Sendezeit legal
Privacy Policy
Last updated September 16, 2026.
1. Sendezeit and the controller
Sendezeit is the name of the social publishing application covered by this policy. It is operated by Anton Rost as an individual business. Anton Rost is the controller responsible for the processing described here.
Anton RostRheinstraße 12
55116 Mainz
Germany
Email: anton-rost.dev@proton.me
Phone: +49 1520 3228208
2. Data Sendezeit processes
Sendezeit processes the data you provide or create in the service, including your account identity, workspace and brand settings, drafts, approved writing examples, media, publishing instructions, scheduled times, publication results, subscription state, support messages, and security and product-usage events.
When you connect a social destination, Sendezeit also processes the account or channel identifier and display name, the permissions you granted, encrypted OAuth access and refresh tokens, public or user-authorized publication metadata, and provider responses needed to display, schedule, publish, verify, import, or remove content at your direction. Your social-platform password is never provided to Sendezeit.
3. Google and YouTube user data
Sendezeit uses Google OAuth and the YouTube Data API only after you choose to connect a YouTube channel. It requests the minimum permissions needed for the visible YouTube features in the application:
- YouTube read-only access to identify and display the channel you chose and to retrieve its authorized channel and public-video metadata for the calendar and connection status.
- YouTube upload access to upload the video, title, description, visibility, audience, synthetic-media declaration, and scheduled publishing time that you explicitly review and approve in Sendezeit.
Sendezeit does not use Google or YouTube user data for advertising, retargeting, data brokerage, credit or lending decisions, surveillance, or the development, improvement, or training of generalized or non-personalized AI or machine-learning models.
4. How Google user data is used and stored
Google user data is used only to provide the user-facing YouTube connection, channel identification, calendar, upload, scheduling, status, and recovery features you request. OAuth credentials are encrypted at rest, used only by Sendezeit's server-side publishing services, and excluded from analytics, application logs, and AI prompts.
Channel identity and publication metadata are stored in Sendezeit's database for as long as the connection or related publishing record is needed in your account. Uploaded media is stored in private object storage and is disclosed to YouTube only when needed to carry out your approved upload. Sendezeit does not create an independent permanent archive of your YouTube account.
5. Sharing, transfer, and disclosure of Google user data
Sendezeit discloses Google user data only in these limited circumstances:
- Google and YouTube: Sendezeit sends the video, metadata, and action you selected to YouTube so that Google can perform the requested upload or account action.
- Infrastructure processors: Vercel, Hetzner, MongoDB Atlas, and Cloudflare may process data only as necessary to operate, host, transmit, secure, back up, or store Sendezeit. Sentry may receive minimized technical error information. OAuth tokens and request bodies are excluded from telemetry. These providers act for Sendezeit under contractual confidentiality and data-protection obligations; they do not receive Google user data for their own advertising purposes.
- Support and security: a person may access specific data only with your affirmative permission to resolve a support request, when necessary to investigate abuse or a security incident, or where access is required by law.
- Legal obligations: data may be disclosed when required by applicable law, regulation, court order, or a valid governmental request.
- Business transfer: Google user data would be transferred as part of a merger, acquisition, or sale of assets only after obtaining the explicit prior consent required by Google's Limited Use rules.
Sendezeit does not sell Google user data and does not share it with advertising platforms, data brokers, or information resellers. Product analytics provider PostHog receives limited page-usage events, not OAuth tokens, uploaded media, draft text, or YouTube content.
6. Google API Services Limited Use
Sendezeit's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only for Sendezeit's prominent user-facing features and the limited security, legal, and user-consented purposes described in this policy.
7. Facebook and Instagram data from Meta
Facebook and Instagram connections are currently disabled for public users while Meta review is pending. The following section describes the limited processing that applies once an eligible user can deliberately connect one of those destinations.
Sendezeit uses Meta APIs only after you choose to connect a Facebook Page or an Instagram professional account. Facebook Login for Business is used to show and verify Pages you manage, identify an Instagram professional account linked to a selected Page, display the connected destination and its authorized publication history or aggregate insights, and publish content that you explicitly approve. For those features Sendezeit requests onlypublic_profile, pages_show_list, pages_read_engagement, pages_manage_posts, instagram_basic, and instagram_content_publish.
Direct Instagram Login lets you connect an Instagram Business or Creator account without requiring a Facebook Page. For that flow Sendezeit requests only instagram_business_basic to identify and display the account and its own media metadata, and instagram_business_content_publish to deliver the posts you approve. Sendezeit does not request Meta permissions for advertising, private messages, comment management, shopping, friends, birthdays, or unrelated accounts.
Meta data may include the account or Page identifier and display name, the linked-account relationship, granted permissions, encrypted OAuth credentials, and the connected destination's own publication identifiers, captions, media metadata, timestamps, status, permalinks, and aggregate performance metrics where available. Sendezeit uses this data only for the visible connection, destination selection, calendar synchronization, publishing, delivery-status, and recovery features you request. It is not sold, used to build advertising profiles, or shared with data brokers or unrelated customers.
Sendezeit sends your approved content and action to Meta to perform the requested Page or Instagram publication. The infrastructure providers named below may process Meta data only as necessary to host, secure, transmit, or store Sendezeit. OAuth credentials are encrypted at rest and excluded from analytics and AI prompts. When you disconnect a Meta destination, Sendezeit attempts to revoke access and removes its local credentials and connection-specific imported history. You may also remove Sendezeit in your Facebook or Instagram access settings, use the data-deletion instructions, delete your Sendezeit account, or email the controller named in Section 1.
8. Other service providers
Sendezeit uses Vercel for the web application, Hetzner for application servers, MongoDB Atlas for structured data, Cloudflare for private object storage and delivery, RevenueCat for subscriptions, Sentry for minimized error reporting, and PostHog for privacy-conscious product analytics. If you deliberately configure an AI provider or use an AI-assisted feature, the content you submit for that job is processed by the selected model provider you configured. Visual context is limited to attached images or, for video, up to two compressed sheets containing eight frames sampled across the full clip. Social access tokens are never included in AI prompts.
9. Legal bases and international transfers
Sendezeit processes data to perform the service you request, based on your consent where required, to protect the service and its users, to comply with legal obligations, and for legitimate interests such as security, reliability, and limited product improvement. Where a provider processes personal data outside the European Economic Area, Sendezeit relies on an applicable adequacy decision, Standard Contractual Clauses, or another valid transfer mechanism.
10. Retention, disconnection, and deletion
OAuth credentials are retained only while the corresponding connection is active. When you disconnect a destination, Sendezeit attempts to revoke the provider token, permanently removes its local credentials, cancels related pending jobs, and removes provider-imported history and connection-specific publication records. You can also revoke Sendezeit from your Google Account's third-party access settings.
Unused draft uploads expire. Other account content remains available while your account is active and may remain read-only after a trial or subscription ends. You can export your account data and request deletion from Settings. Account deletion revokes connected provider credentials and removes or anonymizes account data, subject only to narrowly limited records that must be retained for legal, billing, fraud-prevention, security, or audit obligations. You may also request access, correction, export, or deletion by emailing anton-rost.dev@proton.me.
11. Security
Sendezeit uses encrypted transport, access controls, rotating sessions, CSRF protection, encrypted provider credentials, restricted production secrets, private media storage, audit events, and minimized telemetry. No internet service can guarantee absolute security.
12. Your rights and complaints
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or port your personal data and to withdraw consent for future processing. You may also complain to a competent data-protection supervisory authority. Contact Sendezeit using the details in Section 1 to exercise these rights.
13. Changes to this policy
Sendezeit will update this policy when its processing practices or legal obligations change. Material changes affecting previously authorized Google user data will be communicated before the data is used for a new purpose, and renewed consent will be requested where required.