Legal / privacy
Privacy Policy
Last updated: August 19, 2026
The protection of your personal data is important to us. In the following, we inform you in accordance with Article 13 of the General Data Protection Regulation (GDPR) about which personal data we process in connection with this website (https://www.openpmm.com) and the provision of the OpenPMM web application, for what purposes and on what legal basis this is done, to which recipients data may be passed on, and what rights you have. We process personal data exclusively in accordance with the applicable data protection requirements, in particular the GDPR and the German Federal Data Protection Act (BDSG). Personal data is any information relating to an identified or identifiable natural person, for example your name, your email address or your IP address.
A. Information about the controller
The controller within the meaning of Article 4(7) GDPR, i.e. the entity that alone or jointly with others determines the purposes and means of the processing of personal data, is Heyora UG (haftungsbeschränkt), Leberstraße 63, 10829 Berlin, Germany, represented by its Managing Director Yannick Feige. You can reach us by email at hey@openpmm.com. The company is registered in the commercial register of the Local Court of Charlottenburg (Berlin) under HRB 286080 B. We have not appointed a data protection officer, as we are not legally required to do so. If you have any questions about data protection or wish to exercise your rights, you may contact us at any time directly at the address above or at hey@openpmm.com.
B. Information about the processing of your personal data
I. Provision of the website and server log files
When you use our website purely for informational purposes, i.e. when you do not register or otherwise transmit information to us, the browser used on your device necessarily transmits certain information to the server of our website for technical reasons. This includes in particular your IP address, the type and version of your internet browser, the operating system used, the page accessed, where applicable the previously visited page (referrer URL), and the date and time of access. This data is technically necessary in order to display the content you have requested and is stored temporarily in so-called server log files in order to ensure the secure and stable operation of the website and to detect and trace disruptions, such as attacks on our IT infrastructure.
The legal basis for this processing is Article 6(1)(f) GDPR. Our legitimate interest lies in the reliable provision as well as the security and stability of the IT infrastructure used for the website. The provision of this data is neither legally nor contractually required; however, without it the website cannot technically be delivered. The data stored in the server log files is, in a form that allows your identification, regularly deleted after a short period, unless longer storage is required to investigate a specific security-relevant incident.
Our website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. Vercel processes the aforementioned log data on our behalf as a processor; for this purpose we have concluded a data processing agreement with Vercel pursuant to Article 28 GDPR. As Vercel is based in the USA, a transfer of personal data to a third country may occur. Vercel is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA.
II. Registration and use of a user account
In order to use the OpenPMM web application, you can create a user account. As part of registration, we process the data you provide, in particular your email address and the access credentials required to log in, such as a password chosen by you, which is stored exclusively in encrypted or hashed form. If you provide further information, such as a name or display name, we also process this. In addition, we store administrative data relating to your account, for example the time of registration and of log-ins, account settings, and information needed to provide and secure the service.
We process this data in order to set up and manage your user account, to authenticate you, to enable you to use OpenPMM, and to communicate with you in connection with your account and the service, for example to inform you about security- or function-relevant changes. The legal basis for processing the data required to provide the account and the service is Article 6(1)(b) GDPR, as the processing is necessary for the performance of the user agreement concluded with you regarding the provision and use of the account, or to carry out pre-contractual measures. Insofar as we process the data beyond this in order to ensure the security and functionality of our service and to prevent misuse, we base this on Article 6(1)(f) GDPR; our legitimate interest lies in the secure and reliable provision of our service. Where statutory retention obligations exist, the legal basis is Article 6(1)(c) GDPR.
The provision of the data marked as mandatory is required to set up the account; without this information, we cannot create an account for you or provide the web application. Further information is voluntary. We store the data processed in connection with the account for the duration of the existence of your user account. If you delete your account or request its deletion, the data will be deleted as soon as it is no longer required for the stated purposes and no statutory retention obligations, such as those under tax or commercial law, or other legitimate reasons preclude deletion.
For authentication and the technical provision of the account, we use Supabase as a service provider and processor pursuant to Article 28 GDPR. Supabase provides the authentication, database, and storage services used for the OpenPMM account and workspace. Further information is available in Supabase's privacy policy at https://supabase.com/privacy. We also use Vercel for hosting as described in Section B.I. Any further disclosure of your data to third parties only takes place if this is necessary for the performance of the contract, if you have consented or if we are legally obliged to do so. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
OpenPMM is delivered as a web application. New versions become available when we deploy them to the service. The web application does not perform a separate automatic update check, and it does not perform a periodic status or license check on your device.
III. OpenPMM workspace data and connected services
When you use the OpenPMM web application, we process the data you enter or create there. This may include workspace settings, post content, schedules, publishing statuses, attached images or videos, API and CLI configuration, and feedback or other content that you voluntarily submit. We process this data to provide the functions you request, to save and display your work, to send or schedule posts, and to maintain the security and reliability of the service.
If you connect a publishing channel, we process the account information and OAuth data required to establish and maintain that connection, together with the destination identifiers and publishing results needed to send your posts. We store access credentials and tokens server-side and protect them from being included in content-generation prompts. You complete the OAuth confirmation for each channel yourself. We share content and the information required to publish it with the channel provider you select. You can disconnect a channel through the available product controls; this does not necessarily delete data already published on that provider's service.
We do not currently offer source integrations that pull product context or create posts from GitHub, Linear, or other project-management systems. If that changes, we will describe the relevant provider, data, and purpose before enabling the feature.
Writing refinement with OpenRouter
When you choose the Writing Assistant in the OpenPMM web application, we send the selected post body, your selected or custom instruction, the applicable Workspace writing instructions and the channel-specific formatting rules to OpenRouter, Inc. in the USA. OpenRouter routes this data to a model provider and returns the refined text. We use this data only to provide the writing refinement that you request. The legal basis is Article 6(1)(b) GDPR because this processing is necessary to provide the requested function. The use of the Writing Assistant is voluntary. You can write or edit post content without it.
We require zero-data-retention routing for each writing-refinement request and deny routing to a provider that does not support the required request parameters. OpenRouter states that it does not retain prompts or responses unless prompt logging is expressly enabled. We keep prompt and response logging and the use of inputs or outputs for product improvement disabled. We do not store a history of writing-refinement prompts or responses. We store only the final text when you use it as post content. OpenRouter and the selected model provider process request metadata such as token counts, response time and cost. OpenPMM records only technical metadata needed to operate and secure the function. OpenPMM does not place post content, custom instructions or Workspace writing instructions in application logs, analytics or error reports.
OpenRouter acts as a processor under its Data Processing Agreement and uses model providers as subprocessors for inference. OpenRouter states that transfers outside the EEA or the United Kingdom use an adequacy decision or the European Commission's Standard Contractual Clauses. Further information is available in the OpenRouter Privacy Policy and OpenRouter data-collection documentation.
Supabase acts as a processor for the account, workspace, post, media, and connection data described above. We use technical and organizational measures to protect this data and delete it when the relevant purpose ends, subject to statutory retention obligations and the storage periods described in Section F.
IV. YouTube API Services
OpenPMM uses the YouTube Data API. Connecting a YouTube channel is optional. OpenPMM requests access in context through Google's OAuth consent screen and only when you choose to connect a channel. The permissions OpenPMM requests are youtube.upload, which allows OpenPMM to upload videos you approve, and youtube.readonly, which allows OpenPMM to read information about the connected channel and its videos. OpenPMM does not use the YouTube Analytics API and does not request yt-analytics.readonly or yt-analytics-monetary.readonly. Performance figures shown in OpenPMM come from the YouTube Data API and cover only the videos OpenPMM published for you. If we later introduce a feature that needs additional permissions, we will update this Privacy Policy and request any consent required by Google policies and applicable law first.
When you connect YouTube, OpenPMM accesses, collects and stores the information needed to provide the integration. This includes the connected channel's ID, title and custom URL; the OAuth permissions granted; encrypted access and refresh tokens; connection and revocation timestamps; and the destination selected for the Workspace. When you publish a video, OpenPMM sends the selected video file and the settings you approve to YouTube, including the title, description, category, visibility, audience designation, synthetic-media designation, publication time and subscriber-notification choice. OpenPMM stores the resulting YouTube video ID, upload and processing status, visibility status, publishing result and technical error information so that it can show the state of the send and recover interrupted uploads.
If you enable YouTube analytics, OpenPMM retrieves and displays performance and engagement data made available for your own connected channel and videos, such as views, watch time, average view duration, likes and subscriber changes. OpenPMM uses this data only to provide the analytics features visible to you and the members of the same Workspace whom you authorize to work with the connected channel. OpenPMM does not aggregate YouTube API Data across unrelated channels or content owners and does not create replacement or derived YouTube metrics unless YouTube expressly permits the specific use. OpenPMM does not sell YouTube API Data, share it with advertisers or data brokers, use it for advertising, credit decisions or surveillance, or use it to train generalized or non-personalized artificial-intelligence or machine-learning models. YouTube API Data and OAuth tokens are not included in prompts sent to content-generation providers. If we later use YouTube API Data for a materially different purpose, we will first update this Privacy Policy and request any consent required by Google policies and applicable law.
OpenPMM shares the video, metadata and instructions you approve with Google and YouTube to perform the requested upload, publication, status and analytics operations. Within OpenPMM, the data is available only to authorized members of the relevant Workspace and to Heyora personnel where access is necessary after your affirmative support request, for security or abuse investigation, to comply with law, or in aggregated form for permitted internal operations. Our hosting, database and storage processors may process the data only to the extent necessary to operate and secure OpenPMM and under contractual confidentiality and data-protection obligations. We do not otherwise disclose YouTube API Data to third parties. The legal basis for this processing is Article 6(1)(b) GDPR because it is necessary to provide the YouTube connection, publishing and analytics functions that you request. Where processing is necessary to secure the integration or comply with YouTube and Google requirements, the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in providing a secure and policy-compliant integration.
OpenPMM stores authorization tokens only while needed for the connection and uses them only for the permissions and purposes you approved. While a connection is active, an automated check runs at least every 30 calendar days to confirm that OpenPMM remains authorized for the connected channel. The same check refreshes the channel information OpenPMM stores. If the authorization is no longer valid, or no longer covers the connected channel, OpenPMM stops using it and deletes the YouTube API Data held for that connection. Statistics for your own videos are kept while the authorization remains active and are removed when it ends.
You can disconnect YouTube through OpenPMM. OpenPMM will then revoke the Google authorization, stop future access, and delete the stored OAuth tokens and the YouTube API Data held for that connection, including the channel information, the retrieved statistics, and the upload and processing status of your videos. OpenPMM keeps the identifier and link of each video it published for you as its own record that the publication happened. You may also request deletion of stored YouTube data by deleting your OpenPMM account or contacting hey@openpmm.com. OpenPMM completes a user-requested deletion as soon as possible and within seven calendar days. If you revoke OpenPMM through the Google security settings page, OpenPMM will delete the associated YouTube API Data as soon as it detects the revocation and no later than 30 calendar days after the revocation. Deleting data from OpenPMM does not delete videos or other data stored by YouTube; to delete that data, you must use YouTube or another authorized service that supports deletion.
OpenPMM's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. OpenPMM's use of YouTube API Services is also subject to the YouTube API Services Terms of Service and the YouTube API Services Developer Policies. You can learn how Google processes personal data in the Google Privacy Policy. By using OpenPMM's YouTube integration, you also agree to the YouTube Terms of Service. Questions or complaints about OpenPMM's handling of YouTube or Google user data can be sent to hey@openpmm.com.
V. Meta Platform Services (Facebook, Instagram and Threads)
When a Meta integration is enabled and you choose to use it, OpenPMM uses Meta Platform services to let you connect Facebook Pages, Instagram professional accounts and Threads profiles, publish or schedule content you approve and, where enabled for Facebook or Instagram, retrieve and display analytics for your connected accounts and published content. OpenPMM requests access through Meta's authorization screen only when you choose to connect an account or enable the relevant feature. Depending on the Meta login flow and features you select, the permissions may include pages_show_list to identify Facebook Pages you manage; pages_manage_posts to publish to a selected Page; pages_read_engagement and read_insights to retrieve Page and content performance; instagram_business_basic, instagram_business_content_publish and instagram_business_manage_insights for an Instagram professional account; or the corresponding instagram_basic, instagram_content_publish and instagram_manage_insights permissions where Meta requires the Facebook Login flow. For Threads, OpenPMM requests only threads_basic to access the connected Threads profile and media and threads_content_publish to create and publish content you approve. OpenPMM requests only the permissions shown on the authorization screen and necessary for the features you enable. We will separately update this Privacy Policy and obtain any required authorization before requesting permissions for materially different features, such as private messaging, advertising or audience targeting.
When you connect a Meta account, OpenPMM accesses, collects and stores the information needed to provide the integration. This may include your profile image, display name, username, profile or Page ID; the Facebook Pages, Instagram professional accounts or Threads profiles that you are authorized to manage; the destination you select for the Workspace; the permissions granted; encrypted access tokens; token expiry, connection and revocation timestamps; and technical connection status. When you publish, OpenPMM sends the content and settings you approve to the selected Meta service. This may include post text, links, images, videos, captions, alt text, publication time and other channel-specific settings. OpenPMM stores the resulting post or media ID, permalink where available, publishing status, publishing result and technical error information so that it can display the send and avoid or recover failed publication attempts.
If you enable analytics for a Facebook Page or Instagram professional account, OpenPMM retrieves and displays data made available by Meta for that connected account and its published content. Depending on the service and the metrics Meta makes available, this may include follower counts, reach, impressions, views, watch time, reactions, likes, comments, reposts, shares, clicks, engagement totals and aggregated audience or demographic insights. OpenPMM uses Meta Platform data only to provide the connection, publishing, scheduling, status and, where enabled for Facebook or Instagram, analytics features requested by you and visible to authorized members of the same Workspace. OpenPMM does not sell Meta Platform data, share it with advertisers or data brokers, use it for advertising or credit decisions, build profiles of people outside the connected-account features, or use it to train generalized or non-personalized artificial-intelligence or machine-learning models. Meta access tokens and data retrieved from Meta are not included in prompts sent to content-generation providers.
OpenPMM shares the content, metadata and instructions you approve with Meta to carry out the requested authorization, publishing and status operations. Within OpenPMM, Meta Platform data is available only to authorized members of the relevant Workspace and to Heyora personnel where access is necessary after your affirmative support request, for security or abuse investigation, or to comply with law. Our hosting, database and storage processors may process this data only to the extent necessary to operate and secure OpenPMM and under contractual confidentiality and data-protection obligations. We do not otherwise disclose Meta Platform data to third parties. The legal basis for processing necessary to provide the Meta connection, publishing, scheduling, status and, where enabled for Facebook or Instagram, analytics functions you request is Article 6(1)(b) GDPR. Where processing is necessary to secure the integration, prevent misuse or comply with Meta's platform requirements, the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in providing a secure and policy-compliant integration.
OpenPMM stores authorization tokens only while needed for an active connection and stores other Meta Platform data only for as long as necessary to provide the enabled features, maintain an accurate publishing history and meet legal obligations. You can disconnect a Meta account through OpenPMM or revoke OpenPMM in the applicable Facebook, Instagram or Meta account settings. When you disconnect or revoke access, OpenPMM stops future access and deletes the associated tokens and connection-sourced Meta Platform data without undue delay, normally within 30 days, unless continued storage is required by law. You may also request deletion by deleting your OpenPMM account, contacting hey@openpmm.com or submitting a deletion request through a mechanism made available by Meta. We process valid Meta data-deletion requests without undue delay and delete or irreversibly anonymize the data associated with the requesting Meta account, except where retention is legally required. Deleting data from OpenPMM does not delete posts, media, analytics or other data held by Facebook, Instagram or Threads; you must manage or delete that data through the relevant Meta service.
OpenPMM's use of Meta Platform services is subject to the Meta Platform Terms and Meta Developer Policies. Meta explains its own processing in the Meta Privacy Policy. Your use of the connected Facebook, Instagram and Threads services remains subject to the applicable Meta Terms of Service, Instagram Terms of Use and Threads Supplemental Terms. Questions or complaints about OpenPMM's handling of Meta Platform data can be sent to hey@openpmm.com.
VI. TikTok Content Posting
When the TikTok integration is enabled and you choose to connect it, OpenPMM uses TikTok Login Kit and the TikTok Content Posting API to let you connect a TikTok profile and publish a video that you approve. OpenPMM initially requests only the video.publish permission. This permission allows OpenPMM to retrieve the current creator information and posting choices needed for the confirmation screen, submit the video and settings you approve, and check the status of that publication. OpenPMM does not use this integration to read your existing TikTok posts, analytics, comments, inbox activity or audience data, or to edit or delete content already published on TikTok.
When you connect TikTok, OpenPMM accesses, collects and stores the information needed to provide and secure the connection. This includes your TikTok open_id; creator nickname, username and temporary profile image URL; the permission granted; encrypted access and refresh tokens; token expiry, connection and revocation timestamps; the destination selected for the Workspace; and technical connection status. Before publication, OpenPMM retrieves TikTok's current privacy options, interaction restrictions and maximum video duration for the connected creator so that you can review valid settings. OpenPMM does not request your TikTok password.
When you confirm a TikTok publication, OpenPMM makes the selected video available to TikTok through a verified HTTPS media URL and sends the caption and settings you selected. These settings may include the privacy level, whether comments, Duet and Stitch are allowed, commercial-content disclosures, an AI-generated-content disclosure and the selected cover frame. OpenPMM stores the TikTok publish identifier, processing and moderation status, publishing result, an available public post identifier and limited technical error information so that it can display the state of the send and avoid or recover interrupted publication attempts. TikTok may continue to process or moderate the video after OpenPMM has submitted it.
OpenPMM uses TikTok data only to provide the connection, confirmation, publication and status functions requested by you and visible to authorized members of the same Workspace. TikTok access tokens and data retrieved from TikTok are not included in prompts sent to content-generation providers. OpenPMM does not sell TikTok data, share it with advertisers or data brokers, use it for advertising or credit decisions, build profiles outside the connected-account feature, or use it to train generalized or non-personalized artificial-intelligence or machine-learning models. OpenPMM shares the video, metadata and instructions you approve with TikTok to perform the requested publication and status operations. For users in the EEA, the UK or Switzerland, TikTok Technology Limited in Ireland and TikTok Information Technologies UK Limited act as joint controllers for TikTok's own processing. TikTok may process data outside the EEA as described in its Privacy Policy. Our hosting, database and storage processors may process the data held by OpenPMM only to the extent necessary to operate and secure OpenPMM and under contractual confidentiality and data-protection obligations. We do not otherwise disclose TikTok data to third parties unless required by law.
The legal basis for processing necessary to provide the TikTok connection, publication and status functions you request is Article 6(1)(b) GDPR. Where processing is necessary to secure the integration, prevent misuse or comply with TikTok's platform requirements, the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in providing a secure and policy-compliant integration.
OpenPMM stores authorization tokens only while needed for an active connection. You can disconnect TikTok through OpenPMM or revoke OpenPMM's access through TikTok. When you disconnect through OpenPMM, OpenPMM attempts to revoke the authorization, clears the stored access and refresh tokens and stops future access. OpenPMM may retain the disconnected destination identifier, creator display information and related publishing history while your Workspace exists so that it can preserve an accurate record of posts and support reconnection. You can delete the relevant Workspace data through available product controls or by deleting your OpenPMM account, subject to statutory retention obligations and the general storage periods in Section F. Deleting or disconnecting data from OpenPMM does not delete videos or other data held by TikTok; you must manage or delete that data through TikTok.
TikTok explains its own processing in the TikTok Privacy Policy. Your use of TikTok remains subject to the TikTok Terms of Service, including the policies referenced there. OpenPMM's integration is also subject to the TikTok Developer Terms of Service and TikTok's developer and Content Posting API requirements. Questions or complaints about OpenPMM's handling of TikTok data can be sent to hey@openpmm.com.
VII. LinkedIn API Services
When the LinkedIn integration is enabled and you choose to connect it, OpenPMM uses LinkedIn API Services to let you connect your LinkedIn member account and publish content that you approve. OpenPMM requests openid and profile to authenticate you and retrieve your LinkedIn member identifier, display name and profile image, and w_member_social to publish on your behalf. If company Page publishing has been enabled following the required LinkedIn approval, OpenPMM may also request r_organization_admin to identify the LinkedIn Pages you are authorized to administer and w_organization_social to publish to the Page you select. OpenPMM uses r_organization_admin only for Page discovery and authorization checks, not to retrieve Page analytics. OpenPMM does not request LinkedIn email access or r_member_social.
Before you are redirected to LinkedIn, OpenPMM explains the LinkedIn information it will collect, when and why it will collect it, how it will be disclosed and stored, and how you can withdraw access or request deletion. The connection is optional and begins only when you affirmatively choose to continue to LinkedIn's authorization screen. LinkedIn shows the permissions requested and asks you to approve them. If an access token expires, the permissions change or LinkedIn otherwise requires renewed authorization, OpenPMM asks you to connect again before it resumes access.
When you connect LinkedIn, OpenPMM accesses, collects and stores the information needed to provide and secure the integration. This includes your LinkedIn member identifier or Person URN, display name, temporary profile image URL, the permissions granted, encrypted access and, where LinkedIn issues one, refresh tokens, token expiry, connection and disconnection timestamps, the destination selected for the Workspace and technical connection status. For company Page access, this may also include the Page identifier or Organization URN, Page name, vanity name and the applicable Page administration role or authorization state. OpenPMM does not request your LinkedIn password.
When you confirm a LinkedIn publication, OpenPMM sends LinkedIn the content and settings you selected. This may include post text, images or one video, alternative text, a video title, the selected visibility and whether resharing is allowed. OpenPMM may temporarily store LinkedIn media-upload URLs, upload tokens, media identifiers and technical checkpoint information while an upload or publication is in progress. It stores the resulting post identifier, available LinkedIn URL, publication status, publishing result and limited technical error information only for as long as permitted and necessary to show the send, prevent duplicate publication and recover an interrupted attempt. OpenPMM does not use the LinkedIn integration to retrieve your existing posts, impressions, clicks, likes, reactions, comments, reshares, followers, inbox activity or audience analytics, or to edit or delete content already published on LinkedIn.
OpenPMM uses data received from LinkedIn only to provide the connection, destination selection, confirmation, publication and status functions requested by you and visible to authorized members of the same Workspace. LinkedIn access tokens and member or organization data retrieved from LinkedIn are not included in prompts sent to content-generation providers. OpenPMM does not sell LinkedIn data, share it with advertisers or data brokers, use it for advertising, sales prospecting, recruiting, credit decisions or surveillance, combine it into profiles for unrelated purposes, or use it to train generalized or non-personalized artificial-intelligence or machine-learning models. OpenPMM shares the content, media, metadata and instructions you approve with LinkedIn to carry out the requested publication. Our hosting, database and storage processors may process data held by OpenPMM only to the extent necessary to operate and secure OpenPMM and under contractual confidentiality and data-protection obligations. We do not otherwise disclose LinkedIn data to third parties unless required by law.
The legal basis for processing necessary to provide the LinkedIn connection, destination selection, publication and status functions you request is Article 6(1)(b) GDPR. Where processing is necessary to secure the integration, prevent misuse or comply with LinkedIn's platform requirements, the legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in providing a secure and policy-compliant integration.
OpenPMM stores LinkedIn authorization tokens only while needed for an active connection. LinkedIn company Page profile information received through the LinkedIn Marketing APIs is refreshed or deleted within the periods required by LinkedIn, including no later than eight weeks after retrieval for Page profile data unless it is lawfully refreshed. Page administration data is not kept for more than one year without a permitted refresh or another applicable basis. Temporary media-upload credentials and upload URLs are deleted after the publication attempt no longer needs them. LinkedIn-derived data is stored separately so that it can be selectively deleted.
You can disconnect LinkedIn through OpenPMM or remove OpenPMM under the Permitted Services controls in LinkedIn's account settings. When you disconnect or revoke access, OpenPMM stops future LinkedIn access, deletes the associated authorization tokens without undue delay and deletes all data received through the LinkedIn APIs for that connection, including member, profile, Page, administration, media-upload and publication-result data, as soon as possible and no later than ten days, unless a shorter period is required by LinkedIn or retention is required by law. You may also request deletion by deleting your OpenPMM account or contacting hey@openpmm.com. When you close your OpenPMM account or make a valid deletion request, OpenPMM deletes LinkedIn data collected through the APIs without undue delay, except where retention is required by law. Content and media that you supplied directly to OpenPMM are not data obtained from LinkedIn and remain subject to the general Workspace deletion rules in this Privacy Policy. Deleting or disconnecting data from OpenPMM does not delete posts, media or other data held by LinkedIn; you must manage or delete that data through LinkedIn.
LinkedIn explains its own processing in the LinkedIn Privacy Policy. Your use of LinkedIn remains subject to the LinkedIn User Agreement and Professional Community Policies. OpenPMM's integration is also subject to the LinkedIn API Terms of Use and, for company Page access, the LinkedIn Marketing API Program Terms. Instructions for removing a connected application are available in LinkedIn's Third-party applications data use documentation. Questions or complaints about OpenPMM's handling of LinkedIn data can be sent to hey@openpmm.com.
VIII. Product and usage analysis in the OpenPMM web application
If you have consented to this, we collect anonymized usage and diagnostic data within the OpenPMM web application in order to improve the service, detect errors and vulnerabilities, and better understand which functions are used. For this purpose, we use the analytics tool PostHog. The data processed includes in particular a randomly generated, pseudonymous or anonymous identifier, the version of the web application, browser and operating system information, approximate location derived from the IP address, selected usage events, and onboarding or preference information that you choose to provide. We do not intend to transmit the contents of your posts, passwords, OAuth tokens, or uploaded media as product analytics data.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as the storage of an identifier on your device or access to information on your device is concerned, Section 25(1) TDDDG. The collection only takes place after you have consented. You can withdraw your consent at any time with effect for the future using the available privacy or analytics settings. The lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of the data is neither legally nor contractually required and is not necessary for using OpenPMM; if you do not give consent, you will not suffer any disadvantages. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
The provider is PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, which acts for us as a processor pursuant to Article 28 GDPR. The data is processed on infrastructure within the European Union, including the Frankfurt location, eu.i.posthog.com. Insofar as a transfer to the USA nevertheless occurs, PostHog is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists in this respect. We store the data until the stated purpose ceases to apply.
IX. Crash and error reports in the OpenPMM web application
If you have consented to this, OpenPMM may transmit technical error reports when a crash or other technical error occurs, so that we can analyze the causes and improve the stability of the service. For this purpose, we use the Sentry service. The data processed includes in particular technical error information, such as exception and error messages and stack traces, the route or function involved, browser and device environment information, a pseudonymous account or session identifier where technically necessary, and your IP address for technical reasons. We configure technical filtering to avoid capturing passwords, OAuth access tokens, and post or media content in error reports.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as access to information on your device is concerned, Section 25(1) TDDDG. The transmission only takes place after you have consented. You can withdraw your consent at any time with effect for the future using the available privacy or error-reporting settings. The lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of the data is not necessary in order to use OpenPMM. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place.
The provider is Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, which acts for us as a processor pursuant to Article 28 GDPR. As the provider is based in the USA, a transfer of personal data to a third country may occur. Functional Software (Sentry) is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA.
X. In-app feedback
Within the OpenPMM web application, you can voluntarily send us feedback via a form. This function is triggered exclusively at your own initiative. The data processed includes the content of the feedback you submit, an email address you optionally provide, and accompanying technical information such as the browser or web application version. We use this data to process your feedback, to answer any follow-up questions, and to improve our service. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in processing and evaluating feedback to improve our application. Insofar as your feedback is aimed at the conclusion or performance of a contract, the legal basis is Article 6(1)(b) GDPR. Providing an email address is voluntary; however, without it we cannot reply to you directly.
We store the data until your request has been finally processed and no legitimate reasons preclude deletion. For the technical receipt and forwarding of the feedback, we use Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA; we subsequently manage the feedback received in the project management tool Linear (Linear Orbit, Inc., San Francisco, USA). Both providers act for us as processors pursuant to Article 28 GDPR. As the providers are based in the USA, a transfer of personal data to a third country may occur. Both Cloudflare and Linear are certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists in each case for the transfer to the USA.
XI. Audience measurement and web analysis (website)
In order to statistically analyze the use of our website, to continuously improve it and to better tailor our services to the needs of our visitors, we use analytics tools. Automated decision-making, including profiling within the meaning of Article 22 GDPR, does not take place in this context.
1. Vercel Analytics
We use Vercel Analytics, a web analytics service provided by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA. With Vercel Analytics, we collect aggregated usage statistics, such as which pages are accessed, the approximate origin of the access, and technical information such as browser and device type. The processing is anonymized and does not use cookies; IP addresses are not stored permanently, and no profiles that can be tracked across multiple websites are created. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the statistical, privacy-friendly analysis of website usage to optimize our service. Vercel acts for us as a processor pursuant to Article 28 GDPR. As Vercel is based in the USA, a transfer to a third country may occur. Vercel is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for this transfer.
2. Google Analytics
In addition, we use Google Analytics, a web analytics service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses cookies and similar technologies that enable an analysis of your use of the website. In doing so, information about your use is collected, for example pages visited, time spent, click behavior, approximate origin, a unique identifier for recognizing returning visitors, and technical information about your browser and operating system. This information is generally transmitted to a Google server and stored there. We have activated IP anonymization, so that your IP address is truncated by Google within the member states of the European Union or in other states party to the Agreement on the European Economic Area before transmission. From the data collected, Google creates pseudonymous usage profiles on our behalf, on the basis of which we can analyze where our visitors come from, which areas of the website they access and how they use it.
Google acts as a processor for us in this respect pursuant to Article 28 GDPR. The legal basis for the use of Google Analytics is exclusively your consent pursuant to Article 6(1)(a) GDPR and, insofar as the storage of information on your device or access to it is concerned, Section 25(1) TDDDG. We therefore only use Google Analytics after you have consented via our consent banner. You can withdraw your consent at any time with effect for the future by changing your selection in the cookie settings; the lawfulness of the processing carried out up to the withdrawal remains unaffected. The provision of this data is neither legally nor contractually required and is not necessary for using the website. If you do not give consent, you will not suffer any disadvantages; in that case, simply no analysis is carried out using Google Analytics. As Google is part of a globally operating group, a transfer of data to the USA or other third countries may occur. Google LLC is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission pursuant to Article 45 GDPR exists for the transfer to the USA. The data stored in connection with Google Analytics is deleted as soon as it is no longer required for the stated purposes or after the configured retention periods have expired.
3. Google Ads conversion measurement
We use Google Ads conversion measurement, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, to understand whether a person who clicked one of our ads later signs up for OpenPMM, creates an OpenPMM account, or completes another selected OpenPMM conversion. For this purpose, Google may use cookies and similar technologies and process information associated with the ad click, such as the Google Click Identifier (GCLID), together with information about the conversion interaction and technical information about the browser and device. We use this data only to measure the results of our advertising. We do not use Google Ads on this website for personalized advertising or remarketing. Advertising storage and the transmission of data for advertising measurement remain disabled unless you consent to advertising measurement in the cookie settings.
The legal basis is your consent pursuant to Article 6(1)(a) GDPR and, insofar as information is stored on or accessed from your device, Section 25(1) TDDDG. You can withdraw your consent at any time with effect for the future by changing your selection in the cookie settings. The lawfulness of processing carried out before withdrawal remains unaffected. The provision of this data is neither legally nor contractually required and is not necessary for using OpenPMM or the website. If you do not give consent, OpenPMM remains fully available; we simply cannot attribute a later account registration or other conversion to an ad click. As Google is part of a globally operating group, a transfer of data to the USA or other third countries may occur. Google LLC is certified under the EU-US Data Privacy Framework, so that an adequacy decision of the European Commission exists for the transfer to the USA. You can find further information in Google's privacy policy at https://policies.google.com/privacy.
4. Content management
We maintain the website's marketing pages, blog, and documentation in an editorial content-management workflow. This workflow uses content authored for the website and does not require visitors to submit personal data. It is not used to create visitor profiles or to make automated decisions. Technical data involved in delivering these pages is processed as described in Section B.I.
XII. Consent management (cookie consent)
In order to obtain your consent to the use of non-essential cookies and comparable technologies and to document this in compliance with data protection law, we use a consent tool. In doing so, your consent decision and technically necessary information, such as the time of consent and an identifier, are stored, so that we can take your selection into account when you access the website again and demonstrate that consent has been given. The legal basis for this is our obligation to demonstrate consent pursuant to Article 6(1)(c) GDPR in conjunction with Article 7(1) GDPR, as well as our legitimate interest in a legally compliant design of our service pursuant to Article 6(1)(f) GDPR. The cookies used for this purpose are technically necessary.
XIII. Contact by email
If you contact us by email, we process the data you transmit, in particular your email address and the content of your message, in order to process and respond to your request. The legal basis is Article 6(1)(b) GDPR if your request is aimed at the conclusion or performance of a contract, otherwise Article 6(1)(f) GDPR on the basis of our legitimate interest in responding to requests. We store this data until your request has been finally processed and no statutory retention obligations preclude deletion.
C. Your rights as a data subject
Within the framework of the statutory provisions, you have the following rights with regard to your personal data: pursuant to Article 15 GDPR, you have the right to request information about the personal data we process concerning you. Pursuant to Article 16 GDPR, you may request the rectification of inaccurate data or the completion of your data. Pursuant to Article 17 GDPR, you have the right to request the deletion of your data, insofar as no legal obligations or overriding reasons preclude deletion. Pursuant to Article 18 GDPR, you may request the restriction of processing. Pursuant to Article 20 GDPR, you have the right to receive the data concerning you that you have provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
Insofar as we process data on the basis of your consent, you have the right pursuant to Article 7(3) GDPR to withdraw your consent at any time with effect for the future. The lawfulness of the processing carried out on the basis of the consent up to the withdrawal is not affected by this. Pursuant to Article 21 GDPR, you have the right, for reasons arising from your particular situation, to object at any time to the processing of personal data concerning you that is carried out on the basis of Article 6(1)(f) GDPR. If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.
To exercise your rights, an informal notification to the contact details provided in Section A is sufficient.
D. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right pursuant to Article 77 GDPR to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data infringes the GDPR. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit), Alt-Moabit 59–61, 10555 Berlin. You may also contact the supervisory authority of your habitual residence or place of work.
E. Data security
When you visit the website or use the OpenPMM web application, we use the widely used TLS procedure (Transport Layer Security) in conjunction with the highest level of encryption supported by your browser. You can recognize an encrypted connection by the fact that the address line of the browser begins with "https://". Connections to external services used for authentication, hosting, analytics, error reports, feedback, channel connections, and publishing are also encrypted where technically supported.
In addition, we take appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, loss, destruction or access by unauthorized persons. This includes access controls for account and workspace data, server-side protection of credentials and tokens, and measures designed to prevent sensitive content from being included in diagnostics or analytics where technically possible.
F. Storage period and deletion
We process and store your personal data only for as long as is necessary to achieve the respective processing purposes, or for as long as a statutory retention obligation exists. As soon as the respective purpose ceases to apply and no statutory retention obligation or other legitimate reason precludes deletion, the data concerned is routinely deleted or anonymized. Insofar as more specific information on the storage periods is provided in the preceding sections for individual processing operations, that information takes precedence.
The criteria that determine the specific duration of storage are, in particular: whether and for how long a user account or workspace exists with us, whether an ongoing matter such as a feedback request is still being processed, whether consent that has been given remains in effect, and whether the data is still needed to assert, exercise or defend legal claims. Data that arises for technical reasons, such as server log files, is deleted as soon as it is no longer required for the respective purpose.
Irrespective of this, we retain personal data insofar and for as long as we are legally obliged to do so, in particular due to retention obligations under commercial and tax law, for example under the German Commercial Code and the German Fiscal Code; the retention periods provided for there are usually between six and ten years. Data subject to such a retention obligation is restricted in its further processing for the duration of the period and deleted after the period has expired.
G. Currency and amendment of this privacy policy
This privacy policy is dated August 19, 2026. As our website and our services continue to develop, or due to changed legal or regulatory requirements, it may become necessary to amend this privacy policy. You can access the current version at any time on this website at https://www.openpmm.com/privacy.