Skip to content

privacy policy

This is a convenience translation. Only the German version is legally binding.

This privacy policy informs you about which personal data we process when you visit our website https://app.macreto.com and use our web app "Macreto", for what purposes this is done, on what legal basis, how long we store the data and what rights you have (Art. 13 and 14 GDPR).

1. Controller

Hees & Rosenbusch CodeLabs GbR
Owner: Oliver Hees, Alina Rosenbusch
Das Ortfeld 7, 21394 Westergellersen

E-mail: info@hr-codelabs.de
Phone: +49 4135 6343997

We have not appointed a data protection officer because we are not legally obliged to do so. Please send data protection enquiries to info@hr-codelabs.de.

2. Overview: what we process

Area Typical data Legal basis
Visiting the website IP address, time, page accessed, browser information Art. 6(1)(f) GDPR
Account and login Name, e-mail address, password (only as a hash), session data Art. 6(1)(b) GDPR
Uploads and AI processing Video recordings, voice, image, transcripts, texts, project details Art. 6(1)(b) GDPR
Payments and invoices Name, address, e-mail, VAT ID, payment data (at Stripe) Art. 6(1)(b) and (c) GDPR
System e-mails E-mail address, content of the message Art. 6(1)(b) GDPR
Waiting list E-mail address, time of confirmation Art. 6(1)(a) GDPR
Feedback Your feedback, account data Art. 6(1)(b) or (f) GDPR
Audience measurement (Umami) Anonymised usage statistics without cookies Art. 6(1)(f) GDPR
Error monitoring (GlitchTip) Technical error data, account ID where applicable Art. 6(1)(f) GDPR
Partner programme Referral code, attribution, commissions, bank details Art. 6(1)(b), (c) GDPR; § 25 TDDDG
Social posting (Zernio) Connected social accounts, post content, schedule Art. 6(1)(b) GDPR

You will find the details in the following sections.

3. Hosting and provision of the website

Our website and the web app are operated on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. We also store uploaded files and generated results in Hetzner's object storage at locations in Germany. We have concluded a data processing agreement with Hetzner pursuant to Art. 28 GDPR.

When you access our pages, our server automatically processes information transmitted by your browser (server log files): IP address, date and time of access, URL accessed, amount of data transferred, HTTP status code, referrer URL, browser type and operating system.

  • Purpose: delivery of the website, security (e.g. defence against attacks), error analysis.
  • Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and stable operation of our service.
  • Storage period: server logs are automatically deleted after 14 days, unless a specific security incident requires longer retention for investigation.

The connection to our website is encrypted throughout via TLS.

4. Cookies and similar technologies

We use only a few cookies and do not use advertising or tracking cookies.

Name Purpose Duration Basis
Login session cookie (Better Auth) Keeps you logged in after login and protects against misuse Until logout or expiry of the session § 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR
macreto_sprache Remembers the language you selected (German/English); only set when you switch the language 1 year § 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR
macreto_studio Remembers which team studio you are currently working in; only with team access 1 year § 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR
macreto_kit Remembers the brand kit you last selected; only in the logged-in area 1 year § 25(2) no. 2 TDDDG, Art. 6(1)(b) GDPR

These cookies are strictly necessary so that you can use the service you have requested (your account, your chosen language and workspace); no consent is required for this. They contain no advertising or tracking identifiers and are not passed on to third parties.

Referral links without cookies: If you come to us via a referral link, we do not store anything on your device. The referral code is only carried in the address bar and appears during registration as a pre-filled field "Referral code" that is visible to you and that you can delete. We count the access to a referral link without personal data (only the time and the associated partner).

For audience measurement with Umami, no cookies are set and no information is stored on your device (see Section 11).

5. Registration and customer account

You need an account to use Macreto. In this context, we process:

  • name or display name, e-mail address, password (stored exclusively as a cryptographic hash),
  • time of registration and e-mail confirmation, any invitation or referral code used,
  • session data (login time, IP address and browser identifier of the session) to secure your account,
  • information about your brand or channel that you store in the settings (e.g. channel name, tone, links).

After registration, we send you an e-mail with a confirmation link. Your account (and, where applicable, the free trial video) is only activated after confirmation.

  • Purpose: creation and management of your account, provision of our services, protection against misuse (e.g. multiple use of the free video).
  • Legal basis: Art. 6(1)(b) GDPR (contract or pre-contractual measures); protection against misuse: Art. 6(1)(f) GDPR.
  • Storage period: for the duration of the user relationship. If you delete your account, we delete your account data immediately (database backups after 28 days at the latest), unless statutory retention obligations apply (see Section 7).

You can delete your account yourself at any time at /app/konto and download an export of your data there beforehand.

6. Uploaded recordings and AI processing

The core of Macreto is the automatic processing of your recordings. In this context, we process:

  • raw data: screen recordings (tutorials) and facecam recordings, including your image, your voice and everything that can be seen and heard on the screen or in the picture – possibly also data of third parties;
  • derived data: transcripts, analyses, scripts, titles, descriptions, thumbnails, edit lists, the finished video, Shorts and social media posts;
  • project details and your correction requests and approvals.

Transcription: The conversion of speech to text takes place by default on our own servers in Germany (software "faster-whisper"); your audio data does not leave our infrastructure. Optionally, transcription can take place via the ElevenLabs service (Scribe); in that case, the audio track is transmitted to ElevenLabs.

AI analysis and text creation: For analysis, script and texts, we transmit transcripts, texts, project details and individual still images or image excerpts from your recordings to Anthropic PBC (USA), provider of the AI model Claude. Anthropic processes this data as our processor and, according to its own statements, does not use data transmitted via the API to train its models.

AI generation of images, sound effects and music: For images, sound effects and music, we transmit exclusively text descriptions (prompts) to Kie AI, which forwards them to the respective model providers. Your recordings, your image and your voice are not transmitted. We design the prompts so that they do not contain any personal data.

Human oversight: The AI does not make any decisions about you that have legal effect (no automated decision-making within the meaning of Art. 22 GDPR). You check every result and approve it yourself.

No use for advertising purposes: We do not use your recordings and results as a reference, for advertising or for training our own AI models, unless you have expressly consented. Staff only access your content insofar as this is necessary in individual cases for support, troubleshooting or the prevention of misuse.

  • Purpose: provision of the contractually agreed service (analysis, script, editing, package).
  • Legal basis: Art. 6(1)(b) GDPR. Insofar as third parties can be seen or heard in your recordings, we process their data on the basis of Art. 6(1)(f) GDPR (interest in fulfilling the contract with you); you are responsible for ensuring that you are permitted to use these recordings. If you are an entrepreneur (Unternehmer), we process personal data in your content as your processor in accordance with our Data Processing Agreement.
  • Special categories: We do not analyse your recordings biometrically (no facial or voice recognition for identification). Should your recordings contain health data or other special categories (Art. 9 GDPR), we only process them because you upload them yourself, and only to provide the service.
  • Storage period:
    • Raw data (tutorials, facecam recordings) is automatically deleted 30 days after the last activity in the respective project.
    • Results (videos, scripts, packages, transcripts) are stored until you delete them, at the longest until your account is deleted (then immediately; in database backups for up to 28 more days).
    • Database backups are retained for 28 days and then overwritten; deleted data may still be contained in backups until then.

7. Ordering, payment and invoices (Stripe)

You conclude paid subscriptions via the payment service Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland. Stripe processes payment, invoice and tax data (including name, address, e-mail, country, VAT ID where applicable, card data or bank details, IP address for fraud prevention and location determination for VAT purposes). We do not receive the complete payment data (e.g. card number); we only see, for example, the card type and the last four digits.

We also use Stripe for the customer portal (plan changes, payment methods, cancellation), invoicing and VAT calculation (Stripe Tax).

  • Legal basis: Art. 6(1)(b) GDPR (performance of contract); Art. 6(1)(c) GDPR (obligations under tax and commercial law); fraud prevention: Art. 6(1)(f) GDPR.
  • Role of Stripe: Stripe acts partly as our processor and, for certain purposes (e.g. fraud prevention, fulfilment of its own regulatory obligations as a payment service provider), as an independent controller. Stripe's privacy notice: https://stripe.com/de/privacy. Stripe may also transfer data to Stripe, Inc. in the USA; Stripe, Inc. is certified under the EU-US Data Privacy Framework.
  • Storage period: We retain invoices and accounting vouchers for eight years in accordance with § 147 AO (German Fiscal Code) and § 257 HGB (German Commercial Code), and commercial books and other documents for up to ten years (in each case from the end of the calendar year).

8. E-mails from the service

We send you e-mails that are necessary for using the service: confirmation of your e-mail address, password reset, notices that a result is ready for review, invoice and contract information and important changes. We use the service Brevo (Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany) as a processor for sending them. The data is processed in the EU.

  • Legal basis: Art. 6(1)(b) GDPR.
  • Storage period: sending logs (recipient, time, delivery status) at the mail service are deleted after 30 days. We do not store the content of the e-mails separately.

We only send promotional e-mails (newsletters) with your consent.

9. Waiting list (double opt-in)

If you put yourself on our waiting list, we process your e-mail address in order to inform you as soon as Macreto is available to you (e.g. with an invitation code). After signing up, you will receive an e-mail with a confirmation link; your address is only added after you click on this link (double opt-in). As evidence, we store the time of sign-up and confirmation as well as the IP address used.

  • Legal basis: your consent, Art. 6(1)(a) GDPR; logging as evidence of consent is based on Art. 6(1)(c) in conjunction with Art. 7(1) GDPR.
  • Withdrawal of consent: You can unsubscribe at any time via the unsubscribe link in every e-mail or by sending a message to info@hr-codelabs.de.
  • Storage period: until you unsubscribe or until the end of the waiting list. We automatically delete unconfirmed sign-ups after 7 days. We may retain evidence of consent given for up to three years after you unsubscribe in order to be able to defend against claims.

10. Feedback and contact requests

If you give us feedback (e.g. via the feedback form in the app or as a participant in the beta phase) or contact us by e-mail, we process your information and its association with your account in order to deal with your request and improve Macreto.

  • Legal basis: Art. 6(1)(b) GDPR insofar as the feedback is part of the beta agreement or your request concerns the contract; otherwise Art. 6(1)(f) GDPR (improving our service, answering enquiries).
  • Publication: We only publish quotes or testimonials with your express consent.
  • Storage period: feedback for up to 24 months or until your account is deleted; thereafter only in anonymised form. We delete enquiries as soon as they have been dealt with conclusively and no retention obligations apply.

11. Audience measurement with Umami (self-hosted)

In order to understand how our website is used, we use the open-source software Umami, which we operate ourselves on our servers at Hetzner in Germany. Umami sets no cookies, stores nothing on your device and creates no personal usage profiles. Your IP address is not stored; visits are counted using a value that changes daily and cannot be reversed. We only receive aggregated statistics (e.g. page views, referring pages, device type, country). Data is not passed on to third parties.

  • Legal basis: Art. 6(1)(f) GDPR – legitimate interest in data-minimising analysis and improvement of our service.
  • Objection: You can object at any time, e.g. by using an ad or tracking blocker or by activating the "Do Not Track" setting in your browser.
  • Storage period: We store the statistics data for 24 months; after that it is deleted automatically.

12. Error monitoring with GlitchTip (self-hosted)

In order to detect and fix technical errors quickly, we use the open-source software GlitchTip, which we operate ourselves at Hetzner in Germany. If an error occurs, technical information is recorded: error message, time, affected function, browser and operating system, and where applicable your internal account ID. We configure GlitchTip so that no content of your recordings, no passwords and, where possible, no IP addresses are stored.

  • Legal basis: Art. 6(1)(f) GDPR – legitimate interest in a stable and secure service.
  • Storage period: error reports are automatically deleted after 90 days.

13. Partner programme (affiliate)

Every customer receives a personal referral link. For this purpose, we process:

  • For referred persons: the referral code via which you came to us (from the "Referral code" field during registration, see Section 4), the association of your account with the referring person and your payments to us (net revenue) in order to calculate the commission. The referring person does not see who you are, but only aggregated information (e.g. number of registrations, paying customers, amount of commission).

  • For partners: commission balances, payouts, name, address, bank details (IBAN), tax details (e.g. tax number, VAT ID, small business status) for the self-billing credit note (Gutschrift).

  • No cookie: We do not store anything on your device for the partner programme; attribution is based solely on the visible "Referral code" field during registration (see Section 4).

  • Legal basis: attribution and commission calculation: Art. 6(1)(f) GDPR with regard to referred persons (interest in running the partner programme) and Art. 6(1)(b) GDPR with regard to partners; credit notes: Art. 6(1)(c) GDPR.

  • Storage period: The attribution exists as long as the referred person is a paying customer and the partner programme exists; if we terminate, until the end of the 12-month run-off period (Partner Programme Terms § 8(3)). We retain credit notes for eight years (§ 147 AO).

14. Social media publishing via Zernio

If you connect your social media accounts (e.g. YouTube, Instagram, TikTok, LinkedIn) to Macreto in order to have posts published on a schedule, we use the service Zernio (Zernio Software SL, Carrer Mallorca 2A, 17230 Palamós, Girona, Spain) as a processor. The following is processed: the access authorisations (tokens) for your connected accounts, account name and ID, the content to be published (videos, texts, images), the publication time and status and statistics data of the posts.

The posts are then published via the official interfaces of the respective platform. The processing on the platform itself is governed by the privacy policy of the respective platform, with which you have a user relationship under your own responsibility. For YouTube, the YouTube Terms of Service (https://www.youtube.com/t/terms) and Google's Privacy Policy (https://policies.google.com/privacy) apply. You can disconnect access in Macreto at any time and additionally revoke it via the security settings of your Google account (https://myaccount.google.com/permissions).

  • Legal basis: Art. 6(1)(b) GDPR – the function is only used if you actively set it up.
  • Storage period: We delete access tokens as soon as you disconnect or delete your account; post data as for results (Section 6).

15. Recipients and transfers to third countries

We only pass on personal data insofar as this is necessary for the purposes stated. Recipients are primarily our service providers, whom we have carefully selected and – insofar as they act on our behalf – contractually obliged in accordance with Art. 28 GDPR. You can find a current list under Sub-processors.

Some service providers are located outside the EU or EEA (third countries), in particular in the USA:

  • Anthropic PBC (USA) – AI processing of transcripts, texts and image excerpts. Basis: the EU Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), insofar as Anthropic is certified, and in addition EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) within the framework of Anthropic's Data Processing Addendum.
  • ElevenLabs (only for optional transcription) – basis: EU-US Data Privacy Framework or EU Standard Contractual Clauses according to ElevenLabs' Data Processing Addendum.
  • Kie AI (NexusAI Services LLC, USA) – receives exclusively text prompts without personal data; to that extent, no transfer of personal data takes place.
  • Stripe – see Section 7.

Since 10 July 2023, there has been an adequacy decision for the USA for companies certified under the EU-US Data Privacy Framework. Where no certification exists, we base the transfer on EU Standard Contractual Clauses. You can request a copy of the safeguards at info@hr-codelabs.de.

In addition, we only pass data on to authorities or third parties if we are legally obliged to do so or if it is necessary to enforce our rights (Art. 6(1)(c) or (f) GDPR), for example to tax advisors or tax authorities.

16. Obligation to provide data

Providing an e-mail address and password is required for registration; payment and invoice data are required for paid plans. Without this data, we cannot conclude or perform the contract. All other information is voluntary.

17. Your rights

Subject to the respective statutory requirements, you have the following rights:

  • access to the data we store about you (Art. 15 GDPR),
  • rectification of inaccurate data (Art. 16 GDPR),
  • erasure (Art. 17 GDPR) – you can also do this yourself via /app/konto,
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR) – via the data export at /app/konto,
  • withdrawal of consent given, with effect for the future (Art. 7(3) GDPR).

Right to object (Art. 21 GDPR): Insofar as we process data on the basis of Art. 6(1)(f) GDPR (legitimate interests), you may object at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, or the processing serves the establishment, exercise or defence of legal claims. You may object to processing for direct marketing purposes at any time without giving reasons.

For all concerns, please contact us informally at info@hr-codelabs.de.

18. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority responsible for us is the data protection supervisory authority of the federal state (Bundesland) in which we have our registered office:

Die Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5, 30159 Hannover, Germany
Phone: +49 511 120-4500
E-mail: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de

19. Data security

We protect your data with technical and organisational measures, including TLS encryption of all connections, storage of passwords only as a hash, strict separation of data per customer account, restriction of access to the necessary personnel, automatic deletion periods and regular backups. Details are described in Annex 1 of our Data Processing Agreement.

20. Changes to this privacy policy

We adapt this privacy policy when our service or the legal situation changes. The version published here at any given time applies.

Last updated: [STAND fehlt]