Skip to main content

Privacy policy

Information on data processing at PostMaestro.ai

Stand: September 23, 2026 (Version 3.2)

PostMaestro.ai takes the protection of your personal data very seriously. This privacy policy informs you about the type, scope and purpose of the processing of personal data on our landing page, in our application and in our newsletter service.

01 Person responsible

The controller within the meaning of the General Data Protection Regulation (GDPR) is

Nexaluna AI Solutions UG (limited liability)

Trading under: Nexaluna AI Solutions

Renkenweg 23

83209 Prien

Germany

Email:info@nexaluna.ai

Phone: +49 151 28858234

Website:www.nexaluna.ai

02 Data Protection Contact

We are not legally required to appoint a data protection officer (Art. 37 GDPR, § 38 BDSG). For all inquiries regarding data protection, the exercise of your rights, and AI transparency and labeling, please contact us at info@nexaluna.ai. We typically respond to inquiries within 30 days.

03 Scope of application

This privacy policy applies to

Landing page (postmaestro.ai): Information website about our services

Web application: Complete platform for registered users

Newsletter service: e-mail marketing and notifications

Data processing differs depending on the area. This is explained in detail below.

04 Data processing on the landing page

The following data is processed on our landing page (postmaestro.ai):

4.1 Technical data (log files)

  • The following information is automatically collected when you visit our website:
  • - IP address (anonymised after 7 days)
  • - Date and time of access
  • - Pages and files accessed
  • - Amount of data transferred
  • - Browser type and version
  • - Operating system
  • - Referrer URL (previously visited page)

Purpose: This data is collected exclusively for technical purposes (security, error analysis, system stability) and is not used to create user profiles.

Legal basis: Legal basis: Art. 6 para. 1 lit. f GDPR (legitimate interest in system security)

Storage period: Storage period: 7 days, then automatic anonymisation

4.2 Hosting and content delivery

  • Our website is hosted on Amazon Web Services (AWS) and delivered via Amazon CloudFront (Content Delivery Network).
  • The primary origin servers and storage resources are located in an EU region, currently primarily in Frankfurt (eu-central-1).
  • CloudFront is a global content delivery network. During content delivery, technical connection data—specifically IP addresses, requested URLs, timestamps, and HTTP headers—may be processed at edge locations, including those outside the EU or the EEA.
  • AWS processes this data on our behalf and in accordance with our instructions, based on the AWS Data Processing Addendum (AWS DPA). For transfers to third countries, the EU Standard Contractual Clauses incorporated into the AWS Terms of Service apply.

Legal basis: Legal basis: Article 6(1)(f) GDPR (legitimate interests), Article 28 GDPR (processing by a processor)

4.3 Cookies and local storage

  • Our landing page uses cookies and local storage:
  • - Session cookie: To save your language setting
  • - Theme preference: To save your dark/light mode preference
  • - Local Storage: Storage of language and country (no exact location)
  • These cookies do not contain any personal data and are used exclusively for functionality.

Notice: Cookie Banner: A consent banner is active for optional analytics and marketing cookies. Optional cookies are set only after you have given your consent. You can give, change, or withdraw this consent at any time via the link in the footer.

Legal basis: Legal basis: For technically necessary cookies and local storage, Section 25(2)(2) of the TDDDG in conjunction with Article 6(1)(f) of the GDPR; for optional analytics and marketing cookies, Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR (consent).

4.4 Newsletter Sign-Up via the Coming-Soon Window

  • You can subscribe to our newsletter via the "Coming Soon" window. Among other things, it will keep you informed about the public launch of PostMaestro.ai.
  • Your registration will not take effect until you click the link in our confirmation email (double opt-in).
  • Section 6 describes what data we process in this context, how we document your consent, how long we store the data, and how you can unsubscribe.

Legal basis: Legal basis: Art. 6(1)(a) GDPR (consent); details in Section 6.

Storage period: Retention period: as described in Section 6.

05 Data processing in the application

More extensive data is processed in the full PostMaestro.ai application (after registration):

5.1 Registration and account data

  • When you register, we collect:
  • • Email address (required)
  • • Username (required)
  • • Password (encrypted with bcrypt, at least 8 characters)
  • • Account type (Personal or Company)
  • • Date of registration
  • • Two-factor authentication (2FA) — optional but recommended
  • Purpose: Providing and managing your account, authentication, security
  • The 2FA data is stored only locally on your device (QR code scan). We store only the activation status.
  • Note: Alternatively, you can also register or log in via Google, Meta (Facebook), LinkedIn, TikTok, or X—see Section 5.1a for the data and permissions requested in each case.
  • To protect against automated registrations (bots), we use Cloudflare Turnstile (see Section 10a.2).

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Storage period: Storage period: Until account deletion

5.1a Registration & Sign-In via Third-Party Providers (Social Login)

  • In addition to the standard registration with an email address and password, you can register or log in to PostMaestro.ai using the following third-party providers. These connections are used exclusively for account creation and login and are independent of the social media links used for publishing posts (see Section 5.5)—in each case, separate OAuth permissions (scopes) with significantly more limited access are requested:
  • • Google (Scopes: openid, profile, email) — the following information is transmitted: Google ID, email address, first and last name, profile picture, and language
  • • Meta / Facebook Login (Scopes: public_profile, email) — the following information is transmitted: Facebook ID, email address, first and last name, profile picture, and language
  • • Instagram Business Login (Scope: instagram_business_basic) — the following information is transmitted: Instagram ID, username, display name, and profile picture (no email address—this is requested separately during onboarding)
  • • LinkedIn (OpenID Connect, scopes: openid, profile, email) — the following information is transmitted: LinkedIn ID, email address, first and last name, profile picture, and language
  • • TikTok Login Kit (Scopes: user.info.basic, user.info.profile) — TikTok Open ID, username, display name, and profile picture are transmitted (TikTok does not provide an email address; a placeholder address is used internally until one is entered during onboarding)
  • • X / Twitter (OAuth 2.0 with PKCE, scopes: users.read, users.email, tweet.read) — the following information is transmitted: X ID, username, display name, profile picture, and — if provided to X — the verified email address
  • These scopes allow only the retrieval of basic profile data for account creation. No posts are published, no messages are read, and no access to your contacts is granted.
  • If an email address that is already registered signs up again through a different provider, we recognize the existing account based on the email address (regardless of case) and link the new provider ID retroactively (account linking) instead of creating a duplicate account.
  • If enabled in your security settings, we will send an email notification each time you log in (including via social login), including the time, device, browser, and approximate location. Your location is determined based on your IP address using the third-party provider ipinfo.io (see Section 10a.1).
  • Meta Account Deletion: For sign-ups via Meta (Facebook/Instagram), we provide the callback endpoints required by Meta for deauthorization and data deletion. If you remove the app in your Facebook account settings or request data deletion there, we automatically receive a corresponding request and provide the processing status via a status URL displayed by Meta.

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract for account creation), Art. 6(1)(f) of the GDPR (legitimate interest in detecting abuse through IP geolocation for login notifications)

Storage period: Retention period: as described in Section 5.1 (Registration Data) — until the account is deleted

5.2 Brand profiles and brand data

  • When creating a brand profile, we save:
  • - Brand name and description
  • - Website URL (for Brand Analyser)
  • - Uploaded brand guidelines and documents
  • - Analysed brand data (colours, fonts, tone of voice)
  • - Logo and visual assets
  • - Target group definitions
  • - Industry and category
  • Purpose: Creation of market-compliant content, brand identity management

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Storage period: Storage period: Until deletion of the brand profile or account deletion

5.3 Content data (posts, media, campaigns)

  • When you use the content creation feature, we store:
  • • Social media posts created and scheduled (text, captions, hashtags)
  • • Uploaded and generated images, videos, and graphics
  • • Campaign data and templates
  • • Idea validation (swipe data in the Idea Generator)
  • • Research Documents
  • • Content Status (Draft, Review, Scheduled, Published)
  • • Publication dates and platforms
  • • Tagging and origin data for generated media (content class, tagging status, metadata status), as well as your confirmation of the editorial review of generated texts
  • Purpose: Content management, planning, automation, archiving, and compliance with AI transparency requirements
  • To the extent technically feasible, generated media files contain labeling information, metadata, or comparable technical indicators that indicate that the content is AI-generated or AI-assisted (see Section 8.2).

Important: Marketing use: The Provider may use posts and media uploaded by you or created or published through the Platform for its own advertising, showcases, presentations, case studies, and PR materials. The corresponding setting is enabled by default when an account or company is created. You can disable this setting at any time in the privacy settings with effect for the future. After deactivation, further use will cease within 30 days; marketing materials already produced or published cannot always be withdrawn retroactively for technical and organizational reasons. Names, contact details, or other personal data will not be used in marketing materials without a separate legal basis or explicit consent (see Terms and Conditions, Section 7.2).

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Storage period: Storage period: Until manual deletion or account deletion. Published posts remain on social media platforms.

5.4 Usage data and analytics

  • We store data to improve the platform:
  • - Login times and session duration
  • - Features and functions used
  • - Token consumption and billing data
  • - Error reports and performance data
  • - Feedback and support requests
  • Purpose: Platform improvement, error analysis, support, billing

Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)

Storage period: Storage period: Until account deletion (usage data), billing data in accordance with the statutory retention obligation (10 years)

5.5 Social Media Platform Links (Publication)

  • When you connect social media accounts for publishing (LinkedIn, Instagram, Facebook, Threads, WhatsApp Business, X, YouTube, TikTok, Wix, WordPress, your own website), each platform uses OAuth to request only the permissions (scopes) necessary for that purpose. These connections are independent of the social login used for account registration (see Section 5.1a).
  • OAuth access and refresh tokens are stored in the database, encrypted using AES-256-GCM for each platform (see Section 10). Expired, non-renewable tokens are automatically invalidated.
  • The following sections describe, for each platform, what data is processed, how it is used, and when it is deleted. Platform data is used exclusively for managing the respective customer’s associated online presence.
  • You can disconnect any connection at any time in the settings. We also recommend revoking the app's permission directly on the respective platform (e.g., in your LinkedIn or Meta account settings).

5.5.1 LinkedIn (Profile & Company Pages)

Data Processed

  • • Authorization tokens (OAuth access and refresh tokens), stored using AES-256-GCM encryption
  • • Profile IDs and organization IDs, as well as display name, profile picture, or logo
  • • Company pages you manage (ID, name, logo) for selecting the publication destination
  • • Only to the extent necessary for the features you actively use and to the extent that the respective LinkedIn endpoints provide this data: LinkedIn posts, comments, reactions, and aggregated analytics data

Permissions (Scopes): r_basicprofile, w_member_social, w_member_social_feed, r_member_postAnalytics, r_member_profileAnalytics, r_1st_connections_size, rw_organization_admin, r_organization_social, r_organization_social_feed, w_organization_social, w_organization_social_feed, r_organization_followers

Purpose limitation: We use LinkedIn data solely to provide the requested social-media management services for the connected LinkedIn account or LinkedIn Page, including creating, scheduling and publishing posts, displaying and responding to comments, and providing analytics.

Not used for: We do not sell LinkedIn data, use it for advertising, sales, profiling, or enrichment purposes, or share one customer's LinkedIn data with other customers.

Deletion and withdrawal: LinkedIn credentials and retrieved LinkedIn data are deleted when you disconnect the integration or delete your account, unless statutory retention obligations apply. We will also delete relevant data where required by LinkedIn. We comply with LinkedIn's privacy, security, trust, and storage requirements.

5.5.2 Facebook Pages

Data Processed

  • • Authorization tokens, page IDs, display name, and logo
  • • Automatically detected links between Facebook Pages, Instagram Business accounts, and WhatsApp Business accounts (linked accounts are "carried over" when establishing a connection)
  • • Only to the extent necessary for the actively used features: posts, comments, engagement statistics
  • • Private messages are only available through the Community Manager feature you have enabled (Facebook Messenger)

Permissions (Scopes): pages_show_list, pages_read_engagement, pages_manage_posts, pages_messaging, business_management

Purpose limitation: Facebook data is used exclusively to manage the respective customer’s linked Facebook page, specifically to list pages, create, schedule, and publish posts, view engagement statistics, and—if enabled—respond to Messenger messages.

Not used for: We do not sell Facebook data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer's Facebook data with other customers.

Deletion and withdrawal: Facebook login credentials and Facebook data that has been retrieved will be deleted when you disconnect, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.

5.5.3 Instagram Business

Data Processed

  • • Authorization token, Instagram Business Account ID, display name, and profile picture
  • • Only to the extent necessary for the actively used features: posts, comments, insights
  • • Direct messages are only available if you have enabled the Community Manager feature (Instagram Direct)

Permissions (Scopes): instagram_basic, instagram_content_publish, instagram_manage_comments, instagram_manage_insights, instagram_manage_messages (+ Facebook Page scopes)

Purpose limitation: Instagram data is used exclusively to manage the respective customer’s linked Instagram Business account, specifically to create, schedule, and publish posts; manage comments; retrieve Insights; and—if enabled—respond to direct messages.

Not used for: We do not sell Instagram data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s Instagram data with other customers.

Deletion and withdrawal: Instagram login credentials and retrieved Instagram data will be deleted when you disconnect, delete your account, or Meta requests us to do so, subject to any mandatory legal retention requirements.

5.5.4 Threads

Data Processed

  • • Authorization token, Threads account ID, display name, and profile picture
  • • Only to the extent necessary for actively used features: Threads posts and aggregated statistics

Permissions (Scopes): threads_basic, threads_content_publish, threads_manage_insights

Purpose limitation: Threads data is used exclusively to manage the respective customer's Threads account, specifically to create, schedule, and publish posts, as well as to retrieve statistics.

Not used for: We do not sell Threads data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer's Threads data with other customers.

Deletion and withdrawal: Threads login credentials and retrieved Threads data will be deleted when you log out, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.

5.5.5 WhatsApp Business

Data Processed

  • • Authorization token, WhatsApp Business account ID, and display name
  • • Message content is limited to the scope of the Community Manager feature you have enabled (sending and receiving WhatsApp messages)

Permissions (Scopes): whatsapp_business_management, whatsapp_business_messaging, business_management

Purpose limitation: WhatsApp data is used exclusively to link the associated WhatsApp Business account and—if enabled—to manage customer conversations in Community Manager.

Not used for: We do not sell WhatsApp data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s WhatsApp data with other customers.

Deletion and withdrawal: WhatsApp login credentials and retrieved WhatsApp data will be deleted when you disconnect, delete your account, or Meta requests that we do so, subject to any mandatory legal retention requirements.

5.5.6 X / Twitter

Data Processed

  • • Authorization token, including expiration time for automatic renewal (offline.access)
  • • Account ID, display name, and profile picture
  • • Only to the extent necessary for the actively used features: Posts, including media

Permissions (Scopes): tweet.read, tweet.write, users.read, media.write, offline.access

Purpose limitation: X data is used exclusively to manage the respective customer's associated X presence, in particular to create, schedule, and publish posts, including media.

Not used for: We do not sell X data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s X data with other customers.

Deletion and withdrawal: X login credentials and X data you have accessed will be deleted when you log out, delete your account, or when X requests that we do so, subject to any mandatory legal retention requirements.

5.5.7 YouTube (Google)

Data Processed

  • • Authorization token, channel ID, display name, and channel image
  • • Only to the extent necessary for the actively used features: uploaded videos and associated channel data

Permissions (Scopes): youtube.upload, youtube.readonly, youtube.force-ssl

Purpose limitation: YouTube data is used exclusively to manage the respective customer's linked YouTube channel, in particular to upload videos and to read the channel data required for that purpose.

Not used for: We do not sell YouTube data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s YouTube data with other customers.

Deletion and withdrawal: YouTube login credentials and YouTube data you have accessed will be deleted when you log out, delete your account, or when Google requests that we do so, subject to any mandatory legal retention requirements.

5.5.8 TikTok

Data Processed

  • • Authorization token, TikTok account ID, display name, and profile picture
  • • Only to the extent necessary for the actively used features: videos, as well as profile and statistics data

Permissions (Scopes): user.info.basic, user.info.profile, user.info.stats, video.list, video.upload, video.publish

Purpose limitation: TikTok data is used exclusively to manage the respective customer's associated TikTok account, specifically to publish videos and view profile and statistics data.

Not used for: We do not sell TikTok data, use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s TikTok data with other customers.

Deletion and withdrawal: TikTok login credentials and retrieved TikTok data will be deleted when you log out, delete your account, or TikTok requests that we do so, subject to any mandatory legal retention requirements.

5.5.9 Wix

Data Processed

  • • Authorization data via the Wix App Installer, including the expiration date for automatic renewal
  • • Website/blog identifiers, to the extent necessary for publication

Permissions (Scopes): App Permissions via the Wix App Installer (not the traditional scope model)

Purpose limitation: Wix data is used exclusively for publishing blog posts on the respective customer's affiliated Wix website.

Not used for: We do not sell Wix data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s Wix data with other customers.

Deletion and withdrawal: Wix login credentials and retrieved Wix data will be deleted when you disconnect or delete your account, subject to any mandatory legal retention requirements.

5.5.10 WordPress

Data Processed

  • • An application password you provided instead of an OAuth token
  • • Website URL and, if necessary, username for publication

Permissions (Scopes): Application password created by you (not OAuth)

Purpose limitation: WordPress login credentials are used exclusively for publishing blog posts on your self-hosted WordPress website.

Not used for: We do not sell WordPress data, do not use it for advertising, sales, profiling, or data enrichment, and do not share a customer’s WordPress data with other customers.

Deletion and withdrawal: WordPress login credentials are deleted when you log out or delete your account, subject to any mandatory legal retention requirements.

5.5.11 Own website

Data Processed

  • • The webhook URL and secret you configured, instead of an OAuth token

Permissions (Scopes): The webhook URL and secret you configured (no OAuth)

Purpose limitation: The stored endpoint data is used exclusively to transfer data to your own system on your behalf.

Not used for: We do not sell this endpoint data, use it for advertising, sales, profiling, or data enrichment, or share it with other customers.

Deletion and withdrawal: The webhook URL and secret will be deleted when you disconnect or delete your account, subject to any mandatory legal retention requirements.

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract)

Storage period: Retention period: Until the connection is terminated or the account is deleted. Expired, non-renewable tokens are automatically invalidated. Platform data is also deleted if the respective platform requests that we do so, subject to mandatory legal retention requirements.

5.6 Team and company account data

  • For company accounts with multiple users, we also store data:
  • - Team members and their roles
  • - Authorisations and access control
  • - Approval workflows and comments
  • - Activity logs (audit log)
  • Purpose: Team collaboration, access control, compliance

Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)

Storage period: Storage period: Until deletion of the company account

5.7 Notifications (in the app, push notifications, and email)

  • PostMaestro.ai notifies you about events in your account, such as comments and mentions, completed generations, publications, team invitations, billing, security, and maintenance. To do this, we process:
  • • Notifications in your inbox (bell icon), including "read" and "hide" statuses
  • • Your notification settings by channel, category, section, and team group
  • • For push notifications (mobile app and browser): device token, a random device ID, device name, platform, app version, and the time of last use
  • • Whether the app is currently open on a device (visibility signal, valid for 90 seconds), so that you don't receive an additional push notification on the device you're currently using
  • We send push notifications via Firebase Cloud Messaging (Google) and email notifications via SendGrid (see Section 6.3).
  • You can turn optional notifications on or off for each channel under Settings → Notifications; you can also configure push notifications in your device's or browser's settings.
  • We will send notifications required for the use of your account (e.g., payment issues, two-factor authentication requirements, maintenance, changes to the Terms of Service) via the app and email, regardless of these settings. Login notifications are excluded from this and are optional (see Section 12.1). In exceptional cases—such as during maintenance or for security-related notifications—we may also display announcements in the app and via push notifications regardless of your category settings; such notifications are marked as “Important.”
  • You will only receive promotional emails (e.g., about new features) if you have subscribed to the newsletter (Section 6).

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract) for notifications regarding your account; Section 25(2)(2) of the German Telemedia Act (TDDDG) in conjunction with Art. 6(1)(f) of the GDPR for the device ID and visibility signal; Article 6(1)(a) of the GDPR (consent via your device’s or browser’s push notification permission) for push notifications. The transmission of device tokens to Firebase Cloud Messaging (Google) is based on Article 28 of the GDPR; For transfers to the United States, we rely on the Adequacy Decision regarding the EU-U.S. Data Privacy Framework (Google LLC is certified) and, in addition, on the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR.

Storage period: Retention period: Read notifications for 30 days, unread notifications for 90 days, unless you delete them sooner; settings until the account is deleted; Device tokens are deactivated after 60 days of inactivity and deleted 30 days later, or immediately upon logging out of the device.

5.8 News, research and RSS feeds

  • The platform offers a news function that uses AI-supported research (via Perplexity AI) as standard to provide relevant industry news. You can also add your own RSS feeds. In doing so, we process:
  • - Search queries and topic preferences for AI-supported news searches
  • - The URLs of the RSS feeds you have added
  • - Your preferences and categorizations for these feeds
  • - Read or saved articles
  • The platform retrieves the content of the third-party feeds via our servers so that your IP address is not transmitted to the operators of the RSS feeds. When using the AI-supported news search, your search queries are transmitted to Perplexity AI (see section 7.3).
  • Purpose: Providing personalized industry news, research and content inspiration

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfillment of contract)

Storage period: Storage period: Until the feed/preferences are removed by you or until the account is deleted

5.9 Persona, Avatar, and Voice Cloning Data

  • If you use features for creating virtual personas, synthetic voices, avatars, or similar AI-based identity features, we process the data required for these purposes:
  • • Uploaded photographs, portraits, and image files
  • • Audio recordings, speech samples, and other speech data
  • • technical characteristics derived from these recordings for voice synthesis or avatar creation
  • • the persona, avatar, or synthetic voice models generated from them
  • • Related project, usage, and status data, as well as proof of consent (date and time, version of the consent text, user account)
  • Purpose: To provide, generate, manage, and use the persona or voice features you have requested within the platform.
  • Before uploading photos or voice samples, we obtain your explicit consent and display the description of the purpose to you. Without this consent, these features cannot be used.
  • You may only use material for which you hold all necessary rights and—where required—valid consent from the person depicted or whose voice is heard. Cloning the voice or image of third parties without their prior express consent is prohibited (see Terms and Conditions, Section 6.6).
  • Instances of these functions are marked as synthetic content and clearly labeled. This labeling cannot be disabled for these content classes (see Sections 8.2 and 8.3).
  • You can have reference images, language data, and the models generated from them deleted at any time. The deletion process includes source material, derived features, and models.

Legal basis: Legal basis: Article 6(1)(b) of the GDPR (performance of a contract) and Article 6(1)(a) of the GDPR (consent) for the photo, audio, and personal source data you have uploaded. If this data consists of biometric data used for unique identification, the processing is additionally based on Article 9(2)(a) of the GDPR (explicit consent).

Storage period: Retention period: Only for as long as required to use the respective feature—until you delete the data, revoke your consent, or delete your account, provided that no statutory retention requirements prevent this.

Withdrawal: Withdrawal of Consent: If the processing is based on your consent, you may withdraw it at any time with future effect. After you withdraw your consent, the corresponding Persona and Voice features will no longer be available, either in whole or in part.

06 Newsletter Service

  • When you subscribe to our newsletter—via a form on this website (footer or “Coming Soon” window) or when registering in the app—we process:
  • • Email address and language
  • • Source of the registration (e.g., website form, registration)
  • • Time of registration and confirmation
  • • IP address and browser identifier (user agent) at the time of registration and confirmation
  • • Version of the consent text displayed and this privacy policy
  • • For registered users: the link to your account, as well as—for targeted advertising—language, country, and subscribed plan
  • Purpose: To send updates, tips, news, and promotional information about PostMaestro.ai, including the announcement of the public launch. This also includes emails about new posts on our blog and in our news section, as well as emails about new features.
  • We automatically translate newsletter texts using DeepL (Section 7.9); no recipient data is transmitted in the process.

6.1 Double opt-in procedure

After signing up via the website, you will receive an email with a confirmation link. We will add you to the mailing list only after you click on that link. We delete unconfirmed sign-ups after 30 days; we do not send a reminder.

When you register in the app, you confirm your subscription by clicking the link in the confirmation email sent to your account, where we specifically mention this step.

This prevents unauthorized registration of third-party email addresses.

6.2 Proof of Your Consent

To be able to prove that you have given your consent (Art. 7(1) GDPR), we log sign-ups, confirmations, and unsubscriptions, including the time, source, IP address, browser identifier, and the version of the consent text displayed.

We retain this log for 3 years after you unsubscribe and then delete it automatically.

6.3 SendGrid (Email Delivery)

We use SendGrid (Twilio Inc., USA) to send the newsletter as well as service and notification emails.

SendGrid processes your email address and the contents of the email on our behalf and reports technical delivery events to us (delivered, undeliverable, reported as spam, unsubscribed). We use these events to keep the mailing list up to date: Undeliverable addresses and spam reports result in the address being blocked.

We have entered into a Data Processing Agreement (DPA) with SendGrid in accordance with Article 28 of the GDPR. SendGrid is certified under the EU-U.S. Data Privacy Framework.

Further information: https://www.twilio.com/legal/privacy

Twilio (SendGrid) Privacy Policy

6.4 Newsletter Tracking

We currently do not track either opens or clicks.

Before we implement such statistics, we will inform you in advance and—where necessary—obtain your consent.

6.5 Unsubscribe

You can unsubscribe from the newsletter at any time:

• via the unsubscribe link in each email or the unsubscribe feature in your email program

• Using the form at the bottom of this section: Enter your email address, and we’ll send you a link to confirm your unsubscription

• In your PostMaestro account under Settings → Notifications

• via email to support@postmaestro.ai

After unsubscribing, you will no longer receive newsletters. Your email address will then no longer be on the mailing list; only the record specified in Section 6.2 will be retained.

Unsubscribe from the newsletter

Legal basis: Legal basis: Art. 6(1)(a) GDPR (consent); for proof of consent, Art. 6(1)(c) and (f) GDPR in conjunction with Art. 7(1) GDPR; for the processing of delivery events, Art. 6(1)(f) GDPR (legitimate interest in a functioning, abuse-free mailing system).

Storage period: Retention period: Until you unsubscribe; unconfirmed sign-ups for 30 days; proof of consent for 3 years after unsubscribing. We store blocked addresses (undeliverable, reported as spam, or deleted upon request) only as an irreversible hash value so that they are not contacted again.

07 AI-supported data processing and AI providers

PostMaestro.ai uses various AI providers to generate content. When you actively use the respective feature, your input and the content generated from it are transmitted to these providers. Section 8 explains the transparency and labeling requirements that apply to the generated content.

7.1 OpenAI (Text Generation)

  • Provider: OpenAI Ireland Limited, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland; Processing is carried out in part by OpenAI OpCo, LLC, 1455 Third Street, San Francisco, CA 94158, USA
  • Usage: Generating text, captions, descriptions, and ideas using GPT models
  • Submitted data: Your input text, prompts, and brand data (for context generation)
  • Privacy: Access is provided via the API. OpenAI does not use API data to train its models.
  • Location: United States. OpenAI is not certified under the EU-U.S. Data Privacy Framework; data is transferred based on the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
  • For more information: https://openai.com/policies/privacy-policy

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

OpenAI Privacy Policy

7.2 Google Gemini (Image Generation)

  • Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • Usage: Generating images with Google Gemini 2.5 Flash
  • Submitted data: Your image prompts, brand data, style templates
  • Privacy: Google processes data in accordance with the Google Cloud Privacy Policy
  • Location: U.S./EU (depending on server region)
  • For more information: https://policies.google.com/privacy
  • Technical Note: Depending on availability, your request will be processed through one of two channels—Google AI Studio or Google Cloud Vertex AI (both operated by Google). If the web search option is enabled, Google may also use live web search to assist with image generation.

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Privacy policy of Google

7.3 OpenRouter (AI Model Routing for Image Generation)

  • Provider: OpenRouter, Inc., USA
  • Usage: OpenRouter is used as an alternative routing layer for image generation and forwards your request to the configured AI model (currently Google Gemini image models). OpenRouter thus provides another way to access the same models that are also connected directly through Google (see Section 7.2).
  • Data transmitted: Your image prompts, reference images when editing existing images (as image data), desired aspect ratio, and resolution
  • Privacy: OpenRouter processes the request and forwards it to the underlying model provider; in addition, that provider's privacy policy applies.
  • Location: United States
  • For more information: https://openrouter.ai/privacy

Legal basis: Legal basis: Article 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

OpenRouter Privacy Policy

7.4 Mistral AI (OCR and Text Recognition)

  • Provider: Mistral AI, 15 Rue des Halles, 75001 Paris, France
  • Use: OCR (Optical Character Recognition) for reading text from images and documents
  • Transmitted data: Uploaded images, scans, screenshots for text recognition
  • Data protection: Mistral AI is EU-based and GDPR-compliant
  • Location: EU (France)
  • Further information: https://mistral.ai/terms/

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract), Art. 28 of the GDPR (data processing on behalf of a controller); processing within the EU

Privacy policy of Mistral AI

7.5 Perplexity AI (Research, News, and Text Generation)

  • Provider: Perplexity AI, Inc., 115 Sansome Street, Suite 900, San Francisco, CA 94104, USA
  • Uses: Internet research with real-time web search, fact-checking, providing industry news, and text generation
  • Models: Various Perplexity models for context-based text generation and research
  • Data transmitted: search queries, topics, context, text prompts
  • Privacy: Perplexity processes requests to provide search results and content
  • Location: United States. Perplexity AI is not certified under the EU-U.S. Data Privacy Framework; data is transferred based on the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
  • For more information: https://www.perplexity.ai/hub/legal/privacy-notice

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

Perplexity Privacy Policy

7.6 Anthropic (Text Generation)

  • Provider: Anthropic PBC, 548 Market Street, PMB 42098, San Francisco, CA 94104, USA
  • Usage: Generating text, analyses, and content ideas using Claude models
  • Submitted data: Your input text, prompts, and brand data (for context generation)
  • Privacy: The data is accessed via the API. Anthropic does not use API data to train its models.
  • Location: United States. Anthropic is not certified under the EU-U.S. Data Privacy Framework; data transfers are made on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
  • For more information: https://www.anthropic.com/legal/privacy

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Art. 28 of the GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

Anthropic Privacy Policy

7.7 Fal.ai (Image Generation Models)

  • Provider: fal – Features & Labels, Inc., 2261 Market Street, Suite 10467, San Francisco, CA 94114, USA
  • Usage: Advanced image generation using various AI models (including FLUX)
  • Data Sent: Image prompts, style parameters, reference images
  • Privacy Policy: fal.ai processes data for image generation
  • Location: United States. fal.ai is not certified under the EU-U.S. Data Privacy Framework; data is transferred based on the EU Standard Contractual Clauses (Art. 46(2)(c) of the GDPR).
  • Note on labeling: To the best of our knowledge, fal.ai does not include any provider-side watermarks. We therefore apply all labeling to the output of these models ourselves (metadata and content credentials; see Section 8.2).
  • In addition to image generation, fal.ai is also used for automatic background removal (the “BiRefNet v2” and “Pixelcut” models, both hosted on the fal.ai platform), for example, when automatically generating product preview images.
  • For more information: https://fal.ai/legal/privacy-policy

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract); Transfer to a third country based on Article 28 of the GDPR (Data Processing Agreement) in conjunction with Article 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

Fal.ai Privacy Policy

7.8 Creatomate (Video and Thumbnail Creation)

  • Provider: Creatomate BV, Netherlands
  • Usage: Automatic creation of video thumbnails, social media graphics, slideshows
  • Transmitted data: Your images, texts, design templates
  • Data protection: Creatomate is EU-based and GDPR-compliant
  • Location: EU (Netherlands)
  • Further information: https://creatomate.com/privacy-policy

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Privacy policy of Creatomate

7.9 DeepL (Translation of Content)

  • Provider: DeepL SE, Maarweg 165, 50825 Cologne, Germany
  • Usage: Automatic translation of article texts, blog posts, newsletters, notifications, and system email messages into other languages
  • Data Provided: The texts to be translated (e.g., post content) as well as the source and target languages
  • Privacy Policy: DeepL is a German/European company; data processing takes place within the EU
  • Location: EU (Germany)
  • For more information: https://www.deepl.com/de/privacy

Legal basis: Legal basis: Art. 6(1)(b) of the GDPR (performance of a contract), Art. 28 of the GDPR (data processing on behalf of a controller)

DeepL Privacy Policy

7.10 LangSmith / LangChain (AI Quality Assurance and Tracing)

  • Provider: LangChain, Inc., USA
  • Usage: If enabled on the server side, LangSmith logs the processes of our AI agents (e.g., multi-step content generation workflows) for quality assurance, error analysis, and performance monitoring.
  • Data transmitted: prompts, intermediate steps, and responses from the relevant AI workflows—these may contain content and brand data
  • Privacy Policy: Access to the LangSmith Project is restricted to authorized employees
  • Location: United States (or EU endpoint, if configured)
  • For more information: https://www.langchain.com/privacy-policy

Legal basis: Legal basis: Art. 6(1)(b) and (f) of the GDPR (performance of a contract for AI functions, legitimate interest in quality assurance); Transfers to third countries based on Art. 28 of the GDPR (data processing agreement) in conjunction with Art. 46(2)(c) of the GDPR (EU Standard Contractual Clauses)

LangChain Privacy Policy

7.11 Tesseract.js (OCR for images and scans)

  • Use: Open source OCR engine for text recognition in uploaded images, screenshots and scans
  • Processing: Takes place locally in the browser or on our EU servers
  • Transmitted data: Image files for text recognition
  • Data protection: Tesseract is open source, no data transfer to third parties
  • Location: Local processing / EU server

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

7.12 Document Processing (Office files, PDFs, etc.)

  • We use various tools to process uploaded documents:
  • - Officeparser: Reading Word (.docx), Excel (.xlsx), PowerPoint (.pptx) files
  • - Mammoth: Conversion of Word documents
  • - PDF-Parse: Extraction of text from PDF documents
  • - XLSX: Processing Excel files
  • - CSV-Parse: Reading CSV data
  • - Cheerio: Web scraping for website analysis (Brand Analyser)
  • Purpose: Analysing your brand guidelines, documents and websites for the Brand Analyzer
  • Processing: Takes place on our EU servers (AWS)
  • Data protection: All tools are open source or run on our own servers

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

7.13 Google APIs (YouTube and Gmail integration)

  • Usage: Integration with Google Services (YouTube for video posts, Gmail for email notifications)
  • Transmitted data: OAuth tokens for authorisation, post data for YouTube
  • Data protection: Google processes data in accordance with the Google Privacy Policy
  • Location: USA/EU
  • Further information: https://policies.google.com/privacy
  • Status: In development for YouTube integration

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

7.14 Important Note on AI Processing

Your data will only be transmitted to the relevant providers when you are actively using the respective AI feature.

AI providers process your data solely for the purpose of providing the requested service (content generation, translation, text recognition, research).

Data processing agreements pursuant to Article 28 of the GDPR are in place with all AI providers; for providers from third countries, EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR are also in place (see Section 16).

We limit the transfer of personal data to AI providers to what is necessary for the respective function and do not transfer any contact information, payment information, or login credentials from your account. However, it is not possible to completely rule out the transfer of personal data: prompts, brand profiles, reference texts, and uploaded images and documents may contain personal data if you enter or upload such information.

Therefore, please do not enter any personal data of third parties, any special categories of personal data as defined in Article 9 of the GDPR, or any confidential information in prompts or uploads, unless this is necessary for the desired function or you have the necessary rights and consents.

For media content we produce, we use technical disclosure and labeling mechanisms such as metadata, content credentials, watermarks, and visible notices. Details and the allocation of responsibilities under Article 50 of the EU AI Act can be found in Section 8.

The models and providers used may change as the service evolves. We will reflect any significant changes in this Privacy Policy (see Section 20).

08 AI Transparency and Labeling (Art. 50 of the EU AI Act)

PostMaestro.ai is an AI system that generates synthetic content: text, images, videos, graphics, and—where available—synthetic voices. Such systems are subject to the transparency requirements set forth in Article 50 of Regulation (EU) 2024/1689 on Artificial Intelligence (“EU AI Act”). This section explains which obligations we, as the provider, must fulfill and which obligations apply to you, as the operator, when you publish generated content.

8.1 Disclosure of Interaction with an AI System

  • In PostMaestro.ai, you interact directly with AI systems. All features that generate, evaluate, summarize, translate, or rephrase content are AI-powered and are labeled as such in the user interface.
  • The notice is provided before the first interaction, is clear, understandable, and clearly distinguishable from the other user interface elements (Art. 50(1) of the EU AI Act).
  • We provide this information in an accessible format and ensure it complies with recognized accessibility requirements (Art. 50(5) of the EU AI Act).
  • AI responses and suggestions may be incomplete, outdated, or factually incorrect. They do not constitute legal, tax, medical, or financial advice.

8.2 Machine-Readable Markup for Generated Content

  • Under Article 50(2) of the EU AI Act, content generated by AI systems that produce synthetic images, audio, video, or text must be labeled as artificially generated or manipulated in a machine-readable format. The labeling must be effective, interoperable, robust, and reliable.
  • We implement this requirement using several complementary methods, since, given the current state of the art, no single method alone can achieve the required robustness:
  • • Source metadata in the file: During export, we write XMP and IPTC metadata into the generated media files, specifically the IPTC field “Digital Source Type” with the value “trainedAlgorithmicMedia,” as well as information about the AI system used, the model version, and the time of generation.
  • • Content Credentials (C2PA): For generated image and video files, we incorporate a cryptographically signed provenance statement compliant with the C2PA standard into the output pipeline.
  • • Provider-side watermarks: If the respective model provider includes invisible watermarks, these are retained and not removed. For Google Gemini image models, this is the SynthID watermarking method.
  • • Validation: After writing, we read the markup again and log a status for each file (pending, valid, missing, removed). If the embedding fails, we enforce visible labeling for sensitive content classes.
  • The marker is set on the server side before a file is stored or delivered, so that it survives rendering, uploading, and downloading. Technically, it cannot be ruled out that third parties or target platforms may remove metadata during re-uploading, compression, or cropping. In this case, the visible mark remains your safeguard (see 8.3).
  • Implementation Status and Deadline: The transparency requirements under Article 50 of the EU AI Act have been in effect since August 2, 2026. For AI systems that—like PostMaestro.ai—were already on the market prior to this date, the transition period extends until December 2, 2026. We will fully implement the procedures described above within this period and document the implementation status internally.
  • A notice in this privacy policy alone does not satisfy the requirements of Article 50(2) of the EU AI Act. What is required is a machine-readable label on the file itself.

8.3 Your Responsibilities as an Operator Regarding Deepfakes

  • If you publish content generated by PostMaestro.ai, you are considered an “operator” under the EU AI Act. In this case, the disclosure requirement under Article 50(4) of the EU AI Act applies to you, not to us.
  • If you create or edit image, audio, or video content that bears a striking resemblance to real people, objects, places, institutions, or events (“deepfakes”), you must disclose upon publication that the content has been artificially generated or manipulated.
  • According to the European Commission’s guidelines, this obligation applies regardless of whether there was any intent to mislead and even if no specific real person is depicted. It therefore generally applies to posts on social media.
  • To assist you, we provide: a visible label as the default setting for sensitive content classes, a suggested warning message during export, and a note in the publishing workflow.
  • The default setting is always “enabled.” Disabling this feature must be documented: We record the time, user account, workspace, and version of the confirmation text. For photorealistic depictions of people and synthetic voices, disabling this feature is not permitted.
  • You may not remove, disable, circumvent, or interfere with the labeling and disclosure mechanisms we provide (see Section 6.4 of the Terms and Conditions).
  • This requirement applies in addition to the disclosure requirements of the respective social media platform. You must determine for yourself whether a disclosure requirement applies in each individual case.

8.4 AI-Generated Text and Editorial Responsibility

  • With regard to text, Article 50 of the EU AI Act is significantly more narrowly defined than for images, audio, and video. A disclosure obligation applies only if all three of the following conditions are met:
  • 1. The text was generated or manipulated by AI.
  • 2. The text will be published.
  • 3. The purpose of the publication is to inform the public about matters of public interest—such as news, political or social commentary, and contributions to public debates.
  • The labeling requirement does not apply if the content has been subject to human review or editorial oversight and a natural person or legal entity bears editorial responsibility for the publication.
  • There is no general requirement to label every piece of AI-generated text. Anyone who uses AI as an assistive tool, reviews the texts editorially, and takes responsibility for them is generally not subject to any additional labeling requirement.
  • PostMaestro.ai is designed precisely for this purpose: The generated texts are suggestions. Before scheduling or publishing, we require explicit confirmation that you have reviewed the text and assume editorial responsibility. We log this confirmation along with the time, user account, and text version so that the exception remains verifiable.
  • The note in the application reads: “This text is a suggestion. Please review it before publication. By reviewing it, you assume editorial responsibility.”
  • Without this review, you may not publish generated texts as editorially responsible content; the disclosure requirement under Article 50(4) of the EU AI Act may then apply.

8.5 No Emotion Recognition and No Biometric Categorization

  • PostMaestro.ai does not use emotion recognition systems and does not infer emotions, emotional states, or intentions from biometric data.
  • We do not engage in biometric categorization, facial recognition, biometric identification, or the identification of protected characteristics such as ethnic origin, political views, religion, union membership, health, or sexual orientation.
  • Evaluation features such as Idea Validation, Brand Analyser, and performance analyses relate exclusively to content, brand, and reach data—not to individuals or biometric characteristics.
  • The disclosure requirements under Article 50(3) of the EU AI Act for emotion recognition and biometric categorization systems therefore do not apply to us.

8.6 Prohibited Use: Intimate depictions without consent and depictions of child abuse

  • Article 5 of the EU AI Act prohibits AI systems whose reasonably foreseeable output consists of non-consensual intimate images (NCII) or child sexual abuse material (CSAM). As a provider of a general-purpose image and video generation tool, we assess this risk of misuse as early as the design phase and implement technical safeguards.
  • Protective measures implemented:
  • • Input filters that block relevant prompts even before the image and video models are called
  • • Output filters and the security settings of the model providers used
  • • Blocking content that targets minors in a sexualized context or depicts intimate images of identifiable individuals
  • • Disabling the Persona and Voice features without the data subject’s documented consent (see Section 5.9)
  • • Logging of blocked requests for abuse detection, as well as the ability to suspend affected accounts
  • Any use of the platform for these purposes is strictly prohibited and will result in the immediate suspension of the account and, if there is evidence of criminal activity, the involvement of the appropriate authorities.
  • Report Abuse: You and third parties can report violations at any time by emailing info@nexaluna.ai with the subject line “Report AI Abuse.” We prioritize incoming reports and will confirm receipt.
  • We document our risk assessment from the design phase, the filters used, and the handling of reports internally, and provide this documentation to the relevant authorities upon request.

8.7 Division of Roles: Providers and Operators

  • The provider, as defined by the EU AI Act, is Nexaluna AI Solutions UG (limited liability) for the PostMaestro.ai AI system. We are subject to the provider obligations, in particular the machine-readable labeling of outputs pursuant to Article 50(2) and the disclosure of AI interaction pursuant to Article 50(1).
  • You are considered an operator as soon as you use the platform under your own responsibility and publish content you have created. You are subject to the obligations of an operator, in particular the disclosure requirement under Article 50(4) regarding deepfakes and texts of public interest.
  • The base models used are provided by third parties (see Section 7). These third parties are the providers of the respective AI models; we are the provider of the AI system built on top of them.
  • We maintain an internal registry of all models in use, along with their respective role assignments, and update it whenever changes occur.
  • To ensure AI competence in accordance with Article 4 of the EU AI Act, we train our employees on how to use the AI systems we employ and document the training sessions.

8.8 Oversight and Complaints

  • As of July 29, 2026, the Federal Network Agency has been the competent market surveillance authority, central point of contact, and complaints office for the EU AI Act in Germany.
  • Federal Network Agency, Tulpenfeld 4, 53113 Bonn, https://www.bundesnetzagentur.de
  • You can file a complaint regarding AI transparency there at any time. We ask that you contact us in advance at info@nexaluna.ai so that we can address your concern immediately.

09 Payment processing (Stripe)

We use Stripe (Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA) for payment processing.

The following data is transmitted to Stripe for payments:

- Name and e-mail address

- Payment data (credit card number, expiry date, CVV)

- Billing address (if specified)

- Amount and transaction data

We do not store any complete payment data (credit card numbers, CVV) ourselves. These are stored exclusively by Stripe.

We only receive from Stripe:

- Transaction ID

- Payment status (successful/failed)

- Last 4 digits of the payment method (for your overview)

- Stripe Customer ID (for recurring payments)

Legal basis: Legal basis: Art. 6 para. 1 lit. b GDPR (fulfilment of contract)

Third country: Stripe is EU-US Data Privacy Framework certified and offers EU servers.

Storage period: Storage period: transaction data 10 years (statutory retention obligation), payment methods until cancellation by you

Further information: https://stripe.com/de/privacy

10 Data storage and database

10.1 Strapi Backend System

  • All your account data, content and settings are stored in our backend system:
  • - Backend framework: Strapi CMS (Open Source)
  • - Database: PostgreSQL
  • - Hosting: AWS (EU region)
  • - Encryption: SSL/TLS for data transmission, bcrypt for passwords
  • Only authorised employees and systems have access.

10.2 AWS Hosting and Content Delivery

  • Our regional AWS resources are operated in EU regions:
  • • Primary server and storage location: Frankfurt (eu-central-1); other EU regions only if configured accordingly for individual services
  • • S3 buckets: For static assets and media files
  • • RDS PostgreSQL: For database hosting
  • • CloudFront: Global content delivery network; during content delivery, content and technical connection data may be processed via edge locations outside the EU or the EEA
  • AWS processes customer data as a data processor in accordance with Article 28 of the GDPR, based on the AWS Data Processing Addendum (AWS DPA).
  • For any transfers to third countries, the EU Standard Contractual Clauses incorporated into the AWS Terms of Service automatically apply. Under the shared responsibility model, we are responsible for selecting and securely configuring the regions and services.

Legal basis: Legal basis: Art. 6 para. 1 lit. b, f GDPR (fulfilment of contract, legitimate interest)

Storage period: Storage period: See respective data types (account data until deletion, billing data 10 years, etc.)

11 Data security

We use comprehensive technical and organisational measures to protect your data:

  • • SSL/TLS encryption for all data transfers (HTTPS)
  • • Bcrypt encryption for passwords (with a salt)
  • • Two-factor authentication (2FA) is available as an option
  • • Regular security audits and penetration tests
  • • Access control and authentication for all systems
  • • Automatic backups (encrypted)
  • • Firewalls and intrusion detection systems
  • • Regular software updates and security patches
  • • Role-Based Access Control (RBAC) for team accounts
  • • Audit logs for security-related actions
  • • AES-256-GCM encryption for stored social media access tokens (access/refresh tokens)
  • • Signed, time-limited OAuth state parameters (HMAC-SHA256) and PKCE (S256) on X/Twitter to protect against CSRF and code interception attacks
  • • Bot and spam protection during registration/login via Cloudflare Turnstile

Despite all security measures, absolute security cannot be guaranteed for data transmission via the Internet. Please also protect your access data yourself.

12 Support, Security, and Automation Services

For account security, fraud protection, support, and internal automation, we also use the following third-party providers:

12.1 ipinfo.io (IP geolocation for login security notices)

  • Provider: ipinfo.io / IPinfo LLC, USA
  • Usage: When login notifications are enabled, we use the IP address to determine the approximate location (country, continent, network provider) each time a user logs in. Based on this information and the browser identifier, we create a device fingerprint to detect logins from new devices or from new countries. In this case, we’ll notify you in the app, via push notification, and via email about the device and the approximate location of the login.
  • Data transmitted: Your IP address at the time of login. Private/local IP addresses are filtered out in advance and are not transmitted.
  • We do not store the IP address; instead, for up to the 20 most recently used devices, we store a non-reversible hash value derived from the browser, operating system, device type, and country, as well as the time of the last sign-in.
  • We do not send a notification the first time you log in after turning the feature on.
  • Note: Login notifications are turned off by default. You can turn them on or off in your security settings. For company accounts, the account owner can enable them for all members; without active login notifications, no lookup takes place.
  • Location: USA
  • Further information: https://ipinfo.io/privacy-policy

Legal basis: Legal basis: Art. 6(1)(f) GDPR (legitimate interest in account security) and Art. 32 GDPR (security of processing). For transfers to the United States, the EU Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR apply.

Privacy Policy of ipinfo.io

12.2 Cloudflare Turnstile (bot and spam protection)

  • Provider: Cloudflare, Inc., USA
  • Usage: To protect the registration and login processes in the app, as well as the newsletter and unsubscribe forms on this website, from automated requests (bots) using a non-intrusive CAPTCHA method
  • Data transmitted: Interaction and browser signals for bot detection, as well as your IP address
  • Privacy Policy: Cloudflare is certified under the EU-US Data Privacy Framework
  • Location: U.S./EU
  • Further information: https://www.cloudflare.com/privacypolicy/

Legal basis: Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and prevention of misuse)

Cloudflare Privacy Policy

12.3 Linear (Feedback and Support Ticket System)

  • Supplier: Linear Orbit, Inc., USA
  • Usage: Internal processing of feedback, error messages ("Report a Problem"), and support requests as tickets
  • Data submitted: Your email address, the feedback or problem description you provided, the affected page or feature, and any screenshots you may have attached
  • Note: Comments and status updates from Linear will be sent to you via email for your information.
  • Location: United States
  • For more information: https://linear.app/privacy

Legal basis: Legal basis: Art. 6(1)(b), (f) of the GDPR (performance of a contract/support, legitimate interest in product improvement)

Linear Privacy Policy

12.4 GitHub (Workflow Automation)

  • Provider: GitHub, Inc. (Microsoft), USA
  • Usage: Purely technical automation—when a blog post is published, a GitHub Actions workflow is triggered, which, among other things, initiates the sending of the corresponding newsletter notification
  • Data transmitted: Post metadata (slug, language, internal document ID) — no personally identifiable user data
  • Location: United States
  • For more information: https://docs.github.com/en/site-policy/privacy-policies/github-privacy-statement

Legal basis: Legal basis: Article 6(1)(f) of the GDPR (legitimate interest in technical automation)

GitHub Privacy Policy

13 Your rights as a data subject

You have the following rights regarding your personal data:

11.1 Right to information (Art. 15 GDPR)

You can request information about the personal data stored by us at any time.

11.2 Right to rectification (Art. 16 GDPR)

You can request the correction of incorrect data or the completion of incomplete data.

11.3 Right to erasure (Art. 17 GDPR)

You can request the deletion of your personal data, provided that there are no statutory retention obligations.

11.4 Right to restriction (Art. 18 GDPR)

You can request the restriction of the processing of your data.

11.5 Right to data portability (Art. 20 GDPR)

You can receive your data in a structured, commonly used and machine-readable format and have it transmitted to another provider.

11.6 Right to object (Art. 21 GDPR)

You can object to the processing of your data if this is based on legitimate interest (Art. 6 para. 1 lit. f GDPR).

11.7 Withdrawal of consent (Art. 7 para. 3 GDPR)

If the processing is based on your consent, you can revoke it at any time. This does not affect the lawfulness of the processing carried out until the revocation.

11.8 Right to lodge a complaint (Art. 77 GDPR)

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement.

Exercising your rights

To exercise your rights, please contact us at info@nexaluna.ai. We will process your request within 30 days.

14 Automated Decisions and Profiling

We do not make any decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (Art. 22(1) of the GDPR).

Evaluative AI features such as Idea Validation, Brand Analyser, Content Scoring, and performance forecasts generate only non-binding suggestions and assessments regarding content and brands. They do not evaluate individuals or trigger decisions regarding individuals.

Automated processes that have an immediate effect on your account relate exclusively to contract fulfillment and security: blocking paid actions when your token balance is depleted, automatic token reloading after you have previously enabled this feature, bot protection during registration and login, and the blocking of input by our abuse filters (see Section 8.6).

If an automated security or abuse check results in your account being restricted, you can request a manual review at any time, explain your position, and appeal the decision. To do so, please contact info@nexaluna.ai.

No credit scoring, in the sense of a creditworthiness check, takes place. Payment processing, including fraud prevention, is handled by Stripe (see Section 9) in accordance with its own procedures.

15 Overview: All third-party providers used (subprocessors)

The following table provides an overview of all third-party providers that process personal data on our behalf:

Provider Purpose Location Legal Basis
Amazon Web Services (AWS) Hosting, Server Infrastructure, Database (PostgreSQL) EU (primary storage, specifically Frankfurt); globally via CloudFront delivery Art. 28 of the GDPR (General Data Protection Regulation)
Stripe Payment Processing U.S./EU Art. 28 GDPR (AVV), EU-U.S. DPF
SendGrid (Twilio) Email Communications (Newsletters, Service and Notification Emails) United States Art. 28 GDPR (AVV), EU-U.S. DPF
OpenAI Text Generation (GPT Models) United States Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses)
Perplexity AI Research, Web Search, Text Generation United States Art. 28 of the GDPR (AVV) in conjunction with Art. 46(2)(c) of the GDPR (SCC)
Google Gemini Image Generation U.S./EU Art. 28 GDPR (AVV), EU-U.S. DPF
Mistral AI OCR (Optical Character Recognition) EU (France) Art. 28 of the GDPR (AVV)
Fal.ai Image Generation, Background Removal United States Art. 28 of the GDPR (AVV) in conjunction with Art. 46(2)(c) of the GDPR (SCC)
Creatomate Video Thumbnails, Visual Editing EU (Netherlands) Art. 28 of the GDPR (AVV)
Anthropic Text Generation (Claude) United States Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses)
Firebase (Google) Push Notifications (Mobile App and Browser) U.S./EU Art. 28 GDPR (AVV), EU-U.S. DPF
Tesseract.js OCR for Images/Scans (Open Source) Local Processing / EU Art. 6(1)(b) of the GDPR
Google APIs YouTube and Gmail Integration U.S./EU Art. 28 GDPR (AVV), EU-U.S. DPF
OpenRouter AI Model Routing (Image Generation) United States Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses)
DeepL Translation of Content EU (Germany) Art. 28 of the GDPR (AVV)
LangChain / LangSmith AI Quality Assurance and Tracing United States Art. 6(1)(f) GDPR, Art. 28 GDPR (Data Processing Agreement) in conjunction with Art. 46(2)(c) GDPR (Standard Contractual Clauses)
ipinfo.io IP Geolocation for Login Security Notifications United States Art. 6(1)(f) of the GDPR, Art. 46(2)(c) of the GDPR (SCC)
Linear Feedback and Support Ticket System United States Art. 28 of the GDPR (Standard Contractual Clauses) in conjunction with Art. 46(2)(c) of the GDPR (Standard Contractual Clauses)
Cloudflare (Turnstile) Bot/Spam Protection (CAPTCHA) U.S./EU Art. 28 GDPR (AVV), EU-U.S. DPF
GitHub (Microsoft) Workflow Automation (Blog Post) United States Art. 6(1)(f) of the GDPR, EU-U.S. DPF (Microsoft)

We have contracts in place with all data processors in accordance with Article 28 of the GDPR. For providers in third countries without an adequacy decision, we have additionally entered into the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR and documented a data transfer impact assessment (see Section 16). The full names and addresses of the AI providers can be found in Section 7. We keep this list up to date; please refer to the date at the beginning of this statement for the current status.

16 International data transfers

Some of our service providers are headquartered or have server locations in the United States or other third countries outside the EU/EEA. This applies in particular to OpenAI, Anthropic, Perplexity AI, fal.ai, OpenRouter, LangChain/LangSmith, Google/Firebase, Stripe, SendGrid (Twilio), Cloudflare, ipinfo.io, Linear, and GitHub.

These transfers take place regularly and systematically as part of our day-to-day operations. We therefore do not rely on exceptions for individual cases, but rather on appropriate safeguards:

• Data Processing Agreement pursuant to Article 28 of the GDPR with the respective provider

• EU Standard Contractual Clauses of the European Commission pursuant to Article 46(2)(c) of the GDPR, supplemented by additional technical and organizational safeguards (encryption, access control, data minimization)

• Adequacy decision pursuant to Article 45 of the GDPR, provided that the service provider is certified under the EU-U.S. Data Privacy Framework. This is currently the case for Stripe, SendGrid (Twilio), Cloudflare, Google/Firebase, and Microsoft/GitHub.

To the best of our knowledge, OpenAI, Anthropic, Perplexity AI, fal.ai, OpenRouter, and LangChain are not certified under the EU-U.S. Data Privacy Framework. Transfers to these providers are therefore made on the basis of the EU Standard Contractual Clauses pursuant to Article 46(2)(c) of the GDPR.

For every transfer to a third country without an adequacy decision, we conduct and document a Transfer Impact Assessment. We will provide you with the current status of the agreements and assessments upon request at info@nexaluna.ai.

We rely on Article 49(1)(b) of the GDPR exclusively in genuine individual cases where a transfer is necessary to fulfill a specific contract you have requested and is a one-time occurrence.

Despite these guarantees, it cannot be completely ruled out that authorities in third countries may demand access to transmitted data in accordance with their local laws. Therefore, do not include any third-party personal data or particularly sensitive information in prompts or uploads (see Section 7.14).

When delivering content globally via Amazon CloudFront, AWS may process technical connection data at edge locations outside the EEA. The AWS Data Processing Addendum applies in this regard; the Standard Contractual Clauses adopted by the European Commission are incorporated into the AWS Terms of Service for such transfers to third countries and apply automatically.

17 Data storage and deletion periods

We only store your data for as long as is necessary for the respective purposes:

  • • Account data: Until the account is deleted
  • • Content data: Until manually deleted or the account is deleted
  • • Newsletter data: Until unsubscription; unconfirmed subscriptions, 30 days; proof of consent, 3 years after unsubscription (see Section 6.2)
  • • Notifications in the inbox: read for 30 days, unread for 90 days, unless deleted earlier (see Section 5.7)
  • • Device tokens for push notifications: Deactivated after 60 days of inactivity, deleted 30 days after that
  • • Billing data: 10 years (statutory retention requirement pursuant to Section 147 of the German Fiscal Code (AO))
  • • Support requests: 3 years after completion
  • • Server log files: 7 days, followed by automatic anonymization (see Section 4.1)
  • • Persona and voice data: Until you delete it or revoke your consent (see Section 5.9)
  • • Documentation regarding AI labeling (labeling status, test confirmations, documented deviations): 3 years from the date of creation, to fulfill the documentation requirements under the EU AI Act

Account deletion

You can delete your account at any time in the settings.

After an account is deleted, all personal data will be deleted within 30 days.

Exception: Billing data is retained for 10 years in accordance with statutory retention requirements.

Published social media posts remain on their respective platforms and must be deleted there separately.

For Meta connections (Facebook/Instagram), we also support Meta's automated data deletion callback: If you disconnect the app in your Facebook account settings, we automatically receive a deletion request and provide the processing status via a status URL provided by Meta.

18 Cookies and tracking

18.1 Technically Necessary Cookies

  • We use technically necessary cookies and, with your consent, optional cookies:
  • - Session cookie (language setting)
  • - Theme preference (dark/light mode)
  • - Login session (after logging in to the app)
  • - Local Storage (language/country, no location)
  • This technically necessary data is required for the functionality of the website.

18.2 Optional Cookies (Analytics and Marketing)

We use Google Analytics and other tools to analyse user behaviour and for marketing purposes:

- Analytics cookies (e.g. Google Analytics): For the analysis of user behaviour

- Marketing cookies: To display personalised advertising

- Social media cookies: For social media functions

You can give or refuse your consent via the cookie banner.

No optional cookies will be set without your consent.

18.3 Cookie Management

You can manage and delete cookies in your browser settings.

Please note that deactivating technically necessary cookies may restrict the functionality of the website.

You can adjust your cookie settings at any time via a link in the footer or via the cookie banner.

Legal basis: Legal basis: For technically necessary cookies, Section 25(2)(2) of the TDDDG in conjunction with Article 6(1)(f) of the GDPR; for optional analytics and marketing cookies: Section 25(1) of the TDDDG in conjunction with Article 6(1)(a) of the GDPR (consent). No optional cookies will be set without your consent.

19 Children and young people

PostMaestro.ai is not intended for persons under the age of 16.

Persons under the age of 16 may not use the platform.

If we become aware that a person under the age of 16 has created an account, we will delete it immediately.

If you suspect that a minor has created an account without parental consent, please contact us at info@nexaluna.ai.

20 Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy as necessary to reflect changes in the legal landscape or changes to our services.

We will notify you of any significant changes via email or through a prominent notice on the website.

This statement is Version 3.2, dated September 23, 2026. You can always find the most current version at postmaestro.ai/privacy.

This Privacy Policy is available in several languages. The translations are provided for your information only; in the event of any discrepancies, the German version shall prevail.

20.1 Revision History

  • Version 3.2 (September 23, 2026): Section 12.1 clarified (additional notice in the app and via push notification, only when using a new device or in a new country; device fingerprint; mandatory activation by the company owner). Section 4.4: The “Coming Soon” window now subscribes you to the newsletter, which also announces the launch. Section 5.7 expanded to cover “Notifications (in-app, push, and email)” (browser push, device ID, visibility signal, inbox, service notifications, notifications marked as “Important”). Section 6 revised: Registration methods, double opt-in for the website and registration, proof of consent (new Section 6.2), processing of delivery events by SendGrid, unsubscription via form and email client, retention period without an inactivity rule. Section 12.2 has been expanded to include the forms on this website. An overview of DeepL and third-party providers, as well as retention periods, has been added.
  • Version 3.1 (September 14, 2026): The provisions regarding the marketing use of uploaded and created content have been adapted to the sharing feature—which is enabled by default but can be disabled at any time—and aligned with Section 7.2 of the Terms of Service. The information regarding AWS hosting has been clarified to specify primary EU data storage, global CloudFront delivery, as well as the AWS DPA and EU Standard Contractual Clauses.
  • Version 3.0 (August 10, 2026): New Section 8 on AI transparency and labeling pursuant to Article 50 of the EU AI Act—disclosure of AI interaction, machine-readable labeling of generated content, operators’ deepfake obligations, AI-generated text and editorial responsibility, no emotion recognition, prohibited use under Article 5 of the EU AI Act, division of roles between providers and operators, competent supervisory authority. New Section 5.9 on persona, avatar, and voice cloning data. New Section 14 on automated decision-making under Article 22 of the GDPR.
  • Version 3.0 (Continued): Legal basis for transfers to third countries changed from Art. 49(1)(b) GDPR to Art. 28 GDPR in conjunction with Art. 46(2)(c) GDPR (EU Standard Contractual Clauses) and the information regarding OpenAI’s certification under the EU-U.S. Data Privacy Framework has been corrected. The reference to consent through mere use has been removed. Marketing use of customer content has been changed to require explicit consent (opt-in). The legal basis for cookies has been supplemented with Section 25 of the TDDDG. Addresses for fal.ai and Perplexity AI have been added. Contradictory information regarding log files and the cookie banner has been resolved; the section “Data Protection Officer” has been renamed “Contact for Data Protection”; and the table of contents and section numbering have been completely revised.
  • Version 2.0 (July 9, 2026): Addition of social login, platform-specific OAuth authorizations, OpenRouter, DeepL, and LangSmith, as well as support, security, and automation services (ipinfo.io, Cloudflare Turnstile, Linear, GitHub).
  • Version 1.0 (March 15, 2026): Initial release.

21 Contact and questions about data protection

If you have any questions about data protection, exercising your rights or complaints, please contact:

E-mail: info@nexaluna.ai

Phone: +49 151 28858234

Post: Nexaluna AI Solutions UG (haftungsbeschränkt) (Nexaluna AI Solutions), Renkenweg 23, 83209 Prien, Germany

We will process your enquiry within 30 days.

Competent supervisory authority

Bavarian State Office for Data Protection Supervision (BayLDA)

Promenade 18, 91522 Ansbach

Phone: +49 (0)981 180093-0

E-mail: poststelle@lda.bayern.de

Website: https://www.lda.bayern.de/