Privacy Policy

Last updated October 9, 2026

This Privacy Policy explains how personal data is processed when you use Headpat Place ("Headpat"): the website at https://headpat.place, the Headpat mobile app, and related services (the "Services").

Headpat Place is part of Headpat Space (https://headpat.space) and is run by the same operator. This policy applies to Headpat Place only. Headpat Space has its own privacy policy.

1. Who Is Responsible?

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:

Dominic Stilma
Friedhofsweg 10, 49843 Uelsen, Germany
Email: legal@headpat.place

There is no statutory obligation to appoint a data protection officer. For any privacy question, write to the address above.

2. What Data Do We Process?

Account data

When you register we process your email address, display name and password. Passwords are stored only as a hash. If you turn on two-factor authentication we store the secret and backup codes needed for it. If you create API keys we store a hash of each key and its settings.

Legal basis: Art. 6(1)(b) GDPR (providing the Services you signed up for).

Signing in with another account

You can sign in with Google, Discord, GitHub, Apple, Twitch or Eurofurence. If you do, that provider tells us your account ID there, your email address, your name and, where available, your profile picture. We do not receive your password, and we do not read your contacts, friends or posts from that provider. You can remove the connection in your account settings.

Legal basis: Art. 6(1)(b) GDPR.

Profile data

Everything you put on your profile: profile URL, display name, bio, pronouns, status, avatar and banner, links to your other accounts, location text, timezone and date of birth. Your date of birth is used to confirm that you are 18 or older. You decide in your settings whether it is shown on your profile and which parts of it. Most profile fields are optional.

Your profile is public and can be found by search engines. You can turn search engine indexing off in your account settings.

Legal basis: Art. 6(1)(b) GDPR.

Content you post

Gallery uploads with their titles, descriptions and tags, comments and likes, chat and direct messages with attachments and reactions, message drafts, communities and events you create or join, and who you follow, block or mute. Private notes you write about other users are visible only to you.

Legal basis: Art. 6(1)(b) GDPR.

Special categories of data

We do not ask for sensitive data such as your sexual orientation, health or beliefs. What you write in your profile or post, and the communities you join, may still reveal such information. Whether you share it is your choice. Where you make it public yourself, we process it on the basis of Art. 9(2)(e) GDPR, and otherwise on the basis of your consent under Art. 9(2)(a) GDPR, which you can withdraw at any time by removing the content.

Location data

Location sharing is off unless you turn it on. While it is on, we process your position so the people you chose can see it on the map. When you stop sharing, or a share expires, the position is deleted.

Legal basis: Art. 6(1)(a) GDPR (consent). You withdraw consent by turning sharing off.

Sessions and security

For every sign-in we store the IP address and browser or device information (user agent) with the session. We keep an audit log of security-relevant account events, such as account creation and changes to sign-in data. Our servers also process your IP address technically to deliver each request.

Legal basis: Art. 6(1)(f) GDPR (keeping accounts and the Services secure and preventing abuse).

Push notifications

If you allow notifications in the mobile app, we store your device's push token and send notifications through Firebase Cloud Messaging, a service of Google. You can turn notifications off in the app or in your device settings.

Legal basis: Art. 6(1)(a) GDPR (consent).

Email

We send account emails such as address verification and password resets. You can turn other notification emails off in your account settings.

Legal basis: Art. 6(1)(b) GDPR.

Support and reports

If you open a support ticket, report content or write to us, we process what you send together with your account details in order to handle it. Reports are stored with the account of the person who made them.

Legal basis: Art. 6(1)(b) and (f) GDPR, and Art. 6(1)(c) GDPR where we are legally required to act on a report.

Moderation

To enforce our Acceptable Use Policy, moderators can view reported content and take action on content and accounts. Records of moderation decisions are kept.

Legal basis: Art. 6(1)(f) GDPR and, where the law requires us to act, Art. 6(1)(c) GDPR.

3. Cookies and Local Storage

We use only what is needed to run the Services:

  • a session cookie that keeps you signed in; and
  • entries in your browser's local storage that remember your settings, such as theme, language, the NSFW display switch and chat layout.

We do not use advertising or analytics cookies and we do not track you across other websites. Because these items are strictly necessary, no consent banner is shown (§ 25(2) TDDDG).

4. Who Receives Your Data?

Hosting

We operate the Services ourselves. Server infrastructure and networking are provided by Jan Smyrek (PawHost), Gerichtstr. 15, 58540 Meinerzhagen, Germany. Databases and uploaded files are stored in Germany.

Email delivery

Emails are sent through Exchange Online, a service of Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. Microsoft receives the recipient address, the content of the email and the technical data needed to deliver it. We have a data processing agreement with Microsoft under Art. 28 GDPR.

Third-party services

Some features use third-party services. When you use them, your browser connects to the provider directly, so the provider receives your IP address and standard request data such as your browser type. We do not send them your account details.

  • Maps (OpenFreeMap): Maps on the map page, on events and in the location picker are drawn from map data served by OpenFreeMap (tiles.openfreemap.org), operated by Hyperknot Software Kft. in Hungary. Your browser requests the map tiles, fonts and symbols for the area you are looking at. According to its privacy policy, OpenFreeMap does not use cookies or tracking, does not store IP addresses in its access logs by default, and may use Cloudflare as a CDN. Details: https://openfreemap.org/privacy/. Map data is from OpenStreetMap contributors and OpenMapTiles. Your own shared location is never sent to the map provider; only the map area you view is requested.
  • Address search (Nominatim): If you search for a place in the location picker, your search text is sent to the OpenStreetMap Foundation's Nominatim service (nominatim.openstreetmap.org). Details: https://osmfoundation.org/wiki/Privacy_Policy.
  • GIFs (GIPHY): If you open the GIF picker in chat, your searches and your IP address are sent to GIPHY, Inc. in the United States. Details: https://giphy.com/privacy.
  • Push notifications (Google): Notifications to the mobile app are delivered through Firebase Cloud Messaging by Google Ireland Limited. Google receives your device's push token and the content of the notification.
  • Sign-in providers: If you sign in with Google, Discord, GitHub, Apple, Twitch or Eurofurence, that provider learns that you are signing in to Headpat.

Legal basis for these services: Art. 6(1)(f) GDPR (offering maps, location search and GIFs), and Art. 6(1)(a) GDPR for push notifications.

Other recipients

Other users and the public see what you publish. We disclose data to authorities or courts only where the law requires it. We do not sell personal data and we do not use it for advertising.

5. Transfers Outside the EU

Our own systems are in Germany. GIPHY, Discord, GitHub, Twitch, Google, Apple and Microsoft are based in, or may process data in, the United States. Transfers to providers certified under the EU-U.S. Data Privacy Framework rely on the European Commission's adequacy decision (Art. 45 GDPR). Otherwise they rely on standard contractual clauses (Art. 46(2)(c) GDPR), or take place because you chose to use that provider's feature.

6. How Long Do We Keep Data?

  • Account, profile and content: until you delete the item or your account.
  • Sessions: until you sign out or the session expires.
  • Location: deleted when you stop sharing or the share expires.
  • Support tickets: deleted together with your account.
  • Deleted accounts: when you delete your account, your profile, uploads, messages, tickets and other data linked to it are deleted. Direct conversations with one other person are deleted with it. Communities you own are handed to another member where one exists.
  • Legal duties: data may be kept longer where the law requires it or where we need it to establish, exercise or defend legal claims.

7. Your Rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have your data deleted (Art. 17);
  • restrict processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing that is based on our legitimate interests (Art. 21); and
  • withdraw a consent you gave, with effect for the future (Art. 7(3)).

To use any of these rights, an informal email to legal@headpat.place is enough. You can also change most data, and delete your account, directly in your account settings.

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
poststelle@lfd.niedersachsen.de

8. Is Providing Data Required?

An email address, a display name and a password, or a sign-in through one of the listed providers, are needed to create an account. A date of birth is needed to confirm that you are an adult. Everything else is optional. You can browse public pages without an account.

9. Automated Decisions

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

10. Minors

The Services are for adults only. We do not knowingly process data of anyone under 18. If we learn that an account belongs to someone under 18, we close it and delete the data.

11. Security

We protect your data with technical and organisational measures such as encrypted connections, hashed passwords and restricted access. No system is completely secure, so we cannot guarantee absolute security.

12. Changes to This Policy

We update this policy when the Services or the law change. The current version is always on this page. Where a change is significant, we will tell you in the Services or by email.

13. Contact

Privacy questions and requests: legal@headpat.place. General support: https://headpat.place/support.