klixly

Privacy Policy

Last updated: 10.07.2026

This English translation is provided for your convenience. Only the German version is legally binding.

1. Controller

The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:

Heiko Stuhrmann
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach
Email: hello@klixly.app

2. What data we process

2.1 When visiting public bio pages

  • Click statistics: for each click on a link we store a timestamp, the link ID, a 24-hour-salted SHA-256 hash of your user-agent string (for unique-visitor detection, not reversible) and the country of origin derived from your IP address. We ourselves do not store IP addresses in plain text, set no tracking cookies, and perform no fingerprinting.
  • Server logs: on every access the web server writes brief logs (time, path, status code). These are automatically deleted after a maximum of 14 days.

Legal basis: our legitimate interest in an operationally secure and analyzable platform (Art. 6(1)(f) GDPR).

2.2 When registering a klixly account

  • Email address, chosen password (stored only as a bcrypt hash)
  • Username (= default slug of your bio page)
  • Language setting, creation and last-update dates
  • Optional: 2FA secret (for TOTP), backup codes (bcrypt-hashed), passkey credentials

Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

2.3 When operating your bio page

  • Display name, bio text, profile picture, logo, background image
  • Links, embeds, newsletter/form configurations
  • Design customizations (theme, colors, fonts)

This data is generally publicly visible — you decide yourself what appears on your bio page. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

2.4 When visitors use your newsletter or contact form

  • Newsletter: email address + time of sign-up. Visible exclusively to you (the page owner) in the klixly dashboard.
  • Forms: the fields entered by the visitor (name, email, message, custom fields). Likewise visible only to the page owner.

Newsletter sign-ups use a double opt-in process: after entering their email address, the visitor first only receives a confirmation email with a link valid for 24 hours. The sign-up takes effect only once they click that link — i.e. only then does the address count as a subscriber, appear in the CSV export, and get forwarded to an external newsletter provider (if the page owner has connected one). Unconfirmed sign-ups are never forwarded. Until confirmation the address is merely held pending; if the visitor never confirms, it stays unused.

The respective page owner is responsible for the further processing of this data — klixly merely provides the infrastructure.

2.5 When someone reports a bio page (report form)

  • The reason for reporting you select + a free-text description.
  • Optional: your email address (only if you provide it, for follow-up questions).
  • A 24-hour-salted SHA-256 hash of your IP address (to detect mass-report abuse — no plain-text IP, rolls daily).
  • Timestamp + status (open/handled/dismissed) as well as optional internal admin notes.

Legal basis: our legitimate interest in maintaining an abuse-free service (Art. 6(1)(f) GDPR).

2.6 For paid plans (Pro)

  • Handled via Polar as Merchant of Record. The operator is Polar Software, Inc., 548 Market St, PMB 99696, San Francisco, CA 94104, USA. Polar processes payment, invoicing, and tax data under its own responsibility; klixly receives only subscription IDs + status.
  • Because the provider is based in the USA, a transfer of personal data to a third country takes place. The legal basis is the EU Standard Contractual Clauses (SCC) within the scope of the data processing agreement.
  • Further documents: Privacy Policy, Data Processing Agreement (DPA). The list of the sub-processors used (including Stripe) is part of the DPA document.

2.7 For the referral program (referrals)

  • Click on a referral link(klixly.app/r/<username>): we set a first-party cookie klixly-ref containing the referring username, valid for 30 days, exclusively on our own domain. The cookie serves solely to attribute a later registration to the referring user. It contains no personal data about you and is not transmitted to third parties.
  • When registering via a referral link: we create a record that captures the referring user (referrer), the referred user (you), the time of registration, and the current status of the referral (open / qualified). Once you have confirmed your email and published a first bio page, the referral is deemed qualified.
  • Anti-abuse analysis: to detect organized account creation, we evaluate in aggregate and purely technically whether sign-ups cluster suspiciously. This analysis serves exclusively to maintain fair operation of the program. In addition, we limit the number of referral-cookie placements per IP address within a time window (in-memory counting, no persistence of the IP).
  • Reward: upon reaching the applicable threshold (currently 10 qualified referrals per Pro month), a time-limited Pro grant is automatically created for the referring user. A link between the referrer and an individual referred user is visible only internally in the database and is not disclosed publicly.
  • Retention period: referral records are kept until one of the accounts involved is deleted; the cookie automatically becomes invalid after 30 days or is deleted upon successful sign-up.

Legal basis: performance of a contract toward the referring user (Art. 6(1)(b) GDPR) as well as our legitimate interest in abuse-free operation of the program (Art. 6(1)(f) GDPR).

2.8 For connected social media accounts (Content Planner)

When you connect one of your own social media accounts in the Content Planner, we store the access tokens (OAuth) issued by the respective platform, the account identifier, and publicly visible profile information (e.g. display name, username, profile picture) so that you can create, schedule, publish, and view the associated metrics for your own account from within klixly. The tokens are stored encrypted (AES-256-GCM) and used exclusively for actions on your own account. We never access third-party accounts. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).

Depending on the connected platform, your data is transmitted to the respective provider; that provider’s own privacy terms additionally apply:

YouTube. If you connect your YouTube account, klixly uses the YouTube API Services. By using this feature you agree to the YouTube Terms of Service; for data processing by Google, the Google Privacy Policy additionally applies.

Which YouTube API data we access and collect. klixly uses the scopes youtube.upload and youtube.readonly exclusively for your own account, in order to

  • identify your account upon connection — channel ID, channel title, and thumbnail;
  • upload videos you create to your own channel (you set the title, description, tags, category, visibility, and the “made for kids” designation yourself);
  • display, on a read-only basis, the statistics of your own videos and your channel (views, likes, comment count, subscriber count).

No data of other users and no content of third-party channels is read or modified.

What we store and for how long. Until you disconnect, we store the channel ID, the channel title, and the URL of the thumbnail as well as — encrypted (AES-256-GCM) — the OAuth access and refresh tokens. The metrics of your channel and your videos (subscriber, view, like, and comment counts) we retrieve regularly and store as a time series, so that we can show you the development of your reach (e.g. subscriber growth) as a chart. This statistics history is continuously updated and automatically deleted after 180 days at the latest; if you disconnect the account, the stored metrics are removed immediately.

How we process and share the data. The YouTube API data is processed exclusively server-side, to provide you with the functions mentioned above (upload, display of your own statistics). We do not share this data with third parties, do not sell it, and do not use it for advertising, profiling, or the training of AI models. A transfer takes place only to Google itself (for API calls on your behalf) and to our hosting or infrastructure service provider, insofar as that is necessary for technical operation.

Handling of access tokens. The OAuth tokens are used only for the purposes you consented to upon connection. We retain them only for as long as the account connection exists. As soon as you disconnect within klixly, the tokens are immediately and irrevocably deleted. If you instead revoke access directly in your Google account, the stored token thereby becomes worthless; it is fully removed when you disconnect within klixly.

Revocation and deletion. You can disconnect an account at any time within klixly; the stored tokens are irrevocably deleted in the process. In addition, you can revoke klixly’s access to your Google/YouTube account at any time in the security settings of your Google account.

Contact. The controller responsible for processing this data and the point of contact for YouTube-API-related privacy requests is the provider named under section 1 (Controller), reachable at hello@klixly.app.

2.9 For donations / tips to creators (Stripe)

  • When a creator enables monetization, they can offer a donation/tip block on their bio page. The payment is processed by Stripe. klixly acts solely as the technical platform; the merchant of the transaction is the respective creator with their own Stripe account.
  • You enter the payment data (in particular card details) directly on Stripe’s hosted checkout page. klixly processes no card data; we only receive transaction metadata from Stripe (session ID, amount, platform fee, status) in order to show the creator their earnings. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
  • The contracting party for payment processing is Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). Depending on the processing operation, data may be transferred to Stripe, Inc. (USA); the legal basis for this are the EU Standard Contractual Clauses (SCC). Further documents: Privacy Policy, Data Processing Agreement (DPA).

2.10 For digital products and paid links (creator shop)

Creators with monetization enabled can additionally sell digital files on their bio page („digital products“) or place individual links behind a one-time payment („paid links / paywall“). Payment is processed via Stripe just like for tips; the merchant and sole contracting party of the buyer is the respective creator (see § 5b of our T&C), not klixly.

  • Buyer email (digital products): When buying a digital product, Stripe collects the buyer’s email address at checkout. klixly receives this email solely to (a) send the download link to the buyer and (b) show the creator the sale in their earnings overview. The legal basis is the performance of a contract (Art. 6(1)(b) GDPR).
  • No evaluation, no sharing: klixly does not evaluate buyer or customer data, does not build profiles from it, and does not use it for advertising. It is shared with third parties only insofar as technically required for delivery (email dispatch via the mail processor named in section 4) — just as with payments, whose card data remains exclusively with Stripe.
  • Download link: Access to the purchased file is provided via a signed, time-limited link (valid for 7 days) that reveals neither the content nor personal data in the URL. The file itself is stored protected on our server (section 4) and is reachable only via that link.
  • Paid links (paywall): After a successful payment, klixly sets a technically necessary, signed cookie (kx-paid-<link-ID>, max. 30 days) that unlocks access to the paid destination. It contains no personal data, serves no tracking purpose, and is not transmitted to third parties (see section 3).
  • Retention: For each sale we store transaction metadata (session ID, amount, platform fee, status, and where applicable the buyer email) for settlement with the creator and to meet tax and commercial retention obligations (section 5).
  • Creator responsibility: The creator alone is responsible for the product itself, its description, the fulfilment of the purchase contract, and for any customer data the creator collects beyond this.

2.11 Audience measurement with Umami

To statistically analyze the use of our service (which pages are viewed how often, from which country and via which referrers visitors arrive, which device type or browser is used) we use Umami — open-source, privacy-friendly analytics software that we operate ourselves on our own infrastructure. Umami sets no cookies, performs no fingerprinting, and shares no data with third parties. Only aggregated statistics that cannot be traced back to you are collected; your IP address is merely processed temporarily to derive the country of origin and is not stored in plain text.

Because Umami neither stores nor reads information on your device (§ 25 TTDSG), no consent is required for this. The legal basis is our legitimate interest in a statistical evaluation and the needs-based improvement of our offering (Art. 6(1)(f) GDPR).

2.12 klixly newsletter

If you sign up for our newsletter in the footer, we process your email address and — if you provide it — your name in order to send you product updates, new features, and news about klixly. Delivery is handled via Listmonk, open-source newsletter software that we operate ourselves on our own infrastructure. Your data is not shared with external email-marketing services.

Sign-up uses a double opt-in process: after entering your address we first only send you a confirmation email. Your sign-up takes effect — and you start receiving the newsletter — only once you click the link it contains. The legal basis is your consent (Art. 6(1)(a) GDPR). You can unsubscribe at any time via the unsubscribe link at the bottom of every newsletter email; your address is then removed from the distribution list.

3. Cookies

klixly itself sets exclusively technically necessary or functional cookies. We set no tracking or analytics cookies of our own and no third-party cookies — which is why we show no cookie consent banner. For audience measurement we use cookieless Umami (see section 2.11), which works without cookies. Functional cookies (e.g. for language or the last-selected dashboard view) are only set when you use the respective feature.

Exception: if the owner of a bio page embeds their own analytics tool (e.g. Google Analytics or Meta Pixel), a consent notice appears on that specific page. The tracking scripts load only after your explicit consent; you can withdraw your decision there at any time via the cookie icon.

  • klixly_tracking_consent — stores your decision about the analytics tool embedded by the respective page owner; only set on bio pages with embedded tracking (technically necessary, 365 days)
  • __Secure-authjs.session-token — login cookie after sign-in (technically necessary, ~24 h)
  • sidebar_state / NEXT_LOCALE — UI preferences such as language (functional, only set when used)
  • bl-current-page-id — currently selected bio page in the dashboard (functional)
  • klixly-ref — referral attribution upon clicking a /r/<username> link. Contains exclusively the username of the referring user, valid for max. 30 days, deleted upon successful sign-up. See section 2.7 for details.
  • kx-paid-<link-ID> — unlocks access to a paid link after a successful payment (technically necessary, signed, max. 30 days). Contains no personal data; see section 2.10 for details.

4. Hosting and processors

  • Own server: klixly is operated on a dedicated machine in Germany. The database and application server are located in the same place; no data leaves the EU for regular operation.
  • bunny.net (BunnyWay d.o.o.): DNS resolution for our domains is handled via bunny.net, operated by BunnyWay, informacijske storitve d.o.o., Dunajska cesta 165, 1000 Ljubljana, Slovenia (EU). For klixly.app itself, bunny.net provides only the authoritative DNS records; no proxy is placed in front here — all HTTP traffic runs directly through our own server, and only DNS-typical request metadata arises (including the IP address of the requesting DNS resolver and the queried domain name). If a Business customer uses their own domain (custom domain), that domain’s traffic is additionally routed through the bunny CDN so that bunny can issue the TLS certificate and handle delivery; in that case bunny, acting as a processor, also processes the HTTP request data of that domain’s visitors (including IP address and requested URL). In both cases the registered office is within the EU, so no third-country transfer takes place.
  • Strato: for sending email (verification emails, password reset, newsletter confirmations) we use the SMTP relay of Strato AG (Pascalstr. 10, 10587 Berlin). A data processing agreement under Art. 28 GDPR exists with Strato ( strato.de/agb/avv).
  • Polar: billing as “Merchant of Record” by Polar Software, Inc., 548 Market St, PMB 99696, San Francisco, CA 94104, USA. Data transfer to the USA on the basis of supplementary EU SCC. Data processing agreement: polar.sh/legal/data-processing-addendum. See section 2.5 for details.
  • Stripe: payment processing for donations/tips, digital products, and paid links on bio pages (creator marketplace) by Stripe Payments Europe, Ltd. (Dublin, Ireland), with possible transfer to Stripe, Inc. (USA) on the basis of the EU SCC. Data processing agreement: stripe.com/legal/dpa. See sections 2.9 and 2.10 for details.

5. Retention period

  • Account and profile data: until you delete the account.
  • Raw click data: a maximum of 30 days, then aggregated (no more user-agent hash, no more daily salt).
  • Webhook events (Polar and Stripe): 90 days for replay safety.
  • Sales transaction data (tips, digital products, paid links — amount, platform fee, session ID, status): insofar as they concern our own bookkeeping, up to 10 years under tax and commercial retention obligations. We keep the buyer email only for as long as needed for delivery and handling any follow-up questions.
  • Server logs: a maximum of 14 days.
  • Referral records: until one of the accounts involved is deleted. The attribution cookie klixly-ref expires automatically after 30 days at the latest.

6. Your rights

Under the GDPR you have, in particular, the following rights vis-à-vis us:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent given (Art. 7(3) GDPR)

A copy of all data stored about you (access + data portability, Art. 15 / Art. 20 GDPR) you can download yourself at any time as a logged-in user under Account → Export your data as a machine-readable JSON file. For other matters, write us an email at hello@klixly.app.

In addition, you have the right to lodge a complaint with a supervisory authority — for us this is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.

7. Changes to this privacy policy

We adapt this policy as needed — for example when new features are added or processors change. The respective current version is available here; the “Last updated” date stated above indicates the most recent change.