Privacy policy
Last updated: September 2026
This privacy policy applies to the FeedblickSwarm web application.
This privacy policy describes what data FeedblickSwarm processes and how, drafted in good faith based on the features currently in use. It is not a substitute for legal review — please have it checked by a lawyer or data protection officer before relying on it.
Controller
The controller within the meaning of the GDPR is:
- Name:
- Dr. Sergio Vargas - biodatum.io
- Address:
- Nadistr. 06, Muenchen
- Email:
- info@biodatum.io
Full details (incl. tax number / VAT ID) are on the Impressum.
Hosting and server logs
FeedblickSwarm uses Supabase for its database, authentication, and realtime updates, and Vercel Inc. to host and serve the web application itself. Visiting the site automatically causes technical information (e.g. IP address, time of access, browser used, and request metadata in server logs) to be processed by these providers' infrastructure. This is technically necessary to deliver the website and ensure server stability (Art. 6(1)(f) GDPR). Vercel's Frankfurt region (eu-central-1) is used for hosting, and Supabase's EU region (AWS eu-central-1, Frankfurt) for the database, so this data stays within the EU — see the Sub-processors section below.
Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you (Art. 15)
- Have inaccurate data corrected (Art. 16)
- Have your data deleted (Art. 17)
- Request restriction of processing (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing (Art. 21)
- Lodge a complaint with a supervisory authority (Art. 77)
Requesting access
Before you have an account, submitting the "Request access" form stores the name, email address, and team name you provide, so we can review and respond to your request (Art. 6(1)(b) GDPR, a pre-contractual measure). If approved, this becomes the basis for your account invite; if not, you may ask us to delete the record. The form also asks you to confirm that you act in a business capacity and accept the terms (AGB); we store the time of that confirmation and the version of the terms you accepted, as proof of the contract terms (Art. 6(1)(b) and (f) GDPR). The form is protected against automated abuse by Cloudflare Turnstile — see "Request form protection" below.
Host accounts
A host account is created once an access request is approved — we send an invite email with a link to set your password. This stores your email address and an encrypted password (Art. 6(1)(b) GDPR, to perform the contract of use). Emails such as the invitation and password reset are sent through our authentication provider (Supabase).
Participants joining a session
Anyone joining a session via a join code doesn't need an account and never signs in. The name they type, their chosen group, and their Done/Stuck/Need-2-min signal are never written to our database at all — they exist only in a live, temporary realtime channel for the duration of the session, and are discarded the moment that channel closes (the host ending the session, or everyone disconnecting). It's each participant's own responsibility not to type personal data into the name field beyond what they're comfortable sharing with the session.
To keep the host's progress chart complete even if the host's own screen was off for a while, each participant's browser briefly notes how many tasks were open and closed at the end of every focus round and, when the host's browser asks for them, sends those numbers to it over the same live channel. The numbers contain no names or other personal data and are not stored on our servers.
Paid plans and payments (Stripe)
If a host subscribes to the Pro plan, the payment is handled by Stripe on its own page: the name, email address, billing address and — if entered — company name and VAT ID the host provides there, and the payment method. We never see card numbers. On our side we store only a Stripe customer ID, the subscription ID and status, the plan, and the end date of a scheduled cancellation, linked to the host account (Art. 6(1)(b) GDPR, to perform the subscription contract; Art. 6(1)(c) GDPR for the accounting and tax records we are required to keep). Invoices and payment records are kept, by Stripe and by us, for the statutory retention periods even after an account is deleted.
Request form protection (Cloudflare Turnstile)
The "Request access" form is protected against automated abuse by Cloudflare Turnstile. When you open that form, your browser loads a script from Cloudflare, and Cloudflare processes technical data (such as your IP address and browser information) to check that the request comes from a person (Art. 6(1)(f) GDPR, our legitimate interest in protecting the form against abuse). This happens only on that form, not elsewhere on the site.
Local storage (no tracking)
The following is stored only in your browser, not on our servers (except the session token, needed for authentication):
- feedblick-theme — Light/dark theme preference
- feedblick-pomodoro-name-<session code> — Your typed name, remembered per session you've joined (this browser tab only)
- feedblick-pomodoro-ticks-<session code> — The tasks you have ticked off on your own device in a session (this browser tab only)
- feedblick-pomodoro-boundaries-<session code> — The numbers of open and closed tasks your browser noted when a focus round ended, so the host can complete its progress chart (no personal data; this browser tab only)
- sb-*-auth-token — Login session token (signed-in hosts only)
None of this is used for tracking or behavioral analysis. In our assessment, this storage is technically necessary to provide a feature the user explicitly requested and is therefore exempt from consent under §25(2) TTDSG — please have this assessment checked if in doubt.
Sub-processors
We use the following service providers as processors: Supabase, Inc. (hosting, database, authentication, realtime), Vercel Inc. (hosting and serving the web application itself), Stripe (payments for the Pro plan) and Cloudflare, Inc. (protection of the request form). A data processing agreement under Art. 28 GDPR is in place (or being put in place) with each of them.
Retention
Personal data is deleted once the purpose of processing no longer applies, or on request, unless a legal retention obligation applies. Hosts can delete their account and every session they own at any time via Account → Delete account (which also cancels a running Pro subscription), or request deletion by email. Payment and invoice records are kept for the statutory retention period.
Contact for privacy questions
For any privacy questions, please contact: info@biodatum.io
Changes to this policy
This privacy policy is updated as needed, e.g. for new features or changes in the law. The version currently published on this page always applies.