denschCollabs IcondenschCollabs ← Back

Privacy Policy

Last updated: July 2026 – Version 1.5 · Deutsche Version (rechtlich maßgeblich)

This is an English convenience translation of our privacy policy. In case of discrepancies, the German version prevails.

No tracking. Just management.

denschCollabs is deliberately designed to be data-minimal. We:

  • do not use any tracking tools or analytics services
  • do not set any analytics or marketing cookies
  • do not build user profiles for advertising purposes
  • do not share personal data for advertising purposes
  • do not use third-party analytics such as Google Analytics or Meta Pixel

Our platform exists solely for the internal management of brand collaborations – from first inquiry to final invoice.

1. Controller

denschCollabs is a service provided by:

dasdensch.com
Dennis Schneider
Hannoversche Str. 11
37176 Nörten-Hardenberg
Germany

E-mail: datenschutz@dasdensch.com

2. Hosting

The website is hosted by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. As part of the hosting, STRATO processes personal data on our behalf. A data processing agreement pursuant to Art. 28 GDPR is in place.

3. Server log files

When the website is accessed, STRATO automatically collects server log files. These contain:

  • IP address
  • date and time of the request
  • browser type and operating system
  • referrer URL
  • page accessed

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).

4. Registration and user account

Using the platform requires a user account created by an administrator. The following data is processed:

  • username
  • e-mail address (optional)
  • password (stored exclusively as a bcrypt hash, never in plain text)
  • role (user or administrator)
  • account creation date and login activity

Purpose: authentication at login, access management for the platform.

Legal basis: Art. 6(1)(b) GDPR (performance of contract), Art. 6(1)(f) GDPR (legitimate interest in secure access).

5. Collaboration data processed

The core function of denschCollabs is recording and managing brand collaborations. The following data is stored in the course of use:

  • name of the collaboration partner (company or brand)
  • name and e-mail address of the contact person at the partner
  • type of product or service
  • agreed fee and external cost items
  • collaboration status and notes
  • agreed deliverables (e.g. platforms, quantities and dates)
  • uploaded files (contracts, briefings, other documents)

This data is entered and managed exclusively by the logged-in user. It is not shared with third parties and not used for any other purposes.

Legal basis: Art. 6(1)(b) GDPR (performance of contract), Art. 6(1)(f) GDPR (legitimate interest in managing one's own business relationships).

6. File uploads and attachments

Users can upload documents (e.g. contracts, briefings, invoices) to the server. The following applies:

  • Uploaded files are stored in the protected uploads/ directory on the server.
  • Access is restricted to authenticated users.
  • Files are not publicly indexed and not shared externally.

Note: Users are themselves responsible for the contents of uploaded files and for complying with data protection requirements towards the persons contained therein.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

7. Payment processing

For paid subscriptions, payment processing is handled by the payment service provider Stripe Payments Europe, Ltd., Dublin, Ireland. Payment data (e.g. card details) is processed exclusively by Stripe and is not stored on our servers. We only receive anonymised reference IDs for managing the contractual relationship. More information: stripe.com/privacy

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

8. Address autocomplete (Photon / komoot)

When creating or editing contacts, we offer autocomplete for company and address data. For this we use the Photon service, operated by komoot GmbH, Rheinsberger Str. 76/77, 10115 Berlin, Germany.

  • Photon is based on data from OpenStreetMap.
  • The servers are operated in the EU; no data is transferred to third countries.
  • Photon does not set cookies and does not track users.
  • The user's browser does not communicate directly with komoot. Requests are routed through our own server (denschcollabs.com) as a proxy. As a result, neither the user's IP address nor their browser fingerprint is transmitted to komoot — only the entered search text and the IP of our server.
  • Requests are processed solely to provide the autocomplete feature. Neither our server nor komoot stores the input permanently.

Autocomplete only becomes active when the user manually types text into the company or address field. Without input, no transmission takes place.

Availability / fallback: Photon is a free third-party service without an availability SLA. If Photon is unavailable, autocomplete is temporarily not offered. Contact entry remains fully usable manually in that case — all fields (company, address, postcode, city) can be filled in freely at any time. There is no automatic failover to another service and no caching of komoot responses.

More information: photon.komoot.io · komoot.com/privacy

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and error-free address entry).

9. OAuth integrations (YouTube, Instagram, TikTok, Twitch)

To display insights and performance data for content collaborations, users can connect their own social media accounts to denschCollabs via OAuth 2.0. Processing only takes place after active consent in the respective OAuth consent screen. The integration is optional – without a connection, the insights features of the respective platform are simply unavailable; all other features remain fully usable.

9.1 YouTube (Google API Services)

denschCollabs uses the following Google API Services:

  • YouTube Data API v3 (scope: youtube.readonly)
  • YouTube Analytics API (scope: yt-analytics.readonly)
  • YouTube Analytics API – Monetary (scope: yt-analytics-monetary.readonly)

Data retrieved: channel metadata (name, logo, subscriber count), video list, performance metrics of individual videos (views, watch time, impressions, CTR) and – if selected by the user – revenue data of individual videos. If the “minimum account age” option is enabled in a giveaway, the creation date of the YouTube channel of individual commenters is additionally retrieved via the YouTube Data API v3 to apply the filter rule; this value is not stored permanently.

Purpose: displaying this data in the logged-in user's own dashboard to evaluate the performance of collaboration videos.

Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.

Limited Use: denschCollabs' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Data is used exclusively for user-facing features within denschCollabs.
  • No sharing with third parties – except where strictly necessary for providing the service (e.g. hosting by STRATO within the EU) or required by law.
  • No use for advertising or ad personalisation.
  • No use for training AI or machine-learning models.
  • No sale of the data.
  • Staff access only for operating the service, troubleshooting, or complying with legal obligations – unless the user has explicitly consented.

Storage: Access and refresh tokens are stored in the database on the denschCollabs server (STRATO VPS, Germany). All transfers between browser, server and the Google API take place exclusively over TLS-encrypted connections (HTTPS). Database access is restricted to the server user (no external database connections allowed).

Cache mechanism: Retrieved API responses are stored with a cached_at timestamp in the youtube_api_cache table. On every read, the system checks this timestamp; entries older than 24 hours are ignored (cache miss → new API call) and automatically overwritten on the next write. In addition, a nightly cron job (tools/cache-cleanup.php, 03:30) permanently removes expired entries from the database.

Revocation: The user can disconnect at any time within denschCollabs (influencer detail or Settings → “Disconnect”). Alternatively via the Google account: myaccount.google.com/permissions. After disconnecting, stored tokens are deleted immediately and cached API data is removed within 24 hours.

Legal basis: Art. 6(1)(a) GDPR (explicit consent in the OAuth consent screen), Art. 6(1)(b) GDPR (performance of contract).

9.2 Instagram / Meta

For Instagram insights, denschCollabs uses the Instagram Graph API / Facebook Login for Business (operator: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland).

Data retrieved: Instagram business account ID, username, follower counts, reach, impressions and engagement statistics of individual posts of the user's own account.

Purpose: displaying these metrics in the logged-in user's own dashboard.

Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.

Revocation: within denschCollabs (“Disconnect” button) or directly via Facebook under Business Integrations.

Legal basis: Art. 6(1)(a) and (b) GDPR.

9.3 TikTok

For TikTok insights, denschCollabs uses the TikTok Login Kit and the TikTok Display API (operator: TikTok Technology Limited, 10 Earlsfort Terrace, Dublin 2, Ireland).

OAuth scopes used:

  • user.info.basic – open ID, avatar, display name of the connected account
  • user.info.profile – username, bio, profile link, verification status
  • user.info.stats – follower, following, likes and video counts
  • video.list – list of the user's own public videos including performance statistics

Data retrieved: open ID, username, display name, profile picture, video metadata and performance statistics (views, likes, comments, shares) of individual videos of the user's own account.

Purpose: displaying these metrics in the logged-in user's own dashboard.

Retrieval mode: If insights are enabled for an account, denschCollabs automatically retrieves updated performance data via the API once per day (approx. 04:50 UTC). This automatic retrieval replaces the manual refresh and takes place regardless of whether the user is logged in at that time.

Revocation: within denschCollabs (“Disconnect” button) or directly in the TikTok account under Settings → Privacy.

Legal basis: Art. 6(1)(a) and (b) GDPR.

Giveaway comments: Where the giveaway feature (see section 9.6) is used for TikTok posts, denschCollabs retrieves comments via the TikTok API (/v2/video/comment/list/). In doing so, data of commenters (open ID, display name, avatar URL, comment text) is processed. TikTok itself is not certified under the EU-US Data Privacy Framework; transfers to third countries (in particular the USA and China-based backend infrastructure) are based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

9.4 Twitch

For Twitch insights and the giveaway feature, denschCollabs uses the Twitch API (operator: Twitch Interactive, Inc., 350 Bush Street, 2nd Floor, San Francisco, CA 94104, USA – a subsidiary of Amazon.com, Inc.).

Data retrieved (influencer account): Twitch user ID, login name, display name, profile picture URL, broadcaster type, and follower and subscriber statistics of the user's own channel.

OAuth scopes used: user:read:email, chat:read, channel:read:subscriptions, moderator:read:followers. The chat:read scope allows denschCollabs to receive the live chat of the connected channel and evaluate it for the giveaway feature. The connection is optional and requires active authorisation in the Twitch OAuth dialog.

Anonymous chat reading (Twitch IRC): Where the giveaway feature is active, the chat of the connected channel can alternatively be read via an anonymous Twitch IRC connection (without a user token). Twitch permits this method under its developer policy. No account credentials of the influencer are transmitted. The chat contents and user identifiers processed correspond to the data listed in section 9.6.

Purpose: displaying channel metrics in the user's own dashboard and – if enabled by the user – operating the giveaway feature (keyword detection in live chat).

Third-country transfer: As Twitch Interactive, Inc. is based in the USA, data is transferred to the USA during the OAuth exchange and API requests. Twitch Interactive, as a subsidiary of Amazon.com, Inc., is certified under the EU-US Data Privacy Framework (DPF) (certificate available at dataprivacyframework.gov). Legal basis for the third-country transfer: Art. 45 GDPR in conjunction with the EU Commission's adequacy decision on the DPF of 10 July 2023. Where the DPF certificate does not apply in an individual case, the transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

Revocation: within denschCollabs via “Disconnect” or directly in the Twitch account under twitch.tv/settings/connections. After disconnecting, access and refresh tokens are deleted immediately.

Legal basis: Art. 6(1)(a) and (b) GDPR.

9.5 Common provisions

Only data from accounts that the logged-in user has personally authorised is retrieved. Access is limited to read-only scopes – denschCollabs cannot post, modify or delete any content. Connections can be disconnected at any time without restricting any other platform features.

9.6 Giveaway feature: processing of third-party chat messages and comments

The giveaway feature allows users (influencers) to run automated giveaways based on chat messages (Twitch live chat) or comments (Instagram, YouTube, TikTok).

Data of participants processed: When taking part in a giveaway, the following data of chat participants or commenters is processed:

  • platform-specific user ID (e.g. Twitch user ID, Instagram user ID)
  • login name and display name on the respective platform
  • original message or comment text
  • profile picture URL (where publicly accessible)
  • role status on the respective platform (e.g. moderator, VIP, follower, subscriber, broadcaster, founder)
  • subscription status and subscription tier on Twitch (tier 1/2/3), where publicly transmitted upon participation and relevant for giveaway weighting
  • timestamp of participation, detected match reason (JSON structures for internal evaluation)

For Instagram, YouTube and TikTok, comments are loaded via the platforms' respective APIs exclusively upon a manual retrieval triggered by the user (“Fetch comments now”). This is distinct from the daily automated insights retrieval (see sections 9.1–9.3), which concerns insights metrics (reach, followers, performance data) of the user's own account — third-party giveaway comments are not collected by the insights cron.

Who is affected: persons who actively take part in a giveaway by entering the giveaway keyword in chat or by posting a qualifying comment. This participation is deliberate and public on the respective platform.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest). The legitimate interest lies in running a giveaway organised by the respective influencer on behalf of our users. Participants act on their own initiative by actively entering a giveaway keyword or posting a comment. Processing is limited to what is necessary for evaluating the giveaway.

Information of data subjects (Art. 14 GDPR): As participants do not give consent directly to denschCollabs, they must be informed about the data processing pursuant to Art. 14 GDPR. This information is provided (a) via this privacy policy and (b) by the influencer, who is contractually obliged towards denschCollabs to inform their chat or community about the data processing before the giveaway starts.

OBS overlay and public winner display: After the draw is completed, the login name and display name of the winner(s) are shown in a token-protected OBS overlay (overlay-giveaway.php). This overlay is embedded into the livestream by the influencer; the winners' names are thus visible to the stream's viewers. This is based on the influencer's legitimate interest in a transparent, public draw (Art. 6(1)(f) GDPR). Winners are informed in advance through their participation in the public giveaway and the established practice of winner announcements (Art. 14 GDPR via the influencer's notice pursuant to § 6 of the Terms of Service).

Retention: Participation data is deleted 90 days after the giveaway ends. Winner data may be retained for up to 2 years (preservation of evidence in case of disputes). Deletion is automated.

Access and erasure: Data subjects can exercise their rights (Art. 15–17 GDPR) by e-mail to datenschutz@dasdensch.com. For identification, the platform username and the platform concerned must be provided.

10. AI-assisted extraction features (insights screenshots & business cards)

denschCollabs offers optional features where images are read out with the help of an AI service:

  • Insights screenshots: uploaded screenshots of platform statistics are analysed to automatically transfer the metrics they contain into form fields.
  • Business card scan: when creating or editing a contact, a photo of a business card can be read out to automatically fill name, company, position, contact and address details into the contact fields.

Services used / user's own API access: The analysis is performed via an AI provider configured by the respective user in the settings. Available options:

  • Google Gemini API – Google Ireland Limited / Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA (ai.google.dev/gemini-api/terms).
  • Anthropic Claude API – Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA (anthropic.com/legal/privacy).

The user's API key is stored encrypted (AES-256-CBC with a dedicated server key) in the database and can only be decrypted server-side. Without a configured key, no AI analysis takes place and nothing is transmitted to any AI provider.

Transmission path: The respective image is transmitted from the denschCollabs server (not directly from the user's browser) over a TLS-encrypted connection to the selected AI provider, read out there, and the recognised data is returned as structured text.

Image storage: Business card photos are not stored – they are processed transiently for extraction only and discarded immediately afterwards. Insights screenshots are stored on the denschCollabs server (STRATO VPS, Germany) until deleted by the user.

Third-party personal data (business cards): A business card typically contains personal data of a third person (name, position, phone number, e-mail address). The respective user is responsible for recording this data in their contact directory; denschCollabs processes it on their behalf. The alternative “paste text” input processes the card content exclusively locally in the browser and does not transmit any data to an AI provider.

Third-country transfer: Both providers are based in, or operate their processing infrastructure in, the USA; when the AI features are used, the transmitted images are transferred to the USA. Google LLC is certified under the EU-US Data Privacy Framework (DPF) (dataprivacyframework.gov); in this respect the legal basis for the transfer is Art. 45 GDPR in conjunction with the EU Commission's adequacy decision on the DPF. Where a provider is not certified under the DPF (which, in case of doubt, applies to Anthropic PBC), the transfer is based on standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

Use for training purposes: Under the providers' API terms, content submitted via paid API access is not used to train the AI models. When using free tiers (in particular Google AI Studio), submitted content may however be evaluated by the provider for product improvement and possibly reviewed by humans. Anyone having third-party personal data (e.g. business cards) read out by AI should therefore use paid API access with corresponding data protection commitments, or use the AI-free input (“paste text”).

Optional / manual trigger: The AI extraction features are triggered exclusively by an active user action (selecting a photo or screenshot). All fields can be filled in manually at any time; the feature is not required for using denschCollabs.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient and error-free data entry) and Art. 6(1)(b) GDPR in the context of contract performance.

11. Cookies

denschCollabs uses only technically necessary session cookies required for login and the secure operation of the platform. No tracking or marketing cookies are used.

Additionally, an optional cookie can be set for the “trust this device” feature:

  • Name: trusted_device
  • Purpose: skipping two-factor authentication on trusted devices
  • Duration: 14 days
  • Stored data: token hash (not traceable), browser/operating system, IP address, timestamp
  • Type: technically necessary (security feature, no consent required)
  • Management: trusted devices can be viewed and removed at any time in the account settings (max. 5 devices)

Legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR (legitimate interest in secure authentication).

A cookie banner is therefore not required.

12. Security measures

denschCollabs employs the following technical security measures:

  • passwords are stored exclusively as bcrypt hashes
  • CSRF token protection for all form-based actions
  • brute-force protection at login (5 failed attempts → 15-minute lockout)
  • secure session configuration (httponly, strict mode, ID regeneration)
  • SSL/TLS encryption of all data transfers
  • OAuth access tokens (YouTube, Instagram, TikTok, Twitch) and AI API keys (Google Gemini, Anthropic Claude) are stored encrypted in the database (AES-256-CBC with a dedicated server key). Decryption is only possible server-side.

13. Retention periods

  • User account data: until the account is deleted by an administrator, at the latest 30 days after the end of the contract
  • Business card photos: no storage – transient processing for extraction, discarded immediately afterwards
  • Collaboration data and attachments: until manually deleted by the user or after the end of the contract
  • Payment and invoicing data: 10 years pursuant to § 147 AO (German Fiscal Code)
  • Server log files: per STRATO AG's specifications (usually 7–14 days)
  • Twitch OAuth tokens: until the user disconnects; immediate deletion upon disconnect
  • Giveaway participation data (third parties): 90 days after the giveaway ends; winner data up to 2 years (comprising: user ID, login/display name, comment/chat text, platform status, subscription tier and retrieval metadata)
  • Statutory retention obligations remain unaffected in all cases.

14. SSL encryption

The website uses SSL/TLS encryption to protect transmitted content, recognisable by the lock symbol in the browser's address bar.

15. Rights of data subjects

You have the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection (Art. 21 GDPR)

You also have the right to lodge a complaint with the competent data protection supervisory authority. For Lower Saxony, this is the State Commissioner for Data Protection of Lower Saxony (LfD), Prinzenstraße 5, 30159 Hannover, Germany, www.lfd.niedersachsen.de.

For inquiries, please contact: datenschutz@dasdensch.com

© 2026 denschCollabs · dasdensch® – Registered EU trademark

Made with ♥ in Angerstein