Privacy Policy
Last updated: 19 June 2026
This Privacy Policy explains how GenericJapaneseCompany B.V. (“Interlude”, “we”, “us”), registered in the Netherlands under KvK number 97229962 at Faas Wilkesstraat 183B, 1095 MD Amsterdam, Netherlands, handles personal data when you use Interlude (the “Service”). We are committed to processing personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch implementing legislation (UAVG).
For privacy questions or to exercise your rights, contact: hello@interlude.team.
1. A note on how Interlude works
This version of the Service does not use registered accounts or passwords. Access to a submission is controlled by a shareable link, and the names people enter are self-asserted and not verified. As a result, the personal data we hold about most users is limited and is mostly information they choose to provide.
2. What personal data we process
We process the following categories of personal data.
Data you provide directly
- Creator name — a self-asserted name a creator enters when preparing a submission.
- Reviewer / viewer name — a self-asserted name a person enters when opening a link to review or comment.
- Recipient name and email address — only when a creator chooses to send a review link by email to a named recipient. In share-link mode, no recipient email is collected.
- Content you upload or submit — files, captions, proposed posting dates, and comments. These may incidentally contain personal data if you choose to include it.
Data collected automatically
- Continuity cookie — a cookie named
il_vtstored in your browser so that, if you return to or refresh a review link, we can recognize your session and you do not have to re-enter your name. See our Cookie Policy. - Technical and security metadata — for example IP address, timestamps, and the action taken (such as an approval), recorded in an audit log to maintain a record of activity on a submission and to protect the Service against abuse.
- Live presence while reviewing — when several people view the same submission at once, the Service shows who is currently viewing and a transient “typing” indicator. To do this, the self-asserted name you entered is shared in real time with the other people viewing that same submission. This presence information is ephemeral — it is not written to our database and disappears when you close the page.
We do not intentionally collect special categories of data (such as health, religion, or biometric data), and we ask that you do not upload such data unless strictly necessary and lawful.
3. Controller and processor roles
The role we play depends on the data:
- For account-level / operational data we determine the purposes of — such as the recipient email a creator gives us to send an invite, the continuity cookie, and security/audit metadata — we act as the data controller.
- For the deliverable content a creator uploads to share with a brand — the files, captions, and comments — the creator generally determines the purpose, and we act as a data processor on the creator’s behalf, hosting and transmitting that content so it can be reviewed. The creator is responsible for having a lawful basis to share that content with the people they invite.
This split should be confirmed with legal counsel; where we act as processor, a separate data processing arrangement may apply between us and the creator.
4. Why we process it, and our legal basis
| Purpose | Personal data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the core review-and-approval Service | Names, content, captions, dates, comments | Performance of a contract / our legitimate interest in operating the Service (Art. 6(1)(b)/(f)) |
| Send a review link to a named recipient by email | Recipient name and email | Performance of a contract / legitimate interest in delivering the link the creator asked us to send (Art. 6(1)(b)/(f)) |
| Maintain session continuity and show live presence | il_vt cookie; self-asserted name (presence) | Strictly necessary for a function you requested (Art. 6(1)(f); functional) |
| Security, abuse prevention, and keeping a record of approvals | IP, timestamps, action logs | Legitimate interest in securing the Service and maintaining an audit trail (Art. 6(1)(f)) |
| Comply with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interest, we have balanced that interest against your rights; you may object as described in Section 8.
5. Where your data is stored and processed
We have deliberately chosen EU-based infrastructure. Personal data and content are processed and stored within the European Union:
- Database, authentication, and realtime — Supabase (PostgreSQL hosted in the EU,
eu-west-1/ Ireland region). - File and video storage / streaming — Cloudflare (R2 storage and Stream), with storage located in the Western Europe region.
- Transactional email — Resend (EU).
- Application hosting — Vercel (region: EU).
Where any sub-processor’s operations could involve a transfer outside the European Economic Area, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We will keep the list in Section 6 current.
6. Sub-processors
We use the following service providers to operate the Service. Each processes personal data only on our instructions and under a data processing agreement:
- Supabase — database, realtime (live presence and updates), and related backend services.
- Cloudflare — file/video storage, streaming, and network security.
- Resend — sending transactional email (review-link invites).
- Vercel — application hosting.
We will update this list when we add or change a sub-processor.
7. How long we keep data
- Free-tier submissions — submissions and their files, versions, captions, comments, and stored objects are deleted approximately 30 days after creation, automatically.
- Security and audit metadata — kept only as long as needed for security and record-keeping purposes, and then deleted or anonymized.
- Email-delivery records — kept for a limited period to confirm delivery and troubleshoot, then deleted.
- Backups — copies in routine backups age out in the ordinary course after content is deleted.
If we introduce longer-retention paid tiers, the applicable periods will be disclosed at that time.
8. Your rights
Under the GDPR you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
To exercise any right, contact hello@interlude.team. We may need to verify your request. Note that because access is link-based and names are not verified, in some cases we may be unable to associate a request with specific records without additional information from you. Where we act as a processor (Section 3), we may refer your request to the relevant creator.
9. Security
We protect personal data using measures appropriate to the risk, including: encryption in transit (HTTPS); a httpOnly, sameSite continuity cookie that is also marked secure in production; server-side access controls that scope each link to a single submission; rate limiting on link resolution; secret keys held only in server-side environments; and input validation. No system is perfectly secure, and we cannot guarantee absolute security. We accept, and disclose plainly, that anyone holding a valid link can access the associated submission — this is mitigated by link expiry, revocation, and rate limiting.
10. Children
The Service is not directed to children and is intended for users aged 18 or over. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy. The “Last updated” date reflects the latest version. Material changes will be communicated by reasonable means.
12. Contact
GenericJapaneseCompany B.V.
Faas Wilkesstraat 183B, 1095 MD Amsterdam, Netherlands · KvK 97229962
Privacy contact: hello@interlude.team