This Privacy Policy (the “Policy”) describes which personal data is processed when you use the RStudio mobile application for iOS (the “App”), for which purposes and on which legal bases this happens, to whom the data may be disclosed, how long it is stored and which rights you have as a data subject.
The Policy has been prepared in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Act No. 110/2019 Coll. of the Czech Republic on personal data processing, and the requirements of the Apple App Store Review Guidelines.
By using the App you confirm that you have read this Policy. The terms of the service itself are set out in the Terms of Use (EULA).
Language versions. This Policy is published in Russian and in English. The English text is provided for convenience. In case of any discrepancy between the versions, the Russian version prevails.
1. Who we are and how to contact us
The controller of personal data within the meaning of Article 4(7) GDPR is:
DUROMA s.r.o.
Identification number (IČO): 03439054
Registered address: Topolná 391, 687 11 Topolná, Zlínský kraj, Czech Republic
Registered in the commercial register kept by the Regional Court in Brno (Krajský soud v Brně), section C, insert 84842
Phone: +420 605 567 890
Email: support@rstudio.tech
Referred to below as “we”, “us”, the “Company”.
For any questions relating to the processing of personal data, and to exercise the rights listed in section 13, write to support@rstudio.tech with “Personal data” in the subject line.
2. What this Policy covers
The Policy covers the processing of personal data that takes place:
- when you use the RStudio App for iOS;
- when you interact with the services the App contacts in order to perform its functions (the “Platform”): authentication, uploading and publishing videos, live streaming, comments, channel analytics;
- when you contact us by email.
The Policy does not cover third-party sites, services and applications that may be opened from the App (including Platform web forms, government websites, mail clients). Their data processing is governed by their own policies.
The App is a creator tool (a channel management studio). It is intended for persons aged 16 and over and is not directed at children (see section 16).
Where this Policy is available inside the App: “Profile” → “Rules and restrictions”, and on the sign-up screen at the moment the account is created.
3. What data we process
All categories of data processed in connection with the App are listed below. We do not collect data beyond this list.
3.1. Account and profile data
- mobile phone number — used for registration, as a username and to confirm sign-in with a one-time code;
- email address — if it is linked to your account; used as an alternative username and to contact you;
- password — stored solely as an irreversible cryptographic hash; the original password value is not available to us;
- one-time confirmation codes (OTP) and records of them being sent;
- internal user and channel identifiers;
- channel name, its description and the default video signature;
- profile image (avatar) and channel cover;
- date of birth and gender — if you provided them in the “My data” section;
- account status information (active, blocked, deleted).
3.2. User content
- videos and short vertical videos, including the source files uploaded from the device library or recorded in the App;
- thumbnails, titles, descriptions, tags, categories, age labelling, playlists;
- live streams: video and audio stream, title, description, thumbnail, stream category;
- comments and replies to comments that you publish on behalf of the channel;
- messages you send to the chat of your own stream;
- drafts and the upload queue, as well as technical information about the upload process (status, file size, upload session identifier).
3.3. Third-party data displayed in the App
To let you work with comments and chat, the App shows you data of other Platform users: their display name, profile image, the text of the comment or message, the date and time of publication, and the author identifier. This data is processed only to the extent necessary for display, replies and moderation, and is not used by us for any other purpose.
3.4. Technical and diagnostic data
- device model, operating system version, language and regional settings;
- App version and build number, configuration type;
- App installation identifier generated automatically by the analytics SDK (it is not an advertising identifier and does not allow you to be tracked across other apps);
- IP address, date and time of requests to the servers, network connection parameters;
- approximate location (at country or city level) determined from the IP address by the analytics service — used only in aggregated statistics; precise coordinates and GPS data are not collected;
- App usage events: screens opened, taps on interface elements, the start and completion of operations (for example, publishing a video), operation results and error codes;
- technical logs and crash reports.
3.5. Support requests
The sender’s address, the content of the request, attached files and the correspondence history.
3.6. Data stored only on your device
- access and refresh tokens — in the system Keychain;
- App user settings — in local settings storage;
- drafts and the upload queue — in a local database;
- image cache and temporary video processing files.
This data is not transmitted to us and is deleted when the App is removed from the device or when you sign out of the account.
3.7. Data we do NOT process
The App does not request and does not collect:
- device location data — the App does not request location permission and does not receive GPS coordinates (the approximate IP-based location is described in clause 3.4);
- contacts, calendars, reminders;
- health, fitness, biometric data or special categories of data within the meaning of Article 9 GDPR (on-device image processing when applying effects does not constitute biometric processing — see section 5);
- readings from motion and device orientation sensors;
- payment card details and banking data inside the App (the App contains no purchases or subscriptions);
- the device advertising identifier (IDFA);
- information about other apps installed on the device;
- the user’s browsing history outside the Platform.
4. Where we obtain the data
- Directly from you — during registration, when filling in your profile, uploading content, running streams and contacting support.
- Automatically from your device — the technical and diagnostic data listed in clause 3.4, when the App starts and while it runs.
- From the Platform — statistics of your channel (views, watch time, traffic sources, de-identified and aggregated audience information), content moderation statuses, comments and chat messages addressed to your channel, and system notifications.
5. Device permissions the App requests
Permissions are requested at the moment the corresponding feature is used for the first time (the local network access request may appear at the first launch of the App) and may be withdrawn at any time in the iOS system settings (“Settings” → “RStudio”). Refusing a permission limits only the corresponding feature and does not block the App as a whole.
| Permission | Why it is needed | What happens to the data |
|---|---|---|
| Camera | Recording video in the App and running live streams | The video stream is sent to the Platform servers only after you have started a stream or confirmed publication of a recording |
| Microphone | Recording sound when capturing video and streaming | Same as the video stream: transmitted only on your command |
| Photo library (photos and videos) | Choosing videos and images to upload and edit and to set thumbnails and the avatar; saving a recorded video to the gallery at your choice | The App gets access only to the files you selected. We do not scan the library and do not upload files without an explicit action by you |
| Local network | Correct operation of network features at the first launch and during streams | The permission is used only to establish service network connections. Information about devices on your local network is not collected and is not transmitted to us |
The App does not use push notifications and does not request permission to send them. Notifications are shown inside the App in the “Notifications” section.
On-device video and image processing
To power the editor and visual effects, the App uses the computer vision facilities built into the operating system and the graphics capabilities of the device (in particular, the system Vision framework). Such processing is carried out locally on your device, in memory, at the moment of editing or recording.
- the results of image analysis are not transmitted to us and are not stored on our servers;
- the processing serves solely to apply effects and process the frame and is not aimed at uniquely identifying a person — therefore it does not constitute biometric data within the meaning of Article 9 GDPR;
- data obtained by image and camera analysis is not used for marketing, advertising or behavioural analysis — neither by us nor by third parties;
- only the final file that you submitted for publication, or the stream of a broadcast you started, reaches our servers.
6. Purposes of processing and legal bases
We process personal data only where there is a legal basis provided for by Article 6 GDPR.
| Purpose | Data categories | Legal basis |
|---|---|---|
| Registration, authentication and account management, restoring access | 3.1, 3.4 | Performance of a contract — Art. 6(1)(b) GDPR |
| Providing App features: uploading and publishing videos, streaming, working with comments, playlists, channel settings | 3.1, 3.2, 3.3, 3.4 | Performance of a contract — Art. 6(1)(b) GDPR |
| Channel analytics and providing statistics to you | 3.2, 3.4 and data received from the Platform | Performance of a contract — Art. 6(1)(b) GDPR |
| Content moderation, handling complaints, preventing abuse, keeping the service secure and protecting the rights of third parties | 3.1, 3.2, 3.3, 3.4 | Legitimate interest — Art. 6(1)(f) GDPR; as regards complying with orders — Art. 6(1)(c) GDPR |
| Keeping the service operational, diagnosing failures, technical usage analytics and improving the App | 3.4 | Legitimate interest — Art. 6(1)(f) GDPR |
| Sending informational and promotional messages about the service | 3.1 | Consent — Art. 6(1)(a) GDPR (a separate checkbox at registration; may be withdrawn at any time) |
| Handling support requests | 3.1, 3.5 | Performance of a contract — Art. 6(1)(b) GDPR; legitimate interest — Art. 6(1)(f) GDPR |
| Responding to lawful requests from public authorities, defending and pursuing legal claims | Any of the above, to the extent necessary | Legal obligation — Art. 6(1)(c) GDPR; legitimate interest — Art. 6(1)(f) GDPR |
About the consent checkboxes on the sign-up screen
At registration the App shows two separate checkboxes:
- “I consent to the processing of personal data” — confirms that you have read this Policy and have been informed about the processing. The processing necessary to create the account and provide App features is carried out on the basis of Art. 6(1)(b) GDPR (performance of a contract) and not on the basis of consent — therefore it cannot be stopped by withdrawing consent alone without ceasing to use the App; in that case the account should be deleted (section 11).
- “I consent to receiving informational and promotional messages from the service” — a standalone consent within the meaning of Art. 6(1)(a) GDPR. It is voluntary, does not affect your ability to register and use the App, and may be withdrawn at any time (section 12).
Our legitimate interest consists in maintaining a secure and operational platform, protecting users and third parties from objectionable content and abuse, and developing the App. We have balanced this interest against your rights and freedoms and use the minimum necessary amount of data.
7. Who we share data with
We do not disclose personal data to anyone other than the categories of recipients listed below, and only to the extent necessary for the relevant purpose.
| Recipient | Role | What data and why |
|---|---|---|
| YANDEX LLC (the AppMetrica service), 16 Lva Tolstogo St., Moscow, 119021, Russia | Processor, acts on our instructions | Technical and diagnostic data (clause 3.4): App usage analytics and crash report collection |
| Platform infrastructure operators: hosting, video storage and delivery (CDN), video processing and transcoding, streaming servers | Processors | Account data, user content, technical data — for storing, processing and delivering content |
| Communication and message delivery providers | Processors | Phone number or email address — to deliver one-time confirmation codes and service messages |
| Platform moderators and support team | Processors | Content, complaints, requests — for moderation and handling requests |
| Public authorities, courts, law enforcement | Independent controllers | Only where there is a lawful basis and to the extent provided for by law |
Requirement for third parties. We require any third party that receives access to personal data of App users (including analytics providers, infrastructure providers and third-party SDKs, as well as any parties related to us — parent, subsidiary and affiliated companies) to ensure a level of protection of that data no lower than the level established by this Policy and by the Apple App Store Review Guidelines.
A data processing agreement in accordance with Article 28 GDPR is concluded with each such party. Such parties may process data solely on our documented instructions, to the extent necessary to provide the service, must observe confidentiality, apply appropriate technical and organisational protection measures, and may not use the data for their own purposes, pass it to other parties or sell it.
Information about downloading and installing the App, as well as your Apple account data, is processed by Apple Inc. in accordance with its own privacy policy. We do not receive such data.
8. We do not track and do not sell data
- The App does not track you in the sense Apple gives to the term “tracking”: we do not link data collected in the App with data from other companies’ apps and websites for targeted advertising or advertising measurement purposes, and we do not pass data to data brokers.
- The App does not request permission through App Tracking Transparency because it does not carry out tracking, and does not use the advertising identifier (IDFA). The App’s Privacy Manifest states
NSPrivacyTracking = false. - The App contains no ad networks or advertising SDKs.
- We do not sell personal data and do not pass it to third parties for their own marketing purposes.
- We do not pass personal data to third-party artificial intelligence services.
- We do not build hidden user profiles and do not attempt to de-anonymise de-identified data.
9. Transfers outside the EEA
The Platform the App connects to and the analytics provider are located outside the European Economic Area, including in the Russian Federation. There is no European Commission adequacy decision (Art. 45 GDPR) in respect of the Russian Federation.
Such transfers are carried out:
- on the basis of the standard contractual clauses approved by the European Commission, together with additional technical and organisational measures (Art. 46(2)(c) GDPR); and/or
- in so far as the transfer is necessary for the performance of a contract between you and us, or to take pre-contractual steps at your request (Art. 49(1)(b) GDPR) — namely, to publish your content on the Platform, run streams and obtain statistics.
You may request information from us about the safeguards applied by writing to support@rstudio.tech. You should also be aware that the level of data protection in the recipient’s country may differ from the level guaranteed in the EEA.
10. Data retention periods
We store personal data no longer than is necessary for the purposes for which it was collected, or than the law requires.
| Data category | Retention period |
|---|---|
| Account and profile data | For as long as the account exists and up to 30 days after its deletion |
| User content | Until you delete the relevant material or until the account is deleted |
| Backups | Up to 90 days from the moment the data is deleted from production systems, after which the copies are overwritten |
| Technical logs and IP addresses | Up to 12 months |
| Crash reports | Up to 12 months |
| Usage analytics events | Up to 24 months in non-aggregated form; after that only in de-identified aggregated form |
| Correspondence with the support team | Up to 3 years from the last message |
| Materials relating to content complaints and records of violations | Up to 3 years — to prevent repeat violations and to defend legal claims |
| Consent to receive promotional messages and records of its withdrawal | Until consent is withdrawn and 3 years thereafter — as evidence of lawful processing |
Once the retention period expires, the data is deleted or irreversibly de-identified.
11. Account deletion and data deletion
You can delete your account right in the App:
“Profile” → “My data” → the “Delete profile” button → confirmation in the dialog.
What is important to know about deletion:
- the entire account is deleted, it is not temporarily deactivated;
- the channel and all content published on it is permanently deleted together with the account: videos, short videos, streams, playlists, thumbnails, descriptions, and the comments you published;
- deletion is initiated immediately; full deletion of data from production systems takes up to 30 days, and from backups up to 90 days;
- after deletion it will not be possible to register again with the same phone number;
- no additional payment, phone calls or contacting support is required in order to delete the account.
If for any reason you cannot use the in-app feature, send a deletion request to support@rstudio.tech from the address or number registered to the account. We will process such a request within 30 days.
What may be retained after account deletion. To the minimum necessary extent we may retain:
- records of identified violations and of the fact of blocking — to prevent the offender from registering again and to protect other users;
- data necessary to establish, exercise or defend legal claims — until the relevant limitation periods expire;
- de-identified aggregated statistical data that does not allow you to be identified.
12. Withdrawing consent
Processing based on consent (sending informational and promotional messages) may be stopped at any time:
- via the “unsubscribe” link in the message itself;
- by writing to support@rstudio.tech with the subject “Withdrawal of consent”.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal and does not stop processing based on other legal bases (for example, processing necessary for the performance of a contract). Device permissions (camera, microphone, photo library, local network) can be withdrawn in the iOS system settings at any time.
13. Your rights
Under Articles 15–22 GDPR you have the right:
- of access — to obtain confirmation as to whether your data is being processed, and a copy of that data;
- to rectification — to request correction of inaccurate data and completion of incomplete data;
- to erasure (the “right to be forgotten”) — to request deletion of data where the grounds set out in Art. 17 GDPR apply;
- to restriction of processing — in the cases set out in Art. 18 GDPR;
- to data portability — to receive the data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
- to object — to object to processing based on legitimate interest, and at any time to processing for direct marketing purposes;
- to withdraw consent — in the manner described in section 12;
- not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects you (see section 15);
- to lodge a complaint with a supervisory authority (see section 14).
How to exercise a right. Send a request to support@rstudio.tech. We will reply no later than one month from receipt of the request. In complex cases this period may be extended by a further two months, of which we will notify you within the first month, stating the reasons.
To protect your own data we must make sure the request comes from you: if we have reasonable doubts about the identity of the applicant, we may request additional information allowing you to be identified (for example, confirmation that you control the email address or phone number linked to the account).
Exercising your rights is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee or refuse to act on the request, giving reasons for the refusal.
14. Complaint to a supervisory authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority — in the first place at the place of our establishment:
Úřad pro ochranu osobních údajů (Office for Personal Data Protection of the Czech Republic)
Pplk. Sochora 27, 170 00 Praha 7, Czech Republic
Phone: +420 234 665 111
Email: posta@uoou.gov.cz
Website: uoou.gov.cz
You may also contact the supervisory authority of the EU member state of your habitual residence or place of work, or of the place of the alleged infringement, and pursue judicial remedies.
15. Automated processing and moderation
Uploaded content, comments and chat messages undergo automated checks for compliance with the Platform rules (including automated filters for objectionable content and protection against spam and artificial inflation of metrics). An automated check may result in the material being referred for human review, in display being restricted, in publication being rejected, or in access to the account being restricted.
Decisions that significantly affect you — rejection of content or blocking of the channel — are not taken solely by automated means: they are reviewed by a staff member. You have the right to contest any such decision, express your point of view and request human review of the decision by writing to support@rstudio.tech.
We do not carry out profiling for advertising purposes.
16. User age and protection of minors
The App is intended for persons aged 16 and over. We do not knowingly collect personal data of persons under 16.
The age threshold we have set is higher than the threshold provided for by Art. 8 GDPR as implemented in Czech law (§ 7 of Act No. 110/2019 Coll. — 15 years), therefore processing based on consent does not require authorisation by a legal guardian.
Persons aged between 16 and 18 may use the App provided that their legal guardian has read this Policy and the Terms of Use and does not object to the use of the App; the corresponding representation is given when the Terms are accepted.
If we learn that an account has been created by a person under 16, that account and the related data will be deleted. If you are a legal guardian and believe that a minor has provided us with their data, let us know at support@rstudio.tech — we will delete the data as soon as possible.
17. Data security
We apply technical and organisational measures proportionate to the risks, including:
- data is transmitted between the App and the servers over the secure HTTPS/TLS protocol;
- access tokens are stored on the device in the system Keychain and are not stored in plain form;
- passwords are stored only as an irreversible cryptographic hash;
- signing in to the account is confirmed with a one-time code sent to the linked phone number or email address;
- access to data by employees and contractors is granted on a need-to-know basis and is accompanied by confidentiality obligations;
- access is logged, and regular backups and change control are applied.
No method of transmitting or storing data is completely secure. If you become aware of a security incident or of your account being compromised, tell us immediately at support@rstudio.tech. Where the grounds set out in Articles 33–34 GDPR apply, we will notify the supervisory authority of the breach within 72 hours and, if the breach results in a high risk to your rights, we will notify you personally.
18. Data disclosures made in the App Store
The following data types are declared in the “App Privacy” section of the App’s App Store listing. This information is consistent with this Policy.
| Data type | Purpose | Linked to you | Used for tracking |
|---|---|---|---|
| Email address | App functionality | Yes | No |
| Phone number | App functionality | Yes | No |
| User ID | App functionality | Yes | No |
| User content (videos, photos, comments, messages) | App functionality | Yes | No |
| Usage data and diagnostics | Analytics, app performance | Yes | No |
| Coarse location (from IP address) | Analytics | No | No |
The App is not used for tracking; the advertising identifier is not collected.
19. Changes to the Policy
We may change this Policy — for example, when new App features appear or legal requirements change. The current version is always available at the permanent address of this page; the effective date and version number are stated at the top of it.
We will give notice of material changes at least 14 days before they take effect — by a notification in the App and/or a message to the linked email address. If a change affects processing based on your consent, we will ask for consent again. Continuing to use the App after the changes take effect means that you have read the new version.
20. Contacts
DUROMA s.r.o.
IČO: 03439054
Topolná 391, 687 11 Topolná, Zlínský kraj, Czech Republic
Commercial register: Krajský soud v Brně, section C, insert 84842
Phone: +420 605 567 890
Email: support@rstudio.tech