Privacy Policy
This page explains how personal data is processed when you visit the Published website or use account-related features. It documents all third-party services that process personal data on our behalf or in connection with our services. The application itself launches shortly and is already described here in full, so that you can see before signing up what will happen to your data; the sections on accounts, media, AI analysis, publishing, and payments apply from the moment it goes live.
1. Controller
Cosmic Code GmbH
Ehrenbergstraße 44, 22767 Hamburg, Germany
2. Purposes and legal bases
We process personal data only to the extent necessary to operate the website, provide secure account access, answer inquiries, and protect the product against misuse.
Depending on the specific processing activity, the legal bases are Article 6(1)(b) GDPR where processing is necessary to provide account and contract-related functionality, Article 6(1)(f) GDPR for security, abuse prevention, and technical operation, and Article 6(1)(c) GDPR where statutory retention duties apply.
3. Website access data
- When you visit the site, technical request data may be processed, including IP address, browser and device information, timestamps, referrer, and requested resources.
- We use this data to deliver the site securely, diagnose technical issues, and maintain system integrity.
- Retention depends on operational necessity and security requirements.
4. Cookies and local storage
- This website does not use tracking, analytics, or marketing cookies, and no third-party tracking scripts are loaded. A cookie consent banner is therefore not required.
- If you switch between light and dark mode, your preference is stored in your browser’s localStorage. This storage is triggered by your own action and is strictly necessary to provide the function you requested; it is therefore permitted without consent (Section 25(2) no. 2 of the German TDDDG).
- Our hosting provider Cloudflare may set strictly necessary cookies (for example “__cf_bm”) for bot detection and to protect the site against automated abuse. These cookies are required for the secure operation of the site (Section 25(2) no. 2 TDDDG, Article 6(1)(f) GDPR) and expire after a short time.
5. Desktop plugins (Lightroom, Eagle)
- Our plugins for Adobe Lightroom Classic and Eagle run on your own computer and upload media into your account. They are our own software; no third party is involved in the connection itself.
- Pairing runs through a sign-in in your browser plus a short-lived PIN. The PIN record holds the pairing state, your user and account reference, the number of attempts, and an expiry timestamp, and it is deleted once it has been redeemed or has expired.
- A successful pairing issues an access token for the plugin. We store only a hash of that token plus a short non-secret prefix that lets you recognise it in the list, together with the time it was last used. You can revoke a token at any time in the settings, which ends the plugin’s access immediately.
- Uploading transfers the original image and video files together with their embedded metadata — EXIF, XMP, and IPTC, which can include capture time, camera and lens, GPS coordinates, and the names of photographers or rights holders. This data is stored with the file and is used for the features that build on it, such as location tagging.
- Legal bases: Article 6(1)(b) GDPR for the upload and the connection itself, and Article 6(1)(f) GDPR for the abuse protection built into pairing (attempt counting, lockout, expiry).
6. Email signup and opt-in proof
- When you join the waitlist or newsletter, we store in our own database — as the controller, separately from our email provider — your email address, opt-in status, the request and confirmation timestamps, and the version of the consent text shown to you.
- For abuse prevention (Article 6(1)(f) GDPR) we additionally record the IP address and user agent captured at opt-in. These two fields are automatically deleted 90 days after confirmation.
- The opt-in status, timestamps, and consent copy version are retained as proof of consent (Article 7 GDPR) for as long as you remain subscribed.
7. Processors and third-party services
The following third-party services process personal data on our behalf or in connection with our services.
7.1 Kinde — Authentication and user management
We use Kinde Pty Ltd (Level 4, 60 Martin Place, Sydney NSW 2000, Australia) for registration, sign-in, session management, user administration, and related security features. Kinde operates regional infrastructure; for our deployment customer data is processed in the European Union.
Under Kinde’s Data Processing Addendum, we act as controller for our end users’ personal data and Kinde acts as processor. Kinde may process limited account information as an independent controller where required to operate the service and the contractual relationship with us.
- Categories of data: email address, name, profile image URL, authentication identifiers, session data, technical metadata such as IP address, browser and device information, and where applicable role and permission assignments.
- Purposes: account creation, sign-in, verification, session management, abuse prevention, and account administration.
- Legal bases: Article 6(1)(b) GDPR for account and contract functionality, plus Article 6(1)(f) GDPR where security and misuse prevention measures are required.
7.1.1 Transfer safeguards
Kinde is headquartered in Australia and runs regional data residency. EU customer data is hosted in EU regions. Where Kinde or its subprocessors process data outside the EEA, the Kinde DPA incorporates Standard Contractual Clauses as the transfer mechanism.
- Primary measure: EU data residency for end-user authentication data.
- Fallback mechanism: Standard Contractual Clauses as incorporated by the Kinde DPA.
- Current subprocessors and their processing locations are published by Kinde on its trust and subprocessor pages.
7.2 Convex — Backend infrastructure and database
We use Convex, Inc., San Francisco, CA, United States, as our backend infrastructure provider. Convex hosts our application database, executes serverless functions, and provides file storage. In this context, Convex acts as a processor under Article 28 GDPR.
- Categories of data: user profile data linked to authentication (user IDs, display names, email addresses), application content created or uploaded by users (documents, media references, project metadata, image metadata including EXIF/XMP/IPTC), organization and membership data, and technical metadata (timestamps, function execution logs).
- Purposes: persistent storage of application data, execution of server-side business logic, real-time data synchronization between clients, and file storage.
- Legal bases: Article 6(1)(b) GDPR for contract performance and Article 6(1)(f) GDPR for system integrity and security.
7.2.1 Processing location and transfer safeguards
Our Convex deployment runs in Convex’s European region. Convex hosts its platform on Amazon Web Services; the region we use is AWS eu-west-1 (Ireland). Application data is therefore stored and processed within the European Union.
Convex, Inc. is headquartered in the United States, so access from the United States for operating and supporting the platform cannot be excluded. Such access is governed by the Convex Data Processing Addendum, which forms part of our agreement with Convex and incorporates the EU Standard Contractual Clauses (Module Two, controller to processor) as the transfer mechanism.
7.3 Cloudflare — Hosting, CDN, and object storage
We use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States, for website hosting (Cloudflare Pages), serverless computing (Cloudflare Workers), content delivery (CDN), and object storage (Cloudflare R2). Cloudflare acts as a processor for these services.
- Categories of data: IP addresses and technical request metadata (browser, device, timestamps, referrer) processed during content delivery, as well as user-uploaded media files stored in R2 (which may contain embedded image metadata such as EXIF data including GPS coordinates).
- Purposes: secure delivery and hosting of the website, edge computing for image processing, and persistent storage of user-uploaded media.
- Legal bases: Article 6(1)(b) GDPR for providing the service and Article 6(1)(f) GDPR for security, performance optimization, and DDoS protection.
7.3.1 Transfer safeguards
Our R2 bucket is created with the EU jurisdictional restriction. Cloudflare guarantees for such buckets that the objects they hold are stored within the European Union — user-uploaded media therefore rests exclusively on EU infrastructure.
Delivery is a separate matter from storage: hosting, CDN, and image processing run on Cloudflare’s global network, and content is served from the edge location closest to the visitor. Temporary cached copies of publicly delivered media can therefore exist at edge locations outside the EU.
Cloudflare, Inc. is based in the United States. It is self-certified under the EU–U.S. Data Privacy Framework and offers a Data Processing Addendum that includes Standard Contractual Clauses.
7.4 Stripe — Payment processing
We use Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, CA 94080, United States, and its EU entity Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland, for payment processing. Depending on the processing activity, Stripe acts as a processor on our behalf or as an independent controller for its own fraud prevention, regulatory compliance, and financial reporting obligations.
Payment card details are collected directly by Stripe through Stripe Elements. Card numbers are never transmitted through or stored on our servers. Stripe is a certified PCI DSS Level 1 service provider.
- Categories of data: name, email address, billing address, payment method details (handled directly by Stripe), transaction amounts, currency, transaction identifiers, and device data and IP address for fraud detection.
- Purposes: processing payments for subscriptions or purchases, invoice generation, fraud detection and prevention, and regulatory compliance (anti-money laundering, sanctions screening).
- Legal bases: Article 6(1)(b) GDPR for payment processing necessary to perform the contract, Article 6(1)(c) GDPR for Stripe’s statutory obligations as a payment service provider, and Article 6(1)(f) GDPR for fraud prevention.
7.4.1 Transfer safeguards
Stripe Payments Europe, Ltd. processes EU payment data within the EEA where possible. For transfers to Stripe, Inc. in the United States, Stripe relies on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses.
7.5 Google Vertex AI — AI-assisted image analysis and text generation
We use Vertex AI, a Google Cloud service, for automated image and text analysis inside our application. For customers with a billing address in Europe, the Middle East, or Africa, the contracting entity is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google acts as a processor under the Cloud Data Processing Addendum.
Note that this is the enterprise Google Cloud offering, not the Gemini consumer app or the Gemini Developer API — a different set of terms applies, and Google does not use the data we submit to train or improve its models.
- Categories of data: uploaded image files and video frames, their embedded metadata, captions and other text submitted for analysis or generation, the analysis results themselves, and the API request data required to authenticate the call.
- Purposes: structured analysis of uploaded media (among others mood, style, shot type, lighting, colour, subject, and context), generation of caption and hashtag suggestions per target platform, and the calculation of vector embeddings that make semantic search across a media library possible.
- Legal bases: Article 6(1)(b) GDPR, because AI-assisted analysis and generation are core functions of the product, and Article 6(1)(f) GDPR for assessing content quality and relevance.
- No automated decision-making with legal or similarly significant effect within the meaning of Article 22 GDPR takes place. Every generated result is a draft that users review, edit, or discard.
7.5.1 Processing location
We call Vertex AI in the Google Cloud regions europe-west4 (Netherlands) and the EU multi-region. Analysis and generation therefore run on European infrastructure.
Google Ireland Limited is established in the European Union. Where Google or its affiliates access data from outside the EEA — for support and operations, for example — the Cloud Data Processing Addendum provides the transfer mechanism, including Standard Contractual Clauses.
7.5.2 Abuse monitoring
Google documents that, where automated safety classifiers flag suspicious activity, prompts may be logged in order to examine whether the acceptable use policy has been violated. According to Google, such logged data is not used to train models, is stored for up to 90 days, and remains in the region or multi-region selected for the project — for us, therefore, within the EU.
7.6 Social media integrations — Publishing to social media platforms
Our application publishes and manages content through accounts on Instagram, Facebook, Threads, X, Bluesky, Pinterest, and TikTok; which of these platforms can currently be connected is shown in the app. When a user connects a platform, our application accesses that platform’s API on the user’s behalf using OAuth tokens.
The platforms themselves act as independent controllers for the data processed on their own services — including the data of people who see or interact with published content. We act as a controller for the OAuth tokens and connection data stored in our systems. OAuth tokens are stored encrypted.
- Categories of data: OAuth access and refresh tokens (stored encrypted), platform user identifiers, page, board, or profile identifiers, profile names and avatars, platform-specific content identifiers, and the content and performance metadata returned by the platform APIs.
- Purposes: authenticating with the platform on the user’s behalf, publishing content to connected accounts, retrieving post performance data, and managing platform connections.
- Legal bases: Article 6(1)(b) GDPR for providing the publishing functionality as part of the service.
7.6.1 Publishing to a platform is a transfer to that platform
Whatever a user publishes through us — images, videos, captions, hashtags, and any location a user tags — is transmitted to the selected platform and is subject to that platform’s own privacy policy and terms from that point on. Several of these platforms are based in the United States and operate globally. Users decide themselves which content goes to which platform.
Where an image shows identifiable people, publishing it makes their personal data available on the platform in question. Responsibility for having the necessary legal basis for that publication lies with the user who publishes.
7.6.2 Token lifecycle and disconnection
OAuth tokens are stored only for as long as a platform connection is active. When a user disconnects a platform, the access token — and, for Bluesky, the session — is deleted from our systems and the connection is marked as disconnected. Its platform identifier and profile name and the content already synchronised from it remain stored until the brand is deleted (with the exceptions listed in the deletion guide) or we have carried out an erasure request. Token refresh cycles follow each platform’s expiry policy.
7.7 OpenStreetMap (Nominatim) — Location search for post tagging
When a user searches for a place to tag on a post, or when we turn the GPS coordinates found in an image’s metadata into a place name, we query Nominatim, the geocoding service of the OpenStreetMap Foundation, St John’s Innovation Centre, Cowley Road, Cambridge CB4 0WS, United Kingdom. The Foundation acts as an independent controller for the operation of that service.
The query is sent from our backend, not from the user’s browser. The user’s IP address and browser information are therefore not disclosed to the Foundation; what reaches it is the search term or the coordinates.
- Categories of data: the search term entered by the user, or latitude and longitude — which may originate from the GPS data embedded in an uploaded photo.
- Purposes: finding places for location tagging and resolving coordinates into a readable place name.
- Legal bases: Article 6(1)(b) GDPR, since location tagging is part of the publishing functionality the user requested.
7.7.1 Use by the Foundation and transfer safeguards
According to its privacy policy, the Foundation may analyse Nominatim queries in order to improve the OpenStreetMap dataset, for example to identify missing addresses and postcodes, and may publish data derived from this. The Foundation states that it does not release personal information, or information linked to an individual, to third parties.
The United Kingdom is a third country for which the European Commission has issued an adequacy decision (renewed on 19 December 2025 and valid until 27 December 2031). The transfer is therefore based on Article 45 GDPR and requires no additional safeguards.
7.8 Brevo — Email delivery and contact list management
We use Brevo (operated by Brevo SAS, Paris, France; DACH entity Sendinblue GmbH, Cologne, Germany) to deliver our emails and to manage subscriber contact lists. Brevo acts as a processor under Article 28 GDPR.
We send two kinds of email over separate streams, and they rest on different legal bases.
- Categories of data: email address, list membership, the content of the email sent, and delivery events (delivery, opens, clicks, unsubscribes, bounces).
7.8.1 Marketing emails
- Content: the double opt-in confirmation email, waitlist announcements, and the newsletter.
- Legal basis: Article 6(1)(a) GDPR — consent, obtained by double opt-in and revocable at any time via the unsubscribe link in every email.
7.8.2 Transactional emails
- Content: notifications about your own use of the product — reports on whether scheduled posts published successfully, and warnings when the connection to a social media account has expired or failed.
- These emails carry the data needed to make the notification useful: the affected brand and social account, post status and scheduling times, and the reason a publication failed.
- Legal bases: Article 6(1)(b) GDPR, because these notifications are part of the service, and Article 6(1)(f) GDPR for informing users about faults in their connected accounts.
- They are not marketing and therefore carry no unsubscribe link. Which notifications you receive is configured in your account settings.
7.8.3 Transfer safeguards
Brevo is an EU-based provider and processes data on servers within the European Union. No transfer to a third country is required for this service.
7.9 webhostone — Mailbox hosting for our contact addresses
The mailboxes behind our published.social contact addresses are hosted by webhostone GmbH, Rheinvogtstraße 17, 79713 Bad Säckingen, Germany. The provider receives and stores email sent to us and dispatches the replies we write. webhostone acts as a processor under Article 28 GDPR.
This is separate from Brevo, which we use to send emails to our subscribers and users. Anything you write to us directly lands here.
- Categories of data: your email address and sender name, the subject and body of your message, any attachments, and the technical headers of the message (timestamps, the IP address of the sending mail server, delivery paths).
- Purposes: receiving, storing, and answering enquiries sent to our contact addresses.
- Legal bases: Article 6(1)(b) GDPR where the correspondence concerns a contract or steps taken prior to entering into one, Article 6(1)(f) GDPR for all other enquiries, and Article 6(1)(c) GDPR where commercial correspondence is subject to statutory retention duties.
7.9.1 Storage location and retention
The mail servers used are operated in Germany, so no transfer to a third country takes place for this service.
We keep correspondence for as long as it is needed to deal with your enquiry and any follow-up questions. Where an email qualifies as commercial or business correspondence, statutory retention periods under German commercial and tax law apply (six or ten years, Section 257 HGB, Section 147 AO).
8. International transfers
The processing that touches the most data runs inside the European Union: application data and file storage at Convex in Ireland, AI analysis at Google Vertex AI in EU regions, authentication at Kinde in EU regions, and email delivery at Brevo on EU servers.
Third-country transfers remain in three places. Cloudflare serves the site from the edge location closest to the visitor and therefore operates globally. Stripe processes payment data in the United States. Content that a user publishes goes to the social media platform they selected, several of which are US-based. Where personal data is transferred to a third country, the transfer relies on the mechanism described in the relevant service section above (EU–U.S. Data Privacy Framework, Standard Contractual Clauses, or other applicable safeguards).
9. Storage periods
Account data and the content you upload are stored for as long as your account exists.
We do not currently run an automated account-deletion routine. If you ask us to erase your data, we carry out the deletion by hand and inform you of the outcome within the period set by Article 12(3) GDPR — one month from receipt of the request, extendable by a further two months for complex requests, in which case we will tell you within the first month.
- Deleted automatically on a schedule: the IP address and user agent recorded at newsletter opt-in, 90 days after confirmation; email delivery records after 30 days; notification events after 45 days; the pairing PIN for a desktop plugin after five minutes; OAuth state tokens after a short period.
- Deleted on your action: the access token of a desktop plugin when you revoke it, and the access token (for Bluesky also the session) of a social media account when you disconnect it. The connection itself is marked as disconnected; its platform identifier and profile name and the content already synchronised from it remain stored and are removed together with the brand — with the exceptions listed in the deletion guide — or on request.
- Retained despite an erasure request: data subject to statutory retention duties, in particular invoices and commercial correspondence under Section 257 HGB and Section 147 AO (six or ten years). Its processing is restricted to those retention purposes.
- Log and security data is kept for short operational periods where this is necessary to detect abuse or investigate incidents.
10. Recipients
Personal data is disclosed only where this is necessary for service delivery, legal compliance, or secure technical operations. The following recipients process personal data in connection with our services:
A current list, stating for each provider its legal entity, where it processes data, and on what basis, is kept at published.social/subprocessors.
- Kinde for Authentication and user management.
- Convex for Backend infrastructure and database.
- Cloudflare for Hosting, CDN, and object storage.
- Stripe for Payment processing.
- Google Vertex AI for AI-assisted image analysis and text generation.
- Social media integrations for Publishing to social media platforms.
- OpenStreetMap (Nominatim) for Location search for post tagging.
- Brevo for Email delivery and contact list management.
- webhostone for Mailbox hosting for our contact addresses.
11. Data subject rights
- Right of access under Article 15 GDPR.
- Right to rectification under Article 16 GDPR.
- Right to erasure under Article 17 GDPR.
- Right to restriction of processing under Article 18 GDPR.
- Right to data portability under Article 20 GDPR.
- Right to object under Article 21 GDPR.
- Right to lodge a complaint with a supervisory authority.
12. Security
We implement technical and organizational measures appropriate to the risk in order to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.
13. Updates to this policy
We may update this privacy policy where our services, processors, or legal obligations change. The version published on this page is the current version.