Skip to content
stuv Friends
DE

Privacy policy

The German version is legally binding; this translation is provided for convenience.

Draft – to be reviewed together with the data protection impact assessment (Art. 35 GDPR) before launch.

1. Controller

stuv e. V., Emil-Fischer-Straße 90, 97074 Würzburg, Germany, e-mail SUPPORT_EMAIL. The University of Würzburg is not the controller; it merely provides the login service used once at registration.

2. The core idea: pseudonymity by design

  • University account: checked once via the university's login service. Your password is forwarded unchanged and neither stored nor logged. The service also tells us whether the account belongs to the student status group – only accounts with that status can register, and the answer itself is discarded immediately – and returns your university e-mail address (see below). Afterwards we keep only a keyed hash (HMAC) of the account name whose key lives outside the database. The hash cannot be reversed, is not linked to your profile and only prevents a second registration with the same account.
  • Real name: never stored, displayed or logged.
  • Date of birth: checked for age 18+ at registration; only month and year are stored.
  • Pseudonym, languages and questionnaire: the only things your match sees before a mutual yes. There are no photos, no free text and no free contact field.
  • University e-mail address: the only contact stuv Friends hands over. It is encrypted with a random per-user data key, which is itself wrapped with a key derived from your password (Argon2id). Without your password nobody – including us – can read it. When you say yes, it is re-encrypted for your match's public key; your match can only read it once both of you have said yes. Please note: university addresses usually contain your name, so after a mutual yes your match can recognise who you are.
  • Block list: stores only a keyed hash of the unordered pair of pseudonyms. The database does not reveal who said no.
  • Timestamps are rounded to the day or week wherever the function does not require more precision.

3. Gender and who you want to meet

Your gender and the genders you would like to meet serve only as a comfort filter for forming matches, for example if you would rather meet only women. By default all are selected. stuv Friends is not a dating platform; these details are not about romantic interest. Your match does not see them.

4. Purposes and legal bases

  • Running the platform, forming matches, handing over the university e-mail address after a mutual yes: performance of the contract with you (Art. 6(1)(b) GDPR).
  • Blocking after complaints, preventing circumvention of blocks: legitimate interest in a safe service (Art. 6(1)(f)).
  • We do not send e-mails; there are no notifications.

5. Cookies – no banner

We set only strictly necessary cookies: a session cookie after login, a short-lived token during registration, a form-protection token and your language choice. These fall under § 25(2) TDDDG and require no consent, which is why there is no cookie banner. There are no analytics, no tracking, no third-party content, fonts or scripts.

6. Logs

The application writes no access log with IP addresses or account names. The upstream web server keeps a technical access log in which IP addresses are anonymised after 24 hours; logs are deleted after 7 days. Security-relevant events (login, round, decision, block, admin actions) are kept in an audit log without account names, hashes or passwords, with time rounded to the day.

7. Retention

  • E-mail address handed over after a mutual yes: deleted after 30 days.
  • Matches without a mutual yes: decisions and encrypted content are deleted when the round ends; only “no mutual match” remains.
  • Profiles without login for 6 months are warned; after 7 months they are deleted automatically.
  • After you delete your profile, the hash of your university account remains for 12 months (to prevent circumvention of blocks) and is then deleted.

8. Recipients

No data is passed to third parties. The servers are located in the EU on encrypted storage with encrypted backups. The university's login service receives your account name and password once, for verification only, and returns your status group and university e-mail address.

9. Your rights

Access (Art. 15) and data portability (Art. 20) are available self-service as a JSON download in your account; deletion (Art. 17) via “Delete profile”. For rectification, restriction, objection or questions write to SUPPORT_EMAIL. You may complain to a supervisory authority, e.g. the Bavarian State Office for Data Protection Supervision (BayLDA).