Privacy Policy
This policy explains which personal data we process when you use UNLOCKY, why we process it, and which rights you have under the GDPR.
1. Controller
Papi App UG (haftungsbeschränkt), Friedrichstraße 155, 10117 Berlin, Germany, represented by the managing director Michele Lipski.
Email: papi.app.world@gmail.com · Phone: +49 152 37778618. Commercial register: Amtsgericht Charlottenburg, HRB 289191 B.
2. Scope
This policy covers the UNLOCKY web application. We only describe processing that actually takes place in the application. We do not operate advertising networks, we do not use third-party analytics or tracking pixels, and we do not set marketing or tracking cookies.
3. User account and registration
To use the platform you create an account. Authentication is handled by our backend provider (Supabase, operated via the Lovable Cloud platform). Depending on the sign-up method we process:
- Email address and a securely hashed password (email/password sign-up),
- the account data supplied by Google when you use “Continue with Google” (Google account identifier, email address, and — if provided — name and profile picture),
- account metadata such as the account ID, creation date, and last sign-in.
Legal basis: Art. 6(1)(b) GDPR (performance of the user contract). When you sign up you confirm that you are at least 18 years old and accept our Terms & Conditions.
4. Profile and public profile information
Your profile contains a username, an optional display name, an optional bio and an optional profile photo. This information, together with your public unlocks and your position in the public creator ranking, is visible to other users and to visitors of your public profile page. Previous usernames are stored so that old profile links keep working after a username change. Do not publish data in your profile that you do not want to be public. Legal basis: Art. 6(1)(b) GDPR.
5. Unlocks and uploaded content
When you create an unlock we store its title, description, price, visibility status, sales counters and the uploaded media files. Media files are stored in private storage buckets. Original files and previews are never public: they are delivered exclusively through short-lived signed URLs, and access to the original file is only granted after the server has verified a completed purchase or your ownership of the content. Access rules are additionally enforced in the database through row level security. Legal basis: Art. 6(1)(b) GDPR.
6. Messages and conversations
Messages you send are stored together with sender, recipient, timestamp, message type (text, media or paid unlock) and any attachments, so that conversations can be displayed. Messages are not end-to-end encrypted. Reported conversations may be reviewed by our moderation team to investigate the report. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (platform safety and legal compliance).
7. Purchases, transactions and payments
Payments are processed by Stripe Payments Europe, Ltd. We create a Stripe Checkout session and redirect you to Stripe. Card data and other payment credentials are entered directly on Stripe’s systems; we never receive or store full payment card details. Stripe acts as an independent controller for payment processing and fraud prevention.
We store in our own database:
- the purchased unlock, the buyer and seller account, the amount, the buyer service fee and the creator fee,
- the purchase status (pending, paid, refunded, disputed, failed),
- the Stripe checkout session and payment intent identifiers,
- the timestamp of the transaction.
Stripe sends signed webhook notifications about completed payments, refunds and disputes; these events are verified and recorded server-side. Content is only unlocked after this server-side verification. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR (accounting obligations).
8. Payouts
If you sell content as a creator, we store the data required to pay you out: the account holder name, the last four digits of your IBAN and an internal reference (the full account details are not kept in the application), your billing address (first name, last name, street, house number, postal code, city, country) and the status and amount of your payout requests. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR.
9. Creator verification
Before payouts can be released, creators must complete a manual identity check. For this purpose you upload a selfie and an identity document. These documents are stored in a private storage bucket that is only accessible to our review team, together with the verification status (not submitted, pending review, approved, rejected) and, where applicable, a rejection reason. Identity documents may contain special categories of data; you provide them voluntarily on the basis of your explicit consent (Art. 9(2)(a) GDPR) in combination with Art. 6(1)(b) and (c) GDPR. You can withdraw this consent at any time by contacting us, in which case payouts cannot be processed.
10. Reports and blocks
If you report content, a user or a conversation, we store the report, the reported object, the reporting account, the reason and the moderation result. Blocks you set are stored as a relation between the two accounts. Legal basis: Art. 6(1)(f) GDPR (protection of users and of the platform) and Art. 6(1)(c) GDPR (legal obligations regarding illegal content).
11. Notifications
We store in-app notifications about events that concern your account, for example sales, new messages or the result of your verification.
11a. Cookies and consent
We only set strictly necessary cookies and local storage entries without your consent — they keep you signed in, secure the service and run the Stripe checkout (§ 25(2) TTDSG, Art. 6(1)(f) GDPR). Functional, analytics and marketing technologies are used exclusively on the basis of your consent (§ 25(1) TTDSG, Art. 6(1)(a) GDPR) and are not loaded before you agree.
On your first visit a consent banner is shown; your decision is stored locally in your browser so it is not requested again on every page. You can change or withdraw it at any time with effect for the future on our Cookie Settings page.
12. Technical and security data
When the application is accessed, our hosting infrastructure and our backend provider process technical connection data such as IP address, date and time of the request, the requested resource, HTTP status and user agent. This data is used to deliver the service, to keep it secure and to detect abuse. In addition, the application reports technical errors (error message, technical stack trace, affected page) to the hosting platform so that faults can be fixed. Legal basis: Art. 6(1)(f) GDPR.
Fonts are loaded from Google Fonts (Google Ireland Limited). Your IP address is transmitted to Google for this purpose. Legal basis: Art. 6(1)(f) GDPR (consistent presentation of the service).
We use only technically necessary storage in your browser (in particular the login session token). We do not use tracking or advertising cookies.
13. Processors and recipients
- Supabase / Lovable Cloud — database, authentication, file storage and hosting of the application.
- Stripe Payments Europe, Ltd. — payment processing, refunds and dispute handling.
- Google (Google Ireland Limited) — sign-in with Google (only if you use it) and delivery of web fonts.
- Public authorities, where we are legally obliged to disclose data.
Where data is transferred outside the EU/EEA by these providers, the transfer is based on the EU standard contractual clauses or another valid transfer mechanism.
14. Storage period and deletion
We store your data for as long as your account exists. You can delete your account at any time in your profile settings. Deletion removes your profile, your unlocks and your uploaded files, including avatars, media, previews and verification documents.
If paid transactions exist for your account, the transaction records are retained to comply with statutory commercial and tax retention obligations (generally 6 to 10 years under German law, §§ 147 AO, 257 HGB). In that case your profile is closed and anonymised instead of being fully removed.
15. Your rights
Under the GDPR you have the right to:
- access to your personal data (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR),
- withdraw consent you have given, with effect for the future (Art. 7(3) GDPR).
To exercise these rights, contact papi.app.world@gmail.com. You also have the right to lodge a complaint with a data protection supervisory authority, for example the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
16. Changes to this policy
We may update this policy when the application or the legal requirements change. The current version is always available at /privacy. Material changes will be communicated in the application.
Last updated: 20 August 2026