Privacy Policy
Last updated: July 2026
Note: This English translation is provided for convenience only; the German version is legally binding and prevails.
1. Controller
Controller within the meaning of the Datenschutz-Grundverordnung (DSGVO, GDPR):
Richard Mann
c/o Autorenglück #44796
Albert-Einstein-Str. 47
02977 Hoyerswerda
Germany
Email: [email protected]
2. General Information on Data Processing
I process personal data only insofar as this is necessary to provide this website and my content and services. As a rule, processing takes place only with the consent of the user (Art. 6(1)(a) GDPR) or where processing is permitted by statutory provisions (Art. 6(1)(b), (c), (f) GDPR).
3. Cookies & consent
On your first visit we show a consent banner. We always set strictly necessary cookies — no consent is required for these (Art. 6(1)(b) and (f) GDPR). Optional categories (analytics and support chat) are off by default and are only activated after your explicit consent. We store your choice locally in your browser (first-party, not a cookie). You can change or withdraw it at any time via “Cookie settings” in the footer; withdrawing is as easy as consenting.
Necessary — always on:
- Clerk sets session cookies required for login and session security.
- Stripe sets cookies only during the checkout process on the checkout pages operated by Stripe.
- Functional preferences (e.g. sidebar, view) are stored locally in your browser.
Optional — only with consent:
- Analytics (PostHog, EU hosting Frankfurt): reach and usage analytics and session replays. PostHog operates in two stages: without consent it only performs anonymous reach measurement in memory — no cookie, no localStorage, no access to your device (legitimate interest, Art. 6(1)(f) GDPR). Only with your consent (Art. 6(1)(a) GDPR) does PostHog set persistent identifiers (cookie + localStorage), link the measurement to your account and record session replays. On withdrawal we switch back to the anonymous stage and delete the identifiers PostHog has set.
- Support chat (Crisp): loaded only after your consent and exclusively inside the signed-in application — it is not embedded on this website (home page, pricing, legal pages). Crisp then sets a cookie for the chat session. On withdrawal the chat is hidden and the data Crisp has set locally is deleted.
No third-party advertising cookies are set and no data is shared with third parties for advertising purposes.
4. Hosting (Railway)
This website as well as the Ikrames application and the render service are hosted by Railway Corporation, San Francisco, California, USA. When the website is accessed, technically necessary data is processed (server logs):
- IP address of the accessing device
- Date and time of access
- Accessed URL and HTTP status code
- User agent (browser and operating system)
- Referrer URL
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable provision of the website). The transfer to the USA takes place on the basis of the EU Standard Contractual Clauses (SCC, Module 2 Controller-to-Processor), which Railway's data processing agreement (DPA) incorporates (applicable law: Irish law).
Data processing agreement (DPA): railway.com/legal/dpa. List of sub-processors: trust.railway.com. Railway data protection contact: [email protected]
5. DNS and Security (Cloudflare)
To provide the domain and for security functions (protection against DDoS, SSL encryption), Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA is used. For this purpose, Cloudflare processes technically necessary connection data including the IP address.
Legal basis: Art. 6(1)(f) GDPR. Cloudflare is certified under the EU-US Data Privacy Framework.
Cloudflare privacy policy: cloudflare.com/privacypolicy
6. Waitlist (Supabase)
If you sign up for the waitlist, the following data is processed and stored in a database at Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 (server location: EU):
- Email address
- Stated interest (e.g. Trial, Founder, Voice Lab)
- Time of registration
Purpose: information about the launch and about Founder offers from Ikrames. Legal basis: Art. 6(1)(a) GDPR (consent through active sign-up) and Art. 6(1)(b) GDPR (pre-contractual measures).
You can withdraw your consent at any time by sending an email to [email protected]. In this case your data will be deleted without delay.
Supabase privacy policy: supabase.com/privacy
7. Authentication (Clerk)
For the login area, Clerk Inc., 660 King Street, San Francisco, CA 94107, USA is used. When you register or sign in, the following data is processed:
- Email address
- Optional: name, profile picture
- Session data and IP address for session security
- Timestamp of the login
Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Clerk is certified under the EU-US Data Privacy Framework.
Clerk privacy policy: clerk.com/legal/privacy
8. Payment Processing (Stripe)
For the processing of payments (subscriptions, one-time purchases, Founder offers), Stripe is used. The provider for users in the European Economic Area is Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. The parent company is Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA.
During a payment process, the following data is transmitted to Stripe and processed there:
- Name and email address
- Billing address (if provided)
- Payment data (credit card information, IBAN, etc.) — this is transmitted directly from the browser to Stripe and is not stored on my servers
- Transaction amount and currency
- IP address for fraud prevention
- Device information and browser metadata
The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in fraud prevention).
A transfer of data to the USA to Stripe, Inc. may take place within the scope of intra-group processing. Stripe is certified under the EU-US Data Privacy Framework. In addition, Standard Contractual Clauses pursuant to Art. 46 GDPR have been agreed.
Stripe privacy policy: stripe.com/de/privacy
9. AI Services for Content Generation
Ikrames uses the following AI service providers to generate content (images, videos, audio, text):
fal.ai(Features & Labels, Inc., 2261 Market St Suite 10467, San Francisco, CA 94114, USA) — media inference (image, video, audio and transcription models). Legal basis: Art. 6(1)(b) GDPR. Data transfer to the USA on the basis of Standard Contractual Clauses. When processing personal data, we set the header X-Fal-Store-IO: 0 to suppress storage of the requests. Details: fal.ai/legal/privacy-policy
Anthropic (Anthropic PBC, USA) — language models (Claude) for processing content texts. Legal basis: Art. 6(1)(b) GDPR. Inference data is not used for training. Details: anthropic.com/legal/privacy
OpenAI (OpenAI, L.L.C., USA) — transcription of voice recordings (Whisper) and text embeddings. Legal basis: Art. 6(1)(b) GDPR. Details: openai.com/policies/privacy-policy
ElevenLabs (ElevenLabs Inc., USA) — text-to-speech, voice clones and music generation. Legal basis: Art. 6(1)(b) GDPR. Data transfer to the USA on the basis of Standard Contractual Clauses. Details: elevenlabs.io/privacy
HeyGen (HeyGen Technology Inc., USA) — generation of avatar videos (persona images). Legal basis: Art. 6(1)(b) GDPR. Details: heygen.com/privacy-policy
10. Social Media Publishing (Bundle.social)
Provider: Bundle.social. Data processed: connected social media accounts, OAuth tokens, post content. Legal basis: Art. 6(1)(b) GDPR.
Bundle.social privacy policy: bundle.social/privacy
11. Overview of Recipients and Processors
As part of providing Ikrames, personal data is processed by the following service providers:
- Railway — Hosting of the application and the render service (app data in transit, server logs)
- Supabase — Database and file storage (all user data)
- Clerk — Identity and authentication (email, name, sessions)
- Stripe — Payments and invoices
- Bundle.social — Social media publishing, OAuth tokens of the connected channels
- ElevenLabs — Voice clones (voice samples)
- Anthropic — LLM processing of content texts
- OpenAI — Whisper transcription (voice recordings), embeddings
- fal.ai — Image and video generation (prompts, in part brand images)
- Cloudflare — DNS/proxy for ikrames.com
- HeyGen — Avatar videos (persona images)
- PostHog — Product and reach analytics (page views, usage events) and session replays. EU hosting in Frankfurt (Germany). Anonymous reach measurement without access to your device on the basis of legitimate interest (Art. 6(1)(f) GDPR); identified analytics and session replays only with your consent (Art. 6(1)(a) GDPR). Provider: PostHog, Inc.
- Crisp — Support chat inside the signed-in application (chat contents, email and name, connection data). Provider: Crisp IM SAS, Nantes, France; storage in the Netherlands and Germany. Connection logs may pass through relay servers outside the EU (basis: standard contractual clauses)
12. Your Rights as a Data Subject
You have the following rights vis-à-vis the controller:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to the processing (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
Account deletion (Art. 17 GDPR): You can delete your account directly in the application (Settings → “Delete account”). Deletion is immediate and final and covers all content including data held at the connected services. Invoice data remains with the payment provider due to statutory retention obligations (§ 147 AO, § 14b UStG — German tax law).
Data export (Art. 20 GDPR): You can export your data directly in the application (Settings → “Export my data”). You receive your data in a machine-readable JSON format; the download link is valid for 24 hours.
In addition, an informal email to [email protected] is sufficient to exercise your rights.
13. Right to Lodge a Complaint with the Supervisory Authority
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The supervisory authority responsible for me is:
Der Sächsische Datenschutz- und Transparenzbeauftragte
Devrientstraße 1
01067 Dresden
www.saechsdsb.de
14. Retention Period
Personal data is stored only for as long as is necessary for the respective purpose or as required by statutory retention periods. Server logs are deleted after 30 days at the latest. Waitlist data is stored until withdrawal of consent or until the start of the service (then, where applicable, transferred into a customer account with consent).
15. SSL Encryption
For security reasons, this website uses SSL encryption. You can recognize an encrypted connection by the fact that the address bar of the browser begins with “https://”.
16. Changes to This Privacy Policy
I reserve the right to amend this privacy policy so that it always complies with the current legal requirements or in order to implement changes to my services. The new privacy policy will then apply to your next visit.