Privacy Policy
Skreen — Automated Reply Moderation for Bluesky
Set IT Free Medien GmbH — Set IT Free Medien GmbH, Wehrgasse 15/3, 1050 Wien, Austria / Europe — ATU71910569
Version: 27 July 2026
1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Set IT Free Medien GmbH
Wehrgasse 15/3
1050 Wien, Austria / Europe
Email:
VAT: ATU71910569
2. Principles of Data Processing
We process personal data only to the extent necessary to provide our service, where a legal basis exists, or where consent has been given. We do not collect data speculatively.
The legal bases for our processing are:
- Art. 6(1)(b) GDPR — Performance of a contract
- Art. 6(1)(c) GDPR — Legal obligation (in particular VAT law)
- Art. 6(1)(f) GDPR — Legitimate interests
3. What Data We Process and Why
3.1 Registration and Account Data
Data: Name, email address, password (hashed), preferred language, notification preferences, registration date
Purpose: Creating and managing the user account, authentication, communication
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Retention: For the duration of the contractual relationship, then 12 months, after which the account and the data stored with it are deleted. Where an account is registered but no subscription is ever concluded, the same 12 months run from registration. In both cases a warning is sent to the registered address 30 days beforehand, and the account can be deleted sooner at any time from the profile page. Billing data is kept separately for the statutory period (see 3.2).
3.2 Billing and Payment Data
Data: Billing name, company name, full billing address, country code, VAT identification number (for businesses), tax-exempt status, applicable VAT rate, payment history, Stripe customer ID
Purpose: Contract processing, invoicing, compliance with Austrian VAT law obligations
Legal basis: Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(c) GDPR (legal obligation)
Retention: 7 years in accordance with the Austrian Federal Fiscal Code (Bundesabgabenordnung, BAO)
Note on VAT ID verification: To verify VAT identification numbers for reverse charge purposes, these are checked via the EU Commission's VIES system. Country code and VAT number are transmitted to VIES for this purpose. Legal basis: Art. 6(1)(c) GDPR.
Note on address verification: The billing address is checked for plausibility so that it is correct on the invoices we are required to issue. Street, postal code, city and country code are transmitted to an address verification service operated by us on our own infrastructure; the result and the date of the check are stored. When entering the city, the search term you type is transmitted to GeoNames (Unxos GmbH, Switzerland) to offer a list of places; your IP address is not transmitted to GeoNames, because the request is made by our server and not by your browser. Legal basis: Art. 6(1)(c) GDPR (legal obligation, § 11 UStG) and Art. 6(1)(f) GDPR (legitimate interest in correct billing data).
3.3 Bluesky Credentials
Data: Bluesky handle (username), permanent DID identifier (Decentralized Identifier of the AT Protocol), encrypted App Password
Purpose: Connecting to the Bluesky platform, carrying out moderation actions on the User's behalf
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Security measures: The App Password is stored using AES-256 encryption. It is used exclusively for carrying out moderation actions on Bluesky and is never stored in plaintext or disclosed to third parties.
Retention: For the duration of the Bluesky account connection; upon disconnection of the account or cancellation of the subscription, the App Password is deleted immediately.
3.4 Post and Reply Data / Moderation Logs
Data: URIs and content of the User's monitored posts on Bluesky; content, author handle, and author DID of monitored replies; AI decision, AI reasoning, AI confidence score, AI model used, moderation action taken, timestamps
Purpose: Providing the moderation service; providing the audit log to the User (a core contractual function); traceability of moderation decisions
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Special note regarding reply authors: The content and identifiers of replies originate from persons (reply authors) who are not themselves users of our service. These persons have however posted their replies publicly on Bluesky. The processing of this publicly available data is carried out on the basis of Art. 6(1)(f) GDPR (the User's legitimate interest in moderating their public communication spaces). No special categories of personal data within the meaning of Art. 9 GDPR are processed.
Retention: Reply data — the content, author handle and author DID of monitored replies, together with the moderation decision recorded for each — is deleted 12 months after creation, unless the User has exported or manually deleted it beforehand. The record of the User's own monitored posts is retained for the duration of the subscription, because it is what allows replies to older posts to continue being moderated, and is deleted together with the account (see 3.1).
3.5 AI Processing of Content
Data: Content of the monitored post (for context), content of the reply being evaluated, the User's moderation rules
Purpose: Automatic evaluation of replies according to the User's moderation rules
Legal basis: Art. 6(1)(b) GDPR (contract performance)
AI Provider: AI processing is carried out, depending on configuration, by one of the following providers: Anthropic PBC (USA), OpenAI, L.L.C. (USA), or Mistral AI (France, EU). A Data Processing Agreement (DPA) pursuant to Art. 28 GDPR is in place with each actively used provider. Under the terms of all three providers, data submitted via their API is not used to train their AI models.
Automated decision-making: The AI makes automated decisions about moderation actions. The User can view every decision in the dashboard and manually override it. For reply authors affected by a moderation action: the action is carried out on the instruction of the account holder User and on the basis of the public nature of the content. Affected persons may request information about their data from the controller.
3.6 Notification Emails
Data: User's email address, content of the notification (moderation event, quota warning, invoice, etc.)
Purpose: Contract communication, notification about moderation events and account status
Legal basis: Art. 6(1)(b) GDPR (contract performance)
Email infrastructure: Emails are sent via our own Mailix infrastructure (mailix.de). No external email service provider is used.
3.7 Log Data (Server Logs)
Data: IP address, timestamp, requested URL, HTTP status, browser type (user agent), referrer
Purpose: Security, error diagnosis, abuse detection
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service security)
Retention: 14 days, then automatic deletion
3.8 Spam Protection on Public Forms (Cloudflare Turnstile)
Data: IP address, browser and device characteristics (user agent, browser configuration) and interaction signals, transmitted to Cloudflare when the challenge runs
Purpose: Distinguishing human visitors from automated submissions on our publicly accessible forms, in order to prevent spam and abuse
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in protecting publicly accessible forms against automated misuse)
Retention: We store neither the verification token nor its result. Only the outcome of a rejected check is written to our server log as an error code, without an IP address. Cloudflare's own retention applies to the data transmitted to it; according to Cloudflare, Turnstile does not use cookies for tracking purposes and is not used to build user profiles or for advertising.
4. Recipients and Processors
We share your personal data only to the extent necessary to provide the service. We have concluded Data Processing Agreements pursuant to Art. 28 GDPR with all external service providers processing personal data on our behalf.
| Recipient | Purpose | Location | Basis for third-country transfer |
|---|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing | Ireland (EU) | No third-country transfer |
| Anthropic PBC | AI content analysis | USA | Standard Contractual Clauses (SCCs) |
| OpenAI, L.L.C. | AI content analysis | USA | Standard Contractual Clauses (SCCs) |
| Mistral AI | AI content analysis | France (EU) | No third-country transfer |
| Cloudflare, Inc. | Spam protection on public forms (Turnstile) | USA | Standard Contractual Clauses (SCCs) |
| Bunny.net (BunnyWay d.o.o.) | Web font delivery | Slovenia (EU) | No third-country transfer |
| jsDelivr (Prospect One) | Stylesheet delivery on the payment page | Poland (EU) | No third-country transfer |
| VIES (European Commission) | VAT ID validation | EU | No third-country transfer |
| GeoNames (Unxos GmbH) | City lookup for the billing address | Switzerland | Adequacy decision (Art. 45 GDPR) |
Skreen operates with only one AI provider active at any given time; which of the three listed providers is active can be changed administratively. Data is only transferred to a third country (USA) when Anthropic or OpenAI is active, safeguarded by Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR. When Mistral AI is active, data remains within the EU.
5. Your Rights as a Data Subject
Under the GDPR you have the following rights, which you may exercise by contacting us at :
Right of access (Art. 15 GDPR): You may request information about the data stored about you.
Right to rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
Right to erasure (Art. 17 GDPR): You may request the deletion of your data, to the extent that no statutory retention obligations apply.
Right to restriction of processing (Art. 18 GDPR): Under certain conditions, you may request that processing be restricted.
Right to data portability (Art. 20 GDPR): You may receive your data in a structured, commonly used, machine-readable format. The service provides an export function in the dashboard for this purpose.
Right to object (Art. 21 GDPR): You may object to processing of your data on the basis of legitimate interests.
Right to lodge a complaint: You have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, dsb.gv.at).
Rights of Reply Authors (Non-Registered Third Parties)
Persons whose replies on Bluesky have been processed by our service and who are not themselves users of our service may also exercise their data protection rights by contacting us at . To process such requests, provision of the relevant Bluesky handle or DID, together with proof of the right to use it, is required.
6. Data Security
We implement technical and organisational measures to protect your data against unauthorised access, loss, or destruction. These include in particular:
- Encryption of Bluesky App Passwords using AES-256
- Encrypted transmission of all data via HTTPS/TLS
- Access restrictions on personal data based on the principle of least privilege
- Regular security updates to the software used
- Storage of invoice PDFs in a non-publicly-accessible directory, served via signed temporary URLs only
7. Cookies and Web Analytics
7.1 Technically Necessary Cookies
The service uses technically necessary session cookies for authentication and operation of the web application. No advertising cookies or third-party cookies are used. Consent is not required for technically necessary cookies.
7.2 Web Analytics with Matomo
We use Matomo (formerly Piwik), an open-source web analytics software, to analyse visitor behaviour on our website in a privacy-friendly manner. Matomo is operated exclusively on our own servers in Austria. No data is transmitted to third parties.
The following privacy-protective measures are in place for visitors to our public website:
- No cookies: Matomo is configured without cookies. No tracking cookie is set on your device.
- IP anonymisation: IP addresses are anonymised before storage. The last two octets of IPv4 addresses and the last 80 bits of IPv6 addresses are masked. The full IP address is never stored.
- No cross-site tracking: Because no cookies are used, tracking across different websites is not possible.
- Data stored: Anonymised IP address fragment, pages visited, time of visit, approximate geographic region (country/city level only, derived from the anonymised IP), browser type, operating system, referrer URL, session duration.
When logged in to the dashboard: If you are logged in to your dashboard as a registered user, your usage is additionally linked to an internal, purely numeric account identifier (not your name or email address). This allows us to understand how individual accounts use our service, for example for troubleshooting or to understand which features are used. For visitors to our public website who are not logged in, analytics remain fully anonymous as described above.
Subscription and payment data: When a payment succeeds, the amount paid and the subscribed plan are linked to your internal account identifier in Matomo for revenue reporting.
Purpose: Understanding how our website and service are used in order to improve them, and revenue reporting for our business operations. For visitors to our public website who are not logged in, no individual user profiles are created; for logged-in users, account-linked analysis takes place as described above.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving our service and in revenue reporting for our business operations. Because no cookies are used and IP addresses are anonymised, anonymous analysis of website visits does not require consent under the ePrivacy Directive or Austrian TKG.
Opt-out: You may object to the anonymous analysis of your website visit at any time. If your browser sends a Do Not Track (DNT) signal, Matomo respects it and does not record your visit — since Matomo operates without cookies, this setting is re-checked on every page visit. The transmission of confirmed subscription and payment data (see above) is not affected by this setting, as it forms part of the contractual processing of a payment that has already been completed, rather than analysis of your browsing behaviour. You may submit access or deletion requests regarding this data at any time via .
Retention: Analytics data in Matomo is automatically deleted after 12 months. This applies only to the copy of the data held in Matomo; the underlying invoices themselves remain separately subject to the statutory seven-year retention period under the Austrian Federal Fiscal Code (Bundesabgabenordnung) — see Section 3.2.
8. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy to reflect changes in legal requirements or changes to our service. The current version is always available on our website. Registered Users will be notified by email of material changes.
9. Privacy Contact
For questions about data protection please contact:
Set IT Free Medien GmbH
Attn: Data Protection
Wehrgasse 15/3
1050 Wien, Austria / Europe
Skreen — Set IT Free Medien GmbH — Version: 27 July 2026