Privacy Policy

This privacy policy informs you, in accordance with Articles 13 and 14 of the EU General Data Protection Regulation (GDPR), about the processing of personal data when you use the LeanStream platform (web and mobile app).

1. Controller

The controller within the meaning of the GDPR is the provider named in the imprint.

2. Data we process

2.1 Account data

On registration we collect: name, email address, optional profile picture. Authentication is handled via email/password or magic link (passwordless sign-in). Processing is based on performance of the user contract (Art. 6 (1) (b) GDPR).

2.2 Content

You can upload videos, comments, reactions, and profile information to your organisation. This content is made visible within the respective organisation. Videos are processed and stored via Cloudflare Stream; additional media files (e.g. voice-over recordings) via Cloudflare R2. Both services are operated in a GDPR-compliant manner with EU data processing agreements in place.

2.3 Push notifications (mobile only)

If you allow the mobile app to send notifications, we store your Expo push token so we can notify you about activity in your organisation. You can disable push notifications at any time in your device’s system settings.

2.4 Usage data

We record which videos you have watched and reacted to (seen-tracking) in order to sort your feed. This data stays within your organisation.

2.5 Server logs

When our servers are accessed, technically necessary information (IP address, user agent, timestamp) is stored in server logs for a maximum of 14 days (Art. 6 (1) (f) GDPR – legitimate interest in security and operational stability).

2.6 Diagnostic data (mobile only)

In the published version of the mobile apps we collect technical crash and error reports via Sentry in order to fix stability issues (Art. 6 (1) (f) GDPR – legitimate interest in error-free operation). No content or contact data is transmitted and no user identifier is set.

3. Recipients / processors

We use the following service providers as processors:

  • Hetzner Online GmbH (Germany) – server hosting
  • Cloudflare, Inc. (EU data processing) – video and file hosting (Stream, R2), CDN
  • Resend, Inc. – delivery of transactional emails (magic links, invitations, password reset)
  • Expo / Apple / Google – delivery of push notifications to mobile devices
  • Functional Software, Inc. (Sentry) – crash and error diagnostics for the mobile apps (diagnostic data, no content or contact data)

4. Storage period

Account and content data are stored for as long as your account is active. When you delete your account:

  • Immediately: sessions are closed, push tokens are deleted, your account is deactivated.
  • After 30 days: personal data (name, email, profile picture, authentication credentials) is permanently erased. Uploaded videos and posts remain in your organisation and are displayed anonymously (“Deleted user”). Behavioural data (watched videos, reactions) is deleted.

Server logs are deleted after a maximum of 14 days. Audit logs for security-relevant events are retained for up to 90 days.

5. Your rights

At any time you have the right to:

  • Access the personal data stored about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure of your account (Art. 17) – see section 4
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Lodge a complaint with a supervisory authority (Art. 77) – e.g. your state data-protection authority

You can delete your account directly in the app under Profile → Delete account or by email to hello@leanstream.app.

6. Cookies

We set only technically necessary cookies (a session cookie for sign-in). These do not require consent (§ 25 (2) TDDDG). There is no third-party tracking.

7. Transfers to third countries

Cloudflare processes data primarily in the EU; in exceptional cases a transfer to the USA may occur. Resend (USA) sends our emails via servers in the EU (Amazon SES, Ireland region); Sentry (USA) receives diagnostic data from the apps. Push notifications pass through Apple (USA) and Google (USA) servers for delivery — no content matching takes place. All transfers to the USA are safeguarded by the EU standard contractual clauses (Art. 46 GDPR) or the EU-US Data Privacy Framework.

8. Changes to this policy

We update this policy when our service changes materially. You can always find the current version at this URL.

Last updated: July 2026