Privacy
Last updated: June 11, 2026
Controller
The controller for the processing of personal data described on this page is the provider identified in the imprint. This privacy notice applies to the Diggr website, the Diggr app, and Diggr community features unless a more specific notice is shown for a particular service.
General information
Diggr is designed to keep as much personal app organization local on your device as practical. Server-side processing is used where necessary to provide community features, account functionality, public profiles, public crates, support communication, and media delivery.
Categories of personal data
Depending on how you use Diggr, the following categories of personal data may be processed:
- Technical request data such as IP address, browser type, operating system, requested URL, date and time of access, and server log information
- Account and authentication data, including Sign in with Apple identifiers, email address, display name, and session or refresh tokens
- Profile data such as handle, display name, biography, links, profile image, and profile metadata
- Community data such as published crates, crate descriptions, crate ordering, saved profiles, and public crate snapshots
- Content moderation data, including reports of objectionable content, block relationships between users, and related moderation records
- Support communication data, including the content of your request and any information you choose to send to Diggr
Website access and server logs
When you visit the Diggr website, technical request data is processed to deliver the website, ensure stability, defend against abuse, and maintain IT security. The legal basis is Art. 6(1)(f) GDPR. The legitimate interest is the secure and reliable provision of the website and related infrastructure.
The website does not intentionally use non-essential cookies, advertising technologies, or analytics scripts at the time of writing. If this changes, the privacy notice will be updated accordingly and any legally required consent mechanism will be introduced.
Accounts and Sign in with Apple
If you create or use an account, Diggr processes the information required to authenticate you and operate your account. This includes your Sign in with Apple subject identifier, your email address where provided, email verification status, display name where provided, private relay status where provided by Apple, and authentication token data.
This processing is carried out for the performance of the user relationship and to provide account-based features pursuant to Art. 6(1)(b) GDPR. Where security-related verification or fraud prevention is necessary, processing may also be based on Art. 6(1)(f) GDPR. The legitimate interest is protecting the integrity of the service and preventing unauthorized access.
Apple acts as an independent controller for the Sign in with Apple service. Diggr receives only the data that is made available to the app through that login flow.
Profiles, public crates, and community features
If you create a Diggr profile, Diggr processes your handle, display name, biography, links, avatar metadata, and related timestamps. Profiles are public by design. If you publish crates to your profile, Diggr also processes and displays the crate title, description, order, publication status, and the app snapshot data included in the published crate.
This processing is carried out to provide the community features you actively request and is therefore based on Art. 6(1)(b) GDPR. To the extent publication creates publicly accessible profile pages and discoverability features, processing may also be based on Art. 6(1)(f) GDPR. The legitimate interest is operating a public-facing discovery and profile system as part of the Diggr service.
Please note that public profile information and published crates may be visible worldwide and may be indexed by search engines or accessed by third parties. Once information has been copied, cached, archived, or indexed by third parties, Diggr may not be able to fully control further downstream use by those third parties.
Community standards, reporting, and content moderation
Diggr requires all users to agree to its Terms of Use before accessing community features. The Terms make clear that objectionable content and abusive behaviour are not tolerated. This section describes how Diggr processes personal data in connection with content moderation.
Reporting objectionable content
Diggr provides an in-app mechanism that allows you to report content or profiles you consider objectionable. When you submit a report, Diggr processes the identifier of the reported content or profile, the category of the report, any description you provide, and identifiers necessary to associate the report with the reporting and reported accounts.
The legal basis for this processing is Art. 6(1)(f) GDPR. The legitimate interest is maintaining a safe, respectful community environment and fulfilling the operational duty to review and act on content reports.
Filtering objectionable content
Diggr applies technical and operational measures to detect and filter content that violates community standards. Where content moderation involves processing personal data, the legal basis is Art. 6(1)(f) GDPR. The legitimate interest is protecting users from harmful or objectionable material and ensuring the integrity of the community.
Blocking users
Diggr provides an in-app mechanism that allows you to block another user. When you block a user, Diggr stores the block relationship between the two accounts and enforces the following protections immediately:
- The blocked user can no longer view your profile or save your account
- You can no longer view the blocked user's profile or find them in search results
Diggr also receives a notification of the block in order to monitor for patterns of abusive behaviour and to take appropriate moderation action where necessary.
The legal basis for processing block relationships is Art. 6(1)(b) GDPR, as blocking is a feature you actively use to manage your experience. To the extent Diggr uses block data to detect abuse patterns, processing is also based on Art. 6(1)(f) GDPR. The legitimate interest is protecting users from abusive accounts and maintaining community standards.
Moderation response and removal
Diggr reviews content reports and takes action within 24 hours of receipt. Where content is found to violate community standards, Diggr will remove the content and may suspend or permanently terminate the account responsible. Diggr retains records of moderation decisions for accountability, to defend against disputes, and to identify repeat offenders. This retention is based on Art. 6(1)(f) GDPR. The legitimate interest is documenting moderation actions and preventing circumvention of community standards.
If your content or account is subject to a moderation decision, you may contact Diggr using the contact details below to seek clarification or to exercise your rights under applicable data protection law.
Profile images and media storage
If you upload a profile image, Diggr generates a short-lived upload URL and stores the resulting file in Cloudflare R2 object storage. Diggr stores the public media URL, the internal object key, and related metadata necessary to display and manage the image. This processing is based on Art. 6(1)(b) GDPR because it is required to provide the upload feature you use.
Media delivery may involve Cloudflare infrastructure. If infrastructure providers process connection metadata such as IP addresses, user agent data, or request timing data for delivery, abuse prevention, or security purposes, this is generally based on Art. 6(1)(f) GDPR. The legitimate interest is secure, performant, and reliable media delivery.
Support requests and communication
If you contact Diggr, including by email, Diggr processes the information you provide in order to respond to your request, investigate issues, and document the support process. This may include your email address, device type, operating system version, screenshots, diagnostic details, and the content of your message.
The legal basis is Art. 6(1)(b) GDPR where the request relates to an existing user relationship or pre-contractual communication, and otherwise Art. 6(1)(f) GDPR. The legitimate interest is handling inquiries, improving the service, and resolving technical problems.
Recipients of personal data
Personal data may be disclosed to service providers and processors that support the operation of Diggr where this is necessary for the stated purposes. This may include in particular hosting providers, infrastructure and CDN providers, media storage providers, email providers, and technical service providers needed to operate backend systems and domain infrastructure.
Where personal data is transferred to processors, such providers are engaged under appropriate data processing agreements where legally required.
Transfers to third countries
Some service providers used by Diggr may process personal data outside the European Union or the European Economic Area. Where such transfers take place, Diggr will rely on an appropriate legal transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, unless another lawful transfer basis applies.
Storage period
Diggr stores personal data only for as long as necessary for the purposes described in this notice, unless a longer retention period is required by law. In practice, this means:
- Server log data is generally kept only as long as required for security, debugging, and abuse prevention
- Account and profile data is stored for as long as your account exists
- Public profile and crate data is stored for as long as you keep your account and profile active or until you remove the relevant content
- Profile images are stored until you replace or delete them, or until your account is deleted
- Content moderation records, including reports, block relationships, and moderation decisions, are retained for as long as necessary to enforce community standards, document accountability, and prevent circumvention — typically for the duration of the reported or blocking account's existence plus a limited period thereafter
- Support communications may be retained for as long as necessary to handle the request and document follow-up, unless statutory retention duties apply
- Backups may persist for a limited transitional period before they are overwritten or deleted in the regular backup cycle
Your rights
Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing, data portability, and objection. Where processing is based on consent, you also have the right to withdraw that consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
You also have the right to lodge a complaint with a supervisory authority, in particular in the member state of your habitual residence, place of work, or place of the alleged infringement.
Obligation to provide data
You are not generally required by law to provide personal data. However, certain data is necessary if you want to use account-based features, publish a profile, upload a profile image, or contact Diggr for support. Without that data, the relevant feature may not be available.
No automated decision-making
Diggr does not currently use automated decision-making or profiling within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.
Account deletion
You can request deletion of your account through the app where that function is available. Account deletion removes the account and associated community data from the operational backend systems, subject to legal retention duties, limited backup retention, and any data that must temporarily remain for security or abuse-prevention purposes.
External links and app store pages
Diggr may link to third-party websites, App Store pages, or developer websites. If you follow such links, the relevant third party is responsible for its own data processing. Please consult the respective privacy information provided by those third parties.
Contact for privacy matters
For privacy questions or to exercise your rights, please use the contact details in the imprint or write to contact@usedigger.com.