Privacy Policy
1. General Information
This Privacy Policy explains the nature, scope, and purpose of the processing of personal data on our website and in the Skazoria mobile application.
Certain data processing activities differ between the website and the mobile application. The following sections describe the respective processing activities applicable to each service.
2. Data Controller
The controller responsible for the processing of personal data is:
Eugen Batsin
Erkelenzer Str. 28
41844 Wegberg
Germany
Email: info@skazoria.com
3. Legal Bases for Processing
We process personal data in particular on the basis of the following legal grounds under the General Data Protection Regulation (GDPR):
- Article 6(1)(a) GDPR (Consent)
- Article 6(1)(b) GDPR (Performance of a contract)
- Article 6(1)(f) GDPR (Legitimate interests)
4. Data Collection on This Website
When you visit our website, your browser automatically transmits technical information to our servers. This processing is necessary to provide the website and to ensure its stability and security.
The data processed may include, in particular:
- IP address
- Date and time of the request
- Time zone
- Requested page or file
- HTTP status code
- Amount of data transferred
- Referrer URL
- Browser type and browser version
- Operating system
- Browser language settings
This information is processed exclusively for the secure operation of the website, error analysis, and the prevention of misuse. The legal basis for this processing is Article 6(1)(f) GDPR (Legitimate Interests).
5. Cookies and Web Analytics with Matomo
Our website uses technically necessary cookies that are required for the proper operation of the website. In addition, we use the self-hosted web analytics platform Matomo to analyze the use of our website and to improve our services. Matomo is hosted exclusively on our own servers. Analytics data is not shared with third parties.
Web analytics are carried out only with your prior consent in accordance with Article 6(1)(a) GDPR. You may withdraw your consent at any time via the cookie banner or the cookie settings. As part of the analytics process, the following data may be processed in particular:
- Pages visited
- Date and time of the visit
- Duration of the visit
- Referrer
- Browser type and browser version
- Operating system
- Screen resolution
- Language settings
- Anonymized IP address
Your IP address is anonymized before being stored and is not combined with any other personal data. For more information about Matomo, please visit:
https://matomo.org/privacy-policy/
6. Contact, Feedback and Participation Forms
Various forms are available on our website that allow you to contact us, submit feedback or ideas, apply to become a beta tester, or express an interest in contributing to Skazoria.
Depending on the form used, the following data in particular may be processed:
- first and last name or name
- email address
- content of messages, feedback or ideas
- preferred languages
- devices used or available for testing
- information about previous testing experience
- desired role or type of contribution
- portfolio or website link
- information about writing, editing or translation experience
- other information provided voluntarily
The data is processed exclusively for the purpose for which it was submitted. This includes, in particular, processing and responding to contact requests and feedback, reviewing submitted ideas, organizing the beta program, and contacting and coordinating with people who wish to contribute to Skazoria.
Where the contact is related to entering into or performing a contractual relationship, the processing is based on Art. 6(1)(b) GDPR. For other inquiries, processing is based on Art. 6(1)(f) GDPR due to our legitimate interest in processing and responding to inquiries and feedback and in organizing our services.
The submitted data will only be stored for as long as necessary for the respective purpose. It will subsequently be deleted unless statutory retention obligations or other legal grounds require or permit further storage.
7. Author Area / Content Editor
An internal author area is provided for the creation, editing, and management of content. The following personal data may be processed in particular:
- Name
- Email address
- Created and edited content
- Technical access data (e.g. IP address and login timestamps)
This processing is carried out exclusively for the purpose of providing, administering, and securing the author area, as well as managing the content created within it.
The legal basis for this processing is Article 6(1)(b) GDPR, where the processing is necessary for the performance of a contract or for taking steps prior to entering into a contract, and Article 6(1)(f) GDPR based on our legitimate interest in the secure and proper operation of the author area.
8. Hosting
This website is hosted by the following external hosting provider:
STRATO GmbH
Otto-Ostrowski-Straße 7
10249 Berlin
Germany
Email: datenschutz@strato.de
Further information about STRATO's privacy practices is available at:
https://www.strato.de/datenschutz/
We use this hosting provider to ensure the secure, fast, and reliable delivery of our online services. As part of the hosting services, server log files are processed. These may include, in particular:
- IP address
- Date and time of the request
- Requested pages or files
- Browser information
- Operating system
The processing is carried out on the basis of Article 6(1)(f) GDPR (our legitimate interest in the secure and reliable provision of our website). We have concluded a Data Processing Agreement (DPA) with the hosting provider in accordance with Article 28 GDPR.
9. Storage and Delivery of Content (Cloud Storage)
We use an external cloud storage provider, Wasabi Technologies LLC, for the storage and delivery of content. The service is used for the following purposes:
- Storage location: EU data center (Germany, region eu-central-2)
- Purpose: Storage and delivery of content (e.g. story data and media files)
We have concluded a Data Processing Agreement (DPA) with Wasabi Technologies LLC in accordance with Article 28 GDPR. When content is requested, technical data such as your IP address may be processed. The legal basis for this processing is Article 6(1)(f) GDPR (Legitimate Interests).
10. Skazoria Mobile Application
The Skazoria mobile application is designed for reading children's stories.
No registration is required to use the application. No user accounts are created, and no names, email addresses, or passwords are processed.
Each installation of the application is assigned a randomly generated installation identifier (UUID v4) when it is first launched. This identifier is used solely for the technical identification of an app installation and does not, by itself, allow any direct conclusions to be drawn about the identity of a natural person. Many features of the application operate entirely on the user's device. These include, in particular:
- Reading progress
- Favorites
- Ratings
- Downloaded content
- Language settings
- Reader settings
These data generally remain stored on the device and are not transmitted for analytical purposes without your explicit consent.
For technically necessary communication with our servers, the following data are processed:
- Installation ID
- Platform (Android or iOS)
- Application identifier
- Application version
- Technical application token
To ensure the secure and reliable operation of the application, technical log data are also processed whenever requests are sent to our servers. These data may include, in particular:
- IP address
- Date and time of the request
- Requested API endpoint
- HTTP status code
- Response time
- User-Agent
- Installation ID
- Platform
- Application version
These data are processed exclusively for the provision of the application, ensuring IT security, error analysis, and the detection and prevention of misuse.
The legal basis for this processing is Article 6(1)(f) GDPR (Legitimate Interests).
Unless a longer retention period is required to investigate specific security incidents or to comply with legal obligations, log data are deleted after a maximum of 90 days.
11. Voluntary Usage Statistics
The application can collect voluntary usage statistics. Usage statistics are disabled by default and are processed only after you have given your explicit consent. The legal basis for this processing is Article 6(1)(a) GDPR (Consent). Your consent is stored within the application under the identifier statistics-v2. Only the following information is collected:
- Synchronization success and synchronization duration
- Stories started
- Stories completed
- Story ID and story version
- Language
- Reading duration
- Reading progress
- Completion status
- Favorites
- Ratings (1 to 5 stars)
- Opened push notifications (only if push notifications have also been enabled)
No statistical events are generated or stored without your consent. Usage data collected before consent is granted is not transmitted retrospectively. While the application is used offline, only events that occur after consent has been granted may be stored. If consent is withdrawn, any statistical data that has not yet been transmitted will be permanently deleted. No personal usage profiles are created.
12. Anonymous Aggregate Statistics
To improve the application, pseudonymous statistical data may be permanently anonymized once a sufficient data basis has been reached.
Aggregation takes place no earlier than after:
- at least 180 days
- at least five different installations
The permanent aggregate statistics contain only:
- month
- story ID
- number of story starts
- number of story completions
- rating distribution (1 to 5 stars)
These data do not contain any installation ID, IP address, language settings, session data, or individual events. Once the aggregate statistics have been fully anonymized, they can no longer be linked to individual persons or devices and are currently retained indefinitely. If an installation is deleted before final anonymization, its contributions are removed from any analyses that have not yet been anonymized.
13. Push Notifications
Push notifications are optional and are activated only after you have given your explicit consent.
For the delivery of push notifications, we use Firebase Cloud Messaging (FCM), a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Automatic initialization of Firebase Cloud Messaging remains disabled until you provide your consent. Your consent is stored within the application under the identifier push-v1.
Once push notifications have been activated, the following data may be processed in particular:
- Firebase Cloud Messaging token (FCM token)
- cryptographic HMAC-SHA-256 hash value of the FCM token (token hash)
- installation ID
- platform (Android or iOS)
- language
- push notification permission status
- delivery status
- technical errors
- dates and times of token registration and token updates
The FCM registration token is stored in encrypted form on our servers.
In addition, we store a pseudonymous verification value generated using HMAC-SHA-256 (token hash). This is used exclusively to reliably detect duplicate push registrations or push registrations transferred to another installation and to ensure the integrity of push registrations.
Push notifications are sent only where you have consented to this feature.
The opening of a push notification is recorded only where you have also consented to voluntary usage statistics.
If you withdraw your consent to push notifications, the stored FCM token, the associated HMAC-SHA-256 verification value, and the push registration stored on our servers will be deleted.
The application does not use Firebase Analytics, does not use Firebase Crashlytics, does not display advertising, and does not create advertising profiles or user profiles.
When Firebase Cloud Messaging is used, personal data may also be processed outside the European Union. Google states that it uses appropriate safeguards in accordance with Article 46 GDPR, in particular Standard Contractual Clauses (SCCs).
Further information is available at:
Google Privacy Policy: https://policies.google.com/privacy
Firebase Privacy and Security Information: https://firebase.google.com/support/privacy
14. Data Retention
Personal data are retained only for as long as necessary to fulfill the respective processing purpose.
The following retention periods generally apply:
- API logs: 90 days
- Technical metadata of inactive installations: 90 days
- Installation data: up to 365 days without activity
- Pseudonymous raw statistical data: up to 210 days
- Fully anonymized aggregate statistics: currently retained indefinitely
Data stored locally on your device remain on the device until they are deleted.
15. Your Rights
Subject to the applicable legal requirements, you have the following rights under the GDPR:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to withdraw your consent at any time with effect for the future
- Right to lodge a complaint with a competent data protection supervisory authority
If you wish to exercise any of these rights, please contact us at:
Email: info@skazoria.com
Deleting Your Data Within the Application
Using the "Delete My Skazoria Data" feature, you can delete all locally stored data as well as all installation-related data stored on our servers.
If you continue using the application afterwards, a new installation ID will be generated automatically.
Once aggregate statistics have been fully anonymized, they can no longer be associated with individual installations and therefore cannot be deleted.
16. Children and Parents or Legal Guardians
Skazoria is intended for children and their families.
Protecting children's privacy is particularly important to us. For this reason, the application processes only the personal data that are necessary for its operation.
Optional features such as usage statistics and push notifications are activated only with voluntary consent and can be disabled again at any time.
The application currently does not include a technically verified age verification system or parental approval mechanism.
The decision to use the application and to enable optional features rests with the person who manages the device or configures its settings.
We encourage parents and legal guardians to accompany younger children while using the application and to configure the privacy settings together.
17. Data Security
We implement appropriate technical and organizational measures in accordance with Article 32 GDPR to protect personal data against loss, misuse, unauthorized access, alteration, or disclosure.
These measures include, in particular:
- Encrypted data transmission (TLS)
- Access controls
- Regular security updates
- Measures to protect our servers and applications
Access to personal data is restricted to authorized persons and is granted only where necessary for the performance of their respective duties.
18. Changes to this Privacy Policy
We reserve the right to amend this Privacy Policy at any time to ensure that it complies with current legal requirements or reflects changes to our services.
The latest version published on our website shall always apply.
Document Version: 1.0.1
Last Updated: 30 August 2026
