Privacy
Privacy Policy
Version: 26 August 2026
1. Controller
Joshua Hoppe, sole trader operating under AutoPilot Creator, Trommershausenstraße 9, 42697 Solingen, Germany, email: support@autopilot-creator.com.
2. Data we process
Depending on use, we process identity and contact details, login and account data, plan, invoice and payment status, uploaded videos and derived audio, image and text data, AI inputs and results, platform connections, publication data, support messages, cancellation and withdrawal declarations, and technical connection, security and log data.
Special-category data is not required for the service. Please upload such data only if you are authorised to do so and the processing is necessary for your chosen purpose.
3. Purposes and legal bases
We process data to enter into and perform the user contract, manage accounts and plans, process videos, provide AI analysis, publish to connected platforms, handle billing, support, cancellation, and withdrawal under Article 6(1)(b) GDPR.
Tax, commercial, and other mandatory records are processed under Article 6(1)(c) GDPR. Security, abuse prevention, troubleshooting, evidence of declarations, and legal claims rely on Article 6(1)(f) GDPR; our legitimate interest is the secure and verifiable operation of the service. Where we expressly ask for consent, Article 6(1)(a) GDPR applies and consent may be withdrawn for the future.
4. Supabase
We use Supabase for authentication, database services, and file storage. This includes account and profile data, plan and usage data, video metadata, uploaded files, platform connections, support data, and evidence of cancellation or withdrawal declarations. Video and publishing storage areas are not public. The production project is configured for region eu-central-1.
5. Vercel
Vercel hosts and delivers the web application and server-side API endpoints. IP address, time, browser and device information, requested URL, response status, and technical logs may be processed. Server-side functions are configured for region fra1 (Frankfurt). This supports contract performance and our legitimate interest in secure, stable hosting.
6. Stripe
Stripe processes checkout, subscriptions, invoices, tax, and payments. Payment details are collected directly by Stripe; we receive and store customer, checkout, price, invoice, and subscription identifiers plus status and tax information. Stripe may perform its own payment, fraud, and compliance checks. Contract performance and legal obligations are the main legal bases; security and fraud prevention also rely on legitimate interests.
At the first paid checkout, we record the express request for immediate performance with a server timestamp, language, and wording version in Stripe metadata.
7. OpenAI and AI features
When you start optional AI analysis, audio extracted from the video is sent to the OpenAI API for transcription. The transcript and up to three checked still frames are then processed with instructions to create a title, description, caption, hashtags, and call to action. The legal basis is performance of the function you request.
The application sets store: false for Responses requests. Under the published API data controls, API content is not used to train models by default unless data sharing is expressly enabled. Under standard API data controls, content from Responses requests may be processed in abuse-monitoring logs for up to 30 days. Zero Data Retention and OpenAI EU Data Residency are not represented as enabled for this service.
Audio Transcriptions are handled under OpenAI's separate endpoint-specific data controls. In OpenAI's current table, /v1/audio/transcriptions is listed with neither application-state retention nor abuse-monitoring retention. That endpoint entry does not mean that Zero Data Retention is enabled for the account.
8. Cloudflare Turnstile
Cloudflare Turnstile protects registration, sign-in, password recovery, and public cancellation and withdrawal functions from automated abuse. Technical connection, device, and interaction data may be transferred to Cloudflare. The legal basis is our legitimate interest in security and abuse prevention.
9. Email: IONOS and Resend
IONOS is used for business mailboxes and forwarding. Resend is used for technical and transactional messages, including authentication email and acknowledgements for cancellation or withdrawal declarations. Recipient and sender address, subject, required message content, delivery status, and technical sending data are processed for contract performance, legal obligations, and reliable communication.
10. Connected platforms
If you voluntarily connect a supported social-media platform, we process authorisation data, platform account details, selected content, and publication status to provide the connection and publication you request. OAuth tokens are stored encrypted on the server. Each platform provider also processes data under its own privacy notice. Connections can be removed in platform management.
For Instagram, we process the business-account ID, username and account type, plus the video, caption and publication status you select. We request only basic business-account data and content publishing permissions. For Facebook, we process the Page ID and Page name you select, available Page tasks, and the selected video, accompanying text and publication status. We request only Page listing, Page engagement reading and Page post management. Meta processes data independently for its services as described in the Meta Privacy Policy.
For TikTok, we process the Open ID, Union ID, display name and profile image, plus the selected video, TikTok-provided publishing options and publication status. We request only basic profile data and Direct Post; draft-upload access is not requested. The TikTok Privacy Policy also applies.
For Bluesky and the AT Protocol, we process the DID, handle, public profile and OAuth session data, plus the selected video, post text and job status. Permission is limited to creating posts and video blobs; email, direct messages, profile changes and general account management are not requested. The Bluesky AT Protocol Network Services Privacy Notice also applies to network services operated by Bluesky.
AutoPilot Creator uses YouTube API Services to display your connected YouTube account and publish videos and metadata that you select to YouTube. The Google Privacy Policy also applies.
You can disconnect access in platform management and review or revoke your Google/YouTube permissions at any time in Google Security settings. After revocation, we remove the authorisation and stored YouTube API Data covered by it in accordance with the applicable requirements.
11. Cancellation, withdrawal, and support
For cancellation and withdrawal declarations, we process name, email, contract or reference identifier, type and content of the declaration, requested end date or reason where applicable, receipt time, and confirmation status. For support, we process the submitted contact and message data and account or technical data needed to respond. This supports handling, legal obligations, and evidence of receipt.
12. Browser storage, cookies, and service worker
The application uses only storage technologies required for sign-in, security, language preferences, core operation, and PWA or offline functions. These may include local authentication and preference data, technically necessary cookies, and service-worker cache entries. Cloudflare Turnstile may process browser data needed for its security check.
We currently do not use analytics, marketing, or advertising trackers or non-essential cookies intended for those purposes. No consent banner is therefore currently displayed for them. If this changes, we will update this notice and obtain any required consent before processing.
13. Recipients and international transfers
Data is disclosed only to providers required for the relevant operation, connected platforms, payment and communication providers, and public authorities or other recipients where required by law. Providers are engaged as processors where required.
Some providers are part of groups outside the European Economic Area or may process data there. Where an adequacy decision does not ensure an adequate level of protection, the applicable contractual safeguards, in particular EU Standard Contractual Clauses, and required supplementary measures are used. You may request information about safeguards for a specific recipient through the privacy contact address.
14. Retention and deletion
Videos and related content are generally stored until you delete the relevant video or your account. Active records and storage objects are then removed through the implemented deletion flow unless a statutory retention duty applies.
OAuth secrets and active session material for a platform connection are removed immediately when you disconnect it or delete your account. Any inactive, non-secret connection metadata that remains after disconnection is deleted within no more than 30 days.
Detailed upload and AI usage events are retained for 90 days. Aggregated lifetime counters needed to calculate quotas may be maintained independently until account deletion. Publishing jobs and Stripe webhook deduplication data are each retained for 90 days.
Support cases are retained for three years from the end of the year in which the case was closed. Cancellation and withdrawal declarations and their evidence are retained for three years from the end of the relevant year. Consent and contract evidence is likewise retained for three years from the end of the relevant year and is pseudonymised after account deletion where continued retention is required.
Invoices and tax or accounting records required by law are retained for the applicable statutory period. Routine system logs have a target retention of 30 days; different technical provider settings and necessary security, abuse-prevention, or legal purposes may require a different period. At the end of the applicable period, data is deleted or anonymised unless a statutory exception applies.
15. Your rights
Within statutory limits, you have rights of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, you may withdraw it for the future. You may object on grounds relating to your situation to processing under Article 6(1)(f) GDPR.
You may also complain to a data-protection authority, in particular the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia or the authority at your place of residence.
16. Required data and automated decisions
Without required account, contract, and payment data, we cannot provide an account or paid plan. Optional content and platform connections do not have to be provided, but the related function then cannot be used. We do not ourselves make decisions about you based solely on automated processing that have legal or similarly significant effects. Payment and platform providers may conduct their own automated security or compliance checks.
17. Privacy contact
Send privacy requests to support@autopilot-creator.com.
18. Version and changes
Version: 26 August 2026. We update this notice when functions, providers, or legal requirements materially change.