Skip to content
Postpilot
Back to home

Privacy policy

Your data is yours. This page explains what we collect, why, where it lives, and how to get it deleted. We host everything in Germany and use no third-party tracking.

Last updated · 16 September 2026

Data controller

Burak Basci · Witte-Wie 18 · 44892 Bochum · hello@benotable.de · +49 1590 2640684

What we collect

Your account email, the social-media account handles you connect, the posts you publish through Postpilot, and the public engagement metrics (likes, comments, saves) that the platforms expose. We never collect message content from DMs unless your plan includes the inbox and you explicitly connect that platform.

Why we collect it

To deliver the service: scheduling, publishing, analytics, inbox replies. No data is sold and none is used to train external AI models. For AI text suggestions we send the content you enter (topic, brand profile, the comment to answer) to the NVIDIA NIM API (NVIDIA Corporation, Santa Clara, USA; transfer based on Standard Contractual Clauses under Art. 46 GDPR). It is processed there solely to generate the suggestion.

Where it lives

All account and content data sits in PostgreSQL and MinIO on Hetzner servers in Falkenstein, Germany. Backups are encrypted and stored in the same region. The only third-country transfers are the AI requests described above and the data Stripe needs for payment processing.

How long we keep it

Active account data lives for the life of your subscription. After cancellation we retain it for 30 days (in case you re-activate), then permanently delete. Anonymised analytics may persist longer to improve the product.

Your rights under GDPR

Access, rectification, deletion, portability, restriction, and objection — all available on request. Mail hello@benotable.de from the address registered to your account and we respond within 14 days.

Cookies and tracking

We set a functional cookie for your login session, a CSRF cookie, your language choice and your cookie decision. No tracking cookies, no third-party analytics (no Google Analytics, no Meta Pixel, no Hotjar). For error monitoring we use Sentry in its EU data centre; it processes technical error data, not your content.

Contact

Data-protection questions: hello@benotable.de. Designated Data Protection Officer (DPO) once we cross the GDPR threshold — currently not legally required.