Privacy Policy
Privacy Policy
Applies to silverfriend.de and related online offerings of Silverfriend GmbH. The mobile app is also covered by sections 5.5 to 5.7 of this policy. The German Datenschutzerklärung is the legally binding original; this English version is a courtesy translation.
Last updated: 24 August 2026
Version: 1.3
🌐 Diese Richtlinie auf Deutsch lesen
1. Controller (Art. 4(7) GDPR)
Silverfriend GmbH
Döringstraße 6, 10245 Berlin, Germany
Email: datenschutz@silverfriend.de
Phone: +49 15678 616839
Managing Director: Feras Alsamawi — see Legal Notice.
2. Data Protection Officer
Until an external Data Protection Officer has been formally appointed by name, please reach us on any data-protection matter directly at:
Email: datenschutz@silverfriend.de
Postal: c/o Silverfriend GmbH, Döringstraße 6, 10245 Berlin, Germany
3. Scope and definitions
This policy explains:
- who we are and how to reach us,
- what personal data we process,
- why we process it and on what legal basis,
- who receives it,
- how long we store it,
- what rights you have and how to exercise them.
"Personal data" means any information relating to an identified or identifiable natural person (Art. 4(1) GDPR).
4. Two data-subject roles
Our service involves two distinct categories of people with different roles:
- Subscriber / family caregiver — the person who signs up and uses the app.
- Senior / called person — the person our phone companion calls.
Each has its own rights and its own consent path. The senior's consent for voice processing is captured directly on the call, not through the caregiver's app.
5. What we process and why
5.1 When you visit the website
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, browser user-agent, request timestamp | Site delivery, security logging | Art. 6(1)(f) GDPR (legitimate interest: operations and security) | 14 days in access logs, then deleted or pseudonymised |
| Pseudonymous session data (privacy-focused analytics, with consent) | Reach analytics | Art. 6(1)(a) GDPR + §25(1) TTDSG | 13 months (anonymised) |
| Contact-form contents | Reply to enquiry | Art. 6(1)(b) GDPR (pre-contractual) | until resolved + 6 months |
| Newsletter sign-up | Sending requested content | Art. 6(1)(a) GDPR + §7(2)(3) UWG | until withdrawal |
Cookies and similar device-storage technologies: see Cookie Policy.
Google Tag Manager and Google Analytics 4 (Consent Mode v2). The tags GTM-NMC7NN5Q and G-JHE4G5MDW7 load on every page, but their consent state defaults to denied (ad_storage, ad_user_data, ad_personalization, analytics_storage). Until you opt in, only anonymous, aggregated signals without cookie or user identifiers ("cookieless pings") are sent to Google. Only after you actively consent in the cookie banner ("Statistics" or "Marketing") do we update the respective consent state to granted — at which point Google may set cookies and process identifiable events. Legal basis: Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG.
Meta Pixel (Facebook/Instagram). The Meta Pixel with ID 1748447405861991 is embedded on this site. The pixel is only loaded after you actively consent to the "Marketing" category — no data is transmitted to Meta before that point. Once consented, the pixel allows us to measure the effectiveness of our advertising on Facebook and Instagram and to share conversion events (e.g. page views) with Meta. Cookies (_fbp, _fbc) are then set and data is transmitted to Meta Platforms Ireland Ltd. (4 Grand Canal Square, Dublin 2, Ireland); within the corporate group, data is also shared with the parent company Meta Platforms, Inc. (USA). The legal basis for the US transfer is the EU Standard Contractual Clauses (Module 2) together with the EU-US Data Privacy Framework. Legal basis for the processing: Art. 6(1)(a) GDPR in conjunction with § 25(1) TTDSG. You can withdraw your consent at any time via the cookie-settings button in the footer.
5.2 When you create a subscriber account
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, phone, postal code, living situation, interests | Contract performance; service personalisation | Art. 6(1)(b) GDPR | Subscription duration + 30 days |
| Authentication data (password hash, session tokens) | Account login | Art. 6(1)(b) GDPR | per auth lifecycle (refresh: 30d; access: 1h) |
| Payment data | Contract execution and bookkeeping | Art. 6(1)(b) and (c) GDPR (§147 AO) | 10 years (tax law) |
| Consent records | Accountability | Art. 6(1)(c) GDPR (Art. 7(1) GDPR) | 3 years after withdrawal or end of relationship |
5.3 Phone companion (for the called senior)
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Memory notes | Personalisation across calls | as above | 730-day sliding window with relevance pruning |
| Life chronicle (anniversaries, events) | Long-term continuity | as above | Subscription duration + 30 days |
| Call metadata (timestamp, duration, status) | Service delivery, accountability | Art. 6(1)(b) and (f) GDPR | 12 months |
| Safety events (see §6) | Wellbeing notice to caregiver | Art. 6(1)(d) + Art. 9(2)(c) GDPR (vital interests) | 3 years |
5.4 Push notifications (app)
| Category | Purpose | Legal basis | Retention |
|---|---|---|---|
| Push token (device identifier) | Notification delivery | Art. 6(1)(a) GDPR + §25(1) TTDSG | until withdrawal, app uninstall, or 90-day inactivity |
| Notification type (no content in payload) | as above | as above | as above |
5.5 Mobile app — specific disclosures
The SilverFriend app does not collect any personal data beyond the categories described in sections 5.1 to 5.4 and 5.7. In particular:
- Usage analytics and crash reports only with consent: The app includes the services PostHog and Google Firebase Crashlytics. Both are switched off when the app starts and become active only after your explicit consent. See section 5.7.
- No cross-app tracking: The app does not use tracking frameworks (e.g. Apple ATT/IDFA, Google Advertising ID). No data is shared with advertising networks and no data is passed to third parties for advertising purposes.
- No advertising: The app contains no advertisements and does not share data with third parties for advertising purposes.
- Account deletion: You can permanently delete your account and all associated data at any time in the app under Settings → Delete Account. Deletion is completed within 30 days.
- Subscription management: Payments are processed through Apple StoreKit (iOS) or Google Play Billing (Android) and managed by RevenueCat. SilverFriend does not store credit card or bank details.
5.6 Privacy nutrition labels (Apple App Store / Google Play)
| Data type | Collected? | Linked to identity? | Used for tracking? |
|---|---|---|---|
| Name | Yes | Yes | No |
| Email address | Yes | Yes | No |
| Phone number | Yes | Yes | No |
| Device ID (FCM token) | Yes | No | No |
| Purchase history (via RevenueCat) | Yes | Yes | No |
| Usage data / product interaction (only after consent, see 5.7) | Yes, opt-in | Yes (pseudonymous user ID) | No |
| Diagnostics / crash reports (only after consent, see 5.7) | Yes, opt-in | Yes (pseudonymous user ID) | No |
All data is encrypted in transit (HTTPS/TLS 1.2+). A deletion mechanism is available in the app (see above).
5.7 Usage analytics and crash reports in the mobile app
Only with your consent. Our mobile app uses two services to understand which areas and features of the app are used and where technical errors occur: PostHog (usage analytics) and Google Firebase Crashlytics (crash reports). Both are switched off when the app starts and become active only if you explicitly agree in the app (consent prompt on first launch, or the “Usage analytics” switch in Settings). Both depend on the same consent — withdrawing it switches off both together. The legal basis is your consent under Art. 6(1)(a) GDPR; § 25(1) TTDSG applies accordingly to storing the identifiers this requires on your device.
What we process. With consent given, we collect pseudonymised usage data: screens viewed, feature events (e.g. “setup step completed”, “settings changed”) and technical device information (device model, OS version, app version, language). Crash reports additionally contain the technical error report, the time of the crash, and the language and subscription-status values. All of it is linked to an internal pseudonymous user ID — not to your name, email address, or phone number.
What is expressly not collected. No content and no recordings of the companion calls, no names or phone numbers (neither yours nor your relative's), no free-text input, no location data. There is no cross-app tracking, no advertising use, and no matching with third-party data.
Recipients, storage location, third-country relevance. The processor for usage analytics is PostHog, Inc. (USA); processing and storage of this data take place exclusively on servers in the European Union (Frankfurt am Main, AWS region eu-central-1). The processor for crash reports is Google Ireland Limited (Firebase Crashlytics). The legal instruments are set out in section 7 and in our list of subprocessors.
Retention. Raw usage-analytics data is deleted after 90 days; aggregated analyses derived from it after 24 months. Crash reports are deleted after 90 days.
Withdrawal and deletion. You can withdraw your consent at any time with future effect (Settings → Usage analytics). Withdrawal ends collection, discards crash reports not yet transmitted, and resets the pseudonymous analytics ID on your device. When you delete your account, the data stored under your ID with the services named above is deleted as well. Your rights under section 10 remain unaffected.
6. Express clarifications about the voice service
Two important points we want to make explicit:
1. SilverFriend does not analyse the senior's mood or mental state. No such assessments are produced or shared with the caregiver.
2. Exception — emergency: on concrete signs of acute danger (e.g. suicidal ideation or imminent harm), we ask the caregiver to check on the senior in person — without disclosing the content of the call. Legal basis: Art. 6(1)(d) GDPR (vital interests) read with Art. 9(2)(c) GDPR.
The speech model runs on EU-hosted infrastructure. Under the applicable processing terms, inputs are not used to train the base model.
7. Recipients and processors
A complete, current list is published at silverfriend.de/datenschutz/subprocessors.
Key recipients:
| Recipient | Role | Legal instrument | Location |
|---|---|---|---|
| Amazon Web Services EMEA SARL (AWS) | Processor (hosting, database, authentication, voice model). All data is stored exclusively in the Frankfurt region (eu-central-1). Services: Amazon Cognito, Amazon Aurora PostgreSQL, AWS Lambda, Amazon S3. | Art. 28 GDPR + EU SCCs (Module 2) | EU (Frankfurt); US parent |
| Twilio Inc. | Processor (phone connection for the phone companion service) | as above | EU; US parent |
| Google Ireland Limited (Firebase Cloud Messaging) | Processor (push notifications in the app). Only pseudonymous device tokens are transmitted. | as above | EU (Ireland); US parent |
| Google Ireland Limited (Google Analytics 4, Google Tag Manager) | Processor (website reach measurement and tag management). Personal events are processed only after your consent in the “Statistics” or “Marketing” category (see section 5.1). | Art. 28 GDPR (Google Ads Data Processing Terms) + EU SCCs (Module 2) + EU-US Data Privacy Framework | EU (Ireland); US parent |
| Google Ireland Limited (Firebase Crashlytics) | Processor (crash reports from the app). Only after your consent (see section 5.7). | as above | EU (Ireland); US parent |
| Meta Platforms Ireland Ltd. | Processor (measuring the effectiveness of our advertising on Facebook and Instagram). Only after your consent in the “Marketing” category (see section 5.1). | as above | EU (Ireland); US parent |
| PostHog, Inc. | Processor (usage analytics for the mobile app). Only after your consent (see section 5.7); stored exclusively in the EU (Frankfurt am Main). | Art. 28 GDPR + EU SCCs (Module 2) + EU-US Data Privacy Framework | USA; data located in the EU |
| RevenueCat Inc. | Processor (subscription management via Apple StoreKit and Google Play Billing). Processes purchase receipts and subscription status. | as above | US (DPF-certified) |
| HubSpot Inc. | Processor (website, CRM, marketing — caregiver data only) | as above | EU (EU1); US parent |
| Tax adviser | Processor (bookkeeping) | Art. 28 GDPR | Germany |
The named list of current subprocessors (company name, address, role) is maintained and published at silverfriend.de/en/datenschutz/subprocessors.
8. Transfers to third countries
Processing is in the EU by default (data centre in Frankfurt am Main, region eu-central-1). Exceptions — control-plane access by certain US providers — are covered by EU Standard Contractual Clauses (Module 2) plus supplementary measures (encryption with customer-managed keys, TLS 1.2+, data residency, logging).
For the mobile app's usage analytics (section 5.7), data is stored exclusively in the EU. Where PostHog, Inc. (USA) accesses those systems from the US as a processor in an individual case, this is covered by the EU Standard Contractual Clauses and by PostHog, Inc.'s certification under the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Art. 45 GDPR).
The Transfer Impact Assessment is available from the DPO. We monitor the validity of the EU-US Data Privacy Framework for the listed US providers, all of which are DPF-certified.
9. Retention — overview
For each data category we have set a specific retention period (see tables above). Our full deletion strategy follows DIN 66398 and is documented internally — see DATA_RETENTION_SCHEDULE.
10. Your rights
As subscriber or as senior you have the right to:
- Access the data we process about you (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16),
- Erasure ("right to be forgotten", Art. 17),
- Restriction of processing (Art. 18),
- Data portability (Art. 20),
- Object to processing based on legitimate interest (Art. 21),
- Withdraw consent at any time, with effect for the future (Art. 7(3)),
- Lodge a complaint with a supervisory authority (Art. 77).
Please contact: datenschutz@silverfriend.de.
We respond within 30 days. Where identity verification is required we will request a suitable proof (e.g. confirmation from the registered email account). Seniors may submit requests via the caregiver or during a call ("nicht mehr anrufen" / "do not call again" stops further calls immediately).
Supervisory authority: Berlin Commissioner for Data Protection and Freedom of Information, Friedrichstr. 219, 10969 Berlin — https://www.datenschutz-berlin.de.
11. Automated decision-making
There is no automated decision-making within the meaning of Art. 22 GDPR. Specifically:
- We do not create credit, personality, or health profiles.
- The only model-supported analysis is the post-call check for acute-danger signals (see §6). Its result is reviewed by a person before any notice goes out, and then triggers no more than a human-oriented request for the caregiver to check in person — no automatic consequence, and no automated decision within the meaning of Art. 22 GDPR.
12. Security (Art. 32 GDPR)
Among the technical and organisational measures we apply:
- Encryption of stored data with customer-managed keys,
- TLS 1.2+ for all transit,
- Role-segregated database access,
- Credential management via a dedicated secrets-management system,
- Web Application Firewall,
- Logging of security-relevant events,
- Quarterly security reviews and annual external audits.
13. Changes to this policy
We update this policy on material processing changes. Active subscribers are informed at least 14 days before the change takes effect by email or in-app banner. A change history appears at the end of this page (once changes occur).
14. Children and minors
SilverFriend is not directed at children under 16. Subscribers are adult family caregivers; end users of the phone companion are elderly adults. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete that data promptly. Please contact us at datenschutz@silverfriend.de if you suspect such a case.
15. Change history
| Date | Version | Material changes |
|---|---|---|
| 2026-04-13 | 1.0 | Initial publication (pre-launch) |
| 2026-04-17 | 1.1 | Named processors explicitly (AWS, Twilio, FCM, RevenueCat, HubSpot); specified Frankfurt data centre; added app-specific privacy disclosures and privacy nutrition labels (Apple/Google); added children and minors section; added contact phone number; added language switcher |
| 2026-05-08 | 1.2 | Added Meta Pixel (Facebook/Instagram) as a processor; pixel only fires after marketing consent (TTDSG § 25(1), GDPR Art. 6(1)(a)); EU-US Data Privacy Framework added as transfer basis |
| 2026-08-24 | 1.3 | New section 5.7 (usage analytics and crash reports in the mobile app: PostHog and Google Firebase Crashlytics, both opt-in); section 5.5 corrected — its earlier statement that the app shares no data with third-party analytics providers had not been accurate since July 2026; privacy nutrition labels (5.6) extended with product-interaction and diagnostics data; section 7 extended with Google Ireland Limited (Analytics 4 / Tag Manager and Crashlytics), Meta Platforms Ireland Ltd. and PostHog, Inc.; section 8 extended with the PostHog third-country note; adopted “wellbeing notice” as the name of the safety feature and clarified in section 11 that a person reviews the result before any notice is sent |
Last updated: 24 August 2026 · Controller: Management of Silverfriend GmbH · DPO: appointment in progress