In short: Epilou stores your library on your device. There are no ads, no tracking and no analytics. If you use sync, your data is uploaded to our server end-to-end encrypted only – nobody can read it there, not even us. You don’t need an email address, name or password.
1. Controller
Niklas Ruzycki
c/o Online-Impressum 11446
Europaring 90
53757 Sankt Augustin
Germany
Email: [email protected]
No data protection officer has been appointed, as there is no legal obligation to do so.
2. Data on your device
Your titles, progress, ratings, notes, lists, favorites, custom covers and settings are stored locally on your device. They only leave the device if you set up sync (section 4) or export a backup yourself. Uninstalling the app removes this data from the device.
Sync keys and credentials are kept in your operating system’s secure key storage.
3. Searching for series and movies (TMDB)
Epilou uses the database of The Movie Database (TMDB) for searching. By default, searches go through our server: the app sends the search term, the requested language and, for details, the TMDB ID of the title to our server, which forwards the request to TMDB. TMDB only receives our server’s request, not your IP address. TMDB’s responses are cached in the server’s memory for up to 24 hours without any link to you.
To ensure only the app uses the server, each installation receives a randomly generated, pseudonymous access token on first launch. It contains no information about you or your device.
Cover images from TMDB are loaded directly from TMDB’s servers (image.tmdb.org). For technical reasons, your IP address is transmitted to TMDB. If you enter your own TMDB API key in the settings, searches also go directly from your device to TMDB.
Provider: TMDB, Inc., USA. TMDB processes this data under its own responsibility; the TMDB privacy policy applies. Data may be transferred to the USA.
Legal basis: Art. 6(1)(b) GDPR (providing the search feature you use).
4. Sync (optional)
Sync is optional. When you set it up, the app creates a random sync key on your device, which is also your 12-word recovery key. It never leaves your device in plain text.
What the server stores
- Your library data – titles, progress, ratings, notes, lists, favorites and custom covers – end-to-end encrypted only (XChaCha20-Poly1305). We cannot decrypt this content.
- Technical metadata needed for syncing: random record IDs (UUIDs), record type, modification time and size.
- A random account ID and a hash of a login key derived from your sync key (never the key itself).
- For each connected device, a session with a device label (e.g. “Epilou · android”), creation and last-use time, and a hash of the login token.
To connect another device, you scan a QR code. For this, the server keeps a pairing ID and your sync key – encrypted with a one-time key from the QR code – in memory for at most five minutes.
Retention and deletion
- How to delete your data from the server: In the app, go to Settings → Sync is on → “Delete sync”. This immediately removes your account, all connected devices and all synced data from the server. The data on your devices is kept. If you no longer have a device, reinstall the app, enter your recovery key under “Set up sync” and then delete sync as described.
- A device’s session ends automatically after 90 days without use.
- To protect against data loss, we create daily server backups that are overwritten after 14 days. Deleted data may remain in these backups until then – also encrypted only.
Legal basis: Art. 6(1)(b) GDPR (providing the sync you requested).
5. Server, hosting and logs
Our server is operated by Henrik Kramer e. K. (Prepaid-Hoster), Kurpromenade 48, 23743 Grömitz, Germany; the data center is located in Offenbach am Main (Germany). A data processing agreement under Art. 28 GDPR is in place with this provider.
When the app contacts the server, your IP address is processed for technical reasons to establish the connection. Our server does not store IP addresses or search terms. It only logs errors and the creation and deletion of accounts with their pseudonymous ID in order to keep the service running (Art. 6(1)(f) GDPR).
All connections between the app and the server are encrypted via HTTPS.
6. Camera and photos
- Camera: Only for scanning the QR code when connecting devices, and only with your permission. The camera image is analyzed on the device only and is neither stored nor transmitted.
- Photos: When you pick a cover for a custom entry, only that one image is imported into the app. It is stored locally and only transmitted, encrypted, if sync is active.
7. Backups
When you export a backup, the app creates a file in a location of your choice. This file is not encrypted; where you store or share it is up to you.
8. What Epilou doesn’t do
- No ads and no advertising IDs
- No tracking, no analytics or crash reporting services
- No sharing or selling of data to third parties
- No access to contacts, location or microphone
9. External links
Links in the app (e.g. to our website or to TMDB) open in your browser. The respective provider is responsible for any data processed there.
10. Google Play
If you install Epilou from Google Play, Google processes data under its own responsibility. The Google privacy policy applies.
11. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). You may also lodge a complaint with a data protection supervisory authority.
Since we collect neither names nor email addresses, we cannot link synced data to a person. You can therefore exercise most rights directly in the app: you can view and export your data at any time, and “Delete sync” removes everything from the server. If you have questions, contact us at the address above.
12. Children
Epilou is not specifically directed at children under 13.
13. Changes
If the app’s features change, we will update this policy. The version published here applies.