PostOmnia ← Back Deutsch

Privacy Policy

This policy explains how PostOmnia processes account, channel, content and billing data. The German version is the legally binding one.

1. Controller

Fade Media GmbH, Beispielweg 1, 10115 Berlin, email: info@postomnia.com

2. What data we process

3. Purposes & legal bases

Provision of the service and performance of the contract (Art. 6(1)(b) GDPR), retaining and responding to historical agency enquiries and related pre-contractual steps (Art. 6(1)(b)) on the basis of the contact consent originally given (Art. 6(1)(a)), security and abuse prevention (Art. 6(1)(f)), and statutory retention of invoices (Art. 6(1)(c)). Consent may be withdrawn at any time by email with effect for the future.

4. Recipients / processors

We use the following processors under data processing agreements pursuant to Art. 28 GDPR:

4a. AI processing in detail

AI features only run when you trigger them – with one exception: if you enable evergreen recycling for a published post, PostOmnia automatically rephrases that post's text at the configured time and creates a scheduled draft from it. The draft is never published without your involvement. This automatic rephrasing happens only for posts you explicitly enabled recycling for.

What is transmitted to the AI provider is the post text or image brief in question plus the brand settings stored in your workspace (tone, audience, word lists). Account data, access tokens of connected channels, billing data and analytics data are not transmitted.

Every use of AI is recorded in your workspace audit log (time, action, model, output length). The prompt and the generated text are not stored there.

There is no automated decision-making within the meaning of Art. 22 GDPR: AI output is a suggestion, and you decide whether to publish. Which systems we use and how generated content is labelled is set out in our AI transparency statement.

5. Transfers to third countries

Where processors are located in the USA (Anthropic, Google, GitHub, Stripe), transfers are safeguarded by an adequacy mechanism under Art. 44 ff. GDPR – in particular certification under the EU-US Data Privacy Framework and/or EU standard contractual clauses (SCCs) concluded with the respective provider. Backup data transferred to GitHub is additionally encrypted before it leaves the EU, so the provider never has access to readable personal data.

6. Google user data and YouTube

When you connect a Google or YouTube account, PostOmnia uses Google OAuth to request only the permissions needed to provide the features you choose. This may include access to your YouTube channel identity, upload/publishing permissions for videos you select, and basic metadata or metrics needed to show whether publishing succeeded and to display performance information in PostOmnia.

PostOmnia uses Google user data only to connect your selected channel, publish or schedule content on your behalf, display connected-account information, and show related publishing status or analytics inside PostOmnia. We do not sell Google user data, use it for advertising, or transfer it to unrelated third parties.

OAuth access and refresh tokens are stored only for as long as the channel remains connected and are used solely to keep the connection working. You can disconnect a Google/YouTube channel at any time in PostOmnia; after disconnection, PostOmnia no longer uses the token for that channel. You may also revoke PostOmnia's access in your Google Account security settings.

PostOmnia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Product analytics

If you consent to analytics, PostOmnia records first-party product events to understand which pages, buttons and workflows are useful and where the product can be improved. The events are stored on this server as daily CSV files under data/tracking. We do not use third-party analytics scripts, advertising networks or cross-site tracking for this.

Analytics events contain technical product context such as event name, page path without query parameters, visible button/link label, active view, language, viewport size, anonymous session identifier and, for signed-in use, general account context such as role and plan. We do not store passwords, form field values or full URLs with tokens in these tracking files. If present, campaign parameters such as utm_source or utm_campaign and internal experiment variants may be stored to measure which campaigns or page variants work best. If a workflow is abandoned, an optional short reason can be recorded. Aggregated weekly analytics reports, monthly CSV summaries, Google-Sheets-ready exports, scoring summaries and critical product alerts may be sent internally to the PostOmnia operators. Product state such as verification, connected channels, posts and trial status may also be used to show setup checklists and send occasional lifecycle emails that help users complete onboarding. The default retention period is 180 days.

Independently of optional analytics consent, closing the registration wizard before an account is created generates a strictly limited operational event and an immediate internal notification to the PostOmnia operators. It contains only the wizard step, selected plan and billing interval, page path, duration and an anonymous session identifier; registration form values are not transmitted. A reason is added only if you voluntarily submit it in the follow-up dialog.

8. Backups

To protect against data loss, an encrypted backup of the database is created nightly and stored off-site in a private repository. Backups are encrypted on our server before transfer; the key is never stored alongside the backups. Backups are kept for a rolling window of 30 days and then deleted automatically. Backups are used exclusively for disaster recovery and are never used to restore individual deleted accounts.

9. Retention

Account data until your account is deleted; invoices in accordance with statutory periods (typically 10 years). Optional product analytics events are kept for up to 180 days by default. Historical agency enquiries are deleted after no more than 12 months if no contractual relationship results, or earlier after consent is withdrawn unless a legal retention duty applies.

If you delete your account (or a team), the data is removed from the live systems immediately. Copies inside encrypted backups disappear automatically with the backup rotation, at the latest 30 days after deletion.

10. Cookies / local storage

PostOmnia sets no third-party cookies and no tracking cookies. We only use your browser's local storage: technically necessary entries for login, your language/theme preference and your consent choice, plus – only if you accept analytics – a local, anonymous session identifier for our own privacy-friendly product analytics. No personal data is shared with third parties for advertising.

Your consent is optional, revocable at any time and expires after 12 months (we ask again afterwards). Manage or withdraw it here:

Open cookie settings

10a. Marketing / advertising (only with consent)

If – and only if – you accept the “Marketing” category in our consent settings, we load advertising pixels of the following third parties to measure and optimize our advertising campaigns. Without your consent these are never loaded and no data is sent to them:

These providers may process data outside the EU. You can withdraw your marketing consent at any time via the cookie settings; withdrawal takes effect for all further page loads.

11. Your rights

You have the right to access, rectification, erasure, restriction, data portability and objection. In PostOmnia you can exercise these directly:

You also have the right to lodge a complaint with a data protection supervisory authority.

12. Contact

Privacy questions: info@postomnia.com

Last updated: 2026-08-02