Privacy Policy

Last updated: 14 August 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

AJ GmbH

Danziger Str. 80

65191 Wiesbaden

Germany

Represented by: Dr Andreas Jahnke

Privacy contact: privacy@shortlistbuddy.com

2. Scope and minimum age

This Privacy Policy applies to the website and the ShortlistBuddy photo-selection service. The service is intended for personal, private or family photo management.

Use requires a minimum age of 18. The service is offered to adult users only — including where Article 8 GDPR would already allow a person to consent for themselves from the age of 16: the terms of the AI provider we use prohibit applications directed at minors or likely to be used by them. You confirm your age yourself; we collect no further data for age verification. Minors may appear in private photos and reference photos.

The user decides which private photos and which known persons are analysed. ShortlistBuddy must not be used for professional or commercial purposes, public person searches, surveillance or identification of unknown persons. For the optional Persons feature, before using a reference photo the user confirms that they are authorised to use it in a private, personal or family context; details and the applicable limits are in section 4.3.

3. Website access and technical log data

When the website is accessed, technically necessary data is processed, in particular the IP address, time, requested URL, HTTP status, data volume, referrer information, browser/device information and technical error data. This processing is necessary to deliver the website, prevent attacks and misuse, and maintain stability.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of the service. Recipients include our hosting provider Vercel Inc. and its subprocessors.

Regular retention period for hosting/security logs accessible to us: 30 days. Relevant data may be retained for longer where necessary to investigate security incidents or establish, exercise or defend legal claims.

4. AI-assisted photo selection

4.1 Data processed and workflow

When you start a photo-selection job, you select photos on your device or in your connected cloud. ShortlistBuddy creates reduced JPEG previews in your browser with a maximum size of 512 × 512 pixels. High-resolution originals are transferred neither to AJ GmbH nor to our AI provider; they stay wherever you keep them — locally on your device or in your Dropbox, for example. The later download/ZIP file is created locally in your browser.

For the analysis, we process the previews, a technical job identifier and, where required for sorting, selected metadata such as capture date and camera model. The optional Persons feature runs independently of this, entirely on your device; we receive neither the reference photo, nor a name, nor a result from it, and none of it is transmitted to Google — see section 4.3 for details. Where a photo contains GPS coordinates, we send them along in rounded form so the AI can derive a place name from them; details and the reason for the rounding are in section 6.

The previews are transmitted through our technical infrastructure to Google’s paid Gemini Developer API. The AI evaluates the images against criteria selected by the user and creates a non-binding proposed selection. The user can review, modify or reject the result.

4.2 Roles, purposes and legal framework

AJ GmbH is the controller for website operation, security and abuse logs, support, product updates and its own contractual data. The relevant purposes and legal bases are described in the respective sections of this Privacy Policy.

For the photo content selected by the user, metadata and analysis results, AJ GmbH processes the data solely on the instruction triggered by the user and only to perform the specific private analysis job. AJ GmbH does not pursue its own purposes with this content, does not use it for advertising or model training and is structured as a processor in this respect. The user determines the photos, selection criteria and private purpose. The supplementary processing terms form part of the Terms of Use. Reference photos and the facial features derived from them for the optional Persons feature are not covered by this processing arrangement — AJ GmbH never receives them, see section 4.3.

Where the user processes photos solely in the course of personal or household activities, the user’s own processing falls within the household exemption in Article 2(2)(c) GDPR. This exemption does not apply to AJ GmbH or the technical providers we use; we remain subject in particular to the data-protection and security obligations applicable to processors. ShortlistBuddy does not make solely automated decisions producing legal or similarly significant effects within Article 22 GDPR.

4.3 Reference photos and local person search

The optional Persons feature compares the face in a reference photo with faces in the private photos selected by the user, in order to find a previously specified person known to the user. This matching runs entirely in the user’s browser; no transfer to AJ GmbH, Google or any other third party takes place.

The reference photo, the facial features derived from it (biometric data within the meaning of Article 9(1) GDPR), the photos being searched and the matching result never leave the user’s device. AJ GmbH receives neither the reference photo nor the derived features nor the result, and can therefore neither store, evaluate nor use them for its own purposes. The software used for this is served from our own infrastructure; once loaded, matching also works without an active internet connection.

Because AJ GmbH is not technically involved in this specific processing operation, we take the view that we are not a controller within the meaning of Article 4(7) GDPR for the local person search itself; we merely provide the technical tool. There is no supreme-court decision yet on this specific configuration — a service providing a face-search feature that runs entirely in the private user’s browser and whose data never reaches the provider — and we consider this classification well-founded, though not conclusively settled.

Where the user processes photos solely in the course of personal or household activities, the user’s own processing regularly falls within the household exemption in Article 2(2)(c) GDPR — for example, finding family members or friends in private holiday or everyday photos.

The Persons feature may be used only in a private, personal or family context. In particular, the following are prohibited: professional, commercial or institutional use — for example towards employers, employees, customers or event attendees —, surveillance of public or semi-public spaces, security or law-enforcement purposes, building person or facial databases, and creating commercial person profiles. Before using a reference photo, the user confirms that they are authorised to use it in a private, personal or family context. This is a contractual representation, not consent under Article 9(2)(a) GDPR — we do not consider such consent necessary for purely local processing.

The user decides how strict or lenient the person search is in reporting matches. At most four reference persons can be stored at the same time.

Whether and to what extent the Persons feature is available is governed by the Terms of Use. This has no effect on the processing described in this section.

4.4 Objection and requests from persons shown

A person shown may tell the user that their reference photo must no longer be used for the person search; the user must respect that decision. Because processing takes place exclusively on the user’s own device and AJ GmbH receives no data about it, our privacy contact can only speak to how the feature works in general — we cannot act on a specific processing operation, as we have no access to it.

Do not upload identity documents, medical images, intimate content or other highly sensitive images. If such content is nevertheless uploaded, it is technically processed like any other preview; no separate professional or substantive analysis is intended.

5. Google Gemini Developer API

We use a paid Gemini Developer API account for AI analysis. According to Google’s current contracting-entity information, the contracting entity for customers with a German billing address is generally Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, unless the specific cloud agreement states otherwise.

Under the Paid Services terms, Google does not use submitted inputs, files or responses to improve or train its models. We do not enable voluntary sharing of logs or datasets with Google and do not use the data for model training.

What governs is the data processing agreement concluded with the AI provider, in the version applicable at the time of the relevant processing. AI providers may change their terms for the future. Should a provider change its terms such that the commitments described in this section — in particular the exclusion of model training and the limited retention — no longer apply, we will discontinue that provider before the change takes effect for us, or switch to another provider. We will update this Privacy Policy beforehand. For processing already completed, the version described at the time of processing remains decisive.

Google may retain inputs and outputs for security, abuse-detection and legal purposes for a limited period. Google’s current documentation states that this may be up to 55 days. Additional retention may arise depending on the API features used. We therefore do not use the File API, permanently stored datasets or persistent context caching, and disable storage for stateful API features where technically possible.

Google may process data in countries where Google or its subprocessors maintain facilities. The relevant data processing agreement, European Commission Standard Contractual Clauses and/or an applicable adequacy decision provide the transfer basis. Residual risks may remain for processing outside the European Economic Area, particularly statutory access powers in the recipient country.

6. Place names from GPS data

Many cameras and smartphones write the location of capture into the image file as GPS coordinates. So that you can sort your selection by place, the AI derives a place name from those coordinates (“Lisbon, Portugal”). The place name is shown in the results overview and can be used as the folder structure in the download file.

This is done by the same AI provider that performs the image analysis anyway (section 5). We use no additional geocoding service and no further recipient for it.

Coordinates are rounded before transmission. We send them truncated to two decimal places, which corresponds to a grid of roughly one kilometre. That is enough to name a town or region, and it makes deriving a single address considerably harder. We cannot rule it out: in sparsely populated areas, or combined with the image content, even such a grid may point to a particular building. The full coordinates never leave your device — they appear only in the locally generated download file, which also stays on your device.

The legal basis is Article 6(1)(b) GDPR: assigning places is part of the selection service you commissioned. If a photo contains no GPS data, nothing is transmitted for that photo and no place name is formed. If you would rather not transmit location data at all, remove the GPS data from your photos before uploading or switch off location recording in your camera app.

AJ GmbH does not permanently store the coordinates. Retention at the AI provider is governed by section 5.

7. Optional cloud import and export

Dropbox is currently enabled as a cloud provider, both for importing photos and for exporting your selection. Other providers (such as Microsoft OneDrive) are prepared but not active; before enabling any of them we will name it at this point.

Authorisation is performed via OAuth. We request permissions separately and only when you trigger the relevant operation: for export, the write permission only; for import, read permission for file and folder information and for file content. So that you can pick your photos from any folder, the read permission covers your entire Dropbox rather than just an app folder. We see only what you actually open and select in the picker; we do not search your storage on our own initiative and do not build an index of it.

Files flow directly between your browser and Dropbox — not through our servers. OAuth tokens are held in memory only for the duration of the transaction or browser session and are not stored permanently. You can revoke the connection at any time in the security settings of your Dropbox account.

The legal basis is Article 6(1)(b) GDPR. The privacy terms of the relevant cloud provider also apply to processing within your cloud account. Review the displayed permissions before granting access.

8. Feedback, support and product updates

If you send feedback or a support request, we process your contact details, message and necessary technical information to handle the request and improve the service. Depending on the content, the legal basis is Article 6(1)(b) or (f) GDPR. Our legitimate interest is handling requests and correcting errors.

Regular retention period for feedback/support data: 12 months after closure, unless statutory retention duties or legal claims require longer storage.

If you subscribe to product updates, we process your email address based on your consent under Article 6(1)(a) GDPR and section 7(2) of the German Unfair Competition Act. Where used, we apply a double-opt-in procedure. You may withdraw consent at any time through the unsubscribe link or by contacting us. Evidence of consent may be retained for statutory limitation periods.

We use Upstash, Inc. to store feedback, email addresses and abuse-prevention counters; the database is restricted to an EU region. To send emails — in particular account confirmation and sign-in emails and the forwarding of feedback to our inbox — we use Resend, Inc. (USA), which in turn uses Amazon Simple Email Service as a subprocessor. We have concluded Article 28 GDPR processing agreements with both providers; EU Standard Contractual Clauses provide the basis for transfers to the USA.

8a. Payment processing

At present only the free plan is enabled; no payment processing takes place. Once you book a paid plan, we process the payment through Stripe Payments Europe, Ltd. (Ireland). You enter your payment details directly with Stripe; complete card or account details do not reach us.

In this context we process the payment reference, the plan booked, the amount, the payment status and the time, together with the invoice data Stripe reports back to us. The legal basis is Article 6(1)(b) GDPR (performance of contract) and, as regards invoices and accounting records, Article 6(1)(c) GDPR in conjunction with commercial and tax retention obligations.

Stripe acts as an independent controller for the payment transaction and for meeting its own regulatory obligations; Stripe’s privacy policy applies in addition.

8b. Withdrawal via the withdrawal function

On the “Withdraw from contract” page you can declare your withdrawal electronically. For this we process the details section 356a(2) of the German Civil Code provides for that function: your name, the identifier of the contract or order, the email address for the acknowledgement of receipt, and any voluntary additional information you choose to give. We also record the time at which your declaration reached us.

The purpose is to handle your withdrawal and to evidence that and when it was received. The legal basis is Article 6(1)(b) GDPR for performing the contractual relationship and Article 6(1)(c) GDPR for the statutory duties under sections 355 and 356a of the German Civil Code — in particular the duty to confirm receipt to you without undue delay on a durable medium.

We send the acknowledgement by email through our delivery provider Resend (see sections 8 and 10). Your details are transmitted to that provider for this purpose.

We keep the withdrawal declaration together with its time of receipt for as long as claims arising from the contract concerned can be brought or defended, and delete it afterwards. Unlike our other beta records, these entries are not trimmed automatically: they evidence that you exercised a statutory right, and that evidence serves your interest too.

You may equally declare your withdrawal informally by email or letter; the function is an additional route, not a precondition.

9. Cookies, local storage and audience measurement

We use technically necessary cookies or similar storage access only where required for a function expressly requested by you. The legal basis for access to your terminal equipment is section 25(2) TDDDG; subsequent processing of personal data is based on Article 6(1)(b) or (f) GDPR.

9.1 Our own usage and campaign measurement

To understand where the service is intelligible and where users drop out, we record our own events — for example opening the home page, starting a photo selection, completion or failure of an analysis, and downloading the result. The events are sent exclusively to our own endpoint on the same domain and stored with our provider Upstash in the EU. We do not embed any third-party counting pixels, tags or scripts for this.

With an event we store a random session identifier, the device class (mobile, tablet, desktop), operating-system and browser family, the language version, a coarse size band for the number of photos selected, and — if you arrived through an advertisement we placed — the campaign markers contained in the address you called up (the so-called UTM parameters). We do not store file names, image content, location data or email addresses.

This measurement does not access your terminal equipment. The session identifier exists only in your browser’s memory and ends when you close the page; it is stored neither in a cookie nor in your browser’s local storage. No consent under section 25 TDDDG and no cookie banner is therefore required. The price of this restraint is that we cannot recognise returning visitors — which is intended.

Click identifiers assigned by advertising networks (such as gclid or fbclid), which may be attached to the address when you arrive through an advertisement, are neither stored nor evaluated by us.

If you are signed in to your user account, we additionally associate these events with a pseudonymous identifier derived from your account identifier. This is the only way for us to see whether the service is used a second time. No such association is made while you are not signed in.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is being able to assess the intelligibility, technical quality and economics of the service in a data-minimising way without using third-party tracking services. You may object to this processing under Article 21 GDPR; please contact our privacy contact. For retention periods see section 11.

9.2 Audience measurement by Vercel

In addition to our own measurement under section 9.1, we use Vercel Web Analytics to assess reach and the technical quality of the website. The service works without cookies and without any other access to your device; no cross-device or cross-site user profiles are created.

According to the provider, the following is collected: time of the request, the address and page pattern requested, the referring page, campaign parameters, an approximate location derived from the request (country, region, city), operating system, browser and device type each with version, and the version of the measurement script.

To distinguish requests, Vercel derives a hash from the incoming request — not a recognition value stored on your device. According to the provider that hash is discarded after 24 hours at the latest; only aggregated reports remain afterwards.

We do not transmit query strings. Before sending, we remove all query parameters except the campaign identifiers (utm_*), and requests to our administrative area are not reported at all. Neither payment or job identifiers nor access keys therefore reach the service.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is understanding usage and technical quality in a data-minimising way. As no access to your device takes place, consent under section 25 TDDDG is not required. The recipient is Vercel Inc.; on transfers to third countries see section 10. You may object to this processing under Article 21 GDPR.

9.3 No third-party analytics or marketing services

Google Analytics, Google Ads, the Meta pixel and other non-essential analytics or marketing services are not active. We have deliberately decided against using them to evaluate our advertising campaigns and instead evaluate those through our own measurement described in section 9.1. If such services are introduced later, they will be activated only after voluntary consent and this Privacy Policy will be updated in advance.

10. Recipients and processors

Depending on the functions used, the following recipients may process data:

Google Cloud EMEA Limited and Google subprocessors – AI analysis through the paid Gemini Developer API;

Vercel Inc. and subprocessors – hosting, delivery, security logs and cookieless audience measurement (section 9.2);

Upstash, Inc. and subprocessors – feedback, update subscriptions, abuse-prevention counters and the events of our own usage measurement under section 9.1, in the EU region;

Supabase, Inc. and subprocessors – accounts, authentication and job data (see section 15);

Resend, Inc. and Amazon Web Services – delivery of account and feedback emails;

Stripe Payments Europe, Ltd. – payment processing once you book a paid plan (see section 8a);

Dropbox – only if you use the cloud import or export; other cloud providers currently not active;

IT, security, legal or public authorities where required to comply with legal obligations or establish, exercise or defend legal claims.

We enter into Article 28 GDPR processing agreements with processors. Where required for third-country transfers, we rely on adequacy decisions, EU Standard Contractual Clauses and supplementary safeguards.

11. Retention periods

High-resolution originals: not sent to Google and not stored by AJ GmbH;

Previews at AJ GmbH: no permanent application-database storage; processed only for the job and technically unavoidable short-term storage;

Reference photos, facial features derived from them and matching results of the Persons feature (section 4.3): never leave the user’s device; AJ GmbH does not receive or store them;

Previews and responses at Google (general photo analysis, section 5): under current documentation, up to 55 days for security/abuse purposes unless a shorter binding zero-data-retention configuration applies;

Hosting/security logs: 30 days, see section 3;

Feedback/support and update subscriptions: as stated in section 8;

Rounded GPS coordinates used for place naming: not stored by AJ GmbH; at the AI provider the same periods apply as for the previews;

Events of our own usage measurement under section 9.1: 90 days in individual form, thereafter only in aggregated form without any session or account reference;

Payment and invoice data under section 8a: for the duration of commercial and tax retention periods, as a rule up to ten years;

Confirmation of authorisation to use reference photos (section 4.3): client-side only; not transmitted to or stored by AJ GmbH;

Consent evidence for product updates and other legally relevant records: for the applicable statutory evidence and limitation periods.

12. Data security

We implement technical and organisational measures appropriate to the processing risk. These include encrypted transmission, access restrictions, separate key and permission management, data minimisation, abuse controls, logging of security-relevant events and regular provider reviews. Absolute security of transmission or storage cannot be guaranteed.

13. Your rights

Subject to statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time with future effect. Processing carried out before withdrawal remains lawful.

Send requests to the privacy contact in section 1. As we do not permanently store photos and normally do not retain identity data linked to a job, we may require additional information about the time and circumstances of the job to locate relevant data. We will not retain additional data solely to identify a person where this is not required.

You also have the right to lodge a complaint with a supervisory authority. The authority normally responsible for AJ GmbH is:

The Hessian Commissioner for Data Protection and Freedom of Information

Wilhelmstraße 7

65185 Wiesbaden

Germany

14. Objection to processing under Article 6(1)(f) GDPR

You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will then cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is required to establish, exercise or defend legal claims.

15. User Account and Registration

When you create a user account, we process your email address, your encrypted password, the selected language (locale setting), and the timestamp and record of your acceptance of the Terms of Use and your acknowledgement of this Privacy Policy. The legal basis is Article 6(1)(b) GDPR (performance of contract).

15.1 Account when starting an analysis

Every analysis technically runs against a named job so that photo volumes, allowances and results can be assigned unambiguously. An account with a confirmed email address is required to run an analysis — including on the free plan. The reason is the statutory confirmation of the contract in text form (section 312f of the German Civil Code): without an address we could not send it to you.

The legal basis is Article 6(1)(b) GDPR; without this assignment the job you initiated cannot be carried out. Anonymous accounts without contact details may still exist from the earlier open beta phase; they do not allow sign-in from another device. We delete those accounts and the associated job data on a routine basis, at the latest 90 days after the last job.

15.2 Account and usage measurement

While you are signed in, we associate the events described in section 9.1 with a pseudonymous identifier derived from your account identifier. We do not build profiles of individual users from this; we evaluate only how often the service is used a second time overall.

We use Supabase (Supabase Inc., 970 Trestle Glen Rd, Oakland, CA 94610, USA) as a processor for authentication and profile data storage. Supabase hosts data on servers in the EU region Frankfurt (AWS eu-central-1). We have concluded a data processing agreement with Supabase under Article 28 GDPR; EU Standard Contractual Clauses provide the basis for transfers to the USA.

Account data is stored for as long as the account exists. You can delete your account at any time; upon deletion your data will be permanently removed within 30 days. You may exercise your rights of access, rectification and erasure at any time through our privacy contact.

16. Changes to this Privacy Policy

We update this Privacy Policy when functions, providers or the law change. The version published on the website applies. We will not implement material changes requiring new consent without obtaining that consent.