Legal

Privacy policy

Translation notice: This English translation is provided for convenience. The German privacy policy is legally authoritative.

1. Controller

The controller responsible for processing personal data on this website is:

Ruth Scherz
Business name: Ruth Scherz Medienproduktion

Speierlingweg 25
60388 Frankfurt
Germany

Telephone: +49 155 67023672
Email: datenschutz@fearscore.de

2. Hosting and server log files

This website is hosted by:

ALL-INKL.COM – Neue Medien Münnich
Proprietor: René Münnich
Hauptstraße 68
02742 Friedersdorf
Germany

When you visit this website, the hosting provider automatically processes information transmitted by your browser to the web server. This particularly includes:

This processing is necessary to provide the website, ensure its stability and security, identify technical faults and defend against attacks.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure, reliable and functional operation of this website.

Server log files are deleted after no more than seven days. They may be retained longer in individual cases if required to investigate a specific security incident.

ALL-INKL.COM processes hosting data on our behalf. We have concluded a data-processing agreement with the hosting provider pursuant to Article 28 GDPR.

Further information about the provider's processing is available at all-inkl.com/datenschutzinformationen/.

3. Encrypted transmission

This website uses TLS encryption. Data transmitted between your browser and our website is therefore protected against unauthorised access by third parties.

An encrypted connection can be identified in particular by “https://” in the browser address bar.

4. Contacting us

If you contact us by email or telephone, we process the data you provide. This may include your name, email address, telephone number, the content of your message and any other information you provide voluntarily.

If contact relates to entering into or performing a contract, Article 6(1)(b) GDPR is the legal basis. Other enquiries are processed on the basis of Article 6(1)(f) GDPR. Our legitimate interest is handling and responding to your enquiry.

The data is deleted once your enquiry has been conclusively handled and no statutory retention obligation or legitimate interest requires further storage. Providing your data is voluntary. Without the contact details needed for a response, we may be unable to handle your enquiry.

5. Local storage on the website, web app and end devices

The website at fearscore.de and the web app at app.fearscore.de use your browser's local storage (localStorage). Depending on the function used, this may store your chosen language, festival city and festival year, ratings already submitted and a randomly generated device identifier. In the native FearScore app, your festival schedule, watchlist, personal film ratings and technical settings are initially stored on the device used.

Local storage keeps functions and settings you expressly select available on subsequent visits, helps limit duplicate votes and allows the app to remain usable during a temporary loss of connection. The device identifier contains neither a name nor an email address. It is nevertheless a pseudonymous identifier and may constitute personal data when combined with stored actions.

Storing and accessing this information on the end device does not require consent under section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG), because it is strictly necessary to provide the function expressly requested, such as language selection, festival schedule, watchlist, personal rating or voting. The information is not used for advertising, analytics or tracking.

Where locally stored information is personal data, processing is based on Article 6(1)(b) GDPR where required to provide the requested function, and otherwise on Article 6(1)(f) GDPR. Our legitimate interest is the functional and user-friendly provision of FearScore.

Purely local storage does not by itself transmit information to us. Browser data can be deleted in your browser settings; local app data can be removed by deleting the app or through the relevant system functions. Separate server-side and iCloud-based synchronisation are described below.

6. Server-side web app functions and synchronisation

To make personal selections available again within the web app and to provide community functions, the web app transmits the random device identifier together with the selected function data to its servers. This may include film or screening identifiers in the festival schedule and watchlist, personal film ratings, and liked or saved FearLog posts. These functions do not request names, email addresses or payment information.

This server-side storage is separate from storage on the device. It allows the function state associated with the device identifier to be retrieved again. The identifier is pseudonymous but remains technically retrievable for the server-side functions of the web app. Only aggregated information, such as the number of votes and average score, is displayed publicly; the device identifier and personal festival schedule are not public.

Ratings on the fearscore.de website are processed separately. Before permanent storage, the random device identifier is pseudonymised as an HMAC hash using a secret server value. The category, content identifier, rating and time are also stored to help limit duplicate votes from the same browser.

The legal basis is Article 6(1)(b) GDPR where processing is required to provide the expressly requested function, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is the reliable operation, prevention of misuse and user-friendly synchronisation of the web app.

The web app is provided through ChatGPT Sites by OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. OpenAI processes Hosted Data as our processor and uses further sub-processors, including Cloudflare for content delivery and web hosting. Further information is available in the ChatGPT Sites Data Processing Addendum and the sub-processor list.

7. Native FearScore app and Apple iCloud

In the native FearScore app, your personal festival schedule, watchlist and personal film ratings are additionally synchronised between devices using Apple's iCloud key-value storage. This requires the same Apple Account to be used for iCloud on those devices and iCloud to be available for FearScore. The synchronised content is stored in the user's private iCloud area. The synchronisation does not include names, email addresses or payment information collected by FearScore and is not used for advertising or tracking.

For processing, storing and handling personal app data supplied by FearScore through the iCloud interfaces, Apple acts under the Apple Developer Program terms as a service provider or processor on our behalf. For management of the Apple Account, provision of iCloud, billing, security, fraud prevention and Apple's own technical and diagnostic processing, Apple acts as an independent controller under its own privacy terms.

For users in the European Economic Area, Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, is generally responsible for Apple's own iCloud processing. You can manage iCloud use in your device settings. Further information is available in Apple's Privacy Policy and Apple Account and iCloud privacy information.

8. Cookies and similar technologies

FearScore currently uses no advertising, analytics or tracking cookies. Apart from the functionally necessary local storage described in section 5, no comparable technologies are used to store or access information on end devices for advertising or analytics purposes.

The storage access currently used is strictly necessary and therefore does not require consent under section 25(2)(2) TDDDG. A cookie consent banner is not currently used. Should FearScore introduce non-essential analytics, advertising or tracking technologies in the future, consent will be obtained before they are used.

9. Voluntary support through PayPal

No PayPal content or scripts are embedded on this website. Only when you select a support link do you leave FearScore and open PayPal's external service. PayPal may process connection, account and payment data there under its own privacy policy. PayPal is responsible for that processing.

10. External links

FearScore links to external providers of trailers, streaming, purchases, information and payments. Their content is not embedded automatically. The respective external website opens only after you select a link. That provider's privacy policy then applies.

11. Recipients of personal data

Depending on the function used, the following recipients may receive personal or pseudonymous data:

Data is disclosed to further recipients only where necessary to handle an enquiry or provide an expressly used function, where we are legally obliged to do so, where necessary to establish, exercise or defend legal claims, or where prior consent has been given.

12. Transfers to third countries

When iCloud synchronisation is used, Apple may process personal data through Apple Inc. or other affiliated companies outside the European Union or European Economic Area, particularly in the United States. Apple states that international transfers of personal data collected in the European Economic Area are governed by the European Commission's Standard Contractual Clauses.

OpenAI and its sub-processors may also process web app data in countries outside the European Union or European Economic Area. OpenAI Ireland Ltd. states that it relies in particular on adequacy decisions and the European Commission's Standard Contractual Clauses for such transfers. Details are available in the ChatGPT Sites Data Processing Addendum and the current sub-processor list.

If you voluntarily open an external service, that provider's privacy information also applies.

13. Retention periods

We retain personal data only for as long as required for the respective purpose. It is then deleted unless statutory retention duties, ongoing legal disputes or other legitimate reasons require further storage.

The specific retention period for server log files is stated in the “Hosting and server log files” section. Information stored locally remains until removed through browser or app data settings or by deleting the app. App data stored in iCloud remains subject to the user's iCloud settings and deletion actions. Film and article rating records and pseudonymous web app function data are deleted no later than 24 months after the last use.

14. Rights of data subjects

Subject to the statutory requirements, you have the right:

To exercise your rights, contact us at datenschutz@fearscore.de.

15. Right to object

Where we process personal data on the basis of Article 6(1)(f) GDPR, you have the right to object at any time on grounds relating to your particular situation.

We will then cease processing the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is required to establish, exercise or defend legal claims.

16. Right to lodge a complaint

You have the right to lodge a complaint about the processing of your personal data with a data protection supervisory authority.

In particular, you may contact the state data protection authority responsible for our registered office or the supervisory authority of your habitual residence.

17. Automated decision-making

No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place.

18. Changes to this privacy policy

We update this privacy policy if the services used, the processing of data or the legal requirements change.

Last updated: 1 September 2026