Privacy Policy

Last updated: 5 July 2026

Protecting your personal data matters to us. Skriza is in a closed beta: the website provides information and accepts beta applications, and beyond that, testers holding a beta invitation can create an account and use the platform. We process as little data as possible. Our servers are in the European Union; the sole exception is the content delivery network in front of the site, which we disclose in section 2.

1. Controller

The controller for data processing on this website is:

Yusuf Senel, Von-Hünefeld-Str. 8, 40764 Langenfeld, Deutschland

Email: [email protected]

2. Hosting and server log files

This website runs on servers within the European Union. When you access the site, your browser automatically transmits information stored in server log files: a shortened IP address, date and time of access, the page requested, the browser and operating system used, and the referring page.

Purpose: ensuring reliable operation, system security and technical administration. Legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). Log files are deleted after a short period unless needed to investigate security incidents.

Hosting: This website is hosted by netcup GmbH, Daimlerstraße 25, 76185 Karlsruhe, Germany; the server location is Germany. Processing takes place under a data-processing agreement pursuant to Art. 28 GDPR.

Delivery and protection (Cloudflare): To deliver the website securely and quickly, we use the content delivery network of Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare routes the connections and protects the site against attacks (e.g. DDoS). This may involve a transfer of connection data to the USA, safeguarded by appropriate guarantees (EU Standard Contractual Clauses). Legal basis is Art. 6(1)(f) GDPR (secure, stable operation). Further information: https://www.cloudflare.com/en-gb/privacypolicy/.

3. Beta application

If you use the beta application form, we process the data you provide: name, email address and — optionally — your reason/message.

Purpose: handling your application, managing the waiting list and contacting you regarding the beta. Legal basis is Art. 6(1)(a) GDPR (consent by submitting) and Art. 6(1)(b) GDPR (pre-contractual measures). Data is deleted once the purpose no longer applies or you withdraw your consent, at the latest when the beta ends.

3a. Account and content during the beta

With a beta invitation you can create an account. We then process: your email address and a password hash for signing in, your profile details (display name, username, optionally a biography and a picture) and the content you create yourself — posts, comments, reactions, direct messages and, if you use them, live audio and video rooms. Legal basis is Art. 6(1)(b) GDPR (performance of the contract of use).

Direct messages are meant for the people in that conversation. They are not end-to-end encrypted at present: transport is secured with TLS and the data sits encrypted on European servers, but we as the operator can technically access it. We do not do so routinely, only where necessary to fix a fault, handle a report, or comply with a legal obligation.

Your content and account remain stored while the account exists. You can delete individual posts. For deleting the whole account and for a copy of your data, an informal message to the address above is enough; we carry it out by hand during the beta.

3b. Profile picture

A profile picture is optional. Without one we show your initials.

Using your Google picture: if you sign in with Google, Google hands us the address of your profile picture there. We do not display that picture directly. We ask whether you want to adopt it and only park the address until you answer. The reason is practical: embedding the picture from Google's servers would make your browser tell Google which page is open every time an avatar renders. If you say yes, we download it once and keep our own copy. Google is not contacted again after that.

Uploading your own: the file is validated and re-encoded before it is stored. That removes all metadata — in particular the GPS coordinates phone photos carry. Your profile picture then no longer reveals where it was taken.

Automatic check: before publication every picture goes through an automated check for sexual or pornographic content. A single downscaled still frame is sent to our own checking service for this. It runs on the same infrastructure in Germany as the website; the picture does not leave it, and no third party is involved. What is recognised is image content — there is no face recognition and no biometric identification.

Outcome: if the check objects to the picture, or the checking service cannot be reached, the picture is not published but put in front of a person on the team. We keep those two cases apart: “objected to” is a statement about your picture, “could not be reached” is a statement about our infrastructure, and the second is never held against you. In both cases you keep seeing your own picture while others do not, and you can upload a different one at any time.

Pictures awaiting review are stored apart from public storage under an unguessable address. They are never publicly retrievable; reviewers get a link that expires after five minutes. The check result is stored alongside the picture so a decision can be made.

The legal basis for storing your picture is Art. 6(1)(b) GDPR (performance of the contract of use); for the content check it is our legitimate interest in a platform without pornographic material and in protecting minors (Art. 6(1)(f) GDPR). You can replace or remove your profile picture at any time.

4. Cookies and local storage

We use technically necessary storage only. Your preferred language and theme (light/dark) are stored locally in your browser to make the site usable. If you sign in as a beta tester, a technically necessary session cookie is set. There is no cookie banner, because there is nothing to consent to.

4a. Audience measurement (Skriza Pulse)

We measure traffic to this website with Skriza Pulse, our own analytics service. It runs on the same European servers as the site, the data never leaves them, and no third party is involved. We previously used Google Analytics via Cloudflare Zaraz for this and switched it off in July 2026.

Pulse stores nothing on your device and reads nothing from it: no cookie, no localStorage, no sessionStorage, no cache-based identifier. § 25 TDDDG (and Art. 5(3) ePrivacy) governs storing or accessing information on terminal equipment and is therefore not triggered, so no consent is required. The legal basis for the remaining processing is Art. 6(1)(f) GDPR (legitimate interest in operating and improving this website).

We process: the page requested, the referring page, your browser's screen resolution and language setting, the time the page was actually visible to you, and — derived from your IP address — country and network operator (ASN). The IP address itself is not stored.

So that two requests in one session belong together, the server derives an identifier from a random value that is destroyed nightly at 00:00 UTC. After that point not even we can link today's visit to yesterday's. That costs us the count of unique visitors across several days, which is why we do not report it.

Objection: if your browser sends Do Not Track or the Global Privacy Control signal (Sec-GPC), we discard the report server-side before it is counted. Independently of that you can object permanently on our “Pulse privacy” page; this sets a cookie named skriza_pulse_optout that records nothing but your objection and, as a function you asked for, needs no consent under § 25(2) no. 2 TDDDG.

5. Disclosure of data

Your data is not shared with third parties for advertising or tracking. Where we use service providers (e.g. hosting), this is based on a data-processing agreement under Art. 28 GDPR. Those providers are located in the European Union; the sole exception is the content delivery network named in section 2, where connection data can be transferred to the USA and for which EU Standard Contractual Clauses are in place.

6. Your rights

Under the GDPR you have the following rights:

  • Access to the data stored about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17) and restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing (Art. 21)
  • Withdrawal of consent with effect for the future (Art. 7(3))

7. Right to complain

You have the right to lodge a complaint with a data-protection supervisory authority — in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).

8. Encryption

For security this website uses TLS/SSL encryption, recognisable by “https://” in your browser's address bar.

9. Bot protection (Skriza Shield)

To protect against automated access, spam and abuse we use our own bot-protection system, “Skriza Shield” — no Google, no cookies, no cross-site tracking. Shield guards the beta application, registration, sign-in and the appeal page in particular. The full description lives in the separate Skriza Shield privacy notice at skriza.com/shield-privacy; this section summarises the part that applies to skriza.com.

Nothing on your device: Shield stores no information on your terminal equipment and reads nothing stored there — no cookie, no localStorage, no sessionStorage, no cache-based identifier. § 25(1) TDDDG is therefore not engaged and Shield needs no consent. Verifiable in the storage tab of your developer tools (detail: shield-privacy#geraetespeicher).

In the browser we evaluate characteristics typical of automated browsers — each reduced to a boolean or a small rounded number in the browser itself, so that the exact graphics renderer name, for example, never leaves the device. No recognisable device fingerprint is produced: no canvas image, no font hashing, no renderer string (detail: shield-privacy#browser-signale).

Server-side we process: your IP address only as a non-reversible HMAC hash (the key for short-lived abuse and block counters; the plaintext IP is not stored), country and network operator (ASN) derived from it, counters over checks and failures, and — only during an interactive challenge — anonymous motion samples (the time and angle of a rotation). Those samples serve only the immediate “human or bot” decision and are discarded afterwards; they are not linked to a profile (detail: shield-privacy#server-daten).

Automated decision and blocks: the risk score decides whether you are allowed through, asked for an interactive challenge, or blocked for a limited time. A block affects only the protected endpoint — not your account and no contract — expires by itself when its window elapses, and never rests on special categories of data under Art. 9 GDPR. Recital 71 GDPR names fraud prevention explicitly but requires safeguards: every block states a reason and points to the appeal page, where a person reviews the decision and can reverse it. This keeps open the route to human intervention and to contesting the decision under Art. 22(3) GDPR (detail: shield-privacy#automatisierte-entscheidung).

If your access was temporarily blocked, you can verify you're human via an appeal page. You may optionally provide an email address; we assess its trustworthiness by domain (e.g. established provider vs. disposable address) and store the request for manual review. We use the email address solely to handle this unblock request; the appeal works without one, but then we cannot tell you the outcome.

The legal basis is our legitimate interest in the security, integrity and availability of our systems and in preventing fraud and abuse (Art. 6(1)(f) GDPR; see Recitals 47 and 49 GDPR, under which preventing abuse and ensuring network and information security constitute a legitimate interest).

Abuse and block data (hashed IP, counters) are kept only briefly and deleted automatically — minutes to hours depending on purpose, the cross-site reputation counter in a rolling 24-hour window, and aggregate non-personal statistics counters for at most around 90 days. Appeal records with an email address are kept only as long as necessary for the review and for evidentiary and security purposes. You have, in particular, the right to object to this processing (Art. 21 GDPR).

Processing takes place on servers within the European Union. There is no third-country transfer.

9a. Moderation and its record

Reported content and incidents in live rooms are reviewed by people. Every measure is logged: who took it, what it relates to, which measure it was and on what grounds. Without that record the statement-of-reasons duty in Art. 17 DSA, the complaint procedure in Art. 20 DSA and the reporting duty in Art. 24 DSA could not be met — a decision that leaves no entry did not happen as far as a regulator is concerned.

In live rooms the host and moderation can intervene: withdraw the right to publish, remove someone from the room, or — moderation only — end a broadcast. Withdrawing the right to publish does not disconnect anyone; it stops what is being sent.

If we decide something against you, you are told. When a profile picture is rejected, a chat message hidden, or your right to publish in a room withdrawn, you get a notification with the reason, with whether automated means were involved, and with what the measure rests on. Art. 17 DSA requires this — and without it moderation feels arbitrary even when it is not. Our automatic picture check is automated *detection*; a person made the decision in every case, and the notification says so.

Messages in stream chat are hidden by a moderation decision rather than deleted outright. That is deliberate: a hard delete destroys the evidence for the report that led to the removal, and an appeal would then have nothing left to assess. The message is no longer served.

The legal basis is compliance with our obligations under the Digital Services Act (Art. 6(1)(c) GDPR) and our legitimate interest in workable moderation (Art. 6(1)(f) GDPR).

Retention: pictures held for review and their check result are deleted 90 days after the case is closed. A case that was never decided expires by itself after 180 days — “not reviewed yet” is no reason to keep a picture of a person indefinitely. The record of measures is kept for two years; it contains no content, only who took which measure when and on what grounds, and it is the basis for the reporting duty in Art. 24 DSA. A job running daily enforces these periods.

Exception: where official or court proceedings are under way, an account can be placed under a legal hold. While one is in place none of the automatic deletions apply — and the account cannot delete itself either. That is the conflict between the right to erasure (Art. 17 GDPR) and the duty not to destroy evidence in live proceedings; we resolve it in favour of the proceedings and name it here rather than leaving it unsaid.

10. Updates

The current version published on this website applies. As Skriza develops and opens to users, this policy will be updated.