1. Controller
Marco Wachsmann
von-Brentano-Str. 36
90542 Eckental
Germany
Email: hallo@relayplay.app
This privacy notice covers the current RelayPlay setup: website on its own domain, hosting at Hetzner, and a dedicated HTTPS endpoint for technical app events. This English version is provided for convenience; the German version remains authoritative.
Marco Wachsmann
von-Brentano-Str. 36
90542 Eckental
Germany
Email: hallo@relayplay.app
No separate data protection officer is currently designated in this version.
If one is appointed later, their name and contact details will be added here.
The website is hosted on infrastructure provided by Hetzner Online GmbH. When pages are accessed, technically necessary connection data is processed on the server, including in particular:
Processing takes place to provide the website securely, to analyze errors, and to defend against misuse on the basis of Art. 6(1)(f) GDPR.
Hosting provider: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
The RelayPlay website may use Google Analytics 4 for privacy-friendly usage statistics and analysis of website usage. Google Analytics is activated only if you explicitly accept analytics in the consent banner. Before your consent, the Google Analytics script is not loaded and no Google Analytics page views are sent.
For users in the EU, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The purpose is to better understand general website usage, page views, and technical usage data, and to improve the website. We do not use Google Analytics to analyze support requests, email contents, form input, or other directly entered support messages.
We use Google Consent Mode v2 for the integration. By default, analytics storage, advertising storage, personalized advertising, and advertising data sharing are disabled. Analytics storage is enabled only after you consent. Your choice is stored locally in the browser. You can change or withdraw it at any time using the “Privacy Settings” link on the website.
In addition, after your consent RelayPlay may send a simple internal page-view measurement to the RelayPlay server. This internal measurement is used for technical evaluation of real website usage and to verify website functionality. Without analytics consent, these optional website analytics events are not sent either.
The website may embed videos from the RelayPlay YouTube channel. Before playback, only a locally hosted preview image is displayed and no connection to YouTube is made. The player is loaded from youtube-nocookie.com only after you press the play button.
When the player loads, YouTube or Google receives technically necessary connection data such as your IP address, the time, the page accessed, and browser and device information. Depending on your Google settings, additional data may be processed. For users in the EU, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The video loads only after your deliberate activation. More information is available in the Google Privacy Policy.
If you contact us by email, we process the information you provide in order to handle your request. This typically includes your name, email address, the content of your message, and any additional information you voluntarily provide.
The legal basis is Art. 6(1)(b) GDPR where the request relates to a contract or pre-contractual measures; otherwise Art. 6(1)(f) GDPR.
When you suggest an independent podcast for Indie Spotlight in the RelayPlay app, we process your name, email address, the podcast name or link you enter, the RSS feed URL resolved from it, publicly available podcast metadata, and the timestamps of submission, consent, and editorial processing. We also store the editorial status of the submission, such as new, under review, accepted, rejected, or archived.
The data is used only to personally and editorially review the suggested podcast, identify duplicate submissions, manage the review status, and contact you where a question or possible inclusion makes that necessary. Your name and email address are not shown publicly. If a podcast is included, only its already public podcast and feed details appear in Indie Spotlight.
The legal basis is your consent under Art. 6(1)(a) GDPR. RelayPlay records the time of consent so that it can be demonstrated. You can withdraw consent for the future or request deletion of your submission at any time by emailing hallo@relayplay.app. This does not affect the lawfulness of processing before withdrawal.
Submission data is stored on RelayPlay's own server infrastructure hosted by Hetzner. Access is limited to the people responsible for operation and personal editorial review. The data is not sold, used for advertising, or disclosed to podcast platforms or other submitters.
RelayPlay transmits certain technical usage and diagnostic events to a dedicated HTTPS endpoint on our own server. At present, the app does not use third-party analytics, advertising trackers, or external tracking SDKs for this purpose. This processing concerns the app and is included in this privacy notice because the technical server path belongs to the same controller.
Depending on the event type, the following data may be processed in particular:
Processing serves stable app operation, troubleshooting, analysis of technical irregularities, improvement of app features, high-level usage evaluation, and protection of server operations. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is reliable, secure, and maintainable app operation.
Events are not used to create advertising profiles and are not passed on to advertising networks. Names or titles of other podcasts and episodes, audio URLs, feed hosts, search terms, playback positions, chapter timestamps, Moment content, transcript text, podcast content, or audio data are not transmitted through this event tracking. For “RelayPlay Lab”, only a hashed episode identifier is transmitted. The readable title is resolved on our own server from the public RelayPlay Lab catalogue maintained there. The identifier does not reveal other podcasts or content listened to.
The installation identifier is a random UUID. It is not derived from device or account data, is not used to track users across other apps or websites, and is not used for advertising. It may change, in particular, when the app is reinstalled. Event ingestion processes IP address and user agent only technically during the request; internal event raw data and analytics do not permanently store these values.
In Apple's privacy disclosures, this data is declared as “Usage Data – Product Interaction” and, conservatively because of the random installation identifier, as “Identifiers – Device ID”. Both categories are used only for analytics, are not linked to a real-world identity, and are not used for tracking.
Find events are immediately reduced on the server to daily counters per fixed surface and action. Random event IDs are stored only as one-way hashes to prevent duplicate counting. They contain no installation, device, podcast, or episode identifier and are deleted after no more than 30 days.
For podcast search and the Discover view, RelayPlay may use Apple's publicly available iTunes Search and Lookup interfaces. Search requests made by the app are transmitted to Apple. Apple receives technically necessary connection data such as IP address, time, requested URL, and device or user-agent information.
When you subscribe to podcasts, play episodes, load cover artwork, or retrieve audio files, the app connects to the respective podcast hosts, feed providers, CDN providers, or media services. These providers may technically see which feed, image, or audio file was requested and generally process connection data such as IP address, time, URL, and user agent. This processing is separate from RelayPlay event tracking and is technically necessary for podcast search, display, and playback.
At your explicit request, RelayPlay can automatically transcribe a short Moment clip that you have saved. Before the first transcription, iOS asks for permission to use speech recognition. RelayPlay does not create transcripts without this permission.
The clip and the resulting transcript are stored locally within the app on your device. RelayPlay does not transmit the clip or transcript to the RelayPlay server. They are not used for analytics, advertising, recommendations, or user profiles. Event tracking contains only two cumulative daily counters: how many Moments were saved and how many transcripts were created. These counters contain no titles, identifiers, timestamps, text, audio content, or URLs.
If the device supports on-device speech recognition for the language in use, RelayPlay requires processing to remain on the device. If on-device recognition is unavailable, Apple's speech recognition may require a network connection and may transmit the clip to Apple for processing. Apple's Privacy Policy also applies to that processing.
You can withdraw speech-recognition permission at any time in iOS Settings. When you delete a saved Moment, RelayPlay removes the local audio clip and its transcript from the device. Automatically generated transcripts may contain errors or be incomplete and are intended for personal reference only.
Recipients are generally only the parties responsible for operation, maintenance, and evaluation within the RelayPlay project, as well as technical service providers where their involvement is necessary for hosting or administration. At present, this primarily includes the hosting provider. For external search, feed, artwork, and audio requests, the respectively requested providers also receive the technically necessary connection data.
RelayPlay uses an internal, access-restricted dashboard for product maintenance and operational decisions. This dashboard combines first-party website and app events with aggregated data from App Store Connect, Apple Ads, Google Search Console, and Google Analytics 4. Dashboard clients do not talk directly to Google, Apple, or Reddit APIs; they access only the RelayPlay server.
Returner and active-time reporting uses only time-limited pseudonymous technical buckets. They are used to recognize multiple active days of the same app installation within the 30-day window. They are not used for advertising, user profiling, or combining Reddit, Google, Apple, website, and app users.
For the official “RelayPlay Lab” podcast, the dashboard can report completed plays per episode. After the raw-data window expires, only daily counters per non-speaking episode identifier remain; installation, event, session, and user identifiers are not carried over.
Moment usage appears in the dashboard only as aggregate counts of saved Moments and created transcripts. Content and metadata of individual Moments are neither collected nor displayed. Cumulative daily values are evaluated only once per installation using their highest reported value.
If marketing events such as Reddit or other community posts are documented in the dashboard, only public post data, aggregate metrics, and manual notes are processed. Comment author names are omitted or hashed where possible, and they are not linked to app users.
We store personal data only as long as necessary for the stated purposes or as required by statutory retention obligations.
After the 30-day period, RelayPlay app and website raw events should no longer allow conclusions about individual installations, devices, or possible users. Small person-related reporting buckets are suppressed in the anonymous aggregates. RelayPlay Lab content-only counters contain no installation or user count and are therefore exempt from that suppression.
Providing website access data is technically necessary in order to deliver the pages. The provision of app-related event data depends on the specific RelayPlay implementation. Where events are necessary for technical operation, troubleshooting, or security purposes, the ability to fully diagnose certain app states may otherwise be limited.
Under the GDPR, you have in particular the following rights:
At present, there is no solely automated decision-making, including profiling within the meaning of Art. 22 GDPR, that produces legal effects concerning you or similarly significantly affects you.
We update this privacy notice if the technical or legal situation changes. The version published on this page is authoritative.
If in-app purchases, subscriptions, accounts, iCloud synchronization, push notifications, crash reporting, or additional third-party providers are added later, this privacy notice must be expanded before use.
Version: August 23, 2026