Privacy Policy
Version: privacy_v4_2026-09-27 · Last updated: 2026-09-27
StereoLift Live Privacy Policy
Version: 27 September 2026
1. Controller and contacts
StereoLift Live is provided by:
StereoLift – Dr. Marvin Weigand
Lammertstraße 15–19
63075 Offenbach am Main
Germany
Website: https://stereolift.live
Privacy: privacy@stereolift.live
Support: support@stereolift.live
Legal: legal@stereolift.live
Abuse and security: abuse@stereolift.live
Dr. Marvin Weigand is the controller for the processing described in this Policy unless a platform or service provider acts as an independent controller for its own purposes.
2. Scope and current product profile
This Policy covers the public website, waitlist, accounts, registration where offered, magic-link login, account portal, device authorisation, entitlement and usage control, the Meta Quest companion app where it communicates with StereoLift, support, security and optional desktop diagnostics.
Accounts may be provisioned by StereoLift or created through registration where that function is enabled. The account-processing rules below apply to the steps shown to you.
Where a paid package is offered, the Paid-Processing Privacy Information supplements this Policy with the additional order, billing and payment processing.
3. Local media and local device processing
In supported normal use, capture and conversion run on your PC. The raw desktop stream and live conversion output travel over your local network to the StereoLift Quest app. StereoLift cloud systems are not used as a relay or storage location for that raw stream.
Your PC, headset and local network may process raw screen and audio content, local conversion output, controller input, local configuration, logs, pairing state and local diagnostic files. StereoLift does not receive this data merely because it is processed locally.
Online services separately process account, device-authorisation, entitlement, usage, security, support, update and optional diagnostics data as described below.
4. Public website and security
When you use the public website, we and our service providers may process connection IP address, request time, requested resource, browser and device information, security events, rate-limit information and operational logs.
We use this data to deliver and secure the website, prevent abuse, diagnose faults and maintain availability. The legal basis is our legitimate interest in operating and protecting the service under Article 6(1)(f) GDPR. Where processing is needed to respond to a request you make, Article 6(1)(b) GDPR also applies.
5. Waitlist
If a waitlist is offered and you select the control requesting a launch or availability notice, we process your email address, request status, delivery or suppression status and limited anti-abuse information.
We use the address only for the requested launch or access notice and closely related access instructions, not for a general newsletter. The legal basis is your consent under Article 6(1)(a) GDPR, expressed by the clearly labelled waitlist submission. You can withdraw that consent at any time by using a removal link or contacting privacy@stereolift.live.
6. Account access and sessions
For account registration, provision and magic-link login, we may process:
- email address, internal account ID and account status;
- magic-link, session and refresh records;
- login, logout and session-revocation events;
- agreement-document identifiers and the recorded acceptance event; and
- request and security metadata needed to protect account access.
We use this data to authenticate the requested account, maintain sessions, record the base agreement, protect the account and provide account functions. The legal basis is Article 6(1)(b) GDPR for requested pre-contract steps and performance of the agreement, and Article 6(1)(f) GDPR for security, fraud prevention and legal defence.
7. Device authorisation, access profiles, entitlement and usage
We may process high-level account and security data such as:
- account status and assigned access profile;
- device public identity and device/server associations;
- credential, authorisation, revocation and entitlement references;
- usage and limit records;
- software version and compatibility information; and
- audit and security events.
We use this data to authorise devices, apply the assigned profile, issue and verify access, enforce limits, prevent circumvention, investigate faults and protect the service.
The legal basis is Article 6(1)(b) GDPR where processing is needed to provide the requested account and product functions, Article 6(1)(f) GDPR for security, abuse prevention and legal defence, and Article 6(1)(c) GDPR where a legal duty applies.
Required account, device, entitlement, usage and security data is not used for advertising, sale of profiles, cross-service profiling or unrelated analytics.
8. Quest app and desktop software
The Quest app and desktop software store some information locally, including keys or credentials protected by the device, pairing and trust state, signed authorisations, configuration, local logs and local diagnostic files.
When they communicate with StereoLift online services, the categories in sections 6 and 7 may be transmitted. Private keys intended to remain on the device are not sent to StereoLift merely because the device is authorised.
Meta processes Meta account, device, Store and platform data under Meta’s own terms and privacy information. StereoLift does not currently receive Meta account IDs, Quest serial numbers, advertising IDs or raw hand-tracking data as part of the described account and entitlement flow.
9. Support, administration and security incidents
When you contact us or when an operational or security issue must be handled, we may process your message, contact details, account and device references, relevant entitlement or usage state, voluntarily supplied files or report IDs, and an audit record of sensitive administrative actions.
We use this data to answer the request, correct account or entitlement state, investigate abuse or incidents, secure the service and establish or defend legal claims. The legal bases are Article 6(1)(b), 6(1)(f) and, where applicable, 6(1)(c) GDPR.
Only send information needed for the request. Review a support bundle before sending it.
10. Optional desktop diagnostics
Diagnostics upload is optional and off by default. The affirmative diagnostics switch is the consent choice; no separate account link or second consent checkbox is required.
If enabled, an uploaded technical report may contain random report and envelope IDs, software versions, feature flags, coarse system and compatibility categories, event or creation times that may be precise, session or stream outcomes, error classes, timing summaries and bounded technical evidence.
Reports are designed not to include raw screen or audio content, screenshots, URLs, access tokens, private keys, pairing secrets, private file paths, hostnames, usernames, account IDs, email addresses or direct device or licence identifiers. They are not indexed by account, email or licence identity.
Because a report can contain precise timing and may become linked to a support request through a report ID, StereoLift treats uploaded diagnostic reports as personal data unless they have been demonstrably anonymised. We use the reports to investigate faults and improve product reliability, performance and quality. The legal basis for receiving and analysing them is your consent under Article 6(1)(a) GDPR.
Turning diagnostics upload off withdraws consent for future uploads. It does not affect processing already carried out lawfully or erase separate account, entitlement, security or audit records. To withdraw consent for continued use of an existing identifiable report or request its deletion, provide the report ID where available; we then stop consent-based use and delete the report unless another legal basis requires limited retention. Anonymous aggregate results that can no longer be related to a person are unaffected.
If you voluntarily provide a report ID in a support request, we may locate the report and associate it with that support case. If a report cannot be identified from your account or identity, we do not collect additional account or device identity solely to make it searchable. A report ID may therefore be needed to act on a report-specific rights request.
11. Diagnostics upload protection
The network and security provider handling a diagnostics request necessarily receives the connection IP address while routing it. The upload protection may derive a short-lived day-specific limiter value and counter. This protection data is kept separate from the diagnostic report and is not used to identify an account, device or licence or to link activity across days.
We process this limited connection data under Article 6(1)(f) GDPR to prevent junk or abusive submissions and protect service availability. It is deleted when no longer needed for the short-lived abuse-control window, subject to any independently required security record.
12. Cookies, local storage and anti-abuse technology
We use only storage or access that is needed for authentication, session continuity, security, anti-abuse protection, service operation or a preference you request. This can include a secure refresh cookie, short-lived in-memory access data, a theme preference and anti-abuse tokens or results.
We do not currently use advertising cookies, marketing pixels, cross-site tracking or unrelated analytics storage. For the stated necessary functions, no cookie-consent banner is used. If non-essential tracking is introduced, it will not be used before the required choice is obtained.
An anti-abuse provider may receive browser and request signals needed to assess whether a form submission is legitimate. Where a named third-party service is used at a form, any additional information required for that service is provided there or through Legal & licences.
13. Recipients, service providers and transfers
We disclose personal data only where needed for the purposes described above, where required by law or where you ask us to do so. Recipient categories can include website and security providers, hosting and database providers, email delivery providers, diagnostics storage providers, app-distribution platforms and professional advisers or authorities where legally necessary.
Our service providers may process personal data outside the European Economic Area. Where an applicable European Commission adequacy decision covers the recipient, we rely on that decision. For other transfers, we use the European Commission’s Standard Contractual Clauses with supplementary safeguards where necessary. You can request information about, or a copy of, the applicable safeguards from privacy@stereolift.live.
Platform providers such as Meta may act as independent controllers for their own platform, account, security and legal purposes.
14. Retention
We retain personal data only for as long as needed for its purpose and any applicable legal, security or claims period. In particular:
- account and agreement records are retained while the account or agreement exists and afterwards only as needed for security, legal defence or legal duties;
- magic-link and session records expire or are revoked according to the authentication lifecycle;
- device, authorisation and revocation records are retained as long as needed to operate access and prevent replay or circumvention;
- usage records are retained for the relevant limit, entitlement, support and abuse-review period;
- waitlist data is retained until the requested launch/access communication and a limited suppression or objection-handling period are complete;
- support and administrative audit records are retained for the request, security, accountability and claims period;
- routine diagnostic reports and their detailed technical records are scheduled for deletion after 30 days; designated tester reports and their detailed records after 90 days; invalid tester submissions retained for validation after 14 days; a limited report index after 180 days; and technical summary records after 13 calendar months. These periods run from upload or receipt for the corresponding records, except summary periods, which run from the report day. Local analysis copies use corresponding or shorter periods; and
- short-lived diagnostics abuse-control values are deleted when the relevant limiter and security purpose ends.
Account-system recovery backups normally retain recent copies for seven days and selected daily copies for up to 30 days; manually created backups normally expire after 30 days. The latest successful automatic recovery copy may be kept longer while no replacement is available. Backup deletion occurs through scheduled rotation. Separately retained exports and legally required records follow the rules applicable to those records.
The retention periods and criteria above are applied through scheduled deletion and archival processes. Credential expiry does not by itself erase all related security or agreement records.
15. Your rights
Subject to the legal conditions, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent for future processing where consent is the basis.
Right to object
Where we process personal data on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. We will then stop that processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. You may object to processing for direct marketing at any time; we will then stop processing for that purpose. Send an objection to privacy@stereolift.live.
Send requests to privacy@stereolift.live. We may need information reasonably necessary to verify the request and locate the relevant data. We do not require or collect additional identity merely to identify a diagnostic report that is not indexed by identity; providing the report ID can enable a report-specific request.
You may lodge a complaint with a competent data-protection supervisory authority.
16. Required data and automated technical checks
Email and essential account, device, entitlement, usage and security data are needed for the corresponding account and protected product functions. Without them, those functions cannot be provided. Optional diagnostics is not required for access.
We use automated technical checks for authentication, rate limiting, device authorisation, entitlement, usage limits and abuse prevention. They decide whether a request or function is technically authorised but are not automated decisions producing legal or similarly significant effects within Article 22 GDPR.
17. Security
We use technical and organisational measures intended to protect personal data, including access controls, scoped and expiring credentials, device-bound security, revocation, encryption where appropriate, restricted administrative access and audit records.
No system can be guaranteed perfectly secure. You are responsible for securing your own computer, headset, local network and email account.
18. Children
StereoLift Live accounts and the current consumer offer are intended only for adults aged 18 or older.
19. Changes
We update this Policy when the product, providers or processing changes. Material changes are communicated where required. The Privacy Policy is information and is not accepted as a contract.