The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
Marvin Rüßbüldt c/o IP-Management #8928, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany Email: info@goru.rocks
In the course of operating the goru.rocks platform, the controller processes the following categories of personal data:
(a) account data: email address, display name, and the identifier of the OAuth provider (provider user ID), obtained via the Google OAuth or Discord OAuth login;
(b) payment data: transaction data processed via Stripe;
(c) generated videos: the video files created by the user;
(d) activity logs: log data relating to video generations, renders, purchases, logins, and Live Chat activity; the details are described in Section 3;
(e) generated scripts: the full text of the generated video scripts;
(f) consent logs: evidence data on consents given during paid transactions and on the Join-Consent declaration when entering public Live Chat rooms;
(g) hashed IP addresses: SHA-256 hashes of IP addresses with salt, used for securing operations, for abuse prevention, and to prevent duplicate voting. IP addresses are never stored in plain text in the application databases;
(h) script drafts: drafts stored in the local storage of the browser (localStorage), which do not leave the user's browser;
(i) Live Chat messages: message content exchanged in public or private rooms;
(j) Live Chat username: the display name set by the user for the Live Chat;
(k) Live Chat character and country assignment: the country selected by the user as well as the character selected per room;
(l) Reports: data on reported Live Chat messages including the reason for reporting and, where applicable, the surrounding message context;
(m) voting data: votes submitted by the user (question, selected option, timestamp) and vote comments;
(n) power and contribution log: points (Power) earned by the user through contributions in the Live Chat for the selected country, including the assignment of user identifier, country code, timestamp, and point value;
(o) gamification data: the current chat streak (consecutive days of activity), the last chat date, and the completion status of daily tasks;
(p) analytics data: page views, session duration, bounce rate, and navigation paths (which pages were visited and in what order), recorded via a session-based identifier;
(q) moderation logs: results of automated content review and the measures derived from them (warnings, content removal, mutes, suspensions);
(r) user-created questions: questions created by the user for the voting system, including answer options and the associated view and vote counts;
(s) Vote Result Videos: video files automatically rendered from vote results, including the associated render metadata;
(t) question feedback: ratings (positive/negative) submitted by the user for individual voting questions;
(u) skip data: voting questions skipped by the user, used for personalising the question feed;
(v) device fingerprint: an identifier derived from general browser and device characteristics (screen resolution, timezone, language settings, graphics capabilities), used to recognise previously banned devices. The fingerprint does not identify the user personally.
For the secure provision of the Platform, for abuse detection, for error correction, and for quality improvement, the controller logs certain activities. The following data are recorded in detail:
(1) For each video generation and each render:
(a) hashed IP address;
(b) user identifier (user ID) for logged-in users, or session identifier (session ID) for users who are not logged in;
(c) the topic or prompt entered;
(d) the generated script in its full wording;
(e) the characters used (names and type);
(f) the selected format (Chat or Quiz);
(g) the selected tab (Countries or Characters);
(h) the timestamp;
(i) the user's usage plan;
(j) the credits spent (number and purpose).
(2) For each purchase:
(a) hashed IP address;
(b) user identifier (user ID);
(c) the product purchased (subscription plan or credit package);
(d) the amount;
(e) the payment method;
(f) the timestamp;
(g) the accepted version of the Terms;
(h) confirmation of the relevant controls (checkbox confirmations).
(3) For each login and each account action:
(a) hashed IP address;
(b) timestamp;
(c) the OAuth provider used (Google or Discord);
(d) session identifier (session ID).
(4) For each Live Chat activity:
(a) hashed IP address;
(b) user identifier (user ID);
(c) Username;
(d) the selected character and country assignment;
(e) room identifier and type of room (public or private);
(f) message content;
(g) timestamp;
(h) the action performed (in particular joining, leaving, sending a message, mute by the host, submission of a Report).
(5) Live Chat messages are stored on the server side and are encrypted at rest using AES-256 encryption. There is no end-to-end encryption in either public or private rooms. Server-side storage and the ability to decrypt messages are prerequisites for the moderation of reported messages (Section 4(3), Section 13) and for the generation of highlight and session videos from the Live Chat.
(6) For each vote:
(a) for logged-in users: user identifier (user ID);
(b) for users who are not logged in: hashed IP address to prevent duplicate voting, and the selected country stored in the cookie (see Section 12);
(c) question, selected option, and timestamp;
(d) any comments submitted.
(7) For each contribution that earns Power points for a country: user identifier, country code, timestamp, and point value.
(8) Sessions of logged-in users are stored with user identifier and hashed IP address.
(9) For each content and moderation review (Section 13), the result of the automated review and the measures derived from it (warning, content removal, mute, suspension) are stored.
Processing of the data referred to in Sections 2 and 3 is based on the following legal bases:
(1) Performance of a contract pursuant to Art. 6(1)(b) GDPR for: account data, payment data, generated videos, the purchase- and account-related log data (Section 3(2) and (3)), the provision of the Live Chat including the processing of Live Chat messages, Username, character selection, and the Live Chat log data (Section 3(4)), the country assignment and Power tracking (Section 3(7)), the gamification functions (streak, daily tasks), the voting system for logged-in users (Section 3(6)(a), (c), (d)), the creation and publication of voting questions by users, and the automated rendering of Vote Result Videos. These functions are integral parts of the service.
(2) Legal obligation pursuant to Art. 6(1)(c) GDPR for: payment data and consent logs within the scope of tax retention obligations.
(3) Legitimate interest pursuant to Art. 6(1)(f) GDPR for:
(a) the activity logs (Section 3(1)) and generated scripts for the purposes of abuse detection, error correction, and quality improvement;
(b) hashed IP addresses and session data for security, prevention of duplicate voting, and the imposition and enforcement of IP-based restrictions (Section 9(3));
(c) the automated moderation of all Live Chat messages and comments by artificial intelligence services and the retention of moderation logs and reported messages for evidentiary purposes. The legitimate interest consists in the protection of users from unlawful content, harassment, hate speech, and spam, and in the enforcement of the Terms of Service;
(d) voting data of users who are not logged in, including the hash of the IP address, to prevent duplicate voting (Section 3(6)(b));
(e) anonymised analytics for service improvement (Section 10);
(f) internal operational notifications via Discord and email (Section 9(2)).
(4) Script drafts are stored exclusively in the user's local browser storage and are not transmitted to the controller.
The data categories referred to are retained for the following periods:
(a) account data: until deletion of the user account;
(b) activity logs relating to generations and renders: 12 months, followed by anonymisation;
(c) hashed IP addresses in activity and analytics logs: 90 days, followed by deletion;
(d) hashed IP addresses on ban lists (IP bans): retained indefinitely as long as the security interest persists;
(e) generated scripts: 12 months with personal data, then anonymised (user ID, IP hash, and session ID are removed); anonymised scripts are retained indefinitely for analytics and service improvement;
(f) purchase data and consent logs: 10 years pursuant to tax retention obligations;
(g) generated video files: 24 hours after creation, followed by deletion;
(h) script drafts: until deleted by the user in local browser storage;
(i) Live Chat messages in public rooms: stored permanently until deletion of the user account;
(j) Live Chat messages in private rooms: stored permanently until deletion of the user account;
(k) reported messages (Reports) including the surrounding message context: 5 years for evidentiary purposes within the scope of community safety;
(l) moderation logs (results of automated review and the measures derived from them): 5 years;
(m) recorded rule violations (Violations): retained indefinitely; upon account deletion the personal components are anonymised;
(n) Live Chat Username, character and country assignments, and other Live Chat master data: until deletion of the user account; the country remains as a statistical attribute after anonymisation;
(o) voting data and vote comments: retained indefinitely; upon account deletion the personal components are anonymised so that the data can no longer be linked to a person;
(p) Power points and contribution log: retained indefinitely; upon account deletion the personal components are anonymised, while the aggregated points of the country are preserved;
(q) gamification data (streak, daily tasks): until deletion of the user account;
(r) detailed analytics data of logged-in users: 12 months, then aggregation; aggregated and anonymised data without time limit;
(s) analytics session identifiers of users who are not logged in: 24 hours, then anonymisation;
(t) user agent strings: 30 days, then shortened to a generic form;
(u) sessions of logged-in users: 90 days;
(v) server log files: 30 days (Section 8);
(w) user-created questions including answer options, view and vote counts: until deletion of the user account; upon account deletion the personal components (link to the creator) are anonymised, while the question itself may be retained for statistical purposes;
(x) Vote Result Videos: rendered video files 24 hours after creation, followed by deletion; the underlying aggregated vote results are retained pursuant to letter (o);
(y) question feedback: retained indefinitely; upon account deletion the personal components (link to the rating user) are anonymised, while the feedback data are retained in aggregated form for quality control;
(z) skip data: until deletion of the user account. For users who are not logged in, skip data are stored exclusively in the local browser storage (localStorage) and are not transmitted to the controller;
(aa) device fingerprints of non-banned users: until deletion of the user account;
(ab) device fingerprints of banned users: retained indefinitely for the purpose of preventing the circumvention of platform bans.
(1) After expiry of the respective retention period, the personal components (in particular user ID and hashed IP address) are removed from the logs. Anonymised and aggregated data without personal reference — such as the number of videos generated per day, the aggregate scores of countries, or the distribution of vote results — may be stored for an unlimited period.
(2) Anonymised and aggregated voting statistics — such as the percentage of users from a specific country who selected a particular option — do not constitute personal data within the meaning of the GDPR. Such aggregated data may be retained indefinitely, used by the controller for its own commercial purposes, and licensed to third parties for market research and statistical analysis.
(1) Backups are created regularly to secure the Platform. Backups may contain personal data. Backups are stored encrypted with AES-256-CTR on a Hetzner Storage Box located within Germany. Backup data are overwritten and deleted in accordance with the regular backup rotation cycle.
(2) The backup rotation cycle is structured as follows:
(a) daily backups are retained for 30 days;
(b) weekly backups are retained for 90 days;
(c) after expiry of these periods, the backups are automatically overwritten or deleted.
(3) In addition, backup copies may be retained on external, offline storage media for the purpose of disaster recovery. These archival backups are not actively processed, not accessed, and are not subject to any rotation cycle. Personal data contained in such archival backups may therefore be stored indefinitely. In the event of an erasure request pursuant to Art. 17 GDPR, the data are deleted from the active system without undue delay; data contained in archival backups remain for technical reasons until the respective storage medium is eventually overwritten and are processed solely in the event of disaster recovery.
(1) The Platform is operated on the servers of Hetzner Online GmbH within Germany.
(2) Each access automatically records information in server log files, which are automatically deleted after 30 days. For technical reasons, the server log files may contain the IP address in plain text for the duration of storage, in contrast to the application databases. Processing is based on the legitimate interest in the secure and efficient provision of the online service pursuant to Art. 6(1)(f) GDPR.
(1) The controller engages the following services:
(a) Stripe: payment processing;
(b) OpenAI: generation of video scripts and automated moderation of the Live Chat and vote comments;
(c) Google: OAuth login. The controller accesses solely the display name, the email address, and the Google account identifier;
(d) Discord: OAuth login. The controller accesses solely the display name, the email address, and the Discord user identifier;
(e) Hetzner Online GmbH (Germany): hosting of the servers and provision of a Storage Box for encrypted backups.
(2) For operational purposes, the controller sends internal notifications to itself, for example regarding purchases, errors, registrations, and moderation events (Reports and suspensions). Delivery takes place via a Discord webhook and by email via the controller's own mail server. The notifications contain the event type (for example "New purchase: Starter plan"), a timestamp, and aggregated statistics. Real-time signup notifications transmit neither name nor email address; only the event type "new user registered" is sent. Moderation alerts (for Reports and suspensions) contain the user ID and the reason and are transmitted exclusively to the internal Discord server. IP addresses and full chat or script texts are not part of these notifications.
(3) Within the scope of abuse prevention, IP-based restrictions may be imposed. The restrictions are implemented on the basis of the hashed IP address; a reversal of the hash to the original IP address is not possible. In cases of severe or repeated rule violations, IP-based restrictions may be applied permanently (Section 17 of the Terms).
(4) In addition to IP-based restrictions, the controller collects a browser-based device fingerprint upon registration, login, and use of the Live Chat. This fingerprint is derived from general browser and device characteristics such as screen resolution, timezone, language settings, and graphics capabilities. It does not identify the user personally but allows the system to recognise previously banned devices. Device fingerprints of banned users are retained indefinitely to prevent the circumvention of platform bans; device fingerprints of non-banned users are deleted upon account deletion. The legal basis is the legitimate interest in preventing abuse and protecting the community from harmful content pursuant to Art. 6(1)(f) GDPR.
(1) The controller collects anonymised usage statistics to improve the service. Page views, session duration, bounce rate, and navigation paths are recorded.
(2) Recording takes place without the use of third-party trackers or advertising cookies. Session identifiers are stored exclusively in the browser's sessionStorage and are deleted when the tab is closed.
(3) Session identifiers of users who are not logged in are anonymised within 24 hours. IP-based identifiers are deleted after 90 days. User agent strings are shortened to a generic form after 30 days. For users who are not logged in, no user identifier is stored.
(4) The legal basis is the legitimate interest in service improvement pursuant to Art. 6(1)(f) GDPR. Due to the anonymisation, the processing no longer constitutes personal data processing within the meaning of the GDPR after expiry of the periods stated.
(1) The use of Stripe, OpenAI, Google, and Discord may result in transfers of personal data to the United States of America. These providers ensure an adequate level of data protection through Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR or a data processing agreement.
(2) Within the scope of automated moderation, chat messages and comments are transmitted to OpenAI in real time. The messages are processed solely for the purpose of evaluation and are not retained by the AI service providers.
(1) The controller uses solely technically necessary means that serve the provision of the service and for which no consent is required under Section 25(2) no. 2 TDDDG (the German implementation of the ePrivacy Directive):
(a) a session cookie for maintaining the login;
(b) a vote_country cookie for storing the country selected by the user for the voting system, retention period 1 year;
(c) a CSRF token cookie for protection against cross-site request forgery attacks;
(d) the local browser storage (localStorage) for saving script drafts;
(e) the browser's sessionStorage for the session identifier of the analytics system (Section 10), which is deleted when the tab is closed.
(2) In the course of payment processing, Stripe may set its own cookies. Their necessity depends on the respective cookie type.
(3) No marketing or tracking cookies and no third-party trackers are used. A cookie banner is therefore not required.
(1) To maintain a safe community, chat messages, vote comments, and other user-generated texts are reviewed automatically by artificial intelligence services (OpenAI) for potential rule violations — in particular harassment, hate speech, threats, and spam.
(2) The AI-supported review may trigger automated measures, in particular warnings, the removal of individual messages, temporary mutes, and further restrictions on the user account.
(3) Insofar as such a measure has legal or similarly significant effects on the user, the controller draws attention to the user's right under Art. 22(1) GDPR not to be subject to a decision based solely on automated processing. The user may request human review of any automated moderation decision at any time. Such requests shall be sent to: info@goru.rocks.
(4) The final decision on the merit of a Report and on permanent suspensions is made by the controller following manual review.
(5) Within the scope of processing by OpenAI, neither the email address, the Username, the user ID, nor any other identifying characteristic of the user is transmitted to the AI providers. Only the text to be reviewed and, where applicable, the immediately preceding message context are transmitted.
(1) The user has the following rights:
(a) access to the data stored about the user (Art. 15 GDPR);
(b) rectification of inaccurate data (Art. 16 GDPR);
(c) erasure of the user's data (Art. 17 GDPR);
(d) restriction of processing (Art. 18 GDPR);
(e) data portability (Art. 20 GDPR);
(f) objection to processing (Art. 21 GDPR);
(g) lodging a complaint with a supervisory authority (Art. 77 GDPR);
(h) human review of an automated moderation decision (Art. 22 GDPR; see Section 13(3)).
(2) The data export and the deletion of the user account can be carried out by the user directly in the account settings (profile) at any time. The data export is provided in a machine-readable format (JSON) and includes the profile information, votes submitted, chat messages, activity history, and gamification data. The rights of access, rectification, restriction, and objection, as well as the request for human review pursuant to paragraph 1(h), may be exercised via info@goru.rocks. Requests are processed within 30 days.
(3) The competent supervisory authority is the Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany.
(1) The user may delete their user account in full at any time directly in the account settings (profile).
(2) Upon deletion, the account data (in particular email address and display name) are deleted from the active system without undue delay. Any existing subscription is cancelled; the billing period already paid is not refunded. Unspent credits expire without substitute and without any claim to a refund.
(3) Activity data that are required for statistical purposes and for the integrity of the service (in particular votes, Power contributions, and Live Chat messages in public rooms) are anonymised and retained in this form. A link to the user as a person is no longer possible after anonymisation. Vote comments and Live Chat messages in private rooms are removed upon account deletion, unless a retention interest under Section 5(k) or (l) continues to apply.
(4) Payment and consent data continue to be stored for the duration of the statutory retention periods and are erased thereafter.
(5) Section 7 applies to data contained in backups.
The controller may amend this Privacy Policy. Registered users will be notified of material changes by email and prompted to review and accept the updated version upon their next login. The currently applicable version is made available at goru.rocks/privacy.
For enquiries on data protection, data portability, deletion, and requests for human review of automated moderation decisions (Art. 22 GDPR):
Marvin Rüßbüldt, info@goru.rocks
Version 1.0 — 31 May 2026: Initial release.
Version 1.1 — 4 June 2026: Added data processing disclosures for voting system, country system, user-created questions, vote result videos, AI moderation (Art. 22 GDPR), IP banning, skip and feedback data, and the commercial-use clause for aggregated data. Added device fingerprint processing for abuse prevention.