Privacy policy

Your meeting stays on your computer.

Last updated 30 September 2026

The short version. SpotOn has no accounts, no database and no cookies. The names and spotlight state it works with are handled inside your Zoom client and stay on your own computer. Our server only serves the app, completes the install with Zoom, and keeps short technical logs that contain no participant names and no IP addresses. We count how the website and the app are used with anonymous, cookieless statistics that never include names or meeting content (section 5).

This policy explains what personal data SpotOn processes, why, on what legal basis, for how long, and what rights you have. It covers the website spoton.nvcrising.org and the Zoom App SpotOn – Spotlight Director.

1. Who is responsible

Global Rising GbR
Vaubanallee 2
79100 Freiburg, Germany
shahar@nvcrising.org

We have not appointed a data protection officer, because the law does not require one for us. Write to the address above with any privacy question.

2. Using SpotOn in a Zoom meeting

What SpotOn reads. When you open SpotOn in a meeting or webinar, it uses the Zoom Apps SDK inside your Zoom client to read:

Why. To show you who is on stage and let you spotlight, queue, lock and time speakers. SpotOn never receives, records or stores audio or video.

Where it is processed. On your computer, inside the Zoom client. This data is not sent to our server, and we cannot see it.

What SpotOn remembers, and for how long. SpotOn keeps a small amount of data in the Zoom client's local app storage on the host's own computer:

WhatContainsKept
SettingsYour SpotOn preferences, such as the default speaking timeUntil you delete them
ScenesThe layouts you save, with the display names of the people in themUntil you delete the scene
Queue and locksThe display names you queued or locked in a meeting, stored under that meeting's IDDeleted automatically 30 days after the last change

You can delete all of it at any time: in SpotOn, open Help (?) and choose Delete SpotOn data on this computer.

What other participants may see. Some features show information to others in the meeting. Zoom delivers it; it does not pass through our server:

Legal basis. Processing on your device runs the function you asked for (Art. 6(1)(b) GDPR). As the host, you decide how SpotOn is used in your meeting, and you are responsible for your participants' data in that meeting under the rules that apply to you.

3. Adding SpotOn to Zoom

When you add SpotOn, Zoom sends our server a one-time authorization code. The server exchanges it for an access token and uses that token once, to ask Zoom for a link that opens SpotOn in your Zoom client. The token is not stored: it is discarded when that request ends. We do not request your Zoom profile, we do not create an account for you, and we receive no other data from Zoom.

Legal basis: Art. 6(1)(b) GDPR (providing the app you asked to add).

4. Technical logs

To keep the service working and investigate faults, our server writes short technical log lines:

Our logs do not record IP addresses, OAuth codes or tokens. They are kept for 30 days and then deleted automatically. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in a secure, working service).

5. The website and usage statistics

This website sets no cookies and loads nothing from third parties: fonts, images and scripts are served from our own server. The demo meeting runs entirely in your browser with made-up participants. Requests to the site are logged as described in section 4.

Anonymous usage statistics. To learn which pages and features are used, so that we can improve them, the website and the app send usage events to PostHog, an analytics service. What is sent:

What is never sent: participant names or IDs, meeting IDs or topics, chat messages, scene names, audio or video. The statistics have no user accounts or profiles, and we do not combine them with other data.

No cookies, nothing stored on your device. The statistics run in PostHog's cookieless mode. To count visitors without storing an identifier on your device, PostHog forms a one-way hash of your IP address, your browser's user agent and a secret value that it replaces every day, so visits on different days cannot be linked. Events pass through our own server, which does not log them.

Do Not Track. If your browser sends a Do Not Track signal, the website and the app send no usage events at all.

Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in understanding how SpotOn and its website are used, in order to improve them). You can object at any time (Art. 21 GDPR): switch on Do Not Track, or write to us. Usage statistics are deleted after 12 months.

6. Support requests

If you email us, we use what you send (your address, your message and anything you attach, such as a copy of SpotOn's Log) to answer you and fix problems. Legal basis: Art. 6(1)(b) and (f) GDPR. We delete support emails 12 months after the request is resolved, or earlier on request.

7. Who else is involved

We do not sell personal data or use it for advertising. Participant names, meeting IDs and other meeting content are never shared with third parties or sent to analytics.

8. Retention at a glance

9. Your rights

Under the GDPR you have the right to access your data (Art. 15), to have it corrected (Art. 16) or erased (Art. 17), to restrict processing (Art. 18), to data portability (Art. 20), and to object to processing based on our legitimate interests (Art. 21). To exercise them, email shahar@nvcrising.org. Because meeting data stays on the host's computer, the quickest way to erase it is the Delete SpotOn data on this computer button described above.

You also have the right to complain to a data protection supervisory authority, for example the one where you live or the one responsible for us: the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg.

10. Removing SpotOn

You can remove SpotOn from your Zoom account at any time (see the user guide). We hold no data about you to delete, because we never stored any. Data kept on your computer can be deleted with the button in SpotOn's Help before you remove the app.

11. Security

All traffic uses HTTPS (TLS 1.2 or 1.3). The server runs in an isolated, sandboxed service with no database. The only secrets it holds are the app's own Zoom credentials, kept outside the code in a file only the system administrator can read.

12. Children

SpotOn is a tool for meeting hosts and is not directed at children under 16.

13. Changes

If we change how SpotOn handles data, we will update this page and its date. For significant changes we will also note them on the support page.