← back

Privacy Policy

Last updated: August 2026

Note: This English translation is provided for convenience only; the German version is legally binding and prevails.

1. Controller

Controller within the meaning of the Datenschutz-Grundverordnung (DSGVO, GDPR):

Richard Mann
c/o Autorenglück #44796
Albert-Einstein-Str. 47
02977 Hoyerswerda
Germany
Email: [email protected]

2. General Information on Data Processing

I process personal data only insofar as this is necessary to provide this website and my content and services. As a rule, processing takes place only with the consent of the user (Art. 6(1)(a) GDPR) or where processing is permitted by statutory provisions (Art. 6(1)(b), (c), (f) GDPR).

3. Cookies & consent

On your first visit we show a consent banner. We always set strictly necessary cookies — no consent is required for these (Art. 6(1)(b) and (f) GDPR). The optional analytics category is off by default and is only activated after your explicit consent. We store your choice locally in your browser (first-party, not a cookie). You can change or withdraw it at any time via “Cookie settings” in the footer; withdrawing is as easy as consenting.

Necessary — always on:

  • Clerk sets session cookies required for login and session security.
  • Stripe sets cookies only during the checkout process on the checkout pages operated by Stripe.
  • Functional preferences (e.g. sidebar, view) are stored locally in your browser.

Optional — only with consent:

  • Analytics (PostHog, EU hosting Frankfurt): reach and usage analytics and session replays. PostHog operates in two stages: without consent it only performs anonymous reach measurement in memory — no cookie, no localStorage, no access to your device (legitimate interest, Art. 6(1)(f) GDPR). Only with your consent (Art. 6(1)(a) GDPR) does PostHog set persistent identifiers (cookie + localStorage), link the measurement to your account and record session replays. On withdrawal we switch back to the anonymous stage and delete the identifiers PostHog has set.

No third-party advertising cookies are set and no data is shared with third parties for advertising purposes.

4. Hosting (Railway)

Our application and the render service are operated at Railway; since 17 August 2026 they run in the European Union (Amsterdam, Netherlands) on Google Cloud Platform infrastructure. The provider is Railway Corporation, San Francisco, USA. Railway processes account and usage data of our account as an independent controller in the United States as well; the basis for that transfer are the EU standard contractual clauses (data processing agreement of 16 August 2026).

When the website is accessed, technically necessary data is processed (server logs):

  • IP address of the accessing device
  • Date and time of access
  • Accessed URL and HTTP status code
  • User agent (browser and operating system)
  • Referrer URL

The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the stable provision of the website). The transfer to the USA mentioned above is governed by the EU Standard Contractual Clauses (SCC, Module 2 Controller-to-Processor), which Railway's data processing agreement (DPA) incorporates (applicable law: Irish law).

Data processing agreement (DPA): railway.com/legal/dpa. List of sub-processors: trust.railway.com. Railway data protection contact: [email protected]

5. DNS and Security (Cloudflare)

To provide the domain and for security functions (protection against DDoS, SSL encryption), Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA is used. For this purpose, Cloudflare processes technically necessary connection data including the IP address.

Legal basis: Art. 6(1)(f) GDPR. Cloudflare is certified under the EU-US Data Privacy Framework.

Cloudflare privacy policy: cloudflare.com/privacypolicy

6. Waitlist (Supabase)

If you sign up for the waitlist, the following data is processed and stored in a database at Supabase PTE. LTD., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. The server location is the project region eu-west-1 (Ireland, European Union):

  • Email address
  • Your answer to the form's single question: how your brand's content has mainly been created over the past three months. You pick one of five given answers; there is no free-text field.
  • Plan, billing cycle and the occasion of the sign-up — these three follow from which button you clicked, you do not enter them.
  • Where the sign-up came from: the campaign parameters in the address you opened (utm_source, utm_medium, utm_campaign), or the referring page. This lets us tell sign-ups from different channels apart; it does not identify a person.
  • Time of registration
  • The time of your consent and the version of the consent text you agreed to

Purpose: information about the launch and about Founder offers from Ikrames, and getting in touch with you about early access. Your answer to the question above is only evaluated in aggregate across all sign-ups, so that we understand how the people interested in Ikrames work today. Legal basis: Art. 6(1)(a) GDPR — your consent, which you give explicitly when you submit the form. Without that checkbox nothing is stored.

Signing up includes a confirmation email: we send you a link, and your address counts as confirmed only once you have opened it. Until you do, we send you no further emails.

After confirming, you can optionally answer two questions about how your content gets made (monthly spend and weekly hours, each as a choice from given ranges). These answers are voluntary, the waitlist works exactly the same without them, and they fall under the same consent as your sign-up.

You can withdraw your consent at any time with effect for the future: an informal email to [email protected] is enough, and you do not have to give a reason. This does not affect the lawfulness of the processing carried out before the withdrawal.

Retention period: until you withdraw your consent, at the latest until the early-access outreach is complete. After that we delete your data or, with your consent, transfer it into a customer account.

The data is held in the EU (Ireland). As our processor, however, Supabase may also access it from outside the EU — for support and administration, or via sub-processors. That transfer is based on the EU Standard Contractual Clauses incorporated into Supabase's data processing agreement, which takes effect upon acceptance of the terms.

Supabase privacy policy: supabase.com/privacy

7. Authentication (Clerk)

For the login area, Clerk Inc., 660 King Street, San Francisco, CA 94107, USA is used. When you register or sign in, the following data is processed:

  • Email address
  • Optional: name, profile picture
  • Session data and IP address for session security
  • Timestamp of the login

Legal basis: Art. 6(1)(b) GDPR (performance of a contract). Clerk is certified under the EU-US Data Privacy Framework.

Clerk privacy policy: clerk.com/legal/privacy

8. Payment Processing (Stripe)

For the processing of payments (subscriptions, one-time purchases, Founder offers), Stripe is used. Our contracting party is Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland — a company established in the European Union. The transfer of your payment data to Stripe is therefore not a transfer to a third country. The group's parent company is Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA.

During a payment process, the following data is transmitted to Stripe and processed there:

  • Name and email address
  • Billing address (if provided)
  • Payment data (credit card information, IBAN, etc.) — this is transmitted directly from the browser to Stripe and is not stored on my servers
  • Transaction amount and currency
  • IP address for fraud prevention
  • Device information and browser metadata

The legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as Art. 6(1)(f) GDPR (legitimate interest in fraud prevention).

Stripe processes part of this data not on our behalf but as an independent controller within the meaning of Art. 4(7) GDPR — in particular to detect and prevent fraudulent transactions, to meet its own legal and regulatory obligations, and to involve banks and payment method providers. Stripe determines the purposes and means of that processing itself; it is not covered by our mandate. Stripe's own privacy policy governs in that respect.

Within the Stripe group, data may be passed on to Stripe, Inc. in the USA. Stripe is responsible for that onward transfer as our processor; it is governed by Stripe's data processing agreement, which incorporates the EU Standard Contractual Clauses.

Stripe privacy policy: stripe.com/de/privacy

9. Handling of Cancellations

When you submit a declaration through our cancellation button or our withdrawal button, we record it before we do anything else. The time of receipt is the legally decisive fact: the deadlines run from that moment, whether or not our confirmation email arrives. We process:

  • Name
  • Email address
  • Type of declaration (cancellation or withdrawal)
  • for a cancellation: ordinary or extraordinary
  • for an extraordinary cancellation: a voluntary reason. Your cancellation is just as valid without it, and we do not need any details about your health or your finances.
  • Contract designation and desired termination date, if provided
  • Time of receipt

Purpose: handling your cancellation and keeping it verifiable — the match to your contract, the termination on the correct date, and the record of when your declaration reached us. Legal basis: Art. 6(1)(b) GDPR (performance of the contract, including its termination).

We ask for nothing here beyond the statutory mandatory details — no retention offer, no survey, and no question about your reasons for an ordinary cancellation.

Recipients: the data is held in our database at Supabase (server location eu-west-1, Ireland). We send your confirmation of receipt via Resend, with a copy to our own contact address. Both providers appear with their purpose and legal basis in the overview below.

Retention period: until your account is deleted. If you delete your account, the declaration is deleted with it. Declarations we could not match to an account are kept until the case has been resolved manually; after that we delete them. You can request deletion at any time by emailing [email protected].

10. AI Services for Content Generation

Ikrames uses the following AI service providers to generate content (images, videos, audio, text):

fal.ai (Features & Labels, Inc., 2261 Market St Suite 10467, San Francisco, CA 94114, USA) — media inference (image, video, audio and transcription models). Legal basis: Art. 6(1)(b) GDPR. Data transfer to the USA on the basis of Standard Contractual Clauses. When processing personal data, we set the header X-Fal-Store-IO: 0 to suppress storage of the requests. Details: fal.ai/legal/privacy-policy

Anthropic(Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, Ireland; parent company: Anthropic PBC, San Francisco, USA) — language models (Claude) for processing content texts. Our contracting party is the Irish company; the transfer to it is therefore not a transfer to a third country. Any onward intra-group transfer to the USA is governed by Anthropic's data processing agreement, which incorporates the EU Standard Contractual Clauses. Legal basis: Art. 6(1)(b) GDPR. Inference data is not used for training. Details: anthropic.com/legal/privacy

OpenAI (OpenAI, L.L.C., USA) — transcription of voice recordings (Whisper) and text embeddings. Legal basis: Art. 6(1)(b) GDPR. Details: openai.com/policies/privacy-policy

ElevenLabs (Eleven Labs Inc., 169 Madison Ave #2484, New York, NY 10016, USA) — text-to-speech, voice clones and music generation. Legal basis: Art. 6(1)(b) GDPR. Data transfer to the USA on the basis of Standard Contractual Clauses. Details: elevenlabs.io/privacy

11. Social Media Publishing (Bundle.social)

Provider: BUNDLE sp. z o.o., ul. Hoża 86/410, 00-682 Warsaw, Poland. Data processed: connected social media accounts, OAuth tokens, post content. Processing takes place in the European Economic Area; individual subprocessors and the connected platforms may process data outside the EEA. Legal basis: Art. 6(1)(b) GDPR.

Bundle.social privacy policy: bundle.social/privacy

12. Product Improvement Through Aggregated Statistics

We analyse performance data of published content (e.g. reach, impressions, interactions, follower trends) as well as related content characteristics (e.g. format, template, time of publication) in aggregated, de-identified form across customers in order to improve Ikrames — for instance for better defaults, generation quality and planning recommendations.

The following applies: analyses are only produced above fixed minimum thresholds (several brands from several mutually independent accounts), so that no conclusions can be drawn about individual customers, brands or persons. No profiling of natural persons takes place; data is not passed on to third parties for this purpose.

The legal basis is our legitimate interest in improving and further developing the service (Art. 6(1)(f) GDPR). You may object to this processing at any time with effect for the future (Art. 21 GDPR); please contact us via the channels stated in the legal notice.

13. Overview of Recipients and Processors

As part of providing Ikrames, personal data is processed by the following service providers:

  • Railway — Hosting of the application and the render service (app data in transit, server logs). Operated in the EU (Amsterdam, Netherlands) since 17 August 2026, on Google Cloud Platform infrastructure. In addition, Railway processes account and usage data of our own account as an independent controller in the United States (basis: EU standard contractual clauses, Module 2, from the data processing agreement concluded on 16 August 2026). Provider: Railway Corporation, San Francisco, USA
  • Supabase — Database and file storage (all user data). Project region eu-west-1 (Ireland, EU)
  • Clerk — Identity and authentication (email, name, sessions)
  • Stripe — Payments and invoices
  • Bundle.social — Social media publishing, OAuth tokens of the connected channels. Provider: BUNDLE sp. z o.o., ul. Hoża 86/410, 00-682 Warsaw, Poland; processing within the European Economic Area
  • ElevenLabs — Voice clones (voice samples)
  • Anthropic — LLM processing of content texts
  • OpenAI — Whisper transcription of standalone voice recordings, embeddings
  • fal.ai — Image and video generation (prompts, in part brand images) and transcription of video audio tracks
  • Cloudflare — DNS/proxy for ikrames.com
  • PostHog — Product and reach analytics (page views, usage events) and session replays. EU hosting in Frankfurt (Germany). Anonymous reach measurement without access to your device on the basis of legitimate interest (Art. 6(1)(f) GDPR); identified analytics and session replays only with your consent (Art. 6(1)(a) GDPR). Provider: PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, USA. The data is hosted in the EU; where PostHog processes it in the USA beyond that, the EU Standard Contractual Clauses from PostHog's data processing agreement apply
  • Resend — Delivery of system and transactional emails (recipient address, subject, message content). Provider: Plus Five Five, Inc. (trading as “Resend”), 2261 Market Street #5039, San Francisco, CA 94114, USA; basis: EU standard contractual clauses. Covers the acknowledgement for cancellation/withdrawal, the purchase confirmation for digital products, and the delivery of freebies together with the corresponding confirmation and welcome email
  • Inngest — Job orchestration (event payloads containing user and content IDs and job parameters). Provider: Inngest Inc., United States; processing takes place in the USA. The EU standard contractual clauses are the envisaged basis for the transfer; the data processing agreement that makes them binding has been requested and is not yet in place
  • Evomi — Proxy for source downloads in the render service — both for retrieval via yt-dlp and for direct file downloads. For encrypted targets (HTTPS) the proxy sees only the target host, the time and the amount of data transferred, not the content transmitted; for unencrypted targets (HTTP) it also sees the content. Provider: TeraShift GmbH, Switzerland; the transfer is based on the European Commission's adequacy decision for Switzerland (Decision 2000/518/EC, Art. 45 GDPR) — standard contractual clauses are not required for it

14. Your Rights as a Data Subject

You have the following rights vis-à-vis the controller:

  • Access to the data stored about you (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to the processing (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

Account deletion (Art. 17 GDPR): You can delete your account directly in the application (Settings → “Delete account”). Deletion is immediate and final and covers all content including data held at the connected services. Invoice data remains with the payment provider due to statutory retention obligations (§ 147 AO, § 14b UStG — German tax law).

Data export (Art. 20 GDPR): You can export your data directly in the application (Settings → “Export my data”). You receive your data in a machine-readable JSON format; the download link is valid for 24 hours.

In addition, an informal email to [email protected] is sufficient to exercise your rights.

15. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data (Art. 77 GDPR). The supervisory authority responsible for me is:

Der Sächsische Datenschutz- und Transparenzbeauftragte
Devrientstraße 1
01067 Dresden
www.saechsdsb.de

16. Retention Period

Personal data is stored only for as long as is necessary for the respective purpose or as required by statutory retention periods. Server logs are deleted after 30 days at the latest. Waitlist data is stored until withdrawal of consent or until the start of the service (then, where applicable, transferred into a customer account with consent). Cancellations and withdrawals (section 9) are stored until your account is deleted.

17. SSL Encryption

For security reasons, this website uses SSL encryption. You can recognize an encrypted connection by the fact that the address bar of the browser begins with “https://”.

18. Changes to This Privacy Policy

I reserve the right to amend this privacy policy so that it always complies with the current legal requirements or in order to implement changes to my services. The new privacy policy will then apply to your next visit.

Last updated: August 2026

Cancel contracts hereWithdraw from contract