Privacy policy
Information on data processing at PostMaestro.ai
PostMaestro.ai takes the protection of your personal data very seriously. This privacy policy informs you about the type, scope and purpose of the processing of personal data on our landing page, in our application and in our newsletter service.
Table of Contents
01 Person responsible
The controller within the meaning of the General Data Protection Regulation (GDPR) is
Nexaluna AI Solutions UG (limited liability)
Trading under: Nexaluna AI Solutions
Renkenweg 23
83209 Prien
Germany
Email:info@nexaluna.ai
Phone: +49 155 63429119
Website:www.nexaluna.ai
02 Data Protection Contact
We are not legally required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG). For all inquiries regarding data protection, the exercise of your rights, and AI transparency and labeling, please contact us at info@nexaluna.ai. We typically respond to inquiries within 30 days.
03 Scope of application
This privacy policy applies to
Landing page (postmaestro.ai): Information website about our services
Web application: Complete platform for registered users
Newsletter service: e-mail marketing and notifications
Data processing differs depending on the area. This is explained in detail below.
04 Data processing on the landing page
The following data is processed on our landing page (postmaestro.ai):
4.1 Technical data (log files)
- The following information is automatically collected when you visit our website:
- - IP address (anonymised after 7 days)
- - Date and time of access
- - Pages and files accessed
- - Amount of data transferred
- - Browser type and version
- - Operating system
- - Referrer URL (previously visited page)
Purpose: This data is collected exclusively for technical purposes (security, error analysis, system stability) and is not used to create user profiles.
Legal basis: Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in system security)
Storage period: Storage period: 7 days, then automatic anonymisation
4.2 Hosting and content delivery
- Our website is hosted on Amazon Web Services (AWS) and delivered via Amazon CloudFront (Content Delivery Network).
- Server location: EU (Frankfurt/Ireland)
- AWS processes technical data on our behalf and in accordance with our instructions.
- Further information: https://aws.amazon.com/de/privacy/
Legal basis: Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest), Art. 28 GDPR (order processing)
4.3 Cookies and local storage
- Our landing page uses cookies and local storage:
- - Session cookie: To save your language setting
- - Theme preference: To save your dark/light mode preference
- - Local Storage: Storage of language and country (no exact location)
- These cookies do not contain any personal data and are used exclusively for functionality.
Notice: Cookie Banner: A consent banner is active for optional analytics and marketing cookies. Optional cookies are set only after you have given your consent. You can give, change, or withdraw this consent at any time via the link in the footer.
Legal basis: Legal basis: For technically necessary cookies and local storage, Section 25(2)(2) of the TDDDG in conjunction with Article 6(1)(f) of the GDPR; for optional analytics and marketing cookies, Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR (consent).
4.4 Pre-release notifications
- If you register for notifications via the pre-release modal, we will save your data:
- - E-mail address
- - Timestamp of the application
- - Opt-in status
- Purpose: Information about the public launch of PostMaestro.ai
- After the launch notification has been sent, the data will be deleted unless you subscribe to the newsletter.
Legal basis: Legal basis: Art. 6 para. 1 lit. a GDPR (consent)
Storage period: Storage period: Until launch notification is sent, maximum 12 months
05 Data processing in the application
More extensive data is processed in the full PostMaestro.ai application (after registration):
5.1 Registration and account data
- When you register, we collect:
- • Email address (required)
- • Username (required)
- • Password (encrypted with bcrypt, at least 8 characters)
- • Account type (Personal or Company)
- • Date of registration
- • Two-factor authentication (2FA) — optional but recommended
- Purpose: Providing and managing your account, authentication, security
- The 2FA data is stored only locally on your device (QR code scan). We store only the activation status.
- Note: Alternatively, you can also register or log in via Google, Meta (Facebook), LinkedIn, TikTok, or X—see Section 5.1a for the data and permissions requested in each case.
- To protect against automated registrations (bots), we use Cloudflare Turnstile (see Section 10a.2).
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
Storage period: Storage period: Until account deletion
5.1a Registration & Sign-In via Third-Party Providers (Social Login)
- In addition to the standard registration with an email address and password, you can register or log in to PostMaestro.ai using the following third-party providers. These connections are used exclusively for account creation and login and are independent of the social media links used for publishing posts (see Section 5.5)—in each case, separate OAuth permissions (scopes) with significantly more limited access are requested:
- • Google (Scopes: openid, profile, email) — the following information is transmitted: Google ID, email address, first and last name, profile picture, and language
- • Meta / Facebook Login (Scopes: public_profile, email) — the following information is transmitted: Facebook ID, email address, first and last name, profile picture, and language
- • Instagram Business Login (Scope: instagram_business_basic) — the following information is transmitted: Instagram ID, username, display name, and profile picture (no email address—this is requested separately during onboarding)
- • LinkedIn (OpenID Connect, scopes: openid, profile, email) — the following information is transmitted: LinkedIn ID, email address, first and last name, profile picture, and language
- • TikTok Login Kit (Scopes: user.info.basic, user.info.profile) — TikTok Open ID, username, display name, and profile picture are transmitted (TikTok does not provide an email address; a placeholder address is used internally until one is entered during onboarding)
- • X / Twitter (OAuth 2.0 with PKCE, scopes: users.read, users.email, tweet.read) — the following information is transmitted: X ID, username, display name, profile picture, and — if provided to X — the verified email address
- These scopes allow only the retrieval of basic profile data for account creation. No posts are published, no messages are read, and no access to your contacts is granted.
- If an email address that is already registered signs up again through a different provider, we recognize the existing account based on the email address (regardless of case) and link the new provider ID retroactively (account linking) instead of creating a duplicate account.
- If enabled in your security settings, we will send an email notification each time you log in (including via social login), including the time, device, browser, and approximate location. Your location is determined based on your IP address using the third-party provider ipinfo.io (see Section 10a.1).
- Meta Account Deletion: For sign-ups via Meta (Facebook/Instagram), we provide the callback endpoints required by Meta for deauthorization and data deletion. If you remove the app in your Facebook account settings or request data deletion there, we automatically receive a corresponding request and provide the processing status via a status URL displayed by Meta.
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract for account creation), Art. 6(1)(f) of the GDPR (legitimate interest in detecting abuse through IP geolocation for login notifications)
Storage period: Retention period: as described in Section 5.1 (Registration Data) — until the account is deleted
5.2 Brand profiles and brand data
- When creating a brand profile, we save:
- - Brand name and description
- - Website URL (for Brand Analyser)
- - Uploaded brand guidelines and documents
- - Analysed brand data (colours, fonts, tone of voice)
- - Logo and visual assets
- - Target group definitions
- - Industry and category
- Purpose: Creation of market-compliant content, brand identity management
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
Storage period: Storage period: Until deletion of the brand profile or account deletion
5.3 Content data (posts, media, campaigns)
- When you use the content creation feature, we store:
- • Social media posts created and scheduled (text, captions, hashtags)
- • Uploaded and generated images, videos, and graphics
- • Campaign data and templates
- • Idea validation (swipe data in the Idea Generator)
- • Research Documents
- • Content Status (Draft, Review, Scheduled, Published)
- • Publication dates and platforms
- • Tagging and origin data for generated media (content class, tagging status, metadata status), as well as your confirmation of the editorial review of generated texts
- Purpose: Content management, planning, automation, archiving, and compliance with AI transparency requirements
- To the extent technically feasible, generated media files contain labeling information, metadata, or comparable technical indicators that indicate that the content is AI-generated or AI-assisted (see Section 8.2).
Important: Marketing Use Only with Consent: We use the content you create for our own marketing purposes only if you have actively consented to this in advance. The corresponding toggle in the account settings is disabled by default (opt-in). The legal basis in this case is Article 6(1)(a) of the GDPR. You may revoke your consent at any time with future effect; however, for technical reasons, we may not always be able to remove marketing materials that have already been produced and published. Without your consent, your content will not be used for marketing purposes (see Terms and Conditions, Section 7.2).
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
Storage period: Storage period: Until manual deletion or account deletion. Published posts remain on social media platforms.
5.4 Usage data and analytics
- We store data to improve the platform:
- - Login times and session duration
- - Features and functions used
- - Token consumption and billing data
- - Error reports and performance data
- - Feedback and support requests
- Purpose: Platform improvement, error analysis, support, billing
Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)
Storage period: Storage period: Until account deletion (usage data), billing data in accordance with the statutory retention obligation (10 years)
5.5 Social Media Platform Links (Publication)
- When you connect social media accounts for publishing (Instagram, Facebook, Threads, WhatsApp Business, LinkedIn, X, YouTube, TikTok, Wix, WordPress, your own website), each platform uses OAuth to request only the permissions (scopes) necessary for that purpose. These connections are independent of the social login used for account registration (see Section 5.1a). In this process, we store:
- • OAuth access and refresh tokens for each platform, stored in the database encrypted using AES-256-GCM (see Section 10)
- • Platform account, page, and channel IDs, as well as display name, profile picture, or logo
- • On LinkedIn, additionally: company pages you manage (ID, name, logo) for selecting the publication destination
- • On Facebook/Instagram/WhatsApp: automatically detected links between a Facebook Page, an Instagram Business account, and a WhatsApp Business account (linked accounts are "carried over" when establishing a connection)
- • Expiration time of the access token for automatic renewal (e.g., for X and Wix)
- • For WordPress or your own website: the login credentials you provided (application password or endpoint URL and secret) instead of an OAuth token
- This data is used exclusively to publish posts on the linked accounts on your behalf and to display related statistics (analytics) within PostMaestro.ai. Access to private messages or contacts occurs exclusively within the scope of the Community Manager feature you have enabled (Facebook Messenger, Instagram Direct, WhatsApp).
- You can disconnect any connection at any time in the settings. We also recommend revoking the app's permission directly on the respective platform (e.g., in your Meta account settings).
| Platform | Permissions (Scopes) | Purpose |
|---|---|---|
| Facebook Pages | pages_show_list, pages_read_engagement, pages_manage_posts, pages_messaging, business_management | List pages, publish posts, view engagement statistics, send Messenger messages (Community Manager) |
| Instagram Business | instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights, instagram_manage_messages (+ Facebook Page scopes) | Post updates, manage comments, view insights, reply to direct messages |
| Threads | threads_basic, threads_content_publish, threads_manage_insights | Post on Threads, view statistics |
| WhatsApp Business | whatsapp_business_management, whatsapp_business_messaging, business_management | Connect a WhatsApp Business account, send/receive messages (Community Manager) |
| LinkedIn (Community Management API) | r_basicprofile, w_member_social, w_member_social_feed, r_member_postAnalytics, r_member_profileAnalytics, r_1st_connections_size, rw_organization_admin, r_organization_social, r_organization_social_feed, w_organization_social, w_organization_social_feed, r_organization_followers | Posting via personal profile AND managed business pages, including statistics |
| X / Twitter | tweet.read, tweet.write, users.read, media.write, offline.access | Publish posts, including media; offline.access enables automatic token renewal |
| YouTube (Google) | youtube.upload, youtube.readonly, youtube.force-ssl | Upload videos, read channel data |
| TikTok | user.info.basic, user.info.profile, user.info.stats, video.list, video.upload, video.publish | Post videos, view profile and statistics data |
| Wix | App Permissions via the Wix App Installer (not the traditional scope model) | Publish Blog Posts on Your Wix Website |
| WordPress | Application password created by you (not OAuth) | Publishing Blog Posts on Your Self-Hosted WordPress Website |
| Own Website | The webhook URL and secret you configured (no OAuth) | Transfer Contributions to Your Own System |
Legal basis: Legal basis: Article 6(1)(b) of the GDPR (performance of a contract)
Storage period: Retention period: Until the connection is terminated or the account is deleted. Expired, non-renewable tokens are automatically invalidated.
5.6 Team and company account data
- For company accounts with multiple users, we also store data:
- - Team members and their roles
- - Authorisations and access control
- - Approval workflows and comments
- - Activity logs (audit log)
- Purpose: Team collaboration, access control, compliance
Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)
Storage period: Storage period: Until deletion of the company account
5.7 Push Notifications (Mobile App)
- If you use our mobile app and enable push notifications, we process:
- • Device token for sending notifications
- • Notification Preferences
- We use Firebase Cloud Messaging (Google) to send push notifications.
- You can turn off push notifications at any time in your device's settings.
Legal basis: Legal basis: Article 6(1)(a) of the GDPR (consent). The transfer of device tokens to Firebase Cloud Messaging (Google) is based on Article 28 of the GDPR (data processing by a processor); for transfers to the U.S., we rely on the Adequacy Decision regarding the EU-U.S. Data Privacy Framework (Google LLC is certified) and, in addition, on the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR.
Storage period: Retention period: Until notifications are disabled or the account is deleted
5.8 News, research and RSS feeds
- The platform offers a news function that uses AI-supported research (via Perplexity AI) as standard to provide relevant industry news. You can also add your own RSS feeds. In doing so, we process:
- - Search queries and topic preferences for AI-supported news searches
- - The URLs of the RSS feeds you have added
- - Your preferences and categorizations for these feeds
- - Read or saved articles
- The platform retrieves the content of the third-party feeds via our servers so that your IP address is not transmitted to the operators of the RSS feeds. When using the AI-supported news search, your search queries are transmitted to Perplexity AI (see section 7.3).
- Purpose: Providing personalized industry news, research and content inspiration
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)
Storage period: Storage period: Until the feed/preferences are removed by you or until the account is deleted
5.9 Persona, Avatar, and Voice Cloning Data
- If you use features for creating virtual personas, synthetic voices, avatars, or similar AI-based identity features, we process the data required for these purposes:
- • Uploaded photographs, portraits, and image files
- • Audio recordings, speech samples, and other speech data
- • technical characteristics derived from these recordings for voice synthesis or avatar creation
- • the persona, avatar, or synthetic voice models generated from them
- • Related project, usage, and status data, as well as proof of consent (date and time, version of the consent text, user account)
- Purpose: To provide, generate, manage, and use the persona or voice features you have requested within the platform.
- Before uploading photos or voice samples, we obtain your explicit consent and display the description of the purpose to you. Without this consent, these features cannot be used.
- You may only use material for which you hold all necessary rights and—where required—valid consent from the person depicted or whose voice is heard. Cloning the voice or image of third parties without their prior express consent is prohibited (see Terms and Conditions, Section 6.6).
- Instances of these functions are marked as synthetic content and clearly labeled. This labeling cannot be disabled for these content classes (see Sections 8.2 and 8.3).
- You can have reference images, language data, and the models generated from them deleted at any time. The deletion process includes source material, derived features, and models.
Legal basis: Legal basis: Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(a) of the GDPR (consent) for the photo, audio, and personal source data you have uploaded. If this data consists of biometric data used for unique identification, the processing is additionally based on Article 9(2)(a) of the GDPR (explicit consent).
Storage period: Retention period: Only for as long as required to use the respective feature—until you delete the data, revoke your consent, or delete your account, provided that no statutory retention requirements prevent this.
Withdrawal: Withdrawal of Consent: If the processing is based on your consent, you may withdraw it at any time with future effect. After you withdraw your consent, the corresponding Persona and Voice features will no longer be available, either in whole or in part.
07 AI-supported data processing and AI providers
PostMaestro.ai uses various AI providers to generate content. When you actively use the respective feature, your input and the content generated from it are transmitted to these providers. Section 8 explains the transparency and labeling requirements that apply to the generated content.
7.1 OpenAI (Text Generation)
- Provider: OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; Processing is carried out in part by OpenAI OpCo, LLC, 1455 Third Street, San Francisco, CA 94158, USA
- Usage: Generating text, captions, descriptions, and ideas using GPT models
- Submitted data: Your input text, prompts, and brand data (for context generation)
- Privacy: Access is provided via the API. OpenAI does not use API data to train its models.
- Location: United States. OpenAI is not certified under the EU-U.S. Data Privacy Framework; data is transferred based on the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
- For more information: https://openai.com/policies/privacy-policy
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.2 Google Gemini (Image Generation)
- Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Usage: Generating images with Google Gemini 2.5 Flash
- Submitted data: Your image prompts, brand data, style templates
- Privacy: Google processes data in accordance with the Google Cloud Privacy Policy
- Location: U.S./EU (depending on server region)
- For more information: https://policies.google.com/privacy
- Technical Note: Depending on availability, your request will be processed through one of two channels—Google AI Studio or Google Cloud Vertex AI (both operated by Google). If the web search option is enabled, Google may also use live web search to assist with image generation.
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
7.3 OpenRouter (AI Model Routing for Image Generation)
- Provider: OpenRouter, Inc., USA
- Usage: OpenRouter is used as an alternative routing layer for image generation and forwards your request to the configured AI model (currently Google Gemini image models). OpenRouter thus provides another way to access the same models that are also connected directly through Google (see Section 7.2).
- Data transmitted: Your image prompts, reference images when editing existing images (as image data), desired aspect ratio, and resolution
- Privacy: OpenRouter processes the request and forwards it to the underlying model provider; in addition, that provider's privacy policy applies.
- Location: United States
- For more information: https://openrouter.ai/privacy
Legal basis: Legal basis: Article 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.4 Mistral AI (OCR and Text Recognition)
- Provider: Mistral AI, 15 Rue des Halles, 75001 Paris, France
- Use: OCR (Optical Character Recognition) for reading text from images and documents
- Transmitted data: Uploaded images, scans, screenshots for text recognition
- Data protection: Mistral AI is EU-based and GDPR-compliant
- Location: EU (France)
- Further information: https://mistral.ai/terms/
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract), Art. 28 of the GDPR (data processing on behalf of a controller); processing within the EU
7.5 Perplexity AI (Research, News, and Text Generation)
- Provider: Perplexity AI, Inc., 115 Sansome Street, Suite 900, San Francisco, CA 94104, USA
- Uses: Internet research with real-time web search, fact-checking, providing industry news, and text generation
- Models: Various Perplexity models for context-based text generation and research
- Data transmitted: search queries, topics, context, text prompts
- Privacy: Perplexity processes requests to provide search results and content
- Location: United States. Perplexity AI is not certified under the EU-U.S. Data Privacy Framework; data is transferred based on the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
- For more information: https://www.perplexity.ai/hub/legal/privacy-notice
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.6 Anthropic (Text Generation)
- Provider: Anthropic PBC, 548 Market Street, PMB 42098, San Francisco, CA 94104, USA
- Usage: Generating text, analyses, and content ideas using Claude models
- Submitted data: Your input text, prompts, and brand data (for context generation)
- Privacy: The data is accessed via the API. Anthropic does not use API data to train its models.
- Location: United States. Anthropic is not certified under the EU-U.S. Data Privacy Framework; data transfers are made on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
- For more information: https://www.anthropic.com/legal/privacy
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.7 Fal.ai (Image Generation Models)
- Provider: fal – Features & Labels, Inc., 2261 Market Street, Suite 10467, San Francisco, CA 94114, USA
- Usage: Advanced image generation using various AI models (including FLUX)
- Data Sent: Image prompts, style parameters, reference images
- Privacy: fal.ai processes data for image generation
- Location: United States. fal.ai is not certified under the EU-U.S. Data Privacy Framework; data transfers are made on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
- Note on labeling: To the best of our knowledge, fal.ai does not include any provider-side watermarks. We therefore apply all labeling to the output of these models ourselves (metadata and content credentials; see Section 8.2).
- In addition to image generation, fal.ai is also used for automatic background removal (the “BiRefNet v2” and “Pixelcut” models, both hosted on the fal.ai platform), for example, in the automatic creation of product and 3D model preview images.
- For more information: https://fal.ai/legal/privacy-policy
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Article 28 of the GDPR (Data Processing Agreement) in conjunction with Article 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.8 Creatomate (Video and Thumbnail Creation)
- Provider: Creatomate BV, Netherlands
- Usage: Automatic creation of video thumbnails, social media graphics, slideshows
- Transmitted data: Your images, texts, design templates
- Data protection: Creatomate is EU-based and GDPR-compliant
- Location: EU (Netherlands)
- Further information: https://creatomate.com/privacy-policy
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
7.9 DeepL (Translation of Content)
- Provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany
- Use: Automatic translation of blog posts into other languages, as well as newsletter and system email texts
- Data Provided: The texts to be translated (e.g., post content) as well as the source and target languages
- Privacy Policy: DeepL is a German/European company; data processing takes place within the EU
- Location: EU (Germany)
- For more information: https://www.deepl.com/de/privacy
Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract), Art. 28 of the GDPR (data processing on behalf of a controller)
7.10 LangSmith / LangChain (AI Quality Assurance and Tracing)
- Provider: LangChain, Inc., USA
- Usage: If enabled on the server side, LangSmith logs the processes of our AI agents (e.g., multi-step content generation workflows) for quality assurance, error analysis, and performance monitoring.
- Data transmitted: prompts, intermediate steps, and responses from the relevant AI workflows—these may contain content and brand data
- Privacy Policy: Access to the LangSmith Project is restricted to authorized employees
- Location: United States (or EU endpoint, if configured)
- For more information: https://www.langchain.com/privacy-policy
Legal basis: Legal basis: Art. 6(1)(b) and (f) of the GDPR (performance of a contract for AI functions, legitimate interest in quality assurance); Transfers to third countries based on Art. 28 of the GDPR (data processing agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)
7.11 Tesseract.js (OCR for images and scans)
- Use: Open source OCR engine for text recognition in uploaded images, screenshots and scans
- Processing: Takes place locally in the browser or on our EU servers
- Transmitted data: Image files for text recognition
- Data protection: Tesseract is open source, no data transfer to third parties
- Location: Local processing / EU server
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
7.12 Document Processing (Office files, PDFs, etc.)
- We use various tools to process uploaded documents:
- - Officeparser: Reading Word (.docx), Excel (.xlsx), PowerPoint (.pptx) files
- - Mammoth: Conversion of Word documents
- - PDF-Parse: Extraction of text from PDF documents
- - XLSX: Processing Excel files
- - CSV-Parse: Reading CSV data
- - Cheerio: Web scraping for website analysis (Brand Analyser)
- Purpose: Analysing your brand guidelines, documents and websites for the Brand Analyzer
- Processing: Takes place on our EU servers (AWS)
- Data protection: All tools are open source or run on our own servers
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
7.13 Google APIs (YouTube and Gmail Integration)
- Usage: Integration with Google Services (YouTube for video posts, Gmail for email notifications)
- Transmitted data: OAuth tokens for authorisation, post data for YouTube
- Data protection: Google processes data in accordance with the Google Privacy Policy
- Location: USA/EU
- Further information: https://policies.google.com/privacy
- Status: In development for YouTube integration
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
7.14 Important Note on AI Processing
Your data will only be transmitted to the relevant providers when you are actively using the respective AI feature.
AI providers process your data solely for the purpose of providing the requested service (content generation, translation, text recognition, research).
Data processing agreements pursuant to Article 28 of the GDPR are in place with all AI providers; for providers from third countries, EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR are also in place (see Section 16).
We limit the transfer of personal data to AI providers to what is necessary for the respective function and do not transfer any contact information, payment information, or login credentials from your account. However, it is not possible to completely rule out the transfer of personal data: prompts, brand profiles, reference texts, and uploaded images and documents may contain personal data if you enter or upload such information.
Therefore, please do not enter any personal data of third parties, any special categories of personal data as defined in Article 9 of the GDPR, or any confidential information in prompts or uploads, unless this is necessary for the desired function or you have the necessary rights and consents.
For media content we produce, we use technical disclosure and labeling mechanisms such as metadata, content credentials, watermarks, and visible notices. Details and the allocation of responsibilities under Article 50 of the EU AI Act can be found in Section 8.
The models and providers used may change as the service evolves. We will reflect any significant changes in this Privacy Policy (see Section 20).
08 AI Transparency and Labeling (Art. 50 of the EU AI Act)
PostMaestro.ai is an AI system that generates synthetic content: text, images, videos, graphics, and—where available—synthetic voices. Such systems are subject to the transparency requirements set forth in Article 50 of Regulation (EU) 2024/1689 on Artificial Intelligence (“EU AI Act”). This section explains which obligations we, as the provider, must fulfill and which obligations apply to you, as the operator, when you publish generated content.
8.1 Disclosure of Interaction with an AI System
- In PostMaestro.ai, you interact directly with AI systems. All features that generate, evaluate, summarize, translate, or rephrase content are AI-powered and are labeled as such in the user interface.
- The notice is provided before the first interaction, is clear, understandable, and clearly distinguishable from the other user interface elements (Art. 50(1) of the EU AI Act).
- We provide this information in an accessible format and ensure it complies with recognized accessibility requirements (Art. 50(5) of the EU AI Act).
- AI responses and suggestions may be incomplete, outdated, or factually incorrect. They do not constitute legal, tax, medical, or financial advice.
8.2 Machine-Readable Markup for Generated Content
- Under Article 50(2) of the EU AI Act, content generated by AI systems that produce synthetic images, audio, video, or text must be labeled as artificially generated or manipulated in a machine-readable format. The labeling must be effective, interoperable, robust, and reliable.
- We implement this requirement using several complementary methods, since, given the current state of the art, no single method alone can achieve the required robustness:
- • Source metadata in the file: During export, we write XMP and IPTC metadata into the generated media files, specifically the IPTC field “Digital Source Type” with the value “trainedAlgorithmicMedia,” as well as information about the AI system used, the model version, and the time of generation.
- • Content Credentials (C2PA): For generated image and video files, we incorporate a cryptographically signed provenance statement compliant with the C2PA standard into the output pipeline.
- • Provider-side watermarks: If the respective model provider includes invisible watermarks, these are retained and not removed. For Google Gemini image models, this is the SynthID watermarking method.
- • Validation: After writing, we read the markup again and log a status for each file (pending, valid, missing, removed). If the embedding fails, we enforce visible labeling for sensitive content classes.
- The marker is set on the server side before a file is stored or delivered, so that it survives rendering, uploading, and downloading. Technically, it cannot be ruled out that third parties or target platforms may remove metadata during re-uploading, compression, or cropping. In this case, the visible mark remains your safeguard (see 8.3).
- Implementation Status and Deadline: The transparency requirements under Article 50 of the EU AI Act have been in effect since August 2, 2026. For AI systems that—like PostMaestro.ai—were already on the market prior to this date, the transition period extends until December 2, 2026. We will fully implement the procedures described above within this period and document the implementation status internally.
- A notice in this privacy policy alone does not satisfy the requirements of Article 50(2) of the EU AI Act. What is required is a machine-readable label on the file itself.
8.3 Your Responsibilities as an Operator Regarding Deepfakes
- If you publish content generated by PostMaestro.ai, you are considered an “operator” under the EU AI Act. In this case, the disclosure requirement under Article 50(4) of the EU AI Act applies to you, not to us.
- If you create or edit image, audio, or video content that bears a striking resemblance to real people, objects, places, institutions, or events (“deepfakes”), you must disclose upon publication that the content has been artificially generated or manipulated.
- According to the European Commission’s guidelines, this obligation applies regardless of whether there was any intent to mislead and even if no specific real person is depicted. It therefore generally applies to posts on social media.
- To assist you, we provide: a visible label as the default setting for sensitive content classes, a suggested warning message during export, and a note in the publishing workflow.
- The default setting is always “enabled.” Disabling this feature must be documented: We record the time, user account, workspace, and version of the confirmation text. For photorealistic depictions of people and synthetic voices, disabling this feature is not permitted.
- You may not remove, disable, circumvent, or interfere with the labeling and disclosure mechanisms we provide (see Section 6.4 of the Terms and Conditions).
- This requirement applies in addition to the disclosure requirements of the respective social media platform. You must determine for yourself whether a disclosure requirement applies in each individual case.
8.4 AI-Generated Text and Editorial Responsibility
- With regard to text, Article 50 of the EU AI Act is significantly more narrowly defined than for images, audio, and video. A disclosure obligation applies only if all three of the following conditions are met:
- 1. The text was generated or manipulated by AI.
- 2. The text will be published.
- 3. The purpose of the publication is to inform the public about matters of public interest—such as news, political or social commentary, and contributions to public debates.
- The labeling requirement does not apply if the content has been subject to human review or editorial oversight and a natural person or legal entity bears editorial responsibility for the publication.
- There is no general requirement to label every piece of AI-generated text. Anyone who uses AI as an assistive tool, reviews the texts editorially, and takes responsibility for them is generally not subject to any additional labeling requirement.
- PostMaestro.ai is designed precisely for this purpose: The generated texts are suggestions. Before scheduling or publishing, we require explicit confirmation that you have reviewed the text and assume editorial responsibility. We log this confirmation along with the time, user account, and text version so that the exception remains verifiable.
- The note in the application reads: “This text is a suggestion. Please review it before publication. By reviewing it, you assume editorial responsibility.”
- Without this review, you may not publish generated texts as editorially responsible content; the disclosure requirement under Article 50(4) of the EU AI Act may then apply.
8.5 No Emotion Recognition and No Biometric Categorization
- PostMaestro.ai does not use emotion recognition systems and does not infer emotions, emotional states, or intentions from biometric data.
- We do not engage in biometric categorization, facial recognition, biometric identification, or the identification of protected characteristics such as ethnic origin, political views, religion, union membership, health, or sexual orientation.
- Evaluation features such as Idea Validation, Brand Analyser, and performance analyses relate exclusively to content, brand, and reach data—not to individuals or biometric characteristics.
- The disclosure requirements under Article 50(3) of the EU AI Act for emotion recognition and biometric categorization systems therefore do not apply to us.
8.6 Prohibited Use: Intimate depictions without consent and depictions of child abuse
- Article 5 of the EU AI Act prohibits AI systems whose reasonably foreseeable output consists of non-consensual intimate images (NCII) or child sexual abuse material (CSAM). As a provider of a general-purpose image and video generation tool, we assess this risk of misuse as early as the design phase and implement technical safeguards.
- Protective measures implemented:
- • Input filters that block relevant prompts even before the image and video models are called
- • Output filters and the security settings of the model providers used
- • Blocking content that targets minors in a sexualized context or depicts intimate images of identifiable individuals
- • Disabling the Persona and Voice features without the data subject’s documented consent (see Section 5.9)
- • Logging of blocked requests for abuse detection, as well as the ability to suspend affected accounts
- Any use of the platform for these purposes is strictly prohibited and will result in the immediate suspension of the account and, if there is evidence of criminal activity, the involvement of the appropriate authorities.
- Report Abuse: You and third parties can report violations at any time by emailing info@nexaluna.ai with the subject line “Report AI Abuse.” We prioritize incoming reports and will confirm receipt.
- We document our risk assessment from the design phase, the filters used, and the handling of reports internally, and provide this documentation to the relevant authorities upon request.
8.7 Division of Roles: Providers and Operators
- The provider, as defined by the EU AI Act, is Nexaluna AI Solutions UG (limited liability) for the PostMaestro.ai AI system. We are subject to the provider obligations, in particular the machine-readable labeling of outputs pursuant to Article 50(2) and the disclosure of AI interaction pursuant to Article 50(1).
- You are considered an operator as soon as you use the platform under your own responsibility and publish content you have created. You are subject to the obligations of an operator, in particular the disclosure requirement under Article 50(4) regarding deepfakes and texts of public interest.
- The base models used are provided by third parties (see Section 7). These third parties are the providers of the respective AI models; we are the provider of the AI system built on top of them.
- We maintain an internal registry of all models in use, along with their respective role assignments, and update it whenever changes occur.
- To ensure AI competence in accordance with Article 4 of the EU AI Act, we train our employees on how to use the AI systems we employ and document the training sessions.
8.8 Oversight and Complaints
- As of July 29, 2026, the Federal Network Agency has been the competent market surveillance authority, central point of contact, and complaints office for the EU AI Act in Germany.
- Federal Network Agency, Tulpenfeld 4, 53113 Bonn, https://www.bundesnetzagentur.de
- You can file a complaint regarding AI transparency there at any time. We ask that you contact us in advance at info@nexaluna.ai so that we can address your concern immediately.
09 Payment processing (Stripe)
We use Stripe (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA) for payment processing.
The following data is transmitted to Stripe for payments:
- Name and e-mail address
- Payment data (credit card number, expiry date, CVV)
- Billing address (if specified)
- Amount and transaction data
We do not store any complete payment data (credit card numbers, CVV) ourselves. These are stored exclusively by Stripe.
We only receive from Stripe:
- Transaction ID
- Payment status (successful/failed)
- Last 4 digits of the payment method (for your overview)
- Stripe Customer ID (for recurring payments)
Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)
Third country: Stripe is EU-US Data Privacy Framework certified and offers EU servers.
Storage period: Storage period: transaction data 10 years (statutory retention obligation), payment methods until cancellation by you
10 Data storage and database
10.1 Strapi Backend System
- All your account data, content and settings are stored in our backend system:
- - Backend framework: Strapi CMS (Open Source)
- - Database: PostgreSQL
- - Hosting: AWS (EU region)
- - Encryption: SSL/TLS for data transmission, bcrypt for passwords
- Only authorised employees and systems have access.
10.2 AWS Hosting (EU)
- Our servers are hosted on Amazon Web Services (AWS) in the EU:
- - Server location: Frankfurt and/or Ireland (eu-central-1, eu-west-1)
- - S3 buckets: For static assets and media files
- - CloudFront: Content delivery network for fast delivery
- - RDS PostgreSQL: For database hosting
- AWS processes data on behalf of Art. 28 GDPR.
- Further information: https://aws.amazon.com/de/privacy/
Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)
Storage period: Storage period: See respective data types (account data until deletion, billing data 10 years, etc.)
11 Data security
We use comprehensive technical and organisational measures to protect your data:
- • SSL/TLS encryption for all data transfers (HTTPS)
- • Bcrypt encryption for passwords (with a salt)
- • Two-factor authentication (2FA) is available as an option
- • Regular security audits and penetration tests
- • Access control and authentication for all systems
- • Automatic backups (encrypted)
- • Firewalls and intrusion detection systems
- • Regular software updates and security patches
- • Role-Based Access Control (RBAC) for team accounts
- • Audit logs for security-related actions
- • AES-256-GCM encryption for stored social media access tokens (access/refresh tokens)
- • Signed, time-limited OAuth state parameters (HMAC-SHA256) and PKCE (S256) on X/Twitter to protect against CSRF and code interception attacks
- • Bot and spam protection during registration/login via Cloudflare Turnstile
Despite all security measures, absolute security cannot be guaranteed for data transmission via the Internet. Please also protect your access data yourself.
12 Support, Security, and Automation Services
For account security, fraud protection, support, and internal automation, we also use the following third-party providers:
12.1 ipinfo.io (IP geolocation for login security alerts)
- Provider: ipinfo.io / IPinfo LLC, USA
- Use: To determine the approximate location (country, continent, network provider) based on the IP address, in order to inform you in login security notifications about the location of a login attempt
- Data transmitted: Your IP address at the time of registration. Private/local IP addresses are filtered out in advance and are not transmitted
- Note: This prompt will only appear if you have enabled login notifications in your security settings.
- Location: United States
- For more information: https://ipinfo.io/privacy-policy
Legal basis: Legal basis: Art. 6(1)(f) of the GDPR (legitimate interest in account security)
12.2 Cloudflare Turnstile (Bot and Spam Protection)
- Provider: Cloudflare, Inc., USA
- Purpose: To protect registration and login from automated access (bots) using a non-intrusive CAPTCHA method
- Data transmitted: Interaction and browser signals for bot detection, as well as your IP address
- Privacy: Cloudflare is certified under the EU-U.S. Data Privacy Framework
- Location: U.S./EU
- For more information: https://www.cloudflare.com/privacypolicy/
Legal basis: Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in IT security and the prevention of misuse)
12.3 Linear (Feedback and Support Ticket System)
- Supplier: Linear Orbit, Inc., USA
- Usage: Internal processing of feedback, error messages ("Report a Problem"), and support requests as tickets
- Data submitted: Your email address, the feedback or problem description you provided, the affected page or feature, and any screenshots you may have attached
- Note: Comments and status updates from Linear will be sent to you via email for your information.
- Location: United States
- For more information: https://linear.app/privacy
Legal basis: Legal basis: Art. 6(1)(b), (f) of the GDPR (performance of a contract/support, legitimate interest in product improvement)
12.4 GitHub (Workflow Automation)
- Provider: GitHub, Inc. (Microsoft), USA
- Usage: Purely technical automation—when a blog post is published, a GitHub Actions workflow is triggered, which, among other things, initiates the sending of the corresponding newsletter notification
- Data transmitted: Post metadata (slug, language, internal document ID) — no personally identifiable user data
- Location: United States
- For more information: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement
Legal basis: Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in technical automation)
13 Your rights as a data subject
You have the following rights regarding your personal data:
11.1 Right to information (Art. 15 GDPR)
You can request information about the personal data stored by us at any time.
11.2 Right to rectification (Art. 16 GDPR)
You can request the correction of incorrect data or the completion of incomplete data.
11.3 Right to erasure (Art. 17 GDPR)
You can request the deletion of your personal data, provided that there are no statutory retention obligations.
11.4 Right to restriction (Art. 18 GDPR)
You can request the restriction of the processing of your data.
11.5 Right to data portability (Art. 20 GDPR)
You can receive your data in a structured, commonly used and machine-readable format and have it transmitted to another provider.
11.6 Right to object (Art. 21 GDPR)
You can object to the processing of your data if this is based on legitimate interest (Art. 6 para. 1 lit. f GDPR).
11.7 Withdrawal of consent (Art. 7 para. 3 GDPR)
If the processing is based on your consent, you can revoke it at any time. This does not affect the lawfulness of the processing carried out until the revocation.
11.8 Right to lodge a complaint (Art. 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.
Exercising your rights
To exercise your rights, please contact us at info@nexaluna.ai. We will process your request within 30 days.
14 Automated Decisions and Profiling
We do not make any decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (Art. 22(1) of the GDPR).
Evaluative AI features such as Idea Validation, Brand Analyser, Content Scoring, and performance forecasts generate only non-binding suggestions and assessments regarding content and brands. They do not evaluate individuals or trigger decisions regarding individuals.
Automated processes that have an immediate effect on your account relate exclusively to contract fulfillment and security: blocking paid actions when your token balance is depleted, automatic token reloading after you have previously enabled this feature, bot protection during registration and login, and the blocking of input by our abuse filters (see Section 8.6).
If an automated security or abuse check results in your account being restricted, you can request a manual review at any time, explain your position, and appeal the decision. To do so, please contact info@nexaluna.ai.
No credit scoring, in the sense of a creditworthiness check, takes place. Payment processing, including fraud prevention, is handled by Stripe (see Section 9) in accordance with its own procedures.
15 Overview: All third-party providers used (subprocessors)
The following table provides an overview of all third-party providers that process personal data on our behalf:
| Provider | Purpose | Location | Legal Basis |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, Server Infrastructure, Database (PostgreSQL) | EU (Frankfurt/Ireland) | Art. 28 of the GDPR (AVV) |
| Stripe | Payment Processing | U.S./EU | Art. 28 GDPR (AVV), EU-U.S. DPF |
| SendGrid (Twilio) | Email Distribution (Newsletter) | United States | Art. 28 GDPR (AVV), EU-U.S. DPF |
| OpenAI | Text Generation (GPT Models) | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| Perplexity AI | Research, Web Search, Text Generation | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| Google Gemini | Image Generation | U.S./EU | Art. 28 GDPR (AVV), EU-U.S. DPF |
| Mistral AI | OCR (Optical Character Recognition) | EU (France) | Art. 28 of the GDPR (AVV) |
| Fal.ai | Image Generation, Background Removal | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| Creatomate | Video Thumbnails, Visual Editing | EU (Netherlands) | Art. 28 of the GDPR (AVV) |
| Anthropic | Text Generation (Claude) | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| Firebase (Google) | Push Notifications (Mobile App) | U.S./EU | Art. 28 GDPR (AVV), EU-U.S. DPF |
| Tesseract.js | OCR for Images/Scans (Open Source) | Local Processing / EU | Art. 6(1)(b) of the GDPR |
| Google APIs | YouTube and Gmail Integration | U.S./EU | Art. 28 GDPR (AVV), EU-U.S. DPF |
| OpenRouter | AI Model Routing (Image Generation) | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| DeepL | Translation of Content | EU (Germany) | Art. 28 of the GDPR (AVV) |
| LangChain / LangSmith | AI Quality Assurance and Tracing | United States | Art. 6(1)(f) GDPR, Art. 28 GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) GDPR (Standard Contractual Clauses) |
| ipinfo.io | IP Geolocation for Login Security Notifications | United States | Art. 6(1)(f) of the GDPR, Art. 46(2)(c) of the GDPR (SCC) |
| Linear | Feedback and Support Ticket System | United States | Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses) |
| Cloudflare (Turnstile) | Bot/Spam Protection (CAPTCHA) | U.S./EU | Art. 28 GDPR (AVV), EU-U.S. DPF |
| GitHub (Microsoft) | Workflow Automation (Blog Post) | United States | Art. 6(1)(f) of the GDPR, EU-U.S. DPF (Microsoft) |
We have contracts in place with all data processors in accordance with Article 28 of the GDPR. For providers in third countries without an adequacy decision, we have additionally entered into the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR and documented a data transfer impact assessment (see Section 16). The full names and addresses of the AI providers can be found in Section 7. We keep this list up to date; please refer to the date at the beginning of this statement for the current status.
16 International data transfers
Some of our service providers are based in or have server locations in the United States or other third countries outside the EU/EEA. This applies in particular to OpenAI, Anthropic, Perplexity AI, fal.ai, OpenRouter, LangChain/LangSmith, Google/Firebase, Stripe, SendGrid (Twilio), Cloudflare, ipinfo.io, Linear, and GitHub.
These transfers take place regularly and systematically as part of our day-to-day operations. We therefore do not rely on exceptions for individual cases, but rather on appropriate safeguards:
• Data Processing Agreement pursuant to Article 28 of the GDPR with the respective provider
• EU Standard Contractual Clauses of the European Commission pursuant to Article 46(2)(c) of the GDPR, supplemented by additional technical and organizational safeguards (encryption, access control, data minimization)
• Adequacy decision pursuant to Article 45 of the GDPR, provided that the provider is certified under the EU-U.S. Data Privacy Framework. This is currently the case for Stripe, SendGrid (Twilio), Cloudflare, Google/Firebase, and Microsoft/GitHub.
To the best of our knowledge, OpenAI, Anthropic, Perplexity AI, fal.ai, OpenRouter, and LangChain are not certified under the EU-U.S. Data Privacy Framework. Transfers to these providers are therefore made on the basis of the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR.
For every transfer to a third country without an adequacy decision, we conduct a Transfer Impact Assessment and document it. We will provide you with the current status of the agreements and assessments upon request at info@nexaluna.ai.
We rely on Article 49(1)(b) of the GDPR exclusively in genuine individual cases where a transfer is necessary to fulfill a specific contract you have requested and is a one-time occurrence.
Despite these guarantees, it cannot be completely ruled out that authorities in third countries may demand access to transmitted data in accordance with their local laws. Therefore, do not include any third-party personal data or particularly sensitive information in prompts or uploads (see Section 7.14).
17 Data storage and deletion periods
We only store your data for as long as is necessary for the respective purposes:
- • Account data: Until the account is deleted
- • Content data: Until manually deleted or the account is deleted
- • Newsletter data: Until unsubscription or 24 months of inactivity
- • Accounting data: 10 years (statutory retention requirement pursuant to Section 147 of the German Fiscal Code (AO))
- • Support requests: 3 years after completion
- • Server log files: 7 days, followed by automatic anonymization (see Section 4.1)
- • Personal and voice data: Until you delete them or revoke your consent (see Section 5.9)
- • Records related to AI labeling (labeling status, test confirmations, documented deviations): 3 years from the date of creation, to comply with the record-keeping requirements under the EU AI Act
- • Pre-release notifications: Until launch or for a maximum of 12 months
Account deletion
You can delete your account at any time in the settings.
After an account is deleted, all personal data will be deleted within 30 days.
Exception: Billing data is retained for 10 years in accordance with statutory retention requirements.
Published social media posts remain on their respective platforms and must be deleted there separately.
For Meta connections (Facebook/Instagram), we also support Meta's automated data deletion callback: If you disconnect the app in your Facebook account settings, we automatically receive a deletion request and provide the processing status via a status URL provided by Meta.
19 Children and young people
PostMaestro.ai is not intended for persons under the age of 16.
Persons under the age of 16 may not use the platform.
If we become aware that a person under the age of 16 has created an account, we will delete it immediately.
If you suspect that a minor has created an account without parental consent, please contact us at info@nexaluna.ai.
20 Changes to this privacy policy
We reserve the right to amend this Privacy Policy as necessary to reflect changes in the legal landscape or changes to our services.
We will notify you of any significant changes via email or through a clear notice on the website.
This statement is Version 3.0, dated August 10, 2026. You can always find the most current version at postmaestro.ai/privacy.
This Privacy Policy is available in several languages. The translations are provided for your information only; in the event of any discrepancies, the German version shall prevail.
20.1 Revision History
- Version 3.0 (August 10, 2026): New Section 8 on AI transparency and labeling pursuant to Article 50 of the EU AI Act—disclosure of AI interaction, machine-readable labeling of generated content, operators’ deepfake obligations, AI-generated text and editorial responsibility, no emotion recognition, prohibited uses under Article 5 of the EU AI Act, division of roles between providers and operators, competent supervisory authority. New Section 5.9 on persona, avatar, and voice cloning data. New Section 14 on automated decision-making under Article 22 of the GDPR.
- Version 3.0 (Continued): Legal basis for transfers to third countries changed from Article 49(1)(b) of the GDPR to Article 28 of the GDPR in conjunction with Article 46(2)(c) of the GDPR (EU Standard Contractual Clauses) and corrected the information regarding OpenAI’s certification under the EU-U.S. Data Privacy Framework. The reference to consent implied by mere use has been removed. Marketing use of customer content has been changed to require explicit consent (opt-in). The legal basis for cookies has been supplemented with Section 25 of the TDDDG. Addresses for fal.ai and Perplexity AI have been added. Contradictory information regarding log files and the cookie banner has been resolved; the section “Data Protection Officer” has been renamed “Contact for Data Protection”; and the table of contents and section numbering have been completely revised.
- Version 2.0 (July 9, 2026): Addition of social login, platform-specific OAuth authorizations, OpenRouter, DeepL, and LangSmith, as well as support, security, and automation services (ipinfo.io, Cloudflare Turnstile, Linear, GitHub).
- Version 1.0 (March 15, 2026): Initial release.
21 Contact and questions about data protection
If you have any questions about data protection, exercising your rights or complaints, please contact:
E-mail: info@nexaluna.ai
Phone: +49 155 63429119
Post: Nexaluna AI Solutions UG (haftungsbeschränkt) (Nexaluna AI Solutions), Renkenweg 23, 83209 Prien, Germany
We will process your enquiry within 30 days.
Competent supervisory authority
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18, 91522 Ansbach
Phone: +49 (0)981 180093-0
E-mail: poststelle@lda.bayern.de
Website: https://www.lda.bayern.de/