Last updated: October 9, 2026
companycore ai UG (haftungsbeschränkt)
Sömmeringstraße 69, 50823 Cologne, Germany
Email: jan@companycore.ai
Represented by: Jan Bennefeld
Our systems consist of three separate areas, all hosted at IONOS (Germany):
In addition, we use the following service providers:
Where these service providers process personal data on our behalf, data processing agreements pursuant to Art. 28 GDPR are concluded with them. These are intended to ensure that the data is processed only in accordance with our instructions and in compliance with statutory data protection requirements.
We offer forms on our website through which you can contact us without obligation — for example to request custom trial access (e.g. without payment details, longer than 3 days or on special terms) or an intro call.
When you submit a form, we process the following information:
In addition, our hosting provider IONOS processes technical connection data (e.g. IP address, timestamp, user agent) required for proper operation and abuse prevention.
The data is used exclusively to respond to your request — for example to set up custom trial access or to arrange an intro call. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures taken at the request of the data subject) and Art. 6(1)(a) GDPR (consent) for the processing of additional voluntary information.
The form data is processed via a server-side endpoint on our IONOS server (Germany) and forwarded by email to jan@companycore.ai. No permanent storage in a database takes place in connection with the form; the data remains in our mailbox until the matter is closed.
No data is passed on to third parties. The email is sent exclusively via German IONOS mail servers.
The form contains a hidden honeypot field to protect against automated bot requests. This field is evaluated exclusively for bot detection and is not processed further.
You can object to the processing or withdraw your consent at any time by sending a short message to jan@companycore.ai. We delete your request no later than 6 months after the conversation has ended, unless statutory retention obligations require otherwise.
Registration and login in our web app take place via Supabase Auth, hosted in the EU region (eu-central-1, Frankfurt). We process the following data:
Passwords are processed exclusively by Supabase and stored securely hashed. We never have access to passwords and do not store them in our systems.
In addition, Supabase stores technical metadata such as the time of registration, the time of the last login, and the email verification status. System emails (registration confirmation, team invitations, password reset) are triggered via Supabase Auth.
This data is required to provide access to the web app (legal basis: Art. 6(1)(b) GDPR).
Accounts belong to an organization. For each member we process: email address, first name, last name, optional phone number, language, role (e.g. owner, admin, editor, viewer, customer), and status. Basic member data (name, email address, role) is visible to other members of the same organization; the "customer" role (external approvers) has no access to the member list.
Company and billing details (company name, VAT ID, billing email, address) can also be stored at the organization level. These are maintained by the owner and used exclusively for contract administration. Payment data (e.g. card or bank details) is entered directly with our payment service provider Stripe when booking; we do not store full card or bank details (see section 4 l). Legal basis: Art. 6(1)(b) GDPR.
Content created in the app – post drafts including the chat history with the AI, scheduled and published posts, uploaded media, the brand profile, and calendar data – is stored in our database and file storage (Supabase, Frankfurt). Content belongs to the respective brand or organization and is visible to the members working with that brand (depending on their role).
A post is never published without prior manual scheduling by the user. Publishing takes place exclusively on a scheduled basis for posts that the user has reviewed, approved, and scheduled with a date and time. Depending on the organization's settings, upstream approval steps (admin and/or customer approval) may apply.
We use several AI services. Each service receives only the content required for the specific feature. Passwords, social media tokens, and email addresses are never transmitted to AI services.
Anthropic (Claude) – text generation and image/brand analysis. Depending on the feature, the following is transmitted:
fal.ai – image generation. For each generation, the prompt text and the reference images required for the selected mode are transmitted – this may include: up to six reference photos of a person (see section 4 e), photos of clothing items, products, and rooms, style references, or a source image to be edited. Generated images are transferred to our file storage (Supabase, Frankfurt) immediately after generation.
xAI (Grok) – daily topic suggestions. We transmit the industry, automatically shortened versions of the elevator pitch and target audience description from the brand profile, and a list of existing topic phrases. The automatic shortening removes typical company, personal, and location references based on fixed text patterns; complete anonymization is not guaranteed in every case. The service uses a web search for research.
Website analysis: For the brand analysis, our own server retrieves the publicly accessible company website you provide (text content and a screenshot). The screenshot is used for the analysis and is not stored permanently.
Users can create a personal AI model to generate AI images featuring their own person. For this, a set of defined reference photos of a person is collected (facial shots from several angles as well as half-body and full-body shots). These photos are specially protected data, as they can enable the unique identification of a person.
The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which is requested before the model is activated. You can withdraw your consent at any time with effect for the future by deleting the model in the app or by emailing jan@companycore.ai. When a model is deleted, the stored reference photos are removed from file storage; on request, we ensure complete deletion including any residual data.
Photos of other persons: If you upload reference photos of another person (e.g. an employee), you are responsible for ensuring that their explicit consent has been obtained (see also our Terms of Service).
Anthropic, fal.ai, and xAI are providers based in the USA; processing may take place there. We base these transfers on appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses or – where applicable – the provider's certification under the EU-U.S. Data Privacy Framework. The content described in sections 4 d) and e) is transmitted – including uploaded images (including photos of persons) and document contents. Passwords, social media tokens, and email addresses are not transmitted to these providers.
Images and videos are delivered in the browser via time-limited, cryptographically signed links. A shortened validity period applies to photos of persons. Anyone in possession of a valid link can retrieve the respective file until it expires; the links are used only within the app and are passed to the respective platform when publishing so that it can retrieve the media file.
To protect against abuse, we process technical connection data (IP address, user agent, requested path, timestamp), in particular for failed login attempts, rejected registrations, and unusual access patterns. Automatic rate limits also apply; repeated failed logins lead to a temporary lockout. The legal basis is our legitimate interest in secure and stable operation (Art. 6(1)(f) GDPR). We retain these logs only for as long as necessary for these purposes.
Neither our website nor our web app uses cookies, tracking, or analytics services. No content from advertising or analytics third parties is loaded; fonts are served locally from our own servers. Exception: when you book a plan, our payment service provider Stripe may set its own cookies required for payment processing and fraud prevention (see section 4 l).
The web app stores technically necessary data in your browser's storage: in sessionStorage, the session tokens and an excerpt of your profile (removed on logout or when the tab is closed); in localStorage, UI preferences such as language, color scheme, active brand, and interface states. This data remains on your device and is not transmitted to third parties. Legal basis: § 25(2) no. 2 TDDDG (technical necessity).
For the photo session, the app can access the device camera (without microphone) after your explicit permission in the browser. Capture takes place locally in your browser; only the photos you actively take are transmitted.
AI-generated images with a realistic appearance are marked with a visible label ("KI-GENERIERT" / AI-generated; cf. Art. 50 of the EU AI Act). When publishing to Instagram, the platform's self-disclosure for AI-generated content is additionally set.
If you book a plan online in the app, we process the payment via the payment service provider Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland). Stripe processes the data required for the payment, in particular name, email address, billing address, payment method (e.g. card details or IBAN), amount and time of payments, and technical data for fraud prevention. You enter your payment details directly with Stripe; we do not store full card or bank details.
The legal basis is Art. 6(1)(b) GDPR (performance of contract) and, for retaining billing records, Art. 6(1)(c) GDPR (commercial and tax retention obligations). For certain processing, such as fraud prevention and compliance with its own legal obligations, Stripe acts as an independent controller. In this context, data may be transferred to Stripe, Inc. in the USA; such transfers are based on appropriate safeguards under Art. 44 et seq. GDPR, in particular EU Standard Contractual Clauses or — where applicable — certification under the EU-U.S. Data Privacy Framework. More information: stripe.com/privacy.
We send members notifications about events in the app, for example failed or upcoming publications, expiring or disconnected social media connections, and approvals. For this we process the email address, first name, language and the event data concerned (post title, scheduled time, platform, error reason). Emails are sent through our email service provider (the same SMTP access used for system emails, see section 2); each email is stored in our database (Supabase, Frankfurt) before it is sent. We retain the sending log for as long as it is needed to prove delivery and to troubleshoot errors.
Each member decides under "Notifications" in the settings which messages they receive in the app and by email; owners and admins determine which roles are notified for which event. The legal basis is Art. 6(1)(b) GDPR (performance of the contract) and, for optional notifications, Art. 6(1)(f) GDPR (legitimate interest).
Our app offers the option of connecting LinkedIn accounts in order to automatically publish manually reviewed and scheduled content.
With the LinkedIn OAuth connection, we receive:
The name of the connected LinkedIn profile is displayed in the app so that it is clear which account is used for publishing; it is therefore also visible to other members working with the same brand.
We do not read contacts, third-party profiles, messages, or follower lists. Engagement data on your own posts (e.g. reactions and comments) is currently not retrieved; should this feature be activated, we will update this policy beforehand.
Tokens are stored encrypted with AES-256-GCM in our Supabase database. They are used exclusively to publish posts that the user has previously approved and scheduled.
Retention: Tokens are stored for as long as the connection is active. When the connection is disconnected or upon your request (e.g. by email), all tokens are deleted immediately and completely.
The access tokens are renewed automatically in the background for as long as the connection exists. If an access token can no longer be renewed permanently (e.g. because it has expired or you revoked it with the platform), we disconnect the connection, delete the stored tokens and inform the responsible members (see section 4 m). Posts that have already been scheduled are retained and may need to be rescheduled after you reconnect.
Users can disconnect the LinkedIn account at any time:
All stored LinkedIn tokens are deleted immediately and completely from our system when the connection is disconnected. Posts already published on LinkedIn remain unaffected.
Our app offers the option of connecting Facebook and Instagram accounts in order to automatically publish manually reviewed and scheduled content on these platforms. The integration uses official OAuth flows of the Meta Graph API.
When connecting via Facebook Login, we receive:
When connecting via Instagram Login, we receive:
We do not read contacts, third-party profiles, messages, or follower lists. We do not retrieve comment texts or profile data of commenting persons. Aggregated engagement counts for your own posts (e.g. number of likes and comments) may be retrieved to display post performance.
Facebook Login:
Instagram Login (direct):
When publishing, we transmit to the respective platform: the post text, the media files (via a time-limited retrieval link or, for LinkedIn, via direct upload), optional alt texts you have written, and – if set by you – tags and collaborator accounts (Instagram usernames of third parties, for tags including the position in the image). If a media item is AI-generated, the corresponding self-disclosure is additionally set on Instagram. Tags and collaborator accounts are entered by you; please note section 9 in this regard.
All Meta tokens are stored encrypted with AES-256-GCM in our Supabase database (EU-central-1, Frankfurt). They are used exclusively to publish posts that the user has actively approved and scheduled on the selected platforms.
Retention: Tokens are stored for as long as the connection is active. Upon disconnection, an automatic deletion request from Meta, or upon your request, all tokens are deleted immediately and completely.
The access tokens are renewed automatically in the background for as long as the connection exists. If an access token can no longer be renewed permanently (e.g. because it has expired or you revoked it with the platform), we disconnect the connection, delete the stored tokens and inform the responsible members (see section 4 m). Posts that have already been scheduled are retained and may need to be rescheduled after you reconnect.
As with LinkedIn, the same applies to Facebook and Instagram: no post is ever published without explicit manual scheduling by the user. The AI creates suggestions; publishing itself only takes place for posts that the user has reviewed and deliberately scheduled with a date and time.
Users can revoke the Meta connection at any time:
Meta automatically sends us a deletion request as soon as a user removes the
app on Meta's side. Our systems process this request via a cryptographically
signed endpoint (/meta/data-deletion) and delete
immediately and completely:
After deletion, the user receives a publicly accessible status URL with a confirmation code, under which the status of the deletion request can be checked at any time.
Our app lets you connect a TikTok account so that manually reviewed and scheduled video and photo posts are automatically published to TikTok. The integration uses the official TikTok Login Kit and the TikTok Content Posting API (Direct Post). The recipient of the data is TikTok Technology Limited, Dublin, Ireland.
When you connect, we receive: your TikTok account identifier (open_id), display name and a profile picture address (not displayed in our app) via user.info.basic, your username (@…) via creator_info (Content Posting API), an access token (valid 24 hours), and a refresh token (valid 365 days from first issuance; replaced by a new one on every refresh). When the post editor opens and again right before every publish, we fetch your account's current status (creator_info): whether comments, duet and stitch are allowed on this account, which visibility levels are available, and the maximum video length. We hold this information only transiently (at most 60 seconds) in memory.
We do not read your contacts, follower lists, direct messages, other people's comments, or your video list. Mentioned or tagged TikTok accounts of other users are not looked up via the API.
When publishing, we send to TikTok: the video or photo file(s), the post text as caption (or, for photo posts, title and description), the visibility level you chose yourself (never pre-selected by us), your comment/duet/stitch settings, your commercial-disclosure choice (Your brand / Branded content), and – if the media is AI-generated or AI-edited – the corresponding self-disclosure. TikTok fetches the file from our server via a time-limited, cryptographically signed link.
Before every publish we show you a preview and require you to explicitly confirm TikTok's required consent statement (Music Usage Confirmation or Branded Content Policy); we record which member of your organisation confirmed it and when.
All TikTok tokens are stored AES-256-GCM encrypted in our database (Supabase, region eu-central-1, Frankfurt, Germany) and used exclusively to publish posts you have actively reviewed and scheduled. Until TikTok grants our Content Posting API audit, TikTok itself restricts every post to "Only me", regardless of the visibility you chose.
While the connection is active, we renew the access token automatically in the background. If it can no longer be renewed (e.g. because it has expired or you revoked access at TikTok), we disconnect the account, delete the stored tokens and inform the responsible members (see section 4 m). Posts already scheduled are kept and may need to be rescheduled after reconnecting.
You can disconnect TikTok at any time:
Disconnecting in our app immediately removes the stored TikTok tokens, the account data (account identifier, display name, username) and the copy of account identifier and display name carried by scheduled and published posts for display. Your calendar keeps the posts themselves (text, media, status) and the link to a post already published. Posts already published on TikTok are unaffected; they can only be edited or deleted in the TikTok app.
The legal basis is Art. 6(1)(b) GDPR (performance of the contract); connecting is voluntary and happens only at your explicit request.
Our app lets you connect a YouTube channel so that manually reviewed and scheduled short videos (YouTube Shorts) are automatically uploaded. The integration uses Google's YouTube API Services (YouTube Data API v3). The recipient of the data is Google Ireland Limited, Dublin, Ireland.
Use of YouTube API Services: By connecting your YouTube account, you agree to companycore's use of YouTube API Services and to be bound by the YouTube Terms of Service. The Google Privacy Policy additionally applies. You can revoke companycore's access to your Google account at any time via the Google security settings.
When you connect, we receive: your YouTube channel identifier, channel title, channel handle (@handle) and a channel picture address (not displayed in our app), plus an access token (valid about one hour) and, on first consent, a refresh token. We refresh the channel title and handle via the API at least every 30 days. After an upload we read the processing status of that video we uploaded only. A Google account without its own YouTube channel cannot be connected; only the channel owner (or someone with brand account access) can connect it.
We do not read your subscribers, comments, other videos on your channel, or analytics data.
We deliberately do not request the broader youtube / youtube.force-ssl scopes, which would allow editing or deleting content directly on YouTube.
When uploading, we send to YouTube: the video file, a public title you have confirmed (up to 100 characters), a description you have confirmed (up to 5,000 bytes), the visibility you chose (public, private or unlisted), your "made for kids" designation (yes/no), your "allow embedding" and "notify subscribers" settings, and – if the video contains realistic AI-generated or AI-altered content – your corresponding self-disclosure. We never change your title or description on our own and never add our own text.
Until Google completes our YouTube API compliance audit, YouTube forces every uploaded video to "private" – regardless of the visibility chosen in our app.
If you mention another YouTube channel by @handle in a description, our server checks with an API key whether that channel exists. Only public channel data (id, title, handle) is read; your access token is not used for this. The result is held transiently in memory for at most 7 days and never stored in a database.
All YouTube tokens are stored AES-256-GCM encrypted in our database (Supabase, region eu-central-1, Frankfurt, Germany). If you disconnect in our app, we revoke the token with Google and immediately delete all YouTube account data stored with us (Authorized Data under the YouTube API Services Terms of Service): the tokens, channel identifier, channel title and handle, and the copy of channel identifier and title carried by scheduled and published posts for display. Your calendar keeps the posts themselves (text, video, status) and the link to a video already published. If you instead revoke access via the Google security settings, we detect this at the latest during the next regular refresh (every 29 days) or on the next access attempt and then immediately delete all YouTube account data stored with us, including the copies on posts – in any case within 30 days of your revocation. The stored channel title (including the copies on posts) is refreshed or deleted at least every 30 days.
Disconnecting or deleting at companycore does not delete any videos on YouTube. Videos already uploaded stay on your channel and can only be edited or deleted in YouTube Studio.
companycore's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube data for advertising, for training AI models, or share it with third parties.
You can disconnect YouTube at any time:
The legal basis is Art. 6(1)(b) GDPR (performance of the contract); connecting is voluntary and happens only at your explicit request.
In some places, users can enter or upload data of third parties – for example, Instagram usernames for tags and collaborations, alt texts, photos showing other persons, or reference photos of other persons for an AI model. We process this data exclusively to provide the respective feature (e.g. publishing the post with the tag, image generation). The user is responsible for the lawfulness of the input – in particular any required consents of the persons depicted or tagged (see our Terms of Service). Data subjects can contact jan@companycore.ai at any time.
We only share personal data if:
We never sell data and do not transmit anything to uninvolved third parties.
In addition, you can request the deletion of your data at any time by email to jan@companycore.ai.
You have the following rights under the GDPR:
Contact: jan@companycore.ai
Right to lodge a complaint with a supervisory authority: Without prejudice to other remedies, you have the right to lodge a complaint with a data protection supervisory authority, in particular the authority responsible for your place of residence or work (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestr. 2-4, 40213 Düsseldorf, Germany.
We reserve the right to amend this privacy policy as necessary.