Privacy
How we use your data
A brief, easy-to-understand overview before the legal details.
Providing the service
Generating stories and providing core features.
Account management
Authentication, subscription management and support.
Service improvement
Optimising performance and developing features.
Security & compliance
Ensuring security and protecting rights.
Privacy & security
Our security measures
Encryption
End-to-end encryption for sensitive data
Access controls
Role-based permissions and authentication
Regular backups
Automated backups with a recovery strategy
Security audits
Regular security checks and updates
Your rights
You have the following rights regarding your personal data:
Access
Request a copy of the personal data we hold about you
Rectification
Have inaccurate personal data updated or corrected
Erasure
Request the erasure of your personal data (subject to statutory retention obligations)
Data portability
Receive your data in a structured, machine-readable format
Objection
Object to certain processing of your personal data
Children's data & parental rights (Article 8 GDPR)
SchlummerMärchen is a service for creating personalised stories for children. Protecting children's data is our highest priority.
Important information for parents and legal guardians
Registration by adults only
Under Article 8 GDPR, only people aged 16 or over may independently consent to data processing. Parents or legal guardians register and manage the data of their children under 16.
Parental consent required
When registering, you confirm that you are an adult. All child profiles are assigned to your account and can only be managed by you. By creating child profiles, you give your express consent to the processing of children's data in accordance with this privacy policy.
Full control for parents
You can view, edit or completely delete children's data at any time. Contact us to request access to or erasure of data.
What children's data do we process?
Name or nickname
To personalise stories (e.g. "A story for Emma")
Age or age group
For age-appropriate stories and suitable language complexity
Avatar image (optional)
AI-generated avatar image based on descriptions – no storage of real photographs of children
Interests and preferences
Favourite topics (e.g. dinosaurs, princesses) for personalised stories
Generated stories
Stored stories and audio files created for the child
Retention period & data erasure
Children's data is stored for as long as your account is active. Cancelling a subscription only ends the subscription and does not automatically delete the account. To delete your account, please use the deletion process described below, which requires your explicit confirmation.
Whether or not you have an active subscription, you can request the deletion of your account through our public account deletion process. Deletion is not triggered merely by opening a link; it requires your explicit confirmation.
Your rights as parents
As a legal guardian, you have the following rights regarding your child's data:
Right of access
Request a complete overview of all stored data about your child
Right to rectification
Edit your child's data yourself in your account at any time
Right to erasure
Completely delete individual child profiles or all data
Data portability
Export all children's data in a machine-readable format (JSON)
Contact for children's data
For access to, rectification or erasure of children's data, contact us at hallo@schlummermaerchen.de. We handle requests concerning children's data with the highest priority within 72 hours.
Account deletion
You can request the deletion of your SchlummerMärchen account without logging in or having the app installed at /account-deletion . After you enter your email address, we send you a confirmation link that is valid for 24 hours. Account deletion is only scheduled once you explicitly confirm it on the linked page.
Your active subscription is cancelled upon confirmation. Your account and profile, child profiles, stories, audio files, saved images and uploads, and authentication data are scheduled for permanent deletion in 30 days.
Data that we must continue to store to fulfil statutory retention obligations may be retained beyond this point. This applies only to the data and retention periods required in each case.
Key points at a glance
Hosting
Externally with Hetzner in Germany.
Cookies
Necessary, optional, no third-party advertising providers.
Server logs
Technical data for stability.
Contact form
Enquiries are stored for their intended purpose.
Analytics
PostHog, configured for data protection compliance.
Payments
Processed via Stripe, SCCs, data processing agreement.
Legal bases
Article 6 GDPR and consent.
AI services
Story, image and audio generation.
Authentication & database
Supabase, Google OAuth.
Children's data
Article 8 GDPR – parental rights and protection.
The legal details follow
1. Data protection at a glance
General information
The following information provides a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to identify you personally.
Data collection on this website
Who is responsible for data collection on this website?
Data on this website is processed by the website operator. You can find their contact details in the section "Information about the controller" of this privacy policy.
How do we collect your data?
Some data is collected when you provide it to us. This may, for example, be data you enter in a contact form.
Other data is collected automatically or with your consent by our IT systems when you visit the website. This is primarily technical data (e.g. your browser, operating system or the time a page is accessed). This data is collected automatically as soon as you enter this website.
What do we use your data for?
Some data is collected to ensure that the website works correctly. Other data may be used to analyse your usage behaviour.
What rights do you have regarding your data?
You have the right to obtain information about the origin, recipients and purpose of your stored personal data at any time, free of charge. You also have the right to request the rectification or erasure of this data. If you have consented to data processing, you may withdraw your consent at any time with effect for the future. You also have the right, under certain circumstances, to request the restriction of processing of your personal data. You further have the right to lodge a complaint with the competent supervisory authority.
You may contact us at any time about this or any other data protection questions.
Analytics tools and third-party tools
When you visit this website, your browsing behaviour may be statistically analysed. This is primarily done using analytics software.
Detailed information about this analytics software can be found in the privacy policy below.
2. Hosting
We host the content of our website with the following provider:
This website is hosted externally. Personal data collected on this website is stored on the servers of the hosting provider(s). This may include, in particular, IP addresses, contact enquiries, metadata and communication data, contract data, contact details, names, website accesses and other data generated via a website.
External hosting serves to fulfil contracts with our prospective and existing customers (Article 6(1)(b) GDPR) and our interest in the secure, fast and efficient provision of our online service by a professional provider (Article 6(1)(f) GDPR). Where the relevant consent has been requested, processing is carried out exclusively on the basis of Article 6(1)(a) GDPR and section 25(1) TDDDG, insofar as consent covers the storage of cookies or access to information on the user's device (e.g. device fingerprinting) within the meaning of the TDDDG. Consent may be withdrawn at any time.
Our hosting provider(s) will process your data only to the extent necessary to fulfil their service obligations and will follow our instructions regarding this data.
We use the following hosting provider(s):
Hetzner Online GmbH
Industriestr. 25
91710 Gunzenhausen
Processing on our behalf
We have concluded a data processing agreement (DPA) for the use of the above service. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
3. General information and mandatory disclosures
Data protection
We take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy.
Various personal data is collected when you use this website. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this takes place.
Please note that data transmission over the internet (e.g. communication by email) may have security vulnerabilities. Complete protection of data against access by third parties is not possible.
Information about the controller
The controller responsible for data processing on this website is:
dotnetic GmbH
Königstraße 26
48268 Greven
info@dotnetic.de
Telephone: 02571/5699051
Email: info@dotnetic.de
The controller is the natural or legal person who, alone or jointly with others, determines the purposes and means of processing personal data (e.g. names, email addresses or similar).
Retention period
Unless a more specific retention period is stated in this privacy policy, your personal data will remain with us until the purpose of processing no longer applies. If you make a valid request for erasure or withdraw your consent to data processing, your data will be erased unless we have other legally permissible grounds for storing your personal data (e.g. retention periods under tax or commercial law); in the latter case, erasure takes place once those grounds no longer apply.
General information on the legal bases for data processing on this website
If you have consented to data processing, we process your personal data on the basis of Article 6(1)(a) GDPR or Article 9(2)(a) GDPR where special categories of data under Article 9(1) GDPR are processed. If you expressly consent to the transfer of personal data to third countries, processing is also based on Article 49(1)(a) GDPR. If you have consented to the storage of cookies or access to information on your device (e.g. via device fingerprinting), processing is additionally based on section 25(1) TDDDG. Consent may be withdrawn at any time. If your data is required to fulfil a contract or take steps prior to entering into a contract, we process it on the basis of Article 6(1)(b) GDPR. We also process your data on the basis of Article 6(1)(c) GDPR where necessary to fulfil a legal obligation. Data processing may further be based on our legitimate interest under Article 6(1)(f) GDPR. The following sections of this privacy policy explain the legal bases applicable in each case.
Information on data transfers to the USA and other third countries
We use, among other things, tools from companies based in the USA or other third countries that are not considered safe under data protection law. When these tools are active, your personal data may be transferred to and processed in these third countries. Please note that a level of data protection comparable to that in the EU cannot be guaranteed in these countries. For example, US companies are required to disclose personal data to security authorities without you, as a data subject, being able to take legal action against this. It therefore cannot be ruled out that US authorities (e.g. intelligence agencies) may process, analyse and permanently store your data held on US servers for surveillance purposes. We have no influence over these processing activities.
Withdrawal of your consent to data processing
Many data processing operations are only possible with your express consent. You may withdraw consent you have already given at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Right to object to data collection in specific cases and to direct marketing (Article 21 GDPR)
IF DATA PROCESSING IS BASED ON ARTICLE 6(1)(e) OR (f) GDPR, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME, ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION, TO THE PROCESSING OF YOUR PERSONAL DATA; THIS ALSO APPLIES TO PROFILING BASED ON THOSE PROVISIONS. THE RELEVANT LEGAL BASIS FOR PROCESSING IS SET OUT IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS THE PERSONAL DATA CONCERNED UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR PROCESSING WHICH OVERRIDE YOUR INTERESTS, RIGHTS AND FREEDOMS, OR THE PROCESSING SERVES THE ESTABLISHMENT, EXERCISE OR DEFENCE OF LEGAL CLAIMS (OBJECTION UNDER ARTICLE 21(1) GDPR).
WHERE YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF PERSONAL DATA CONCERNING YOU FOR SUCH MARKETING; THIS ALSO APPLIES TO PROFILING INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE USED FOR DIRECT MARKETING PURPOSES (OBJECTION UNDER ARTICLE 21(2) GDPR).
Right to lodge a complaint with the competent supervisory authority
In the event of GDPR infringements, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or the place of the alleged infringement. This right is without prejudice to any other administrative or judicial remedy.
Right to data portability
You have the right to receive, or have a third party receive, data that we process by automated means on the basis of your consent or in performance of a contract, in a commonly used, machine-readable format. If you request direct transmission to another controller, this will only take place where technically feasible.
Access, erasure and rectification
Within the scope of the applicable legal provisions, you have the right at any time to obtain, free of charge, information about your stored personal data, its origin and recipients and the purpose of processing, and, where applicable, a right to rectification or erasure of this data. You may contact us at any time about this or any other questions concerning personal data.
Right to restriction of processing
You have the right to request the restriction of processing of your personal data. You may contact us at any time for this purpose. The right to restriction of processing applies in the following cases:
If you contest the accuracy of the personal data we hold about you, we generally need time to verify it. You have the right to request restriction of processing of your personal data for the duration of this verification.
If the processing of your personal data was or is unlawful, you may request restriction of processing instead of erasure.
If we no longer need your personal data but you require it to exercise, defend or establish legal claims, you have the right to request restriction of processing of your personal data instead of erasure.
If you have lodged an objection under Article 21(1) GDPR, your interests must be weighed against ours. Until it has been established whose interests prevail, you have the right to request restriction of processing of your personal data.
If the processing of your personal data has been restricted, that data may, apart from storage, only be processed with your consent or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.
SSL or TLS encryption
This website uses SSL or TLS encryption for security reasons and to protect the transmission of confidential content, such as orders or enquiries that you send to us as the website operator. You can recognise an encrypted connection by the address in your browser changing from "http://" to "https://" and by the padlock symbol in your browser's address bar.
When SSL or TLS encryption is enabled, data you transmit to us cannot be read by third parties.
4. Data collection on this website
Cookies
We use necessary cookies to provide core features. We only enable optional analytics cookies with your consent. No third-party advertising or tracking cookies.
Our web pages use cookies. Cookies are small data packets and do not harm your device. They are stored on your device either temporarily for the duration of a session (session cookies) or permanently (persistent cookies). Session cookies are automatically deleted at the end of your visit. Persistent cookies remain on your device until you delete them yourself or your browser deletes them automatically.
In some cases, cookies from third-party companies may also be stored on your device when you enter our website (third-party cookies). These allow us or you to use certain services provided by the third party (e.g. cookies for processing payment services).
Cookies serve various purposes. Many cookies are technically necessary because certain website features would not work without them (e.g. shopping cart functionality or displaying videos). Other cookies are used to analyse user behaviour or display advertising.
Cookies required to carry out electronic communications, provide certain features you request (e.g. shopping cart functionality) or optimise the website (e.g. cookies for measuring website audiences) (necessary cookies) are stored on the basis of Article 6(1)(f) GDPR unless another legal basis is specified. The website operator has a legitimate interest in storing necessary cookies to provide its services correctly and in an optimised manner. Where consent to the storage of cookies and similar recognition technologies has been requested, processing is carried out exclusively on the basis of that consent (Article 6(1)(a) GDPR and section 25(1) TDDDG); consent may be withdrawn at any time.
You can configure your browser to notify you when cookies are set, allow cookies only on a case-by-case basis, reject cookies in certain cases or generally, and automatically delete cookies when closing the browser. Disabling cookies may limit the functionality of this website.
Where cookies from third-party companies or cookies for analytics purposes are used, we will inform you separately in this privacy policy and request consent where applicable.
Server log files
The provider of these pages automatically collects and stores information in server log files, which your browser automatically transmits to us. This includes:
Browser type and version
Operating system used
Referrer URL
Host name of the accessing computer
Time of the server request
IP address
This data is not combined with other data sources.
This data is collected on the basis of Article 6(1)(f) GDPR. The website operator has a legitimate interest in the technically correct presentation and optimisation of its website, which requires server log files to be collected.
Contact form
If you send us enquiries using the contact form, we will store the information provided in the form, including your contact details, to process your enquiry and handle any follow-up questions. We will not share this data without your consent.
This data is processed on the basis of Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) where it has been requested; consent may be withdrawn at any time.
Data you enter in the contact form remains with us until you request its erasure, withdraw your consent to storage or the purpose of storing the data no longer applies (e.g. once your enquiry has been fully processed). Mandatory statutory provisions, particularly retention periods, remain unaffected.
Enquiries by email, telephone or fax
If you contact us by email, telephone or fax, we will store and process your enquiry, including all resulting personal data (name, enquiry), for the purpose of handling your request. We will not share this data without your consent.
This data is processed on the basis of Article 6(1)(b) GDPR where your enquiry relates to the performance of a contract or is necessary to take steps prior to entering into a contract. In all other cases, processing is based on our legitimate interest in effectively handling enquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR) where it has been requested; consent may be withdrawn at any time.
Data you send us in contact enquiries remains with us until you request its erasure, withdraw your consent to storage or the purpose of storing the data no longer applies (e.g. once your request has been fully processed). Mandatory statutory provisions, particularly statutory retention periods, remain unaffected.
CCM19
Our website uses CCM19 to obtain your consent to storing certain cookies on your device or using certain technologies, and to document this in compliance with data protection law. The provider of this technology is Papoo Software & Media GmbH, Auguststr. 4, 53229 Bonn (hereinafter "CCM19").
When you enter our website, a connection is established to CCM19's servers to obtain your consent and other declarations concerning the use of cookies. CCM19 then stores a cookie in your browser to associate you with the consent you have given or its withdrawal. The data collected in this way is stored until you request its erasure, delete the CCM19 cookie yourself or the purpose of storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.
CCM19 is used to obtain the consent legally required for the use of cookies. The legal basis is Article 6(1), first sentence, point (c) GDPR.
Processing on our behalf
We have concluded a data processing agreement (DPA) for the use of the above service. This is a contract required by data protection law which ensures that the provider processes the personal data of our website visitors only in accordance with our instructions and in compliance with the GDPR.
5. Analytics tools and advertising
PostHog
This website uses PostHog, an analytics and product analytics service provided by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA.
PostHog allows us to collect and analyse data about how visitors use our website. Among other things, this allows us to identify when particular pages were viewed and which features were used.
Usage analytics with your consent
We only use PostHog if you have consented to usage analytics in the privacy settings. We collect, among other things, page views, feature usage, time spent on a page and its maximum scroll depth. Scroll depth is recorded as a proportion to understand how much of our content is viewed.
To recognise returning visits, we use pseudonymous identifiers as well as cookies, LocalStorage and SessionStorage. PostHog cookies are configured to last for up to 365 days. Names and email addresses, information about children and their loved ones, story content and form entries are not transmitted as analytics data. Query parameters, fragments and private identifiers are removed from page addresses before transmission.
Country analysis
PostHog processes the IP address used for the connection to approximately assign a country. Only the country name and country code are stored for this analysis, not cities, postcodes or coordinates. The IP address is removed from the analytics event. We do not access your device's location permission. The country assigned may differ from the country you are actually in, for example when using a VPN.
The legal bases are your consent under Article 6(1)(a) GDPR and, where information is stored on or read from your device, section 25(1) TDDDG. You may withdraw your consent at any time in the privacy settings with effect for the future. Collection then stops. This usage analysis does not take place without consent.
We use PostHog EU Cloud. Analytics does not include session recordings (session replay).
PostHog has implemented compliance measures for international data transfers. These are based on the EU Standard Contractual Clauses (SCCs). Further information is available at: posthog.com/privacy.
Voluntary cancellation survey
During the cancellation process, we offer a short, voluntary survey to understand your reasons for cancelling (e.g. "did not enjoy the stories", "not enough time", "too expensive", "missing features"). You may also optionally leave a free-text comment.
Participation in this survey is entirely voluntary and your cancellation takes effect whether you participate in the survey or skip it. Ending the contract is not conditional on completing the survey.
The legal basis for processing, including an optionally completed free-text field, is Article 6(1)(f) GDPR. Our legitimate interest is to improve the product based on actual usage and reasons for cancellation. Before submitting the form, you may change or clear your selection and the free-text field at any time, or simply choose "Skip". Afterwards, it is technically no longer possible to link your response to you due to pseudonymisation (see the next paragraph), so an individual response cannot subsequently be withdrawn.
Responses are stored with a cryptographically pseudonymised identifier (a SHA-256 hash of your user ID combined with an undisclosed server-side secret). This hash only allows us to technically prevent duplicate submissions. We cannot subsequently trace it back to you; accordingly, we cannot ask follow-up questions or subsequently identify or delete individual responses. Data is not shared with third parties and is only analysed internally to improve the product. Responses are regularly reviewed and deleted no later than after 24 months.
Payments
Payments are processed via Stripe using current Standard Contractual Clauses (SCCs). We only transmit the data required for processing. Further details are provided in the following section.
Stripe
We offer payment processing through the payment service provider Stripe, ℅ Legal Process, 510,Townsend St., San Francisco, CA 94103 (Stripe). This serves our legitimate interest in offering an efficient and secure payment method (Article 6(1)(f) GDPR). In this context, we share the following data with Stripe insofar as necessary to fulfil the contract (Article 6(1)(b) GDPR).
Cardholder's name
Email address
Customer number
Order number
Bank details
Credit card details
Credit card expiry date
Credit card verification code (CVC)
Date and time of the transaction
Transaction amount
Provider's name
Location
Processing the data listed in this section is required neither by law nor by contract. Without transmitting your personal data, we cannot process a payment via Stripe. No alternative payment method is currently available.
Stripe has a dual role in data processing activities as both controller and processor. As a controller, Stripe uses the data you provide to fulfil regulatory obligations. This serves Stripe's legitimate interest (Article 6(1)(f) GDPR) and the performance of the contract (Article 6(1)(b) GDPR). We have no influence over this process.
Stripe acts as a processor to complete transactions within payment networks. Within this processing relationship, Stripe acts exclusively on our instructions and is contractually required under Article 28 GDPR to comply with data protection provisions.
Stripe has implemented compliance measures for international data transfers. These apply to all global activities in which Stripe processes personal data of individuals in the EU. These measures are based on the EU Standard Contractual Clauses (SCCs).
Further information on options for objection and erasure in relation to Stripe is available at: /privacy-center/legal
We store your data until payment processing is complete. This also includes the time required to process refunds, manage claims and prevent fraud.
Legal information
Address
Stripe Payments Europe Limited 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland
6. Authentication and data storage
Supabase
We use Supabase, a service provided by Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992, to store your user data, authenticate users and manage files. Supabase provides a managed PostgreSQL database, authentication services and file storage. Data is processed on servers in the EU (region eu-central-1, Frankfurt am Main).
In particular, the following data is stored in Supabase:
Account data (email address, name)
Child profile data (first name, age, interests, chosen avatar)
Generated stories
Session and authentication data
Processing is based on Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(f) GDPR (legitimate interest in secure and reliable data storage). Supabase has implemented compliance measures for international data transfers based on the EU Standard Contractual Clauses (SCCs). Further information: supabase.com/privacy.
Google OAuth (social login)
We offer the option of signing in to our website using your Google account (social login). The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
When you sign in with Google, Google sends us your name and email address. We use this data exclusively to create and manage your user account. No other data is retrieved from your Google account.
Processing is based on Article 6(1)(b) GDPR (performance of a contract) and your consent under Article 6(1)(a) GDPR, which you give by clicking the Google login button. You may disconnect the account at any time in your Google account settings. Further information: policies.google.com/privacy.
7. AI-powered services
SchlummerMärchen uses various AI services to generate personalised stories, illustrations and audio versions. Only the child's first name, interests and a description of their appearance are transmitted to the respective services – no surnames, addresses or other identifying data.
Story generation (LLM services)
To create personalised stories, we use large language models (LLMs) through the following providers:
OpenRouter – OpenRouter Inc., USA. The primary service for story generation. OpenRouter forwards requests to various AI models.
Google Gemini – Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Used for premium speech synthesis and as an alternative LLM service.
Groq – Groq Inc., USA. Used as a fallback service for audio transcription.
The following is transmitted to these services: the child's first name, age group, interests and preferences, and descriptions of their appearance to personalise the story. No complete user profiles or contact details are transmitted.
Processing is based on Article 6(1)(b) GDPR (performance of a contract – creating personalised stories is the core service). EU Standard Contractual Clauses (SCCs) apply to transfers to the USA.
Image generation
We use the following services to create illustrations for stories:
WaveSpeed – WaveSpeed AI, USA. The primary service for image generation.
Google Gemini – Google Ireland Limited, Dublin, Ireland. An alternative image generation service.
Descriptions of the desired illustrations, based on the story content, are transmitted to these services. No personal data is transmitted directly, but the descriptions may indirectly refer to the child's first name or appearance.
Processing is based on Article 6(1)(b) GDPR (performance of a contract). EU Standard Contractual Clauses (SCCs) apply to transfers to the USA.
Audio generation (text-to-speech)
We use the following services to create audio versions of stories:
Google Cloud Text-to-Speech – Google Ireland Limited, Dublin, Ireland. The primary service for speech synthesis.
The text of the generated story, which may contain the child's first name, is transmitted to these services. Processing is based on Article 6(1)(b) GDPR (performance of a contract). EU Standard Contractual Clauses (SCCs) apply to transfers to the USA.
Audio transcription
We use the following for transcribing audio content:
OpenAI Whisper – OpenAI OpCo, LLC, San Francisco, USA. Converts audio files into text.
Only audio files are transmitted for processing. Processing is based on Article 6(1)(b) GDPR (performance of a contract). EU Standard Contractual Clauses (SCCs) apply to transfers to the USA.
8. Email delivery
Resend
We use Resend, a service provided by Resend Inc., to send transactional emails (e.g. registration confirmations, password resets and subscription notifications). Data is processed on servers in the EU (region eu-west-1, Ireland).
The recipient's email address and the content of the respective email are transmitted to Resend. Processing is based on Article 6(1)(b) GDPR (performance of a contract). As processing takes place in the EU, no transfer to a third country is required. Further information: resend.com/legal/privacy-policy.