Privacy Policy
Last updated: 27 July 2026
This Privacy Policy explains how we process personal data when you use the Vink mobile application and related services ("Vink", the "App"). Vink is a market-research style app in which adult users upload their own photos and receive aggregated feedback on how members of different demographic groups responded to them. The App is strictly for users aged 18 and over.
1. Controller
The controller responsible for the processing of your personal data is:
Tom Skoropinski, trading as TSK Software (sole proprietorship)
Raiffeisenstraße 2, 63633 Birstein, Germany
Email: contact@vink-app.com
We have not appointed a Data Protection Officer. Under Art. 37 GDPR we are not required to do so, because our core activities do not consist of large-scale processing that requires regular and systematic monitoring or large-scale processing of special categories of data.
2. What data we process, why, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, password (hashed), authentication tokens | Create and secure your account; sign you in | Art. 6(1)(b) GDPR (performance of a contract) |
| Photos you upload | Show them to other users for rating and display your own results | Art. 6(1)(b) GDPR |
| Profile data you provide (date of birth / age, gender, height, country) | Operate the service; produce the demographic statistics shown to photo owners; enforce the 18+ requirement | Art. 6(1)(b) GDPR; for any data revealing a special category, Art. 9(2)(a) (explicit consent) |
| Ratings you give and receive, derived scores and statistics | Provide the core feedback feature; rank photos in the rating queue | Art. 6(1)(b) GDPR |
| Reports, moderation records, block lists | Content moderation, safety, abuse and fraud prevention, compliance with the Digital Services Act | Art. 6(1)(f) GDPR (legitimate interest in a safe service); Art. 6(1)(c) GDPR (legal obligation) |
| Device push tokens | Send you notifications you have enabled | Art. 6(1)(b)/(a) GDPR |
| Transactional emails (e.g. email verification, account and safety notices) | Operate and secure your account | Art. 6(1)(b) GDPR |
| Bot-/fraud-prevention signals (e.g. interaction timing) | Protect the integrity of ratings | Art. 6(1)(f) GDPR |
| Product-analytics events | Understand and improve the App | Art. 6(1)(a) GDPR (consent) — only if you opt in |
| Server and security logs | Operate, secure and debug the service | Art. 6(1)(f) GDPR |
You do not have to provide profile data beyond what is needed to run the service, but some features will not work without it (for example, demographic statistics need your demographic data).
3. How your score is calculated
Your score and statistics are calculated from the ratings given by other members of the community — they are human votes, aggregated and presented back to you. At present we do not run any artificial intelligence on your photos to generate or adjust your score, and we do not create biometric templates to uniquely identify you.
If we introduce automated or AI-based analysis of photos in the future, we will update this Policy, obtain any consent required, and clearly label any score or output that is generated by such automated means, in line with Art. 50 of Regulation (EU) 2024/1689 (the EU AI Act), whose transparency obligations apply from 2 August 2026.
The same applies if we later develop or train our own models. We will not use your photos or the ratings you give to develop or train a model unless you have given separate, opt-in consent for that specific purpose (Art. 6(1)(a) GDPR; where photos of you are involved, additionally your explicit consent under Art. 9(2)(a) GDPR). That consent is optional, is asked for separately from using the App, and you can withdraw it at any time in the App's settings. Until you give it, your data is used only to run the service as described in this Policy.
4. Special categories of data
A photograph of a person may, in some circumstances, allow inferences about special categories of data within the meaning of Art. 9 GDPR. We do not currently use your photos to derive such data, we do not perform biometric identification, and at launch we do not run AI on your photos. Where any processing we carry out would involve special categories of data — including any future model development or training as described in Section 3 — we rely on your explicit consent (Art. 9(2)(a) GDPR), which is optional and which you can withdraw at any time.
5. Profiling and automated decision-making
We use your demographic data together with community ratings to produce aggregated statistics for you and to order the photos shown in the rating queue (using a statistical ranking method). This constitutes profiling within the meaning of Art. 4(4) GDPR, and we disclose it to you here in accordance with Art. 13(2)(f) GDPR.
This processing does not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22(1) GDPR: your score is informational feedback shown to you as the owner of the photo. It does not gate access to features, it does not control who can contact or match with you, and it does not determine whether you are shown to other users. We do not make solely automated decisions with legal or similarly significant effects about you.
6. Recipients and processors
We use the following service providers, who process personal data on our behalf as processors under Art. 28 GDPR (or, where indicated, govern their own processing once you choose to share with them):
| Service | Provider | Purpose | Location / transfer safeguard |
|---|---|---|---|
| Database, authentication, file storage | Supabase | Store your account, profile and photos | EU region; Standard Contractual Clauses where applicable |
| Push notifications, crash diagnostics | Google / Firebase (Google Ireland Ltd.) | Deliver notifications; diagnose crashes | May be processed in the USA under the EU–US Data Privacy Framework, with Standard Contractual Clauses as a fallback |
| Transactional email | Brevo | Send verification and service emails | EU |
| Automated image moderation | Sightengine | Screen uploaded photos for prohibited (e.g. explicit) content before storage | EU; some processing may take place outside the EU under Standard Contractual Clauses |
| Product analytics | PostHog (EU Cloud) | Usage analytics — only if you opt in | EU |
| Application hosting | Render (Render Services, Inc.) | Run the App's backend | EU region (Frankfurt, Germany); the provider is US-based and certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses as a fallback |
Instagram / Meta: the App lets you share an image to your Instagram Story. This uses your device's operating-system sharing function; we do not transmit your data to Meta in the background and Meta is not our processor for this feature. If you choose to share, the sharing and anything you post is handled by Instagram under Meta's own privacy policy.
We do not sell your personal data, and we do not share it with third parties for their own purposes except as described in this Policy or where required by law.
7. International transfers
Where a provider processes data outside the EU/EEA (see the table above), we rely on an adequacy decision (such as the EU–US Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses together with appropriate supplementary measures. You can request more information about these safeguards using the contact details in Section 1.
8. Retention
| Data | Retention |
|---|---|
| Your photos and data derived from them (scores, statistics) | Deleted within 30 days of account deletion or withdrawal of the relevant consent |
| Account and profile data | For the life of your account; inactive accounts are deleted after 24 months of inactivity |
| Ratings you have given to others | Anonymised on account deletion (kept in aggregate so other users' results remain valid) |
| Server and security logs | 14 days |
| Moderation and report records | Up to 3 years, to handle disputes and establish, exercise or defend legal claims |
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing is based on consent, you may withdraw your consent at any time, as easily as you gave it, without affecting the lawfulness of processing before withdrawal.
You can delete your account at any time directly in the App (Settings → Delete account). This permanently deletes your photos and the data derived from them; your demographic data is not exempt from deletion or correction. Information on deleting your account is also available at https://vink-app.com/delete-account/.
You also have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
Postfach 3163, 65021 Wiesbaden, Germany — https://datenschutz.hessen.de
10. Cookies, SDKs and consent
The App uses storage and software development kits (SDKs) that are strictly necessary to provide the service. Non-essential SDKs — in particular our product-analytics SDK — are only loaded and allowed to store or read information on your device after you have given your consent, in line with § 25 TDDDG. You can change your choice at any time in the App's settings.
11. Children
Vink is intended exclusively for adults. You must be at least 18 years old to use it. We do not knowingly process data of anyone under 18; if we learn that an account belongs to a minor, we delete it.
12. Changes to this Policy
We may update this Policy to reflect changes to the service or the law. We will update the "Last updated" date above and, where appropriate, notify you in the App. The version published at https://vink-app.com/privacy/ is authoritative and is kept identical to the version shown in the App.
13. Contact
For any privacy request or question, contact us at contact@vink-app.com.