Privacy policy
Last updated: Oct 7, 2026
This page explains what data Fiveover processes, why, on what legal basis, who receives it, how long we keep it and what rights you have.
In short
- The controller is Glockner Holding UG (haftungsbeschränkt) in Mannheim, Germany. Because we're based in Germany, the EU General Data Protection Regulation (GDPR) applies to everyone who uses Fiveover, wherever you live, together with the German Federal Data Protection Act (BDSG) and the German Telecommunications and Digital Services Data Protection Act (TDDDG). Where US state privacy laws apply to us, you also have the rights they give you. Some, like the CCPA, apply only to larger businesses; whether or not they apply to us, you have the rights described here.
- We don't use cookies and don't track you across other websites. We only count usage statistics if you allow it. On your device, the website and app store only that choice; the app also stores what it needs to work.
- Your reports are stored encrypted on servers in Frankfurt, Germany. What you say is turned into text by AssemblyAI in the EU. For the AI that writes your report, for emails and for payments we use providers that also process data in the USA. Who they are and how we protect transfers is explained below.
- We never store the audio. We keep what was said for you until 48 hours after the report is finished, then delete it.
- We learn from reports, also to train AI, without names or signatures. You can switch it off in the app.
- You can ask for access, correction or deletion and object to processing at any time: privacy@fiveover.app.
Who is responsible
Glockner Holding UG (haftungsbeschränkt)
Julius-Hatry-Straße 1
68163 Mannheim
Germany
Represented by the managing director, Tim Glockner
Email: privacy@fiveover.app
Contact form: fiveover.app/en-us/contact
We're not required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG). For privacy questions, write to us directly.
Private or business use
If you use Fiveover privately, for example for your own home or after a car accident, we're the controller as described on this page. If a business uses Fiveover, such as a property manager or a tradesperson, the business is the controller of the data in its reports. We then process it on the business's behalf under our data processing agreement and with these sub-processors. Please send questions and requests about such reports to the business first; if they reach us, we pass them on. For accounts, purchases, the security of Fiveover and usage statistics, we remain the controller ourselves.
When you visit the website or use the app
We deliver the website and app through Cloudflare's network. When the app loads or saves data, requests go through Supabase, our database and sign-in service. On every request these services process your IP address, the date and time, the address requested, your browser and operating system (user agent) and the page you came from. No page can be delivered without them. We also use them to fend off attacks and abuse; for example, we count how often one IP address sends a form. When you open fiveover.app without a country in the address, Cloudflare tells us which country your IP address is in, and we send you to the pages for that country in your language, so you see prices in your currency and the terms that apply to you. We don't store the country.
- Legal basis: our legitimate interest in running the website and app securely and reliably, and in showing you the pages for your country (Art. 6(1)(f) GDPR); if you use the app for a report, also our contract with you (Art. 6(1)(b) GDPR).
- How long: abuse counters are deleted after two days. Cloudflare and Supabase delete their logs after a few days, at most after 90 days.
What is stored on your device
We don't use cookies. The website only stores your choice about usage statistics, and the app also what it needs to work. Your browser's storage holds only the following:
- Your usage statistics choice: whether you allowed usage statistics and when, with no identifier (local storage, on the website and in the app separately). It's stored only once you choose; after 12 months we ask again.
- Sign-in: a session key so you stay signed in and find your reports again (local storage). It's created only when you start a report, open one through a link or QR code, or sign in, and stays until you sign out or clear your browser storage.
- Language and country: your choice, for example "en-gb", with no identifier (local storage).
- Work in progress: for example a sign-in waiting for your code (session storage, deleted when you close the tab).
- Offline queue: what you typed, photos and speech recorded without a signal, not uploaded yet (IndexedDB). They're removed once our server has accepted them; speech also when you discard it or sign out.
- App files: the app's code, so it can start without a connection (service worker). It contains no data about you.
All of this is strictly necessary to provide the website and app the way you have asked for, including your choice about usage statistics (§ 25(2) no. 2 TDDDG). What Turnstile and error reports read from your browser is explained in their sections.
Reports
A report is written only by the person who started it. The other side, such as the tenant or the client, can read it and sign it where the form offers them a signature; they can't change it.
What we process: your name and email address; the other side's name and, only if it is given, their email address and whether it was confirmed; the roles; what the report is about, such as an address, a vehicle or a job; the text of each section, the facts in its fields (such as meter readings, dates, plates and hours worked) and the photos; the remark the other side may add when signing; the signatures (drawn or typed) and who wrote, changed and signed what and when, including what the AI wrote. Every change goes into a history that can't be altered unnoticed. The record contains no IP addresses or device identifiers; it only notes whether someone signed on their own device or a shared one. What was said isn't in the PDF (see "AI features").
Why: to write the report, seal it, deliver it to the people who signed it and make it verifiable later. When sealing, our server sends only a checksum of the PDF to DigiCert's timestamp service, never its content.
Photos: the app removes location and other metadata before a photo is uploaded. Please avoid photographing people who aren't involved.
Injuries in an accident report: an accident report has a section on injuries. What it says about someone's health is a special category of personal data. We process it only to write, seal, deliver and keep the report, so that the people involved can use it to establish, exercise or defend legal claims (Art. 9(2)(f) GDPR). Only say there what the report needs.
Who sees it: the other side, where the form offers them a signature and you choose a way: they read the report on your phone, on their own phone through a QR code or link (read only), or get the PDF by email. They never see what was said. Anyone with your link or QR code sees only your name and the form's name beforehand, including in messenger link previews. The verification page shows anyone with the verification code only when the report was sealed, how many people signed it, whether only one side signed or the other side confirmed it afterwards, and checksums, never names or content.
The other side's signature: each form says whether the other side is offered a signature, and you can change that for each report. If they sign on your phone, we process their name, their signature and, only if they give it, their email address: we then send them a one-time code to confirm it, and later the sealed PDF. If they sign on their own phone through a QR code or link, they confirm their email address with a code like any account. If you choose "later by email", we process the name and email address you enter for them, seal the report with your signature and send them the PDF and a link to confirm it within 30 days; that email points to this privacy policy. If they confirm, we seal the report again with their signature under the same verification code; the earlier version stays verifiable and is deleted with the report. When they sign, the other side may add one remark of up to 1,000 characters; it's printed with their signature and sealed with the report.
- Legal basis: our contract with you for using Fiveover (Art. 6(1)(b) GDPR), and with the other side where they use Fiveover themselves to sign. For details about the other side that you enter, for our emails to them, and for text and photos about other people, we rely on both sides' and our own legitimate interest in a complete, traceable report (Art. 6(1)(f) GDPR); for injuries in an accident report, also on Art. 9(2)(f) GDPR.
- How long: sealed records are deleted 3 years after sealing. Reports that are never sealed are deleted after 90 days without changes; paid ones and ones already signed at the latest 3 years after they were created. Database backups that contain them are deleted after 35 days. If you need the report for longer, download the PDF.
Sign-in and account
You can start without an email address; we then create an anonymous account. To sign your report, you confirm your email address with a six-digit code we send you. The confirmation counts for 30 days on your account, so you don't need a new code for every report. If the other side signs on your phone and gives an email address, the code goes to their address. Supabase keeps a sign-in log with IP address and browser.
To stop bots from creating accounts and triggering code emails, Cloudflare Turnstile checks that a human is using the app when you sign in or request a code. Turnstile processes technical details of your connection and browser, such as IP address and user agent, and may store information in your browser for this. Cloudflare also uses these details as a controller in its own right to improve bot detection, never for advertising (Cloudflare's notice).
- Legal basis: our contract with you (Art. 6(1)(b) GDPR). For Turnstile and the sign-in log, our legitimate interest in protecting accounts and email sending from abuse (Art. 6(1)(f) GDPR); accessing your browser for this is strictly necessary (§ 25(2) no. 2 TDDDG).
- How long: anonymous accounts that aren't part of any report are deleted after 30 days without sign-in. An account with an email address stays until you ask us to delete it. The sign-in log is deleted after 90 days.
AI features
For these features we send data to OpenAI:
- Start: what you type or say when you start a report and your answers to its questions, so the AI picks or builds a fitting form.
- Writing the report: what you say (as text, see "Talking" below) and type. With every request, the AI also gets the form (its sections with their guidance and fields), the report's title and purpose, the current text of every section, the first 160 characters of each fact in a field, and everything said and typed in this report so far (in a very long report, the last 40,000 characters). That way it can follow corrections such as "strike that" and doesn't write anything twice. It writes the text of the sections and fills in fields such as meter readings, dates and plates. Where it's clear from what was said, it writes who said something into the text ("According to the tenant, …"), otherwise "a person present"; it never guesses a name.
- Photos: photos you take with Fiveover's camera or add to the report, together with the form's fields, the first 160 characters of each entry already in the report and what was said just before, so the AI can read values (such as a meter reading or a plate) and put the photo in the right section.
- What's missing: before you finish, the whole report goes to the AI: its texts and fields with the form and the purpose, but not what was said. It lists what the form asks for that the report doesn't say yet. The list is neither stored nor sealed, and it doesn't check whether the report is correct or complete.
- Your own forms: when you upload your own form, the file goes to OpenAI: a PDF and photos as they are, a Word file as its text only. The AI turns it into a Fiveover form and copies the fixed text it contains; it is printed word for word once you've confirmed your form says exactly that. We don't keep the file; we only keep its checksum (SHA-256), so the same file doesn't go to the AI twice. A form that's already filled in can contain personal data, so upload a blank one if you can. Only your account sees your own forms, and we don't develop new forms from them.
- Your logo: a business account with Pro can add its logo. We store it while it's in your profile and print it at the top of the reports you seal with Pro from then on; if Pro ends, it stays stored until you remove it. A report with your logo keeps it for as long as the report is stored; once nothing needs it, we delete the file.
- Better forms: we develop new forms from what people type when they start a report and from the sections and fields they add to one. Before that, we automatically remove email addresses, phone numbers, links, IBANs, postal addresses and names; the filter doesn't always catch names in German text. The cleaned text is sent to OpenAI. If it doesn't lead to a form, we delete it after 365 days. When we don't, is explained under "Learning from reports".
- Learning from reports: we use reports and their photos to improve Fiveover and to train AI models, ourselves or through providers working for us. First we remove what identifies people, such as names, contact details and signatures; we never use audio or what was said for this. We keep these copies as long as we need them for this and never publish or sell them. If you switch off "Let Fiveover learn from my reports" in the app, we stop using your reports and input for it. Reports of business accounts follow the data processing agreement.
OpenAI processes this data on our behalf and doesn't use it for training. We don't ask OpenAI to store anything, but OpenAI keeps requests for up to 30 days to detect abuse and automatically scans images for child sexual abuse material. So that the many requests about one report are answered faster and at lower cost, OpenAI may keep the unchanged beginning of a request (such as the form and what was said so far) in memory for a few minutes and reuse it for the next request about the same report (prompt caching); it isn't stored for this.
What comes from the AI: the AI writes text and facts, and may build the title and the form. Once you've changed a section's text yourself, the AI doesn't overwrite your words: its change waits until you use it or keep your version. The PDF's metadata says in machine-readable form what came from AI, including whether the title or form did (Art. 50 EU AI Act); the text itself doesn't mark it. The AI makes no decisions about people.
Talking: while you have the microphone on, what is said goes live to AssemblyAI in the EU, including what other people near your phone say. AssemblyAI turns it into text and tells different voices apart (as voice A, voice B and so on) without recognising who anyone is; the first voice your phone hears counts as yours. The AI then writes the report from that text, as from typed text; the audio never goes to OpenAI. Without a signal, short recordings stay on your device until they are sent. AssemblyAI deletes recordings and text once converted, and we never store the recordings. Tell the people with you that you're talking to Fiveover and that what they say may be written into the report. Where your browser recognises speech on the device itself and talking isn't switched on here, the sound stays on your device.
What was said: we keep what was said and typed in a report, as text with its voice labels, on our servers in Frankfurt, Germany. That way the AI gets it again with every request, and you can read it under "What was said". Only you see it; the other side doesn't, and it isn't in the PDF. We delete it 48 hours after the report is sealed or cancelled; if a report is never sealed, we delete it with the report. The text of speech sent without a report, for example when you start, is deleted 48 hours after it was sent.
- Legal basis: start, writing, talking, photos, your own forms and "What's missing" are part of the service you use (Art. 6(1)(b) GDPR). For what other people near your phone say and what the report says about them, we rely on both sides' and our own legitimate interest in a complete, understandable report (Art. 6(1)(f) GDPR). We develop new forms and learn from reports based on our legitimate interest in improving Fiveover and its AI (Art. 6(1)(f) GDPR).
- How long: for what was said, see above. Forms we generate for you when you start, by the AI or, when it can't help, as a general form named after the beginning of what you typed, are deleted after 90 days if no report uses them; a report keeps its own copy for as long as it is stored. Your own forms, uploaded or saved from a report, stay with your account until you remove them or have your account deleted; a report made on one keeps its copy. Which account used an AI feature without a report and when, for example when starting, is also deleted after 90 days. Except for an account that is still anonymous: the record that it had forms generated counts towards the limit for such accounts, so we keep it for as long as the account stays anonymous.
Payments
You pay on Stripe's page. You enter card and other payment details directly with Stripe; we never see or store them. Stripe tells us what you bought, the amount, currency, payment status, a customer and subscription number and your email address. To calculate tax, Stripe asks for your country and, where needed, your address. Before you buy, we record that and when you asked us to start right away or agreed to automatic renewal, so we can prove it.
Stripe processes some payment data as a controller in its own right, for example to prevent fraud and for anti-money-laundering checks, and collects device information on its pages for this. Stripe's privacy policy applies to that.
- Legal basis: our contract with you (Art. 6(1)(b) GDPR) and our legal retention duties (Art. 6(1)(c) GDPR).
- How long: accounting records such as payment records and invoices for eight years, business correspondence for six years, each from the end of the calendar year (German Fiscal Code § 147, Commercial Code § 257).
Withdrawals and cancellations
When you withdraw from a contract or cancel a subscription through our forms, we store what you sent, when it arrived and what we did about it, and send you and us a confirmation by email. To cancel, we look up your subscription at Stripe by your email address.
- Legal basis: our legal duties (Art. 6(1)(c) GDPR) and our contract with you (Art. 6(1)(b) GDPR).
- How long: 3 years after receipt, the usual period in which claims about them can be made.
Emails from us
We send you sign-in codes, the confirmation of your order, the link to your sealed PDF (valid for 7 days), reminders about your subscription and, if you sign up, the waitlist confirmation. They're sent through Resend in the USA. Resend keeps delivery data and content for 30 days and processes sender, recipient and delivery data partly as a controller in its own right to prevent abuse.
- Legal basis: our contract with you and our legal duties (Art. 6(1)(b) and (c) GDPR); for the waitlist, your consent.
Contact form and emails to us
We use your name, email address and message to reply to you. The form stores the message with Supabase and sends it through Resend to our mailbox. If you report illegal content (Art. 16 EU Digital Services Act), we also process where it is, your explanation and your statement that your details are correct, confirm receipt by email and tell you what we decided.
- Legal basis: our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR); if it concerns a contract with us, that contract or steps before entering into it (Art. 6(1)(b) GDPR); for reports of illegal content, our duties under the Digital Services Act (Art. 6(1)(c) GDPR, Art. 16 DSA).
- How long: 180 days in our database. In our mailbox until your enquiry is dealt with; if it concerns a contract, six years from the end of the calendar year.
Waitlist
When you sign up, we store your email address, your country, for "Hold my price" the plan, for a Team request that it's about Team, and when you signed up and confirmed. You first get an email with a confirmation link (double opt-in); only then are you on the list. We write to you when Fiveover opens in your country; if you asked about Team, we write to you to set up your team.
- Legal basis: your consent (Art. 6(1)(a) GDPR). We keep the timestamps to be able to prove your consent (Art. 7(1) GDPR).
- Withdrawal: at any time with effect for the future, by a short message to privacy@fiveover.app.
- How long: until we've opened in your country and written to you, for Team until we've written to you about it, or until you withdraw. Sign-ups nobody confirms are deleted after 7 days.
Usage statistics and tests
To see where people get stuck, we count steps such as "page viewed", "report started" or "sealed" with PostHog (servers in Frankfurt, Germany). We only do this if you allow it in the "Usage statistics" notice; until then, the website and app send no events and create no ID. An event contains the step, the page, market and form, for tests the variant shown, for a visit through a campaign link its source, medium and campaign name (utm_source, utm_medium, utm_campaign), and a random ID. The ID is new for every page view and only covers that view and the report you start from it. Events from the app also carry the report's ID, so we can count the way from start to sealing. We use no cookies, store nothing on your device except your choice, and build no profiles; we never send names, email addresses or content. Your IP address is technically sent along with the request; PostHog doesn't store it or derive a location from it.
Sometimes we show different versions of a text or step (A/B tests). Which one you see is decided at random from that ID or the report; nothing is stored on your device for it. That's only if you've allowed usage statistics; otherwise you see the usual version.
If your browser sends Global Privacy Control or Do Not Track, neither the website nor the app sends any of these events, and we don't ask. Separately, our server notes when each step of a report happened (such as started, opened, paid); that belongs to the report and is deleted with it.
- Legal basis: your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG). You can withdraw it at any time with effect for the future under "Privacy settings" at the bottom of every page and in the app.
- How long: up to one year.
Error reports
If an error happens in the app, it sends a report to Sentry (servers in Frankfurt, Germany): what went wrong, on which page, browser and operating system, language and time zone. We remove invite codes from web addresses, and your IP address isn't stored. Unlike usage statistics, we don't ask for consent here: we need them to keep the app secure and working, and they contain nothing we could recognise you by.
- Legal basis: our legitimate interest in finding and fixing errors quickly (Art. 6(1)(f) GDPR); reading these browser details is strictly necessary for this (§ 25(2) no. 2 TDDDG).
- How long: 90 days.
Who receives data
These providers process data on our behalf and on our instructions (Art. 28 GDPR). Where one also uses data for its own purposes, that's explained above.
- Cloudflare, Inc. (USA): delivering the website and app, protection from attacks, Turnstile. Worldwide network, usually a data centre close to the user. EU-US Data Privacy Framework, plus standard contractual clauses.
- Supabase Pte. Ltd. (Singapore): database, sign-in, file storage, contact form. Stored encrypted in Frankfurt, Germany; maintenance and support also from Singapore and the USA. Standard contractual clauses.
- Google Cloud EMEA Ltd (Ireland): creating and sealing the PDFs, and database backups, in Frankfurt, Germany. For access from the USA: EU-US Data Privacy Framework (Google LLC).
- OpenAI Ireland Ltd (Ireland): AI features: writing reports from what is said and typed, reading photos, listing what's missing, building forms. Processing also in the USA and other countries. Standard contractual clauses.
- AssemblyAI, Inc. (USA): turning speech into text while someone talks to write a report, telling different voices apart. Processing in the EU; recordings and text are deleted there once converted. Processing in the EU; standard contractual clauses for any access from the USA.
- Stripe Payments Europe, Limited (Ireland): payments and tax calculation, partly as a controller in its own right. Also in the USA (Stripe, LLC): EU-US Data Privacy Framework, plus standard contractual clauses.
- Resend (Plus Five Five, Inc., USA): sending emails. EU-US Data Privacy Framework, plus standard contractual clauses.
- PostHog, Inc. (USA): usage statistics. Servers in Frankfurt, Germany; access from the USA possible. EU-US Data Privacy Framework, plus standard contractual clauses.
- Functional Software, Inc. (Sentry) (USA): error reports. Servers in Frankfurt, Germany; access from the USA possible. EU-US Data Privacy Framework, plus standard contractual clauses.
The other side of a report also receives its content when you give it to them to sign, never what was said; our email provider keeps what you write to us. Our tax adviser may receive invoice and payment data. Authorities and courts only receive data where a law requires it or we need to defend our rights.
Transfers outside the EU
Some providers process data in the USA or access it from there, Supabase also from Singapore, and OpenAI also in other countries where its sub-processors are. Where a provider is certified under the EU-US Data Privacy Framework, we rely on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR; list of certified companies). For all others, and in addition, the European Commission's standard contractual clauses apply (Art. 46(2)(c) GDPR). We'll send you a copy on request.
Do you have to provide data?
Not by law. But without a name and a confirmed email address you can't sign your report; someone who signs on your phone only needs a name. Without an email address you can't pay, and we can't reply to you or add you to the waitlist. Talking, photos and everything else are optional.
No automated decisions
We don't make decisions based solely on automated processing that have legal effects on you or similarly significantly affect you (Art. 22 GDPR). You can change anything the AI wrote before you finish; whoever signs confirms what the report says.
Children
Fiveover is meant for adults. If you're under 18, only use it with your parents' permission. You must be at least 16 to join the waitlist.
Your rights
You have the right to access your data and get a copy (Art. 15 GDPR), to correction (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20), to object (Art. 21, see below) and to withdraw consent at any time with effect for the future (Art. 7(3)). Write to privacy@fiveover.app or use the contact form; we reply within one month. This is also how you can have your account deleted. On request, you get a copy of your data in a common, machine-readable format (JSON), together with your sealed PDFs.
A sealed record is evidence for the other side too. If you ask us to delete your data, we delete your account and everything that concerns only you. We keep the shared record, with restricted processing, for the other side until the end of the retention period where they need it as evidence (Art. 17(3)(e), Art. 6(1)(f) GDPR).
Your right to object
Objection under Art. 21 GDPR
Where we process data based on our legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We'll then stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims.
You can object to learning from reports and to the use of your input for new forms without giving reasons: under "Let Fiveover learn from my reports" in the app or with a short message to privacy@fiveover.app. On request, we'll explain how we balanced each interest. You withdraw your consent to usage statistics under "Privacy settings" at the bottom of every page.
Complaints
If you have a concern, please write to us first. You can also complain to your state attorney general or to a data protection authority in the EU (Art. 77 GDPR). The authority responsible for us is the Baden-Württemberg Commissioner for Data Protection and Freedom of Information (LfDI), Heilbronner Straße 35, 70191 Stuttgart, Germany, poststelle@lfdi.bwl.de, baden-wuerttemberg.datenschutz.de.
If you're in the US
What we collect: identifiers (name, email address, IP address), commercial information (what you bought), content you add (what you say and type, the report's text, photos, signatures, the other side's remark), audio while you talk to Fiveover (turned into text, never stored) and usage events. An accident report can describe injuries, which is health information; we use it only for the report. We share it only with the other side of your report and the service providers listed above. We don't sell your personal information, share it for cross-context behavioral advertising or use it for profiling.
Do Not Track: we don't track you across other websites. We only collect usage events if you allow them, and you can change that under "Privacy settings" at the bottom of every page and in the app. If your browser sends Global Privacy Control or Do Not Track, we don't collect them and don't ask. Two other companies may collect information about your activity across sites: Stripe on its checkout pages, to prevent fraud, and Cloudflare Turnstile, which runs on many websites, to improve bot detection.
Children: Fiveover is not for children under 13, and we don't knowingly collect their personal information. If you think a child has given us personal information, write to us and we'll delete it.
Review and changes: to see, correct or delete your information, email us; we answer within 45 days. When we change this policy, we post the new version here with a new date and tell you in the app or by email if the change is significant.
Changes
We update this policy when Fiveover or the law changes. The date at the top shows the current version. We'll tell you about significant changes in the app or by email.