
Privacy Policy
Security & Privacy
1. Contact
KoalaSync is operated by Timo Schmidt.
For privacy-related questions, contact: [Show Email]
2. Website Hosting & Access Logs
KoalaSync is hosted on infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The server is located in Finland, within the EU/EEA. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Hetzner.
When you visit this website, standard access logs may include your IP address, browser/user agent and timestamp. These logs are used only for security, stability and abuse prevention and are automatically deleted after 7 days.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in operating the website securely, maintaining stability, and preventing abuse.
3. No Third Parties & Open Source
KoalaSync deliberately avoids analytics tools, tracking cookies, or advertising networks. We do not load any third-party resources (such as Google Fonts) to maximize the protection of your privacy.
Since KoalaSync is 100% open-source, every single line of code can also be publicly viewed and audited for security on our GitHub repository.
4. Official Relay Server & Room Data
The official KoalaSync relay server does not keep persistent logs. It does not store room history, sync history, watch history, room messages, playback events, tab titles, or media titles on disk.
To provide the room feature, the relay temporarily processes room and synchronization data in memory while a room is active. This can include room ID, peer ID, display name, playback state, sync events, and, depending on title privacy settings, tab/media titles. This data is only forwarded to participants in the same room and is removed from memory when the room expires or is closed.
Legal basis: Art. 6(1)(f) GDPR, legitimate interest in providing the requested synchronization functionality, maintaining security, and preventing abuse.
Room and peer counts are aggregated operational metrics used to monitor server status.
5. Browser Extension & Local Storage
To synchronize playback between participants in the same room, the KoalaSync browser extension temporarily captures data from the currently active video tab (e.g., tab title, media metadata like the video title, and playback state). Tab or media titles can potentially be personal depending on content. They are only processed for the synchronization feature, can be limited or disabled through title privacy settings in the extension, are forwarded only to room participants, and are not logged or stored persistently by the relay.
The extension stores only settings required for operation locally in the browser, such as username, server URL, current room credentials, language, title privacy settings, notification preferences and audio-processing settings. KoalaSync does not store general browsing history or a persistent watch history.
The extension only connects to the relay server while you are actively in a room. No persistent background connection is maintained, so your IP address is not exposed to the server when you are not using the extension.
6. Extension Permissions
To fulfill its technical purpose, the browser extension requires certain permissions. Each permission is used exclusively for core functionality:
- storage: Allows local storage of your username, server URL, room credentials, and settings in your browser so they persist between sessions.
- tabs: Required to list open tabs in the extension's dropdown and read their titles, making it easy for you to select the correct video tab.
- scripting: Required to securely inject the synchronization script (content.js) into your selected video tab.
- alarms: Prevents the extension's background service worker from being suspended by the browser during an active synchronization session.
- activeTab: Enables secure, temporary interaction with the currently active tab for direct playback commands.
- notifications: Enables optional desktop notifications, such as when a new friend joins the room.
- <all_urls> (Host permission): Allows the extension to scan for HTML5 video elements on any website, enabling cross-platform synchronization (e.g., on YouTube, Netflix, Jellyfin etc.).
7. Brute-Force & Rate-Limit Protection
For abuse prevention, failed join/login attempts may temporarily keep IP address and room ID in memory for up to 15 minutes. This data is not written to disk, is not exposed publicly, and is deleted automatically. Legal basis: Art. 6(1)(f) GDPR, legitimate interest in preventing brute-force attacks and abuse.
8. Recipients & Third Parties
Technical hosting and connection data may be processed by Hetzner as hosting provider on behalf of the operator. Room sync data is forwarded only to participants in the same room. KoalaSync does not use analytics providers, advertising networks, or tracking services.
9. Required & Optional Data
Providing technical connection data is necessary to access the website and use the relay. Room credentials and sync events are necessary to use room synchronization. Sharing tab/media titles is optional and can be limited through the extension’s privacy settings.
10. Data Subject Rights
Under the GDPR, you may have the right to access, rectification, erasure, restriction of processing, data portability, objection, and the right to lodge a complaint with a supervisory authority.
Because KoalaSync does not use accounts and does not keep persistent room logs or watch history, many data points are either short-lived or cannot be linked back to a specific person after deletion. KoalaSync does not collect or retain additional identification data solely to identify users for rights requests.
Contact for privacy requests: [Show Email]
11. No Profiling & Automated Decision-Making
KoalaSync does not use profiling or automated decision-making within the meaning of Art. 22 GDPR.
12. Third-Country Transfers
The regular hosting setup is located within the EU/EEA. No regular transfer of personal data to third countries takes place.