Privacy policy
This policy explains which personal data Post Audit processes, why, and what rights you have. Draft as of 12 September 2026.
1. Controller
souveraign minds GmbH
Wipfelweg 9a
44265 Dortmund
Germany
Represented by: Andreas Christiani (managing director)
Register: Amtsgericht Dortmund, HRB 32685
VAT ID: DE277514575
Email: information@souveraign.de
2. What we process
- X account data: your X user ID, handle, display name, follower count and account creation date.
- Your posts: text, timestamps and metrics (impressions, replies, likes, bookmarks, reposts, quotes) of your latest original posts, and for the Full Audit also of your own replies.
- For the Full Audit: for each substantive reply, the follower count of the account you replied to and the time of their post. We do not store the text of other people's posts.
- OAuth tokens from X, stored encrypted (AES-256-GCM).
- Optional: your email address, and your choices for the 4-week reminder and the benchmark pool.
- Payments: checkout session ID, payment ID, product, amount, currency and status from Stripe, plus the version and time of your consent to the immediate start. If your account has no email address, we use the address you entered at checkout once for the purchase confirmation and do not store it. We never see card details.
- Technical data: a signed session cookie, a short-lived login cookie, and a keyed hash of your IP address for rate limiting.
- Email log: type, time and delivery status of the mails we sent you. The log holds no email addresses.
3. Purposes and legal bases
- Running the checks you request and showing you the result: performance of a contract, Art. 6 (1) (b) GDPR.
- Adding pseudonymised numbers to the benchmark pool: your separate consent, Art. 6 (1) (a) GDPR. Withdraw any time by deleting your account.
- The 4-week reminder and waitlist emails: your consent, Art. 6 (1) (a) GDPR, confirmed by double opt-in for the waitlist.
- Security, abuse prevention and cost limits: legitimate interest, Art. 6 (1) (f) GDPR.
We make no decisions based solely on automated processing that have legal or similarly significant effects on you (Art. 22 GDPR). The classification of your posts only feeds the statistics in your own report.
4. Processors and recipients
Processors acting on our instructions under Art. 28 GDPR:
- Anthropic PBC, USA: classification of your post texts. We send the text, the date and your handle of each post, never your metrics.
- Supabase: database hosting.
- Resend: sending the emails listed above.
- Hetzner Online GmbH, Gunzenhausen, Germany: running the website and the job worker on a server in Germany.
Independent parties, not our processors:
- X Corp.: the source of your data. We read it through the official X API after you granted read-only access, and X sees that access.
- Stripe and Link: the checkout runs on Stripe's pages. With Stripe Managed Payments, Link is the merchant of record for your purchase, is the controller for the payment details you enter there and handles them under Stripe's privacy policy. We only receive the payment status and identifiers listed above.
Where data is processed outside the EU, transfers rely on the EU-US Data Privacy Framework or standard contractual clauses.
5. Benchmark pool
Only with your separate opt-in. The pool holds numbers and category labels per post (reach, bookmarks, replies, post type, hook and similar), your follower range and the week of posting. It holds no text, no handle and no post IDs; keys are one-way pseudonyms, so the rows stay pseudonymous rather than anonymous and remain linked to you until you delete your account. Deleting your account removes your pool rows.
6. Storage and deletion
We keep your data while your account exists. You can delete your account at any time in your account page; this deletes your account, tokens, posts, labels, checks, reports and pool rows and revokes our access at X. Posts you deleted on X are removed with the next check. Payment records are kept as required for bookkeeping, without link to your deleted account.
7. Your rights
You have the right of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent. You can lodge a complaint with a data protection supervisory authority.
8. Cookies
We use only technically necessary cookies: a session cookie (30 days) and a login cookie (10 minutes). No tracking, no analytics cookies.