Privacy policy

> Translation of the German text above. The German version is the binding one. > Same fill-in markers, same section numbers.

Privacy Policy

Last updated: `7 August 2026`

Zapello is a player. It plays back the access you bring yourself. We do not supply channels, playlists or any content, and video traffic runs directly between your device and your provider's server — never through us. That is why a lot of data other services have to store never comes into existence here.

This policy tells you which data we do process, why, on what legal basis, for how long, and who else gets to see it.

1. Who is responsible?

Controller within the meaning of Art. 4(7) GDPR:

Traian Fotios Jelastopoulos
Reichenhaller Str. 59
70372 Stuttgart
Germany

Email: info@zapello.app

We have not appointed a data protection officer. We are not required to under Art. 37 GDPR and § 38 BDSG; we review this once a year.

2. Contact for privacy matters

Write to `info@zapello.app`. For requests about your rights (section 12) please use the email address your account is registered with — that is how we know the request is really yours. If that is not possible, we will send a confirmation code to the account address.

Abuse reports and rights holder enquiries: `abuse@zapello.app`.

3. What we do not process

These are build constraints, not good intentions. They are written into our specifications as "red lines" and verified by automated tests.

4. Processing at a glance

The table below is complete. It comes from our internal record of processing activities; each row states purpose, legal basis, storage location and retention.

WhatPurposeLegal basisWhereHow long
Account email addressaccount, sign-in, transactional emailArt. 6(1)(b)Neon (EU)14 days after account deletion
Device name, platform, last activity, hash of the device key; device swap recordslicence, five-device limit, protection against trial abuseArt. 6(1)(b) and (f)Neon (EU)with the account; account-less device hashes 24 months after last activity
Entitlements and payment references (IDs only)performance of the contractArt. 6(1)(b)Neon (EU)statutory retention periods
Sync data (encrypted blobs)syncing your settings across devicesArt. 6(1)(b)Neon (EU)with the account
Interim state on simultaneous edits (encrypted)merging two changesArt. 6(1)(b)Neon (EU)24 hours
One-time codes and sessionssecure sign-inArt. 6(1)(b) and (f)Neon (EU)code 24 hours, session 30 days
QR sign-in on TV: visible code, device name, platform, hash of the device keysigning in on a TV without a keyboardArt. 6(1)(b)Neon (EU)120 seconds, then cleanup job
QR handover from phone: public key and encrypted envelopesending a playlist from your phone to the TVArt. 6(1)(b)Neon (EU), encrypted onlyimmediately after pickup, otherwise after 120 seconds
Replay protection (idempotency key, path, response)prevents double execution after a dropped connectionArt. 6(1)(b)Neon (EU)24 hours
Post-trial offer window (account ID or device hash, expiry)time-limited offer after the trialArt. 6(1)(b)Neon (EU)when the window expires (48 hours)
Request counters (peppered hash instead of IP, time window, count)abuse and overload protectionArt. 6(1)(f)Neon (EU)2 days
Escrowed sync key (encrypted envelope)cross-device sync without re-entry — section 6Art. 6(1)(b)Neon (EU) plus Google Cloud KMS (europe-west3)with the account; immediately if you enable "Enhanced privacy"
A marker that you switched on "Enhanced privacy" (a timestamp, nothing else)so we show you the right explanation when no key is deposited — without it, “you switched this on” cannot be told apart from “you have never set up a sync”, and we would tell one person what applies to the otherArt. 6(1)(b)Neon (EU)with the account; it clears itself as soon as a key is deposited again
Log of every key retrieval (account, device, time, peppered hash instead of IP)so that unauthorised access is noticedArt. 6(1)(f)Neon (EU)90 days
Support conversationshandling your requestArt. 6(1)(b) and (f)ticket system90 days
Diagnostic reports (install ID, error code, device model, report)troubleshooting — only if you send them; prepared, not currently created, section 7Art. 6(1)(a)Neon (EU)90 days
Telemetry (random install ID, events from a fixed list)product improvement — outside the beta only with your consent; during the closed beta the measurement is part of taking part in the test programme, section 7Art. 6(1)(a); for beta participants Art. 6(1)(b)Neon (EU)raw data 90 days, aggregates indefinitely in aggregated form
Server logsoperations and securityArt. 6(1)(f)Vercel7 days
Waitlist: email address, language, confirmation statuslaunch notification, double opt-inArt. 6(1)(a)Neon (EU)unconfirmed 30 days, confirmed until you opt out
Check value for your 12-word recovery codedetects a mistyped code immediately instead of letting you fail on unreadable data — section 6Art. 6(1)(b)Neon (EU)with the account
Beta unlock flag on your account (a single yes/no)access control for the closed betaArt. 6(1)(b)Neon (EU)with the account; the flag goes away when the beta ends
Beta participation of your account (just the date you joined)records since when you take part in the test programme — and therefore since when the measurement rests on it; section 7Art. 6(1)(b)Neon (EU)with the account; cleared immediately if you leave the test programme, and gone when the beta ends
Roadmap: your votes (account and card)one vote per account and card; only the total is publicArt. 6(1)(b)Neon (EU)with the account
Roadmap: your wishes and comments (text, moderation status)ideas and discussion; public only after human approval, without naming youArt. 6(1)(b)Neon (EU)with the account; rejected contributions 90 days after the decision
Sign-in token in your browser's session storagekeeps you signed in to the customer area while the tab is openArt. 6(1)(b), § 25(2) TDDDGonly in your browser, never with uswhen you close the browser, immediately on sign-out

Active since 6 August 2026: crash reports (Sentry, legitimate interests, 90 days — name, email address, user identifier and IP address are removed before sending; a coarse location (country/city) derived from the connection is still processed by Sentry server-side, see section 9) and website statistics (Plausible, cookieless, aggregated only) — see sections 8 and 9.

Retention is set out in detail in section 11.

5. Legal bases

We rely on three bases, and the table above shows which one applies per row.

Contract (Art. 6(1)(b) GDPR). Everything needed for Zapello to do what you installed it for: account and sign-in, the five-device limit, syncing your settings, handing a playlist from your phone to your TV, entitlements. Without this data there is no feature.

Legitimate interests (Art. 6(1)(f) GDPR). Operations and security: server logs, abuse limits, the key-retrieval log, crash reports. Our interest is a working, attack-resistant service. We balanced this against your interests and kept the intrusion minimal — which is why we store peppered hashes instead of IP addresses and why the periods are short (7 days, 2 days, 90 days). You can object (section 12).

Consent (Art. 6(1)(a) GDPR). Optional things: telemetry, diagnostic reports, the waitlist. Nothing happens here without your active yes, and you can withdraw it at any time with effect for the future (section 13). The app works fully if you decline all of it.

One exception while the closed beta runs: whoever takes part in the test programme is measured — that is the purpose of a test programme, and therefore part of taking part (Art. 6(1)(b)), not a separate consent alongside it. We expressly do not make access depend on ticking a box; consent obtained that way would not be freely given under Art. 7(4) GDPR. What gets measured is in section 7 and in full in the terms of the test programme. If you do not want to be measured, you leave the test programme; when the beta ends we ask everyone explicitly for consent, and until then the toggle in the app settings stays what it is — a toggle you can flip.

For payments, statutory retention duties apply on top (Art. 6(1)(c) GDPR in conjunction with § 147 AO and § 257 HGB). Invoice data sits with our payment provider, not with us; we only store the reference ID.

6. Your playlist credentials and sync data — please read carefully

This is the most important section of this policy, because it is about your credentials. We tell you plainly who can technically read them.

How the encryption works. Your playlist credentials (server address, username, password or M3U link) and your sync data (favourites, sort orders, settings, progress) are encrypted on your device before they reach us. What sits on our server is an encrypted block. We do not decrypt it, and our software has no function that could. The admin area we use to look after accounts has no way to view your playlist data either.

Where the key is kept — and what that means. So that a new device can read your data straight away without you typing in 12 words, we escrow the key with us during normal operation. Specifically:

And now the honest consequence: as long as this escrow is active, we could technically retrieve the key from the key service and decrypt your sync data and playlist credentials. We do not do this, there is no built-in function for it, and every retrieval leaves a trace — but the technical possibility exists. That is why we do not call this state "zero-knowledge". Anyone who does is promising more than the technology delivers. In legal terms: in this state the encrypted blobs are personal data for us as well.

How to switch it off: "Enhanced privacy". There is a toggle in the app settings. Turning it on deletes the escrowed key on our side. The customer area on this website currently has no such toggle — there you only see that it is on (your playlists stay locked in the browser). From then on:

We do not know this code. It is generated on your device. All we store is a check value that lets the app spot a wrong entry immediately; the code cannot be reconstructed from it.

Handing a playlist from phone to TV works on the same principle: your phone encrypts the credentials with a public key that only your TV can open. We see the envelope and delete it as soon as the TV has collected it, at the latest after 120 seconds.

Since August 7, 2026 you can also set up this key in your browser if your account doesn't have one yet — the process works exactly the same way as in the app: in your browser, not on our servers. A browser that does this does not count as one of your five playback devices (see the device slots section) — it only sets up the key and then uses it like any other device.

7. Telemetry and diagnostics — both optional

Telemetry is off by default. If you turn it on, we send a random install ID and events from a fixed, exhaustive list: steps during first-time setup, the duration of a channel change plus technical context (which playback engine, which container, how long resolving a master playlist took, whether it came from cache, how many quality levels were offered), cold start duration, a signal for abandoned flows, and a daily "did not crash today" ping.

Explicitly not included: channel names, playlist contents, your provider's addresses or hosts, your device model or device name, your IP address. The install ID is separate from the device key and is never linked to your account. That is not a promise on request: the relevant tables deliberately have no column that could point to an account, and an automated test enforces it. Events that are not on the list are discarded by the server.

Diagnostic reports are prepared but are not currently created. On an error screen the app offers to copy the diagnostic text to the clipboard — you then decide yourself whether and to whom you send it. A send button that transmits a report to us is planned and not built today; until then the corresponding table stays empty on our side. Once it exists the following applies: only on your active tap, and the report contains technical logs, your device model and the error code shown. Credentials and passwords never appear in it — that is a hard build constraint for logs, telemetry, tickets and error reports alike.

You can turn both off again at any time in the settings. Raw data already transmitted is deleted after 90 days; analyses that no longer relate to a single installation are kept in aggregated form.

During the closed beta a different basis applies to telemetry. The test programme has exactly one purpose — finding out where the app breaks — and the measurement is that purpose, not an addition to it. For test participants it therefore rests on the participation itself (Art. 6(1)(b)) and not on consent. For this we store one date with your account: since when you take part. What that means precisely, which values are collected and how to leave is set out in the terms of the test programme. Crash reports are not part of this — they run on legitimate interests and come from all users (section 9). When the beta ends, so does this basis: after that we ask you explicitly, and without your yes nothing is sent.

8. Cookies and analytics

We set no cookies on our website. No consent banner, because there is nothing to consent to.

The website does put two things in your browser, both technically necessary and both gone again without you doing anything:

Since 6 August 2026 we measure our website's reach with Plausible: cookieless, no cross-device recognition, aggregated figures only (page views, referrer, coarse region derived from the IP — Plausible does not store the IP address itself). Legal basis is legitimate interests (Art. 6(1)(f) GDPR): we want to know whether our pages are found at all, without recognising any single device or you as a person. The embedding code still only loads while the corresponding domain is configured.

The customer area has been publicly reachable since 2 August 2026. It still works without a cookie: what it needs is the sign-in token in session storage mentioned above, and that is exempt from consent under § 25(2) no. 2 TDDDG, because without it the sign-in you asked for does not work. Should a strictly necessary cookie be added later, we will name it here before we set it.

9. Who else processes data

We do not sell data and do not pass it on for advertising. We do work with service providers who act for us and on our instructions (processors under Art. 28 GDPR). A data processing agreement is in place with each of them.

ProviderPurposeDataPlace of processing
Vercel Inc., USAhosting of website and APIall request data in transit, server logsdata centres in the EU; company seat USA
Neon Inc., USAdatabasethe data listed in section 4EU, Frankfurt am Main
Resend Inc., USAtransactional email (sign-in codes, notices, waitlist confirmation)email address, content of the respective messageUSA
Cloudflare Inc., USADNS for our domains; object storage for app updates (Western Europe region); email routing for `info@` and `support@`connection data on retrieval, content of forwarded emailEU/Western Europe and USA
Google (Cloud KMS, europe-west3)encrypts the escrowed sync key — section 6the key, nothing elseFrankfurt am Main; company seat USA
Google (mailbox)destination of the email forwarding for `info@` and `support@`content of the email you send usEU data centres and USA
Functional Software, Inc. (Sentry), USAcrash reports from the app (sections 4/5)scrubbed error reports without credentials, channel names, user identifiers or stored IP address; Sentry derives a coarse location (country/city) from the connection server-sideEU region (`de.sentry.io`)
Plausible Insights OÜ, Estoniawebsite statistics (section 8)aggregated page views, no IP storage, no cookiesEU

In use since 6 August 2026: Sentry (crash reports, EU region) and Plausible (website statistics, EU). Both are listed in the table above.

Beyond that we disclose data only where we are legally obliged to, for example in response to a government order. On playlist and sync data see section 6: what we cannot decrypt, we cannot hand over.

10. Transfers to third countries

Our storage locations are all in the EU: the database in Frankfurt, the key service in Frankfurt, object storage in Western Europe, hosting in EU data centres. The providers are US companies, however, and could in theory access their systems from the USA. That constitutes a transfer to a third country.

The basis for this:

When transactional email is sent via Resend and when mail is forwarded to the Google mailbox, data leaves the EU in substance as well. So do not email us anything you would not want processed in the USA; we never need credentials and never ask for them.

A residual risk remains: under the CLOUD Act, US authorities can demand access to data controlled by US companies. That is precisely why the "Enhanced privacy" toggle in section 6 is more than cosmetics.

11. How long we store data

The exact period is given per row in the table in section 4. The principle: we delete automatically, not on request. Cleanup jobs run daily.

Device hashes without an associated account — they arise when someone uses the trial without an account — are deleted 24 months after the last activity.

12. Your rights

You have the following rights towards us. They are free of charge, and we respond within one month.

How to identify yourself: write from the email address your account is registered with, or confirm a code we send there. We need no other proof — and we do not ask for ID documents.

13. Withdrawing consent

Where we rely on your consent — telemetry, diagnostic reports, waitlist — you can withdraw it at any time with effect for the future, at no disadvantage to you. This does not affect the lawfulness of processing up to the withdrawal (Art. 7(3) GDPR).

How:

14. Right to lodge a complaint

If you believe we are processing your data unlawfully, you can lodge a complaint with a data protection supervisory authority, whether or not you talked to us first (Art. 77 GDPR). The competent authority is the one at your habitual residence, your place of work or the place of the alleged infringement. The authority responsible for us is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Heilbronner Straße 35, 70191 Stuttgart

We would prefer you write to us first. But you do not have to.

15. No automated decision-making

We make no decisions about you that are based solely on automated processing and produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). There is no profiling and no scoring.

Automated checks exist only where they slow down abuse: anyone making a great many requests in a short time is temporarily throttled. That is a technical limit, not an assessment of your person, and you can contact `info@zapello.app` in such cases.

16. Changes to this policy

We update this text when the processing changes — in particular before a new provider goes live, not afterwards. The date at the top shows the current version. For material changes we will also notify you by email or in the app.

---