occurs in an EU region (eu-west-1); the provider is Resend, Inc. (USA). If you sign in with Google, Google receives the data necessary for the sign-in process as an independent controller; that provider's own privacy policy applies, and in the web app that sign-in runs as a redirect, as described above. Signing in with Apple ("Sign in with Apple") is not offered at present; the alternative to Google is always a code emailed to you. We do not use any advertising SDK or third-party analytics; our only diagnostics tools are Firebase Crashlytics (installed app) and Sentry (web app) as described above, and we do not sell your data. Legal basis for each purpose: providing the app (account, profile, groups, swipes, matches, your list, push delivery when enabled, and the Plex connection once you establish it) rests on Art. 6(1)(b) GDPR; sharing your likes with a group rests on your consent, Art. 6(1)(a), withdrawable at any time with effect for the future (Art. 7(3)); crash reports in the installed app (Firebase Crashlytics) rest on your consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG), withdrawable at any time with effect for the future (Art. 7(3)) via the "Crash reports" switch in your profile; error reports in the web app (Sentry) rest on our legitimate interest in the stability of the web app (Art. 6(1)(f) GDPR); abuse prevention and rate limiting rest on Art. 6(1)(f) (protecting the service from automated abuse); feedback handling rests on Art. 6(1)(b)/(f); and the record that you accepted the Terms (time, accepted version, and the 16+ confirmation) rests on Art. 6(1)(b) GDPR too, because it evidences the conclusion of the very contract under which we provide the app — and it is also what tells the app whether to ask you again. Handling reports — receiving them, examining them, deciding, and notifying both sides — rests on Art. 6(1)(c) GDPR (compliance with our obligations under Art. 16 and Art. 17 of Regulation (EU) 2022/2065 on digital services), and the retention beyond that, described in section 2 above, additionally on Art. 6(1)(f) GDPR. The blocking feature — the list of accounts you have blocked — rests on Art. 6(1)(b) GDPR, because hiding them at your own request is part of the service we owe you. Internal statistical evaluation of usage: we also evaluate the data we already hold for providing the app in aggregated form — for example how many accounts, groups, swipes, or matches there are per day — to understand how the app is used and what we should improve; this collects no new data, produces no profiles about individual people, and we pass these figures on to no one. The legal basis is further processing for statistical purposes, which is compatible with the original purpose (Art. 5(1)(b), second half-sentence, together with Art. 89(1) GDPR). You may request access to or erasure (deletion) of your data at any time, in-app or via our public account deletion page — no login required. Deleted data disappears immediately; backups are retained for 7 days, so complete removal from backups happens within 7 days. One exception, for reports about you: the reports you filed yourself are deleted with your account, but a report another person filed about you remains — without the link to your account, yet with its text and our decision unchanged, so it may still contain information about you. The basis is Art. 17(3)(e) GDPR (establishment, exercise or defence of legal claims): otherwise an account could erase the evidence of its own breach by deleting itself. That record has its own, longer retention period, stated with the report disclosure below. Shorter, separate retention periods apply to crash and error reports and to the rate-limiting hashes described here; each period is stated where that data is described. You also have the right to rectification (Art. 16 GDPR), restriction of processing (Art. 18), and data portability (Art. 20). Where we process data based on legitimate interests you may object at any time (Art. 21). You may also lodge a complaint with a data protection supervisory authority (Art. 77), for example the Bavarian Data Protection Authority (BayLDA), Ansbach, Germany — www.lda.bayern.de. To prevent abuse of that public deletion page, we temporarily store a SHA-256 hash of your email address and a SHA-256 hash of the requesting IP address, each for about a day, solely to rate-limit that one endpoint — neither is ever stored in plaintext. Failed attempts to join a group with a wrong invite code are rate-limited the same way, keyed per account and per network via a SHA-256 hash of the requesting IP address (kept for about a day, never in plaintext); successful joins are not recorded. The same kind of short-lived counter limits how many Plex import batches your device may submit per hour: it is keyed by a SHA-256 hash of your account id (plex-import:submit:<hash>), kept for about a day and cleaned up the same way, and your account id is never stored in plaintext there either.

Reports and blocks. Inside the app itself there are two things you can report: a member's display name (from the menu next to their name in a group) and a group's name (from the group's own menu). Anything else — an avatar image, for example — you report through the "Send feedback" entry or the contact address in the Impressum; the Terms of Service name the same routes. When you send a report, we store: your account as the reporter, the reported account and the group concerned (where there is one), which surface you reported (display name, avatar, group name, or "other"), your free-text description (up to 2,000 characters), and the time of the report. We add how we handled it: the state of the report (open, actioned, or dismissed), the time of our decision, our reasons, and the time we notified you of that decision. We send these notices to your account's email address. If we take a measure regarding your account or something you submitted, we write to that address too — including where the measure did not follow a report of your own. Reports are not visible to any other user — not to the person reported either; only we, as the operator, read them. We are notified automatically that a new report has arrived; that notification carries no content from your report and no information about you. How long we keep reports: a report is deleted at the earliest 12 months after it arrives, and even then only once we have decided it and notified you of that decision; an open or un-notified report stays stored until that is done. If you delete your account, the reports you filed are deleted with it. Reports about you remain: the link to your account is removed (the account reference is cleared), but the free-text description and the decision are kept unchanged and may still contain information about you — bounded by that same 12-month retention. The legal basis is Art. 17(3)(e) GDPR (establishment, exercise or defence of legal claims) together with our legitimate interest in accountable moderation (Art. 6(1)(f) GDPR). Blocking: when you block a member we store your account, the blocked account, and the time. That list is readable only by you, and the person you block is not told. A block works in your direction only: the blocked person's display name and avatar image are hidden from you (lists show "Blocked member" or "a member" in their place); nothing changes in the other direction, for the person you blocked. What blocking does not do: that person stays in the group, their swipes still count toward the group's matches, new matches can still form, push notifications about new matches still name the group, and a group name that the blocked person chose stays visible (reporting is the path for that). If you want to end contact entirely, leave the group. A block ends as soon as you undo it from the same menu, and it is deleted if you or the blocked person deletes their account.

One exception to deletion, for shared Plex servers: if you had access to a Plex server that another SofaSoGood user also uses (for example because the same library was shared with both of you) and that person stays connected, then your Plex account, your access token and your access grant are all deleted in full — but the server's own technical metadata (its id, name, library sections and the matched titles; no network address is stored in the first place) is retained, because the remaining user needs it for their own use. Any reference to you as that server's owner is removed. Those server records are only deleted once the last user with access deletes their account or disconnects Plex.