1. Controller and contact
Featuring GmbH, Tal 44, 80331 München, Germany, is responsible for Rari under the General Data Protection Regulation (GDPR). It is registered with Amtsgericht München under HRB 287200. Managing director: Gökay Inan. VAT ID: DE426733204.
For privacy questions or support, use the contact details in our Legal Notice.
2. App and website are separate
App data is created when you use the iOS or Android app. It supports your account, Packs, cards, Collections, safety, purchases and support.
Website data is created when you visit getrari.com. A website visit does not automatically create an Rari account or add data to your app profile.
Depending on the purpose, processing is based on performing the service (Art. 6(1)(b) GDPR), legal duties (Art. 6(1)(c)), our legitimate interests in security, fair moderation, technical stability and data-minimised internal product improvement (Art. 6(1)(f)), or your consent (Art. 6(1)(a) GDPR and, where applicable, § 25 TDDDG). Optional consent can be withdrawn at any time; you can object to processing based on legitimate interests.
3. Data in the Rari app
To run Rari, we process an account ID, sign-in provider and the profile information you choose to provide. We also process app and device details such as app version, operating system, language, time zone, technical device and installation identifiers, technical request times and error or abuse signals.
Cards and avatars can contain an image, title, colour information, technical image features, moderation results, controlled content or vibe signals and a private Affinity signal. We process Keeps, Discards, Packs, Live Picks, Collections, card views and other decisions to operate Rari, calculate Taste, Aura, Rarity and Affinity, and protect the community. These scores are product signals, not money and not a judgment of your worth.
Rari may show public cards from creators aged 18 or over that do not show recognisable minors as part of genuine Pack openings on its own organic accounts with social-media services such as TikTok, Instagram and YouTube. For this purpose, we process the card image and, where applicable, its title in a screen recording. We do not show usernames, location data, private Affinity signals or private collecting decisions. The purpose is to present Rari through the real product experience; paid advertising, selling the content and licensing it to other advertisers are not covered. We base this narrowly limited processing on the permission granted in the Terms and our legitimate interest in presenting our product under Article 6(1)(f) GDPR. Affected people may object on grounds relating to their particular situation through the contact details in our Legal Notice.
If you use Friends, we process the connected account IDs, connection time, protected invitation tokens and invitation creation, expiry and acceptance information to connect you and select eligible Live cards from your friends more often. This optional feature is provided under Art. 6(1)(b) GDPR. By sharing an invitation link, you invite whoever validly redeems it; a forwarded link can also be accepted. The connection is created when that person expressly accepts in the app, without another confirmation by the sender. Your Friends list is private; other users cannot browse it. Rari does not upload your address book. Sharing uses the app or service you choose, under that provider’s own privacy terms. Friends do not grant Rari Club access.
Teenagers and adults can become Friends. Before acceptance, a valid unused link may reveal the inviter’s username and avatar, but does not grant the additional Card access described here. When both confirmed friends are currently at least 16, they can see each other’s eligible Created cards and public Collections across the Teen/Adult boundary, and discover and Keep each other’s eligible cards through the Friends slot in Packs. There is no additional age-gap limit. This is a product protection boundary, not a statement of legal permission or a guarantee that a connection is safe. For an under-16 member and an adult, the ordinary directional content boundary remains. Private Collection settings, moderation, reports and blocks continue to apply. Each Card requires access to its own creator; viewing a friend’s Collection does not grant access to other teenagers’ cards.
Removing or blocking a friend ends this additional access, including access based solely on a Keep made through the exception. Independent ordinary access and eligible pre-adult historical Keeps remain governed by their existing rules. Rari rechecks access for new requests; content already received or separately saved cannot be recalled. With Friends notifications enabled, we may notify an inviter of acceptance and a creator of the first eligible friend Keep of their Card. A named Keep notification requires the collector’s public Collection and current content access for the recipient. These settings do not make collecting decisions visible to unrelated users.
From card characteristics and your positive collecting decisions, we normally calculate Affinity, a private signal that helps us select suitable cards. We use only Rari signals, not data from other Featuring apps, advertising or external data sources. Rari does not intentionally use Affinity to infer ethnic origin, health, religion, sexuality or other sensitive traits. You can turn Affinity off in the Privacy Center at any time. We then delete your private Affinity signal, stop updating or using it and choose Packs without it.
If you allow location just in time for publishing or nearby discovery, the app briefly reads an approximate foreground location and processes it into a coarse location area. We do not use background location or image EXIF location. A location used for nearby discovery is used only for that request. A location area for a publication can be stored with the publication. Location is optional and not needed for core collecting. You control future location access through “Location for discovery” in the app settings and your device’s location permission. If access is disabled, the app stops reading new location data. A stored publication location area can remain with the publication until it is removed under the retention rules below.
Push notifications are optional. If enabled, the app receives a device push token and notification status. You can turn notifications off in the device settings.
4. Age and safety information
Rari is for people aged 13 and over. During account setup, Rari requires your exact date of birth and privately derives the time of your eighteenth birthday (adultAt). These private details are needed to enforce the minimum age, ordinary Teen/Adult visibility and the current age-16 boundary for the confirmed-Friends exception. These details remain private and connected to your account and are deleted with the account; limited backup copies can remain for a limited period. Your date of birth is not shown on your public profile or sent to external Analytics or other users. We do not ask for an identity document as a normal part of sign-up.
Teenagers discover Teen cards first and may also discover age-appropriate 13+ cards from adults. Adults cannot newly discover Teen cards in general discovery. The confirmed-Friends exception above applies only when both people are at least 16, and only to the authorized creator. A Teen card kept before the collector turns 18 may remain historically accessible; a Keep made as an adult through Friends does not create that historical permission. A card’s audience does not change after publication. Please provide truthful information; a change can require a security review.
On supported Apple devices, immediately before sign-in, Rari uses Apple’s Declared Age Range API to request only under 13, ages 13 through 17, or ages 18 and over. The result is compared locally with the entered birthday and then discarded. It is not stored or sent to our backend, Google Analytics, Crashlytics or diagnostics, and is not used for advertising. If sharing is declined, or on older iOS versions and Android, the validated birthday self-attestation applies.
5. AI and human moderation
Before a card or avatar is published, a commissioned automated service checks the image and title for safety, rule compliance, basic authenticity and quality. Only the content and technical information needed for that check are transferred. Direct account identifiers, email address, location data and EXIF metadata are not transferred for this check. The service can create internal content and Affinity signals. It is not intended to identify people or infer protected characteristics.
Before your first upload, you clearly confirm these Content Checks. This is a transparency and use requirement for future publishing, not blanket GDPR consent for every purpose. If you withdraw the confirmation on the Content Checks settings page, you can keep collecting but cannot upload new images or titles until you confirm again.
Automated checks can be wrong. A trained Rari operator can review a decision, and you can contact us about a blocked upload or account action. Rari considers context, severity, repetition, the rights of affected people and the interests of teenagers. We do not remove content merely because a fixed number of reports was reached.
We process in-app reports, blocks, moderation actions and their explanations to protect users, respond to complaints and meet legal duties.
6. Internal analytics and diagnostics
A Google Analytics service is active when the Rari app starts. It processes pseudonymous app-instance, device, usage and approximate-location data plus bounded events such as onboarding steps reached, account creation, feature use and Pack use. This helps us understand where flows fail and which core features are actually used. Rari sets no Analytics user ID, age-cohort property or advertising ID, keeps advertising features disabled and does not use the data for advertising.
Separately, Rari privately counts new accounts, the first card publication or first completed Pack, invitations issued and redeemed, and verified or refunded Creator Slot Release purchases on the server. Age is used only at the event time to place the event in the broad internal bands 13–15, 16–17, or 18 and over. Daily counters and Rari Control responses contain neither account ID nor birthday; only timestamps preventing duplicate counting remain on the private account. Age and age band are not sent to Google Analytics, Crashlytics or other external analytics. Sandbox purchases do not contribute.
Google services for crash and performance diagnostics can receive technical data such as app version, device model, operating system, installation or session identifiers and network timings. Rari does not link this diagnostic data to the Rari account ID. Free-form personal content such as titles, images, tokens or email addresses should not appear in technical error data.
We rely on our legitimate interests under Art. 6(1)(f) GDPR for this data-minimised internal product and stability measurement. Analytics and Diagnostics can be turned off independently in the Privacy Center. The settings are stored for the signed-in account and loaded again after sign-in. While no account is bound, the launch default applies. While a signed-in account is loading, and on read errors, Analytics and Diagnostics remain disabled until the stored state is confirmed. Development builds do not send this data.
Technical security services support safe app versions and protection against manipulated clients. They can process technical identifiers needed for those security functions. The website has no advertising or analytics SDK, external embed or tracking pixel.
7. Purchases and Creator Slot Release
The relevant app store processes store payments under its own terms. Rari receives the transaction and entitlement information needed to validate a purchase. A commissioned purchase service helps us verify and record that entitlement.
Creator Slot Release is the current product name for the feature formerly called Card Replacement. It is a one-time purchase that can release an occupied creator slot before a card’s normal end. It does not erase the existing card and does not remove it from people who already collected it. Store and purchase records may therefore remain for billing, fraud prevention and legal accounting.
The feature is available to eligible Rari users aged 13 and over. Required consent for minors and the relevant store, family and payment approvals still apply.
8. Providers, transfers and retention
Rari uses Google services for accounts, app operation, storage, moderation and optional diagnostics. RevenueCat processes purchase entitlement data. Apple provides the local Declared Age Range request on supported devices; Rari does not send its result to the backend. Apple and Google process store and payment data under their own policies. When Rari publishes a Pack recording on one of its own organic social-media channels, the relevant platform provider such as TikTok, Meta or Google also processes the public recording under its own terms and privacy information.
For the website, Rari also uses Cloudflare for delivery and security. Cloudflare can process IP addresses, request and header data, timestamps, security and technical network data and can set strictly necessary security cookies when required. Rari does not use Cloudflare for advertising or website analytics.
These providers may process data in the European Economic Area or in other countries. Where GDPR transfer rules require it, Rari uses an adequacy decision, standard contractual clauses or another lawful safeguard. Provider contracts and privacy notices explain their own roles and processing.
The main retention periods are:
- account, profile and active content: until account deletion or justified global removal;
- friend connections: until either person removes the connection, a block ends it or an account is deleted; friend invitations and protected retry records: valid for at most seven days, then scheduled for deletion; physical cleanup is asynchronous. An invitation can be accepted only once, and acceptance does not extend its expiry;
- stopped cards: at existing collectors until account deletion or global removal;
- organic Pack recordings: until removal from the relevant Rari channel; following a justified objection or global removal, we review and remove the affected recording from our own channels where technically possible and the affected person’s rights prevail;
- pre-publication and Pack-session data: 30 minutes and 24 hours respectively; then it is automatically deleted;
- app and security logs: 30 days; certain provider logs can remain longer under the relevant provider periods;
- Terms acceptance proof: one record per accepted version containing the time, version, language and technical information needed to identify the text shown; contract duration plus the regular three-year limitation period from the relevant year end;
- closed notice evidence: 12 months; minimal decision evidence: three years; longer retention only for a specific proceeding;
- analytics data at user and event level: two months; aggregated reports can remain longer;
- private Growth duplicate-counting markers: until account deletion; identifier-free daily age-band aggregates and internal reports: while needed for documented product decisions;
- crash and performance data: 30 to 90 days depending on the data type;
- accounting and tax records: only where applicable, six, eight or ten years by record type;
- language cookie: 180 days.
If another person collected a card and you only stop its further distribution, it stays in that person’s Collection and your creator slot stays blocked until the original card end. A global legal or safety removal or account deletion can instead remove the card across the app.
9. Website
getrari.com is a website delivered and protected through Cloudflare. A request can create technical usage and security data at the providers involved, such as IP address, time, requested page and request or network data. We do not combine this with app data merely because the same person visits both.
Friend invitation links use open.getrari.com. If your device opens the link on the web, it redirects to the existing getrari.com homepage without passing the invitation token to that page or redeeming it. Technical request logs at the hosting providers may include the original invitation URL. The website does not save an invitation in browser storage or recover it after app installation. After installing Rari and creating an account, open the original invitation again to accept it in the app.
The language choice is stored for up to 180 days in a first-party cookie and contains only “de” or “en”. Rari uses no website cookies for advertising or analytics. Cloudflare can set strictly necessary security cookies when required.
10. Your rights and deletion
You can ask for access, correction, deletion, restriction, data portability or an objection to processing. Where processing is based on consent, you can withdraw consent without affecting earlier processing. Use the contact details in our Legal Notice. You may also complain to a data-protection authority in the EU.
You can delete your account in the app’s account settings or contact us. We may need a fresh sign-in or another reasonable security check before deleting an account. Deletion starts immediately and is normally completed within 30 days. It removes cards from other users’ Collections as well. Legally retained evidence and documented remnants in backup copies or systems of commissioned service providers can remain for their respective limited periods.
If you are recognisable on a Rari card but do not have a Rari account, you can contact us with a precise description, card ID or screenshot and request review or removal.
The competent supervisory authority for Featuring GmbH is the Bavarian State Office for Data Protection Supervision (BayLDA). You may also complain to another authority competent under the GDPR.
We use appropriate technical and organisational safeguards, including access controls, authenticated media access, abuse protection and encrypted connections. No internet service can promise absolute security.
We may update this policy when the app or law changes. The date at the top identifies the current text.