Privacy policy
Last updated: September 25, 2026Deutsche Fassung
Draft — these texts have not been legally reviewed yet and are not final.
This policy explains which personal data we process when you use this website and our idea library, why we do it and which rights you have.
Controller
The controller under the GDPR is:
Nils Husemann
Mittelweg 51
33106 Paderborn
Germany
Email: contentlabfx@gmail.com
Overview
- Visiting the website (server log data)
- Your account (email address, password, an optional display name)
- Your workspace (saved ideas, statuses, ratings, notes, posts and the numbers you enter)
- Purchases (payment is handled by Stripe)
- Emails needed for your account and purchases
We use no analytics or advertising cookies, and we do not sell any data.
Hosting and server logs
The website runs on servers of Vercel Inc. (USA); requests are processed in the EU (Frankfurt) where possible. When you open a page, technical data is recorded automatically: IP address, date and time, the page requested, the referrer, and your browser and operating system. We need this to deliver the website and keep it secure (Art. 6(1)(f) GDPR). The provider keeps log data only for a limited time.
Visitor statistics (Vercel Web Analytics)
[paragraph on Vercel Web Analytics after legal review]
Account and sign-in
For an account we process your email address, your password (stored only as a secure hash) and, if you add one, a display name. We also store when you signed up and last signed in. The legal basis is the performance of our contract (Art. 6(1)(b) GDPR). Sign-in and the database are provided by Supabase, Inc. (USA); your data is stored in the EU (Frankfurt, Germany).
If you sign in with Google, Google Ireland Limited shares your name and email address with us. We use them only for your account.
Your workspace
Saved ideas, statuses, ratings, private notes and the posts and numbers you log are stored with your account so the workspace works (Art. 6(1)(b) GDPR). They are private: only you can see them, and we don’t use them for advertising.
Purchases and payment
Payments are processed by Stripe Payments Europe, Limited (Ireland). You enter your payment details directly on Stripe’s checkout page; we never see full card numbers. We receive the payment status, amount, currency, a customer reference and your email address, and we store which pack you bought and when, including your consent to immediate access (Art. 6(1)(b) and (c) GDPR). Stripe processes data under its own privacy policy, partly in the USA: stripe.com/privacy.
Emails
We only send emails that your account and purchases require: confirming your email address, resetting your password and confirming orders (Art. 6(1)(b) GDPR). We send them through Brevo (Paris, France). There is no newsletter.
Protection against abuse
To protect sign-up, sign-in and password resets against automated abuse, we count requests per IP address. We store only a keyed hash of the address with a counter, for at most one day (Art. 6(1)(f) GDPR; our legitimate interest is a secure service). After sign-in we also count, per account, how often checkouts are started, files downloaded and entries saved, also for at most one day.
Cookies and similar technologies
We only use strictly necessary cookies: to keep you signed in (Supabase session cookies) and, for at most 24 hours after sign-up, to remember which page to open after you confirm your email. They need no consent (§ 25(2) No. 2 TDDDG). Fonts are served from our own server; no data goes to font providers.
Links to other platforms
Ideas link to reference videos on TikTok, Instagram and YouTube. We don’t embed these videos; data only reaches those platforms when you open a link, and their privacy policies apply there.
Recipients and transfers outside the EU
Our service providers process data on our behalf (Art. 28 GDPR) or, for payments, as independent controllers. Where data reaches the USA, the transfer is based on the European Commission’s adequacy decision for the EU-US Data Privacy Framework or on standard contractual clauses (Art. 45, 46 GDPR).
How long we keep data
- Account and workspace data: until you delete your account (on the Account page).
- Purchase records: as long as commercial and tax law requires (up to ten years); after you delete your account, without your name or email address.
- Counters against abuse: at most one day.
- Server logs: for a limited time.
Your rights
You have the right to
- access (Art. 15 GDPR)
- rectification (Art. 16 GDPR)
- erasure (Art. 17 GDPR)
- restriction of processing (Art. 18 GDPR)
- data portability (Art. 20 GDPR)
- object to processing based on legitimate interests (Art. 21 GDPR)
You can delete your account yourself on the Account page. To use your other rights, email us at contentlabfx@gmail.com. You can also complain to a data protection supervisory authority, in particular in the member state where you live, work or where the alleged infringement took place (Art. 77 GDPR).
Required data and automated decisions
An account needs an email address and a password; without them we cannot provide the service. There is no automated decision-making or profiling.
Changes
We update this policy when our services change. The current version always applies.