Last updated: August 12, 2026
companycore ai UG (haftungsbeschränkt)
Sömmeringstraße 69, 50823 Cologne, Germany
Email: jan@companycore.ai
Represented by: Jan Bennefeld
Our systems consist of three separate areas, all hosted at IONOS (Germany):
In addition, we use the following service providers:
Where these service providers process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR are concluded with them. These are intended to ensure that the data is processed only in accordance with our instructions and in compliance with statutory data protection requirements.
We offer a form on our website through which you can request a non-binding 3-day trial access.
When you submit the form, we process the following information:
In addition, our hosting provider IONOS processes technical connection data (e.g. IP address, timestamp, user agent) required for proper operation and abuse prevention.
The data is used exclusively to respond to your request and to set up trial access together with you. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures taken at the request of the data subject) and Art. 6(1)(a) GDPR (consent) for the processing of additional voluntary information.
The form data is processed via a server-side endpoint on our IONOS server (Germany) and forwarded by email to jan@companycore.ai. No permanent storage in a database takes place in connection with the form; the data remains in our mailbox until the matter is closed.
No data is passed on to third parties. The email is sent exclusively via German IONOS mail servers.
The form contains a hidden honeypot field to protect against automated bot requests. This field is evaluated exclusively for bot detection and is not processed further.
You can object to the processing or withdraw your consent at any time by sending a short message to jan@companycore.ai. We delete your request no later than 6 months after the conversation has ended, unless statutory retention obligations require otherwise.
Registration and login in our web app take place via Supabase Auth, hosted in the EU region (eu-central-1, Frankfurt). We process the following data:
Passwords are processed exclusively by Supabase and stored securely hashed. We never have access to passwords and do not store them in our systems.
In addition, Supabase stores technical metadata such as the time of registration, the time of the last login, and the email verification status. System emails (registration confirmation, team invitations, password reset) are triggered via Supabase Auth.
This data is required to provide access to the web app (legal basis: Art. 6(1)(b) GDPR).
Accounts belong to an organization. For each member we process: email address, first name, last name, optional phone number, language, role (e.g. owner, admin, editor, viewer, customer), and status. Basic member data (name, email address, role) is visible to other members of the same organization; the "customer" role (external approvers) has no access to the member list.
Company and billing details (company name, VAT ID, billing email, address) can also be stored at the organization level. These are maintained by the owner and used exclusively for contract administration. Payment data (credit cards, bank details) is not processed in the app. Legal basis: Art. 6(1)(b) GDPR.
Content created in the app – post drafts including the chat history with the AI, scheduled and published posts, uploaded media, the brand profile, and calendar data – is stored in our database and file storage (Supabase, Frankfurt). Content belongs to the respective brand or organization and is visible to the members working with that brand (depending on their role).
A post is never published without prior manual scheduling by the user. Publishing takes place exclusively on a scheduled basis for posts that the user has reviewed, approved, and scheduled with a date and time. Depending on the organization's settings, upstream approval steps (admin and/or customer approval) may apply.
We use several AI services. Each service receives only the content required for the specific feature. Passwords, social media tokens, and email addresses are never transmitted to AI services.
Anthropic (Claude) – text generation and image/brand analysis. Depending on the feature, the following is transmitted:
fal.ai – image generation. For each generation, the prompt text and the reference images required for the selected mode are transmitted – this may include: up to six reference photos of a person (see section 4 e), photos of clothing items, products, and rooms, style references, or a source image to be edited. Generated images are transferred to our file storage (Supabase, Frankfurt) immediately after generation.
xAI (Grok) – daily topic suggestions. We transmit the industry, automatically shortened versions of the elevator pitch and target audience description from the brand profile, and a list of existing topic phrases. The automatic shortening removes typical company, personal, and location references based on fixed text patterns; complete anonymization is not guaranteed in every case. The service uses a web search for research.
Website analysis: For the brand analysis, our own server retrieves the publicly accessible company website you provide (text content and a screenshot). The screenshot is used for the analysis and is not stored permanently.
Users can create a personal AI model to generate AI images featuring their own person. For this, a set of defined reference photos of a person is collected (facial shots from several angles as well as half-body and full-body shots). These photos are specially protected data, as they can enable the unique identification of a person.
The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which is requested before the model is activated. You can withdraw your consent at any time with effect for the future by deleting the model in the app or by emailing jan@companycore.ai. When a model is deleted, the stored reference photos are removed from file storage; on request, we ensure complete deletion including any residual data.
Photos of other persons: If you upload reference photos of another person (e.g. an employee), you are responsible for ensuring that their explicit consent has been obtained (see also our Terms of Service).
Anthropic, fal.ai, and xAI are providers based in the USA; processing may take place there. We base these transfers on appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses or – where applicable – the provider's certification under the EU-U.S. Data Privacy Framework. The content described in sections 4 d) and e) is transmitted – including uploaded images (including photos of persons) and document contents. Passwords, social media tokens, and email addresses are not transmitted to these providers.
Images and videos are delivered in the browser via time-limited, cryptographically signed links. A shortened validity period applies to photos of persons. Anyone in possession of a valid link can retrieve the respective file until it expires; the links are used only within the app and are passed to the respective platform when publishing so that it can retrieve the media file.
To protect against abuse, we process technical connection data (IP address, user agent, requested path, timestamp), in particular for failed login attempts, rejected registrations, and unusual access patterns. Automatic rate limits also apply; repeated failed logins lead to a temporary lockout. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). We retain these logs only for as long as necessary for these purposes.
Neither our website nor our web app uses cookies, tracking, or analytics services. No content from advertising or analytics third parties is loaded; fonts are served locally from our own servers.
The web app stores technically necessary data in your browser's storage: in sessionStorage, the session tokens and an excerpt of your profile (removed on logout or when the tab is closed); in localStorage, UI preferences such as language, color scheme, active brand, and interface states. This data remains on your device and is not transmitted to third parties. Legal basis: § 25(2) no. 2 TDDDG (technical necessity).
For the photo session, the app can access the device camera (without microphone) after your explicit permission in the browser. Capture takes place locally in your browser; only the photos you actively take are transmitted.
AI-generated images with a realistic appearance are marked with a visible label ("KI-GENERIERT" / AI-generated; cf. Art. 50 of the EU AI Act). When publishing to Instagram, the platform's self-disclosure for AI-generated content is additionally set.
Our app offers the option of connecting LinkedIn accounts in order to automatically publish manually reviewed and scheduled content.
With the LinkedIn OAuth connection, we receive:
The name of the connected LinkedIn profile is displayed in the app so that it is clear which account is used for publishing; it is therefore also visible to other members working with the same brand.
We do not read contacts, third-party profiles, messages, or follower lists. Engagement data on your own posts (e.g. reactions and comments) is currently not retrieved; should this feature be activated, we will update this policy beforehand.
Tokens are stored encrypted with AES-256-GCM in our Supabase database. They are used exclusively to publish posts that the user has previously approved and scheduled.
Retention: Tokens are stored for as long as the connection is active. When the connection is disconnected or upon your request (e.g. by email), all tokens are deleted immediately and completely.
Users can disconnect the LinkedIn account at any time:
All stored LinkedIn tokens are deleted immediately and completely from our system when the connection is disconnected. Posts already published on LinkedIn remain unaffected.
Our app offers the option of connecting Facebook and Instagram accounts in order to automatically publish manually reviewed and scheduled content on these platforms. The integration uses official OAuth flows of the Meta Graph API.
When connecting via Facebook Login, we receive:
When connecting via Instagram Login, we receive:
We do not read contacts, third-party profiles, messages, or follower lists. We do not retrieve comment texts or profile data of commenting persons. Aggregated engagement counts for your own posts (e.g. number of likes and comments) may be retrieved to display post performance.
Facebook Login:
Instagram Login (direct):
When publishing, we transmit to the respective platform: the post text, the media files (via a time-limited retrieval link or, for LinkedIn, via direct upload), optional alt texts you have written, and – if set by you – tags and collaborator accounts (Instagram usernames of third parties, for tags including the position in the image). If a media item is AI-generated, the corresponding self-disclosure is additionally set on Instagram. Tags and collaborator accounts are entered by you; please note section 7 in this regard.
All Meta tokens are stored encrypted with AES-256-GCM in our Supabase database (EU-central-1, Frankfurt). They are used exclusively to publish posts that the user has actively approved and scheduled on the selected platforms.
Retention: Tokens are stored for as long as the connection is active. Upon disconnection, an automatic deletion request from Meta, or upon your request, all tokens are deleted immediately and completely.
As with LinkedIn, the same applies to Facebook and Instagram: no post is ever published without explicit manual scheduling by the user. The AI creates suggestions; publishing itself only takes place for posts that the user has reviewed and deliberately scheduled with a date and time.
Users can revoke the Meta connection at any time:
Meta automatically sends us a deletion request as soon as a user removes the
app on Meta's side. Our systems process this request via a cryptographically
signed endpoint (/meta/data-deletion) and delete
immediately and completely:
After deletion, the user receives a publicly accessible status URL with a confirmation code, under which the status of the deletion request can be checked at any time.
In some places, users can enter or upload data of third parties – for example, Instagram usernames for tags and collaborations, alt texts, photos showing other persons, or reference photos of other persons for an AI model. We process this data exclusively to provide the respective feature (e.g. publishing the post with the tag, image generation). The user is responsible for the lawfulness of the input – in particular any required consents of the persons depicted or tagged (see our Terms of Service). Data subjects can contact jan@companycore.ai at any time.
We only share personal data if:
We never sell data and do not transmit anything to uninvolved third parties.
In addition, you can request the deletion of your data at any time by email to jan@companycore.ai.
You have the following rights under the GDPR:
Contact: jan@companycore.ai
Right to lodge a complaint with a supervisory authority: Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular the authority responsible for your place of residence or work (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestr. 2-4, 40213 Düsseldorf, Germany.
We reserve the right to amend this privacy policy as necessary.