Privacy notice
Version: 2026-08-21 (draft, before the service goes on sale). This notice was written without a lawyer's review. That is a deliberate choice by the provider, stated here rather than hidden.
1. Who is responsible, and for what
For the photos and videos of a party, the host (our customer) is the controller under data-protection law; we host and display that content on the host's behalf as a processor (DPA). For platform-level processing — moderation, abuse prevention, statutory preservation, billing and operational telemetry — we are the controller ourselves:
Marc Adrian Peters, Heinrichsallee 22–24, 52062 Aachen, Germany
2. What data is processed
Guests: uploaded photos and videos, a random device identifier, party session state; in durable logs, guest-related identifiers appear only as hashes. Customers: account, order and billing data. Card details go straight to the payment provider and never pass through our code.
Signing in with Google: if you choose to sign in with Google, we link your customer account to your Google account. Google gives us your name, e-mail address (including whether it is verified), possibly your profile picture, and an account identifier. We store those profile details, the link itself, and the scope of the permissions granted. The access and identity tokens Google issues are used exactly once, during the sign-in itself, and are not stored.
3. Purposes and legal bases
Providing the service (Article 6(1)(b) GDPR), moderation and abuse prevention (point (f) — our legitimate interest in a safe service), statutory duties such as reporting and retention obligations (point (c)), and billing (points (b) and (c)). The moderation pipeline exists to prevent abuse; it is expressly not presented as a complete filter for unlawful content.
Signing in with Google serves only to authenticate the customer account, that is, to perform the contract (point (b)). We use the data received from Google for no other purpose: no profiling, no sharing with third parties, no advertising.
4. How long data is kept
Party content is deleted at the end of the retention window that was booked. Every party includes 90 days from the party date, and the window can be extended to one or two years for a fee. Financial records are subject to the statutory retention periods (§ 147 AO: books 10 years, accounting vouchers 8 years, commercial letters 6 years). Content under a statutory preservation duty is excluded from deletion runs for as long as that duty lasts. Account and sign-in data — including the Google link — is kept for the duration of the customer relationship; expired session and sign-in records are removed automatically by an hourly cleanup. We do not store Google access tokens, so there is nothing further to keep.
5. Deletion and restorability — plainly said
"Deleted" means: removed from delivery immediately. Media files are then final at the storage layer — the object store keeps no restorable shadow copies. Control-plane data may remain restorable in platform backups for roughly 30 days and is permanently removed within that window.
6. Logging
Guest-related identifiers are hashed before any durable log entry is written — the logs contain no guest identifiers in the clear.
7. Processors and data locations
Guest media sits in an EU bucket; party state sits in EU-pinned instances; the central control-plane database is EU-pinned as well. It holds minimised account and order data plus publication states, and no guest media — that is data minimisation, not a consequence of the location question. Our processors (list version 2026-08-07):
| Processor | Role | What reaches it | Safeguards |
|---|---|---|---|
| Cloudflare, Inc. | Hosting, object storage (R2), databases (D1/DO), streaming (SFU), bot protection, transactional e-mail | Platform traffic; guest media in the EU bucket; party and guest state in EU-pinned Durable Objects; customer e-mail addresses and message content (receipts, magic links, expiry warnings) | Cloudflare DPA plus EU jurisdiction controls throughout; the control-plane database (D1) is EU-pinned as well. It holds only minimised account and order data plus publication states — data minimisation, not a substitute for location |
| Amazon Web Services (Rekognition) | Image moderation labels | Image bytes and sampled video frames of guest media, transient, region eu-central-1 (Ireland as fallback) | AWS DPA plus standard contractual clauses where applicable; no retention configured |
| Stripe | Payment processing | Customer identity and payment data for the party booking; card data goes straight to Stripe and never passes through platform code | Stripe DPA plus standard contractual clauses; the platform stores only order and fulfilment records |
Signing in with Google: the optional Google sign-in is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google is not our processor here — which is why Google is not in the list above — but an independent controller for the processing inside your own Google account. When you sign in, Google learns that you are signing in to KCAM; Google's own privacy policy applies to that.
8. Your rights
Access, rectification, erasure, restriction, objection, portability — and the right to complain to a data-protection supervisory authority. One limitation stated openly: guest uploads are tied to a random device identifier rather than to a person, so erasure and access requests from guests are in practice answered per device. For party content, address your request to the host; we give the host the tools needed to answer it.