Privacy Policy
How we handle your information. Ad-free, no data resale, EU hosting — and we do not read your private messages.
1. In short
Samling is built to bring people together — not to gather data about them. We are ad-free, we never sell your information, and everything runs in the EU (with the few exceptions noted below). This policy explains what information we process, why, and what rights you have.
As in our Community Rules: we do not read your private messages as part of the normal operation of Samling.
2. Who is the data controller
The data controller is Toysi ApS (VAT no. DK40231110), Denmark. If you have questions about your information, write to [email protected].
Toysi ApS is not required to appoint a data protection officer (DPO) under Article 37 GDPR and has therefore not appointed one. All data protection enquiries are handled via [email protected].
3. What information we process
Account information
Name and display name, email address and optionally a phone number, plus an optional profile picture.
Content you share
Posts, comments, events, groups and lists you create, images and videos you upload, and messages you send in chat.
When you upload an image or video, we automatically remove location data (GPS coordinates) and device/camera information from the file before it is stored — so we do not retain where a photo was taken.
Usage data
Technical information needed to run the service — for example when you were last active (for “active X ago”) and a device token so we can send you push notifications. We also record high-level app usage (which screens are opened, and whether key actions like creating a group or RSVPing complete) in our own database — cookie-free and with no third-party tracking tools — so we can see whether people return to the app and which parts are actually used. We use this information for aggregate statistics about how the app is used — not to profile you as an individual.
Subscription and payment
Information about your subscription and data pool. The card payment itself is handled by our payment provider Mollie — we do not store your card details.
Security and troubleshooting
An audit trail of significant events (for example creating a group or suspending an account) and technical error information if the app crashes.
4. Why we process your information, and on what basis
- To provide Samling (performance of the agreement): your account, your content, your groups and events, chat and push.
- To keep the platform safe (legitimate interest): spam protection, moderation following reports, and the audit trail. The legitimate interests we pursue are preventing abuse and fraud, protecting our users and their content, and keeping the service stable and secure. You can always object to processing based on legitimate interest, see section 9.
- To comply with the law (legal obligation): for example accounting for subscriptions and handling lawful requests.
- With your consent: optional features you turn on yourself and can turn off again at any time.
5. Your private messages
Your messages in chat and closed groups are yours. We do not read through them as part of normal operation, and we do not use them for advertising or profiling. We only access the content of your messages when necessary to handle a report, to provide support at your own request, or when we are legally required to — and only the material needed for that specific case.
6. Who we share information with (processors)
We never sell your information and we use no advertising networks or data brokers. To run the service we use a small number of processors, which may only process data on our instructions:
- Supabase (self-hosted on our own server at Contabo, Germany) — database, login, file storage and realtime. In the EU.
- Brevo (France/Belgium) — sending emails, such as confirmations and invitations. In the EU.
- Apple (APNs) and Google (FCM) — solely to deliver push notifications. Here a device token is sent outside the EU; this is necessary for push to work at all. A device token is a technical address for your device and does not by itself identify you as a person.
- Sentry (EU data centre in Frankfurt, Germany) — collecting technical errors when the app crashes so we can fix them.
- Mollie (Netherlands) — secure payment of subscriptions. In the EU.
- Anthropic (USA) — AI-assisted handling of enquiries in the support chat (“Ask the developer”). Only what you yourself write in the support chat is sent to Anthropic, and the app shows a clear notice about the transfer to the USA before you use the support feature. The transfer is based on the European Commission's Standard Contractual Clauses (SCCs).
- heypster (France) — provides GIFs. We send no personal information about you to heypster as part of GIF search.
One situation is not a sale of data but should be mentioned for completeness: if Toysi ApS is one day acquired by or merges with another company, your information may pass to the new owner, who takes over the obligations under this policy. If that happens, we will inform you before it takes effect, see section 13.
7. Transfers outside the EU/EEA
Our infrastructure is in the EU. There are two routine exceptions. Push notifications are delivered via Apple's and Google's services (APNs/FCM) and may involve transferring a device token outside the EU — this is technically necessary to send messages to your phone. The support chat (“Ask the developer”) is answered with help from Anthropic in the USA; only what you yourself write in the support chat is transferred, the app clearly warns you before you use it, and the transfer is based on the European Commission's Standard Contractual Clauses (SCCs). For both exceptions, the law of the USA does not by itself provide the same level of data protection as in the EU/EEA; we therefore use safeguards such as the Standard Contractual Clauses and limit the transfer to what is necessary.
8. How long we keep your information
We keep your information for as long as you have an account. If you delete your account, we remove your personal data, except what we are legally required to keep (for example accounting data) or need to resolve an ongoing security or abuse case. Deleted comments are marked as deleted so that threads do not break.
Specific retention periods
- Account and content — for as long as your account exists.
- Technical crash reports (crash logs) — 90 days, after which they are deleted automatically.
- Audit trail (audit log) — up to 2 years, for security and to document significant events.
- Accounting data (invoices and payment records) — 5 years from the end of the financial year the material relates to, as required by the Danish Bookkeeping Act.
- Data exports (when you request a copy of your data) — the file and download link are deleted automatically after 7 days.
- Backup copies — the server is backed up daily; each backup is kept for up to 10 days and is then overwritten automatically (rolling).
Two steps: anonymization on account deletion, erasure only on direct request
When you delete your account in the app or on samling.net, your comments and posts are, by default, anonymized: the text itself is kept so that threads and conversations other people took part in do not fall apart, but the content is no longer linked to your identity — it is shown as written by a “deleted user”. This is the normal, automatic process for a regular account deletion.
If you instead want your comments permanently deleted from our active production systems (the right to be forgotten, GDPR Article 17), you must make a direct request to [email protected]. We then carry out a manual, logged deletion of the specific comment rows — not merely hiding them. The deletion takes place in our active production systems; the content may afterwards remain in backup copies for up to 10 days until those are automatically overwritten. Backups are used solely for recovery after operational failures and are not selectively restored. This only happens on your explicit request, because permanent deletion (unlike anonymization) can leave gaps in threads where other users replied to you.
9. Your rights
Under data protection law you have the right to:
- access the information we hold about you;
- have incorrect information corrected;
- have your account and information deleted — you can do this directly in the app or on samling.net (see the section above on anonymization at account deletion versus permanent erasure on direct request);
- receive the personal data you have provided to us in a structured, commonly used and machine-readable format (data portability);
- object to or restrict certain processing;
- withdraw a consent.
You can always complain to the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, DK-2500 Valby, Denmark, www.datatilsynet.dk, if you believe we handle your information incorrectly.
10. Children
Samling is not directed at children under 15, as stated in our Terms of Service. If we become aware of an account created in breach of this, we will close it.
11. Security
Data is protected with row-level access control in the database (Row Level Security), encryption in transit and EU hosting. No solution is 100% secure, but we work continuously to protect your information.
12. Cookies
samling.net uses only the few cookies needed to log in and remember your language choice. See our Cookie Policy for details. The app itself uses no cookies.
13. Changes to this policy
We may update this policy. For material changes we will give notice in the app or on samling.net. The version number at the top shows which edition applies.
14. Contact
Questions about your information? Write to [email protected] · Toysi ApS, Denmark · VAT no. DK40231110.
Version 1.1 · Effective 23 July 2026