Privacy Policy
Data Controller (Verantwortlicher)
The controller responsible for the processing of your personal data under the EU General Data Protection Regulation (GDPR / DSGVO) is:
Ekin Eser Akcay
Avenlo Media
HelgolΓ€nder Str. 32
26316 Varel
Germany
π§ E-Mail: [email protected]
Data-protection and privacy requests can be sent to [email protected], a routed alias that reaches the controller.
1. Who We Are
Avenlo is an AI-powered social media automation platform that helps you create, schedule, and publish content to TikTok, YouTube, and Instagram. This policy explains what data we collect, how we use it, and with whom we share it.
2. What Data We Collect
- Account data: Your name and email address when you register.
- Connected accounts: Access tokens for your TikTok, Instagram, and YouTube accounts so we can publish on your behalf.
- Content: Videos, captions, and scheduling details you create or upload.
- Payment data: Coin purchase records processed through Stripe. We never see or store your card details.
- Usage data: Basic logs of actions taken on the platform for billing and support purposes.
3. How We Use Your Data
- To run your account and provide our services.
- To publish content to your connected social media accounts.
- To manage your coin balance and process payments.
- To send you important notifications about your account.
- To respond to your support requests.
- To detect and prevent fraud or abuse.
We do not sell your data or use it for advertising.
4. Google User Data
When you connect your YouTube account, Avenlo receives access to your Google account data via OAuth 2.0. Specifically:
- We access your YouTube channel information (name, avatar, subscriber count) to display inside your Avenlo dashboard.
- We upload videos to your YouTube channel on your behalf when you explicitly trigger a publish or schedule action.
- We do not sell, rent, transfer, or share your Google user data with any third parties.
- We do not use Google user data for advertising purposes.
- We do not use Google user data to train AI or machine learning models.
- Google user data is used solely to provide the YouTube publishing and analytics features of Avenlo.
- You can revoke Avenlo's access to your Google account at any time at myaccount.google.com/permissions.
5. Third-Party Services
We use the following third-party services to operate Avenlo:
- Stripe β for payment processing.
- Google (YouTube Data API v3) β for YouTube content publishing and channel analytics.
- TikTok β for TikTok content publishing via their official API.
- Meta (Instagram Graph API) β for Instagram content publishing via their official API.
- Cloudflare, Inc. (USA) β CDN, DDoS protection, and bot management; processes request metadata (such as IP address and request headers) as it proxies traffic to our servers.
- Anthropic PBC β Claude API (USA) β AI text generation for video scripts, captions, and post copy; receives the prompts, topics, and text you provide for generation.
- ElevenLabs, Inc. (USA) β AI voice generation; receives the script and dialogue text you provide (and, for voice cloning, the audio samples you upload) to synthesise speech.
- Replicate, Inc. and OpenAI, L.L.C. (USA) β AI image generation; receive the image prompts you provide.
- Resend, Inc. β transactional email service (EU region) β sends transactional emails (verification, password reset, account notifications) on our behalf; receives your email address and the message content. This account is configured to operate from Resend's EU region (EU data residency).
- Pixabay β royalty-free background-music search; receives only non-personal mood and search queries.
Each of these services has its own privacy policy that applies to the data they handle. We do not share your personal data with any of these services beyond what is strictly necessary to provide our features.
6. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We only share data in the following limited circumstances:
- With social media platforms: We share your content and account tokens with TikTok, YouTube, and Instagram solely to publish on your behalf.
- With Stripe: We share transaction identifiers with Stripe to process payments. Stripe does not receive your social media data.
- Legal requirements: We may disclose data if required by law or to protect the rights and safety of our users.
No other sharing, transfer, or disclosure of your data takes place.
7. How Long We Keep Your Data
- Your account and content are kept until you delete your account.
- Payment records are kept for 7 years as required by law.
- Usage logs are kept for 12 months, then deleted.
- When you disconnect a social media account, we immediately and permanently delete both the access tokens and the data we derived from that account β including analytics snapshots, video performance metrics, cached comments, and publish/upload records. This deletion is irreversible.
8. Your Rights
You have the right to access, correct, or delete your personal data at any time. You can also request a copy of your data or ask us to stop processing it. To make a request, email us at [email protected] and we will respond within 30 days.
9. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse.
10. Security and Audit Logging
To keep the platform secure and to investigate abuse, we record two kinds of operational logs:
- Security events β such as failed login attempts, rate-limit hits, and suspicious request patterns. These are stored with the originating IP address and a country derived from it, and are kept for 30 days before automatic deletion.
- Audit logs β a record of actions taken on your account (for example sign-ins, account connections, and security-relevant changes). These are kept for 10 days before automatic deletion.
The legal basis for this processing is our legitimate interest in the security and integrity of our service (Art. 6(1)(f) GDPR / DSGVO).
11. International Transfers
Some of our service providers β including Stripe, Cloudflare, Anthropic, ElevenLabs, Replicate, OpenAI, and Google β are located in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Art. 44 ff. GDPR / DSGVO, namely the providers' certification under the EUβUS Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (SCCs).
12. Cookies
We use only cookies that are strictly necessary to operate the service and keep it secure. We do not set advertising, analytics, or tracking cookies, so no cookie-consent banner is required. The cookies we use are:
- token β your authentication session (a JWT). HttpOnly, Secure, SameSite=Lax.
- csrfToken β a CSRF-protection token (synchronizer pattern). Secure, SameSite=Lax, readable by the page's JavaScript.
- oauth_state_* β short-lived (15-minute) signed cookies set only during a social-account connection flow to secure the OAuth handshake.
- __cf_bm β set by Cloudflare for bot management when traffic passes through their network.
13. Children
Avenlo is not intended for users under 16. If you believe a minor has created an account, contact us and we will remove it.
14. Changes
If we make significant changes to this policy, we will notify you by email at least 14 days before they take effect.
Contact
For any privacy-related questions or data requests:
π§ [email protected]