Privacy Policy

Protecting your personal data is important to us. Below we inform you in accordance with Art. 13, 14 of the General Data Protection Regulation (GDPR) about the processing of your data when using the Nutze.app platform.

1. Controller

The controller within the meaning of the GDPR is:

Chris Wernsmann
Vennstr. 3
48619 Heek
Germany
Email: hello@nutze.app

2. What data we process and for what purposes

Depending on your use of the platform, we process the following data:

3. Storage on your device (TDDDG) and cookieless analytics

We use technically necessary storage technologies (such as local storage in the browser) to keep you logged in and to ensure essential functions of the app (e.g. the booking process).

In the mobile app, local storage is replaced by your operating system's encrypted keychain (iOS Keychain or Android Keystore), which holds your session data and a few display preferences. That data never leaves your device and is removed when you sign out or uninstall the app. The cookieless analytics described below run on the web only — the mobile app contains no analytics, advertising or tracking SDK of any kind.

The storage of this strictly necessary data on your device is based on § 25 (2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act). The subsequent processing of the personal data takes place in accordance with Art. 6 (1) (f) GDPR (legitimate interest in providing the app) or Art. 6 (1) (b) GDPR.

For reach measurement we use Vercel Analytics and Speed Insights. These services work cookielessly and collect data (such as page views) only in anonymised form. No user profiles are created across websites.

4. Sign-in via third-party providers (single sign-on)

In addition to classic registration by email, we offer the option of signing in via the services of Google and Apple.

If you choose this option, we are authorised directly by the respective third-party provider and receive certain profile data from them (such as your name and email address) in order to create your Nutze.app account or log you in. The legal basis for this is the performance of a contract (Art. 6 (1) (b) GDPR) or your consent through the active selection of the provider (Art. 6 (1) (a) GDPR).

5. Recipients of the data and US data transfer (DPF)

To provide our platform, we use specialised service providers (processors pursuant to Art. 28 GDPR).

Every provider listed below is contractually bound — through a data processing agreement under Art. 28 GDPR — to process your data solely on our instructions and for the stated purpose, and to provide the same level of protection for that data as is described in this privacy policy. Your data is never passed on for the providers' own purposes, sold, or used for advertising.

Important note on data transfer to the USA

Some of our service providers are based in the USA. The European Commission has issued an adequacy decision for the EU-US Data Privacy Framework (DPF). Insofar as our US service providers are certified under the DPF, the transfer of data to the USA is permissible under data protection law.

We use the following service providers:

Artificial intelligence (content screening and assistive features)

Artificial intelligence assists us in a few places. The only provider used for this is:

Only what the respective feature needs is transmitted:

Before any content is sent to Google for the first time, the app and the website show you which data is sent to whom, and ask for your decision.

For the four assistive features — listing assistant, category suggestion, search and search keywords — that decision is consent under Art. 6 (1) (a) GDPR: without it nothing is transmitted and the features stay switched off.

Listing screening, by contrast, rests on our legitimate interest (Art. 6 (1) (f) GDPR) — a safety check that could be switched off would not be one. We still follow your decision here: it takes effect as an objection under Art. 21 GDPR, and your listing is then screened by a person instead of an AI. That takes longer, but restricts neither publishing nor any other use of the platform.

Changing or withdrawing your permission: you can change your decision at any time and without giving reasons — in the app under Profile → Account & Security → Artificial intelligence, on the website under Dashboard → Profile → Account & Security → Artificial intelligence. A withdrawal takes effect going forward: from that moment no further content is sent to Google. The lawfulness of processing carried out until then is unaffected.

Uploaded images are converted before being passed on, and GPS coordinates are stripped from the EXIF data in the process.

Not transmitted: chat messages, handover and return records, payment or account data. Your content is not used to train AI models — this is contractually excluded by our use of the paid Google API.

Payment processing via Stripe

For processing payments we use Stripe Payments Europe, Ltd. (Ireland) or its parent company in the USA (certified under the EU-US DPF).

Stripe processes payment information (e.g. credit card details) partly as our processor, but also as an independent controller in order to comply with its own legal obligations (e.g. anti-money-laundering). You can find further information in Stripe's privacy policy: https://stripe.com/privacy.

6. Map services and geocoding

To show you the locations of listings, we embed interactive maps. For data-protection reasons (privacy by design), we host the underlying map tiles (Protomaps/PMTiles) on our own servers. When simply viewing the map, no location data is therefore transmitted to third-party map providers.

However, the following applies to certain additional map functions:

The legal basis for this processing is our legitimate interest in a functioning and appealing location search (Art. 6 (1) (f) GDPR) and the performance of a contract (Art. 6 (1) (b) GDPR).

7. Storage period

We only store your data for as long as is necessary for the respective purpose.

Account deletion

You can delete your account yourself at any time — on the web and in the app under Profile → Account & Security. Deletion happens in two stages.

Immediately upon your request: your profile, your listings and your presence in search disappear at once. From that moment your account can no longer be found by anyone else.

Your access remains for 30 days — deliberately so. Deletion is reversible during that period, and you can only reach the reversal if you are still able to sign in. Pressing "Cancel deletion" on the same page restores your account completely. Simply signing in does not cancel the deletion; that button is the only thing that does.

After the 30 days have passed, your account is automatically and permanently anonymised. We do not delete the row in our database — we delete the person in it. Your name is replaced with "Deleted user"; profile picture, phone number, company details, VAT ID, any stored imprint and terms documents, notification preferences and all Stripe identifiers are removed; your addresses are overwritten. Push tokens, favourites, follows and blocks are deleted. Your credentials are made unusable: password and linked Google/Apple accounts are removed, active sessions are ended, and access is permanently locked. From this point recovery is no longer possible.

Why anonymised rather than deleted: a rental always has two sides. If we removed your row entirely, your counterparty would also lose the record of a booking they were party to — including the invoicing and payment data we are required to retain for up to 10 years under § 147 AO and § 24 Abs. 3 PStTG. Those records therefore remain, but can no longer be attributed to an identifiable person.

That is not the end of it. Anonymisation removes the person from the row; what remains of the content has its own deadline, and an automated process checks daily which of those have passed and erases them. Three years after the end of the year in which they were created, message text, review text and listing descriptions are erased (§ 195, § 199 Abs. 1 BGB). Ten years applies to the booking and payment details that matter for tax (§ 147 AO, § 24 Abs. 3 PStTG) — and § 24 Abs. 3 PStTG expressly requires erasure once the period ends. Images sent in chat are removed as soon as the message they belong to no longer exists.

When we refuse a deletion: while you are party to a booking that is not yet completed, cancelled or rejected, we cannot delete your account — the same applies during an open dispute and while there is an unpaid balance on your Stripe account. In those cases we tell you what is still outstanding. If any of these checks cannot be carried out for technical reasons, we refuse as a precaution rather than perform a deletion that would damage an ongoing rental.

Your right to erasure under Art. 17 GDPR remains unaffected; you can contact us at any time at hello@nutze.app. Where we must keep data to meet a statutory retention obligation, Art. 17 (3) (b) GDPR expressly provides an exception to the right to erasure; we then restrict processing of that data to the retention purpose and delete it once the period ends.

8. Data sharing between users

When you request a booking, we pass on your name and the city of the handover location to the respective other contracting party.

Once a booking is confirmed (that is, accepted and onwards), we additionally pass the following data to the other contracting party so that you can arrange the handover and know who you have entered into a contract with:

This is strictly necessary for the performance of the rental contract between you (Art. 6 (1) (b) GDPR). Before a booking is confirmed we do not share this data. We never pass your email address to the other contracting party — communication runs through the in-app chat.

9. Your rights

You have the following rights with regard to your personal data:

Right to object (Art. 21 GDPR): insofar as we process your data on the basis of legitimate interests (Art. 6 (1) (f) GDPR), you can object to the processing at any time.

To exercise your rights, an email to hello@nutze.app is sufficient.

10. Right to complain to a supervisory authority

You also have the right to complain to a data protection supervisory authority. The supervisory authority responsible for our registered office is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2-4
40213 Düsseldorf, Germany

Last updated: September 2026