Privacy Policy
Version of 27 July 2026 · Version 2.0
1. Controller
Laurenz Fussenegger, sole trader, Dekan-Hausteiner-Weg 6, 6780 Schruns, Austria. Email: laurenz.fussenegger06@gmail.com. No data protection officer is appointed; the conditions of Art. 37 GDPR are not met.
2. In short
We process account and brand data, the content you create, and the access tokens of the social accounts you connect. We use no tracking cookies, run no web analytics and sell no data. All content is AI-generated — see clause 7.
3. Data we process
- Account data — email address, hashed password, registration and last-login timestamps.
- Brand data — the website URL you submit, the screenshot taken of it and the derived brand profile.
- Credentials for a test account you provide — only if you explicitly hand the brand scan a demo account for your own application so it can read what is behind the sign-in. The username and password are used in memory for that single run: they are not stored, not logged and never sent to the language model, and the sign-in happens in our own server function with no additional provider involved. Page text and screenshots captured there come from a restricted area and may contain third-party data, which you are responsible for supplying.
- Content data — strategies, plans, captions, images, videos, avatars, schedules and the approval status of each post.
- Material you supply — uploaded logos, photos, video and text. Where it shows or contains people, we process their data on your behalf (see the DPA).
- Connected social accounts — access and refresh tokens, account ID, handle, profile picture, granted scopes and expiry. See clause 4.
- Contract and payment data — package, subscription status, period end, credit balance, Stripe customer and subscription IDs. We never receive or store full card details.
- Usage and log data — IP address, timestamps, route, status code, user agent and error logs.
4. Social media access tokens
When you connect one of the supported platforms — Instagram, TikTok, YouTube, Facebook, Threads, X, LinkedIn, Pinterest or Bluesky — you authorise us through that platform's official OAuth flow (Instagram Business Login, with no Facebook page linkage). Bluesky offers no OAuth flow; there you create a revocable app password, which we exchange once for session tokens and do not store. We store the issued tokens and basic profile data in our EU-hosted database and in short-lived, server-only cookies. We use them exclusively to publish content you approved and to read that content's performance — never to read your messages, contacts or followers.
Tokens are deleted immediately when you disconnect under Channels or revoke access on the platform (for Instagram, Facebook and Threads, Meta notifies us of that automatically), on termination of the contract, and at the latest when they expire on the platform side (Meta: typically 60 days). See data deletion.
YouTube and Google.To connect YouTube, Share Motion uses the YouTube API Services. We only request permission to upload a video to your channel and to read your channel's name and ID, so you can see where a post goes. We do not read comments, subscribers, playlists or any other channel data. By connecting YouTube you agree to be bound by the YouTube Terms of Service, and Google's processing is governed by the Google Privacy Policy. You can revoke our access at any time via the Google security settings page; we delete the YouTube data we store when you disconnect, and at the latest 30 days after we learn of the revocation. Share Motion's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, use it for advertising, or use it to train AI models.
5. Purposes and legal bases
- Art. 6(1)(b) GDPR — performance of the contract: account, brand scan, strategy, generation, scheduling, approval, publishing, billing and support.
- Art. 6(1)(c) GDPR — legal obligations, in particular retention of invoices under § 132 BAO.
- Art. 6(1)(f) GDPR — legitimate interests: security, abuse and fraud prevention, rate limiting, diagnostics, and the establishment or defence of legal claims.
- Art. 6(1)(a) GDPR — consent, where we ask for it separately; revocable at any time with future effect.
No automated decision-making with legal effect under Art. 22 GDPR takes place. AI suggestions only take effect through your approval.
6. Recipients and third-country transfers
Processors: Supabase Inc. (database, authentication and file storage; data stored in the EU region, Frankfurt), Vercel Inc. (hosting, and the browser that opens a test account you provide during a brand scan), Anthropic PBC (language models), Features & Labels, Inc. / fal.ai (image and video generation), ElevenLabs Inc. (speech synthesis) and microlink.io (website screenshot, EU). Stripe (payments) and the social platforms you connect — Meta Platforms Ireland Ltd. (Instagram, Facebook, Threads), TikTok, Google (YouTube), X, LinkedIn, Pinterest and Bluesky — act as independent controllers for their part of the processing.
Some providers are based in the United States, so personal data is transferred to a third country under Art. 44 ff. GDPR. Transfers rely on the EU-US Data Privacy Framework adequacy decision of 10 July 2023 where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (2021/914) together with a transfer impact assessment and supplementary technical measures. The core data store — accounts, content and tokens — is kept in the EU. We never send passwords, payment data or social tokens to model providers. The full table with seats, purposes and transfer bases is in the German version.
7. AI-generated content and transparency
All content produced in the service is AI-generated. Where the platform offers a corresponding field, we set the AI-generated content flag when publishing. We treat the transparency obligations for AI-generated content under the EU AI Act (Regulation (EU) 2024/1689), applying from August 2026, as the benchmark for our own practice — this is our own commitment, not legal advice. AI output can be wrong or inconsistent; you review every post before approval, and photorealistic depictions of real people require their consent. We do not use your content to train our own models.
8. Retention
- Account, brand and content data — for the term of the contract, then deleted within 30 days unless you ask for immediate deletion.
- Access tokens — as described in clause 4.
- Invoices and accounting records — seven years after the end of the calendar year (§ 132 BAO).
- Logs and error data — 30 days maximum.
- Support correspondence — three years after the case is closed.
9. Cookies and local storage
We use only technically necessary cookies (login session, OAuth anti-forgery values, platform access data); no consent is required for these under § 165(3) TKG 2021. The app additionally keeps working state in your browser's local storage, which you can clear at any time. No web analytics, no retargeting, no ad networks.
10. Security
All transport is TLS-encrypted. Database access is restricted per account at row level, passwords are stored hashed only, and access to production data is limited to the controller. Measures are reviewed regularly.
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), and may withdraw consent at any time. Write to the address in clause 1; for account deletion see data deletion. You may also lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
12. Obligation to provide data
Email address, password and payment data are required to conclude the contract; without them no account can be maintained. Connecting a social account is voluntary — without it, only automatic publishing is unavailable.
13. Changes
We update this policy when the service, the providers we use or the law change. The version published here applies; active customers are additionally informed by email of material changes.