Privacy Policy
Last updated: 12 September 2026
This Privacy Policy explains what personal data Aicut GmbH ("aicut", "we") collects when you use the aicut website, web app, mobile app, API and MCP server (together, the "Service"), why we collect it, who receives it, how long we keep it and what rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR).
German-speaking users can read the German version (Datenschutzerklärung). For consumers in Germany the German version prevails in case of conflict.
1. Controller and contact
The controller responsible for your data is Aicut GmbH, Richard-Wagner-Str. 38, 53115 Bonn, Germany, represented by managing director Simon Both. Email: info@aicut.pro. For any privacy request, including exercising your rights under section 11, write to this address.
2. Data we process, why, and on which legal basis
2.1 Account and login
When you register we store your email address, a password hash (if you use a password), the date of registration, and, if you sign in with Google, the email address, name and profile picture Google shares with us. We also record the sign-up source (for example a referral code or campaign), your IP address and browser at sign-up, and account settings such as language and notification preferences. Authentication is operated with Supabase.
Purpose: to create and secure your account, log you in and provide the Service. Legal basis: performance of the contract (Art. 6(1)(b) GDPR); for security logging our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
2.2 Payments and billing
Purchases are processed by Stripe Payments Europe Ltd. Stripe collects your payment details directly; we never see your full card number. We receive and store your Stripe customer ID, the products, amounts, currency, taxes and dates of your purchases, invoice and billing address data, a VAT ID if you enter one, your subscription status, and your token balances and token usage history. If you cancel, we store the cancellation reason you select.
Purpose: to charge you, manage subscriptions and tokens, prevent fraud and chargebacks, and meet tax and accounting law. Legal basis: contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c), including retention of accounting records), legitimate interest in fraud prevention (Art. 6(1)(f)).
2.3 Your content and AI generations
To generate content we process what you give us: prompts, scripts, ideas, form inputs, uploaded images, videos and audio, reference links, the voices and models you select, and the conversation you have with the in-app agent. We store the resulting videos, images and audio ("Output"), job metadata (model, settings, cost, status, timestamps) and render files so you can view, edit, download and publish them.
AI providers. Text features (script writing, prompt enhancement, ideas, captions, the agent) are answered by large language models. Some are reached directly from their providers and some through the Vercel AI Gateway, which routes a request to the model we selected for that feature. The providers reachable this way are OpenAI, Anthropic, Google, xAI, Mistral, MiniMax, DeepSeek and Z.ai. Which provider answers depends on the model selected for that feature or chosen by you. What we send is the text you supply and the text of your agent conversation; we do not send your account details, email address, billing data or browsing history to these models. Voice messages to the agent are transcribed into text by a speech-to-text model of one of the providers named in this section; the audio clip itself is not stored.
Zero data retention. Every request we send through the Vercel AI Gateway asks for zero data retention: the provider is asked not to store the request after it has been answered and not to use it to train its models. A provider may hold a short-lived prompt cache scoped to our account so a follow-up request in the same conversation costs less; it is never used for training. Production traffic always sends this setting; internal preview and test environments may evaluate a model without a zero-retention route, and no customer data reaches those runs. We cannot guarantee a provider's own conduct, but this is the setting we send.
Media generation. Video, image, voice, music and sound generation is performed by AI models operated by OpenAI, Google, ElevenLabs, Amazon Web Services and the model hosting platforms fal.ai, Replicate and Kie.ai (which host models from further developers such as Kling, MiniMax, Runway, xAI and others). For a generation, the prompt and any reference image, video or audio you attach are sent to the provider operating the model you chose, and its result is returned to us. These providers process this data as our processors or, where they are independently responsible, under their own privacy policies linked in section 6. Uploaded media is stored on Amazon S3 and Cloudflare R2; video rendering runs on Remotion and AWS Lambda.
We do not use your content or Output to train generalized AI models of our own. We may review content, manually or with automated classifiers, to enforce our Terms and the content rules of our providers.
Purpose: to provide the generation, editing, storage and publishing features you request. Legal basis: contract (Art. 6(1)(b)); content safety checks: legitimate interest and legal obligation (Art. 6(1)(f) and (c)).
2.4 Connected social media accounts
When you connect TikTok, YouTube (Google) or Instagram (Meta) we receive, through the platform's OAuth consent flow, an access token and refresh token, your account or channel ID, name, handle and avatar, and, when you use the related features, the videos, titles, descriptions, visibility settings and publishing status of posts you make through aicut, plus the list of your recent posts with their public statistics (views, likes, comments, shares) for the channel performance view. Tokens are stored in our database with access restricted to the systems that need them and are used only to perform the actions you request: publishing and scheduling videos, running the automation campaigns you set up, and reading your channel and post data. Disconnecting an account in the Service deletes its tokens; you can also revoke access in the platform's own settings.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Details are in our Google API Limited Use Disclosure. Google user data is never sold, never used for advertising, never used to train generalized AI models and never read by a human except with your consent, for security purposes or where the law requires.
Legal basis: contract (Art. 6(1)(b)); the platform connection itself is your instruction.
2.5 API keys and connected apps
If you create an API key or authorize a third-party AI client (for example through our MCP server) we store a hash of the credential, its name, creation and last-use dates, the client's identifier and the permissions you granted, and log the requests made with it (endpoint, time, tokens charged, result). Data returned to a connected app is under the control of that app's provider once it leaves the Service. You can revoke keys and apps in your account settings.
Legal basis: contract (Art. 6(1)(b)); request logging: legitimate interest in security and billing accuracy (Art. 6(1)(f)).
2.6 Communication, support and email
When you contact us by email, chat, feedback forms or in-app feature requests, we process your message, your contact details and the account data needed to answer. AI models may help our support team draft answers; a person remains responsible for the reply. Transactional emails (verification, receipts, generation and publishing notifications, security notices) are sent through Resend. Product news and offers are sent only if you have not opted out; every such email contains an unsubscribe link, and you can manage notification categories in your account settings. We record whether emails bounce so we can stop sending to invalid addresses.
Legal basis: contract (Art. 6(1)(b)) for support and transactional email; our legitimate interest in informing existing customers about similar products (Art. 6(1)(f), § 7(3) German UWG) for product news, until you object; consent (Art. 6(1)(a)) where you subscribe to a newsletter without an account.
2.7 Referral, rewards and affiliate programs
For the referral program we store your referral code, who signed up with it and which reward stages were reached. For the content reward program we store the public post URLs you submit, the view counts we read from the platform and the tokens granted. For the affiliate program we use Tolt to attribute sign-ups and purchases to affiliate links with a cookie and to calculate commissions; affiliates provide their payout details to Tolt.
Legal basis: contract (Art. 6(1)(b)) and legitimate interest in preventing reward fraud (Art. 6(1)(f)).
2.8 Usage data, analytics and error monitoring
When you use the Service we automatically log technical data: IP address, device and browser type, operating system, approximate location derived from the IP address, referrer, pages and features used, timestamps, and errors. We use this data to keep the Service running and secure, to fix bugs and to understand which features are used.
- PostHog (PostHog Inc., EU cloud hosted in Frankfurt): product analytics, feature usage and error tracking, including session replays that record how a page is used. Input fields are masked in replays by default.
- Microsoft Clarity: heatmaps and session recordings to see how pages are used.
- Vercel: hosting, request logs and web analytics.
- Server logs: kept for security investigations and debugging.
Legal basis: legitimate interest in operating, securing and improving the Service (Art. 6(1)(f)) for server logs and essential technical data; consent (Art. 6(1)(a) GDPR and § 25(1) German TDDDG) for analytics tools that store or read information on your device, which you can withdraw at any time as described in section 5.
2.9 Marketing measurement
To measure our advertising we use the Meta Pixel and Meta Conversions API (Meta Platforms Ireland Ltd.) and the Google tag for Google Ads (Google Ireland Ltd.). They tell Meta and Google when a visitor who clicked an ad signs up or buys, so we can see which ads work and show relevant ads to similar audiences. For the Conversions API we send hashed identifiers (such as a hashed email address) and event data from our server. Meta and Google may combine this data with your account on their platforms; they are independent controllers for that processing.
Legal basis: consent (Art. 6(1)(a) GDPR and § 25(1) TDDDG). You can withdraw consent at any time; see section 5.
2.10 Trends and publicly available social media data
Our trend and template features analyze publicly available posts on social media platforms, including post metadata, captions, view counts and creator handles, which we obtain through the data platform Apify. This may include personal data of creators who are not aicut users. We use it only to show what is trending and to derive templates, we do not build profiles of individual creators, and we remove a creator's public data from these features on request.
Legal basis: legitimate interest in providing trend discovery (Art. 6(1)(f)).
2.11 Mobile app
The mobile app uses the same account and processes the same data as the web app. With your permission it accesses your photo library to select images for generation and to save results, and sends push notifications about finished generations if you enable them. The app does not sell anything and contains no in-app purchases.
3. Recipients of your data
We share personal data only as far as needed to provide the Service, with the following categories of recipients:
- Processors bound by data processing agreements: hosting and databases (Vercel, Supabase, Amazon Web Services, Cloudflare), payments (Stripe), email (Resend), analytics (PostHog, Microsoft Clarity, Vercel), AI gateway and model providers listed in section 2.3, trend data (Apify), affiliate tracking (Tolt).
- Platforms you connect: TikTok, YouTube/Google and Instagram/Meta receive the content and metadata you publish through aicut and act as independent controllers.
- Connected apps you authorize to access your account.
- Advertising partners (Meta, Google) as described in section 2.9, with your consent.
- Authorities and advisors where the law requires it, to enforce our Terms, or to establish, exercise or defend legal claims.
- A successor in a merger, acquisition or sale of assets, in which case we will inform you before your data becomes subject to a different privacy policy.
We do not sell personal data.
4. International transfers
Several of our providers are located in the United States or process data there (among them Vercel, Amazon Web Services, Stripe, OpenAI, Anthropic, Google, Meta, Microsoft, fal.ai, Replicate, Cloudflare and Resend), and some model providers are located in other third countries. Media processing and storage runs partly in the AWS region us-east-2 (Ohio, USA). Where data is transferred outside the EU/EEA we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for certified providers) or on the EU Standard Contractual Clauses with additional safeguards. You can request a copy of the relevant safeguards from us.
5. Cookies and similar technologies
We use cookies and local storage on your device. Strictly necessary ones keep you logged in, remember your language, protect against attacks and remember referral and affiliate attribution for the purchase. They are used on the basis of Art. 6(1)(b) and (f) GDPR and § 25(2) TDDDG. Analytics and marketing cookies (PostHog, Microsoft Clarity, Meta Pixel, Google tag) are used only with your consent, which you can give and withdraw in the cookie settings of the Service. You can also block or delete cookies in your browser, use the opt-outs offered by Meta and Google, and enable Global Privacy Control in your browser. Blocking necessary cookies may prevent the Service from working.
6. Third-party privacy policies
The privacy policies of the main providers named above:
- Stripe
- Supabase
- Vercel
- Amazon Web Services
- Cloudflare
- Resend
- PostHog
- Microsoft Clarity
- Meta
- TikTok
- OpenAI
- Anthropic
- xAI
- Mistral AI
- MiniMax
- DeepSeek
- Z.ai
- ElevenLabs
- fal.ai
- Replicate
- Kie.ai
- Apify
- Tolt
7. How long we keep data
- Account, content and Output: until you delete them or delete your account. Deleting the account removes your profile, tokens and social connections immediately; your content and Output are removed from our storage within 30 days, and backups are overwritten within a further 30 days.
- Deletion record: when an account is deleted we keep a record of the deletion with the account details for a limited time to handle payment disputes, prevent repeated abuse of free tokens and comply with legal obligations, then delete it.
- Billing records: invoices and payment data for 10 years under German commercial and tax law (§ 257 HGB, § 147 AO).
- Social media tokens: until you disconnect the account or delete your aicut account.
- Agent conversations: for as long as your account exists, so you can return to them; you can delete individual conversations in the Service.
- Server logs and security logs: generally 30 to 90 days, longer while an incident is investigated.
- Analytics data: PostHog and Clarity data is kept for up to 12 months in identifiable form.
- Support correspondence: 3 years after the last message, unless needed longer for a legal claim.
8. Security
We protect your data with encryption in transit (TLS) and at rest, hashed passwords and API keys, role-based access limited to staff who need it, row-level access controls in our database, logging and monitoring, and regular security reviews of our code. No system is perfectly secure; if a breach affects your data we will inform you and the supervisory authority as the GDPR requires.
9. Automated decisions and profiling
We do not make decisions with legal or similarly significant effects on you based solely on automated processing. Automated checks flag content that may violate our rules and transactions that look fraudulent; a person reviews the consequences that matter, such as a suspension.
10. Children
The Service is intended for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (Art. 15);
- rectification of inaccurate data (Art. 16); you can change your email and profile in your account settings;
- erasure (Art. 17); you can delete your account in your account settings or ask us to delete it;
- restriction of processing (Art. 18);
- data portability: receive the data you provided in a machine-readable format (Art. 20); you can download your Output in the Service at any time;
- withdraw consent at any time with effect for the future (Art. 7(3));
- object to processing based on our legitimate interests for reasons arising from your particular situation, and object at any time to direct marketing (Art. 21). To stop marketing emails, use the unsubscribe link or your notification settings;
- complain to a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestr. 2-4, 40213 Düsseldorf, Germany (ldi.nrw.de). You may also complain to the authority of your own place of residence.
To exercise a right, email info@aicut.pro from the address of your account, or from another address with information that lets us verify you. We answer within one month; we may extend this by two months for complex requests and will tell you if we do.
12. Changes to this policy
We update this policy when the Service or the law changes. The date at the top shows the current version. For material changes we notify you by email or in the Service before they take effect. Earlier versions are available on request.