Privacy Policy

Introduction

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as “data”) that we process, for what purposes, and to what extent. This privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and in particular on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).

The terms used are not gender-specific.

Last updated: February 6, 2026

Table of Contents

Controller

Bennett Bock
An der Autobahn 37
28876 Oyten
Germany
Email: support@zufallsgenerator.app

Overview of Processing Activities

The following overview summarizes the types of data processed, the purposes of their processing, and refers to the data subjects concerned.

Types of Processed Data

Categories of Data Subjects

Purposes of Processing

Legal Bases

The following provides an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection provisions may apply in your or our country of residence or establishment. If more specific legal bases apply in individual cases, we will inform you of these in this privacy policy.

In addition to the GDPR, national data protection regulations apply in Germany, in particular the Federal Data Protection Act (BDSG). The BDSG contains special provisions, among other things, on the right to information, the right to erasure, the right to object, the processing of special categories of personal data, processing for other purposes, and data transfers, as well as automated decision-making in individual cases including profiling.

Security Measures

We take appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of the art, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons.

These measures include ensuring confidentiality, integrity, and availability of data by controlling physical and electronic access, input, disclosure, availability, and separation of data. We have also established procedures to ensure the exercise of data subject rights, deletion of data, and responses to data security threats.

TLS Encryption (https): To protect data transmitted via our online offering, we use TLS encryption. You can recognize encrypted connections by the “https://” prefix in your browser’s address bar.

Transfer of Personal Data

In the course of processing personal data, data may be transferred to other entities, companies, legally independent organizational units, or individuals. Recipients may include IT service providers or providers of services and content integrated into a website. In such cases, we comply with legal requirements and conclude appropriate contracts or agreements to protect your data.

Deletion of Data

The data processed by us will be deleted in accordance with legal requirements as soon as consent is withdrawn or other permissions no longer apply (e.g. when the purpose of processing no longer applies). If data is not deleted because it is required for other legally permissible purposes, processing will be restricted to those purposes.

Use of Cookies

Cookies are small text files or other storage notes that store information on end devices and read information from them. Cookies can be used for various purposes, such as functionality, security, convenience, and analysis of visitor flows.

Consent Notice: We use cookies in accordance with legal regulations. We obtain prior consent from users unless consent is not legally required.

Storage Duration:

Provision of the Online Offering and Web Hosting

We process user data in order to provide our online services. This includes processing the user’s IP address, which is required to deliver content to the browser or device.

Web Analytics, Monitoring and Optimization

We use analytics and optimization tools to analyze user behavior and improve the stability, performance, and usability of our online offering. In doing so, pseudonymous usage profiles may be created.

Advertising in the App

Our mobile app “Zufallsgenerator” displays advertising to finance the free availability of the app. External advertising service providers may process personal data such as device identifiers, IP addresses, app usage data, and technical device information.

Sharing Groups

Shared groups are only accessible to individuals who know the non-public access code. Data is stored for a maximum of 72 hours and then automatically deleted.

RandomAI – Use of Artificial Intelligence

The app provides an optional feature called “RandomAI”. When used, user input is transmitted via Google Firebase Functions to external AI services (OpenAI – ChatGPT and Google Gemini) to generate group suggestions. Data is not stored permanently and is not used for training or marketing purposes.

Customer Reviews and Rating Procedures

We may ask users to submit reviews or ratings for our app. Reviews may be displayed publicly together with the chosen username. No obligation exists to submit a review.

Social Media Presences (Facebook & Instagram)

We maintain online presences on social networks and platforms in order to communicate with users and provide information about our services.

When users visit our social media pages, their data may be processed by the respective platform operators. This may include IP addresses, device information, interactions, and usage behavior. We have no full influence over the data processing carried out by the platform providers.

The processing of personal data is based on our legitimate interest in effective user communication and external presentation (Art. 6(1)(f) GDPR).

Further information on data processing can be found in the privacy policies of the respective providers:

Amendments and Updates to the Privacy Policy

We ask you to regularly review the content of our privacy policy. We will update this privacy policy as soon as changes to the data processing carried out by us make this necessary or if legal requirements change.

Rights of Data Subjects

As a data subject, you are entitled to the rights granted under the GDPR, in particular:

Definitions

This privacy policy is based on the definitions used by the GDPR. The most important terms include: