Privacy Policy
Last updated: 28 September 2026
This policy explains which personal data is processed when you use supinion, what we use it for and how long we keep it. The German version of this policy is legally binding; this English version is provided for convenience.
It has three parts:
- Part A – the website supinion.com with its public pages and templates,
- Part B – the app for everyone who has an account and creates presentations,
- Part C – audience members who join a poll, quiz or Q&A via QR code or access code.
After that come the sections that apply to all parts: recipients, transfers to third countries, retention, security and your rights.
1. Controller
TELEPANO, owner: Noel Weinberg
operating the brand 1337 Studios; supinion is a service of 1337 Studios.
Eurotec-Ring 15
47445 Moers
Germany
Phone: +49 2841 8887410
Email: hi@supinion.com
We have not appointed a data protection officer because we are not required to (Section 38 BDSG). Please send data protection questions to hi@supinion.com.
2. The short version
- We use no trackers in your browser, no third-party scripts and no advertising cookies. We measure the reach of our public pages on the server with Matomo, without cookies and without IP addresses (A.7).
- The website loads nothing from third-party servers: no external fonts, no third-party scripts, no content delivery network. A Content Security Policy (
script-src 'self') only allows scripts from our own server. - We do not store IP addresses and keep no access logs.
- All data is stored on our own virtual server operated by Hetzner Online GmbH in its Falkenstein (Germany) data centre.
- Audience members need no account. They only have to give a name if the presenter requires it; a nickname is enough (C.2).
3. When we are the controller – and when we act as a processor
We are the controller for the website (Part A), for accounts, sign-in and payment (Part B) and for handling reports (section C.7).
Presentations, slides, images and audience responses are processed on behalf of whoever uses supinion – for example a school, a company or an event organiser. That organisation is the controller within the meaning of Art. 4(7) GDPR. On request to hi@supinion.com, we conclude a data processing agreement with it under Art. 28 GDPR. If you have questions about a specific poll, please contact the person or organisation that ran it; we forward requests we receive to them.
Part A – Website
A.1 Visiting the website
When you visit the website, your browser transmits technically necessary information to our server, including your IP address, the requested address and browser details. We need this information to deliver the page.
- No logs: The web server writes no access logs. IP addresses are not stored.
- Protection against overload: To slow down abuse (such as mass requests), we derive a key from the IP address that is hashed with a random value (salt) that changes daily; for IPv6 only the /64 address block is used. This key exists only in memory and is never written to disk.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable delivery of the website.
A.2 No trackers in your browser, no embedded third-party content
We do not load any analytics or marketing services into your browser, load no third-party scripts and embed no third-party content (no videos, maps, fonts or social media buttons from other servers). We measure the reach of our public pages exclusively on the server, without cookies and without your IP address (A.7). That is why there is no cookie banner: we only set strictly necessary cookies (see B.3).
A.3 Referral links (?ref= parameter)
Some links to supinion contain an addition such as ?ref=… indicating where a visit came from (for example a template or a recommendation). We count these sources on the server, without a cookie and without storing anything on your device.
- A mere visit only increases a counter per source; no link to you as a person is created.
- If you then start a trial or create an account, we link the source to the account ID so that we can see which paths lead to new accounts.
- Legal basis for this link: Art. 6(1)(f) GDPR. Our legitimate interest is understanding how people find supinion without using tracking tools in your browser. You may object (section 8).
- Retention: counters and links are deleted after 180 days. If you delete your account before then, we remove the link to the account ID immediately; only the number remains.
A.4 Storage in your browser
Besides cookies (B.3), supinion keeps a few entries in your browser's storage. Entries in local storage (localStorage) remain until you delete the website data in your browser; entries in session storage (sessionStorage) disappear as soon as you close the tab. None of these entries is transmitted to us; they are only read in your browser.
| Entry | Storage | Purpose | Duration |
|---|---|---|---|
youpi-lang | localStorage | the language you explicitly chose (de or en) | until deleted in the browser |
youpi:presentTip | localStorage | remembers that you have already seen the tip about presenting | until deleted in the browser |
youpi:nick:<access code> | localStorage | remembers that you were already asked for a name in this session; the name itself is not stored in it | until deleted in the browser |
youpi:beforeBuy | sessionStorage | your plan status before a purchase, to detect the activation after you return from Stripe | until the tab is closed |
youpi:<access code>:<slide> | sessionStorage | your own answers on a slide, so they stay visible after reloading the page | until the tab is closed |
The legal basis for storing and reading these entries is Section 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act): they are strictly necessary for supinion to work the way you use it.
A.5 Contact by email
If you email us, we process your address and the content of your message to answer you. The legal basis is Art. 6(1)(b) GDPR where your request concerns a contract or its preparation, otherwise Art. 6(1)(f) GDPR (answering enquiries).
A.6 Enquiries from schools and universities, EDU verification
For school and campus licences you can send an enquiry using a form. We process your name, organisation, email address, size and message.
For the EDU plan we check eligibility as follows: if the email address of your account clearly belongs to a school or university, we unlock EDU automatically and only store this note with your workspace. Otherwise you tell us your school and, if you like, add a note, and we check manually. For this we also process the name and email address from your account. You do not upload any files.
- Purpose: handling the enquiry, checking eligibility for the EDU plan.
- Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps).
- Retention: 12 months in the database, then deleted automatically. Each enquiry is also sent by email to our mailbox; there we delete it once it has been handled, after 12 months at the latest. The EDU note remains until the account is deleted.
A.7 Audience measurement with Matomo
To understand how often the public pages of the website are visited and which channels visitors come from, we use the open-source software Matomo. Measurement happens exclusively on the server: our server reports a page view directly to our Matomo installation at stats.telepano.de. No script runs in your browser for this, no cookies are set and nothing is stored on or read from your device.
- Which pages: only the public pages of the website (home page, pages for schools, events and universities, comparison with Mentimeter, templates, imprint, privacy policy, point of contact and reports). The app, joining a poll by access code or QR code and all live views are never measured.
- Data transmitted: the address of the page visited, keeping only the campaign parameters
ref,utm_…andmtm_…from any additions; the referring page (referrer), shortened to the domain and only if you come from another website; the language (German, English or not specified); a rough device class (smartphone, tablet or computer). We do not transmit your full browser identifier but a generic sample identifier per device class. Browser and operating system figures in the statistics are therefore not meaningful. - No IP address: your IP address is not transmitted. We replace it with the placeholder 0.0.0.0; no location is determined.
- No recognition: every page view receives a new random identifier. Several page views by the same person cannot be linked; Matomo counts each page view as a separate visit.
- Events: we also count when a trial is started, an account is created or a plan is purchased – only with the source from the referral link (A.3) or the plan purchased, without email address, account ID or any other identifier.
- Purpose: measuring the reach of the website and the effectiveness of our channels.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is improving the website and our communication. We do not access your device for this. Since we do not transmit any identifier, we can neither attribute individual page views nor remove them afterwards.
- Recipients: we operate Matomo ourselves. The server of stats.telepano.de is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (data centres in Germany), acting as our processor.
- Retention: raw data is deleted after 180 days; after that only aggregated reports without individual page views remain.
Part B – App (accounts)
B.1 Account and sign-in by code
supinion works without passwords. To sign in, you enter your email address and receive a 6-digit code by email.
- Data: email address; optionally name and role (teacher, trainer, event or company); chosen language; timestamps (such as creation and last sign-in).
- Sign-in codes are not stored in plain text, only as an HMAC (a check value computed with a server key). A code is valid for 10 minutes; the check value is kept for one day and then deleted.
- Session tokens are stored only as a SHA-256 hash.
- Purpose: providing the account and the app.
- Legal basis: Art. 6(1)(b) GDPR. We use the role to suggest suitable templates; the legal basis for this is Art. 6(1)(f) GDPR. Name and role are optional.
- Retention: until the account is deleted (B.8).
B.2 Trying supinion without an account
You can try supinion without creating an account. For this we create a guest account with a placeholder address – we do not need your email address.
- If you sign up within 7 days, the content of your trial is moved into your account.
- Otherwise we delete the guest account after 7 days together with all content.
- Legal basis: Art. 6(1)(b) GDPR.
B.3 Cookies
We only set strictly necessary cookies. They cannot be read by scripts (HttpOnly) and are not sent along to other websites (SameSite=Lax).
| Cookie | Purpose | Lifetime |
|---|---|---|
youpi_session | keeps you signed in | expires after 90 days without use, at the latest after 400 days; guest accounts 7 days |
youpi_p | recognises a device within a live session (random token, see Part C) | 24 hours |
The legal basis for setting them is Section 25(2) no. 2 TDDDG; for the subsequent processing Art. 6(1)(b) GDPR (account) or Art. 6(1)(f) GDPR (participation, see C.2).
B.4 Presentations, images and results
Whatever you create in supinion – presentations, slides, uploaded images (for example from a PDF import), logos and the results of your live sessions – is stored so that we can provide the app. Where an organisation uses supinion, we do this as its processor (section 3).
- Results of a session are kept for 12 months after the session ends. You can delete them earlier at any time with one click.
- Deleted presentations stay in the bin for 30 days and are then permanently deleted.
- Images no longer used by any slide or logo are deleted after 30 days.
- Legal basis, where we are the controller: Art. 6(1)(b) GDPR.
B.5 Teams and invitations
If you invite others to your workspace, we process their email address to send the invitation. Invitations that are not accepted are deleted after 30 days. The legal basis is Art. 6(1)(b) GDPR towards the inviting workspace and Art. 6(1)(f) GDPR towards the invited person (legitimate interest in working together as a team).
B.6 Payment
Paid plans can be purchased by organisations and – once we enable sales to consumers, with a billing address in the EU – by private individuals. For organisations we process the organisation's name, address, country, VAT ID and billing email for invoicing.
Buying as a private individual. If you buy as a private individual, we process your first and last name instead of an organisation name, plus address and email address. For each purchase we also keep as evidence: contract number, plan, price including VAT, time of the order and of the conclusion of the contract, the end of the withdrawal period and – if you ticked it – the date and time of your request that we begin before the withdrawal period ends. After a withdrawal, the time, the compensation for the service provided and the refund amount are added. Refunds go back to your payment method via Stripe.
Cancellations and withdrawals. When you submit a statement via "Cancel contracts here" or "Withdraw from contract", we store its content (type of cancellation, reason and requested date where given), your name, your email address, what you stated about the contract, the date and time of receipt and the outcome. No sign-in is required; we match the statement to your contract by email address and contract number. We send the acknowledgement of receipt to the address given. We do not store IP addresses. To prevent mass requests we count requests in memory only, with a key that changes daily (see rate-limit keys).
- Legal basis: Art. 6(1)(b) GDPR (the contract and its termination), Art. 6(1)(c) GDPR (obligations under Sections 312f, 312k and 356a of the German Civil Code: confirming contracts, cancellations and withdrawals) and Art. 6(1)(f) GDPR (proof that we handled cancellations and withdrawals correctly; legitimate interest in establishing and defending legal claims).
- Retention: cancellation and withdrawal statements together with our confirmation until the end of the sixth calendar year after receipt (business letters, Section 147 (1) nos. 2 and 3, (3) German Fiscal Code (AO); Section 257 German Commercial Code (HGB)). Purchase records with payment and refund until the end of the eighth calendar year after the contract ends (accounting records, Section 147 (1) no. 4, (3) AO). These records remain even if you delete your account (Art. 17(3)(b) and (e) GDPR). Orders that were never paid are deleted after 30 days.
The payment itself is handled by Stripe Payments Europe, Ltd. (Ireland) – with the payment methods offered there (such as card). You enter payment details (such as card number or IBAN) directly with Stripe; we do not receive them. Stripe describes its own role as acting as controller or processor depending on the activity, including as controller for fraud detection and legal compliance. More information: https://stripe.com/privacy and https://stripe.com/legal/privacy-center.
To process each payment event from Stripe reliably exactly once, we keep a marker per event for 90 days.
- Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (retention obligations under tax and commercial law).
- Retention: billing data for as long as the contract exists; afterwards for another 3 months for queries. Invoices and other accounting records are retained under Section 147 of the German Fiscal Code (AO) (currently eight years for accounting records).
B.7 Sending emails
Sign-in codes, invitations and account notices are sent via SMTP from noreply@supinion.com. Delivery is handled on our behalf by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (data centres in Germany). The legal basis is Art. 6(1)(b) GDPR.
B.8 Deleting your account
You can delete your account yourself in the app; for safety you confirm this by typing in your email address. This deletes your own workspaces with all their content, including plans unlocked with redeemed codes.
Two exceptions: deletion is blocked while a subscription that has not been cancelled is running or while other members are still in your team. In that case, cancel the subscription first or transfer or empty the team. Invoice records that must be kept by law remain until the retention periods expire (B.6). Deleted data disappears from server backups after 14 days at the latest (section 6).
B.9 Trial only once per email address
So that the 14-day trial cannot be used repeatedly by deleting and re-creating an account, we store a pseudonymised checksum of the email address when an account is created (an HMAC with a server key, not the address itself). The checksum is kept after the account is deleted and erased after 24 months. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing misuse of the free trial.
B.10 Newsletter
If you tick the box for news when getting started or in your settings, we first send you an email with a confirmation link (double opt-in). You only receive news after confirming, at most once a month.
- Data: email address, optionally your name, language, time of sign-up and of confirmation, and the wording of the consent you agreed to (as a dated version); together they serve as proof of consent. The confirmation link is stored only as a hash and is valid for 7 days.
- Legal basis: your consent, Art. 6(1)(a) GDPR. You can withdraw it at any time in your settings; the subscription is then deleted immediately.
- Delivery: for now we only collect sign-ups. Before we send the first newsletter, we will add here how it is delivered.
- Retention: until you withdraw consent or delete your account; unconfirmed sign-ups are deleted after 30 days.
B.11 Feedback and ideas
With the “Feedback” button you can send us ideas, bugs or praise, optionally with a screenshot.
- Data: your text, the type of message, the page of the app you were on, your browser identifier (user agent) and an optional image, linked to your account so we can follow up. No IP address.
- Purpose: fixing bugs and improving the product. Legal basis: Art. 6(1)(f) GDPR.
- Ideas up for voting are worded by us (without your name). We store your votes so you can support each idea only once and withdraw your vote; other users only see the count.
- Retention: feedback 12 months, screenshots 30 days; immediately on account deletion, together with your votes.
Part C – Audience members
C.1 Who is responsible
The poll you are taking part in is run by a person or organisation – for example your school, your employer or an event organiser. They are responsible for your answers. We operate the technology on their behalf. We pursue purposes of our own only when protecting against abuse (C.4) and when handling reports (C.7).
C.2 What data is processed
- You need no account.
- In quizzes you can choose a nickname. The presenter can decide for a presentation that everyone must give a name before answering; the name is then shown on the leaderboard. In that case, use a nickname, not your full name. Whether a name is required is decided by the organisation running the session (C.1).
- We store your answers: votes, words, notes, questions, scale values and quiz answers.
- To make sure a vote only counts once and you can carry on after reloading the page, we set the cookie
youpi_pcontaining a random token, valid for 24 hours. On the server we only store a hash of it (the participant identifier). - Legal basis for the technical operation of participation is Art. 6(1)(f) GDPR; the legal basis for the poll itself is determined by the organisation running it (in German schools usually the respective state's school law).
C.3 Anonymisation after 24 hours
24 hours after the session ends, the participant identifier is removed from the answers. The deletion job runs every hour, so the identifier is gone 25 hours after the session ends at the latest. If the presenter does not end a session, it ends automatically once nobody has been active and no device has been connected for 12 hours; after a restart of our server, 24 hours after the last activity at the latest.
After that, no answer can be attributed to a device or cookie – including by us. The answers from one device stay linked to each other as one record, for example for quiz points.
A name you entered stays with the results until they are deleted (C.5). If you entered a recognisable name, the results are not anonymous in that respect; please contact the organisation running the session to have it deleted.
C.4 Word filter and moderation
A word filter automatically holds back posts containing offensive terms. They are not deleted, only not displayed. Presenters can also moderate posts themselves. This does not involve any automated decision with legal effect within the meaning of Art. 22 GDPR. The legal basis is Art. 6(1)(f) GDPR (protecting participants from insults).
C.5 Retention
Session results are kept for 12 months after the session ends unless the presenter deletes them earlier. After that they are deleted automatically.
C.6 Children and young people
Schools also use supinion with pupils, including minors. They take part without an account; they only give a name if the teacher requires it, and then a nickname is enough. We ask schools to remind pupils not to include personal details in free-text answers.
C.7 Reporting content
Every audience view has a “Report content” option. When you report something, we store the reason (illegal, hate/incitement, insult/bullying, personal data, spam, other), your note, the affected session and slide and – only if you wish – your name and an email address for our reply.
- Purpose: reviewing the report and informing you of our decision. If we remove content or block a workspace, we also inform the owner of the workspace, with reasons. They do not learn your name or address.
- Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 16 of Regulation (EU) 2022/2065 (Digital Services Act), and Art. 6(1)(f) GDPR.
- Retention: name, note and contact address are deleted 90 days after our decision. The report itself (reason, session, slide, decision) is deleted 12 months after receipt.
How we handle reports is described on the page “Point of contact and reports”: https://www.supinion.com/en/contact-point
4. Recipients
| Recipient | Task | Role |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | server operation (Falkenstein data centre, Germany), sending emails, storage of the encrypted off-site server backup, server for audience measurement (Matomo at stats.telepano.de, see A.7) | processor |
| Stripe Payments Europe, Ltd. (Ireland) | payment processing | controller or processor depending on the activity (see B.6) |
The off-site backup is encrypted with the tool age before transfer. The storage location only sees encrypted data.
To pay, the app redirects you to a Stripe page. Stripe's privacy policy applies there; on its pages Stripe sets its own cookies and processes, among other things, your IP address (https://stripe.com/privacy).
Beyond this, we only disclose data where we are legally obliged to (for example by order of an authority).
5. Transfers to third countries
Our server is located in Germany. We ourselves do not transfer data to countries outside the EU/EEA.
Stripe states that it transfers personal data to countries outside the EEA, including the USA and India. According to Stripe, it relies on its certification under the EU-U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision, and on the EU Standard Contractual Clauses. Stripe is responsible for these transfers where it acts as controller.
Email delivery, the off-site backup and audience measurement also run at Hetzner Online GmbH in data centres in Germany.
6. Retention at a glance
| Data | Retention |
|---|---|
| Sign-in codes (as HMAC) | 1 day |
Sign-in (youpi_session) | 90 days without use, at most 400 days; guests 7 days |
| Newsletter subscription | until you unsubscribe or delete your account; unconfirmed 30 days |
| Feedback including page and browser identifier | 12 months, immediately on account deletion |
| Guest account without sign-up, including content | 7 days |
Participant cookie youpi_p | 24 hours |
| Participant identifier (token hash) attached to answers | until 24 hours after the session ends (hourly deletion job), then anonymised |
| Nickname or name in a quiz | together with the session results |
| Session results | 12 months after the session ends (can be deleted earlier) |
| Deleted presentations | permanently after 30 days |
| Unused images | 30 days |
| Open team invitations | 30 days |
| School and campus enquiries, EDU proofs | 12 months |
| Reports | 12 months after receipt |
| Name, note and contact address in reports | 90 days after the decision |
| Payment event markers | 90 days |
| Account data | until the account is deleted |
Referral sources (?ref=), counters and link to the account | 180 days |
| Checksum of the email address for the trial | 24 months |
| Billing data | during the contract and 3 months afterwards; accounting records under Section 147 AO |
| Purchase records for consumer purchases, cancellation and withdrawal statements | see B.6 |
| Audience measurement (Matomo), raw data | 180 days, then aggregated reports only |
| Server backups | 14 days |
| Rate-limit keys | in memory only, daily salt |
7. Security
Connections to supinion are encrypted with TLS (HTTPS, HSTS). Sign-in codes and session tokens are stored only as a check value or hash; IP addresses are not stored at all. Off-site backups are encrypted before transfer.
8. Your rights
You have the right to
- access the data stored about you (Art. 15 GDPR),
- rectification of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- withdraw consent with effect for the future (Art. 7(3) GDPR), where we rely on consent.
Right to object (Art. 21 GDPR): Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop processing the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
There is no automated decision-making, including profiling (Art. 22 GDPR); blocks following reports are decided by a human.
An email to hi@supinion.com is enough. As an audience member, please contact the organisation that ran the poll (C.1). Please note: after anonymisation (C.3) we can no longer attribute answers to anyone and therefore cannot provide information about them.
9. Right to lodge a complaint
You can lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de.
10. Obligation to provide data
For an account we need your email address, because otherwise we cannot send you a sign-in code. All other account information is optional. As an audience member you do not have to provide any information about yourself. If the presenter requires a name (C.2), you cannot answer without one; a nickname is enough.
11. Changes
When supinion changes, we update this policy. The version published here applies.