4ever1 Β· PK-Board
πŸ‡©πŸ‡ͺ DeutschπŸ‡ΊπŸ‡Έ English

Privacy Policy

This is a convenience translation. The German version at datenschutz.html is the legally binding one.
Last updated: 24 August 2026

This policy tells you which personal data is processed in the team application 4ever1 PK-Board (available at mein.4ever1.tv and as an Android app). The PK-Board is an internal tool for the members of the streamer agency 4ever1; using it requires an account and activation.

1. Controller

The controller for the data processing is:

4ever1.tv
Owner: Gino Marvin Heidrich
c/o IP-Management #9293
Ludwig-Erhard-Straße 18
20459 Hamburg
Germany
E-mail: fahrlehrermitherz@icloud.com

2. Which data we process

Account & profile

E-mail address (for sign-in, confirmation and password reset), user name, display name, password (stored exclusively as a secure Argon2id hash, never in plain text), optionally a profile picture, details such as gender/age, date of birth, and – if you provide it – your Bigo ID.

Further voluntary profile details

If you fill them in: relationship status and – after both sides confirm it – the linked person, the four lines under "Outside of Bigo" (about me, job, hobbies, music), a profile song you upload yourself, plus your chosen color theme and emblem color. All of these details are voluntary and can be deleted at any time.

Content you create

Posts, comments, team chat and channel messages, status, guestbook entries, uploaded images and voice messages, and your participation in PKs (streamer battles). Bigo IDs of PK participants are visible within the team.

Private messages (end-to-end encrypted)

Direct messages (1:1) and "whisper" messages can be end-to-end encrypted. For this you set a chat password once. If both sides have set one, text and voice messages are transmitted and stored only in encrypted form – the server (and therefore the operator) cannot read them. Without a chat password they are stored on our server like other content; in the chat, a clear indicator above the messages shows whether encryption is currently active or not.

Push notifications

If you enable notifications, a push endpoint (a technical identifier of your device/browser) is stored so that we can send you messages. You can switch notifications off individually in the settings – with three exceptions: PK reminders, team announcements and warnings always stay on. They concern appointments and safety notices where missing one would have real consequences. If you want no notifications at all, you can switch them off for the whole app on your device.

Voice and video calls

Calls and lounge rooms run as a direct connection between the devices wherever possible (WebRTC). The connection setup (signaling) runs through our server. If a direct connection cannot be established – on mobile networks that is the rule rather than the exception – audio and video are forwarded encrypted through our own relay server (coturn, Hetzner, Germany). It only passes the data through; nothing is stored in the process. During connection setup a public STUN server from Google is also queried, and it sees your IP address in doing so; the contents of the conversation never reach it.

Usage & security data

To secure your account and for moderation, sign-in times and the IP address used are logged. Server log files arise for technical reasons.

We also store: a device identifier (a random number your device gives itself – it only serves to tell your at most two simultaneous sign-ins apart), the IP address and browser identifier – at registration to detect duplicate accounts, and at every sign-in so that you can see under "My devices" where you are signed in, and your online status (time of your last activity, so that others can see who is around). None of this is passed on to third parties or used for advertising.

Location

When you tap πŸ“ Location on your status, your device asks you for permission and works out your GPS coordinates. We send those coordinates to Nominatim, the place-name service of the OpenStreetMap Foundation (United Kingdom), to turn them into a place name (such as "Hamburg"). What we then store is only that place name – never the coordinates.

This never happens without you tapping it: there is no background location tracking, and the app does not ask for your location anywhere else. The legal basis is your consent (Art. 6(1)(a) GDPR); the transfer to the United Kingdom is covered by an adequacy decision of the EU Commission (Art. 45 GDPR). You can remove the location from your status again at any time.

Which areas are opened

So that we know what to expand and what to remove, we count which area of the app was opened – for example "My PKs" or "Team chat". Only the name of the area is recorded: no content, no dwell time, and nothing about what you did there.

The link to you personally exists for at most two days, and only because "nine different people" cannot otherwise be told apart from "one person nine times". After that only daily totals without names remain. So no lasting trace is created of who looked at what and when. These figures are visible to the owner only, and only in the separate administration area. The legal basis is our legitimate interest in an app that fits its members (Art. 6(1)(f) GDPR).

Screenshots

The app tries to detect when someone takes a screenshot of a page. If that works, we record: who, on which page and when – and the team leadership is notified about it. We do not get the image itself; we only see that one was probably taken. The purpose is to protect members from content being carried out of the app; the legal basis is our legitimate interest (Art. 6 (1)(f) GDPR). The detection is technically unreliable – it does not always trigger, and it occasionally reports even when no screenshot was taken at all. We delete these entries after 90 days.

Read-aloud function

If you have content read aloud to you, we record which page was read aloud and when. That serves to improve this function; it is deleted after 180 days.

Warnings & member file

If a warning is issued, we record it together with the reason, the time and the person responsible, plus your response to it. The team leadership can add notes about a member; every access to this file is itself logged, and it does not open without a reason being given. The purpose is moderation that is transparent and fair; the legal basis is our legitimate interest (Art. 6 (1)(f) GDPR). You can request information about it at any time.

3. Purposes & legal bases

4. AI assistant "Fidolin"

Fidolin is our AI assistant. It does not run on our systems but at a service provider – everything it processes is transmitted there.

What is transmitted: what you write in the public team chat and in the channels, as well as posts, comments and guestbook entries. Two things happen with this: Fidolin replies when you address it – and it also checks whether someone is in distress, is being threatened or is being bullied (protection check). If this check triggers, we store the classification and an excerpt of up to 160 characters and notify the team leadership. On top of that come individual functions at your request: summaries, phrasing notices factually, recognizing text in uploaded images, and converting voice messages into text.

Only with your consent. We ask you the first time you start the app; without your yes, nothing of yours goes to the AI – not even the protection check. You can withdraw your consent in the settings at any time with effect for the future. The legal basis is your consent (Art. 6 (1)(a) GDPR).

What is NEVER transmitted: your 1:1 direct messages and your whisper messages – neither encrypted nor unencrypted. They are also not scanned for moderation. There is one exception that you trigger yourself: if you report a message, your device sends the relevant excerpt along – otherwise the team leadership could not review the report.

5. Audition (application interview)

If you apply to us, you get an access number from us and can use it to enter the waiting room. An account is not needed for this.

In doing so we process: the first name you enter, optionally your Bigo name, the access number, your IP address, and the times when you entered, were picked up, and when the interview ended. You can voluntarily give your Bigo ID; we check it against our block list. After the interview we record a result (accepted, rejected, later) and an internal note.

In the waiting room you upload at least three and at most six pictures of yourself – they become your later profile. Only the people who decide on your admission see them. If you are accepted they move into your profile; otherwise they are deleted together with your waiting-room entry.

For the interview itself we access camera and microphone with your permission. The same applies to the transmission as to all calls (section 2): directly where possible, otherwise encrypted through our own relay server in Germany.

The interview is recorded. During it you read a short text into the camera with which you consent to the recording and to it being passed on to BIGO support – the text is already in the waiting room, so you can read it calmly beforehand. What is recorded is your image and the voices of everyone involved; only that way can it be traced later what you were answering. The team leadership starts the recording by hand, not automatically.

ID document. In the waiting room you photograph your ID card or passport. We have to check that you are at least 18 years old – BIGO requires that of us. What is stored is the photo as well as name and date of birth, plus who checked and when. We expressly do not store the ID number; you may cover it up on the photo. Only the team leadership sees the photo – it is no longer shown even to you after upload and cannot be retrieved through the normal app.

How long. The ID photo and the recording belong in your file together with the interview result. If you are not accepted or you break off, we delete both automatically after 30 days. If you are accepted, they stay for as long as you are with us – they are our proof towards BIGO – and disappear with your account. You can request information and erasure at any time at support@4ever1.tv.

Legal basis: Art. 6 (1)(b) GDPR (steps prior to entering into a contract) and your consent for camera and microphone (Art. 6 (1)(a) GDPR), which you can withdraw at any time by ending the interview.

Storage period: Waiting-room entries are deleted after 90 days. If you are accepted, the necessary details are carried over into your member account. If you are rejected, we keep your application record for up to 6 months – only so that we are not left without a memory if you apply again. After 90 days we already remove your IP address and your pictures from it; after that only the name, result and note remain there. After 6 months everything is deleted.

Failed attempts at entering an access number or an invitation code are recorded briefly (IP address, time and the first two characters of the entry) so that nobody can try codes out one after another. These entries are deleted after 30 days. The legal basis is our legitimate interest in secure access (Art. 6 (1)(f) GDPR).

You can demand at any time that we delete your application data immediately – one message is enough (section 9).

6. Hosting & storage location

The app is operated on servers of Hetzner Online GmbH in Germany. There is a processing-on-behalf agreement in place.

Transfer to the USA. The content described in section 4 is transmitted to our AI service provider Groq Inc. (Mountain View, California, USA) and processed there; as an alternative, the same function can run via Google (Gemini). Converting voice messages into text always runs via Groq. This therefore constitutes a transfer to a third country within the meaning of Art. 44 et seq. GDPR. It takes place exclusively on the basis of your explicit consent (Art. 49 (1)(a) GDPR) – without your yes, nothing of yours is transmitted there. You are aware that in the USA no level of data protection comparable to that of the EU is guaranteed.

Place names. If you tap πŸ“ Location on your status, the coordinates go to Nominatim of the OpenStreetMap Foundation (United Kingdom) to turn them into a place name. The United Kingdom is covered by an adequacy decision of the EU Commission (Art. 45 GDPR). This never happens without you tapping it; only the place name is stored (see section 2).

Push notifications are, for technical reasons, delivered through the push service of your device manufacturer (Google, Apple or Mozilla). In the process the message is handed over to that service.

7. Disclosure to third parties

We do not sell any data and we use no third-party advertising or tracking networks. Data is passed on only to the service providers named (hosting, AI, push delivery) to the extent necessary for the function, or where we are legally obliged to do so.

One exception: BIGO. If you are accepted as a streamer, we pass on your details from the audition and the recording of your consent to BIGO support – BIGO requires this proof for admission to an agency. You consent to this expressly and audibly during the interview; without this consent we pass nothing on. For family members who do not do an audition, this transfer does not take place.

8. Storage period

Data is stored for as long as your account exists, or for as long as it is necessary for the respective purpose. When your account is deleted, the associated personal data is removed; security logs are deleted after a reasonable period.

Audition. The ID photo is deleted after 30 days – for everyone, accepted applicants included. It has served its purpose once a person has looked at it; what carries the proof is the note beside it (name as shown on the ID, date of birth, who checked, when). The recording of your consent is the proof towards BIGO: if you are accepted, it stays for as long as your account exists – delete your account and it is deleted with it. If you are turned down, or no account is created, it is gone after 30 days; the record itself after 6 months (so that a repeat application does not meet a blank memory). If you do not pass the 18-year check, nothing at all is stored.

9. Your rights

You have the rights to information, rectification, erasure, restriction of processing, data portability and objection. Any consent you have given (e.g. push) can be withdrawn at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.

To exercise them, a message to fahrlehrermitherz@icloud.com is enough. You can also request deletion of your account directly in the app.

10. Minors

The PK-Board is aimed at members of the agency and not at children. Use is only possible from the age of 18. Anyone applying for an audition gives their date of birth; if it is less than 18 years ago, the application is rejected and none of the entered data is stored. BIGO requires you to be of legal age in order to stream, and we enforce that – not with parental consent, but not at all.

11. Changes

We adapt this policy when functions or the legal situation change. The version published here is the one that applies.