Your data rights
If the GDPR applies to you, you hold the rights below. This page says how each one is exercised and what Riluno can actually do today, rather than restating the regulation.
Erasure — deactivated at once, erased 30 days later
Request account and data deletion, from the web or from within the app.
Accounts now exist, so there is something to delete: the address you signed in with, your hashed password, and the identifiers described in the privacy notice. Submitting a request records it, starts the clock on the deadline below, and deactivates your account straight away: every session ends and your videos and channels stop being shown. Nothing is erased for 30 days (never more than one calendar month), so that a deletion made by mistake can be undone by signing in again. After that the erasure runs automatically across every system holding a copy.
Riluno must answer a request within one month, and may extend that by two further months for complex requests, telling you within the first month if it does. That is Article 12(3) and it applies whether or not Riluno has settled its own retention policy.
Some safety-review evidence may be subject to a retention that survives an erasure request; Deletion runs as a tracked workflow with a step for each place a copy lives: your profile and credential, your uploads and the copies the media provider holds, derived assets, caches, interactions, and your sessions — you are signed out everywhere as the first step, and the erasing steps wait until the 30 days are over. A step that fails is retried rather than skipped, and completion is reported only when every step has actually finished. Backups are the exception: they cannot be edited, so they are not used in normal operation and expire on the backup schedule. A step may be held where the law requires the data to be kept — a preservation order, for example. Riluno will tell you that something was retained under legal authority; it will not tell you which thing, because for the likeliest reason a hold exists, naming it would tell the subject of an order that the order exists.
Access and portability
Ask from inside the app or the website while signed in, and Riluno answers immediately with a JSON file — a machine-readable, commonly used, interoperable format, which is what Article 20 asks for. It contains your account identifier, the address you sign in with, the roles the account holds, and the content and comments attributed to you. It deliberately does not contain your password hash or its salt: those are not information about you, they are the mechanism protecting it, and putting them in a file you can forward or lose makes an offline attack cheaper for no benefit to anybody.
Rectification
You can change your password yourself, at any time, from the account screen. The caption and topic on something you uploaded can be corrected while it is yours. The address you sign in with cannot yet be changed in the product — write to privacy@riluno.org and it will be corrected by hand. That is a gap in the product rather than a limit on the right, and it is stated as such.
Restriction and objection
There is no self-service control for this yet. Write to privacy@riluno.org, and the request is recorded and acted on by hand. Two honest limits: safety processing that Riluno is legally obliged to perform — scanning an upload before publication, keeping a moderation record — is not something an objection can switch off, because it rests on a legal obligation rather than on legitimate interests. And restriction is implemented today by suspending the processing in question rather than by a dedicated flag on each record.
Automated decisions
Riluno makes one automated decision that materially affects you: whether your uploaded media may be published. Media is scanned before publication and cannot be published without an affirmative result for that exact version.
Suspected child sexual abuse material and non-consensual intimate imagery are routed to a specialist path and cannot be restored through ordinary appeal. No automated decision refuses anything on its own. The safety scan produces an assessment and a person decides, in both directions — which is why Article 22 does not bite here. If a decision goes against you, you are told what it was and you can appeal it: the appeal is read by a person, and enforcement and appeals sets out who decides and in what time.
Complaints
You may complain to the data protection authority where you live, where you work, or where you believe the problem happened — you do not have to come to Riluno first, and you do not need our permission. The European Data Protection Board publishes the list of national authorities at edpb.europa.eu. Riluno’s own supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, because the controller is established in Berlin. Under § 19 Abs. 1 BDSG the competent authority is the one for the Land of the controller’s main establishment — it is always a state authority, never the federal BfDI, which supervises public bodies and telecommunications rather than services like this one.
Proving who you are
Riluno will ask for more information to confirm your identity only where there is genuine doubt that a request came from you, and will explain why when it does. You will not be asked for an identity document as a matter of routine: demanding one for every request collects more personal data than the request itself involves.
Contact
Write to privacy@riluno.org. No Data Protection Officer is appointed; the privacy notice explains why, and when that will change.