privacy
This privacy policy explains how we process personal data when you visit myscena.app, join the Scena waitlist, or use the Scena app once you have early access. We follow the EU General Data Protection Regulation (GDPR / DSGVO) and the German Federal Data Protection Act (BDSG).
1. controller
The controller responsible for data processing on this website (Art. 4 (7) GDPR) is:
Ronny DörflerUp de Worth 4
22391 Hamburg
Germany
email: hello@myscena.app
We are a small project and are not legally required to appoint a Data Protection Officer (§ 38 BDSG). For any privacy question, write to the email above.
2. overview of processing
We process the following categories of personal data for the following purposes:
- Server log data (IP address, timestamp, requested page, user agent) — to deliver the website and protect it from abuse.
- Waitlist form submissions (name, email address, how you found us, timestamp) — to evaluate your application and notify you when Scena opens for early access.
- Email correspondence (email address, message content) — when you contact us directly.
- App account & content (name, email, your photos of artworks and labels, the venues and artworks you log, ratings, notes, saved venues, and the device type you use) — to provide the personal art diary once you have early access. See section 10a.
The data subjects are visitors to this website, people who apply to the waitlist, and people using the Scena app.
3. legal bases
We rely on the following legal bases under Art. 6 (1) GDPR:
- Consent (Art. 6 (1) (a) GDPR) — for processing your waitlist application after you submit the form.
- Legitimate interests (Art. 6 (1) (f) GDPR) — for operating, securing, and analysing the technical functioning of the website. Our legitimate interest is the safe and reliable provision of an online service.
- Pre-contractual measures (Art. 6 (1) (b) GDPR) — to the extent your application is processed in preparation for a future user relationship with Scena.
4. security
We use appropriate technical and organisational measures (Art. 32 GDPR) to protect your data, including TLS/SSL encryption in transit, access controls on processing systems, and minimisation of stored data. Our processors (listed below) provide their own security guarantees, audited under their respective compliance programmes.
5. recipients and processors
We share personal data only with the processors needed to operate the waitlist. Each is bound by a data processing agreement under Art. 28 GDPR.
- Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, USA) — hosting and content delivery. Processes server log data including IP address. Vercel privacy policy
-
Supabase, Inc. (970 Toa Payoh North #07-04, Singapore 318992) — database hosting for waitlist form submissions. Data is stored on servers located in Frankfurt, Germany (AWS
eu-central-1region), within the European Union. Supabase privacy policy - Resend, Inc. (2261 Market Street #4929, San Francisco, CA 94114, USA) — sends transactional and confirmation emails. Resend privacy policy
- Anthropic, PBC (548 Market Street, PMB 90375, San Francisco, CA 94104, USA) — reads the text on artwork labels/plaques inside the app. When you scan a plaque, that photo is sent to Anthropic's AI to extract the artist, title and details. Anthropic does not use data submitted through its API to train its models. Anthropic privacy policy
-
1&1 IONOS SE (Elgendorfer Straße 57, 56410 Montabaur, Germany) — domain registration and email hosting for the
myscena.appmailboxes. IONOS privacy policy
6. international data transfers
Your waitlist data itself is stored exclusively on servers within the European Union (Supabase Frankfurt). However, some of our processors are headquartered outside the European Economic Area — Vercel, Resend and Anthropic in the United States, Supabase Inc. in Singapore — and may access data from their headquarters for operational, support, or security purposes. Where personal data is transferred outside the EEA in this way, we rely on the safeguards listed in Art. 46 GDPR — in particular, the EU Standard Contractual Clauses and, where available, the EU–US Data Privacy Framework. You may request a copy of these safeguards by writing to the email above.
7. retention
We keep your data only for as long as necessary for the purpose it was collected:
- Server logs — automatically rotated by our hosting provider (typically up to 30 days).
- Waitlist submissions — until Scena opens to the public and your application has been processed, or until you ask us to delete it, whichever comes first.
- Email correspondence — for as long as needed to respond to your inquiry, then deleted unless retention is required by law.
8. cookies and tracking
This website does not use cookies, analytics, advertising pixels, or any other form of tracking. No data about your visit is collected beyond the technical server logs described above.
9. fonts
The fonts used on this site (DM Sans, Space Mono) are served from our own server. They are not loaded from Google Fonts or any third-party CDN, so no IP address or browser information is transmitted to Google when you visit.
10. waitlist form
The homepage shows a short application form. When you submit it, the following data is sent directly from your browser to our Supabase database and stored on our behalf:
- your name
- your email address
- your answer to “how did you find out about Scena”
- the date and time of submission
We use this information to evaluate your application and, if accepted, to notify you when early access opens. We do not send marketing emails, newsletters, or share your data with anyone outside the processors listed in section 5. You can withdraw your consent and ask for deletion at any time by emailing hello@myscena.app.
10a. the Scena app
Once you are approved for early access, you can sign in and use the Scena app. This is where most personal data is processed. The legal basis is the performance of our agreement with you as a user (Art. 6 (1) (b) GDPR) — the app cannot work without it.
- Account & sign-in — your name and email address. Scena uses passwordless sign-in: we email you a one-time magic link, so we never store a password.
- Photos — the pictures you take of artworks and their labels/plaques. These are stored privately in our Supabase storage (Frankfurt, EU) and are visible only to you.
- AI label reading — when you scan a label, that photo is sent to Anthropic (see section 5) to read the artist, title and details. It is used only to fill in that artwork and is not used to train any AI model.
- Your diary — the venues and artworks you log, dates, ratings, personal notes, artist notes and saved venues.
- Location — if you allow it, your device location is used to suggest nearby venues when you log a visit. It is used at that moment to find places around you and is not stored as a location history.
- Device type — we record which kind of device you use the app on (for example iPhone, Android or desktop), so we know which platforms to support. This is a single label on your profile, not detailed tracking.
- Problem reports — if you report a problem or send feedback, we store your message and any screenshot you attach.
Your app content is private to your account and is never shown to other users or sold. You can ask us to delete your account and all its content at any time by emailing hello@myscena.app.
11. your rights
Under Articles 15–21 GDPR, you have the right to:
- access — confirm whether we process data about you and obtain a copy (Art. 15)
- rectification — correct inaccurate data (Art. 16)
- erasure — request deletion of your data (Art. 17)
- restriction — limit how we process your data (Art. 18)
- portability — receive your data in a structured, machine-readable format (Art. 20)
- objection — object to processing based on our legitimate interests (Art. 21)
- withdraw consent at any time, with no effect on processing carried out before withdrawal (Art. 7 (3))
To exercise any of these rights, write to hello@myscena.app. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for us is:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Str. 22
20459 Hamburg, Germany
www.datenschutz-hamburg.de
12. automated decision-making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR. Waitlist applications are reviewed manually.
13. changes to this policy
We may update this policy when the legal situation changes or when we change how we process data. The “last updated” date at the top of this page will always reflect the current version. Material changes will be communicated by email to people on the waitlist.