August 21, 2026
Дані постачальника неповні
Обов'язкові дані про компанію ще не внесено, тому вони позначені як відсутні, а не заповнені прикладом. Задайте ці змінні середовища в панелі Vercel:
COMPANY_LEGAL_NAME · COMPANY_STREET · COMPANY_POSTAL_CODE · COMPANY_CITY · COMPANY_COUNTRY · COMPANY_EMAIL1. Controller
The controller responsible for the processing of personal data within the meaning of Art. 4 (7) of the EU General Data Protection Regulation (GDPR) is:
[noch nicht hinterlegt]
Email: privacy@mytrendview.com
You can reach our data protection contact at dpo@mytrendview.com.
2. Scope and applicable law
This Privacy Policy applies to processing carried out by [noch nicht hinterlegt] when you use mytrendview.com or any of our subdomains, our web application and connected APIs (the "Service"). Processing is governed by the EU GDPR, the German Federal Data Protection Act (BDSG) and the German Telecommunications-Telemedia Data Protection Act (TDDDG / former TTDSG).
3. Categories of personal data we process
Account data: name, email address, hashed password (bcrypt), profile picture (only if you sign in with Google), language preference, time zone.
Brand & business data: the website URL you connect, brand description, industry, target audience and any text you enter into the product.
Social account data: if you connect YouTube (or other platforms in the future), we store the OAuth access token, refresh token, expiry, the channel ID, channel name, handle and avatar URL. We do not read private messages, comments inboxes or non-public videos.
Content data: trend lists, competitor and creator lists, video plans, frames, generated images, captions and hooks generated through our AI features and stored under your account.
Usage and log data: IP address (used only as a short-lived rate-limiting key, not stored in our database), user-agent, requested URL, timestamp, HTTP status, referrer, error logs.
Billing data (once paid plans are launched): name, billing address, VAT-ID, payment method tokens. Card numbers are processed solely by our payment provider; we never see or store full PANs.
4. Purposes & legal bases (Art. 6 GDPR)
Providing the Service — account creation, authentication, running scrapes, generating AI plans and images, publishing to social accounts you have connected: Art. 6 (1) (b) GDPR (performance of a contract).
Security, fraud prevention, abuse detection, server logs: Art. 6 (1) (f) GDPR (legitimate interest in operating a secure service). Server logs are deleted or anonymised after 14 days.
Product improvement: Art. 6 (1) (f) GDPR (legitimate interest). We measure two things, both without any third party.
(a) Inside the app: how long a signed-in user spent in which area — server-side, via the existing session, cookie-free.
(b) On the public pages: which sections of a page were reached, how far it was scrolled, and where clicks landed. This is aggregated as it is written: one row per page, per day, per device class, holding counters only. There is no row per visitor, no identifier, no cookie and no path across pages, so there is nothing that could later be traced to a person. A browser sending Do Not Track is not measured at all. Because nothing is stored on or read from your device, this needs no consent under § 25 TDDDG.
The consent banner you see covers something else: the optional analytics tag, which only loads after you allow it. Declining changes nothing about how the app works. The data is deleted after 90 days (section 10), and immediately when you close your account. You can object at any time under Art. 21 GDPR.
Marketing emails: Art. 6 (1) (a) GDPR (consent) or § 7 (3) UWG for existing-customer recommendations of similar services.
Compliance with legal obligations (tax-, commercial-law-, GoBD-required retention of invoices for up to 10 years): Art. 6 (1) (c) GDPR.
5. Cookies and similar technologies (§ 25 TDDDG)
We only set strictly necessary cookies by default: a NextAuth session cookie (httpOnly, secure, SameSite=Lax), a CSRF token, a language cookie storing your interface language for one year, and — only while you are connecting a social account — a short-lived OAuth state cookie (10 minutes) that protects that flow against tampering. These are required to keep you signed in, to remember your language and to protect form and OAuth submissions. No consent is required for these under § 25 (2) Nr. 2 TDDDG.
We do not currently use third-party analytics, advertising trackers, fingerprinting, Google Analytics, Meta Pixel, Hotjar or similar tools. If we introduce such tools in the future, they will only be loaded after you give explicit, separate, granular consent through a Consent-Management-Platform compliant with § 25 TDDDG and EDPB Guideline 03/2022.
6. Recipients and processors (Art. 28 GDPR)
We use the following processors under a Data Processing Agreement. The list is updated when we add or remove vendors:
- Vercel Inc. (USA) — hosting of the web application. EU data centers used where possible. Transfer based on EU Standard Contractual Clauses (SCCs) and Data Privacy Framework certification.
- MongoDB, Inc. (USA, Atlas cluster located in Frankfurt, eu-central-1) — primary database.
- Cloudinary Ltd. (Israel / EU) — storage and delivery of generated images. Israel is recognised as adequate under the Commission Decision of 31.01.2011.
- Anthropic PBC (USA) — Claude AI models for trend scoring, hook generation and video planning. Anthropic does not train its production models on API inputs. Transfer based on SCCs.
- Google LLC / Google Ireland Ltd. — (a) Google OAuth for "Sign in with Google", (b) Gemini API ("Nano Banana Pro") for image generation, (c) YouTube Data API v3 for publishing if you connect a YouTube account. Transfer based on SCCs and the EU-US Data Privacy Framework.
- Apify Technologies s.r.o. (Prague, Czech Republic, EU) — running scrapers against public web data.
- Resend (Plus Five Five, Inc.) (USA) — transactional email: password resets and team invitations. Transfer based on SCCs.
- Stripe, Inc. (USA) / Stripe Payments Europe Ltd. (Ireland) — payment processing, subscriptions and invoices. Card data is entered directly with Stripe; we never receive it.
- Upstash, Inc. (USA) — Redis used solely for rate limiting. Stores a request counter per key, no message content.
- Sentry (Functional Software, Inc.) (USA) — error reporting, only when enabled. Stack traces may incidentally contain a user id.
Where data is transferred to countries outside the EU/EEA without an adequacy decision, we rely on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and additional technical measures (encryption in transit and at rest).
7. YouTube Data API — limited use disclosure
If you connect your YouTube channel, MyTrendView's use of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
Specifically, we:
- use Google data only to provide the user-facing publishing feature you requested,
- never transfer Google data to third parties except as needed to provide that feature, comply with applicable law or as part of a merger,
- never use Google data for advertising or to train generalised AI/ML models,
- never allow humans to read Google data unless we have your affirmative consent, it is necessary for security/abuse/legal reasons or the data has been aggregated and anonymised.
You can revoke MyTrendView's access to your Google account at any time at
myaccount.google.com/permissions or by writing to privacy@mytrendview.com, in which case we delete the stored tokens without delay. Deleting your MyTrendView account also deletes every stored token.
8. AI processing and automated decisions (Art. 22 GDPR)
MyTrendView uses third-party AI models (Anthropic Claude, Google Gemini) to score trends, generate text and generate images on your behalf. These processors act under our instructions and contractually undertake not to train their public models on our API inputs.
No decision producing legal effects on you or similarly significantly affecting you is made solely by automated means within the meaning of Art. 22 GDPR. All AI outputs are suggestions you can edit or discard.
9. Programmatic access (API and MCP server)
You can create API keys that let an external program act on your account — including an AI assistant connected over the Model Context Protocol (MCP).
What we store about a key: the name you give it, a SHA-256 hash of the key (we never store the key itself and cannot recover it), the visible prefix, and the creation and last-used timestamps. Legal basis: Art. 6 (1) (b) GDPR — you asked for the connection.
What leaves our systems when a key is used: the data the called tool returns — for example your brand names, your ranked trends, your token balance, or generated suggestions. It goes to the client you connected. That client is under your control, not ours. If it is a third-party AI assistant, that provider’s own privacy policy governs what happens to the data once it arrives, and we are not a processor for that step.
Revocation: you can revoke a key at any time in the app; it stops working on the very next call. Closing your account deletes every key. Revocation is forward-looking only — we cannot recall data already delivered to a client you authorised.
10. Source of scraped data (Art. 14 GDPR)
For competitor and creator discovery we collect publicly available metadata from social platforms (e.g. handle, follower count, engagement metrics) through Apify-hosted scrapers and official APIs. We restrict ourselves to data that has been manifestly made public by the data subject (Art. 9 (2) (e) GDPR where applicable). If you are a creator listed in our database and want your data removed, contact privacy@mytrendview.com and we will erase it within 30 days.
11. Retention periods
These periods are declared in the system and enforced by the database itself (TTL indexes). The authoritative source is lib/gdpr/retention, and the same periods are included in every data export you download.
Kept for the lifetime of your account — and removed when you close it:
- Account data, brand profiles, audience analyses
- Weekly plans, tasks, published posts, storyboards, hooks
- Competitor, creator and trend lists, starred trends, swipe cards
- Connected social accounts including OAuth tokens (also removed when you disconnect)
- Cloudinary media is deleted in cascade
Fixed periods, deleted automatically:
- Metric history for your own channels: 90 days
- Time spent per section (cookie-free, see section 5): 90 days
- Refresh and scraper logs: 90 days
- Trend volume history: 90 days
- AI call audit log: 180 days
- Team budget usage records: 12 months
- Abandoned sign-ups: 24 hours
- Technical locks preventing double-charging: 24 hours
- Render and cutter jobs: until the job expires (12 hours after completion)
- Team presence status: 10 minutes
- Server / access logs: 14 days
- Daily backup of your account data, so that accidental deletion can be undone: 3 days
- Figures reported by YouTube Studio, TikTok Studio and Meta Insights about your own connected accounts (reach, watch time, follower gains and losses): 400 days — long enough for a year-on-year comparison, no longer
Anonymised rather than deleted — the content stays with the team, the personal reference (name, email, user id) is removed irreversibly: team chat, task board, usage records. If you own a team, ownership passes to the longest-standing remaining member; if nobody is left, the team is deleted with you.
Deliberately retained:
- Record of your consent to immediate performance: 3 years (1095 days). Without it we could not show that your right of withdrawal expired under § 356 (5) BGB; three years matches the standard limitation period of § 195 BGB.
- Log of privileged administrator actions: 2 years (accountability, Art. 5(2) GDPR). It never contains credentials.
- Invoices and tax-relevant documents: 10 years (§ 147 AO, § 257 HGB).
- Backups: rolling 30-day window; a deletion reaches backups with that delay.
12. Your rights (Arts. 15–22, 77 GDPR)
You have the following rights with regard to your personal data:
- Right of access (Art. 15) — to a copy of the data we hold about you.
- Right to rectification (Art. 16).
- Right to erasure / "to be forgotten" (Art. 17).
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) — in particular against processing based on legitimate interests.
- Right to withdraw consent (Art. 7 (3)) at any time, without affecting prior lawful processing.
- Right to lodge a complaint with a supervisory authority (Art. 77). For us, the competent authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin, Germany.
To exercise any of these rights, email privacy@mytrendview.com. We respond within one month (Art. 12 (3) GDPR).
13. Data security
Personal data is encrypted in transit (TLS 1.2+) and at rest (AES-256 on MongoDB Atlas and Cloudinary). Passwords are hashed with bcrypt. Access to production systems is restricted, logged and requires multi-factor authentication. We follow the state of the art within the meaning of Art. 32 GDPR.
14. Minors
MyTrendView is not intended for users under 16. We do not knowingly collect data from children. If we learn that we have inadvertently collected data from a child, we delete it without delay.
15. Changes to this Privacy Policy
We may update this Policy to reflect changes in our service or in the law. Material changes will be communicated by email and announced in-app at least 30 days in advance. The current version is always available at /privacy.