Last updated: July 2026
1. CONTROLLER
The controller responsible for data processing on this website and in the Maebe application is:
Kristof Puller
Toulouser Allee 7
40211 Düsseldorf
Germany
Email: datenschutz@maebe.app
Phone: +49 176 21800566
Hereinafter also referred to as "we", "us" or "Maebe".
2. GENERAL INFORMATION
2.1 What we collect
We collect personal data when you visit our website, register, use our application, communicate with us or make payments. "Personal data" means any information that relates to you as an individual.
2.2 Your rights
You have the right at any time to:
- Obtain information about the data we store about you (Art. 15 GDPR)
- Request the correction of inaccurate data (Art. 16 GDPR)
- Request the erasure of your data (Art. 17 GDPR)
- Request the restriction of processing (Art. 18 GDPR)
- Receive your data in a portable format (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw consent you have given (Art. 7(3) GDPR)
- Lodge a complaint with a supervisory authority
To exercise your rights, please contact: datenschutz@maebe.app
2.3 Competent supervisory authority
State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen)
Kavalleriestraße 2-4
40213 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
3. SSL/TLS ENCRYPTION
For security reasons and to protect the transmission of confidential content, this site uses SSL/TLS encryption. You can recognize an encrypted connection by the browser's address line changing from "http://" to "https://" and by the padlock symbol in your browser bar.
4. DATA COLLECTION ON OUR WEBSITE AND IN OUR APPLICATION
4.1 Server log files
When you visit our website, the following data is automatically stored in what are known as server log files:
- IP address (anonymized)
- Date and time of the request
- Time zone difference from Greenwich Mean Time (GMT)
- Content of the request (the specific page)
- Access status / HTTP status code
- Amount of data transferred in each case
- Website from which the request originates
- Browser, operating system and language
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the technical provision and security of our website).
Storage period: 14 days, then automatic deletion.
4.2 Registration and user account
When you register, we collect the following data:
- Name (first and last name)
- Email address
- Password (stored encrypted using bcrypt)
- Optional: company name, VAT ID (for B2B invoices)
- Optional: profile picture
- Optional: time zone and language setting
Registration/login via third-party providers (single sign-on): Alternatively, you can register and log in using "Sign in with Google" or "Sign in with Apple". In this case we receive from Google or Apple the data required to create the account (name, email address, unique user identifier). The privacy policy of the respective provider applies in addition (see 5.10 Google and 5.9 Apple).
Purpose of processing: Creation and management of your user account, authentication, provision of the contractually agreed service.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(a) GDPR (consent for optional information and when using single sign-on).
Storage period: For as long as your account exists. After termination, deletion within 30 days, unless statutory retention obligations apply (accounting data 10 years pursuant to Section 147 of the German Fiscal Code, AO).
4.3 Uploaded content (media and posts)
When you upload images, videos, text (captions) and other media via Maebe, these are stored on our servers and in our object storage. This content may contain personal data (e.g. depicted individuals).
Purpose of processing: Provision of the platform functions (storage, editing, approval, publishing to social media platforms, download).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Important notes on uploaded content:
- As a user, you are responsible for holding the necessary rights (e.g. copyrights, personality rights of depicted individuals) to the content you upload.
- You are responsible for obtaining any required consent from depicted individuals (Art. 6(1)(a) GDPR or Section 22 of the German Art Copyright Act, KUG).
- For B2B customers processing third-party data, the separately concluded data processing agreement (DPA) applies.
Storage period: For as long as you keep the content in your account or as long as your account exists. After termination, retention as a backup for 30 days, then deletion.
4.4 Approval links for external persons
Maebe allows you to generate approval links that give external persons (e.g. artists, clients, approvers) access to certain content. When you share such a link, the following data of the external person is processed:
- IP address (at the time of an approval action, as part of the approval log)
- Time of access or action
- Entered PIN (for authentication; stored as a hash)
- Actions taken by the external user (selection, ordering, caption adjustments, comments, approval confirmation, reasons for rejection)
- Optional: name and role of the external approver (if provided by the main user)
Purpose and necessity of storing the IP: In the event of an approval or rejection action, we log the IP address together with a timestamp and PIN record in order to provide a reliable and audit-proof record of the approval (evidence of who approved which content and when). Without this record, the approval would lose its evidentiary value.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the functioning of the platform and in the verifiability of approvals granted).
Storage period: Until the post or account is deleted by the main user.
4.5 Direct publishing to social media platforms
Maebe enables the direct publishing of approved posts to third-party platforms (Instagram, TikTok, YouTube, LinkedIn, WhatsApp and XING). Publishing is carried out via our technical aggregator (see 5.8).
Purpose of processing: Transmission of approved media, captions and publishing metadata to the selected third-party platform; receipt of status webhooks (successfully published, failed, etc.).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Important: As soon as a post has been transmitted to a social media platform, the respective privacy policy of the target platform additionally applies. Maebe has no influence over further processing by the target platform.
4.6 Push notifications (iOS app and web)
If you enable push notifications, we send you notifications about approval requests, comments and status changes. We distinguish two channels:
- iOS app: We process your APNs device token (Apple Push Notification service, see 5.9).
- Browser (web push): We process the push subscription provided by your browser (endpoint URL of your browser vendor's push service as well as cryptographic keys). Delivery takes place via the Web Push protocol (VAPID); the actual delivery is handled by the push service of the respective browser vendor.
Purpose of processing: Sending push notifications.
Legal basis: Art. 6(1)(a) GDPR (consent via the operating system or browser).
Storage period: Until the push permission is withdrawn, the device/browser is unsubscribed, or the app is uninstalled.
4.7 Newsletter
You can subscribe to our newsletter with product news, tips and information about new features — during registration or later in your account settings. The newsletter is sent in the language you have selected (German or English).
We use a double opt-in procedure: after signing up, you receive an email with a confirmation link. Only once you click this link are you added to the mailing list. We log the time of your sign-up and of your confirmation in order to be able to demonstrate consent.
Data processed: email address, first and last name, language setting, and the times of sign-up and confirmation. Sending and list management are handled by our service provider Brevo (see 5.4); the data remains in the EU.
Purpose of processing: sending the newsletter.
Legal basis: Art. 6 (1)(a) GDPR (consent).
Withdrawal: you can withdraw your consent at any time with effect for the future — via the unsubscribe link in every newsletter email or via the toggle in your account settings. After withdrawal, you are removed from the mailing list.
Storage period: until you withdraw your consent or your account is deleted.
4.8 Contact form
You can send us a message via the contact form on our website. Your enquiry is created as a case in our support system and handled there (see 5.12).
Data processed: name, email address, subject and content of your message, the time of the enquiry, and technical details of the submission (page visited, browser identification). If you are signed in, the enquiry is linked to your user account.
Purpose of processing: handling and answering your enquiry.
Legal basis: Art. 6 (1)(b) GDPR (pre-contractual measures or performance of a contract), otherwise Art. 6 (1)(f) GDPR (legitimate interest in answering enquiries).
Storage period: until your enquiry has been dealt with conclusively; beyond that, insofar as statutory retention periods apply.
4.9 Enquiries from non-profit organisations
On our page for non-profit organisations you can send us an enquiry about our offer using a form. This enquiry is not stored in our database; it is transmitted solely by email to our mailbox and handled there.
Data processed: name of the organisation, website and social media profile, legal form, details of the size of the organisation, your description of your work and your needs, the plan you are interested in, and the name, email address and telephone number of the contact person. We also send an automatic acknowledgement of receipt to the email address provided.
Purpose of processing: reviewing and answering your enquiry and, where applicable, initiating a contract.
Legal basis: Art. 6 (1)(b) GDPR (pre-contractual measures).
Storage period: the email is deleted once your enquiry has been dealt with conclusively and no statutory retention obligations apply. If a contract is concluded, the periods set out in section 9 apply.
5. SERVICE PROVIDERS AND THIRD PARTIES USED
In providing Maebe, we rely on carefully selected third-party providers. We have concluded data processing agreements (DPAs) pursuant to Art. 28 GDPR with all providers, insofar as processing on our behalf within the meaning of the GDPR takes place.
5.1 Hetzner Online GmbH (hosting & storage)
Provider: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany.
Purpose: Hosting of the Maebe application (server, database) and storage of media files (object storage, S3 API).
Data location: Falkenstein and Nuremberg, Germany.
Data transferred: All data processed in the application (technically mandatory, as the server is hosted at Hetzner).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract), Art. 28 GDPR (processing on behalf).
DPA: Concluded.
Hetzner privacy policy: https://www.hetzner.com/de/rechtliches/datenschutz/
5.2 BunnyWay d.o.o. (Bunny CDN and Bunny Stream — delivery and video streaming of media files)
Provider: BunnyWay d.o.o., Cesta Komandanta Staneta 4A, 1215 Medvode, Slovenia.
Purpose: Delivery of media files (images, videos, thumbnails) via a content delivery network with a global edge cache. Bunny sits in front of our Hetzner object storage and speeds up content loading worldwide. In addition, the Bunny Stream service creates compressed streaming versions of uploaded videos in multiple quality levels (adaptive preview playback) and delivers them. These derived video versions are stored persistently with Bunny and are automatically deleted together with the associated media item.
Data location: Slovenia (EU). Edge caches are distributed globally; origin pulls are made from the Hetzner object storage in Germany. The streaming versions (Bunny Stream) are stored in Frankfurt am Main (Germany).
Data transferred: IP address (anonymized), HTTP request headers (user agent, referer), requested file URLs, timestamps, cache status. For Bunny Stream additionally: video content of the uploaded media (derived streaming versions).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the high-performance and reliable delivery of media files).
DPA: Concluded.
Bunny privacy policy: https://bunny.net/privacy
5.3 Lemon Squeezy (payment processing — Merchant of Record)
Provider: Sold through Link, LLC (f/k/a Lemon Squeezy LLC), 222 South Main Street, Suite 500, Salt Lake City, UT 84101, USA.
Purpose: Payment processing, invoicing and subscription management. Lemon Squeezy acts as the "Merchant of Record" — meaning Lemon Squeezy concludes the purchase contract for the payment with you and issues your invoice. Maebe is the content provider of the underlying service.
Data location: USA. Lemon Squeezy uses global cloud infrastructure.
Data transferred: Name, email address, billing address, VAT ID (B2B), payment data (card number, IBAN, PayPal identifier — depending on the chosen method), transaction data, order history.
Important: The full payment data (e.g. credit card number) is processed exclusively by Lemon Squeezy and its sub-processors (PCI-DSS certified) and is never stored on our servers. From Lemon Squeezy, Maebe only receives status webhooks and billing metadata (e.g. order number, amount, selected plan), no full payment data.
Note on the iOS app: No purchases or subscriptions are concluded in the iOS app. Bookings and payments are made exclusively via our website in the browser.
Data transfer to the USA: Lemon Squeezy is certified under the EU-U.S. Data Privacy Framework. In addition, Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR are in place.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Lemon Squeezy privacy policy: https://www.lemonsqueezy.com/privacy
5.4 Sendinblue/Brevo SAS (email delivery and newsletter)
Provider: Sendinblue SAS (brand name: Brevo), 106 Boulevard Haussmann, 75008 Paris, France.
Purpose: Sending transactional emails (e.g. registration confirmation, password reset, approval notifications, activity notices, digest emails, reminders) and the newsletter.
Data location: France (EU).
Data transferred: Email address, name, email content, delivery metadata (time, delivery status, bounce status).
Newsletter: The newsletter is sent using the double opt-in procedure. When you sign up, you receive a confirmation email; you are only added to the mailing list after clicking the confirmation link. The sign-up is logged (IP address, time). You can unsubscribe from the newsletter at any time via the unsubscribe link in every email or by emailing datenschutz@maebe.app.
Legal basis:
- Transactional emails: Art. 6(1)(b) GDPR (performance of a contract).
- Newsletter: Art. 6(1)(a) GDPR (consent).
Brevo privacy policy: https://www.brevo.com/legal/privacypolicy/
5.5 Video processing (self-operated)
Uploaded videos are converted into platform-specific formats, resolutions and aspect ratios (e.g. 9:16 for Reels, 1:1 for feed posts). This processing takes place entirely on our own server infrastructure (see the Hetzner section) — without involving external encoding providers.
5.6 Ploi B.V. (server management)
Provider: Ploi B.V., Netherlands.
Purpose: Technical management and maintenance of our Hetzner servers (deployment, configuration, monitoring).
Data location: Netherlands (EU).
Data transferred: Server configurations, deployment logs, technical system metrics (no access to user data during ongoing operation).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in efficient server maintenance).
Ploi privacy policy: https://ploi.io/privacy
5.7 Cybot A/S (Cookiebot — cookie consent management)
Provider: Cybot A/S, Havnegade 39, 1058 Copenhagen, Denmark.
Purpose: Management of cookie consents pursuant to Section 25 of the German Telecommunications-Telemedia Data Protection Act (TTDSG).
Data location: Denmark (EU).
Data transferred: IP address (anonymized), browser information, consent status.
Legal basis: Art. 6(1)(c) GDPR (legal obligation to obtain consent).
Cookiebot privacy policy: https://www.cookiebot.com/en/privacy-policy/
5.8 Postproxy (direct publishing aggregator)
Provider: 64Bit Labs UG (haftungsbeschränkt), Kolonnenstr. 8, 10827 Berlin, Germany.
Purpose: Transmission of approved posts (images, videos, captions, publishing time) to connected social media platforms (Instagram, TikTok, YouTube, LinkedIn, WhatsApp and XING). Receipt of status webhooks.
Data location: Germany (EU).
Data transferred: Uploaded media URLs, caption texts, hashtags, publishing time, platform-specific metadata, account connections (Social Connect tokens), status responses from the target platforms.
Important: As soon as a post has been transmitted by Postproxy to a social media platform (Meta, TikTok, Google, LinkedIn, etc.), the privacy policy of the respective target platform additionally applies.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
Postproxy privacy policy: https://postproxy.dev/privacy-policy/
5.9 Apple Inc. (Apple Push Notification service / iOS app)
Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA (represented in the EU by Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland).
Purpose: Delivery of push notifications to the Maebe iOS app via the Apple Push Notification service (APNs).
Data location: Apple uses global infrastructure including servers in the USA.
Data transferred: APNs device token (anonymous device identifier), push content (title, short text, data payload).
Data transfer to the USA: Apple is certified under the EU-U.S. Data Privacy Framework.
Legal basis: Art. 6(1)(a) GDPR (consent via the operating system).
Apple privacy policy: https://www.apple.com/legal/privacy/en-ww/
5.10 Google Ireland Limited (Google Analytics 4 and Search Console)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (parent company: Google LLC, USA).
Purpose: Analysis of user behavior on our website (Google Analytics 4) and search engine optimization (Google Search Console).
Data location: Google uses global infrastructure, including servers in the USA.
Data transferred (Analytics): IP address (anonymized via IP anonymization), browser information, device information, pages visited, time spent, click events, and possibly conversion data.
Data transfer to the USA: Google is certified under the EU-U.S. Data Privacy Framework. In addition, Standard Contractual Clauses (SCCs) are in place.
Cookies and consent: Google Analytics uses cookies and is loaded exclusively after your consent via our cookie consent banner (Cookiebot). Without consent, no analytics script is executed and no analytics cookies are set.
Legal basis: Art. 6(1)(a) GDPR (consent) in conjunction with Section 25(1) TTDSG.
Withdrawal: You can withdraw your consent at any time via the cookie settings on our website.
Opt-out: You can additionally prevent tracking by Google Analytics by installing the browser plug-in available at https://tools.google.com/dlpage/gaoptout.
Google privacy policy: https://policies.google.com/privacy
5.11 united-domains AG (domain registration)
Provider: united-domains AG, Gautinger Straße 10, 82319 Starnberg, Germany.
Purpose: Registration and management of the domain maebe.app.
Data location: Germany.
Privacy policy: https://www.united-domains.de/datenschutz/
5.12 Support chat and ticketing (self-operated)
For support requests we operate our own chat and ticketing service (chat icon in the bottom-right corner of the application and website) directly on our own server infrastructure — no external chat provider is used.
Data processed: chat and ticket content, the email address and, where provided, the name voluntarily entered by guests, file attachments uploaded by logged-in users, the page visited (URL), browser information and message timestamps.
Data location: Germany/EU (own servers, see the Hetzner section).
AI replies: to answer chat requests automatically, chat content is transmitted to Mistral AI (see the Mistral AI section).
Email notifications about support tickets are sent via Brevo (see the Brevo section).
Cookies: the support chat does not set any third-party tracking cookies and does not require consent via the cookie banner.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract or pre-contractual measures) and Art. 6(1)(f) GDPR (legitimate interest in efficient support).
5.13 Functional Software, Inc. (Sentry — error and stability monitoring)
Provider: Functional Software, Inc. (dba Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA.
Purpose: Detection, diagnosis and resolution of technical errors in our application (server- and frontend-side error tracking) as well as — for error analysis — a limited recording of the session flow in the event of an error ("Session Replay").
Data transferred: Error and stack trace information, the accessed URL/view, browser, device and operating system information, IP address, a pseudonymous user identifier, and — where Session Replay is active — a recording of page content and interactions.
Protective measures: Input fields and sensitive content are masked by default in Session Replay and are not transmitted in plain text. The scope is limited to what is necessary for error analysis.
Data location: USA.
Data transfer to the USA: on the basis of Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR (as well as the EU-U.S. Data Privacy Framework, where certified).
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, reliability and security of our application).
DPA: Concluded.
Sentry privacy policy: https://sentry.io/privacy/
5.14 Mistral AI (AI-powered features)
Provider: Mistral AI SAS, 15 rue des Halles, 75001 Paris, France.
Purpose: Provision of Maebe's AI-powered features — in particular the AI assistant for captions, the campaign assistant, the AI analysis of insights, and machine translation of interface and content texts.
Data transferred: the texts you provide for or that are affected by the respective AI feature (e.g. caption drafts, post context, thematic prompts) as well as aggregated metrics for analysis. Only the content required for the respective request is transmitted.
Data location: European Union (France). No transfer to a third country takes place.
Legal basis: Art. 6(1)(b) GDPR (performance of a contract, where the AI feature is part of the service used) or Art. 6(1)(a) GDPR (consent, where you actively trigger an AI feature).
DPA: Concluded.
Mistral AI privacy policy: https://mistral.ai/terms/#privacy-policy
6. COOKIES AND SIMILAR TECHNOLOGIES
Our website uses cookies. Cookies are small text files that are stored on your device.
6.1 Technically necessary cookies
These cookies are required for the operation of the website and application (e.g. for login sessions, language settings, CSRF protection). They are set without consent on the basis of Art. 6(1)(f) GDPR and Section 25(2) no. 2 TTDSG.
6.2 Optional: analytics and statistics cookies
Cookies from Google Analytics are only set after your consent (Section 25(1) TTDSG, Art. 6(1)(a) GDPR). You can withdraw your consent at any time via the cookie banner.
6.3 Cookie overview
A complete and up-to-date overview of all cookies used can be found in our cookie settings center, which is provided by Cookiebot.
7. PAYMENT PROCESSING AND INVOICES
For payment processing we use Lemon Squeezy as Merchant of Record (see 5.3). Lemon Squeezy concludes the purchase contract for the payment with you, issues your invoice and remits the applicable taxes (e.g. EU VAT). The following data is processed for invoicing:
- Name / company name
- Billing address
- VAT ID (B2B)
- Order data (plan, term, price, booked add-ons)
- Payment data (via Lemon Squeezy)
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR (statutory accounting obligations under Section 147 AO).
Storage period: 10 years (statutory retention period under Section 147 AO).
8. DATA TRANSFERS TO THIRD COUNTRIES
Insofar as data is transferred to countries outside the EU/EEA (in particular to the USA with Lemon Squeezy, Apple, Google and Sentry), this is carried out on the basis of:
- The EU-U.S. Data Privacy Framework (insofar as the respective recipient is certified — including Lemon Squeezy, Apple, Google)
- Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR
- Where consent is given: Art. 49(1)(a) GDPR
We have established the safeguards required under the GDPR with all third-country recipients. The AI processing (Mistral AI) takes place exclusively within the EU.
9. STORAGE PERIOD
We only store personal data for as long as it is necessary for the purposes stated in this privacy policy or for as long as statutory retention periods apply.
Overview of storage periods:
- Account data: Until account deletion + 30-day backup
- Uploaded content: Until account deletion + 30-day backup
- Approval logs (incl. IP of the approval action): Until the post or account is deleted
- Invoicing and accounting data: 10 years (Section 147 AO)
- Server logs: 14 days
- Error/diagnostic data (Sentry, incl. Session Replay): according to Sentry's retention (generally 30–90 days)
- Newsletter sign-up data: Until unsubscribe
- Cookie consents: 12 months
- Support communication: 3 years
- Push tokens (APNs / web push): Until the push permission is withdrawn, the device/browser is unsubscribed, or the app is uninstalled
10. DATA SECURITY
We use technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorized persons. These include, among others:
- SSL/TLS encryption of data transmission
- Bcrypt encryption of passwords
- Regular automated backups (DB + object storage), stored on separate infrastructure
- Servers in Germany (Hetzner), secured by a cloud firewall
- Access controls (role system, team separation)
- Two-factor authentication (available/recommended)
- HMAC-signed webhooks for third-party communication
11. REORGANIZATION AND BUSINESS TRANSFER
In the event of a business restructuring (e.g. conversion of a sole proprietorship into a GmbH or UG, merger, division) or a business sale, personal data may be transferred to the legal successor. The transfer only takes place insofar as this is necessary within the scope of contract performance and in compliance with statutory data protection requirements (Art. 6(1)(b) and (f) GDPR).
Data subjects will be informed by email at least 30 days before a transfer. You may object to the transfer or terminate your contract for good cause. In the event of an objection, the personal data will not be transferred but deleted after the end of the contractual relationship — subject to statutory retention obligations (e.g. Section 147 AO for accounting data).
The legal successor is obliged to process the personal data according to the same data protection standards as described in this privacy policy. For B2B customers, the existing data processing agreement (DPA) also passes to the legal successor.
12. CHANGES TO THIS PRIVACY POLICY
We reserve the right to amend this privacy policy in order to adapt it to current legal requirements or to implement changes to our services. You can always find the current version at https://maebe.app/en/legal/datenschutz.
13. CONTACT
If you have any questions about data protection, please contact:
Kristof Puller
Toulouser Allee 7
40211 Düsseldorf, Germany
Email: datenschutz@maebe.app