Privacy Policy
Last updated: 03.08.2026
Welcome to Offspace!
We are pleased that you are using our app and take the protection of your personal data very seriously. Below we inform you in detail about the type, scope and purpose of the processing of personal data in connection with Offspace. If you have any questions, you can contact us at any time at info@offspaceapp.com
11. Information about the collection of personal data and contact details of the controller
This privacy policy applies to the processing of your personal data by Featuring GmbH, Tal 44, 80331 Munich, Germany (Commercial Register Munich, HRB 287200) in connection with your use of the Offspace mobile application (hereinafter "App").
We have taken technical and organizational measures to ensure that the legal data protection regulations (in particular GDPR and BDSG) are complied with and your data is protected against loss, manipulation, unauthorized access or unauthorized disclosure.
"Personal data" is any information relating to an identified or identifiable natural person. "Processing" is any operation performed with or without the aid of automated procedures in connection with personal data (e.g. collection, storage, use, deletion).
The controller within the meaning of Art. 4 No. 7 GDPR is Featuring GmbH (contact details see 1.1). You can reach our data protection officer at info@offspaceapp.com or by post with the addition "Data Protection Officer".
The app and our backend servers use SSL/TLS encryption to protect the transmission of confidential data.
22. Legal basis for processing
We process your personal data based on the following legal grounds:
- •Art. 6(1)(b) GDPR – Contract fulfillment: Provision of the app and its core functions.
- •Art. 6(1)(a) GDPR – Consent: e.g. push notifications and location data.
- •Art. 6(1)(f) GDPR – Legitimate interest: Ensuring security, error analysis, product improvement.
- •Art. 6(1)(c) GDPR – Legal obligation: e.g. retention and disclosure obligations to authorities.
Interest balancing for Art. 6(1)(f) GDPR:
Our legitimate interests: Ensuring app security, quality assurance, fraud prevention, product improvement
Your interests: Data protection, privacy, control over your data
Balancing: Our interests prevail as they are essential for secure and functional app operation. You can object at any time (Art. 21 GDPR).
33. Storage duration
3.1 We store personal data only as long as necessary to achieve the respective purpose or legal retention periods exist.
3.2 If processing is based on your consent, it ends with your revocation, unless another legal basis applies.
3.3 If data is no longer required for the original purpose, it is regularly deleted or anonymized, unless its (temporary) further processing is necessary to fulfill legal obligations or to protect legitimate interests.
Concrete retention periods:
| Data Category | Purpose | Retention Period | Legal Basis |
|---|---|---|---|
| Log files (IP, Timestamp, User-Agent) | Security, Stability | 30 days | Art. 6(1)(f) GDPR |
| Account data (Name, Email, Profile) | Contract fulfillment | 6 months after account deletion | Art. 6(1)(b) GDPR |
| Thoughts, Messages, Likes | Platform operation | Anonymized after account deletion | Art. 6(1)(f) GDPR |
| Tax-relevant data | Legal obligation | 10 years | Art. 6(1)(c) GDPR |
44. What data do we process and for what purpose?
4.1 App download and technical basic data
When downloading the app from the store (Apple App Store / Google Play Store), certain basic data (including username, email, customer number, time of download, device and operating system information) is transmitted to the respective store operator. We have no influence on this. We only process this data to the extent necessary for download and installation. Legal basis: Art. 6(1)(b) GDPR (contract fulfillment).
When the app starts, we collect server-side log files (date & time of access, IP address shortened to the first 3 octets, operating system, app version, http status code, referrer URL). Processing is based on our legitimate interest in the stability, security and error analysis of the app (Art. 6(1)(f) GDPR). Interest balancing: Our interest in secure app operation outweighs your data protection interests, as the data is processed pseudonymized and time-limited. Log files are automatically deleted after 30 days, unless a security-relevant incident requires longer retention. You can object to the processing at any time (Art. 21 GDPR).
4.2 Registration and user account
To use Offspace, you must create a user account. For this we process:
Required information: First name, last name, email address
Login options:
- • Apple Sign-In (Apple ID)
- • Google Sign-In (Google account)
- • Email / Password
Profile picture can be changed at any time
Legal basis: Art. 6(1)(b) GDPR.
4.3 Content created by you
Offspace thrives on you sharing spontaneous posts ("Posts") and being able to react to posts from others (messages, likes). We store all content that you publish yourself. If you delete your account, your personal profile data is deleted; your posts and comments remain – without profile reference – basically preserved to not destroy the context of other chats, unless you request deletion (Art. 17 GDPR) or legal retention periods are opposed.
Legal basis: Art. 6(1)(b) GDPR (contract fulfillment) and Art. 6(1)(f) GDPR (legitimate interest in the ongoing operation of the platform).
4.4 Profile pictures and photo library
For your profile picture, you can allow the app to access selected photos. Choosing a picture is voluntary; you can revoke the permission at any time in the device settings. The legal basis is Art. 6(1)(a) GDPR.
4.5 Location data (optional)
If you enable the optional location feature, the app sends your current location to our backend and stores it in your non-public profile. It is used for distance-based suggestions and filters and is not shown to other users as an exact position.
Legal basis: Consent (Art. 6(1)(a) GDPR). You can withdraw permission at any time; Offspace then stops updating and removes the stored matching location.
4.6 Contact with us
For support requests (email, in-app form) we process your name, your email address and the content of the message exclusively to process your request (Art. 6(1)(f) GDPR; possibly Art. 6(1)(b) GDPR, if contract-related). After final clarification, the data is deleted, unless legal retention periods are opposed.
4.7 Push notifications
After consent (Art. 6(1)(a) GDPR) you receive push messages about new reactions or important information. Your device push tokens are stored server-side. You can deactivate push messages at any time in the app/system settings.
4.8 Technical operation (Firebase Services)
We use the following Firebase services for crash diagnostics and push notifications:
| Service | Provider | Purpose | Retention |
|---|---|---|---|
| Firebase Crashlytics | Google Ireland Ltd. | Crash reports and error diagnostics | According to the configured Firebase retention periods |
| Firebase Cloud Messaging | Google Ireland Ltd. | Push delivery | While the token is active or required for delivery |
Google Ireland Ltd. processes the necessary device, diagnostic and delivery data as our processor under an agreement pursuant to Art. 28 GDPR.
Crashlytics is used for technical error analysis. Cloud Messaging processes device push tokens to deliver enabled notifications.
4.9 AI-powered functions and profiling
Offspace uses Google Vertex AI to classify shared thoughts semantically and suggest suitable connections to other users. The Vertex AI models used are configured for processing in the EU.
Notice on profiling: Content and the semantic attributes derived from it are processed automatically for personalized suggestions. This is a core function of Offspace.
Data processed: Thoughts you share and profile data required for matching are processed semantically and linked to your account. Private chat messages are not analyzed for this matching.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest). You may object to the processing under Art. 21 GDPR. Because semantic matching is a core feature, an objection may limit the functions available; we assess your request individually.
Mandatory information on AI and profiling (Art. 13, 14, 22 GDPR):
Models used: Gemini models in Google Vertex AI, including Gemini Embedding for semantic vectors
Processor: Google Ireland Ltd.; Vertex AI processing is configured for the EU region
Processing logic: 1) Text analysis of your thoughts, 2) Creation of semantic vectors, 3) Similarity calculation with other users, 4) Ranking and suggestion of matching profiles
Type of automation: PROFILING (Art. 4 No. 4 GDPR) - YES. AUTOMATED DECISION-MAKING (Art. 22 GDPR) - NO, as no legal effects or significant impairments arise.
Interest balancing (Art. 6(1)(f) GDPR): Our legitimate interest in personalized recommendations outweighs your data protection interests because: 1) Profiling is core app function, 2) You consciously registered, 3) Data is processed pseudonymized, 4) You can object at any time.
Your specific rights: Objection to profiling (Art. 21(2) GDPR), Information about profiling logic (Art. 15(1)(h) GDPR), Deletion of profile data (Art. 17 GDPR), Restriction of processing (Art. 18 GDPR), Data portability of profile data (Art. 20 GDPR)
4.10 Chats (direct messages)
When you chat with other users via Offspace, messages are stored exclusively to enable communication (Art. 6(1)(b) GDPR).
If you delete the chat – or one of the participants cancels the connection – all messages in this chat are completely and irrevocably deleted for all participants.
Backups and server logs do not contain this content.
55. Hosting and infrastructure
We host our app services with Google Cloud and Firebase (Google Ireland Ltd.). Central backend and AI functions are configured for EU regions. Individual Firebase services may also process data outside the EU.
Third country transfer to the USA (Art. 44 ff. GDPR):
Notice: Your data may be transmitted to the USA. The following protective measures apply:
- EU-US Data Privacy Framework (EU Commission Adequacy Decision of 10.07.2023)
- EU Commission Standard Contractual Clauses (SCC 2021/914), where required
- Transport encryption and role-based access restrictions
Risks of US transfer: Despite protective measures, US authorities may access data under certain legal conditions. You can direct questions or an objection to info@offspaceapp.com.
66. Your rights as a data subject
- •Information (Art. 15 GDPR) – about your processed data
- •Rectification (Art. 16 GDPR) – correct incorrect data
- •Erasure (Art. 17 GDPR) – "right to be forgotten"
- •Restriction (Art. 18 GDPR) – blocking of processing
- •Data portability (Art. 20 GDPR) – structured output of your data
- •Objection (Art. 21 GDPR) – against processing based on legitimate interest
- •Withdrawal of consent (Art. 7(3) GDPR) – with effect for the future
- •Complaint (Art. 77 GDPR) – with a data protection supervisory authority. Responsible for us is the BayLDA, Promenade 18, 91522 Ansbach.
Biometric data:
Profile pictures are not used for biometric recognition (facial recognition). If we introduce biometric functions in the future, we will inform you in good time and obtain separate consent (Art. 9 GDPR).
Minors:
The app is exclusively intended for users aged 16 and over; we do not process data from persons under 16.
77. Contact and exercise of your rights
For all inquiries about your data subject rights, data protection questions or to exercise your rights, you can reach us at:
Email: info@offspaceapp.com
By post: Featuring GmbH, Tal 44, 80331 Munich, Germany
88. Changes to this privacy policy
Legal, technical or organizational changes may require an adjustment of this privacy policy. We will inform you in good time about significant changes in the app. Your continued use after the entry into force is considered consent. Otherwise, you can delete your account at any time.
Previous versions of this privacy policy are available upon request.