Privacy
Kort, want er valt weinig te vertellen.
Deze website
livebib.com is een set eenvoudige statische pagina’s. Ze plaatst geen cookies, draait geen analytics of trackers, en doet geen verzoeken aan derden — de lettertypen worden vanaf deze site geserveerd, en de pagina’s komen van Europese servers. Daarom is er geen toestemmingsbanner: er valt niets om mee in te stemmen.
De app
Uitzenden gebeurt in de ingelogde app, die losstaat van de openbare pagina’s die je nu leest. Het vereist een account — je logt in met Google of een e-maillink — en gebruikt alleen wat nodig is om je uitzendingen te laten draaien. Accountgegevens staan op EU-infrastructuur.
Wat een uitzendlink laat zien
Een uitzending is live locatie — behandel de link met dezelfde zorg als de informatie zelf. Concreet:
- Iedereen met de link kan kijken naar een uitzending die je deelt: jouw positie op de route, tempo, aankomsttijden naar de posten, en de foto’s en updates die je erop plaatst. Jij bepaalt wie de link krijgt.
- Wie mag kijken is jouw keuze. Uitzendingen kunnen privé zijn, en een link bestaat alleen omdat jij hem gedeeld hebt.
- De pagina blijft na de run bestaan — als je finisht laat dezelfde link de herhaling zien in plaats van een live positie.
Vragen over je gegevens — of wil je iets laten verwijderen? Schrijf naar hello@livebib.com.
Het volledige privacybeleid
Voorlopige versie — juridische toetsing loopt.
Versie 2026-07-16
Dit document is beschikbaar in het Engels.
Last updated: 2026-07-16
This Privacy Policy explains how Livebib collects, uses, shares, and protects personal data, and describes your rights under the EU General Data Protection Regulation (GDPR) and Swedish data-protection law.
Livebib is a live broadcast platform for endurance and outdoor athletes. The core of the Service involves broadcasting real-time geolocation publicly — this is sensitive, high-risk data, and we treat it accordingly. Please read Section 4 carefully.
Livebib is built to be EU-resident by design: the Service runs on EU infrastructure, and your location data, identity, and content are stored only in the EU.
1. Data Controller
The data controller responsible for your personal data is:
Kavod AB Muskötvägen 17B, 184 60 Åkersberga, Sweden Email: hello@livebib.com Data Protection contact / DPO: privacy@livebib.com
Our current legal information is always available at livebib.com. A change of our company name, legal form, or other registration details does not change how your data is protected, does not affect the validity of this policy, and requires no action from you; if the controller entity itself changes (for example within our corporate group), we will update this policy and inform you where the law requires it.
For some processing the third party acts as an independent controller — for example our payment provider Mollie for payment data, and Google/Strava for their side of a sign-in. See Section 6.
2. Scope
This policy applies to anyone who uses Livebib — including registered users (runners, viewers, commenters, crew/moderators) and visitors who view broadcasts without an account. Viewing and following a broadcast is open and does not require an account; commenting and most interactive features require one.
3. What Data We Collect
3.1 Account and profile data
- Your email address (used for magic-link sign-in — we use no passwords), or identifiers from a sign-in provider you choose: Google (which shares your verified email with us) or Strava (which shares your athlete ID; Strava does not share your email).
- Required nickname; optional profile details.
- Session and authentication data.
3.2 Real-time location data — SENSITIVE / HIGH-RISK
- Precise, real-time GPS location while you broadcast, shown live on a map and capable of being archived.
- Routes and historical location traces from past broadcasts.
- Privacy-zone configuration (the areas you ask us to mask).
⚠️ Location data is the most sensitive data we process. Because it can reveal where you are in real time and where you live, train, or routinely go, it carries stalking and physical-safety risks. We handle it as described in Section 4.
3.3 Activity and health-adjacent statistics
- Pace, distance, elevation, and similar activity metrics.
- Heart rate and other biometric/health-adjacent signals you choose to broadcast.
Depending on context and jurisdiction, heart-rate and related biometric data may be treated as special-category (health) data under GDPR Article 9, processed only with your explicit consent or another valid Article 9 basis.
3.4 User content
- Posts (text, photos, video, voice notes), broadcast titles, and other content you publish.
- Comments and “cheers” you send.
3.5 Payment data
- Payments (subscriptions and super-cheers) are processed by Mollie B.V. (Netherlands), an EU-licensed payment institution. We never see or store your full card number or bank credentials. We receive and keep limited transaction data (amount, status, method, identifiers) to deliver what you bought and to meet accounting law.
- If a runner displays a personal support link (for example their own Swish number), any payment you make through it goes directly between you and the runner — Livebib is not involved and receives no data about it.
3.6 Usage, device, and analytics data
- Device and browser information, IP address, app/version, and interaction logs, used for security and operations.
- We run no analytics or tracking scripts — no advertising trackers, no cross-site tracking, no third-party analytics. Server logs are used for security and capacity purposes.
3.7 Communications
- Messages you send to support and related correspondence.
4. How We Handle Location Data (and Safety Mitigations)
Because real-time location is broadcast publicly, we apply specific measures:
- You control broadcasting. Location is shared while you are broadcasting; you choose when to start and stop.
- Public by default. When you broadcast, your live location and content may be visible to anyone, including people without an account. Treat anything you broadcast as public.
- Privacy zones. You can define zones (for example, around your home) where your location is masked or hidden. We strongly recommend configuring them. Privacy zones are a risk-reduction tool, not a guarantee of safety.
- Stalking-risk mitigations. We aim to reduce precision near privacy zones, provide controls to stop broadcasting, and offer reporting and blocking tools (see the Content Moderation & Safety Policy). We are not able to monitor every broadcast or prevent misuse by third parties.
- EU-only storage. Location data is stored on our EU servers and never leaves the EU. It is never sent to any AI provider (Section 5a).
- Not an emergency service. Livebib does not monitor broadcasts for emergencies and cannot dispatch help.
4a. The mobile app and background location
If you install the Livebib mobile app (iOS/Android) and use it as a GPS beacon:
- The app collects your precise location only to power your own broadcast, after you have granted the location permission and confirmed the in-app consent step.
- Collection continues while a broadcast is active, including when the app is in the background or the screen is off — that is the app’s purpose, and it is clearly indicated (on Android via a persistent foreground-service notification).
- Stopping the broadcast, or revoking the location permission in your system settings, stops collection immediately.
- Positions go directly to Livebib’s EU servers. The app sends your location to no one else.
5. Lawful Bases for Processing
We rely on the following GDPR Article 6 (and, where relevant, Article 9) bases:
| Purpose | Lawful basis |
|---|---|
| Providing your account and the core broadcasting service | Contract (Art. 6(1)(b)) |
| Broadcasting your real-time location and content publicly | Consent (Art. 6(1)(a)), and, where applicable for health data, explicit consent (Art. 9(2)(a)) |
| Processing heart-rate / biometric (health-adjacent) data | Explicit consent (Art. 9(2)(a)) |
| Subscriptions and super-cheer purchases (via Mollie) | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c), accounting law) |
| Security, fraud prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal/accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (if any) | Consent (Art. 6(1)(a)) |
Where we rely on consent, you can withdraw it at any time (see Section 9). Where we rely on legitimate interests, you may object (see Section 9), and we have balanced our interests against your rights.
5a. AI commentary — what the AI provider does and does not receive
AI commentary is generated by a third-party model provider (currently Anthropic (Claude); we may also use Mistral (EU) or OpenAI). Whichever provider is used, we apply the same strict data boundary:
- The provider receives only a derived, minimized summary of the broadcast: distance covered, percent done, pace, heart-rate zone (a label — never raw beats-per-minute), effort level, elevation gain, elapsed time, and place names along the route.
- The provider never receives your GPS coordinates, raw heart-rate values, name, nickname, email, or any account identifier. Your name is inserted into the commentary text by Livebib afterwards, on our own servers.
- We configure providers so submitted data is not used to train their models, under our agreements with them.
6. Processors and Sub-Processors
We use the following service providers to operate Livebib. They process personal data on our behalf under data-processing agreements, or as independent controllers where indicated.
| Provider | Role | Location / notes |
|---|---|---|
| Hetzner | Hosting / infrastructure (servers, database) | Germany (EU) |
| Bunny | CDN, DNS, media storage (photos, videos, map tiles) | EU (storage in Germany/Sweden) |
| Scaleway | Transactional email (magic links) and encrypted backups | France (EU) |
| Mollie B.V. | Payment processing (subscriptions, super-cheers) | Netherlands (EU); independent controller for payment data |
| Anthropic | AI commentary — receives only the minimized summary described in Section 5a | US; SCCs + data-minimization; no GPS, no raw heart rate, no names |
| Mistral (if enabled) | AI commentary (same boundary as above) | France (EU) |
| OpenAI (if enabled) | AI commentary (same boundary as above) | US; SCCs + data-minimization |
| Google / Strava | Sign-in providers (only if you choose that login) | Independent controllers for their side of the login |
| mailbox.org | Support mailbox (hello@) | Germany (EU) |
This list may change; the current version of this policy, published at livebib.com/privacy, is always the up-to-date list, and it is also available on request via privacy@livebib.com.
International transfers
The Service is EU-resident by design: hosting, database, media, backups, email, and payments are all EU-based, and your location data never leaves the EU. The one exception is AI commentary when served by a US provider (Anthropic), which receives only the minimized, pseudonymized summary described in Section 5a, under Standard Contractual Clauses (SCCs) and supplementary measures. If you install our mobile app, Apple’s App Store / Google Play handle app distribution under their own policies; they do not receive your broadcast data from us. You can request more information via privacy@livebib.com.
7. How We Use Data
- To operate the Service: create accounts, broadcast runs, display maps/stats, deliver posts and comments, generate AI commentary.
- To deliver what you buy (subscription entitlements, super-cheer highlights) and keep required transaction records.
- To secure the Service, prevent fraud and abuse, and enforce our policies.
- To respond to support requests and communicate service information.
- To analyze and improve the Service (using aggregate, non-tracking data).
- To comply with legal obligations and respond to lawful requests.
We do not sell your personal data, and we run no advertising or cross-site tracking.
8. Data Retention
- Account data is retained while your account is active.
- Run archives (including location traces, statistics, and posts) may be stored long-term so that you and your followers can revisit past broadcasts — unless you delete them or your account.
- Payment/transaction records are retained as required by Swedish accounting law (7 years, bokföringslagen).
- Logs and security data are retained for a limited period appropriate to their purpose.
You can delete your content and your account at any time (self-serve, in settings). Deletion removes your broadcasts — including location traces — your posts, chat messages, and account records. Limited exceptions: data we must retain by law (such as payment records), anonymized aggregate statistics that no longer point to you, and content already copied by others while it was public — broadcasts are public, and we cannot control copies made by third parties.
9. Your GDPR Rights
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — request deletion of your data, subject to legal-retention limits.
- Restriction — ask us to limit processing in certain circumstances.
- Data portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — withdraw consent at any time where processing is based on consent (including for location and health-adjacent data); this does not affect prior lawful processing.
- Not be subject to solely automated decisions with legal or similarly significant effects (note: AI commentary is content generation, not an automated decision about you).
To exercise these rights, contact privacy@livebib.com or hello@livebib.com. We will respond within the timeframes required by GDPR (generally one month). We may need to verify your identity.
10. Cookies and Similar Technologies
We use only strictly necessary, first-party cookies: a session cookie when you sign in, and a short-lived cookie during a Google/Strava login. We set no analytics, advertising, or tracking cookies, which is why the Service shows no cookie banner. Details in the Cookie Policy.
11. Children’s Data
Livebib is not directed at children under 16 (or the applicable minimum age of digital consent, if higher), and we do not knowingly collect their personal data. Given the location-tracking nature of the Service, this is particularly important. If you believe a child has provided personal data, contact privacy@livebib.com and we will take appropriate action. See also the Content Moderation & Safety Policy.
12. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, passwordless authentication (magic links — no password database to breach), access controls, EU-only data residency, and the location-specific mitigations described in Section 4. No system is perfectly secure; we cannot guarantee absolute security, particularly for content you choose to broadcast publicly.
13. Changes to This Policy
We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice. Continued use after changes take effect constitutes acceptance, except where consent is required. A change of our company name or corporate registration details is not a material change to this policy (see Section 1).
14. Contact and Complaints
For privacy questions or to exercise your rights:
Kavod AB — Muskötvägen 17B, 184 60 Åkersberga, Sweden General contact: hello@livebib.com Data Protection / DPO: privacy@livebib.com
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY) — the Swedish Authority for Privacy Protection Website: imy.se
You may also contact the supervisory authority in your EU country of residence.