← Back to TYFF

Datenschutzerklärung / Privacy Policy

Last updated: February 2026

1. Controller / Verantwortlicher

The controller within the meaning of Art. 4(7) GDPR is:

FRYR UG (haftungsbeschränkt)
Alteburger Str. 306
50968 Köln, Deutschland
E-Mail: hello@tyff.me
Website: https://tyff.me

Geschäftsführung: Nadine Walther (CEO), Ben Niehaus (CTO)
Handelsregister: HRB 124094, Amtsgericht Köln
USt-IdNr: DE455407097

2. Overview

TYFF (“Thank You For Failing”) is a community platform that helps entrepreneurs build failure tolerance. This privacy policy explains what personal data we collect, why we process it, and what rights you have under the EU General Data Protection Regulation (GDPR), the EU Data Act (Regulation 2023/2854), and other applicable legislation.

3. What Data We Collect and Why

3.1 Visiting the Website (Server Log Files)

When you access tyff.me, our hosting provider (Vercel) automatically collects server log data including your IP address, browser type and version, operating system, referrer URL, pages visited, and date/time of the request. This data is necessary for the technical delivery of the website and to ensure its security.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure and stable website operation).
Retention: Log files are automatically deleted after 30 days.

3.2 Spice Test (Quiz)

Your quiz answers and calculated spice level are processed entirely in your browser. No quiz data is transmitted to or stored on our servers.

Legal basis: No personal data is processed server-side.

3.3 Story Submissions (Spice Wall)

When you submit a story to the Spice Wall, we collect: your story text, chosen spice level, optional display name, optional location, and optional email address.

Legal basis: Art. 6(1)(a) GDPR (your consent when submitting the form). You can withdraw consent at any time by requesting deletion of your story.
Retention: Stories are retained as long as the Spice Wall is active. You can request deletion at any time via hello@tyff.me.

3.4 Email Subscriptions

If you provide your email address and opt in to community updates, your email is stored by our email marketing provider Mailerlite. We use double opt-in where required.

Legal basis: Art. 6(1)(a) GDPR (your consent).
Retention: Until you unsubscribe. Every email contains an unsubscribe link.

3.5 Analytics (PostHog)

Only with your explicit consent (via the cookie banner), we use PostHog to collect anonymised usage data such as page views, button clicks, and feature usage. PostHog does not use cross-site tracking.

Legal basis: Art. 6(1)(a) GDPR (your consent).
Retention: Analytics data is retained for 12 months, then automatically deleted.

3.6 Content Moderation

Submitted stories are automatically checked for profanity, URLs, and email addresses using rule-based text filters. No artificial intelligence or automated decision-making within the meaning of Art. 22 GDPR is used. Flagged content is reviewed by a human moderator.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in maintaining community standards and protecting users).

4. Cookies and Storage Technologies

We distinguish between technically necessary cookies and optional cookies:

Technically Necessary

  • cc_cookie — Stores your cookie consent preferences. Duration: 6 months. Legal basis: Art. 6(1)(f) GDPR.

Analytics (only with consent)

  • PostHog cookies — Used for anonymised usage analytics. Duration: 12 months. Legal basis: Art. 6(1)(a) GDPR (consent).

You can manage or withdraw your cookie preferences at any time by clicking “Cookie Settings” in the footer or by using the cookie banner that appears on your first visit.

5. Third-Party Services and Data Transfers

We use the following third-party services to operate TYFF:

ServicePurposeData ProcessedLocation
VercelWebsite hosting, edge functionsIP address, request metadataEU / US (SCCs)
SupabaseDatabase, authenticationStory data, email addressesEU (Frankfurt)
PostHogAnalytics (consent required)Anonymised usage eventsEU / US (SCCs)
MailerliteEmail marketing (opt-in only)Email address, nameEU (Lithuania)
UpstashRate limitingIP address (temporary)EU (Frankfurt)

Google Fonts: Typography is self-hosted via Next.js (next/font). No requests are made to Google servers. No data is transferred to Google.

Data Transfers to Third Countries

Some of our service providers process data in the United States. These transfers are protected by EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR and, where applicable, by the EU-U.S. Data Privacy Framework. We ensure that all processors provide adequate safeguards as required by Chapter V GDPR.

6. EU Data Act

In accordance with Regulation (EU) 2023/2854 (Data Act), we inform you that data generated through your use of TYFF (such as story submissions) remains accessible to you. You may request a copy of your data or its deletion at any time. TYFF does not use connected devices or IoT products, so the product data access provisions of the Data Act do not apply to this service.

7. Artificial Intelligence and Automated Decision-Making

TYFF does not employ artificial intelligence systems for profiling or automated decision-making that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR or the EU AI Act (Regulation (EU) 2024/1689). Content moderation uses rule-based text filters (keyword matching), not AI or machine learning models. The Spice Test quiz uses a deterministic scoring algorithm processed entirely in your browser.

8. SSL/TLS Encryption

This site uses SSL/TLS encryption for security reasons and to protect the transmission of personal data. You can recognise an encrypted connection by the “https://” prefix in your browser's address bar.

9. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) — Request information about what data we hold about you.
  • Right to rectification (Art. 16 GDPR) — Request correction of inaccurate data.
  • Right to erasure (Art. 17 GDPR) — Request deletion of your data (“right to be forgotten”).
  • Right to restriction (Art. 18 GDPR) — Request restriction of processing.
  • Right to data portability (Art. 20 GDPR) — Receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Art. 21 GDPR) — Object to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3) GDPR) — Withdraw any previously given consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise any of these rights, contact us at hello@tyff.me. We will respond within one month as required by Art. 12(3) GDPR.

10. Right to Lodge a Complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR. The competent supervisory authority for our company is:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestr. 2–4
40213 Düsseldorf
Website: www.ldi.nrw.de

11. Changes to This Policy

We may update this privacy policy to reflect changes in our data processing practices or legal requirements. The current version is always available at tyff.me/privacy. Material changes will be communicated through a notice on the website.

12. Contact

FRYR UG (haftungsbeschränkt)
Alteburger Str. 306
50968 Köln, Deutschland
E-Mail: hello@tyff.me