Privacy Policy

Last updated: July 2026 · Deutsche Version

1. Privacy at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you use the Offline app. Personal data means any information that can be used to identify you personally. Detailed information on data protection follows in the sections below.

What data do we collect?

We collect data that you actively provide when registering and using the app (e.g. profile details, interests), and data that is generated through your use of the app (e.g. event participation, chat messages, ratings).

What do we use your data for?

Your data is used to suggest personalised events, connect you with other users and provide app features. A subset is sent to OpenAI for AI-assisted event generation (see section 12).

2. Data controller

The controller within the meaning of the GDPR for data processing in the Offline app and on this website is:

Zest UG (haftungsbeschränkt)
Stadtplatz 39
84529 Tittmoning
Germany

Represented by: Justin Brandon Pratt, Managing Director
Commercial register: Amtsgericht Traunstein, HRB 35020

Phone: +49 1512 9786245
Email: info@offline-events.de

We have not appointed a separate data protection officer, as the statutory requirements for doing so are not met. For all data protection matters, please contact us at the email address above.

2a. Minimum age

The Offline app is intended exclusively for people aged 18 and over. We do not knowingly process data of minors. If we become aware that an account was created by a minor, we delete it along with the associated data.

3. Data collected in the app

Profile data

When you register and use the app we collect the following profile data:

  • First name
  • Age
  • Gender
  • City and neighbourhood
  • Interests and activity preferences
  • Profile picture
  • Friendships and follower relationships
  • Login data via Firebase Authentication (email address and password)

Event data

In connection with events we process the following data:

  • Event RSVPs (accepted/declined)
  • Post-event ratings (1 to 10 stars and an optional comment)
  • Ratings of other participants after events
  • Chat messages within events

Posts and feed

When you use the social feed we process:

  • Posts you create (text, images, videos)
  • Likes on other users' posts

Voice messages in chats

You can record and send voice messages in direct chats. The microphone permission is requested on first use. Recordings are transmitted encrypted to our Firebase Storage backend, accessible only to the participants of the respective chat, and deleted when you delete the chat or your account, or at the latest after 12 months of inactivity. We do not analyse or transcribe voice recordings.

Check-in and host programme

If you attend an event run by a host, you can check in on site using a rotating code. In doing so we process the time of the check-in and the coordinates reported by your device at that moment, and store both with the event concerned. We need this information to verify that the check-in actually took place at the venue and to prevent abuse of host compensation. We do not build a movement profile from it.

Checking in is voluntary. You can attend the event without checking in; it serves solely as proof that a meet-up actually took place.

If you act as a host yourself, we additionally process information about your events, the number of check-ins, the provisional and due amounts derived from them, and the status of your payout registration. Your identity, bank and tax details are collected solely by our payment service provider Stripe; we do not receive them. To determine whether a bonus arises and remains, we evaluate whether a person who joined through your event has remained active afterwards and whether they have also attended events run by other hosts.

Subscription and purchase data

Premium subscriptions and credit purchases are processed via the respective app store (Apple App Store, Google Play). We use RevenueCat, Inc. as a technical service provider to sync subscription state across devices and verify entitlements server-side. RevenueCat receives an anonymous user identifier (Firebase UID), purchase and subscription events, and the country of your app-store account. Neither we nor RevenueCat see credit card numbers or bank details. For more information: revenuecat.com/privacy.

Location data

With your explicit permission, we use your device's location (precise GPS) to suggest events near you, surface friends in your area and rank venues by distance. The location is read on the device only when you actively use a location-aware feature and is transmitted to our backend (Firestore) so we can match you to events in the right city. The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG for accessing information on your device. You can revoke the permission at any time in your device's system settings with effect for the future; the lawfulness of processing carried out before revocation remains unaffected. The app remains usable without location access; we then match you based on the home city you provided.

4. Legal bases for processing

We process personal data only where a legal basis under Art. 6 GDPR exists. In detail:

Performance of a contract (Art. 6(1)(b) GDPR)

  • Creating and managing your account, including authentication
  • Profile data, interests and activity preferences as the basis for event matching
  • Event invitations, RSVPs and the composition of groups
  • Chat messages, voice messages, posts, likes and ratings
  • Providing and syncing premium subscriptions and credit balances
  • Operating the host programme, including check-in, determining compensation and paying it out
  • AI-assisted event generation as a core feature of the app (see section 12)

Consent (Art. 6(1)(a) GDPR)

  • Access to your precise device location, additionally § 25(1) TDDDG
  • Personalised advertising in rewarded video ads (Google AdMob), collected via the Google User Messaging Platform
  • Push notifications, where your operating system requires permission for them

You can withdraw consent at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected.

Legitimate interest (Art. 6(1)(f) GDPR)

  • Analysis of aggregated usage data to improve matching quality and event suggestions
  • Use of anonymised example pairs to optimise our AI prompt (see section 12)
  • Ensuring IT security and detecting and preventing misuse, spam and automated access, including checking check-ins against faked meet-ups
  • Automated screening of uploaded images to keep the platform free of unlawful and harmful content

You may object to processing based on legitimate interest at any time (Art. 21 GDPR). We will then stop the processing unless we can demonstrate compelling legitimate grounds.

Legal obligation (Art. 6(1)(c) GDPR)

  • Compliance with commercial and tax retention obligations
  • Handling notices of illegal content and information requests under the Digital Services Act
  • Responding to legitimate requests from public authorities

5. Retention and deletion

As a rule, your data is stored for as long as you use the app. You can delete your account yourself at any time, in the app under Settings > Delete account or via offline-events.de/delete-account.

When you delete your account, we remove your personal data — including profile, posts, event participations, ratings, chat and voice messages — from our production systems without undue delay. Neither you nor we can restore it afterwards. Please note the following:

  • Technical backups: Our systems are backed up regularly. Deleted data may therefore still be contained in backups for a limited period of up to 30 days. These backups are not actively used; they are kept solely for restoration in the event of a failure and are subsequently overwritten.
  • Statutory retention obligations: Data subject to commercial or tax retention periods — in particular payment and accounting data of venue operators and hosts — is retained until the respective period expires (generally six to ten years under § 257 HGB and § 147 AO). During that period the data is restricted and processed solely to fulfil the legal obligation.
  • Content held by other users: Messages you sent in a group or direct chat may remain visible to the other participants who received them. In shared event contexts, purely statistical information that can no longer be linked to you remains.
  • Abuse prevention: Where an account was suspended for a violation, we may retain a minimal ban identifier to prevent circumvention of the suspension. The legal basis is Art. 6(1)(f) GDPR.

Voice messages are deleted after 12 months of inactivity at the latest. Once the relevant period expires, the data is deleted or anonymised.

6. Data sharing

We do not sell your data. We share it with third parties only in the following cases:

  • When required to provide app features (e.g. displaying first names and profile pictures to other event participants)
  • For AI-assisted event generation to OpenAI (see section 12)
  • To Google for using Firebase (authentication, data storage, push notifications) and to Google Cloud Vision for automated image moderation
  • To Google AdMob for serving rewarded video ads, where you voluntarily start such an ad (see section 10)
  • To RevenueCat (subscription receipt validation) and the respective app store (Google Play / Apple) for processing in-app purchases
  • To Stripe, Inc. for processing payouts exclusively for venue operators and hosts (commercial or compensated use); regular app users do not have any data shared with Stripe
  • Where a legal obligation requires disclosure, or where disclosure is necessary to establish, exercise or defend legal claims

Where these providers process data on our behalf and on our instructions, we have concluded data processing agreements with them under Art. 28 GDPR.

7. Transfers to third countries

Some of the services we use are based in the USA or process data there. Transfers to a third country take place only where the requirements of Art. 44 et seq. GDPR are met. In detail:

  • Google Ireland Limited (Firebase, AdMob, Cloud Vision): our contracting party is the Irish entity. Where data is forwarded to Google LLC in the USA, the transfer is based on Google LLC's certification under the EU-US Data Privacy Framework and, additionally, on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
  • OpenAI, L.L.C. (USA): transfer based on the EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.
  • RevenueCat, Inc. (USA): transfer based on the EU Standard Contractual Clauses; only a pseudonymous user identifier plus purchase and subscription events are transmitted.
  • Stripe, Inc. (USA): transfer based on the EU Standard Contractual Clauses, supplemented by certification under the EU-US Data Privacy Framework. Applies exclusively to venue operators and compensated hosts.
  • Netlify, Inc. (USA): hosting of this website, transfer based on the EU Standard Contractual Clauses.

Please note that, despite these safeguards, a residual risk remains: under certain conditions US authorities may access data, and the legal remedies available to data subjects do not in every respect match the European level of protection. We will provide a copy of the relevant safeguards on request at info@offline-events.de.

8. Your rights

You have the right at any time to:

  • Access: Request information about the data we hold about you
  • Rectification: Request the correction of inaccurate data
  • Erasure: Request deletion of your data — in the app at any time via Settings > Delete account
  • Restriction: Request restriction of processing
  • Objection: Object to processing, in particular where it is based on legitimate interest
  • Data portability: Receive your data in a common, machine-readable format
  • Withdraw consent: Withdraw any consent given, with effect for the future

To exercise these rights please contact us at: info@offline-events.de. We handle your request free of charge and generally within one month of receipt.

9. Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority about our processing of your personal data.

Supervisory authority competent for us:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach, Germany
Website: www.lda.bayern.de

You may also contact the supervisory authority of your habitual residence or place of work.

10. Advertising (Google AdMob)

Rewarded video ads in the app

In the app you can voluntarily watch short video ads in order to receive something in return within the app (so-called rewarded ads). These ads are served via Google AdMob, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. AdMob may process device identifiers (e.g. your device's advertising ID), IP address and usage data in order to serve the ad, measure its performance and detect fraud.

An ad is only loaded if you actively start it. We do not currently use fixed banner ads or embedded ad placements in the app.

The legal basis for personalised advertising and for accessing information on your device is your consent under Art. 6(1)(a) GDPR in conjunction with § 25(1) TDDDG. We collect this consent at first app launch via Google's User Messaging Platform (UMP). You can change your choice in the app settings at any time; if you decline, ads are served without personalisation.

You can additionally disable personalised advertising permanently in your Google account at adssettings.google.com. Further information on Google's data processing is available at policies.google.com/privacy and at policies.google.com/technologies/ads.

The offline-events.de website

We do not currently run any advertising on this website. We do not set advertising, tracking or analytics cookies and we do not embed any ad networks. For the data generated when a page is requested and for embedded third-party services, see section 11. Should we introduce advertising on the website in future, we will obtain your consent via a consent banner beforehand and update this privacy policy accordingly.

11. Hosting and technical infrastructure

Google Firebase (authentication and data storage)

Your app data (profile, events, chats, posts) is stored in Google Firebase, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Firebase provides us with the technical infrastructure for authentication (Firebase Authentication) and database services (Firestore).

Processing is based on a data-processing agreement under Art. 28 GDPR. Transfers to third countries take place only under the conditions of Art. 44 et seq. GDPR. Further information: firebase.google.com/support/privacy

Netlify (website hosting)

Our website is hosted by Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, USA. Netlify automatically collects technical access data (IP address, browser type, operating system, date and time of the request). Data transfer to the USA is based on the EU Standard Contractual Clauses. Further information: netlify.com/privacy

No external resources

All components of this website — in particular fonts ("Miriam Libre") and stylesheets — are served from our own server. No connection to Google Fonts, a content delivery network or any other external provider is established when a page is loaded, and no IP address is transmitted to third parties in the process.

12. AI processing and automated content screening

Event generation with GPT-4o

To generate personalised events, your profile data and activity preferences are transmitted to OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA. OpenAI processes this data to produce matching event suggestions via the GPT-4o language model. The transmitted data includes information such as interests, age, city and activity preferences. No full real names or directly identifying contact information are transmitted.

The legal basis for this processing is Art. 6(1)(b) GDPR (contract performance), since AI-assisted event generation is a core feature of the app, as well as Art. 6(1)(f) GDPR (legitimate interest in improving our services). Data transfer to the USA is based on the EU Standard Contractual Clauses.

Further information on OpenAI's data processing: openai.com/privacy

The selection of event suggestions produces no legal effect concerning you and does not similarly significantly affect you. It therefore does not constitute an automated decision within the meaning of Art. 22 GDPR. Whether you attend a suggested event is entirely your own decision.

Improving suggestion quality

To improve the quality of generated events, we evaluate positive user feedback (high ratings, accepted invitations) and use particularly well-received events as anonymised examples in our AI requests. These examples contain information about the event itself only, such as activity, time of day and type of location. They contain no directly identifying data such as names, email addresses, profile pictures or user IDs.

The legal basis is our legitimate interest in improving the service under Art. 6(1)(f) GDPR. You may object to this processing at any time under Art. 21 GDPR at info@offline-events.de.

Automated image moderation (Google Cloud Vision SafeSearch)

To keep the platform free of unlawful and harmful content and to comply with app store guidelines, every image uploaded to the app is automatically screened by Google Cloud Vision SafeSearch (Google Ireland Limited). Content classified as adult, violent or otherwise inappropriate is automatically removed.

The legal bases are our legitimate interest in maintaining a safe platform under Art. 6(1)(f) GDPR and compliance with legal obligations under Art. 6(1)(c) GDPR. If content of yours is removed automatically, you can contact us at any time at info@offline-events.de and we will review the case manually.

13. Changes to this privacy policy

We update this privacy policy when our services or the legal framework change. The version published on this page applies. In the event of material changes we will additionally notify you by email or via a message in the app.

Last updated: July 2026