Skip to content
InFeeo
Login Join
InFeeo
Discover Creators Topics About Community guidelines Copyright Privacy Login Create account

Legal & Transparency

Legal Notice Privacy Terms Community Copyright Cookies Transparency About
InFeeoEffective July 27, 2026

Privacy Policy

Effective date: July 27, 2026 · version 2.2

1. Controller

Adnan S
78224 Singen
Germany
Privacy contact: boss@mailsdu.com

Data protection officer, where designated:
No data protection officer has been designated or published. Contact the privacy address above.

EU representative under Article 27 GDPR, where required:
Not applicable or not designated.

2. Scope and service description

This policy explains how InFeeo processes personal data when people visit the service, create an account, publish or view creative work, use social functions, exchange private messages, submit reports, install the PWA, use persistent sign-in, share links or contact the operator. The service is an independently operated creator network; the operator determines the purposes and means of the platform processing described here.

3. Data categories

Depending on use, the following data may be processed:

  • account data: username, email address, password hash, display name, account status, role and registration data
  • profile data: avatar, cover image, biography, website, interests, appearance preference and media-protection preference
  • public content: artwork, images, animated images, videos, captions, topics, comments and associated metadata
  • social and activity data: follows, followers, likes, views, search terms entered in the service, invitations, feed interactions and mention-notification status
  • private communication data: conversation participants, message text, send time and read status, plus administrator broadcast subject, body, recipient and reply-permission status
  • moderation and legal data: reports, notices, reasons, evidence, decisions, review notes, affected URLs and communication records
  • consent and compliance records: accepted Terms and Privacy versions, source, timestamp, IP address and browser identifier
  • security and technical data: IP address, timestamps, requested resource, browser or device information, session identifiers, persistent-login token identifiers, CSRF data, error logs and administrative audit records
  • upload and storage metadata: filename, MIME type, size, dimensions, checksum, storage node, object path and creation time
  • privacy-request data: request type, message, status, identity-verification information and response notes

Passwords and persistent-login validator secrets are not stored in plain text. Passwords are hashed; persistent validators are stored as one-way hashes.

4. Sources of data

Most data is supplied directly by the user or generated through use of the service. Technical data is generated by the browser, web server, database and configured storage nodes. Reporters, rights holders, authorities or other users may provide information about content or accounts. Public information may be consulted where necessary to verify a notice or legal claim.

5. Purposes and legal bases

Contract and pre-contractual steps — Article 6(1)(b) GDPR

Data is processed to register and authenticate accounts, maintain profiles, publish requested content, deliver media, provide feeds and search, enable follows, likes, comments, mention notifications and private conversations, deliver operational administrator broadcasts, keep user settings, process account deletion and provide the functions requested by members.

Legal obligations — Article 6(1)(c) GDPR

Data may be processed to comply with binding laws, court or authority orders, data-protection duties, Digital Services Act obligations, evidence and recordkeeping duties, tax or accounting obligations where applicable, and lawful requests concerning illegal content or rights infringements.

Legitimate interests — Article 6(1)(f) GDPR

The operator may process data to secure the service, prevent fraud and spam, investigate attacks, enforce rules, moderate content, defend legal claims, maintain backups, diagnose failures, measure basic service integrity without third-party tracking, and preserve a functional creator community. Relevant interests and the rights of affected persons are balanced in each context.

Consent — Article 6(1)(a) GDPR

Consent is used only where a feature legally requires it, for example if the operator later adds optional non-essential tracking or marketing. Consent can be withdrawn for the future without affecting earlier lawful processing. The standard installation does not include advertising or third-party analytics.

6. Public profiles, posts and search engines

Profiles, usernames, public posts, captions, topics, media, comments and interaction counts may be accessible without login. Public pages may be indexed, cached, quoted or linked by search engines and third parties. SEO endpoints may provide controlled image or video previews and structured metadata. Removing content from InFeeo does not automatically erase independent copies, screenshots, search-engine caches or third-party shares.

Users should not publish confidential information or special-category data such as health, political, religious, biometric or sexual-life information unless they intentionally choose public disclosure, possess all necessary rights and understand the consequences. The platform does not require such information.

6A. Private messages, administrator broadcasts and mention notifications

Private one-to-one messages are presented only to the participating accounts through the normal user interface and are excluded from public profiles, feeds, search engines, sitemaps and social previews. They are stored in the service database together with sender, recipient, timestamps and read status so the conversation can be delivered and synchronized. Administrators may also send a private operational message to all active accounts. Each recipient receives an individual read state, and the administrator decides whether recipients may reply to the sending administrator.

When a username is mentioned in a published post or comment, the service can create an account notification containing the mentioned account, the author, the source post or comment, the creation time and read status. Notifications do not make private information public; they point to the already published source content.

The standard installation does not provide end-to-end encryption. The operator and authorized technical personnel may be able to access message, broadcast and notification data where technically necessary for security, troubleshooting, legal obligations or handling a specific abuse report. Users should therefore not use private messages for passwords, payment credentials, highly sensitive records or other secrets.

7. Uploads and the storage cluster

Uploads may be stored locally on the main web server or on one or more administrator-configured remote storage servers. The priority and failover system can select another active node when the preferred server is unavailable or lacks capacity. The database stores the storage reference and technical metadata needed to retrieve or delete the file.

When remote storage is used, the browser may be redirected to a time-limited signed media URL. The remote server can then receive the viewer’s IP address, request time, browser headers, requested object and transfer information. Storage agents communicate with the main application through authenticated HTTPS requests. Server names, countries, processors and locations must be accurately listed here:

Strato Germany

The operator must ensure data-processing agreements under Article 28 GDPR where providers act as processors and must verify that every storage location and backup arrangement is included in the privacy documentation.

8. Hosting, email and other recipients

Main hosting provider:
Strato
https://starto.de

Personal data may be disclosed to hosting, storage, backup, email, maintenance and security providers only to the extent necessary for their tasks. Administrators with authorized access, professional advisers, courts, law-enforcement bodies, regulators and other authorities may receive data where legally justified. Content recipients receive data that users publish publicly.

9. International transfers

No transfer statement has been configured. The operator must disclose any processing outside the EEA and the safeguards used.

Where personal data is processed outside the European Economic Area, the operator must document the applicable adequacy decision, standard contractual clauses or another lawful transfer mechanism, assess supplementary safeguards where necessary and identify the affected providers and countries.

10. Authentication, cookies and local storage

The service uses a technically necessary session cookie for authentication state, CSRF protection and secure requests. A persistent sign-in cookie can keep a user signed in on the same device until logout or token revocation. It contains random token material rather than the password and is protected with HttpOnly, SameSite and, under HTTPS, Secure attributes.

The browser may store the selected Light, Dark or System appearance, PWA installation state, service-worker cache metadata and static application files. These functions are described on the Cookies & Local Storage page. The standard installation does not set advertising or cross-site tracking cookies.

11. PWA and offline cache

If PWA functionality is enabled, the browser can cache the application shell, icons, styles, scripts and offline page. The standard service worker is not intended to create a permanent offline archive of private account pages. Browser and operating-system cache behavior can vary, and users can remove cached data through browser or device settings.

12. Native sharing

Post and profile share buttons use the browser’s Web Share interface only after the user activates the button. The operating system or selected receiving app may then process the title and canonical URL under its own privacy rules. If native sharing is unavailable, the service attempts to copy the link to the local clipboard. The platform does not automatically transmit the user’s contacts or selected sharing destination.

13. Invitations and email

An invitation email address, optional message, sender account, expiry, delivery attempts and use status may be processed to create and deliver a single-use registration invitation. Email delivery providers may receive the recipient address and message content. Invitations expire according to the configured settings and may be retained longer where necessary to prevent abuse or document delivery.

14. Moderation, reports and legal notices

Reports and legal notices may contain reporter identity, contact data, IP address, browser identifier, target URL, allegations, evidence and correspondence. This data is processed to assess content, protect users and rights holders, comply with law, explain decisions where required and defend against abusive or unfounded claims. Information may be shared with the affected user, rights holder, competent authority or adviser where legally necessary, while unnecessary reporter details are withheld where possible.

Blocked-word checks can reject a new post or comment. If enabled by the administrator, a report threshold can automatically hide content pending review. Permanent account restrictions are not made solely by an AI system in the standard installation.

15. Feed ordering and profiling

Discover, Following and Popular feeds use publication time, follow relationships, followed topics, visibility status and interaction signals. This creates limited preference-based ordering but is not used for advertising or a decision producing legal or similarly significant effects. Available feed choices allow users to influence what they see.

16. Retention and deletion

The operator’s actual retention and backup-deletion schedule is:

[Add the actual retention and backup-deletion schedule in the Admin Panel]

In general, account and profile data is kept while the account exists; published content is kept until deletion, moderation or account removal; temporary files should be removed after processing; and security, acceptance, report, legal-notice and audit records may be retained where necessary for legal duties, abuse prevention or legal claims. Backups can retain deleted data until the applicable backup cycle expires. The operator must ensure that the stated schedule matches the real database, server, storage-node and backup configuration.

17. Data-subject rights

Subject to the legal conditions, individuals may request access, rectification, erasure, restriction, portability and objection, and may withdraw consent for the future. A machine-readable account export is available in the Privacy Center. Requests can be submitted there or to boss@mailsdu.com. The operator may request proportionate identity verification and may refuse or charge for manifestly unfounded or excessive requests as permitted by law.

The operator normally responds without undue delay and within one month. That period may be extended by up to two additional months where legally permitted because of complexity or volume; the requester must be informed of the extension and reasons.

18. Right to object

Where processing is based on legitimate interests, the data subject may object on grounds relating to their particular situation. Processing will stop unless the operator demonstrates compelling legitimate grounds that override the person’s interests, rights and freedoms, or the processing is required for legal claims. Direct marketing is not part of the standard installation; an objection to direct marketing would apply without balancing.

19. Complaint to a supervisory authority

A data subject may lodge a complaint with a competent supervisory authority, particularly in the Member State of habitual residence, workplace or the alleged infringement. The authority configured by the operator is:

The competent data protection supervisory authority at the controller’s registered office

20. Children and age requirements

The configured minimum age is 16. The operator must verify that this setting is suitable for the target audience and applicable national law. Where parental authorization is legally required, an account may be used only after valid authorization has been obtained. Child sexual abuse material, grooming, exploitation and sexualized depictions of minors are strictly prohibited and may be reported to competent authorities.

21. Security and personal-data breaches

Measures include password hashing, prepared database statements, CSRF protection, upload validation, access controls, encrypted storage credentials, HMAC-authenticated storage-agent requests, signed media URLs, checksums, audit records and token revocation. Security depends on correct HTTPS, server, database, email, backup and administrator configuration. No internet service can guarantee absolute security.

Where a personal-data breach occurs, the operator assesses risk and documents the incident. The competent authority and affected persons are notified where the GDPR thresholds are met.

22. No sale of personal data

The standard installation does not sell personal data and contains no advertising network or third-party behavioral tracking. If the operator changes this model or adds external services, the Privacy Policy and, where required, the consent mechanism must be updated before activation.

23. Changes to this policy

This policy is updated when functionality, processors, storage locations, retention, legal requirements or the business model changes. Material changes may require a new privacy version and renewed notice or acceptance. Previous acceptance records remain stored as evidence of the version presented at the time.

InFeeo — InFeeo is a visual social network for artists, photographers and digital creators to publish original art, photography, digital art, illustration, animation and short video clips, build a portfolio and discover independent creative work.
Creators Topics RSS Legal NoticePrivacyTermsCommunityCopyrightCookiesTransparencyAbout Report unlawful content

Install app

Add InFeeo to your Home Screen

Open the browser share menu and choose Add to Home Screen. The installed app opens in its own window.