Privacy Policy
Last updated: 26 July 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
AJ GmbH
Danziger Str. 80
65191 Wiesbaden
Germany
Represented by: Dr Andreas Jahnke
Privacy contact: privacy@shortlistbuddy.com
2. Scope and minimum age
This Privacy Policy applies to the website and the ShortlistBuddy photo-selection service. The service is intended exclusively for adult users aged 18 or over and for their personal, private or family photo management. Persons under 18 must not use ShortlistBuddy as users themselves, but they may appear in private photos and reference photos.
The user decides which private photos and which known persons are analysed. ShortlistBuddy must not be used for professional or commercial purposes, public person searches, surveillance or identification of unknown persons. For reference photos, the user gives one confirmation per analysis job that each person shown—or, where necessary, a person authorised to act for them—has agreed to the described use.
3. Website access and technical log data
When the website is accessed, technically necessary data is processed, in particular the IP address, time, requested URL, HTTP status, data volume, referrer information, browser/device information and technical error data. This processing is necessary to deliver the website, prevent attacks and misuse, and maintain stability.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service. Recipients include our hosting provider Vercel Inc. and its subprocessors.
Regular retention period for hosting/security logs accessible to us: 30 days. Relevant data may be retained for longer where necessary to investigate security incidents or establish, exercise or defend legal claims.
4. AI-assisted photo selection
4.1 Data processed and workflow
When you start a photo-selection job, you select photos on your device. ShortlistBuddy creates reduced JPEG previews in your browser with a maximum size of 512 × 512 pixels. High-resolution originals are not sent to our AI provider and remain on your device. The later download/ZIP file is created locally in the browser, provided the relevant function is implemented as described.
For the analysis, we process the previews, a technical job identifier and, where required for sorting, selected metadata such as capture date and camera model. If the optional Persons feature is used, we additionally process one reference photo for each person sought and a neutral label such as “Person A”, preferably without a real name. Real names should not be sent to Google. GPS coordinates are not sent to the AI provider if the system is implemented accordingly. An optional place-name feature is described in section 6.
The previews are transmitted through our technical infrastructure to Google’s paid Gemini Developer API. The AI evaluates the images against criteria selected by the user and creates a non-binding proposed selection. The user can review, modify or reject the result.
4.2 Roles, purposes and legal framework
AJ GmbH is the controller for website operation, security and abuse logs, support, product updates and its own contractual data. The relevant purposes and legal bases are described in the respective sections of this Privacy Policy.
For photo and reference content selected by the user, metadata and analysis results, AJ GmbH processes the data solely on the instruction triggered by the user and only to perform the specific private analysis job. AJ GmbH does not pursue its own purposes with this content, does not use it for advertising or model training and is structured as a processor in this respect. The user determines the photos, persons sought, selection criteria and private purpose. The supplementary processing terms form part of the Terms of Use.
Where the user processes photos solely in the course of personal or household activities, the user’s own processing falls within the household exemption in Article 2(2)(c) GDPR. This exemption does not apply to AJ GmbH or the technical providers we use; we remain subject in particular to the data-protection and security obligations applicable to processors. ShortlistBuddy does not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR.
4.3 Reference photos and biometric person matching
If the optional Persons feature is activated, the face in a reference photo is compared with faces in the selected private photos in order to find a previously specified person known to the user. This technical comparison may generate biometric data for the purpose of unique recognition.
AJ GmbH processes the photo and biometric content solely on the user’s behalf and documented instructions. ShortlistBuddy does not independently collect consent from the person shown. The user may use the feature only in a private or family setting and must be authorised to use each reference photo. In particular, the user must ensure that the person shown—or, where that person cannot validly agree themselves, a person authorised to act for them—has agreed to the temporary AI-assisted recognition and the necessary technical transfer.
One active collective confirmation is sufficient for all reference photos provided through the common upload field in an analysis job. ShortlistBuddy does not require a separate confirmation for each photo or person, an age declaration for the person shown, or written/uploaded evidence of agreement. The confirmation must not be preselected and must be given before the reference photos are transferred.
The collective confirmation is a contractual representation by the user. We record only the timestamp, version of the confirmation text and a technical job identifier; we do not request names, contact details, relationships or consent messages relating to the persons shown. The technical confirmation record is retained for 30 days and longer only in a specific security, misuse or legal case.
Reference photos, temporary feature representations and matching results are processed by AJ GmbH only for the current analysis job and are then deleted from the application environment. We do not create persistent facial templates, embeddings, person databases or reusable person tags. Technically possible retention by Google is described in section 5 and may extend beyond the analysis job.
The feature may be used only to find a previously specified consenting person in private photos selected by the user. It must not be used to identify unknown individuals, search public or third-party image collections, conduct surveillance, support law-enforcement or security purposes, or infer ethnic origin, religion, health, political opinions, sexual orientation, emotions or other sensitive characteristics.
4.4 Objection, withdrawal of permission and requests from persons shown
A person shown may tell the user that their reference photo must not be used in future. The user must respect that decision and must not upload the photo again. Persons shown may also contact our privacy contact. Because we do not store names or persistent facial profiles, retrospective identification will normally require the approximate time and technical job identifier. Security or abuse logs already transmitted to Google may remain until the period described in section 5 expires.
Do not upload identity documents, medical images, intimate content or other highly sensitive images. If such content is nevertheless uploaded, it is technically processed like any other preview; no separate professional or substantive analysis is intended.
5. Google Gemini Developer API
We use a paid Gemini Developer API account for AI analysis. According to Google’s current contracting-entity information, the contracting entity for customers with a German billing address is generally Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, unless the specific cloud agreement states otherwise.
Under the Paid Services terms, Google does not use submitted inputs, files or responses to improve or train its models. We do not enable voluntary sharing of logs or datasets with Google and do not use the data for model training.
Google may retain inputs and outputs for security, abuse-detection and legal purposes for a limited period. Google’s current documentation states that this may be up to 55 days. Additional retention may arise depending on the API features used. We therefore do not use the File API, permanently stored datasets or persistent context caching, and disable storage for stateful API features where technically possible.
Google may process data in countries where Google or its subprocessors maintain facilities. The relevant data processing agreement, European Commission Standard Contractual Clauses and/or an applicable adequacy decision provide the transfer basis. Residual risks may remain for processing outside the European Economic Area, particularly statutory access powers in the recipient country.
6. Optional place-name feature / reverse geocoding
Precise GPS coordinates must not be sent to BigDataCloud until a DPA and appropriate third-country safeguards have been completed. Otherwise remove this section and disable the feature.
If you expressly enable place-name display, GPS coordinates contained in the image file may be sent to BigDataCloud Pty Ltd in Australia to derive a place name. Technical connection data such as the IP address may also be processed. The legal basis is your consent under Article 6(1)(a) GDPR. You may withdraw consent with future effect or choose not to use the feature.
Australia is not generally covered by an EU adequacy decision. The transfer must therefore be based on appropriate safeguards, in particular EU Standard Contractual Clauses and a documented transfer assessment. AJ GmbH does not permanently store the GPS coordinates.
7. Optional cloud import and export
Providers, OAuth scopes, token storage and actual data flows must be technically verified and specifically named in the final version.
If you connect supported cloud storage such as Dropbox or Microsoft OneDrive, authorisation is performed via OAuth. ShortlistBuddy requests only the permissions required for the import or export selected by you. OAuth tokens are used only for the duration of the transaction or browser session and are not stored permanently, provided the system is implemented accordingly.
The legal basis is Article 6(1)(b) GDPR. The privacy terms of the relevant cloud provider also apply to processing within your cloud account. Review the displayed permissions before granting access.
8. Feedback, support and product updates
If you send feedback or a support request, we process your contact details, message and necessary technical information to handle the request and improve the service. Depending on the content, the legal basis is Article 6(1)(b) or (f) GDPR. Our legitimate interest is handling requests and correcting errors.
Regular retention period for feedback/support data: 12 months after closure, unless statutory retention duties or legal claims require longer storage.
If you subscribe to product updates, we process your email address based on your consent under Article 6(1)(a) GDPR and section 7(2) of the German Unfair Competition Act. Where used, we apply a double-opt-in procedure. You may withdraw consent at any time through the unsubscribe link or by contacting us. Evidence of consent may be retained for statutory limitation periods.
We use Upstash, Inc. to store feedback, email addresses and abuse-prevention counters. The database must be restricted to a suitable EU region. The actual email-delivery provider must be added here:
no automated delivery at present
9. Cookies, local storage and audience measurement
We use technically necessary cookies or similar storage access only where required for a function expressly requested by you. The legal basis for access to your terminal equipment is section 25(2) TDDDG; subsequent processing of personal data is based on Article 6(1)(b) or (f) GDPR.
Vercel Web Analytics may be used for aggregated audience measurement in a cookieless configuration. Under our configuration, it does not create cross-device or cross-site user profiles. Reports made available to us are aggregated. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is understanding usage and technical quality in a data-minimising way.
Google Analytics, Google Ads and other non-essential analytics or marketing services are not active in this baseline version. If such services are introduced later, they will be activated only after voluntary consent and this Privacy Policy will be updated in advance.
10. Recipients and processors
Depending on the functions used, the following recipients may process data:
Google Cloud EMEA Limited and Google subprocessors – AI analysis through the paid Gemini Developer API;
Vercel Inc. and subprocessors – hosting, delivery, security logs and, where applicable, cookieless audience measurement;
Upstash, Inc. and subprocessors – feedback, update subscriptions and abuse-prevention counters in the selected region;
BigDataCloud Pty Ltd – only when the place-name feature is enabled;
Dropbox, Microsoft or other cloud providers connected by the user – only during active import/export;
IT, security, legal or public authorities where required to comply with legal obligations or establish, exercise or defend legal claims.
We enter into Article 28 GDPR processing agreements with processors. Where required for third-country transfers, we rely on adequacy decisions, EU Standard Contractual Clauses and supplementary safeguards.
11. Retention periods
High-resolution originals: not sent to Google and not stored by AJ GmbH;
Previews at AJ GmbH: no permanent application-database storage; processed only for the job and technically unavoidable short-term storage;
Reference photos, temporary biometric feature representations and matching results at AJ GmbH: only for the active analysis job, then deleted from the application environment;
Technical record of the reference-photo authority confirmation: without the reference photo, name or contact details for 30 days; longer only in a specific security, misuse or legal case;
Previews and responses at Google: under current documentation, up to 55 days for security/abuse purposes unless a shorter binding zero-data-retention configuration applies;
Hosting/security logs: the actual period inserted in section 3;
Feedback/support and update subscriptions: as stated in section 8;
Consent evidence for product updates and other legally relevant records: for the applicable statutory evidence and limitation periods.
12. Data security
We implement technical and organisational measures appropriate to the processing risk. These include encrypted transmission, access restrictions, separate key and permission management, data minimisation, abuse controls, logging of security-relevant events and regular provider reviews. Absolute security of transmission or storage cannot be guaranteed.
13. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time with future effect. Processing carried out before withdrawal remains lawful.
Send requests to the privacy contact in section 1. As we do not permanently store photos and normally do not retain identity data linked to a job, we may require additional information about the time and circumstances of the job to locate relevant data. We will not retain additional data solely to identify a person where this is not required.
You also have the right to lodge a complaint with a supervisory authority. The authority normally responsible for AJ GmbH is:
The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
65185 Wiesbaden
Germany
14. Objection to processing under Article 6(1)(f) GDPR
You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will then cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required to establish, exercise or defend legal claims.
15. User Account and Registration
When you create a user account, we process your email address, your encrypted password, the selected language (locale setting), and the timestamp and record of consent given to this Privacy Policy and the Terms of Use. The legal basis is Article 6(1)(b) GDPR (performance of contract).
We use Supabase (Supabase Inc., 970 Trestle Glen Rd, Oakland, CA 94610, USA) as a processor for authentication and profile data storage. Supabase hosts data on servers in the EU region Frankfurt (AWS eu-central-1). We have concluded a data processing agreement with Supabase under Article 28 GDPR; EU Standard Contractual Clauses provide the basis for transfers to the USA.
Account data is stored for as long as the account exists. You can delete your account at any time; upon deletion your data will be permanently removed within 30 days. You may exercise your rights of access, rectification and erasure at any time through our privacy contact.
16. Changes to this Privacy Policy
We update this Privacy Policy when functions, providers or the law change. The version published on the website applies. We will not implement material changes requiring new consent without obtaining that consent.