Contents
1. Welche Daten wir verarbeiten2. Camera, microphone, photos and files3. Guest posts, reports and moderation4. WiFi Magic, NFC und Events4a. Optional app push notifications5. Apple and Google Play purchases6. Registration and Account Deletion7. Hosting and service providers8. Storage period and rights

iOS, Android und App Clip

App privacy

These notes explain data processing in the MagicPoster apps and in the App Clip. The general Privacy Policy contains the complete legal basis and recipient information.

Last updated: September 22, 2026

1. Welche Daten wir verarbeiten

Depending on the function used, we process account data, MagicPoster keys, project and event data, WiFi data, uploaded photos, videos, audio, PDFs and texts, pseudonymous contributor IDs, reports and moderation histories, StoreKit transaction data, push tokens, live activity data, support information as well as technical protocol and security data.

2. Camera, microphone, photos and files

The app only accesses the camera, microphone, photo library and files after your selection or consent. Selected content is processed for preview, technical review, optimization and upload. Content that is not selected will not be transferred.

3. Guest posts, reports and moderation

A pseudonymous identifier can be generated for contributions per browser or reliable identity and book. It is used to avoid duplicate reports, limit abuse and block a contributor within this book.

Reports include the affected post, reason, optional description, status, and edit history. The project owner is notified by email and can review, reject, delete or block. A failed email send does not delete the saved message.

4. WiFi Magic, NFC und Events

In particular, SSID, protected WiFi password, encryption, fixed page URL, cover, guest page content and purchase status are processed for WiFi Magic. NFC tags and QR codes contain the fixed MagicPoster URL.

For event functions, the start, end and time zone can be saved. Push notifications and Live Activities are only activated with your consent; Device tokens, activity status, cover, title and event time can be processed.

4a. Optional app push notifications

For optional app notifications, we use Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. We process device and installation tokens, platform, app version, language, permission status and the association with the signed-in account. Photo book events also use book-specific activity tokens, start and end times and update status.

New-entry notifications are enabled explicitly for each project and contain no answers or photos by default. You can turn them off in the project settings and device settings. Signing out disables that device association for delivery; invalid tokens are no longer used. An ownership transfer ends the previous owner’s access to new project notifications. Necessary account, transfer and moderation emails are unaffected.

By default, people with the book link can view entries. The owner can disable guest viewing while guests can still contribute. Private entries and their media are then delivered only to authorized viewers. Copies already downloaded cannot be recalled.

To resume interrupted contributions, text, selected files and a stable submission identifier may be stored locally on the device. The local submission is removed after saving is confirmed. Native retry files have a limited lifetime; browser drafts remain until successful submission or until browser storage is cleared. This storage does not automatically create a new contribution.

Firebase privacyApple privacy policy

5. Apple and Google Play purchases

Apple or Google processes payment data and provides purchase receipts, refunds and subscription management. MagicPoster receives and stores transaction or purchase token verification data, product ID, status, store account association, project association, and verification history to verify permissions server-side, prevent replay, and restore purchases. Purchase tokens are only stored permanently when hashed. We do not receive complete credit card details.

6. Registration and Account Deletion

When signing in with Apple or Google, we process the identifier provided by the provider, confirmed email address and, if applicable, name and Apple Relay email address. Before the account is permanently deleted, you must log in to the linked provider again. The Apple token will be revoked on the server side, if necessary, before the MagicPoster account is deleted.

7. Hosting and service providers

Application data and media are stored in the Supabase project in eu-central-1 (Frankfurt). Vercel provides the web application, CDN and server functions. Apple is involved in StoreKit, Sign in with Apple, push and Live Activities. Google is involved in Google Sign-in, Google Play Billing, the Android Publisher API, Google Cloud Pub/Sub and optional FCM push delivery. Firebase Auth, Firebase Analytics and Crashlytics are not used. IONOS provides email delivery and Usercentrics consent management. External links transfer data only when you open them.

8. Storage period and rights

Project and account data remain stored until deleted or the purpose no longer applies. Sessions expire after 30 days at the latest. Open reports and moderation histories remain stored until completion and only for as long as evidence, security or legal obligations require this. Purchase ledgers and tax-relevant evidence can be stored for up to ten years.

You can request information, correction, deletion, restriction, data portability and objection as well as revoke consent. Send data protection inquiries to hello@getmagicposter.com.

Delete account and dataGeneral Privacy PolicyTerms of UseLegal NoticeSupport
Rechtliches
DatenschutzerklärungImpressumNutzungsbedingungen