This English version is provided for convenience. Only the German version is legally binding.
Last updated: October 3, 2026
This privacy policy explains which personal data we process when you use Aaronstudios, what we use it for, who we share it with and which rights you have.
1. Controller
Aaron Bidzan
Auf der Hüls 128
52068 Aachen
Germany
Email: [email protected]
Phone: +49 152 39601605
We have not appointed a data protection officer because we are not legally required to. If you have questions about data protection, please write to the email address above.
2. Hosting and server log files
Aaronstudios runs on a server of a hosting provider in Germany. Our database and all uploaded files are stored there as well. The provider processes the data only on our behalf; we have a data processing agreement with it under Art. 28 GDPR.
Every time you open the website, our server automatically processes technical data: IP address, date and time, requested address, referrer, amount of data transferred, status code, and browser and operating system. This is necessary to deliver the website and keep it secure and stable (Art. 6 (1) (f) GDPR). We delete server log files after 30 days at the latest, unless we need them to investigate a specific security incident.
3. Registration and user account
For your account we process your username, email address, password (only as a secure hash), language, settings and optional details such as display name, profile picture and bio. We create time-limited codes to confirm your email address, change it and reset your password. The legal basis is the performance of the user agreement (Art. 6 (1) (b) GDPR).
We cannot create an account for you without a username, email address and password. All other details are optional.
If you use the account switcher, we store a device code (cookie "asw_device") to know which accounts are linked on this device.
4. Content, profile and interactions
We store what you publish and do on Aaronstudios: posts with text, images, GIFs, an optional location and AI label, comments, likes and dislikes, mentions, follower relationships, stories, circles and the GIFs you upload. The legal basis is Art. 6 (1) (b) GDPR.
Visibility: Your profile (username, display name, profile picture, bio, join date, follower counts, badges) as well as posts and comments that were not shared in a circle are public. They can be viewed without signing in and can be found by search engines. Posts in circles are only visible to their members. Stories are shown for 24 hours. Public profiles can appear on the leaderboard.
A location is free text that you enter yourself. We do not read location data from your device or from your images' metadata.
5. Direct messages
We store your direct messages, images sent in them, the read status and, briefly, whether you are typing, in order to provide the chat (Art. 6 (1) (b) GDPR). Images from direct messages are kept in a non-public folder and can only be opened by the people in the chat. Messages are not end-to-end encrypted. We only look at them when a message has been reported or we are legally required to.
6. Notifications
In-app notifications
We store notifications about likes, comments, mentions, new followers and moderation decisions. To show new notifications and messages without reloading, we use a real-time service (Mercure) that we run ourselves on our server. It uses the cookie "mercureAuthorization" so that only you receive your own updates.
Email notifications
If you turn them on in your settings, we send you a summary of new notifications by email. You can turn them off at any time.
Push notifications
We only send push notifications to your device if you turn them on and allow them in your browser (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). For this we store the delivery address created by your browser, the related keys and the browser name. Notifications are sent encrypted to the push service of your browser vendor (for example Google Firebase Cloud Messaging for Chrome, Mozilla for Firefox, Apple for Safari or Microsoft for Edge), which delivers them to your device. These services cannot read the content but learn the delivery address and the time. Your browser decides which service is used. The providers are mostly based in the USA; where they are certified under the EU-US Data Privacy Framework, such as Google, Apple and Microsoft, the transfer is based on it. You can turn push notifications off at any time in your settings or your browser, which withdraws your consent for the future.
7. Sending emails
We use an email provider in Germany that acts on our behalf (Art. 28 GDPR) to send confirmation, security and notification emails. The legal basis is Art. 6 (1) (b) GDPR.
8. Verification and display names
If you apply for a verification badge or, as a verified account, for a new display name, we store your application with its explanation, links and the result of the review so we can process it (Art. 6 (1) (b) GDPR).
9. Support tickets
If you open a support ticket, we store your request, our replies and attached images so we can help you (Art. 6 (1) (b) GDPR).
10. Reports and moderation
If you report content, we store your report (reason, explanation, time), your account and a copy of the reported content as it was at the time of the report. If we take action, we store our decision and its reasons. This is how we meet our obligations under the Digital Services Act (Art. 6 (1) (c) GDPR in conjunction with Art. 16 and 17 DSA) and protect our users (Art. 6 (1) (f) GDPR).
The reported person is not told who reported them, unless we are legally obliged to disclose it. If you delete your account, your reports are kept without any reference to your account. Reports about an account and the decisions concerning that account are deleted when the reported account is deleted.
11. Developer API and "Sign in with Aaronstudios"
If you register a developer application, we store its details, your API key (only as a hash) and usage times. If you sign in to another application with Aaronstudios, we store your consent and only pass on the data you approve (for example username, display name, profile picture and, if requested, your email address). The provider of that application is responsible for any further processing. You can revoke access at any time under Settings → Apps. The legal basis is Art. 6 (1) (b) GDPR.
12. Aaronstudios+ and payments
If you redeem a code, we store the code, the time and how long your access lasts (Art. 6 (1) (b) GDPR).
If we offer Aaronstudios+ as a paid subscription, payments are handled by Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. We pass your email address and a customer number to Stripe; you enter your payment details directly with Stripe and we never receive them. Stripe may transfer data to Stripe, Inc. in the USA, which is certified under the EU-US Data Privacy Framework. The legal bases are Art. 6 (1) (b) and (c) GDPR. We keep data relevant for invoices for ten years (§ 147 AO, § 257 HGB).
13. Spam protection when registering (Google reCAPTCHA)
On the registration page we use Google reCAPTCHA by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to stop automated sign-ups by bots (Art. 6 (1) (f) GDPR). reCAPTCHA evaluates, among other things, your IP address, browser and device information and your behaviour on the page and may use cookies or similar technologies for this. Data may be transferred to Google LLC in the USA, which is certified under the EU-US Data Privacy Framework. See Google's privacy policy for more information.
14. Error monitoring (Sentry)
To detect and fix errors and performance problems, our server sends technical information to Sentry by Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA (Art. 6 (1) (f) GDPR). This includes the error message, the requested address, technical details of the request such as browser and operating system, and timestamps. We do not send your IP address or cookies. Because Sentry is based in the USA, this is a transfer to a third country; Functional Software, Inc. is certified under the EU-US Data Privacy Framework, and standard contractual clauses also apply. The data is deleted when Sentry's retention period ends, after 90 days at the latest.
15. Cookies and local storage
We only use cookies and local storage that are strictly necessary to run the platform (§ 25 (2) no. 2 TDDDG). We do not use tracking or advertising cookies. On the registration page, Google reCAPTCHA sets its own cookies (see section 13).
| Name | Purpose | Duration |
| PHPSESSID | Sign-in and session, language setting, form protection | 30 days |
| mercureAuthorization | Receiving your own real-time updates | up to 30 days |
| asw_device | Account switcher on this device | 1 year |
| settingsActiveSection (local storage) | Remembers the settings section you opened last | until you delete it |
| aaronstudios.pushBannerDismissedAt (local storage) | Remembers that you closed the push notification banner | until you delete it |
For push notifications, your browser also registers a service worker that shows incoming notifications.
16. Retention and account deletion
We store your data for as long as your account exists, unless a shorter period is stated above. You can delete individual content yourself at any time.
Under Settings → Your data you can download a copy of your data as a ZIP file and delete your account at any time. When you delete your account, we immediately remove your profile, posts, comments, stories, likes, notifications, direct messages (for both people in the chat), support tickets, applications and uploaded files. Circles you own are handed over to another member. Data we are legally required to keep is restricted until the retention period ends.
17. Recipients and transfers to third countries
We do not sell data or use it for advertising. The only recipients are the service providers named in this policy: our hosting provider and email provider in Germany, the browser vendors' push services, Google (reCAPTCHA), Sentry and, where applicable, Stripe. Transfers to the USA are based on the European Commission's adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR) and, where stated, additionally on standard contractual clauses (Art. 46 GDPR). Authorities only receive data if we are legally required to provide it.
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
18. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can withdraw any consent you have given at any time with effect for the future (Art. 7 (3) GDPR). You can exercise many of these rights directly in your settings; otherwise an email to [email protected] is enough.
Right to object: Where we process data based on legitimate interests (Art. 6 (1) (f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.
Right to lodge a complaint: You can complain to a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
19. Changes to this privacy policy
We update this privacy policy when our platform or the law changes. You can always find the current version on this page.