Privacy policy

What FLEXR does with your data — and what it does not do

Version 2026-08-19 · last updated: 19 August 2026

This is a translation provided for convenience. The German version is the legally binding one; if the two differ, the German wording prevails. That matters in particular for the consent under point 4, which is given in relation to the German version.

In one sentence. FLEXR processes the details you enter yourself, plus what necessarily arises from using it (swipes, messages, subscription status). There is no tracking, no ad networks, no analytics tools and no disclosure for advertising purposes. Your photos are held by a storage service, payment runs through Stripe, the server is located in Germany and transactional emails are sent by Brevo.

1. Controller

Julian Pachernegg
Sole trader, operator of FLEXR
Johann-Schrey-Weg 260, 8232 Grafendorf, Austria
Email: flexr.social@proton.me

No data protection officer has been appointed; in our assessment the statutory requirements of Art. 37 GDPR are not met. Data protection enquiries are handled by the controller personally at the address given above.

2. What data we process

The following table reflects what the code actually stores — no more and no less.

CategorySpecificallySourcePurposeLegal basis
Login data Email address, password as a bcrypt hash (never in plain text) Registration Account, sign-in, contacting you Art. 6(1)(b)
Profile data Name, date of birth, postal code, town derived from it, gym, search radius, bio Registration, profile editing Displaying the profile, radius search Art. 6(1)(b)
Preference data (Art. 9 GDPR) Gender and gender sought — sexual orientation can be inferred from these Registration Matching Art. 9(2)(a) (explicit consent), see point 4
Profile photos Image files and square thumbnails, approval status, reason for rejection from a fixed list Upload by you, moderation decision Displaying the profile, moderation Art. 6(1)(b) and (f)
Verification selfie An image taken live with the camera Taken by you Age and identity check Art. 6(1)(f), see point 5
ID capture Image of an official photo ID, document type Upload by you Age and identity check Art. 6(1)(f), see point 5
Check result Status, reason from a fixed list, timestamps, reviewer identifier, review method (“manual_id”) Manual review Evidence of the age check Art. 6(1)(f)
Email confirmation Time of confirmation; an outstanding token only as a hash, with an expiry time Activation link Making sure the address belongs to you Art. 6(1)(b) and (f)
Device ID A random identifier generated in the browser or the app, plus the user agent Client at registration and sign-in Detecting multiple accounts, preventing a block from being evaded Art. 6(1)(f)
Registration attempts under 18 Only a random device ID and the time — no name, no email, no date of birth Registration form Preventing the age limit from being tried out repeatedly Art. 6(1)(c) and (f)
Usage data Swipes (like/pass), matches, blocks, time of last activity Use of the app Matching, online status, safety Art. 6(1)(b) and (f)
Chat messages Content, sender, timestamp, time read. In addition the version sanitised for the recipient, where links or email addresses were removed Use of the chat Delivery, protection against phishing and scams Art. 6(1)(b) and (f)
Moderation flags Flagging of conspicuous messages together with the reason (such as a detected scam term or link) Automated filter Abuse prevention Art. 6(1)(f), Art. 16 DSA
Reports Who reported whom and on what grounds, reference number, decision and statement of reasons Reporting function, reporting form Notice and action procedure under Art. 16 DSA Art. 6(1)(c) and (f)
Moderation decisions Measure, scope, duration, underlying facts, what prompted it, involvement of automated means, basis Decision by moderation Obligation to state reasons under Art. 17 DSA Art. 6(1)(c) and (f)
Payment data Subscription status, Stripe customer ID, Stripe subscription ID. No card or bank details held by us Stripe checkout Handling FLEXR Premium Art. 6(1)(b), for retention (c)
Consent records Type of consent, version of the text, time, and where applicable the time of withdrawal — without an IP address Registration, account settings Obligation to demonstrate consent under Art. 7(1) Art. 6(1)(c)
Withdrawal statements Name, email, contract reference, wording of the statement, date and time Online withdrawal function Handling and evidence under Section 13a FAGG Art. 6(1)(b) and (c)
Access statistics One entry per account, day and country code. No IP address; the country code is always “AT” Signed-in use Operational statistics (daily active users) Art. 6(1)(f)
Server logs IP address, timestamp, requested path, user agent — at system level on the web server, without any link to an account Automatically on access Operation and defence against attacks Art. 6(1)(f)

3. What we expressly do not do

4. Sexual orientation — the special category

Sexual orientation can be inferred from your gender and the gender you are looking for. That is a special category of personal data under Art. 9(1) GDPR. We process it exclusively on the basis of your explicit consent (Art. 9(2)(a) GDPR), which is requested separately and on its own at registration — not together with the terms and conditions and not mixed in with any other declaration.

What we store about it. The type of consent, the version of the privacy policy you consented to, and the time. Deliberately no IP address: it is not necessary for the evidence required by Art. 7(1).

Withdrawal. You can withdraw your consent at any time with effect for the future — in the account area under “Consents”, with one click. It must not be harder than giving consent (Art. 7(3)), and it is not.

What withdrawal does — honestly. Gender and gender sought are the basis of matching. Without them we can no longer suggest anyone to you and you appear in no deck. Your account continues to exist, but the dating function is empty. If you want to be rid of the details altogether, delete the account — they are then deleted with it.

For context: consent is a precondition for matching to work at all — to that extent the choice is in practice a narrow one. We therefore do not present it as a freely revocable side issue but say precisely what its absence means.

5. Age and identity check

What is checked. Before an account is activated, we check once whether you are at least 18 years old and whether the verification belongs to your profile. For this we process the verification selfie, a temporary image of an official photo ID, the date of birth you stated and the check status.

Not a biometric procedure. A human compares the profile picture, the selfie and the ID photo by visual comparison and cross-checks the date of birth. No automated facial recognition is used, no facial features are computed, stored or compared, no text recognition is applied to the document, and the machine-readable zone is not read out. No external identification service provider is involved. No biometric data within the meaning of Art. 9(1) GDPR arises.

Data minimisation. Only what is needed for the check is required: the photograph, the date of birth and the document type. You may black out details on the document that are not needed before uploading it. The document number and the rest of the document content are neither read out nor stored, and no additional copy of the date of birth is created from the ID. The reverse side of the document is not requested.

Access and storage location. The ID captures are held in a separate, non-publicly accessible area of the object storage. They are given no public address; for the check, only links valid for 60 seconds are generated, and these are shown only to signed-in reviewers.

Legal basis. FLEXR is aimed exclusively at adults. Our legitimate interest is in keeping minors away from the service, making impersonation harder and ensuring the safety of the platform (Art. 6(1)(f) GDPR). Set against that are the short storage period, the purely manual visual check, the option to black out ID details that are not needed, and immediate deletion after the decision. The check is a precondition for using FLEXR — which is why we do not base it on consent.

Cancelling. You can withdraw images that have not yet been reviewed in the app; they are then deleted immediately. Without a completed check the account is not activated.

6. Recipients

ServiceWhat forSeat and transfer
Contabo GmbH, Welfenstraße 22, 81541 Munich, Germany Server operation (virtual server), database Germany / EU
Cloudflare (Cloudflare, Inc. or Cloudflare Germany GmbH) R2 object storage: profile photos; temporarily the verification selfie and the ID capture Cloudflare is a provider seated in the USA. A transfer to the USA cannot be ruled out. See the note below.
Stripe Payment processing, subscription management, invoices Stripe entities in Ireland and the USA. See the note below.
Brevo (Sendinblue SAS, 7 rue de Madrid, 75008 Paris, France) Sending confirmation, withdrawal and report emails France / EU

Processors and third-country transfers

For R2, Cloudflare distinguishes between a mere “location hint” and a true EU jurisdiction. For as long as our configuration has not been switched to a true EU jurisdiction, a transfer to a third country cannot be ruled out. Contabo, Cloudflare and Brevo process data for the purposes named here as service providers. Stripe processes payment data in part under its own data protection responsibility, in particular for payment processing, fraud prevention and compliance with legal obligations.

In so far as data is transferred to the USA or another third country, the providers rely on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) and, where certified, on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR). On request we will tell you which mechanism applies to the service in question.

Beyond that we only disclose data where we are legally obliged to do so or where it is necessary for the prosecution of criminal offences — the procedure for that is set out in the law enforcement guidelines.

7. How long we store data

Blanket statements such as “everything is deleted 30 days after the account is deleted” would be wrong: payment-related records are subject to longer statutory periods, and an official preservation request halts deletion. Hence the table.

CategoryRetentionWhat triggers it
Account and profile datauntil you delete it, then a 30-day grace periodSelf-deletion in the account area
Profile photos and thumbnailswith the account, at the latest 30 days after deletion; individually deleted photos immediatelyDeletion of the photo or the account
Verification selfieimmediately after the review decision; on account deletion immediately, without waiting for the grace periodReviewer’s decision or account deletion
ID captureimmediately after the review decision; images never submitted after 14 days at the latestReviewer’s decision or expiry of the period
Check result (status, reason, timestamps)with the accountAccount deletion
Chat messages, matches, swipes, blockswith the accountAccount deletion
Reports and moderation decisionswith the account of the person involvedAccount deletion
Device ID and user agentwith the accountAccount deletion
Registration attempts under 18only the last 24 hours are evaluatedLapse of time
Stripe identifiers and subscription statuspayment-related records 7 years (Section 132 BAO); the identifiers themselves with the accountStatutory retention period
Withdrawal statements (Section 13a FAGG)7 years as evidence of how the contract was handledStatutory retention period
Consent recordsfor as long as the consent is effective, after that as evidence of withdrawal until the account is deletedAccount deletion
Reports via the public form7 years — they are not attached to any account and evidence compliance with Art. 16 DSAObligation to provide evidence
Server logsshort-lived at system level, without any link to an accountRotation by the operating system

Legal hold. If an authority preserves data (section 7 of the law enforcement guidelines) or a case under section 7 of the community guidelines arises, we exempt the data concerned from the automatic deletion routines until the reason for it has fallen away; a preservation initially lasts 90 days.

On “irrevocably deleted”. After the grace period the records and the associated files in the object storage are deleted and cannot be restored through the app. We do not, however, claim that at that moment every copy everywhere has disappeared: database backups and internal copies held by the storage service may persist for a short time until they are overwritten in the normal cycle. No accounts are restored from such backups.

8. Security

There is no end-to-end encryption of chats. Messages are held in the database in readable form — otherwise reports could not be reviewed and protection against scams could not be implemented. Don’t write anything you would not also show a moderator.

9. Your rights

You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interests (Art. 21) and withdrawal of consent given, with effect for the future (Art. 7(3)).

Much of this can be done directly in the app without writing to us: editing profile data, deleting photos, viewing and withdrawing consents, deleting the account. For everything else, write to flexr.social@proton.me. We reply within one month; for complex requests the period may be extended by two months, and we will tell you if that happens.

So that we do not accidentally give data to the wrong person, we answer access and erasure requests relating to an account only if they come from the email address on file or you can otherwise be identified.

10. Right to lodge a complaint

You can lodge a complaint with a supervisory authority at any time, in particular with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.

11. Obligation to provide data

The details in point 2 (login, profile and preference data) and the age and identity check are necessary in order to use FLEXR. Without them no account can be created. The bio and any photos beyond the first one are optional.

12. Changes to this policy

We adapt this policy when the processing changes. The version published here at any given time is the one that applies; the version status is stated at the top. In the case of material changes we also inform you by email or in the app. Changes that concern a consent are obtained afresh — an old consent does not cover a new text.