ExplainJoy
Privacy Policy for ExplainJoy
This is a courtesy translation. The German version is legally binding.
This privacy policy applies to the web application ExplainJoy (collaborative agile retrospectives) by Deari Software. Our company website is covered by the website privacy policy; the Time Tracker app has its own app privacy policy. Provider details are in the imprint. Product page: ExplainJoy.
1. Controller
Deari Software
Festim Deari
Friedrich-Ebert-Straße 55
42103 Wuppertal
Germany
Email: kontakt@deari.de
2. Principles
ExplainJoy contains no advertising, no analytics or tracking tools (no Google Analytics, no Facebook pixel, no third-party crash tracking) and no profiling for advertising. We do not sell your data and do not share it for advertising purposes.
3. Hosting and server log files
The web application is operated by a professional hosting provider. Access generates technically necessary server log files transmitted by your browser, in particular:
- IP address of the requesting device
- date and time of access
- page or file accessed
- browser type and version and operating system
- referrer URL (previously visited page)
Processing is based on Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). Log files are deleted after a short period once they are no longer needed for security and troubleshooting. A data processing agreement pursuant to Art. 28 GDPR is or will be in place with the hosting provider.
4. Account and sign-in
Creating rooms requires an account. Sign-in is passwordless via a magic link sent to your email address. We process:
- your email address and the one-time sign-in link
- a technical user identifier (UUID)
- optional profile details (display name, profile image URL if provided)
- timestamps of account creation, sign-in and last changes
- your virtual coin balance used to activate sessions (see section 7)
The purpose is to provide your account and the application. The legal basis is Art. 6(1)(b) GDPR (performance of the usage agreement). Sign-in emails are sent by our processor Supabase.
Rooms can also be joined without your own account via a shared link; processing is then limited to what is technically necessary to take part in that room.
5. Data in decks and slides
When you use ExplainJoy we store the content you create:
- Decks: title, optional description, slide order, sharing setting, archive status, owner identifier
- Slides: name, size, background, presenter notes and the progressive reveal configuration
- Slide content: shapes, text, sticky notes, nodes, connectors and freehand drawings, including position, size and formatting
- Comments: text, author, timestamp and the slide or element they belong to, if you use commenting
A deck is private to begin with. It becomes visible to others only once you share it — to view, to comment or to edit, depending on the level you choose. Those rights are checked in the database, not only in the interface.
The legal basis is Art. 6(1)(b) GDPR.
6. Sharing and access
For each deck you decide whether it stays private or is reachable through a link. Anyone who opens a share link sees that deck's content — without an account of their own, if that is how you set it up. Sharing can be withdrawn at any time.
7. Coins and payments
Viewing and presenting are free. To edit, one virtual coin unlocks a seven-day period. We store the start and end of that period and the coin it consumed. The balance is stored on your profile; new accounts receive a starting balance.
Paid coin packs can be bought with PayPal. Checkout happens on PayPal's servers. We receive a payment confirmation (PayPal order id, amount, package, and your account id) so we can credit coins. We do not collect or store card numbers or bank details. The legal basis is Art. 6(1)(b) GDPR (performance of the purchase contract). PayPal acts as an independent controller for the payment itself; see PayPal's privacy statement for that processing.
After a successful purchase we send an invoice to the email address on your account. That is part of the purchase contract and a legal obligation (Art. 6(1)(c) GDPR).
8. Cookies and local storage
We only use technically necessary storage:
- Sign-in session (cookie or browser local storage) so you stay signed in
- Theme preference (light/dark) in your browser’s local storage
- briefly the email address after sending the magic link, so sign-in can be completed
There is no tracking cookie and no marketing-cookie banner because we do not use such cookies. The legal basis for necessary storage is Art. 6(1)(b) and (f) GDPR and § 25(2) TDDDG.
9. Recipients and processors
- Supabase, Inc. — database, authentication and realtime. Your data is stored in the EU: the server location is Ireland (AWS region eu-west-1). A data processing agreement pursuant to Art. 28 GDPR is in place with Supabase. Where, exceptionally, support or maintenance access originates in the USA, we rely on the EU standard contractual clauses (Art. 46 GDPR).
- Hosting provider of the web application — operation and delivery of the interface, including the log files described in section 3.
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — payment processing when you buy coins. PayPal receives the data needed to complete checkout and is an independent controller for that processing. We store the PayPal order id, package and amount so we can credit your coin balance once and prevent duplicate credits.
Fonts are served by us and are not loaded by the browser from Google or another font CDN.
10. Retention and deletion
Account data is kept for as long as your account exists. Rooms and cards remain until the facilitator deletes the room in the application or you request deletion of your account. After account deletion we remove your profile; associated content still needed by others in a room may continue in anonymised form until the room itself is deleted. Purchase records (PayPal order id, package, amount, timestamp) are kept as long as needed to credit coins, prevent duplicate credits, and meet commercial and tax retention duties.
You can have your account and data deleted at any time by emailing kontakt@deari.de. We will confirm once deletion is complete.
11. SSL/TLS encryption
Transmission is encrypted (HTTPS). You can recognise an encrypted connection by the “https://” prefix in the address bar.
12. Your rights
As a data subject, you have the following rights:
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- objection (Art. 21 GDPR, see section 13)
- withdrawal of consent with effect for the future (Art. 7(3) GDPR)
- lodging a complaint with a supervisory authority (Art. 77 GDPR)
To exercise these rights, write to kontakt@deari.de.
13. Right to object (Art. 21 GDPR)
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR (legitimate interest), you have the right to object at any time, on grounds relating to your particular situation, to such processing. We will then no longer process the data concerned unless we can demonstrate compelling legitimate grounds which override your interests, or the processing serves to assert, exercise or defend legal claims.
14. Children
ExplainJoy is intended for adults in professional teams and does not knowingly collect data from children under 16.
15. Changes to this privacy policy
Last updated: September 2026. We will update this policy as soon as the functionality or the data processing changes. The current version is available at this address and in the ExplainJoy application.