Privacy Policy
Last updated: July 2026
The protection of your personal data is important to us. In the following, we inform you in accordance with Article 13 of the General Data Protection Regulation (GDPR) about which personal data we process in connection with this website (https://www.openpmm.com) and the provision of the OpenPMM web application, for what purposes and on what legal basis this is done, to which recipients data may be passed on, and what rights you have. We process personal data exclusively in accordance with the applicable data protection requirements, in particular the GDPR and the German Federal Data Protection Act (BDSG). Personal data is any information relating to an identified or identifiable natural person, for example your name, your email address or your IP address.
A. Information about the controller
The controller within the meaning of Article 4(7) GDPR, i.e. the entity that alone or jointly with others determines the purposes and means of the processing of personal data, is Heyora UG (haftungsbeschränkt), Leberstraße 63, 10829 Berlin, Germany, represented by its Managing Director Yannick Feige. You can reach us by email at hey@openpmm.com. The company is registered in the commercial register of the Local Court of Charlottenburg (Berlin) under HRB 286080 B. We have not appointed a data protection officer, as we are not legally required to do so. If you have any questions about data protection or wish to exercise your rights, you may contact us at any time directly at the address above or at hey@openpmm.com.
B. Information about the processing of your personal data
I. Provision of the website and server log files
When you use our website purely for informational purposes, i.e. when you do not register or otherwise transmit information to us, the browser used on your device necessarily transmits certain information to the server of our website for technical reasons. This includes in particular your IP address, the type and version of your internet browser, the operating system used, the page accessed, where applicable the previously visited page (referrer URL), and the date and time of access. This data is technically necessary in order to display the content you have requested and is stored temporarily in so-called server log files in order to ensure the secure and stable operation of the website and to detect and trace disruptions, such as attacks on our IT infrastructure.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the reliable provision as well as the security and stability of the IT infrastructure used for the website. The provision of this data is neither legally nor contractually required; however, without it the website cannot technically be delivered. The data stored in the server log files is, in a form that allows your identification, regularly deleted after a short period, unless longer storage is required to investigate a specific security-relevant incident.
Our website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes the aforementioned log data on our behalf as a processor; for this purpose we have concluded a data processing agreement with Vercel pursuant to Article 28 GDPR. As Vercel is based in the USA, a transfer of personal data to a third country may occur. Vercel is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA.
II. Registration and use of a user account
In order to use the OpenPMM web application, you can create a user account. As part of registration, we process the data you provide, in particular your email address and the access credentials required to log in, such as a password chosen by you, which is stored exclusively in encrypted or hashed form. If you provide further information, such as a name or display name, we also process this. In addition, we store administrative data relating to your account, for example the time of registration and of log-ins, account settings, and information needed to provide and secure the service.
We process this data in order to set up and manage your user account, to authenticate you, to enable you to use OpenPMM, and to communicate with you in connection with your account and the service, for example to inform you about security- or function-relevant changes. The legal basis for processing the data required to provide the account and the service is Article 6(1)(b) GDPR, as the processing is necessary for the performance of the user agreement concluded with you regarding the provision and use of the account, or to carry out pre-contractual measures. Insofar as we process the data beyond this in order to ensure the security and functionality of our service and to prevent misuse, we base this on Article 6(1)(f) GDPR; our legitimate interest lies in the secure and reliable provision of our service. Where statutory retention obligations exist, the legal basis is Article 6(1)(c) GDPR.
The provision of the data marked as mandatory is required to set up the account; without this information, we cannot create an account for you or provide the web application. Further information is voluntary. We store the data processed in connection with the account for the duration of the existence of your user account. If you delete your account or request its deletion, the data will be deleted as soon as it is no longer required for the stated purposes and no statutory retention obligations, such as those under tax or commercial law, or other legitimate reasons preclude deletion.
For authentication and the technical provision of the account, we use Supabase as a service provider and processor pursuant to Article 28 GDPR. Supabase provides the authentication, database, and storage services used for the OpenPMM account and workspace. Further information is available in Supabase's privacy policy at https://supabase.com/privacy. We also use Vercel for hosting as described in Section B.I. Any further disclosure of your data to third parties only takes place if this is necessary for the performance of the contract, if you have consented or if we are legally obliged to do so. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
OpenPMM is delivered as a web application. New versions become available when we deploy them to the service. The web application does not perform a separate automatic update check, and it does not perform a periodic status or license check on your device.
III. OpenPMM workspace data and connected services
When you use the OpenPMM web application, we process the data you enter or create there. This may include workspace settings, brand context and tone of voice, campaign drafts, generated text, channel-specific post content, schedules, publishing statuses, attached images or videos, and feedback or other content that you voluntarily submit. We process this data to provide the functions you request, to save and display your work, to send or schedule campaigns, and to maintain the security and reliability of the service.
If you connect a publishing channel, we process the account information and OAuth data required to establish and maintain that connection, together with the destination identifiers and publishing results needed to send your posts. We store access credentials and tokens server-side and protect them from being included in content-generation prompts. You complete the OAuth confirmation for each channel yourself. We share content and the information required to publish it with the channel provider you select. You can disconnect a channel through the available product controls; this does not necessarily delete data already published on that provider's service.
If source integrations or other connected services are available and you choose to use them, OpenPMM may process the content and identifiers needed to create a campaign from that source. The specific source providers and their availability are presented in the product when the relevant integration is enabled. The legal basis for this processing is Article 6(1)(b) GDPR when it is necessary to provide the service you requested, and otherwise Article 6(1)(f) GDPR. We do not use your workspace content for automated decision-making within the meaning of Article 22 GDPR.
Supabase acts as a processor for the account, workspace, campaign, and asset data described above. We use technical and organizational measures to protect this data and delete it when the relevant purpose ends, subject to statutory retention obligations and the storage periods described in Section F.
IV. Product and usage analysis in the OpenPMM web application
If you have consented to this, we collect anonymized usage and diagnostic data within the OpenPMM web application in order to improve the service, detect errors and vulnerabilities, and better understand which functions are used. For this purpose, we use the analytics tool PostHog. The data processed includes in particular a randomly generated, pseudonymous or anonymous identifier, the version of the web application, browser and operating system information, approximate location derived from the IP address, selected usage events, and onboarding or preference information that you choose to provide. We do not intend to transmit the contents of your campaigns, passwords, OAuth tokens, or uploaded assets as product analytics data.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as the storage of an identifier on your device or access to information on your device is concerned, Section 25(1) TDDDG. The collection only takes place after you have consented. You can withdraw your consent at any time with effect for the future using the available privacy or analytics settings. The lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of the data is neither legally nor contractually required and is not necessary for using OpenPMM; if you do not give consent, you will not suffer any disadvantages. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, which acts for us as a processor pursuant to Article 28 GDPR. The data is processed on infrastructure within the European Union, including the Frankfurt location, eu.i.posthog.com. Insofar as a transfer to the USA nevertheless occurs, PostHog is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists in this respect. We store the data until the stated purpose ceases to apply.
V. Crash and error reports in the OpenPMM web application
If you have consented to this, OpenPMM may transmit technical error reports when a crash or other technical error occurs, so that we can analyze the causes and improve the stability of the service. For this purpose, we use the Sentry service. The data processed includes in particular technical error information, such as exception and error messages and stack traces, the route or function involved, browser and device environment information, a pseudonymous account or session identifier where technically necessary, and your IP address for technical reasons. We configure technical filtering to avoid capturing passwords, OAuth access tokens, and campaign or asset content in error reports.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as access to information on your device is concerned, Section 25(1) TDDDG. The transmission only takes place after you have consented. You can withdraw your consent at any time with effect for the future using the available privacy or error-reporting settings. The lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of the data is not necessary in order to use OpenPMM. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
The provider is Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, which acts for us as a processor pursuant to Article 28 GDPR. As the provider is based in the USA, a transfer of personal data to a third country may occur. Functional Software (Sentry) is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA.
VI. In-app feedback
Within the OpenPMM web application, you can voluntarily send us feedback via a form. This function is triggered exclusively at your own initiative. The data processed includes the content of the feedback you submit, an email address you optionally provide, and accompanying technical information such as the browser or web application version. We use this data to process your feedback, to answer any follow-up questions, and to improve our service. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in processing and evaluating feedback to improve our application. Insofar as your feedback is aimed at the conclusion or performance of a contract, the legal basis is Article 6(1)(b) GDPR. Providing an email address is voluntary; however, without it we cannot reply to you directly.
We store the data until your request has been finally processed and no legitimate reasons preclude deletion. For the technical receipt and forwarding of the feedback, we use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA; we subsequently manage the feedback received in the project management tool Linear (Linear Orbit, Inc., San Francisco, USA). Both providers act for us as processors pursuant to Article 28 GDPR. As the providers are based in the USA, a transfer of personal data to a third country may occur. Both Cloudflare and Linear are certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists in each case for the transfer to the USA.
VII. Audience measurement and web analysis (website)
In order to statistically analyze the use of our website, to continuously improve it and to better tailor our services to the needs of our visitors, we use analytics tools. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place in this context.
1. Vercel Analytics
We use Vercel Analytics, a web analytics service provided by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. With Vercel Analytics, we collect aggregated usage statistics, such as which pages are accessed, the approximate origin of the access, and technical information such as browser and device type. The processing is anonymized and does not use cookies; IP addresses are not stored permanently, and no profiles that can be tracked across multiple websites are created. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the statistical, privacy-friendly analysis of website usage to optimize our service. Vercel acts for us as a processor pursuant to Article 28 GDPR. As Vercel is based in the USA, a transfer to a third country may occur. Vercel is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for this transfer.
2. Google Analytics
In addition, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies that enable an analysis of your use of the website. In doing so, information about your use is collected, for example pages visited, time spent, click behavior, approximate origin, a unique identifier for recognizing returning visitors, and technical information about your browser and operating system. This information is generally transmitted to a Google server and stored there. We have activated IP anonymization, so that your IP address is truncated by Google within the member states of the European Union or in other states party to the Agreement on the European Economic Area before transmission. From the data collected, Google creates pseudonymous usage profiles on our behalf, on the basis of which we can analyze where our visitors come from, which areas of the website they access and how they use it.
Google acts as a processor for us in this respect pursuant to Article 28 GDPR. The legal basis for the use of Google Analytics is exclusively your consent pursuant to Article 6(1)(a) GDPR and, insofar as the storage of information on your device or access to it is concerned, Section 25(1) TDDDG. We therefore only use Google Analytics after you have consented via our consent banner. You can withdraw your consent at any time with effect for the future by changing your selection in the cookie settings; the lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of this data is neither legally nor contractually required and is not necessary for using the website. If you do not give consent, you will not suffer any disadvantages; in that case, simply no analysis is carried out using Google Analytics. As Google is part of a globally operating group, a transfer of data to the USA or other third countries may occur. Google LLC is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA. The data stored in connection with Google Analytics is deleted as soon as it is no longer required for the stated purposes or after the configured retention periods have expired.
3. Google Ads conversion measurement
We use Google Ads conversion measurement, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to understand whether a person who clicked one of our ads later requests early access, creates an OpenPMM account, or completes another selected OpenPMM conversion. For this purpose, Google may use cookies and similar technologies and process information associated with the ad click, such as the Google Click Identifier (GCLID), together with information about the conversion interaction and technical information about the browser and device. We use this data only to measure the results of our advertising. We do not use Google Ads on this website for personalized advertising or remarketing. Advertising storage and the transmission of data for advertising measurement remain disabled unless you consent to advertising measurement in the cookie settings.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as information is stored on or accessed from your device, Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future by changing your selection in the cookie settings. The lawfulness of processing carried out before withdrawal remains unaffected. The provision of this data is neither legally nor contractually required and is not necessary for using OpenPMM or the website. If you do not give consent, OpenPMM remains fully available; we simply cannot attribute a later account registration or other conversion to an ad click. As Google is part of a globally operating group, a transfer of data to the USA or other third countries may occur. Google LLC is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission exists for the transfer to the USA. You can find further information in Google's privacy policy at https://policies.google.com/privacy.
4. Content management
We maintain the website's marketing pages, blog, and documentation in an editorial content-management workflow. This workflow uses content authored for the website and does not require visitors to submit personal data. It is not used to create visitor profiles or to make automated decisions. Technical data involved in delivering these pages is processed as described in Section B.I.
VIII. Consent management (cookie consent)
In order to obtain your consent to the use of non-essential cookies and comparable technologies and to document this in compliance with data protection law, we use a consent tool. In doing so, your consent decision and technically necessary information, such as the time of consent and an identifier, are stored, so that we can take your selection into account when you access the website again and demonstrate that consent has been given. The legal basis for this is our obligation to demonstrate consent pursuant to Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR, as well as our legitimate interest in a legally compliant design of our service pursuant to Article 6(1)(f) GDPR. The cookies used for this purpose are technically necessary.
IX. Contact by email
If you contact us by email, we process the data you transmit, in particular your email address and the content of your message, in order to process and respond to your request. The legal basis is Article 6(1)(b) GDPR if your request is aimed at the conclusion or performance of a contract, otherwise Article 6(1)(f) GDPR on the basis of our legitimate interest in responding to requests. We store this data until your request has been finally processed and no statutory retention obligations preclude deletion.
C. Your rights as a data subject
Within the framework of the statutory provisions, you have the following rights with regard to your personal data: pursuant to Article 15 GDPR, you have the right to request information about the personal data we process concerning you. Pursuant to Article 16 GDPR, you may request the rectification of inaccurate data or the completion of your data. Pursuant to Article 17 GDPR, you have the right to request the deletion of your data, insofar as no legal obligations or overriding reasons preclude deletion. Pursuant to Article 18 GDPR, you may request the restriction of processing. Pursuant to Article 20 GDPR, you have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
Insofar as we process data on the basis of your consent, you have the right pursuant to Article 7(3) GDPR to withdraw your consent at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent up to the withdrawal is not affected by this. Pursuant to Article 21 GDPR, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Article 6(1)(f) GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
To exercise your rights, an informal notification to the contact details provided in Section A is sufficient.
D. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right pursuant to Article 77 GDPR to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin. You may also contact the supervisory authority of your habitual residence or place of work.
E. Data security
When you visit the website or use the OpenPMM web application, we use the widely used TLS procedure (Transport Layer Security) in conjunction with the highest level of encryption supported by your browser. You can recognize an encrypted connection by the fact that the address line of the browser begins with "https://". Connections to external services used for authentication, hosting, analytics, error reports, feedback, channel connections, and publishing are also encrypted where technically supported.
In addition, we take appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. This includes access controls for account and workspace data, server-side protection of credentials and tokens, and measures designed to prevent sensitive content from being included in diagnostics or analytics where technically possible.
F. Storage period and deletion
We process and store your personal data only for as long as is necessary to achieve the respective processing purposes, or for as long as a statutory retention obligation exists. As soon as the respective purpose ceases to apply and no statutory retention obligation or other legitimate reason precludes deletion, the data concerned is routinely deleted or anonymized. Insofar as more specific information on the storage periods is provided in the preceding sections for individual processing operations, that information takes precedence.
The criteria that determine the specific duration of storage are, in particular: whether and for how long a user account or workspace exists with us, whether an ongoing matter such as a feedback request is still being processed, whether consent that has been given remains in effect, and whether the data is still needed to assert, exercise or defend legal claims. Data that arises for technical reasons, such as server log files, is deleted as soon as it is no longer required for the respective purpose.
Irrespective of this, we retain personal data insofar and for as long as we are legally obliged to do so, in particular due to retention obligations under commercial and tax law, for example under the German Commercial Code and the German Fiscal Code; the retention periods provided for there are usually between six and ten years. Data subject to such a retention obligation is restricted in its further processing for the duration of the period and deleted after the period has expired.
G. Currency and amendment of this privacy policy
This privacy policy is dated July 2026. As our website and our services continue to develop, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. You can access the current version at any time on this website at https://www.openpmm.com/privacy.