Privacy policy
What FLEXR does with your data — and what it does not do
Version 2026-08-19 · last updated: 19 August 2026
This is a translation provided for convenience. The German version is the legally binding one; if the two differ, the German wording prevails. That matters in particular for the consent under point 4, which is given in relation to the German version.
In one sentence. FLEXR processes the details you enter yourself, plus what necessarily arises from using it (swipes, messages, subscription status). There is no tracking, no ad networks, no analytics tools and no disclosure for advertising purposes. Your photos are held by a storage service, payment runs through Stripe, the server is located in Germany and transactional emails are sent by Brevo.
1. Controller
Julian Pachernegg
Sole trader, operator of FLEXR
Johann-Schrey-Weg 260, 8232 Grafendorf, Austria
Email: flexr.social@proton.me
No data protection officer has been appointed; in our assessment the statutory requirements of Art. 37 GDPR are not met. Data protection enquiries are handled by the controller personally at the address given above.
2. What data we process
The following table reflects what the code actually stores — no more and no less.
| Category | Specifically | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Login data | Email address, password as a bcrypt hash (never in plain text) | Registration | Account, sign-in, contacting you | Art. 6(1)(b) |
| Profile data | Name, date of birth, postal code, town derived from it, gym, search radius, bio | Registration, profile editing | Displaying the profile, radius search | Art. 6(1)(b) |
| Preference data (Art. 9 GDPR) | Gender and gender sought — sexual orientation can be inferred from these | Registration | Matching | Art. 9(2)(a) (explicit consent), see point 4 |
| Profile photos | Image files and square thumbnails, approval status, reason for rejection from a fixed list | Upload by you, moderation decision | Displaying the profile, moderation | Art. 6(1)(b) and (f) |
| Verification selfie | An image taken live with the camera | Taken by you | Age and identity check | Art. 6(1)(f), see point 5 |
| ID capture | Image of an official photo ID, document type | Upload by you | Age and identity check | Art. 6(1)(f), see point 5 |
| Check result | Status, reason from a fixed list, timestamps, reviewer identifier, review method (“manual_id”) | Manual review | Evidence of the age check | Art. 6(1)(f) |
| Email confirmation | Time of confirmation; an outstanding token only as a hash, with an expiry time | Activation link | Making sure the address belongs to you | Art. 6(1)(b) and (f) |
| Device ID | A random identifier generated in the browser or the app, plus the user agent | Client at registration and sign-in | Detecting multiple accounts, preventing a block from being evaded | Art. 6(1)(f) |
| Registration attempts under 18 | Only a random device ID and the time — no name, no email, no date of birth | Registration form | Preventing the age limit from being tried out repeatedly | Art. 6(1)(c) and (f) |
| Usage data | Swipes (like/pass), matches, blocks, time of last activity | Use of the app | Matching, online status, safety | Art. 6(1)(b) and (f) |
| Chat messages | Content, sender, timestamp, time read. In addition the version sanitised for the recipient, where links or email addresses were removed | Use of the chat | Delivery, protection against phishing and scams | Art. 6(1)(b) and (f) |
| Moderation flags | Flagging of conspicuous messages together with the reason (such as a detected scam term or link) | Automated filter | Abuse prevention | Art. 6(1)(f), Art. 16 DSA |
| Reports | Who reported whom and on what grounds, reference number, decision and statement of reasons | Reporting function, reporting form | Notice and action procedure under Art. 16 DSA | Art. 6(1)(c) and (f) |
| Moderation decisions | Measure, scope, duration, underlying facts, what prompted it, involvement of automated means, basis | Decision by moderation | Obligation to state reasons under Art. 17 DSA | Art. 6(1)(c) and (f) |
| Payment data | Subscription status, Stripe customer ID, Stripe subscription ID. No card or bank details held by us | Stripe checkout | Handling FLEXR Premium | Art. 6(1)(b), for retention (c) |
| Consent records | Type of consent, version of the text, time, and where applicable the time of withdrawal — without an IP address | Registration, account settings | Obligation to demonstrate consent under Art. 7(1) | Art. 6(1)(c) |
| Withdrawal statements | Name, email, contract reference, wording of the statement, date and time | Online withdrawal function | Handling and evidence under Section 13a FAGG | Art. 6(1)(b) and (c) |
| Access statistics | One entry per account, day and country code. No IP address; the country code is always “AT” | Signed-in use | Operational statistics (daily active users) | Art. 6(1)(f) |
| Server logs | IP address, timestamp, requested path, user agent — at system level on the web server, without any link to an account | Automatically on access | Operation and defence against attacks | Art. 6(1)(f) |
3. What we expressly do not do
- No location data. Neither the browser nor the app asks for a device location. The radius search works solely with the public address of the gym you select yourself and your search radius.
- No cookies for analytics or advertising. We set no cookies at all. Your sign-in token is held in your browser’s local storage (localStorage) and is only ever sent to our own server. That is why there is no consent banner — there would be nothing to consent to.
- No tracking, no analytics tools, no ad networks, no profiling for advertising purposes.
- No external fonts, images or CDNs. Everything this page loads comes from flexr.social — the fonts included. There are no third-party images.
- No automated decision-making within the meaning of Art. 22 GDPR. Every photo approval, every age and identity check and every measure against an account is decided by a human.
- No sale of your data and no disclosure for advertising purposes. Which service providers receive data in order to provide FLEXR is set out in full in point 6.
4. Sexual orientation — the special category
Sexual orientation can be inferred from your gender and the gender you are looking for. That is a special category of personal data under Art. 9(1) GDPR. We process it exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which is requested separately and on its own at registration — not together with the terms and conditions and not mixed in with any other declaration.
What we store about it. The type of consent, the version of the privacy policy you consented to, and the time. Deliberately no IP address: it is not necessary for the evidence required by Art. 7(1).
Withdrawal. You can withdraw your consent at any time with effect for the future — in the account area under “Consents”, with one click. It must not be harder than giving consent (Art. 7(3)), and it is not.
What withdrawal does — honestly. Gender and gender sought are the basis of matching. Without them we can no longer suggest anyone to you and you appear in no deck. Your account continues to exist, but the dating function is empty. If you want to be rid of the details altogether, delete the account — they are then deleted with it.
For context: consent is a precondition for matching to work at all — to that extent the choice is in practice a narrow one. We therefore do not present it as a freely revocable side issue but say precisely what its absence means.
5. Age and identity check
What is checked. Before an account is activated, we check once whether you are at least 18 years old and whether the verification belongs to your profile. For this we process the verification selfie, a temporary image of an official photo ID, the date of birth you stated and the check status.
Not a biometric procedure. A human compares the profile picture, the selfie and the ID photo by visual comparison and cross-checks the date of birth. No automated facial recognition is used, no facial features are computed, stored or compared, no text recognition is applied to the document, and the machine-readable zone is not read out. No external identification service provider is involved. No biometric data within the meaning of Art. 9(1) GDPR arises.
Data minimisation. Only what is needed for the check is required: the photograph, the date of birth and the document type. You may black out details on the document that are not needed before uploading it. The document number and the rest of the document content are neither read out nor stored, and no additional copy of the date of birth is created from the ID. The reverse side of the document is not requested.
Access and storage location. The ID captures are held in a separate, non-publicly accessible area of the object storage. They are given no public address; for the check, only links valid for 60 seconds are generated, and these are shown only to signed-in reviewers.
Legal basis. FLEXR is aimed exclusively at adults. Our legitimate interest is in keeping minors away from the service, making impersonation harder and ensuring the safety of the platform (Art. 6(1)(f) GDPR). Set against that are the short storage period, the purely manual visual check, the option to black out ID details that are not needed, and immediate deletion after the decision. The check is a precondition for using FLEXR — which is why we do not base it on consent.
Cancelling. You can withdraw images that have not yet been reviewed in the app; they are then deleted immediately. Without a completed check the account is not activated.
6. Recipients
| Service | What for | Seat and transfer |
|---|---|---|
| Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany | Server operation (virtual server), database | Germany / EU |
| Cloudflare (Cloudflare, Inc. or Cloudflare Germany GmbH) | R2 object storage: profile photos; temporarily the verification selfie and the ID capture | Cloudflare is a provider seated in the USA. A transfer to the USA cannot be ruled out. See the note below. |
| Stripe | Payment processing, subscription management, invoices | Stripe entities in Ireland and the USA. See the note below. |
| Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) | Sending confirmation, withdrawal and report emails | France / EU |
Processors and third-country transfers
For R2, Cloudflare distinguishes between a mere “location hint” and a true EU jurisdiction. For as long as our configuration has not been switched to a true EU jurisdiction, a transfer to a third country cannot be ruled out. Contabo, Cloudflare and Brevo process data for the purposes named here as service providers. Stripe processes payment data in part under its own data protection responsibility, in particular for payment processing, fraud prevention and compliance with legal obligations.
In so far as data is transferred to the USA or another third country, the providers rely on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) and, where certified, on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). On request we will tell you which mechanism applies to the service in question.
Beyond that we only disclose data where we are legally obliged to do so or where it is necessary for the prosecution of criminal offences — the procedure for that is set out in the law enforcement guidelines.
7. How long we store data
Blanket statements such as “everything is deleted 30 days after the account is deleted” would be wrong: payment-related records are subject to longer statutory periods, and an official preservation request halts deletion. Hence the table.
| Category | Retention | What triggers it |
|---|---|---|
| Account and profile data | until you delete it, then a 30-day grace period | Self-deletion in the account area |
| Profile photos and thumbnails | with the account, at the latest 30 days after deletion; individually deleted photos immediately | Deletion of the photo or the account |
| Verification selfie | immediately after the review decision; on account deletion immediately, without waiting for the grace period | Reviewer’s decision or account deletion |
| ID capture | immediately after the review decision; images never submitted after 14 days at the latest | Reviewer’s decision or expiry of the period |
| Check result (status, reason, timestamps) | with the account | Account deletion |
| Chat messages, matches, swipes, blocks | with the account | Account deletion |
| Reports and moderation decisions | with the account of the person involved | Account deletion |
| Device ID and user agent | with the account | Account deletion |
| Registration attempts under 18 | only the last 24 hours are evaluated | Lapse of time |
| Stripe identifiers and subscription status | payment-related records 7 years (Section 132 BAO); the identifiers themselves with the account | Statutory retention period |
| Withdrawal statements (Section 13a FAGG) | 7 years as evidence of how the contract was handled | Statutory retention period |
| Consent records | for as long as the consent is effective, after that as evidence of withdrawal until the account is deleted | Account deletion |
| Reports via the public form | 7 years — they are not attached to any account and evidence compliance with Art. 16 DSA | Obligation to provide evidence |
| Server logs | short-lived at system level, without any link to an account | Rotation by the operating system |
Legal hold. If an authority preserves data (section 7 of the law enforcement guidelines) or a case under section 7 of the community guidelines arises, we exempt the data concerned from the automatic deletion routines until the reason for it has fallen away; a preservation initially lasts 90 days.
On “irrevocably deleted”. After the grace period the records and the associated files in the object storage are deleted and cannot be restored through the app. We do not, however, claim that at that moment every copy everywhere has disappeared: database backups and internal copies held by the storage service may persist for a short time until they are overwritten in the normal cycle. No accounts are restored from such backups.
8. Security
- Transmission exclusively over HTTPS.
- Passwords are stored only as a bcrypt hash, never in plain text. Tokens from confirmation links are likewise stored only as a hash.
- ID captures are held in a non-publicly accessible area and can only be reached via links valid for 60 seconds.
- Uploaded images are checked server-side for their actual format and size, not on the basis of what the client states.
- Rate limiting against password guessing.
- The administration area is separate from the user accounts and blocked for search engines.
There is no end-to-end encryption of chats. Messages are held in the database in readable form — otherwise reports could not be reviewed and protection against scams could not be implemented. Don’t write anything you would not also show a moderator.
9. Your rights
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21) and withdrawal of consent given, with effect for the future (Art. 7(3)).
Much of this can be done directly in the app without writing to us: editing profile data, deleting photos, viewing and withdrawing consents, deleting the account. For everything else, write to flexr.social@proton.me. We reply within one month; for complex requests the period may be extended by two months, and we will tell you if that happens.
So that we do not accidentally give data to the wrong person, we answer access and erasure requests relating to an account only if they come from the email address on file or you can otherwise be identified.
10. Right to lodge a complaint
You can lodge a complaint with a supervisory authority at any time, in particular with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.
11. Obligation to provide data
The details in point 2 (login, profile and preference data) and the age and identity check are necessary in order to use FLEXR. Without them no account can be created. The bio and any photos beyond the first one are optional.
12. Changes to this policy
We adapt this policy when the processing changes. The version published here at any given time is the one that applies; the version status is stated at the top. In the case of material changes we also inform you by email or in the app. Changes that concern a consent are obtained afresh — an old consent does not cover a new text.