Privacy Policy
1. Controller
The controller responsible for data processing is:
Hefti OG
Schillerstraße 53, 6700 Bludenz, Österreich
Email: mail@hefti.at
2. What data we process
- Master & contact data (e.g. name, email address) to provide your account
- Usage data (e.g. content you create, settings, login times)
- Payment data to handle paid plans (via the respective payment provider)
- Device & notification data (e.g. push subscription, browser/device info), only if you enable push notifications
- Media data: images/videos you upload as well as AI-generated images you use in the app
- Social media connection data: if you connect a Facebook/Instagram account, the ID and name of your Facebook Page and Instagram business account, a user ID assigned by Meta, access tokens, and the reach/engagement/follower statistics we retrieve (see section 4b)
3. Purposes & legal bases
Processing is carried out to perform the contract (Art. 6(1)(b) GDPR), to comply with legal obligations (lit. c) and on the basis of legitimate interests (lit. f), e.g. for the security and improvement of the service.
3a. Push notifications
If you enable notifications, we store the subscription data technically required for this (push endpoint and keys) as well as a browser/device identifier for device management. The basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time in the settings or on your device.
3b. Cookies and local storage (Sec. 25 TDDDG)
Technically necessary storage (no consent required, Sec. 25(2) TDDDG):
- Application session cookie: keeps you logged in and becomes invalid when you close the browser or after the session expires.
- Your browser's local storage (localStorage): stores your app settings (e.g. light/dark mode, view states) solely on your device.
- Service worker cache (PWA): stores program files locally so the app loads faster and works offline.
Referral and campaign cookies (only set if you reach us via a referral or campaign link):
- "sp_ref": remembers the referral code so a referral can be attributed correctly (lifetime 30 days).
- "sp_src": remembers the source/campaign of your visit (lifetime 30 days).
- "sp_refclk_...": prevents the same click from being counted multiple times (lifetime 1 day).
These cookies are set exclusively by us (first-party) and are not used for cross-device or cross-site tracking by third parties. The legal basis is our legitimate interest in a functioning referral program (Art. 6(1)(f) GDPR). You can delete these cookies at any time in your browser settings.
External content (demo video):
A demo video may be embedded on our home page. If it is stored as a YouTube or Vimeo video, it is not loaded automatically: at first only a placeholder appears, and only when you actively click "Load video" is the video loaded from the respective provider (YouTube/Google or Vimeo, USA). In doing so, data (including your IP address) is transmitted to the provider; the legal basis is your consent via the click (Art. 6(1)(a) GDPR). A self-hosted video is delivered directly from our server without third parties.
3c. Access by our team (support, optimization & security)
Staff with administrator rights may, to the extent necessary, access the content stored in your account (e.g. your content library with ideas and posts). Such access takes place exclusively for the following purposes: handling support and help requests, fixing technical faults and errors, ensuring proper operation, improving and optimizing our service, and maintaining security (e.g. checks in the event of justified suspicion of abuse). Access is limited to a small group of authorized persons bound to confidentiality, is read-only, and is logged together with the reason for access. We do not use your content for unrelated purposes and do not pass it on to third parties. The legal basis is our legitimate interest in a secure, stable and continuously improved service and in functioning support (Art. 6(1)(f) GDPR); insofar as access is necessary to handle your request, additionally the performance of the contract (Art. 6(1)(b) GDPR).
4. Disclosure to third parties
Data is only disclosed insofar as this is necessary to perform the contract (e.g. hosting, external storage of media files, payment processing, AI services for text and image generation) or is required by law. Contracts pursuant to Art. 28 GDPR exist with processors.
4a. Storage of media files (images/videos)
Images/videos you upload and AI-generated images/videos are stored on our behalf in object storage within the EU (processor located in Germany/the EU). Delivery takes place via publicly accessible, non-guessable links (random file names); this is technically required in order to display the media in the app and publish it on the social media networks you choose. Please only upload content that is intended for publication. For faster display, small preview images may additionally be stored on our server.
If you connect an external cloud source (e.g. Google Drive or OneDrive), the files remain in your own cloud; we only store the shareable link you have released.
For AI image generation, we transmit the necessary inputs to an AI provider (OpenAI, USA); the third-country transfer is safeguarded by standard contractual clauses / the EU-US Data Privacy Framework.
4b. Connecting your social media accounts (Meta: Facebook & Instagram)
When you connect your Facebook Page and/or Instagram business account to the app, we process the data required for this via Meta's official programming interfaces (Facebook Graph API / Instagram Graph API):
- Account connection data: the ID and name of your Facebook Page, the ID of your connected Instagram business account, a user identifier assigned by Meta (app-scoped user ID) and the access tokens technically required for the connection. Access tokens are stored securely and used exclusively to maintain the connection you requested.
- Publishing: content you create and approve in the app (feed posts, carousels, reels, stories) is published on your behalf to the accounts you select.
- Statistics/insights: at your request we retrieve reach, engagement and follower metrics as well as account- and post-related analytics in order to display them to you in the app.
We use this data exclusively to provide the functions you actively use (planning, publishing, analyzing) and do not pass it on to third parties for advertising purposes. The legal basis is the performance of the usage contract concluded with you (Art. 6(1)(b) GDPR).
You can end the connection at any time: in the app settings, in the security settings of your Facebook account (section "Logged in with Facebook" or "Business integrations") or by requesting data deletion. If you disconnect, we delete or block the stored access tokens. You can also trigger deletion of the Meta connection data stored with us at any time via our data deletion page (accessible via the "Data deletion & privacy" link); there you will receive a confirmation code for tracking.
The platform provider is Meta Platforms Ireland Ltd. (Ireland); processing in the USA cannot be ruled out and is safeguarded by appropriate guarantees (EU standard contractual clauses or the EU-US Data Privacy Framework).
5. Storage period
We store personal data only for as long as is necessary for the stated purposes or as long as statutory retention periods exist.
5a. Data backups
For failover protection we automatically create a daily backup of the database. These backups are usually retained for seven (7) days and then deleted automatically. They serve solely for recovery in the event of a fault or emergency and are subject to the same technical and organizational protection measures as the live data. After your data is deleted, it may still be contained in backups created in the meantime for up to seven (7) days before the respective backup is deleted on schedule. If you need your own copy of your data beyond this, you can use the export function in the application at any time.
6. Your rights
You have the right to information, rectification, erasure, restriction of processing, data portability and objection. You also have the right to lodge a complaint with a data protection supervisory authority.
7. Contact
For data protection inquiries you can reach us at: mail@hefti.at
Last updated: 28.07.2026