Privacy
Radio Bollwerk keeps as little about you as it can. Listening, the archive and reading the chat need no account. This page explains, in plain words, what our website, the RBW iPhone app and the server behind both do with data about you, who else gets to see it, how long it stays and what you can do about it.
Last updated: 5 October 2026
The short version
- No ads, no tracking across other sites, and we never sell data about you.
- The website counts visits with Plausible Analytics, which we run ourselves, without cookies. The app has no analytics at all.
- Listening, the archive and reading the chat need no account.
- An account holds your e-mail address, a display name, an optional photo, your chat messages, favourites, follows, blocks, reports and your newsletter choice. Everyone can read the chat, with your display name and photo next to your messages.
- You can delete your account at any time, in the app or on the website.
- Questions? Write to hello@radio-bollwerk.ch.
1. Who we are
Responsible for the data described here is:
Radio Bollwerkc/o Shubhangi Kansal
Länggassstrasse 43
3012 Bern
Switzerland
hello@radio-bollwerk.ch
Write to that address about anything on this page. More about us is on our Info page.
We follow the Swiss Federal Act on Data Protection (FADP, revDSG). Where the EU General Data Protection Regulation (GDPR) applies to our processing of your data, we follow it too.
What this policy covers
- our website, www.radio-bollwerk.ch
- RBW, our iPhone app
- api.radio-bollwerk.ch, the server that supplies both with the programme, the archive, the chat and accounts, and sends our e-mails
- radio.radio-bollwerk.ch, our live and mood streams
- our newsletter, and Radio Bollwerk on Sonos speakers
Sites we only link to, such as Instagram, Facebook, Telegram, TuneIn, Mixcloud, Spotify, YouTube and our shop at shop.radio-bollwerk.ch, have their own privacy policies.
2. Listening and browsing
Whenever you open the website, play a stream or the app loads the programme, your device connects to a server. Each connection shows that server your IP address, usually your browser or device type, and the address you asked for. That is how the internet works; the servers need it to send you the page or the sound.
- The website runs on Vercel, whose servers in Frankfurt, Germany, build every page on request. Your login (your e-mail address and the login link), chat messages and profile changes on the website also pass through Vercel on their way to our server.
- Our server, api.radio-bollwerk.ch, runs at Hetzner in Falkenstein, Germany. The website and the app fetch the programme, the archive, the chat and all pictures from it.
- The streams come from radio.radio-bollwerk.ch, also at Hetzner in Falkenstein. For our listener statistics, our streaming software (AzuraCast, which we run ourselves) records each connection: your IP address, your player or browser, when you started and stopped listening, and the rough location it works out from your IP address. It deletes these records after 60 days.
- Archive episodes in the app play from our storage at Hetzner in Falkenstein, through a link that stops working after six hours.
- On a Sonos speaker, the speaker reports to our server what it played and for how long (playback and item numbers, the station, durations). These reports carry no account and no name, and we delete them after 180 days.
Our server writes a log of errors and important events. It can contain account numbers, Stripe numbers, the address of a newsletter mail that could not be sent, the addresses of hosts and guests whose infosheet mail failed, and error details. The web servers in front of our server and our streams may also keep standard access logs (IP address, time, address asked for, browser). How long logs stay is under How long we keep it.
3. Cookies and your browser
- auth:token
www.radio-bollwerk.ch - Only when you log in on the website. Holds your login token so you stay logged in. Lasts one year, and is removed when you log out or delete your account. Our page's own script reads it to talk to our server.
- radio_bollwerk_session, XSRF-TOKEN
api.radio-bollwerk.ch - Set when your browser loads pictures from our server, which every page of the website does. They come with the software our server is built on and expire after two hours. Logins don't use them, and we don't use them to follow you. For each such session our server records your IP address and browser type, and deletes that record soon after the two hours are up.
Our analytics set no cookies (see Analytics). The website stores nothing else in your browser, apart from a small service worker that keeps our icons and app manifest on your device, nothing about you. SoundCloud and RaiseNow may set their own cookies when their parts of the website load (see SoundCloud, RaiseNow and links).
The app keeps no cookies: it refuses the ones our picture server offers, and sends none. Because it sends none, our server starts a new short session for each picture the app downloads, with your IP address, the app's and iOS's version and which picture it asked for, and deletes it in the same way.
4. Analytics
The website counts visits with Plausible Analytics, which we run ourselves at analytics.radio-bollwerk.ch, on a Hetzner server in Nuremberg, Germany. Its script is part of our website; nothing loads from Plausible's own servers. It sets no cookies and stores nothing on your device.
It records the page you look at and the site you came from, how far you scroll and how long the page is in use, and, worked out from your IP address and browser, your country (and region or city where it can tell), browser, operating system and device type. It also records these events: playing the stream or switching moods, playing an archive episode (with its title and number), adding or removing a favourite, following or unfollowing a host (with the episode's or host's number), asking for a login link, logging in and out, sending a chat message, changing your display name or photo, deleting your account, and using the PRO pages (opening the checkout, the billing portal or the cost table, or the button on the PRO counter). Events never include your e-mail address or your account number. Your IP address and browser reach the analytics server with each request; Plausible is built to count unique visitors without storing them.
The app has no analytics.
5. SoundCloud, RaiseNow and links
SoundCloud
On the website, archive episodes play through SoundCloud's player, which loads only when you press play. Articles under Docs embed SoundCloud's player directly, so there it loads with the article. Once it has loaded, SoundCloud receives your IP address and browser details and may set cookies and track you under its own cookie policy and privacy policy.
In our archive player we switch off what we can: the player is sandboxed, hides the uploader, play counts, sharing and download buttons, and we remove tracking parameters from the track link. The players in Docs articles are SoundCloud's standard player, without these limits.
The app embeds nothing from SoundCloud. If an episode has no audio on our own server, the app opens its SoundCloud page outside the app.
RaiseNow
Our Support page shows a donation form from RaiseNow (donate.raisenow.io). It loads with the page, so RaiseNow receives your IP address and browser details. What you type into the form goes straight to RaiseNow, under RaiseNow's privacy policy; our website and our server never see it.
Everything else
Apart from SoundCloud and RaiseNow, the website loads everything from our own servers: no Google Fonts and no scripts from other companies. Docs articles can embed players from other sites (today only SoundCloud); they load with the article. Instagram, Facebook, Telegram, TuneIn, Mixcloud, Spotify, YouTube and our shop are plain links; nothing is sent to them until you click.
6. Your account
You need an account only to chat, keep favourites, follow hosts and use the newsletter switch in your profile. The same account works in the app and on the website.
Logging in
There are no passwords. You enter your e-mail address and we mail you a login link (on the website) or a link and a 6-digit code (in the app). They work for 15 minutes; the link works once, and the code stops working after 5 wrong tries. We keep them only as hashes (a scrambled form we can check against but can't read back), together with your address, and delete them once they have been expired for a day. Your account is created the first time you log in, not when you ask for a link (unless you're a guest on our booking calendar, see Hosts and guests).
Links for the website open www.radio-bollwerk.ch/auth/verify. Links for the app open a page on api.radio-bollwerk.ch that hands the link to the app; that page sets no cookies and stores nothing itself.
To stop abuse we count login requests per e-mail address (5 an hour) and per IP address (100 an hour). We also limit attempts to enter a code, per address and per IP address. These counters store your address and IP address only in hashed form and run out on their own.
When you log in, your browser or iPhone gets a login token. Our server keeps it as a hash with the time it was last used, and no IP address or device details. It is deleted when you log out, when you delete your account, or after 365 days without use. If our server can't be reached at the moment you log out, you're still logged out on your device, and the token runs out after 365 days without use.
What your account holds
- Your e-mail address, to log you in and, if you want it, for the newsletter. The chat never shows it. But a new account's display name starts as the part of your address before the "@" (for jane.doe@example.com that's "jane.doe"), and the chat shows your display name. Change it in your profile before you write if you'd rather not show it.
- Your display name and photo, if you add one. Both show next to your chat messages. Photos (JPG, PNG or WebP, up to 2 MB) are normally cropped to 200×200 pixels and kept on our server. A new photo replaces the old one; resized copies of the old one are deleted within about a month. The app removes location and camera details from the photo before it uploads it. The website uploads the file as you picked it, so remove location data from it first if you want to be sure.
- Your chat messages (see Chat, reports and blocks).
- Your favourite episodes and the hosts you follow.
- The people you block and the reports you send.
- Whether you get the newsletter.
- Links to the host profiles and shows you're part of, if you're one of our hosts or guests (see Hosts and guests).
- PRO billing details, if you ever become a PRO member (see PRO, donations and payments).
You don't have to give us anything to listen. An account needs an e-mail address; without one we can't log you in. Everything else in it is up to you.
What everyone can see
The chat is public: anyone can read it, in the app and on the website, without logging in. Every message comes with your display name, your photo, your account number and whether you're a moderator. Anyone can load your photo from our server.
7. Chat, reports and blocks
Messages
A message (up to 500 characters) is stored with your account and the time. If you use one of the chat's special commands, such as a song request or a dedication, we also store what you typed for it. Your messages stay in the chat with no set end date, until a moderator removes them or you delete your account.
Moderation
Moderators are members of the station team. They can remove any message and ban an account. A ban stores who was banned, by whom, why and until when, and removes all of that person's messages. The banned person sees the reason and, if there is one, the end date. Removed messages stay in the chat as "deleted", with name and photo but without the text, and are erased 30 days after removal; if one was reported, the report keeps its copy (see below). People make these decisions, not machines.
Reports
When you report a message, we store which message, who reported it, the reason (spam, abuse or other), your optional note, a copy of the message and its author's name at that moment. You can report a message once. The station team gets an e-mail with the report, which names you by display name and account number, never by e-mail address. The person you reported isn't told.
When you are logged out, or reporting through our server doesn't work, the app opens a prefilled e-mail to hello@radio-bollwerk.ch instead. That mail comes from your own mail account, so we see your address.
Blocks
You can block anyone who has written in the chat. A block hides their messages from you only; they aren't told. Logged in, your blocks are stored with your account. Logged out, the app keeps them on your iPhone (their account number and name), copies them to your account when you log in, and keeps them on the iPhone until you unblock.
8. Newsletter
You get our newsletter only if you ask for it: with the form on our website, or with the newsletter switch in your profile (app or website). It's our own news about the station, nobody else's advertising. We store your address, when you signed up and where (website form or profile).
There is no confirmation mail, so please only sign up with your own address. The website form sends your address to our server as part of the web address it calls.
We send the newsletter from our own server, without a newsletter service, tracking pixels or pictures from other servers. Every newsletter has an unsubscribe link, and you can switch it off in your profile. When you unsubscribe, we keep your address marked as unsubscribed. Write to us if you want it erased altogether; deleting your account erases it too.
9. Hosts and guests
Guests on our booking calendar
We plan shows in a private Google Calendar. If you're invited to a show there, our server imports your name and e-mail address from the calendar entry, together with the show's details (title, description, time and place). It creates an account for your address (named after you, or after the part of your address before the "@") and links it to the show, so you see it on your account page.
Once, no earlier than six weeks before your show, we mail you a link to our infosheet. What you fill in there (DJ name, nickname, pronoun, a message, your setup) goes to our team, and a notice with the link appears in our team's Slack. Our info page for hosts on api.radio-bollwerk.ch loads fonts from Google Fonts and a stylesheet from Cloudflare (cdnjs), so both see your IP address when you open it.
Our hosting and booking team
Our admin area keeps the name, nicknames, pronoun, phone number and e-mail address of the members of our hosting and booking team, entered by our team. We use them to match team members to the shows they host or book and to show them those bookings on their account page. Our team's planning pages on api.radio-bollwerk.ch load fonts from Bunny Fonts, which sees your IP address when you open them.
Deleting your account doesn't take you off the calendar: while you're listed there, the next import creates the account again. Write to us if you want to be taken off.
10. PRO, donations and payments
PRO membership
PRO, our paid membership, isn't on offer at the moment, and the app has no way to buy it. If we switch it on, this is what happens:
- Payment runs through Stripe. At your first checkout we create a Stripe customer with your display name and e-mail address.
- You enter your card details on Stripe's own checkout page and change or cancel the membership in Stripe's billing portal. We never see your full card number.
- We keep your Stripe customer number, the card type and last four digits if Stripe sends them, and your membership's status, plan, price, renewal or end date, and which of our PRO mails we've sent (welcome, a reminder a week before a yearly renewal, payment failed, cancelled).
- Our billing log records your account number, Stripe numbers and payment events.
- Deleting your account cancels the membership at once, without a refund for the rest of the period. The customer record at Stripe stays; write to us if you want it removed.
Donations and bank transfers
Donations on our Support page go through RaiseNow (see above). If you pay or donate by bank transfer, the statements from our bank, PostFinance, can show your name and payment note, and we import them into our books.
11. The RBW iPhone app
The app has no analytics, no advertising and no tracking, and no code from other companies. It asks for no permissions: to add a photo it uses Apple's photo picker, which hands over only the photo you choose. It connects only to our server, our streams and our audio storage at Hetzner.
On your iPhone
- Your login, in the iPhone's Keychain, on this iPhone only: it isn't synced to your other devices or restored onto another iPhone. If you delete the app and install it again, the app discards the old login. Your e-mail address and login are never written or logged anywhere else.
- The people you block while logged out (account number and name).
- Which version of the chat rules each account on this iPhone has agreed to.
- A note that the app has been installed, so it can tell a fresh install.
- A cache of pictures (covers, host photos, chat photos), up to 300 MB.
Log out to remove your login from the iPhone, and log out before you delete the app: deleting it removes its settings and its cache, but the iPhone's Keychain keeps the login until you install the app again, and our server keeps it valid until it has gone unused for 365 days. You get the app from Apple's App Store, under Apple's own privacy policy; the app itself sends nothing to Apple.
The app declares to Apple that it collects your e-mail address (to log you in, and for our own newsletter, which counts as marketing in Apple's terms), your name, your photo, your account number and what you write or save (chat messages, reports, favourites, follows, blocks). All of it is linked to your account, and none of it is used for tracking.
12. What our team sees
The station team works in an admin area on our server. Team members with access see accounts (name, e-mail address, photo, PRO status, favourites, follows, chat messages, bans and reports), newsletter subscribers, PRO memberships, infosheet answers and our team's contact records. The admin area logs the changes made in it, and that log is deleted after 180 days.
The admin area's list of accounts shows Gravatar pictures. To do so, the team member's browser sends Gravatar (Automattic) an MD5 hash of each listed e-mail address.
Mail to hello@radio-bollwerk.ch and the report mails arrive in the station's mailbox, which the team reads.
13. Who else gets data, and where
We don't sell data about you and don't share it with advertisers. These companies handle data for us, or receive it when you use their part of our services:
- Hetzner Online
Germany - Hosts our server (with its photos, pictures, logs and backups), the streams and our audio storage in Falkenstein, and our analytics in Nuremberg.
- Vercel
USA, pages built in Frankfurt, Germany - Hosts the website. Receives every website request, including login links, and passes logins, chat messages and profile changes on to our server.
- METANET
Zürich, Switzerland - Runs our mail domain: mail to @radio-bollwerk.ch addresses arrives there. Our server also sends login links and codes, newsletters, report mails, infosheet links and PRO mails through it.
- Laravel Forge
USA - The service we use to set up and update our server. It has administrative access to that server.
- SoundCloud
Germany and USA - Plays archive episodes on the website and the players in Docs articles (see above).
- RaiseNow
Switzerland - The donation form on our Support page.
- Stripe
Ireland and USA - PRO payments, once PRO is on offer: your display name, e-mail address and payment details.
- Google
Ireland and USA - Our private booking calendar (guests' names, e-mail addresses and bookings), the spreadsheets for our bills, and the fonts on our info page for hosts.
- Cloudflare
USA - A stylesheet on our info page for hosts.
- Bunny Fonts
Slovenia - The fonts on our team's planning pages.
- Slack
USA - Our team's messages: notices about new infosheets, backups and errors.
- Gravatar (Automattic)
USA - Pictures in our admin area (see What our team sees). Gravatar doesn't work for us, and we have no contract with it.
- PostFinance
Switzerland - Our bank.
- Apple
Ireland and USA - Distributes the app through the App Store.
Everyone who handles data on our behalf (hosting, mail, our admin tools and payments) is bound to protect it at least as well as this policy describes, and to use it only for the purposes here. SoundCloud, RaiseNow, Gravatar, Cloudflare, Bunny Fonts, Google Fonts, Apple and PostFinance decide themselves what they do with what they receive, under their own privacy policies.
Switzerland recognises Germany, Ireland, Slovenia and the rest of the EU as having adequate data protection; the USA only for companies certified under the Swiss-US Data Privacy Framework. Where a provider is in a country without adequate protection, we rely on its Data Privacy Framework certification or the standard contractual clauses in its terms, where available.
We disclose data to authorities only where the law requires it.
14. How long we keep it
- Login links and codes
- Valid for 15 minutes, deleted once they have been expired for a day.
- Login tokens
- Until you log out or delete your account, or after 365 days without use. Deleting the app doesn't log you out.
- Website login cookie
- One year, or until you log out.
- Cookies from api.radio-bollwerk.ch, and their sessions on our server
- Two hours; the session records are deleted soon after.
- Your account and what's in it
- Until you delete your account.
- Chat messages
- Until you delete your account. Messages a moderator removed: 30 days after removal; if the message was reported, the report keeps a copy of its text (see the next line).
- Reports and bans
- No set end date. Erased when the account that reported, was reported or was banned is deleted.
- Blocks
- Until you unblock, or either account is deleted.
- Newsletter address
- Until you ask us to erase it or delete your account; after you unsubscribe it stays marked as unsubscribed.
- Calendar guests' details and infosheet answers
- No set end date; ask us to remove them.
- Our team's contact records
- As long as you're on our team; ask us to remove them.
- Stream listener records
- 60 days.
- Analytics
- The statistics stay with no set end date. They hold no IP addresses and nothing that names you.
- Sonos play reports
- 180 days.
- Server logs
- 14 days; the PRO billing log, 90 days.
- Access logs of our web servers and streams
- At most 14 days.
- Vercel's request logs
- As long as Vercel keeps them under its terms; we don't copy them.
- Admin change log
- 180 days.
- Mail to hello@radio-bollwerk.ch
- In our mailbox until we delete it.
- Our books (bank statements and payments)
- 10 years, as Swiss law requires.
- Database backups
- Daily, of the database only (not photos or audio), kept with our server: every backup for 7 days, then one a day for 16 days, one a week for 8 weeks, one a month for 4 months and one a year for 2 years, unless older ones are removed earlier to save space. Data you delete can therefore remain in a backup for up to about two and a half years.
- On your iPhone
- Your login: until you log out. If you delete the app without logging out, the login stays in the iPhone's Keychain until you install the app again, and stays valid on our server until it has gone unused for 365 days, so log out first. Blocks: until you unblock or delete the app. The chat rules note and the picture cache: until you delete the app.
15. Why we may use it
Where the GDPR applies, these are our legal bases:
- Our legitimate interests (Art. 6(1)(f) GDPR) in running a radio station, its website, app and streams, keeping them safe and working, and knowing which parts get used: connections, logs, login counters, the image server's cookies, listener statistics, analytics, backups, SoundCloud's player (in our archive only once you press play, in Docs articles with the article) and RaiseNow's form on our Support page, moderation and reports, and planning shows with our team, hosts and guests.
- Providing the account you asked for (Art. 6(1)(b) GDPR): logging in, your profile, chat messages, favourites, follows and blocks, and a PRO membership.
- Your consent (Art. 6(1)(a) GDPR): the newsletter. You can withdraw it at any time with the unsubscribe link or in your profile.
- Legal obligations (Art. 6(1)(c) GDPR): keeping our books, including payments and bank statements, for 10 years.
Swiss law doesn't need a legal basis for each use, but we stick to the same purposes. We make no automated decisions about you; the only automatic limits are rate limits on logins and chat messages.
16. Deleting your account
You can delete your account at any time, with no need to write to us:
- In the app: Account → Info → Delete account.
- On the website: Account → Edit Profile → Delete Account.
Staff accounts can't delete themselves there; write to us. If you're a PRO member, the membership is cancelled first; if Stripe refuses that, nothing is deleted and you'll see an error.
What is erased at once
Your account and what's in it, from our database and our server's disk: your e-mail address, display name and photo (with every resized copy), all your chat messages (removed ones too), favourites, follows, blocks (yours, and other people's blocks of you), reports you made and reports about your messages, bans against you, your newsletter subscription, your links to hosts and shows, your PRO membership records, your login tokens and pending login links, sessions linked to your account, and the admin area's log entries about you. Bans you issued as a moderator stay, without your name.
What stays for a while
- Copies in our database backups, until they expire (see How long we keep it).
- Lines in our server logs (including a note of the deletion with your account number), until they expire.
- Report mails already in our mailbox.
- Your entries in our booking calendar, if you're a guest there; while you're listed, the next import creates the account again (see Hosts and guests). If you're on our hosting and booking team, your contact record in the admin area.
- The admin area's log of changes you made yourself as a team member, for its 180 days.
- The customer record at Stripe, if you ever had PRO.
- What the app stored on your iPhone (blocks made while logged out, the chat rules note, the picture cache), until you delete the app.
You can sign up again with the same address later; you'll start with an empty account.
17. Your rights
At any time, you can:
- ask what data we have about you, and get a copy of it in a common format;
- have it corrected (your display name, photo and newsletter choice you can change yourself in your profile);
- have it deleted, or its use stopped or limited;
- object to uses based on our legitimate interests;
- withdraw your consent to the newsletter.
Write to hello@radio-bollwerk.ch. We may ask you to show that the data is yours, for example by writing from the address of your account, and we answer within the 30 days the law gives us.
If you think we handle your data wrongly, tell us first if you can. You can also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch) or, where the GDPR applies, to the data protection authority in your EU country.
18. Children
Radio Bollwerk is for everyone who likes to listen, and listening needs no data from you. We don't ask anyone's age. If you're under 16, please ask a parent before you create an account or write in the chat. If you're a parent and want your child's account gone, delete it in the app or on the website, or write to us.
19. Changes to this policy
When what we do with data changes, we update this page and the date at the top. This version is from 5 October 2026.