Privacy policy

Kinkventory manages a collection that allows conclusions about a person's sex life. Under Art. 9 GDPR that is a special category of personal data — which is why the app is built so that this data ideally never leaves the device at all.

Last updated: 29 August 2026

The short version.

1. Controller

Udysseus GmbH
Technologiepark 6
33100 Paderborn, Germany
Represented by its managing director, Maximilian Schmöcker
Phone: +49 5251 297 2162
E-mail: datenschutz-kinkventory@udysseus.com

No data protection officer has been appointed, as the statutory conditions for doing so are not met. Privacy enquiries go to the address above.

2. This website

When you open this site, the server processes the access data technically required to deliver it: IP address, time, path requested, status code, volume transferred, browser identification. The legal basis is Art. 6(1)(f) GDPR — the legitimate interest in secure, functioning operation. Logs are deleted after seven days at the latest.

Nothing else. This site sets no cookies, uses no analytics, loads no fonts or scripts from third-party servers and embeds no third-party content. That is also why there is no consent banner: there is nothing to consent to.

The site is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, on servers in Germany, under a data processing agreement pursuant to Art. 28 GDPR.

3. The app: what stays on the device

Everything you record in Kinkventory — items, photos, categories, sizes, prices, storage locations, outfits, events, packing lists, care log — is stored locally on your iPhone. There is no user account, no registration and no server holding your collection. We have no access to this data.

For this on-device processing we are not the controller — it happens entirely on your side. We become the controller where data reaches our server: for image recognition and for credits.

4. Image recognition (only with your consent)

Automatic recognition is the only function where data leaves the device. It is off by default. Before it can be switched on, the app sets out what will be sent; in addition, before every single analysis it shows the specific images and the specific receipt text and waits for your confirmation.

What is sent

Not sent: the rest of your collection, storage locations, events, outfits, notes, names or contact details. If the app detects faces in a photo, it says so before sending.

Where to, and for how long

The request goes to our analysis server (Hetzner Online GmbH, Germany) and from there once to the model provider Anthropic PBC, 548 Market St, San Francisco, CA 94104, USA, which performs the evaluation as a processor. The transfer to the USA is based on the European Commission's standard contractual clauses pursuant to Art. 46(2)(c) GDPR.

Our server stores neither photos nor receipt texts nor responses. They stay in memory for the duration of the evaluation and are discarded afterwards. The only store holding content is a technical cache lasting 24 hours, which ensures that a dropped connection does not destroy a result you already paid for; it is deleted automatically. At the model provider, content is, per its commitment, not used for training and retained for at most 30 days for abuse detection.

The legal basis is your explicit consent under Art. 9(2)(a) in conjunction with Art. 6(1)(a) GDPR. You can withdraw it at any time in the app's settings; from that point no photo leaves the device. The lawfulness of processing carried out beforehand is unaffected.

5. Account identifier, device attestation and credits

For credits, the server needs an anchor without knowing who you are. The app therefore uses a randomly generated identifier (UUID). It contains no name, no e-mail address, no device ID and no password, and we cannot link it to a person.

To improve recognition we additionally count how often each root category was requested in total. That count carries no account reference and cannot technically be joined to the ledger entries. The question "which account analysed what" is therefore unanswerable for us as well — which is the point of the separation.

The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement, in particular correct accounting of credits) and (f) (legitimate interest in abuse protection and in improving recognition quality). Ledger entries are kept for the duration of statutory commercial retention periods.

6. Purchases

Credits are purchased exclusively through the App Store. The payment is handled by Apple; we receive neither your name nor your payment details, only Apple's signed proof that a particular purchase took place. For processing within the App Store, Apple is the controller in its own right and Apple's privacy policy applies.

7. Backup and iCloud

The encrypted export writes your collection into a file protected by your password (PBKDF2 and AES-GCM). Where you keep that file is your decision; we never receive it.

The optional iCloud sync is off by default and runs through your own iCloud. The data then sits in your Apple account, not with us. The provider is Apple and Apple's privacy policy applies.

8. Recipients at a glance

RecipientPurposeWhereWhen
Hetzner Online GmbHHosting of website and analysis serverGermanyalways
Anthropic PBCEvaluation of the photos and texts sentUSA (standard contractual clauses)only with image recognition enabled
Apple Inc. / Apple Distribution InternationalApp Store, purchases, App Attest, DeviceCheck, optional iCloudEU/USAdepending on the function

There are no other recipients. Your data is not sold, not used for advertising and not combined with data from other sources. No automated decision-making with legal effect takes place: recognition makes suggestions, which you confirm or discard.

9. Your rights

Access (Art. 15 GDPR)
Which data we hold under your account identifier.
Rectification (Art. 16), erasure (Art. 17), restriction (Art. 18)
You delete your collection yourself by removing the app — we do not have it. Ledger data under your identifier we delete unless a statutory retention obligation prevents it.
Portability (Art. 20)
For your collection, the export inside the app is the direct route.
Objection (Art. 21)
Against processing based on legitimate interests.
Withdrawal (Art. 7(3))
Consent to image recognition, at any time via the switch in the app.
Complaint (Art. 77)
With a supervisory authority; the one competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Important for access requests: since we do not know who you are, we can only match a request via the account identifier. You will find it in the app's settings. Without it we cannot make the link, pursuant to Art. 11(2) GDPR — that is the flip side of our not keeping accounts.

Requests to datenschutz-kinkventory@udysseus.com.

10. Children and young people

The app is intended for people aged 16 and over and is rated accordingly in the App Store. We do not knowingly process data of anyone under 16.

The age limit has a second reason: consent to image recognition must be something the person concerned can give validly themselves. In Germany that is the case from the age of 16 (Art. 8(1) GDPR), in France from 15. Below that threshold it would take a parent's consent — and a procedure for obtaining it that would let that parent look into the collection. That is precisely what should not exist.

11. Changes

If the processing changes, we change this policy and update the date above. A change that affects your consent is obtained afresh in the app rather than quietly assumed here.