Integritet
Kort, för det finns inte mycket att berätta.
Den här webbplatsen
livebib.com är några enkla statiska sidor. Den sätter inga kakor, kör ingen analys och inga spårare och gör inga anrop till tredje part, typsnitten serveras härifrån, och sidorna levereras från europeiska servrar. Därför finns ingen samtyckesbanner: det finns inget att samtycka till.
Appen
Sändning sker i den inloggade appen, som är skild från de publika sidorna du läser nu. Den kräver ett konto. Du loggar in med Google eller en e-postlänk, och använder bara det den behöver för att köra dina sändningar. Kontodata ligger på EU-infrastruktur.
Vad en sändningslänk visar
En sändning är liveposition, hantera länken med samma omsorg som informationen. Konkret:
- Alla med länken kan titta på en sändning du delar: din position på rutten, fart, ETA:er till kontrollerna och de foton och uppdateringar du lägger upp. Du bestämmer vem som får länken.
- Vem som kan titta är ditt val. Sändningar kan vara privata, och en länk finns bara för att du har delat den.
- Sidan lever kvar efter rundan, när du går i mål visar samma länk reprisen i stället för en liveposition.
Frågor om din data, eller vill du att något tas bort? Skriv till hello@livebib.com.
Den fullständiga integritetspolicyn
Version 2026-08-19Tidigare versioner: 2026-07-29, 2026-07-28, 2026-07-27, 2026-07-26
Det här dokumentet tillhandahålls på engelska.
Last updated: 2026-08-19
This Privacy Policy explains how Livebib collects, uses, shares, and protects personal data, and describes your rights under the EU General Data Protection Regulation (GDPR) and Swedish data-protection law.
Livebib is a live broadcast platform for endurance and outdoor athletes. The core of the Service involves broadcasting real-time geolocation publicly — this is sensitive, high-risk data, and we treat it accordingly. Please read Section 4 carefully.
Livebib is built to be EU-resident by design: the Service runs on EU infrastructure, and your location data, identity, and content are stored only in the EU.
1. Data Controller
The data controller responsible for your personal data is:
Kavod AB Muskötvägen 17B, 184 60 Åkersberga, Sweden Email: hello@livebib.com Data protection contact: privacy@livebib.com
Our current legal information is always available at livebib.com. A change of our company name, legal form, or other registration details does not change how your data is protected, does not affect the validity of this policy, and requires no action from you; if the controller entity itself changes (for example within our corporate group), we will update this policy and inform you where the law requires it.
For some processing the third party acts as an independent controller — for example our payment provider Mollie for payment data, and Google/Strava for their side of a sign-in. See Section 6.
2. Scope
This policy applies to anyone who uses Livebib — including registered users (runners, viewers, commenters, crew/moderators) and visitors who view broadcasts without an account. Viewing and following a broadcast is open and does not require an account; commenting and most interactive features require one.
3. What Data We Collect
3.1 Account and profile data
- Your email address (used for magic-link sign-in — we use no passwords), or identifiers from a sign-in provider you choose: Google (which shares your verified email with us) or Strava (which shares your athlete ID; Strava does not share your email).
- Required nickname; optional profile details.
- Session and authentication data.
- If you follow someone, we store that connection (your account, theirs, and when) to build your Following feed and to notify you when they go live; the person you follow can see that you follow them, nobody else can, and unfollowing or deleting either account removes it.
3.2 Real-time location data — SENSITIVE / HIGH-RISK
- Precise, real-time GPS location while you broadcast, shown live on a map and capable of being archived.
- Routes and historical location traces from past broadcasts.
- Privacy-zone configuration (the areas you ask us to mask).
⚠️ Location data is the most sensitive data we process. Because it can reveal where you are in real time and where you live, train, or routinely go, it carries stalking and physical-safety risks. We handle it as described in Section 4.
3.3 Activity and health data
- Pace, distance, elevation, and similar activity metrics.
- Heart rate and other biometric signals you choose to broadcast.
We treat heart-rate data as data concerning health under GDPR Article 9, and process it only with your explicit consent — its own choice, never bundled with anything else. We take that position because it gives you the stronger protection, not because we are ruling on how anyone else’s heart-rate data should be classified.
Heart rate is off until you turn it on, and off again the moment you turn it back. It has its own setting, separate from accepting this policy — agreeing to use Livebib is not agreeing to be measured. While it is off, heart rate arriving from your watch or strap is discarded on receipt and never stored. Turn it on and heart rate is stored with the broadcast and shown — as a training zone and as beats per minute — to anyone who can see that broadcast. Turn it back off and heart rate already recorded stops being shown too, not just the readings that would have come next. We keep a dated record of when you turned it on and when you turned it off, because we have to be able to show the consent existed while we relied on it.
3.4 User content
- Posts (text, photos, video, voice notes), broadcast titles, and other content you publish.
- Comments and “cheers” you send. A cheer can be a short voice recording — your own voice, sent to the runner you are watching. It is delivered privately to that runner, not published on the broadcast page, and it is never sent to an AI service.
Content can carry more than it says on the surface. A photo shows where you were. A video records whoever was nearby. A post or a spoken message can mention your health, your beliefs or your politics, because you chose to mention them. We do not scan your content looking for such details and we do not use them for anything beyond showing your broadcast; where they concern you, you are publishing them about yourself deliberately, and that is what we rely on. Only spoken messages in text mode are sent to another company (Section 5a) — your posts, photos and videos are never sent to an AI provider.
3.5 Payment data
- Livebib has no paid features yet and takes no payments today, so there is no payment data about you. The rest of this section describes what will happen when paid features launch; the Terms of Service, Section 7, sets out the commercial terms in advance.
- Payments (subscriptions and super-cheers) will be processed by Mollie B.V. (Netherlands), an EU-licensed payment institution. We will never see or store your full card number or bank credentials. We will receive and keep limited transaction data (amount, status, method, identifiers) to deliver what you bought and to meet accounting law.
- If a runner displays a personal support link (for example their own Swish number), any payment you make through it goes directly between you and the runner — Livebib is not involved and receives no data about it.
3.6 Usage, device, and analytics data
- Device and browser information, IP address, app/version, and interaction logs, used for security and operations.
- We run no analytics or tracking scripts — no advertising trackers, no cross-site tracking, no third-party analytics. Server logs are used for security and capacity purposes.
3.7 Communications
- Messages you send to support and related correspondence.
3.8 Optional Spotify connection
The Spotify connection is off unless you turn it on, and you can disconnect it at any time in settings.
- If you connect Spotify, we receive an OAuth authorization token and, for the track playing at the time, its name, artists, album, Spotify link, playback state, progress, duration, and explicit-content flag. We do not receive your Spotify password, your library, your listening history outside these checks, or your Spotify account’s personal details.
- We check what is playing only while one of your own broadcasts is live — never between broadcasts, and never for anyone else’s broadcast.
- Sharing your soundtrack is a separate choice, and it is off by default. Turn it on and the track playing is shown publicly alongside that broadcast, to anyone who can see the broadcast, and is stored with it so the soundtrack can be reconstructed when someone watches the replay. Leave it off and the connection collects nothing for public display.
- OAuth tokens are encrypted at rest and are never exposed to viewers.
- Playback history is deleted after 90 days (Section 8).
- Disconnecting deletes the connection, stops all future collection, and deletes the Spotify playback history we stored for your broadcasts. A broadcast may keep only a yes/no marker that a soundtrack was shown, with no track data behind it.
- Turning a finished broadcast into a playlist is a further, separate authorization. Once a broadcast has ended you can ask us to collect its recorded tracks into one public playlist in your own Spotify account. That requires a permission the ordinary connection does not hold — permission to write to your Spotify account — so we ask for it separately, at the moment you request the playlist, and never in advance. We then store the playlist’s identifier and public link so viewers can open it. Disconnecting removes that identifier and link from Livebib but does not delete the playlist itself: it exists in your Spotify account, and only you can delete it there.
- Spotify is an independent controller for its side of the connection (Section 6). What Spotify does with your use of its service is governed by Spotify’s own terms and privacy policy, not this one. Our Terms of Service, Section 8.1, sets out the Spotify-specific terms that apply to you.
4. How We Handle Location Data (and Safety Mitigations)
Because real-time location is broadcast publicly, we apply specific measures:
- You control broadcasting. Location is shared while you are broadcasting; you choose when to start and stop.
- Public by default. When you broadcast, your live location and content may be visible to anyone, including people without an account. Treat anything you broadcast as public.
- Privacy zones. You can define zones (for example, around your home) where your location is masked or hidden. We strongly recommend configuring them. Privacy zones are a risk-reduction tool, not a guarantee of safety.
- Stalking-risk mitigations. We aim to reduce precision near privacy zones, provide controls to stop broadcasting, and offer reporting and blocking tools (see the Content Moderation & Safety Policy). We are not able to monitor every broadcast or prevent misuse by third parties.
- EU-only storage. Your live position and route traces are stored on our EU servers. They are never sent to any AI provider (Section 5a); the only third country involved at all is the weather and elevation lookup described under International transfers in Section 6.
- Not an emergency service. Livebib does not monitor broadcasts for emergencies and cannot dispatch help.
4a. The mobile app and background location
If you install the Livebib mobile app (iOS/Android) and use it as a GPS beacon:
- The app collects your precise location only to power your own broadcast, after you have granted the location permission and confirmed the in-app consent step.
- Collection continues while a broadcast is active, including when the app is in the background or the screen is off — that is the app’s purpose, and it is clearly indicated (on Android via a persistent foreground-service notification).
- Stopping the broadcast, or revoking the location permission in your system settings, stops collection immediately.
- Positions go directly to Livebib’s EU servers. The app sends your location to no one else.
5. Lawful Bases for Processing
We rely on the following GDPR Article 6 (and, where relevant, Article 9) bases:
| Purpose | Lawful basis |
|---|---|
| Providing your account and the core broadcasting service | Contract (Art. 6(1)(b)) |
| Broadcasting your real-time location and content publicly | Consent (Art. 6(1)(a)), and, where applicable for health data, explicit consent (Art. 9(2)(a)) |
| Sensitive details you choose to put in your own content (health, beliefs, and similar), in a post, a photo, a video or a spoken message | Manifestly made public by you (Art. 9(2)(e)), alongside the consent above for the broadcast itself |
| Sending a spoken message to the transcription provider when you have switched that setting on | Explicit consent (Art. 9(2)(a)) — its own consent, separate from the broadcast, withdrawable at any time (Section 5a) |
| Processing heart-rate / biometric (health-adjacent) data | Explicit consent (Art. 9(2)(a)) |
| Subscriptions and super-cheer purchases (via Mollie), once paid features launch | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c), accounting law) |
| Security, fraud prevention, service improvement | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal/accounting obligations | Legal obligation (Art. 6(1)(c)) |
| Connecting Spotify, showing your soundtrack publicly, and exporting it as a playlist (Section 3.8) | Consent (Art. 6(1)(a)) — three separate choices, each asked for on its own; the playlist additionally needs permission to write to your Spotify account |
| Marketing communications (if any) | Consent (Art. 6(1)(a)) |
Why broadcasting rests on consent, not on our contract with you. Holding a Livebib account does not involve broadcasting: most people who sign up watch, follow and comment, and never broadcast themselves. Publishing your live position is therefore not necessary to deliver the account or the Service — it is a separate thing you choose to do — so we ask for your consent instead of relying on the contract. Starting a broadcast is that consent; stopping it withdraws the consent, and stopping is always one action away.
What stopping does, precisely. Stopping ends the collection — no further positions are recorded from that moment. It does not, by itself, unpublish what was already broadcast: the page stays up and shows the finished run as a replay, which is the point of having a page at all. The archive is yours to remove, and removing it is the other half of stopping — delete the broadcast, or your account, and the recorded route goes with it (Section 8). We say this plainly because “stopping withdraws consent” would otherwise read as though the map emptied itself when you pressed stop, and it does not. What we cannot undo is copying by other people while the broadcast was public.
Where we rely on consent, you can withdraw it at any time (see Section 9). Where we rely on legitimate interests, you may object (see Section 9), and we have balanced our interests against your rights.
5a. AI features — what the AI provider does and does not receive
AI commentary is generated by a third-party model provider (currently Mistral, established in France). Whichever provider is used, we apply the same strict data boundary:
- The provider receives only a derived, minimized summary of the broadcast: distance covered, percent done, pace, heart-rate zone (a label — never raw beats-per-minute), effort level, elevation gain, elapsed time, and place names along the route.
- The provider never receives your GPS coordinates, raw heart-rate values, name, nickname, email, or any account identifier. Your name is inserted into the commentary text by Livebib afterwards, on our own servers.
- We configure providers so submitted data is not used to train their models, under our agreements with them.
Spoken messages you choose to have written down. Voice messages are normally published as audio, like any other post you make. If you switch that setting to text, the recording is sent to the same EU provider to be turned into words, and what appears on your page is the text — the recording itself is not published at all. We keep the original recording, the way we keep the original of a photo you post, but nobody watching your page can hear it while that mode is on. If the words cannot be produced for any reason, nothing is published; we do not fall back to publishing the audio.
This is the one AI feature that receives your recorded voice. The summary described above is stripped down to numbers and place names; a recording cannot be reduced that way — it is your voice, and it carries whatever you said. It therefore never happens without your separate, explicit consent, asked on its own and never bundled with anything else. You can withdraw that consent at any time, and from that moment no further recording of yours is sent to the provider.
What you say is what is sent. Speech is free-form, so a message can mention things the law treats as sensitive — your health, your beliefs, your politics — simply because you said them out loud. We do not look for such information or use it for anything beyond producing the text of your own post, but your consent to this feature covers it, which is one reason the consent is asked separately and can be withdrawn at any time. If you would rather a particular message not go to the provider at all, send it as audio instead.
6. Processors and Sub-Processors
We use the following service providers to operate Livebib. They process personal data on our behalf under data-processing agreements, or as independent controllers where indicated.
| Provider | Role | Location / notes |
|---|---|---|
| Hetzner | Hosting / infrastructure (servers, database) | Germany (EU) |
| Bunny (BunnyWay d.o.o.) | CDN, DNS, media storage (photos, videos, map tiles) | Slovenia (EU); storage in Germany/Sweden |
| Scaleway | Transactional email (magic links) and encrypted backups | France (EU) |
| Mollie B.V. | Payment processing (subscriptions, super-cheers) — not in use yet, see Section 3.5 | Netherlands (EU); independent controller for payment data |
| Mistral | AI commentary — receives only the minimized summary described in Section 5a | France (EU); no GPS, no raw heart rate, no names |
| Google / Strava | Sign-in providers (only if you choose that login) | Independent controllers for their side of the login |
| Open-Meteo | Weather forecasts and elevation lookups along a route | Switzerland (EU adequacy decision); receives route coordinates, no identity |
| Spotify | Optional music connection — only if you connect it (Section 3.8) | Independent controller for its side of the connection |
| mailbox.org | Support mailbox (hello@) | Germany (EU) |
This list may change; the current version of this policy, published at livebib.com/privacy, is always the up-to-date list, and it is also available on request via privacy@livebib.com.
International transfers
The Service is EU-resident by design: hosting, database, media, backups, email, payments, and AI commentary are all EU-based, and your identity, content and broadcast location data stay in the EU. The only data that leaves the EU/EEA is the route coordinates we send to Open-Meteo (Switzerland) to look up weather and elevation — a place lookup that carries no name, account identifier or live position of yours, and Switzerland is covered by an EU adequacy decision. If we ever need to engage a processor outside the EU/EEA, we will update this policy before doing so and rely on a valid transfer mechanism such as Standard Contractual Clauses (SCCs) with supplementary measures. If you install our mobile app, Apple’s App Store / Google Play handle app distribution under their own policies; they do not receive your broadcast data from us. You can request more information via privacy@livebib.com.
7. How We Use Data
- To operate the Service: create accounts, broadcast runs, display maps/stats, deliver posts and comments, generate AI commentary.
- To deliver what you buy (subscription entitlements, super-cheer highlights) and keep required transaction records.
- To secure the Service, prevent fraud and abuse, and enforce our policies.
- To respond to support requests and communicate service information.
- To analyze and improve the Service (using aggregate, non-tracking data).
- To comply with legal obligations and respond to lawful requests.
We do not sell your personal data, and we run no advertising or cross-site tracking.
8. Data Retention
- Account data is retained while your account is active.
- Run archives (including location traces, statistics, and posts) may be stored long-term so that you and your followers can revisit past broadcasts — unless you delete them or your account.
- Payment/transaction records, once paid features exist and there are any, are retained as required by Swedish accounting law (7 years, bokföringslagen).
- Logs and security data are retained for 30 days and then deleted automatically.
- Spotify playback history (the tracks we recorded during your broadcasts) is retained for 90 days and then deleted automatically — sooner if you disconnect Spotify, which deletes it immediately (Section 3.8).
- A playlist you asked us to create leaves two things with us: its Spotify identifier and its public link, kept alongside the broadcast so viewers can open it, and removed when you disconnect Spotify. The playlist itself is not ours to retain or delete — it lives in your Spotify account, where it stays until you remove it there (Section 3.8).
You can delete your content and your account at any time (self-serve, in settings). Deletion removes your broadcasts — including location traces — your posts, chat messages, and account records. Limited exceptions: data we must retain by law (such as payment records), anonymized aggregate statistics that no longer point to you, and content already copied by others while it was public — broadcasts are public, and we cannot control copies made by third parties.
9. Your GDPR Rights
You have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”) — request deletion of your data, subject to legal-retention limits.
- Restriction — ask us to limit processing in certain circumstances.
- Data portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent — withdraw consent at any time where processing is based on consent (including for location and health-adjacent data); this does not affect prior lawful processing.
- Not be subject to solely automated decisions with legal or similarly significant effects (note: AI commentary is content generation, not an automated decision about you).
To exercise these rights, contact privacy@livebib.com or hello@livebib.com. We will respond within the timeframes required by GDPR (generally one month). We may need to verify your identity.
10. Cookies and Similar Technologies
We use only strictly necessary, first-party cookies: a session cookie when you sign in, and a short-lived cookie during a Google/Strava login. We set no analytics, advertising, or tracking cookies, which is why the Service shows no cookie banner.
11. Children’s Data
Livebib is not directed at children under 16 (or the applicable minimum age of digital consent, if higher), and we do not knowingly collect their personal data. Given the location-tracking nature of the Service, this is particularly important. If you believe a child has provided personal data, contact privacy@livebib.com and we will take appropriate action. See also the Content Moderation & Safety Policy.
12. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, passwordless authentication (magic links — no password database to breach), access controls, EU-only data residency, and the location-specific mitigations described in Section 4. No system is perfectly secure; we cannot guarantee absolute security, particularly for content you choose to broadcast publicly.
13. Changes to This Policy
We may update this Privacy Policy. We will post the updated version with a new “Last updated” date and, for material changes, provide additional notice. Continued use after changes take effect constitutes acceptance, except where consent is required. A change of our company name or corporate registration details is not a material change to this policy (see Section 1).
14. Contact and Complaints
For privacy questions or to exercise your rights:
Kavod AB — Muskötvägen 17B, 184 60 Åkersberga, Sweden General contact: hello@livebib.com Data protection contact: privacy@livebib.com
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY) — the Swedish Authority for Privacy Protection Website: imy.se
You may also contact the supervisory authority in your EU country of residence.