Privacy Notice
Last updated: 30 June 2026
About us
This Privacy Notice (the “notice”) explains how Reecorder Labs GmbH, with its registered office at Choriner Straße 14, 10119 Berlin, Germany (“we” or “us”), collects and uses personal data when you visit or use our websites (www.reecorder.com, www.reecorder.ai or www.reecorder.app), our multi-model data infrastructure and SaaS platform, and/or related services (together, the “Services”).
If you have any questions or comments in relation to this notice, please reach out to us by email at privacy@reecorder.com, referencing “privacy notice” in the subject line.
What this notice covers
This notice applies to personal data processed in connection with the Services, including browsing the website, using our applications, creating an account, and marketing communications.
This notice does not cover third-party websites, apps or services that you may access via links on our website. We advise you to review any third-party terms and conditions, including privacy notices, where applicable.
The personal data we collect
Through our Services, we collect the following categories of data:
Data you provide to us
- Identity and account data: username, password, email address, account/platform identifiers, profile pictures, country of residence.
- Multi-model content: raw livestream video and audio recordings, voice data, transcripts, chat messages, engagement metrics and derived clips.
- Transaction and billing data: billing address, legal name, VAT number, tax identification number.
Data we collect automatically
- Technical & telemetry: IP address, device ID, browser information, analytics, usage data, language settings, operating system, time zone, screen resolution, application settings, performance and crash logs.
- Usage data: pages visited, clicks, preferences and settings, session duration, content viewed, search activity, stream management actions, content editing, shopping/cart events (e.g., add-to-cart and purchase events).
- Approximate location data: country code, region, time zone (derived from IP address).
- Account/platform identifiers: TikTok User ID, TikTok Live Creator ID, platform account identifiers, connection status and authentication metadata.
We do not intentionally collect data from minors, nor do we collect special categories of personal or criminal offence data. If you provide such data to us voluntarily (for example, you are talking about political views on your own livestream), we will process and store this data only as necessary and delete it where appropriate.
Purpose and legal basis for processing
We process personal data only when we have a legal basis to do so under applicable laws, including the EU General Data Protection Regulation (“GDPR”) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, “BDSG”).
| Purpose | Data categories | Legal basis | Retention period |
|---|---|---|---|
| Account creation and authentication | Identity and account data; Technical & Telemetry | Performance of contract | Duration of account + 30 days after deletion request |
| Stream connection and recording | Multi-model content; Technical & Telemetry | Consent | Until deleted by user or according to storage settings |
| Replay storage and management | Multi-model content | Performance of contract | Until deleted by user or account closure |
| AI-generated highlights and clip creation | Multi-model content | Consent | Until deleted by user or account closure |
| Video editing and export tools | Multi-model content | Performance of contract | Until deleted by user or account closure |
| Analytics and engagement insights | Technical & Telemetry; Usage Data; Multi-model content | Legitimate interest | 24 months |
| Customer support | Identity and account data; Support communications | Legitimate interest | 24 months after ticket closure |
| Payment processing and payouts | Identity and account data; Transaction and billing data | Performance of contract & Legal obligation | 7–10 years depending on applicable tax and accounting laws |
| Fraud prevention and platform security | Technical & Telemetry; Identity data | Legitimate interest | 24 months |
| AI marketplace participation and licensing | Identity data; Transaction and billing data; Consent records | Performance of contract, Consent, Legal obligation | Contract duration + 7 years; anonymized licensing data may be retained indefinitely |
| Compliance with legal obligations | Any data required by law | Legal obligation | According to applicable legal retention periods |
| Service improvement and debugging | Technical & Telemetry; Usage Data | Legitimate interest | 24 months |
| Viewer replay and social clipping functionality | Identity and account data; Multi-model content | Performance of contract | Until content deletion or account closure |
When we rely on legitimate interests for the processing of your personal data, we will always balance our interests against your rights and expectations. Where we rely on your express consent, you have the right to withdraw your consent at any time.
Who we share your data with
We share personal data only when reasonably necessary and subject to appropriate contractual safeguards (including data processing agreements where required). For example, to process your payment we need to share data with our payment processor; this typically includes your transaction and billing data.
In addition, we use service providers to operate the website and provide our Services, including cloud infrastructure providers, AI providers, analytics providers, social platform integrations, customer support providers and AI marketplace partners. No data is shared without the appropriate contractual protections in place.
We may add or replace providers over time. An up-to-date list of our service providers is available upon request at privacy@reecorder.com. We reserve the right to share data with professional advisers (such as auditors and legal advisors) and with competent authorities where required by law or to establish, exercise or defend legal claims.
Use of artificial intelligence
Reecorder uses artificial intelligence to provide core platform functionality, including highlight detection, video segmentation, transcription, engagement analysis, clip recommendations, and content search and categorization.
AI models and providers
We use a combination of internally developed AI models and commercial AI APIs, including providers such as OpenAI, Anthropic and Google AI. The provider mix may evolve over time. Data is transmitted to these providers via APIs and secure backend services over encrypted infrastructure.
Data used by AI systems
Our AI systems may process user-generated content, including video recordings, audio, transcripts, chat messages, clips, metadata, and creator-uploaded assets. This content is stored within secured cloud infrastructure.
AI training
By default, your content is not used to train AI models. You may choose to opt in through the Master Content Agreement (MCA), available via the in-app consent flow. If you do, your content may be used for foundation model training by verified enterprise partners under the conditions set out in that agreement. You may withdraw your consent at any time; withdrawal does not affect the lawfulness of any processing that took place before withdrawal.
Automated recommendations
Our platform generates personalized recommendations, such as suggested highlights, clip proposals, and engagement insights. These outputs are assistive in nature and do not constitute automated decisions with legal or similarly significant effects on you.
Biometric verification
For account access and streamer authentication, we use facial recognition technology to verify that you are who you claim to be. This processing involves biometric data as defined under applicable law and is based on your explicit consent.
International transfers
We process your personal data as much as possible within the European Economic Area (the “EEA”). Some providers (particularly AI providers and certain cloud infrastructure providers) may operate from outside the EEA. Where we are unable to process within the EEA, or where we work with third parties outside the EEA, we will only transfer your personal data outside of the EEA with appropriate safeguards in place (such as Standard Contractual Clauses).
Security
We implement appropriate technical and organizational measures to protect personal data, including encryption and appropriate security measures. These measures are reviewed periodically to ensure an appropriate level of protection. However, no method of transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately.
Cookies and similar technologies
We use cookies and similar technologies for essential site functionality, security, preferences, analytics and marketing. Where required by law we will ask for your consent before placing non-essential cookies. You can manage your cookie preferences at any time via our Cookie Policy. For more information, see the overview below:
| Cookie/Tag | Purpose | Typical expiry |
|---|---|---|
| Technical or functional cookies | Intended to ensure that our website and its forms work quickly and smoothly for the visitor. | Session cookie |
Data retention
We keep personal data only for as long as necessary for the purposes described in this notice, unless a longer period is required or permitted by law (for example, legal, tax or accounting obligations).
Your rights
You have the right to be informed of the personal data we hold, process and share about you. You can contact us at any moment via privacy@reecorder.com to request a copy of your personal data. We aim to respond within the applicable deadlines. In addition, you have the right to:
- access your personal data;
- request rectification of your personal data;
- request erasure of your personal data (“right to be forgotten”), or restrict further processing;
- lodge a complaint before the competent authorities (in Germany, the Berliner Beauftragte für Datenschutz und Informationsfreiheit, BlnBDI);
- data portability;
- object to processing based on legitimate interests, including direct marketing; and/or
- withdraw consent at any time where processing is based on consent.
Automated decision-making
Reecorder uses automated systems, including artificial intelligence and machine learning technologies, to provide certain features and improve the user experience. These systems may be used to generate suggested highlights and clips, recommend content categories or metadata, analyze engagement patterns, detect potential security threats, fraud, abuse or suspicious activity, improve content search and discovery, and generate personalized recommendations for creators and viewers.
These automated processes are designed to assist users and support the operation of our Services. They do not result in decisions that produce legal effects or similarly significant effects on individuals within the meaning of Article 22 GDPR. Where automated systems identify potentially fraudulent, abusive or suspicious activity, any significant action affecting a user’s account (such as suspension, restriction or termination) is subject to human review before a final decision is made. We do not make decisions about you solely by automated means that produce legal or similarly significant effects, unless we have a lawful basis to do so; where we do, you have the right to request human review.
How to exercise your rights
To exercise your rights, contact us at privacy@reecorder.com. We may ask you to verify your identity before we process your request, to ensure your data is kept protected. If you object to marketing emails, you can also unsubscribe using the link in the email.
Complaints
If you believe our processing of your personal data infringes data protection law, you can lodge a complaint with the supervisory authority in your EU/EEA country of habitual residence, place of work, or place of the alleged infringement. In Germany, the competent supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), see datenschutz-berlin.de.
Minors
Our Services are intended for users aged 18 and older. We take reasonable measures to prevent minors from accessing our Services. If you believe a minor has nonetheless provided us with personal data, please contact us so we can take appropriate action.
Changes to this notice
We may update this notice from time to time, for example to reflect changes in our services, providers or legal requirements. We will post the updated version on this page and changes will take effect from the moment this notice is updated. If any changes are material, we will aim to provide you with appropriate advance notice.