Privacy policy
What we know — and what we don’t
As of September 26, 2026
This English version is provided for convenience. The German version is legally binding.
Short version: we store what we need to run your account, keep your projects and bill you. Your browser renders and exports your images and videos — we never see the finished exports. We use no analytics or advertising services, and our servers are in the EU. Everything else is below.
1. Controller
Ryvelia UG (haftungsbeschränkt) Wasserturmstraße 3 04442 Zwenkau Germany
Represented by the managing director: Kimon Neuhoff Phone: +49 173 1921654 Email: [email protected]
Where this policy says “we”, “us” or “Showoff”, it means Ryvelia UG (haftungsbeschränkt). Showoff is the name of the service at showoff.dev; it includes the website, the editor, the documentation at docs.showoff.dev and the app for pairing a phone.
2. Data protection officer
No data protection officer has been appointed; based on our ongoing review there is currently no obligation to appoint one. Send privacy requests to [email protected].
3. Who is responsible for what
For your account, your organization, billing, the security of the service and its technical operation, we are the controller within the meaning of the GDPR.
For the content you upload to your projects — screenshots, screen recordings, videos, audio, texts — you are responsible. Where it shows personal data, such as names or messages in a screenshot, we process it exclusively as a processor under Art. 28 GDPR: we store it and deliver it to your editor, we do not analyze it. If you use Showoff for business we sign a data processing agreement with you; write to us for it.
4. Legal bases
- Art. 6 (1) (b) GDPR — performance of the contract with you (account, projects, collaboration, billing, support).
- Art. 6 (1) (c) GDPR — legal obligations, in particular commercial and tax retention duties.
- Art. 6 (1) (f) GDPR — legitimate interests, in particular security, abuse prevention, error analysis and improving the documentation.
- Art. 6 (1) (a) GDPR — consent, where we explicitly ask you; revocable with effect for the future.
- Art. 28 GDPR — processing on your behalf for the content of your projects.
5. Visiting this website and server logs
When you visit showoff.dev, docs.showoff.dev or the editor, your browser transmits your IP address, date and time, the requested address, the referring link, browser and operating system. We process this data to deliver the pages and secure their operation (Art. 6 (1) (f) GDPR). Server logs are overwritten continuously and usually deleted after 30 days at the latest; longer only if an incident needs investigating.
Website, editor, database and uploaded files are hosted on a server of OVH GmbH (OVHcloud), St.-Johanner-Straße 41–43, 66111 Saarbrücken, Germany, in a data center in France. OVHcloud processes on our behalf under Art. 28 GDPR.
All requests to showoff.dev and its subdomains pass through Cloudflare (Cloudflare, Inc., San Francisco, USA, represented by Cloudflare Germany GmbH). Cloudflare provides DNS and TLS certificates, forwards the requests to our server and fends off attacks; in doing so Cloudflare processes IP addresses and request data (Art. 6 (1) (f) GDPR). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses apply in addition.
We serve fonts, device models and all other parts of the pages ourselves. No content is loaded from third-party servers.
6. Cookies and local storage
We only set strictly necessary cookies (§ 25 (2) TDDDG): a language cookie (“showoff_locale”, one year) that remembers the language version you last read, and after sign-in the session cookies of our authentication.
In your browser’s local storage we keep: the light/dark mode and, once you have rated a documentation page, a note about it (“showoff:docs-feedback:…”) so we do not ask again. A screen recording you make in the editor stays in your browser’s IndexedDB until its upload has finished, so that reloading the page does not lose it. None of this is transmitted to us before you upload it yourself.
There are no analytics, tracking or advertising services, no third-party cookies and no consent banners — because there is nothing to consent to.
7. Account and sign-in
For registration we process your email address, name, a password (hash only), the time of registration, your preferred language and session data (session identifier, IP address, browser, time of last activity). Optionally you upload a profile picture, set up two-factor authentication (secret and recovery codes) or passkeys (public key, device identifier). There is no sign-in via third parties such as Google or GitHub. The legal basis is Art. 6 (1) (b) GDPR; for session protection and abuse prevention Art. 6 (1) (f) GDPR.
8. Organizations, invitations and sharing
Projects and folders belong to an organization that can have several member accounts. We process the organization’s name and identifier, memberships and roles, and for invitations the invited person’s email address and the inviting account (Art. 6 (1) (b) GDPR). An invitation is deleted once accepted or expired.
Within an organization, members see each other’s name, email address and profile picture, for example when sharing a project with selected people. For every project and folder we store who may access it.
9. Projects and uploaded files
We store your scenes — devices, arrangement, camera, light, animation, texts — in our database, together with the name, folder, time of the last change, the person who last changed it, and a preview image rendered by your browser.
Images, videos, audio and screen recordings you upload are stored as files on our server. We deliver them to signed-in users only. When you remove a file from your projects or delete a project, a nightly clean-up deletes every file that no project, template or profile refers to any more, once it is older than one day.
10. Real-time collaboration
When you open a project in the editor, your browser keeps a WebSocket connection to our server. It carries your changes to the scene, which we store, and details that only matter for the moment: who currently has the project open (name and profile picture), mouse pointers, selection and playback. These details are held in memory only and disappear once the last window is closed (Art. 6 (1) (b) GDPR).
11. Pairing a phone
With our app you can pair a phone with a project. The editor shows a QR code containing an access code that is valid for one minute and issued only for you and this project. The app uses the camera only to read this code.
The paired phone sends orientation data (its position in space) and its device name through our server to the project’s open editor windows. We do not store them; only if you apply the orientation to the scene does it become part of the project.
The image of your phone’s screen and full-resolution screenshots are sent by the app via WebRTC directly to your browser, within the same local network and without relay servers. Only the messages for setting up the connection, including the local network addresses of both devices, pass through our server; the image itself never reaches us. Only when you add a screenshot or recording to the project is it stored like any upload (section 9).
12. Rendering and export
Your browser renders the scene on your device. Exporting images and videos also happens entirely in your browser; the exported files are saved directly on your device and not transmitted to us. For billing we record that and when an organization exported a rendering, not its content.
13. Billing and payment
Billing is per organization, according to the chosen plan. Usage, plan and invoices are managed with Autumn (Autumn Inc., USA) as our billing service; for this Autumn receives the organization’s identifier, name and handle, the name and email address of the person setting up billing, and the usage events. Payments are processed by Stripe Payments Europe, Ltd., Dublin, Ireland. Stripe processes payment data (card or account details, name, billing address, amount) under its own responsibility; full card details never reach us. We receive the payment status, the amount and the last digits of the payment method. We retain invoice data under § 147 AO and § 257 HGB for the statutory periods of up to ten years (Art. 6 (1) (b) and (c) GDPR). Standard contractual clauses apply to Autumn.
14. Emails
We send you the emails the service needs: confirmation of your address, password reset, notices about the security of your account, invitations to organizations and answers to your requests. We do not send advertising. Delivery runs through Resend (Plus Five Five, Inc., USA) on the basis of standard contractual clauses; Resend processes recipient address, subject, content and delivery status and tells us via webhook whether a message arrived.
15. Contact form and support
If you write to us through the contact form or by email we process your name, email address, phone number and company where given, and your message, in order to answer it (Art. 6 (1) (b) and (f) GDPR). Messages from the form reach us by email via Resend (section 14). We delete requests once they are settled and no retention duty applies.
16. Feedback on the documentation
Below every documentation page we ask whether it helped. If you answer, we store only the page, language, yes or no and the time — without IP address, account or browser identifier. We keep your IP address in memory for at most one hour to fend off mass submissions; it never reaches the database (Art. 6 (1) (f) GDPR).
17. Error reports
If an error occurs in the editor or the dashboard while you are signed in, your browser reports it to our server. We log the time, account identifier, requested address, error message, technical stack trace and browser so that we can fix it (Art. 6 (1) (f) GDPR). The reports are kept in the server logs and deleted with them.
18. Retention and deletion
- When you delete a project we delete the scene and its sharing settings immediately; the nightly clean-up removes the uploaded files once nothing refers to them any more.
- When you delete your account we delete the account, sessions, organizations without other members and all projects in them. When an organization is deleted, we also delete its customer account at Autumn and Stripe. Invoice data remains stored, restricted, for the statutory period.
- Server logs and error reports: usually 30 days at most.
- Feedback on the documentation contains no personal data and is kept.
- Contact requests: until settled, otherwise according to statutory periods.
19. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You may withdraw any consent at any time. Much of this you can do yourself in your account: export data, delete projects and your account. For everything else write to the address above.
You may lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Saxon Commissioner for Data Protection and Transparency, Devrientstraße 5, 01067 Dresden, Germany (datenschutz.sachsen.de).
20. Changes
We update this policy when the service or the legal situation changes. The current version is always available at this address; the date above shows its state. For material changes we inform signed-in users by email.
Any further questions? We are happy to help.
Get in touch