SplivexSplivex

Privacy notice

What happens with your data on Splivex, in the order the GDPR asks for it. Every entry describes something the service actually does.

Last updated: 8 September 2026

1. Who is responsible

Controller under Art. 4 no. 7 GDPR:

Noah Maximilian Janko St. Veiterstraße 92 8046 Graz Austria

Email: splivex.support@gmail.com

2. What Splivex is

Splivex connects two people who hold opposite positions on a question for a video conversation of up to twenty minutes. Afterwards each person is asked once whether their view changed.

Understanding that shapes everything below: most of what is processed here is not a by-product of the service, it is the service. Positions are what matching works from; without them there is no opposite to find.

3. What is processed, why, and on what basis

Almost nothing here runs on consent. Account, positions, matching and the conversation itself are the service somebody signed up for — Art. 6(1)(b) GDPR, performance of a contract. Consent is needed for what is not part of the service, and that is listed separately in section 9.

DataPurposeLegal basisKept
Email address, passwordsign-in, confirmation, noticesArt. 6(1)(b)until deletion
Username, display name, bio, profile pictureprofile, being recognisable to the other personArt. 6(1)(b)until deletion
Date of birth, countryage check, 18 and overArt. 6(1)(b)until deletion
Positions on questionsmatching people who disagreeArt. 6(1)(b)until deletion
Conversations: question, participants, language, start, end, durationhistory, statistics, moderationArt. 6(1)(b)until deletion
Whether your view changedyour own statisticsArt. 6(1)(b)until deletion
Video and audiothe conversation itselfArt. 6(1)(b)not stored — see section 4
Still frame from a reportmoderation, protecting other usersArt. 6(1)(f)30 days after the case is closed
Reports: reason, description, who reported whommoderationArt. 6(1)(f)until deletion
Statements on questions, replies, markspublished to everybody who has answered that questionArt. 6(1)(b)until you delete it, or the account
Messages you send us through the feedback boxanswering you, and finding faultsArt. 6(1)(f)until dealt with
Follows, blocks, invitationsthe social side of the serviceArt. 6(1)(b)until deletion
Daily counters, queue entries, sessionslimits, matchingArt. 6(1)(b)minutes to one day, see section 7
Subscription: customer and subscription reference, statusbillingArt. 6(1)(b)as long as required by law
IP address and browser identification on admin accesssecurity of the administration areaArt. 6(1)(f)until revoked

Legitimate interests, spelled out

Two rows above rest on Art. 6(1)(f), and the interest has to be named rather than asserted.

Reports and the still frame: without a picture, moderation cannot decide a report about behaviour on camera — and without moderation the platform is unsafe for everyone else. The frame is a single image, captured in the reporting person’s browser at the moment they submit, and visible only to moderation.

Admin access records: if somebody gets into the administration area, every account on the platform is affected. Recording which account entered, from which address and which browser, is what makes that noticeable and reversible.

4. What you write on a question

Statements are published, and they stay until you remove them.

Everything else here happens between two people and is gone when the conversation ends. What you write on a question is different: it is shown to everybody who has answered that question, under your username, and it remains readable until you delete it or your account.

You can delete your own statements at any time, individually or by deleting the account. Moderation can remove one that breaks the house rules.

When somebody reports a statement, the text is copied into the report so that it can be reviewed even if it is deleted in the meantime. That copy is kept as long as the report is.

Reading requires a position of your own on that question, so the audience is limited to people who have answered it — but it is not a private space, and it is not encrypted. Write accordingly.

5. Video and audio

We do not record conversations.

Participants may record or stream one between themselves if both agree, and that agreement has to be given before it starts. Anything made that way is theirs, not ours — we neither hold it nor have access to it.

A conversation goes directly from one browser to the other. It does not pass through a server of ours, and it is stored nowhere.

About one connection in six cannot go direct — a company firewall, a restrictive mobile network. In that case a relay server forwards the data stream. It is encrypted between the two participants; the relay passes the packets on and cannot read them.

Camera and microphone are required to take part. You can switch either off during a conversation.

When public discussions are available

Two people can agree, before a conversation starts, to let others watch. Both have to choose it; a private conversation never becomes public afterwards.

A public conversation is relayed by a video server so that the audience can receive it. It is transmitted live and kept nowhere. Viewers can neither send video nor audio.

6. Who else receives data

These are processors under Art. 28 GDPR, acting on instructions. A data processing agreement has to be in place with each of them.

ServiceWhat it doesDataLocation
Supabasedatabase, sign-in, file storage, live signallingall account and usage data, profile pictures, report imageseu-central-1, Frankfurt
Vercelrunning the applicationall requests, including IP address and browser identificationfra1, Frankfurt
Cloudflareaddress lookup and relay for video connectionsIP addresses; the encrypted stream when relaying is neededworldwide
Resendsending emailsrecipient address, content of the messageUSA
Stripesubscription billingcustomer reference, payment details entered directly at StripeUSA

Card details never reach Splivex. Payment runs entirely on Stripe’s own pages.

Beyond these, nothing. Splivex uses no analytics service, no error tracking, no external fonts, no maps and no advertising network.

7. Transfers outside the EU

The database, the file storage and the application itself run in Frankfurt. Account data, profile pictures, statements and report images do not leave the EU in normal operation.

Three services can process data outside it, and each is named with what reaches it:

  • Cloudflare — IP addresses during connection setup, and the encrypted stream on the roughly one connection in six that cannot go direct. Cloudflare operates a worldwide network, so the relay used is whichever is nearest.
  • Resend (USA) — the recipient address and the content of emails we send you.
  • Stripe (USA) — only once a subscription exists: a customer reference. Card details are entered at Stripe and never reach us.

These transfers rest on the standard contractual clauses adopted by the European Commission, agreed as part of each provider’s data processing terms, and where the provider is certified, additionally on the EU-US Data Privacy Framework.

8. How long data is kept

Most data stays until the account is deleted. Some is removed automatically, and those periods run as scheduled jobs rather than as intentions:

DataRemoved after
Report images30 days after the case is closed
Trial accounts without registration7 days after last use
Viewer passes2 days
Queue entries, viewer entries, session recordsminutes to two hours
Rate limiting records1 day

Beyond that, statutory retention obligations apply to billing records — 7 years (§ 132 BAO).

9. Your rights

You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).

You can delete your account yourself at any time under Settings. That removes your profile, your positions, your conversation history and your reports. A running subscription is cancelled first.

For anything else, write to splivex.support@gmail.com.

Right to complain

You can complain to a supervisory authority, in Austria the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at.

10. Cookies and consent

Splivex sets two cookies, and neither of them is for tracking:

CookiePurposeDuration
Sign-in sessionkeeps you signed inuntil sign-out
splivex_devicerecognises a device for the administration area, so an unfamiliar sign-in there raises an alert. Stored as a hash2 years

Both are technically necessary, so no consent banner is required and none is shown. Splivex stores nothing in local storage.

What you did consent to

Before the trial mode and at registration, five points are confirmed individually: being 18 or over, this privacy notice, the use of camera and microphone, the terms of service, and how the trial works. The time of consent is recorded.

If something changes that requires agreement again, you are asked once the next time you open Splivex, with a summary of what changed.

11. Automated decisions

There are none in the sense of Art. 22 GDPR. Matching is a database query over the positions you gave: it looks for somebody who answered a question the other way, in your language, whom you have not just spoken to.

Splivex uses no AI to analyse, summarise or evaluate conversations. What you say is not processed, not transcribed and not scored.

12. Is providing data required

To use Splivex, yes. An account needs an email address, a username and a date of birth; a conversation needs camera and microphone. Without them the service cannot be provided. Nothing beyond that is required — display name, bio and profile picture are optional.

13. Changes to this notice

If Splivex changes in a way that affects this notice, it is updated beforehand. Where a change needs your agreement again, you are asked the next time you open Splivex rather than being told afterwards.