Privacy Policy
This privacy policy explains how we process personal data when you use our service SocialCommander (the „Service“), an application for planning, creating and publishing social media posts and for reviewing the related statistics.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
IT Commander GmbH & Co. KG
Geistwall 12+14, 32312 Lübbecke, Germany
Phone: +49 (0) 5741 60 89 12 0
Email: [email protected]
2. What data we process
- Account data: name, email address and password (stored encrypted) for registration and sign-in.
- Connected social media accounts: when you connect an account, we store the access tokens provided by the respective platform (access/refresh tokens), the account/page/channel ID, the display name and, where applicable, the profile picture.
- Content: posts you create, captions, uploaded media, carousel content and scheduled publishing times.
- Statistics: metrics retrieved from the platforms (e.g. reach, impressions, followers) for your connected accounts.
- Usage / log data: technical data such as IP address, timestamps and error logs for operating and securing the Service.
3. Purposes and legal bases
We process your data to provide the Service (Art. 6(1)(b) GDPR – performance of a contract), to safeguard our legitimate interests in secure and stable operation (Art. 6(1)(f) GDPR) and – where required – on the basis of your consent (Art. 6(1)(a) GDPR), in particular when connecting your social media accounts.
4. Connecting social media accounts (OAuth)
SocialCommander acts on your behalf. When you connect an account, you are redirected to the official OAuth flow of the respective platform to sign in and grant consent. We only receive the permissions (scopes) you approve and use them solely for the functions you request (e.g. publishing, retrieving statistics). You can revoke the access tokens at any time by disconnecting the account or in the settings of the respective platform.
Meta (Facebook & Instagram)
Processing via the Meta Graph API to publish posts and retrieve statistics. The Meta Privacy Policy also applies. You can request deletion of the Meta data stored by us at any time (see the „Data deletion“ section).
Google (YouTube & Google Business Profile)
Processing via the YouTube Data API and the Google Business Profile APIs to publish or manage your content. The Google Privacy Policy also applies. Use of data from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
Processing via the LinkedIn Marketing/Share APIs to publish posts for your profile or your organization pages. The LinkedIn Privacy Policy also applies.
TikTok
Processing via the TikTok Content Posting API to publish videos. When you connect a TikTok account we receive your basic profile information (open ID, avatar, display name) via the TikTok Login Kit (scope user.info.basic) and use it only to display the connected account. Videos are posted on your behalf to your authorized TikTok account. The TikTok Privacy Policy also applies.
5. AI-assisted features
For the optional generation of texts and carousel content we use the API of Anthropic (Claude). The topics/prompts you enter are transmitted to Anthropic in order to generate the content. The Anthropic Privacy Policy also applies.
For the optional generation and editing of AI images we use the API of OpenAI (USA). The image descriptions or editing instructions you enter are transmitted to OpenAI in order to create the image. The OpenAI Privacy Policy also applies.
6. Hosting, CDN & media storage
The Service runs on servers in Germany (Hetzner Online GmbH). It is fronted by Cloudflare, Inc. (USA) as a content delivery network and reverse proxy; in doing so, connection data (in particular IP addresses) and the transmitted traffic are processed in order to deliver the Service and protect it against attacks. Media you upload (images/videos) are stored via Cloudflare R2 (storage location: European Union). We have data processing agreements pursuant to Art. 28 GDPR in place with all of the above providers. Regarding transfers to Cloudflare, see the section „Transfers to third countries (USA)“.
7. Transfers to third countries (USA)
Some of the services used and platforms you connect are based in the USA (including Cloudflare, Meta, Google, LinkedIn, TikTok and the AI providers Anthropic and OpenAI). Personal data may be transferred to the USA in this context. Such transfers take place on the basis of appropriate safeguards under Art. 44 et seq. GDPR – in particular the EU Standard Contractual Clauses (Art. 46 GDPR) and, where the respective provider is certified, the EU-US Data Privacy Framework (adequacy decision of the EU Commission). Despite these safeguards, the level of data protection in the USA may be lower than in the EU (e.g. government access options). Where your consent is required for a processing operation, we additionally base the transfer on Art. 49(1) GDPR.
8. Cookies and local storage
We do not use any analytics, tracking or marketing cookies and do not embed any external tracking services. To operate the Service we use exclusively technically necessary local storage in your browser (local/session storage), in particular to maintain your sign-in (login token) and your active workspace. This storage is required to provide the functions you request and therefore does not require consent pursuant to Section 25(2) TTDSG. The upstream service Cloudflare may also set technically necessary security cookies (e.g. for attack detection).
9. Retention period
We store your data for as long as your account exists or for as long as this is necessary to provide the Service. Access tokens are deleted as soon as you disconnect the respective account. After you delete your account, your personal data is removed unless statutory retention obligations apply.
10. Data deletion & withdrawal
You can request deletion of your data in the following ways:
- In the application: disconnect individual accounts or delete your user account in the settings.
- By email: send a request to [email protected].
- Via Meta: when you remove our app in your Facebook/Instagram settings, a data deletion request is automatically sent to and processed by us.
11. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You can withdraw any consent you have given at any time with effect for the future. You also have the right to lodge a complaint with a data protection supervisory authority.
12. Recipients / processors
Your data is only shared insofar as this is necessary to provide the Service – in particular with the platforms you connect, with our hosting provider (Hetzner Online GmbH), the CDN and media storage provider (Cloudflare, Inc.) and the AI providers Anthropic and OpenAI. We have corresponding agreements pursuant to Art. 28 GDPR in place with our processors.
13. Changes to this privacy policy
We update this privacy policy whenever changes to the Service make this necessary. The current version published here applies.
Last updated: June 2026