Privacy Policy
Controller (Verantwortlicher)
Alexander Scherer, Scharfland 75, 48683 Ahaus, Deutschland, E-Mail: info@schealex.de
Further contact details are available in the imprint.
Overview and Principles
obidience is a private application for consenting adults (18+) who practise power-exchange and D/s relationships. Protecting your data is a core part of how this service is designed.
Personal data is processed only where a legal basis under Art. 6 GDPR exists, or — for special-category data — under Art. 9 GDPR. The app does not use tracking, advertising, or marketing analytics. Only strictly necessary cookies are set.
This privacy policy informs you about the nature, scope, and purpose of the processing of personal data in connection with this service, in accordance with the General Data Protection Regulation (GDPR) and the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG).
Legal Bases for Processing (Art. 6 GDPR)
Art. 6(1)(a) GDPR — Consent: where you have given freely-given, specific, informed, and unambiguous consent (e.g. age confirmation, optional AI features).
Art. 6(1)(b) GDPR — Contract performance: processing necessary to provide the service you have registered for.
Art. 6(1)(c) GDPR — Legal obligation: where processing is required to comply with a legal obligation.
Art. 6(1)(f) GDPR — Legitimate interests: e.g. server security log files, to the extent that your fundamental rights and freedoms do not override these interests.
Special-Category Data — Sexual Preferences (Art. 9 GDPR)
IMPORTANT: The content you create on obidience — including consent categories, desires, marks, rules, tasks, rituals, protocols, and experiences — constitutes special-category personal data within the meaning of Art. 9(1) GDPR, as it relates to your sexual life and sexual orientation.
The legal basis for processing this data is your explicit consent under Art. 9(2)(a) GDPR, which you provide when you create an account and confirm the terms of use. You may withdraw this consent at any time by deleting your account; withdrawal does not affect the lawfulness of processing prior to withdrawal.
This data is processed exclusively to operate the service for you and your partner. It is not shared with third parties for advertising or profiling purposes.
Hosting and Server Log Files
The service is hosted on servers located in Germany. The hosting provider processes data on our behalf as a data processor (Auftragsverarbeiter) under Art. 28 GDPR.
When you visit the application, the web server automatically records log files that your browser transmits. These include: IP address, date and time of the request, requested URL, HTTP status code, data volume transferred, referring URL, and browser/OS information.
These log files are processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in security and stable operation). They are not combined with other data sources. Server log files are deleted after no more than 30 days.
Cookies
obidience uses only strictly necessary cookies. No consent banner is required for these under the TDDDG.
Session / authentication cookie: Keeps you logged in during your session. Deleted when the session ends or after 7 days.
Age-confirmation cookie (obidience_age_ok): Records that you have confirmed you are 18 or older. Persistent, valid for 12 months.
No marketing, tracking, analytics, or advertising cookies are used. No third-party cookies are set.
Account Registration and Account Data
To use obidience you must register with an e-mail address, a password (stored as a hash — the plain-text password is never retained), and a display name. This data is processed on the basis of Art. 6(1)(b) GDPR (contract performance).
Your account data is used solely to operate your account, authenticate you, and — where you choose to connect — link you with your partner via an invite code.
User-Created Content and Media
All content you create within the app — rules, tasks, rituals, protocols, experiences, desires, marks, notes, and uploaded media (photos, files) — is stored on our servers in Germany and constitutes special-category data (see Section 4 above). It is processed on the basis of your explicit consent (Art. 9(2)(a) GDPR).
Uploaded media files are stored in object storage (MinIO) operated on self-hosted infrastructure in Germany.
This content is shared only with your linked partner and with no one else, except where you explicitly trigger an AI feature (see below).
Optional AI Features
obidience offers optional AI-powered features (e.g. scene playbooks, rule suggestions, weekly digests). These features are disabled by default and must be explicitly enabled.
When an AI feature is used, selected relationship context — such as category names, text content of rules or tasks, and tone preferences — is transmitted to an AI API provider (OpenRouter, USA). Your name, e-mail address, and account identifiers are never transmitted.
The legal basis for this transfer is your consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR). You can withdraw consent at any time by disabling AI features in settings.
The transfer to the USA is based on the EU–US Data Privacy Framework (adequacy decision of 10 July 2023) and/or EU Standard Contractual Clauses (SCCs, Commission Implementing Decision (EU) 2021/914).
E-mail Sending (Transactional)
Transactional e-mails (e.g. password reset, invite notifications) are sent via Resend (USA), acting as a data processor under Art. 28 GDPR.
Only the recipient's e-mail address and the content of the transactional message are transmitted. The legal basis is Art. 6(1)(b) GDPR (contract performance).
The transfer to the USA is based on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
Payment Processing (Stripe)
Subscription payments are processed by Stripe. The contracting entity for EU customers is Stripe Payments Europe, Ltd. (Ireland); card processing and fraud protection is additionally performed by Stripe, Inc. (USA, 510 Townsend Street, San Francisco, CA 94103).
Data processed: the subscriber's e-mail address, billing and subscription metadata (plan, status, next billing date), and payment data entered directly in Stripe's hosted checkout. Card data is entered exclusively with Stripe and is never transmitted to or stored by us.
Purpose: subscription billing (including the 7-day trial period), recurring charges, and cancellation processing.
Legal basis: Art. 6(1)(b) GDPR (contract performance) for subscription payment processing; Art. 6(1)(f) GDPR (legitimate interest: fraud prevention and payment security) for the security infrastructure operated by Stripe in its capacity as an independent controller.
A Data Processing Agreement (DPA) with Stripe Payments Europe, Ltd. pursuant to Art. 28 GDPR is in place. Stripe, Inc. (USA) is certified under the EU-US Data Privacy Framework; transfers to the USA are additionally based on EU Standard Contractual Clauses (SCCs).
For further information on data processing by Stripe, see Stripe's Privacy Policy: https://stripe.com/privacy
Web Push Notifications (VAPID)
If you enable push notifications, your browser's push service (operated by Google, Mozilla, Apple, or another browser vendor) delivers notifications to your device via VAPID.
A push subscription endpoint is stored for your device. The browser vendor's push infrastructure may be located outside the EU. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time in your browser or device settings.
Calendar Synchronisation (Google Calendar — Optional)
If you choose to connect Google Calendar, obidience will write protocol and ritual entries to your calendar on your behalf. This requires granting the app access to your Google Calendar via OAuth.
Only the calendar data you have chosen to sync is transmitted to Google's servers (USA). No other personal data is shared with Google.
The legal basis is your consent (Art. 6(1)(a) GDPR). You can disconnect Google Calendar at any time in the app settings. The transfer to the USA is based on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (SCCs).
Recipients and Data Processors (Auftragsverarbeiter)
The following service providers process personal data on our behalf as data processors pursuant to Art. 28 GDPR.
Hosting provider (Germany) — server infrastructure and web hosting.
PostgreSQL database — self-hosted on the above infrastructure (Germany).
MinIO object storage — self-hosted on the above infrastructure (Germany) — media files.
OpenRouter (USA) — AI features (only when explicitly used; no identity data transmitted).
Resend (USA) — transactional e-mail delivery.
Browser push services (Google/Mozilla/Apple, potentially outside EU) — web push notifications.
Google LLC (USA) — Google Calendar synchronisation (only when explicitly connected).
New Relic, USA — application monitoring.
Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA) — payment processing (subscriptions).
International Data Transfers to Third Countries (USA)
Some of the data processors listed above are based in the United States (OpenRouter, Resend, Google, browser push vendors, New Relic, Stripe).
Transfers to the USA are based on one or more of the following mechanisms: (a) the EU–US Data Privacy Framework (adequacy decision of 10 July 2023), where the recipient is certified; and/or (b) EU Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914.
Data Retention and Deletion
Personal data is retained for as long as your account is active and necessary to provide the service.
When you delete your account (or your couple connection is dissolved), your personal data and all user-created content are deleted, unless statutory retention obligations require longer storage.
Server log files are deleted after no more than 30 days. Transactional e-mail logs are retained for no more than 30 days.
Where statutory retention obligations apply (e.g. tax law), the relevant data is stored for the legally required period and then deleted.
Data Security
The operator takes appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Data transmitted between your device and the server is encrypted in transit using TLS (Transport Layer Security). Data is encrypted at rest on the storage infrastructure.
Note: obidience does not offer cryptographic end-to-end encryption (E2EE) in the technical sense — the operator's infrastructure can access stored data. If you require E2EE, please do not use this service for sensitive content.
Your Rights (Art. 15–21 GDPR)
You have the following rights regarding your personal data, which you may exercise free of charge by contacting the operator at the address in the imprint:
Right of access (Art. 15 GDPR): You may request confirmation of whether personal data concerning you is being processed, and a copy of that data.
Right to rectification (Art. 16 GDPR): You may request correction of inaccurate or incomplete personal data.
Right to erasure (Art. 17 GDPR): You may request deletion of your personal data where the conditions of Art. 17 GDPR are met.
Right to restriction of processing (Art. 18 GDPR): You may request that processing be restricted in certain circumstances.
Right to data portability (Art. 20 GDPR): You may request your data in a structured, commonly used, machine-readable format.
Right to object (Art. 21 GDPR): You may object to processing based on Art. 6(1)(f) GDPR (legitimate interests) at any time on grounds relating to your particular situation.
Right to withdraw consent (Art. 7(3) GDPR): Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority — in particular in the EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. The competent supervisory authority for the operator is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de.
Right to Lodge a Complaint with the Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR.
The competent supervisory authority for the operator is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de.
Minors
obidience is intended exclusively for adults aged 18 and over. Persons under 18 are not permitted to use the service. If the operator becomes aware that personal data from a person under 18 has been collected, it will be deleted immediately.
Changes to this Privacy Policy
The operator may update this privacy policy from time to time to reflect changes in law or in the service. The current version published on this page governs. Where changes are material, registered users will be notified.
Effective Date
Last updated: 14 June 2026.