← Back

Privacy Policy

Last updated: June 2026

1. Controller / Verantwortlicher

Oswald & Sommer GbR
Sonnhalde 94, 79194 Gundelfingen, Germany
E-Mail: contact@privshield.app
Steuernummer: 07068/02307

2. What data we collect and why

2.1 Waitlist sign-up

When you join the waitlist, we store your email address to notify you at launch. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw at any time by emailing us.

2.2 Account & alias data

When you create an account, we store:

  • Your email address (for login and forwarding)
  • The alias addresses you create, including their labels and activity counters
  • Your spam-sensitivity preference and custom spam rules
  • Sender-level spam feedback you provide (approve / mark as spam) — stored as per-sender score adjustments
  • Your preferred language and app settings

Legal basis: performance of contract (Art. 6(1)(b) GDPR).

2.3 Email processing & in-app inbox

When an email arrives at one of your alias or temporary addresses it passes through our infrastructure. We store the following in your personal inbox so you can read and manage your mail inside the app:

  • Sender address and display name
  • Subject line
  • Email body (HTML and plain text)
  • Spam score and classification category
  • Timestamp and forwarding status

During delivery, emails are automatically analysed for spam. This involves:

  • SPF / DKIM header verification
  • Content scoring via Postmark Spamcheck — the full email (up to 512 KB) is sent to Postmark's API
  • Sentiment analysis and subject-line embedding via Cloudflare Workers AI (models: distilbert-sst-2-int8 for negative-sentiment detection; bge-small-en-v1.5 for subject similarity on Premium accounts)
  • Sender-domain lookup against the Spamhaus DBL DNS blocklist

For Premium users, a vector embedding of the email subject is stored alongside the message to power personalised spam detection. Emails classified as auto-delete (score > 15) are discarded immediately — no database entry is created.

Legal basis: performance of contract (Art. 6(1)(b) GDPR); legitimate interest in spam protection (Art. 6(1)(f) GDPR).

2.4 Email forwarding

If you enable forwarding, emails that pass our spam filter are relayed to your real address via Resend. The full email content is transmitted during forwarding. You can disable forwarding at any time in settings. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

2.5 Phone Shield (masked phone numbers)

If you use the Phone Shield feature, we provision a masked phone number via Twilio. We store your real phone number in our database to enable forwarding of incoming SMS messages. SMS content passes through Twilio's infrastructure and, depending on your settings, may be relayed to your real number or displayed inside the app. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

2.6 Push notifications

If you enable push notifications, we store a device push token (APNs / FCM) in your profile to deliver alerts about new emails or account events. You can revoke this by disabling notifications in your device settings. Legal basis: consent (Art. 6(1)(a) GDPR).

2.7 Account migration & IMAP scanning

The optional account-migration feature lets you scan an existing email inbox to discover aliases you have registered elsewhere. To do this, you provide IMAP credentials (address and password) which are transmitted to our Supabase edge function over an encrypted connection. We do not persist your IMAP credentials — they are used only for the duration of the scan and then discarded. Legal basis: consent (Art. 6(1)(a) GDPR).

2.8 Payment data

If you subscribe to Privacy Shield Pro, payments are processed by Stripe. We do not store your card details. We only receive an anonymised customer reference from Stripe. Legal basis: performance of contract (Art. 6(1)(b) GDPR).

3. Third-party processors

We use the following sub-processors to operate the service. All transfers to the US are covered by Standard Contractual Clauses (SCCs) under Art. 46 GDPR.

ProviderPurposeLocation
Google (GA4)Web analytics — only after consentUSA
SupabaseDatabase, authentication, edge functionsUSA (EU infrastructure: Frankfurt)
CloudflareEmail routing, infrastructure, Workers AI (spam analysis)USA
Postmark (ActiveCampaign)Spam scoring via Spamcheck API — receives email contentUSA
SpamhausDNS-based sender-domain blocklist lookupUK / USA
ResendOutbound email delivery (forwarding)USA
TwilioMasked phone numbers and SMS forwarding (Phone Shield)USA
StripePayment processingUSA
RevenueCatIn-app subscription management (iOS)USA

4. Data retention

DataRetention
Waitlist emailUntil you unsubscribe or the service launches
Account & alias dataUntil you delete your account
Emails in inbox (body, subject, metadata)Until you delete the message or your account
Emails classified as auto-delete (score > 15)Not retained — discarded immediately
Subject embeddings (Premium)Until the associated email is deleted
Spam feedback & sender adjustmentsUntil you delete your account
SMS messages (Phone Shield)Until you delete the message or your account
Device push tokenUntil you disable notifications or delete your account
IMAP credentials (migration scan)Not retained — discarded after scan completes
Payment records10 years (German commercial law / § 147 AO)

5. Your rights

Under GDPR, you have the right to:

  • Access the data we hold about you (Art. 15)
  • Correction of inaccurate data (Art. 16)
  • Deletion of your data (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time without affecting prior processing

To exercise any of these rights, contact: contact@privshield.app

You also have the right to lodge a complaint with your local data protection authority. In Baden-Württemberg: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.

6. Cookies & analytics

This website uses Google Analytics 4 (Measurement ID: G-CC1W9LW6CC) to understand how visitors use the site. GA4 is loaded with Consent Mode active: analytics_storage and ad_storage default to denied — no data is collected or transmitted to Google until you explicitly accept via the cookie banner.

If you accept, Google Analytics sets cookies to measure sessions, page views, and traffic sources. You can withdraw consent at any time by clicking “Reject” in the cookie banner (clear your browser's localStorage for privshield.app to make it reappear).

Your theme preference (light / dark) and language choice are stored in localStorage on your device only and are never transmitted to us.

Legal basis for analytics: your consent (Art. 6(1)(a) GDPR).

7. Changes to this policy

We may update this policy as the service evolves. Material changes will be communicated via email (if you have an account) or a notice on the website. The date at the top of this page always reflects the most recent revision.