Privacy Policy
Last updated: September 21, 2026
How we process personal data on blog-maker.com and blog-maker.de. GDPR compliant.
1. Controller
Controller for data processing is Digital Mind Agency Ltd., Evagora Pallikaridi 38, 8010 Paphos, Cyprus, registered in the Cypriot company registry under HE 428155. Represented by Oliver Albrecht. Contact: hello@blog-maker.com.
2. What data we collect
We process only the data necessary to operate the service. On registration we store your name, email address, and a hashed password (bcrypt). If you arrive via a campaign link (utm parameters such as source, medium and campaign), we store these origin details with your account to evaluate the success of our advertising (legitimate interest, Art. 6(1)(f) GDPR); on a purchase they are also passed to Stripe as metadata, and they are deleted with the account. On creating a brand we store domain, brand voice texts, and WordPress connection data (app-password encrypted at-rest). For article generation we store topics, outlines, pipeline outputs, and final content. If you use Stripe Checkout we forward name, email, and customer ID to Stripe; we only store the Stripe customer ID locally.
3. Cookies and Consent Mode v2
We set technically necessary cookies for login session, locale (de/en), and A/B variant persistence. These are permitted without consent (Art. 6(1)(f) GDPR, legitimate interest). Optional analytics and marketing services load only after your active consent via the cookie banner (Basic mode: before you choose, no analytics or marketing script is loaded and no connection to the providers is made). For the Google services we use Google Consent Mode v2: the default state is 'denied' (analytics_storage, ad_storage, ad_user_data, ad_personalization), and signals are only set to 'granted' after your consent. In the banner you can allow or decline each service individually (e.g. only Google Analytics but no Meta Pixel).
4. Analytics and marketing services with consent
Only with your active, per-service consent do we use: (1) Google Analytics 4 (provider Google LLC, USA; measurement ID G-ED583SQNZQ; reach measurement and page views with anonymized IP, anonymize_ip enabled; Consent Mode v2). (2) Meta Pixel (Meta Platforms Ireland Ltd.; conversion tracking and retargeting for Facebook/Instagram ads; the pixel has no Consent Mode pathway and is therefore hard-blocked in code until you consent to Meta; if you complete a subscription, we also send your email address to Meta as a one-way SHA-256 hash, never in plain text, so Meta can better attribute the subscription to the ad that led to it, Advanced Matching. In addition to the browser Pixel, we also send certain events server-side via the Meta Conversions API, so they still reach Meta even with an ad blocker or Safari's tracking protection active, with the same signals as the browser Pixel of the matching event: for page views and for watching a podcast video episode (first playback start and a full watch-through, if the episode has a hosted video), your browser's own cookie value (fbc/fbp), IP address, and user agent in plain text, no email hash; for the start and completion of a subscription, additionally the same hashed email address described above. Each server-side event carries the same event id as its browser-Pixel counterpart, so Meta does not count both as separate events). (3) Google Ads (Google LLC, USA; remarketing lists and conversion tracking; only active if configured). (4) Microsoft Clarity (Microsoft Ireland Operations Ltd.; heatmaps and session recordings to analyze user behavior; like the Meta Pixel it has no Consent Mode pathway and is therefore hard-blocked in code until you consent; only active if configured). For these services data is transferred to the USA; the transfer is safeguarded by the respective providers' Standard Contractual Clauses (SCC). Your choice takes effect immediately and is documented (hashed IP and user agent, no plain-text storage, Art. 7 GDPR). You can revoke any consent per service at any time via 'Cookie Settings' in the footer or the privacy control at the bottom left; on revocation we remove the scripts, browser globals, and cookies that were set.
5. Third parties without consent (data processors)
Necessary for the service: Anthropic PBC (USA, AI article generation via Claude API). Per Anthropic Commercial Terms, API inputs are NOT used to train models by default (source: privacy.claude.com 'Is my data used for model training'). Standard Contractual Clauses (SCC) are auto-incorporated in the Anthropic Commercial DPA. Data is processed and stored in the USA. The commercial Anthropic API generally provides backend deletion within 30 days; contract variations, features with longer storage, legal requirements and abuse controls may differ. For flagged violations, Anthropic states up to two years for content and seven years for safety scores; certain Covered Models have separate safety rules. Perplexity AI, Inc. (USA, AI-powered web research with source citations, used automatically for topic and competitor research at article generation time). A planned extension would additionally let you optionally use Perplexity when manually enriching an article in the editor with extra context; this feature is not yet active. Once it launches, the context text entered there is sent to Perplexity so it can research facts with citations for it; third-party personal data should not be entered there. Perplexity's Data Processing Addendum is automatically incorporated by reference into the Perplexity API Terms of Service (source: perplexity.ai/hub/legal/dpa), including Standard Contractual Clauses (SCC) for the transfer to the USA; no separate signature is required. DataForSEO OÜ (Estonia, EU entity, company registration no. 14502291; SEO and keyword data for the keyword cluster feature, which lets you pull related keywords and search volume for a search term you enter). When you use this feature, the search term you enter (together with language and target country) is sent to DataForSEO; no brand, domain or account data is sent. Personal names should not be entered there. Per its own privacy policy, DataForSEO deletes stored data after 365 days. For transfers to third countries, DataForSEO uses Standard Contractual Clauses (SCC) or relies on adequacy decisions per its own privacy policy. The DPA is automatically incorporated by reference into DataForSEO's Privacy Policy (source: dataforseo.com/privacy-policy); no separate signature is required. Google Ireland Limited or Google LLC (USA, image generation via the Gemini API, Gemini Image models a.k.a. Nano Banana). When an article image is generated, we send the image prompt (derived from the article topic, image description and your brand's image guidelines) to Google; for place-specific motifs we additionally send publicly available reference photos (for example from Wikimedia Commons) as image input. When you edit an existing article image, we additionally send the current article image and your editing instruction to Google. The legal basis is performance of the contract (Art. 6(1)(b) GDPR); the purpose is generating the article images you request. Under the Gemini API Terms, Google does not use prompts and responses to improve its products when the service is used as a paid service (Paid Services); Google logs prompts and responses for a limited period solely to detect violations of its Prohibited Use Policy and for legally required disclosures (source: ai.google.dev/gemini-api/terms, effective March 23, 2026). Google states 55 days for prompts, context and outputs; for EEA use, Gemini's terms apply these Paid Services data rules even to free quota, and this does not promise a separate retention period specifically for uploaded images. For transfers to third countries the Google Data Processing Addendum applies, which provides for Standard Contractual Clauses (SCC) where no other transfer mechanism is available (source: business.safety.google/processorterms, version 10 of May 7, 2026). Please do not enter third-party personal data in image descriptions. Stripe Payments Europe Ltd. (Ireland/USA, payment processing, own SCC). Sentry (USA, error tracking with anonymized source maps, SCC). Plesk mail server (EU, transactional mail).
5a. Uploaded images and provenance log
When you upload an image for an article, we check, orient and convert it to WebP without embedded metadata; the received original bytes are not stored permanently, we only store the cleaned version. This upload alone does not transmit the image to an AI provider. Access to unpublished images is protected to you alone; public delivery starts only once you decide to publish. We do not use your uploaded images for other customers' articles. For every upload we keep a provenance log: account, brand and article association, checksum, time, displayed text version and language, technical file details, origin, and deletion/publication status. Checksums and identifiers may be personal data; the log supports traceability and, where necessary, legal defence, and does not prove your image rights. It contains no IP address, user agent or original filename. AI providers only come into play when you separately request it: for an image description we transmit the image to Anthropic (Claude API); for AI editing we transmit it together with your editing instruction to Google (Gemini API). If you request both together, we disclose both steps before your request. A description alone does not change the image; results actually edited with AI receive an appropriate label. The AI action performed, the model, and, where applicable, the prompt are added to the provenance log. Details on how Anthropic and Google process data for these image features are in section 5 above. You may request removal of an image. Removing it from the current article alone does not automatically delete lawfully retained version references or copies on your own website; those copies must be removed there separately. We inform you about the scope of blocking or deletion within Blog-Maker; we cannot retrieve copies already downloaded. You can report possible infringements affecting uploaded or image-generated content through the linked reporting mechanism or hello@blog-maker.com; please provide the precise location and reason where possible. We assess every notice, acknowledge receipt where contact details are provided, and communicate our decision and available remedies; measures are targeted, not triggered merely by submitting a notice. The rights of people shown remain unaffected. Where we process personal log data on the basis of legitimate interests, you may object on grounds relating to your particular situation. We will assess whether compelling legitimate grounds or the establishment, exercise or defence of legal claims justify continued processing. Contact us at hello@blog-maker.com.
6. Hosting and storage location
Server infrastructure: Dawico Deutschland GmbH (dawico.de), certified to ISO 27001 / ISO 50001 / ISO 9001, locations Berlin and Frankfurt am Main, Germany. Data Processing Agreement (DPA) under Art. 28 GDPR is in place. PostgreSQL 16 database encrypted at-rest, daily backups, 30-day retention. Account data, brand data, and article volumes remain in Germany. Only individual API calls to Anthropic, Perplexity, Google (image generation), and DataForSEO leave the EU. On request we can future-set Anthropic's `inference_geo` parameter to anchor inference compute in a specific region (1.1x token surcharge). Anthropic data storage currently remains in the USA with SCC protection.
7. Retention period
Account data is deleted 90 days after account deletion. Articles and brand data are deleted by the user actively. For each article we additionally keep the last 4 versions (revision history, for example before an AI-assisted rewrite); older versions are deleted automatically and irrevocably as soon as a new version is created. Stripe-related data is kept for 10 years per commercial-law requirements. Server logs are anonymized after 30 days.
8. Your rights (GDPR)
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), objection (Art. 21), data portability (Art. 20). Send an email to hello@blog-maker.com. We respond within 30 days. You can also file a complaint with the relevant supervisory authority (in Cyprus: Office of the Commissioner for Personal Data Protection, https://www.dataprotection.gov.cy).
9. Security
Encrypted connection (TLS 1.3, HSTS), password hashing (bcrypt cost 12), brand credentials AES-256 encrypted, regular security audits, Sentry for real-time error monitoring. In case of data breaches we inform you and the supervisory authority within 72 hours.
10. Changes
We update this policy when features or processors change. Last change: September 21, 2026 (added section 5a on uploaded images and the provenance log). Before that, September 19, 2026 (Google Gemini added as data processor for image generation). Before that, September 18, 2026 (keyword cluster feature with DataForSEO as data processor is available, details on transmitted data and retention added; origin details from campaign links at registration added). We inform you by email about material changes.