Privacy Policy
Last updated: July 2026
This document is not yet available in your language. The English version is shown.
The German version is authoritative. Translations are provided for convenience.
Calfira needs no sign-up and no password. You join an event via a QR code or a short code. Events and their photos are deleted automatically once the event is over (usually around 30 days after it ends).
We show no advertising, build no advertising profiles and never sell data. Your photos are stored on a server in Germany.
1. Who is responsible?
Responsible for data processing within this app and website is:
Ali Makhloufi
Bergiusstr. 7
40880 Ratingen, Germany
Email: info@calfira.app
2. What data is processed?
Calfira is built to be data-minimal. There is no user account. Instead of a sign-in, the app uses a random, pseudonymous device identifier so it can recognise your own events and uploads.
Processed data includes: the device identifier, a display name you choose yourself, the photos and messages you upload, the technical details of those files (time, size, format), the IP address at the time of upload, and the events you have joined. On the website, the usual server log files are recorded briefly.
3. Legal bases
Processing is based on Art. 6(1) GDPR:
- point (b) (performance of the service): providing events, joining, uploading and displaying photos.
- point (f) (legitimate interests): secure and stable operation, protection against misuse.
- point (c) (legal obligation): handling reported unlawful content and notifying authorities where required by law.
- point (a) (consent): wherever you actively upload content (photos, avatar) or make a purchase.
4. Photos and the people in them
People may be identifiable in uploaded photos. Whoever uploads a photo is responsible for holding the necessary rights and consents of the people shown. Please do not upload photos you do not hold the rights to.
The host of an event can remove photos and participants. On notice, we remove infringing content promptly.
Which content is permitted and what measures may follow a breach is set out in our Terms of Use.
5. Reporting function and handling of reported content
In every event you can report photos and messages. There are two levels, and they lead to different paths.
Level 1: "It bothers me" - report to the host
The report goes to the person who created the event. They decide whether the content is removed. The photo stays visible until then. We as the provider are not informed and keep no copy.
Level 2: "Illegal content" - report to us
The content is hidden from all participants immediately and forwarded solely to us as the provider. The person who created the event can neither lift nor dismiss this report. This is deliberate: they could be the person who uploaded the content.
In this case we create a secured copy. We store:
- the reported photo or text
- the time of upload and the time of the report
- the pseudonymous device identifier and IP address of the uploading person
- the name and code of the event
- a checksum of the file (SHA-256), proving the file has not been altered
This copy is stored separately from the gallery, in an area of our German server that cannot be reached from outside. It is exempt from the automatic deletion of the event - otherwise no evidence would remain in a case still open.
Purpose and legal basis
The purpose is to examine the suspicion, to protect other users and, where necessary, to pass the case to the competent authorities. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing and investigating criminal offences on our platform) and Art. 6(1)(c) GDPR where legal obligations apply to us.
How long we keep the copy
We delete the copy once the case is closed. If our review finds no indication of illegal content, we restore the content and the copy is deleted in the same step.
If an authority is involved, we keep the copy for as long as the proceedings require. We review open cases regularly so that nothing is left unnoticed.
Abusive reports
The number of reports per device is limited. Repeated baseless reports may lead to exclusion from the service.
6. Hosting
The website and the Calfira server are hosted by:
ALL-INKL.COM - Neue Medien Münnich
Owner: René Münnich
Hauptstraße 68, 02742 Friedersdorf, Germany
The servers are located in Germany. A data processing agreement under Art. 28 GDPR is in place with the provider.
7. Third parties
Google Play (Android)
The app is distributed through Google Play. Optional purchases (additional storage) are handled by Google. We only receive confirmation that a purchase was made - no payment data.
Apple App Store (iOS)
On iPhone and iPad the app is distributed through the Apple App Store. Optional purchases (additional storage) are handled by Apple. We only receive confirmation that a purchase was made - no payment data.
Fonts
The fonts used (Baloo 2, Nunito) are served locally from our own server. No connection to Google is made and your IP address is not transmitted to third parties.
Social networks
We run a TikTok presence under the umbrella brand Galtasar. Neither the app nor the website embeds content or buttons from these networks. No data is therefore transmitted to TikTok unless you go there yourself. If you visit our presence there, the privacy notices of the respective operator apply.
8. What we do NOT do
- No user account, no passwords
- No cookies and no tracking on the website
- No analytics tools (e.g. Google Analytics, Facebook Pixel)
- No advertising
- No sharing or selling of data to advertising partners
- No profiling
9. Retention
Events and the photos in them are limited in time. They are deleted automatically once an event has ended (usually around 30 days). If the host ends an event, final deletion follows after a short grace period; cancelling deletes immediately.
An avatar remains stored for your device until you change or remove it. Data on your device (device identifier, name, settings) is deleted when you uninstall the app. Server log files are stored only briefly.
The IP address stored at upload is deleted together with the respective photo. One exception applies to content reported as illegal: for these we keep a secured copy for as long as this is necessary to preserve evidence or to meet legal obligations. Details are set out in section 5.
10. Your rights (GDPR)
You have the right to:
- Access the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Lodge a complaint with a supervisory authority (Art. 77 GDPR)
Because we deliberately store no personal identifiers, we may need additional information from you in order to identify your data.
11. Contact for privacy matters
For questions about data protection, or to exercise your rights, write to:
You also have the right to lodge a complaint with the supervisory authority responsible for us: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, Germany.
12. Changes to this policy
We may amend this privacy policy, for example when features change or the legal situation develops. The current version is always available at calfira.app/datenschutz.php. Where changes are significant, we point them out inside the app.