← Back

Privacy policy

Note on this translation: The legally binding version of this document is the German one. This English translation is provided to help you understand it; in case of any discrepancy, the German wording applies.

1. Controller

Samuel Liba

Samuel Liba Digital Solutions

Geranienweg 7, 85586 Poing, Germany

E-Mail: hallo@framepath.de

2. Data collected

When you use this platform, the following data are processed:

  • Email address (for registration and login)
  • Display name, username, profile data (avatar choice, genre preferences, equipment, software, experience level, city) — your profile is publicly accessible under your username
  • Your answers from the onboarding survey (goal, time budget, prior experience)
  • Learning progress data: completed skills and phases, quiz attempts and results, XP collected, streak, practice days logged, reviews due and daily tasks redeemed
  • Shared links: when you share your learning progress or a DJ spot, an address is created under which the shared content is accessible to ANYONE who knows the link — even without an account. You can withdraw a link at any time; after that it leads nowhere.
  • Reports: when you report a post in the community feed, we store WHICH post you reported, the reason you picked and your optional note — together with your identifier. Without it, misuse of the reporting function could not be detected. The author of the reported post does NOT learn who reported it; only the operator can read the report. If you delete your account, your reports go with it.
  • DJ spots with location data (only if you place them yourself — you choose the coordinates) along with photos, videos, voice notes and the names of any companions you enter
  • Mix recordings you upload and the feedback you write on other people's mixes
  • Friend requests and friendships (only with mutual consent)
  • Notifications (receipt, read status, timestamp)
  • Push subscriptions: when you enable push notifications on a device, we store the delivery address issued by your browser and its encryption keys. If you disable push, the entry is deleted.
  • Technical access data (IP address, browser, timestamp) — in server logs
  • Error diagnostic data when an error occurs in the app (error message, stack trace, page called up, browser identifier) — see section 8
  • Anonymous page-view statistics (Vercel Web Analytics): page visited, referrer, country, device type and browser — without cookies, without a persistent identifier and without profiling; the numbers are only visible in aggregate and cannot be traced back to a person

3. Purpose of processing

The data are used exclusively to provide the platform's functions: authentication, storing your learning progress and personalising the learning experience. They are not passed on to third parties for advertising purposes.

4. Legal basis

Your data are processed on the basis of Art. 6 (1) (b) GDPR (performance of a contract) and Art. 6 (1) (f) GDPR (legitimate interest in operating the platform).

5. Third-party provider — Supabase

This platform uses Supabase (Supabase Inc., 970 Toa Payoh North, Singapore) as its backend infrastructure for authentication and database services. Supabase processes data in accordance with its own privacy policy. The data are stored in EU data centres.

6. Hosting — Vercel

This platform is hosted by Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA). When the website is accessed, technical data (including IP address, browser, timestamp) are automatically recorded in server logs. Vercel processes these data in accordance with its privacy policy. The transfer of data to the USA takes place on the basis of the EU standard contractual clauses (Art. 46 GDPR).

7. Map service — Mapbox

The DJ spot map uses Mapbox (Mapbox Inc., 740 15th Street NW, 5th Floor, Washington DC 20005, USA) to display map tiles. As soon as you load a page containing a map (for example /karte), your IP address is transmitted to Mapbox so that the map data can be delivered. Mapbox processes the data in accordance with its privacy policy.

The transfer takes place on the basis of our legitimate interest (Art. 6 (1) (f) GDPR) in offering you the map functions. The transfer of data to the USA is safeguarded by EU standard contractual clauses.

8. Error analysis — Sentry

So that we can notice and fix crashes and errors in the app, we use Sentry (Functional Software, Inc. d/b/a Sentry, 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA). When an error occurs, the following are transmitted: the error message and stack trace, the page called up, details of the browser, operating system and device, and your IP address. In addition, performance data are recorded for a sample of around 10% of page views.

We deliberately transmit no user identity to Sentry — neither your email address nor your user ID nor your name. Session recordings (“session replay”), meaning the capture of your screen contents and input, are completely disabled.

The legal basis is our legitimate interest in the stable, secure operation of the platform (Art. 6 (1) (f) GDPR). The transfer of data to the USA is safeguarded by EU standard contractual clauses (Art. 46 GDPR). Details in Sentry's privacy policy.

Independently of this, we also log errors in our own database (Supabase, see section 5) in order to evaluate them on our internal error board. What is stored is the error message, the stack trace, the page called up, a browser identifier and — if you are logged in — your user ID. These data do not leave our own infrastructure.

9. Email notifications — Resend

To send reminder emails we use Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). What is transmitted is your email address and the contents of the message (for example your DJ name and the state of your learning streak).

There are exactly two kinds of such mail: a reminder when your learning streak is about to lapse, and a weekly summary of your progress. They go only to active users. We do not send third-party advertising, and your address is not passed on or sold.

Every one of these emails contains an unsubscribe link. One click stops all reminder emails permanently; your account is unaffected. The legal basis is our legitimate interest in communicating with our users about their own learning progress (Art. 6 (1) (f) GDPR); you may object to this processing at any time (Art. 21 GDPR).

The transfer of data to the USA is safeguarded by EU standard contractual clauses (Art. 46 GDPR). Details in Resend's privacy policy.

System-critical emails — for example to reset your password or confirm your address — are triggered by Supabase (see section 5) and likewise delivered via Resend. The information in this section applies to those messages too. They are necessary for the operation of your account and cannot be unsubscribed from.

10. Retention period

Your data are stored for as long as your account is active. You can permanently delete your account and all associated data at any time via your profile settings — deletion takes place without delay.

Supabase and Vercel may keep short-term technical backups (up to 30 days). After that these too are overwritten automatically. Server access logs (IP, timestamp) are kept for a maximum of 14 days and then anonymised or deleted.

Error reports at Sentry (section 8) are deleted automatically after 90 days. Delivery data at Resend (section 9) are deleted no later than on termination of the service. Entries on our internal error board are cleared once the error in question has been fixed.

11. Your rights

Under the GDPR you have the following rights:

  • access to the data stored about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure of your data (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • objection to processing (Art. 21 GDPR)

To exercise your rights, contact us by email at hallo@framepath.de. You also have the right to lodge a complaint with a data protection supervisory authority.

12. Cookies & local storage

This platform uses only technically necessary cookies for authentication (session tokens from Supabase Auth). No tracking or advertising cookies are used. Consent is not required for technically necessary cookies (§ 25 (2) TDDDG, Art. 6 (1) (f) GDPR).

In addition we store small amounts of data in your browser's local storage in order to remember UI settings (for example your chosen map style or your onboarding position). These data do not leave your device.

13. Minors

Our service is aimed at people aged 16 and over. If you are younger, you need the consent of a parent or guardian before creating an account. We do not knowingly collect data from children under 16. If we become aware of such data, we delete them immediately.

14. Push notifications

If you enable push notifications on a device (streak reminder and weekly recap), your browser creates a delivery address with your browser vendor’s push service (e.g. Google, Mozilla or Apple). We store this address and its encryption keys so we can send you messages. The content of the messages is end-to-end encrypted — your browser vendor’s push service cannot read it.

The legal basis is your consent (Art. 6(1)(a) GDPR): nothing is stored and nothing is sent without your explicit “Enable” on the device and your browser’s permission. You can withdraw your consent at any time — via “Disable” under notifications or in your browser settings; the stored entry is then deleted. If you delete your account, all push entries are deleted along with it.

15. Audience measurement (Vercel Web Analytics)

To understand which pages are read, we use Vercel Web Analytics — audience measurement without cookies and without a cross-device identifier. It records the page visited, the referrer, country, device type and browser; evaluation is exclusively aggregate, no conclusions about individual persons are possible and no profiling takes place. The provider is Vercel Inc., which also provides the hosting (section 7).

The legal basis is our legitimate interest in analysing and improving the free offering (Art. 6(1)(f) GDPR). As no cookies are set and no information is stored on your device, no consent is required (§ 25 TDDDG does not apply).

As of: 2026