This Privacy Policy (Datenschutzerklärung) explains how AxonCraft processes your personal data when you use our platform and visit our website. It is written to meet the requirements of the EU General Data Protection Regulation (Datenschutz-Grundverordnung, GDPR/DSGVO) and the German Federal Data Protection Act (Bundesdatenschutzgesetz, BDSG).
1. Controller and Contact
The controller (Verantwortlicher) responsible for the processing of your personal data described in this policy is:
- Axoncraft — business designation (Geschäftsbezeichnung) of Arnab Biswas
- Legal form: sole proprietorship (Einzelunternehmen); Inhaber (owner): Arnab Biswas
- Address: Adolf-Kolping-Straße 7, 65385 Rüdesheim am Rhein, Germany
- Email (privacy matters): privacy@axoncraft.ai
- Email (general): hello@axoncraft.ai
The controller is a natural person trading under a business designation, not a company. There is no separate legal entity, no commercial-register entry and no managing director; the owner named above is the controller.
Data Protection Officer (Datenschutzbeauftragter)
We have not appointed a Data Protection Officer, because we are not required to. Axoncraft is a one-person business with no employees, so fewer than twenty persons are constantly occupied with the automated processing of personal data and the threshold in § 38(1) BDSG is not met. We also do not carry out processing that triggers a mandatory appointment under Art. 37(1) GDPR: we are not a public authority, our core activity is not large-scale regular and systematic monitoring of data subjects, and we do not process special categories of data or criminal-conviction data on a large scale.
For any data-protection matter — including the rights described in Section 9 — please write to privacy@axoncraft.ai. That address reaches the owner directly.
Impressum
Our full legal disclosure under § 5 DDG is available in our Impressum at https://axoncraft.ai/app/legal/impressum.
2. Overview and Scope
AxonCraft is a cloud platform of AI-powered tools for creatives and creative and media agencies. You submit briefs and other inputs ("Inputs") and receive AI-generated creative ideas, boards, and decks ("AI Outputs").
This policy applies to the personal data we process when you:
- visit our website;
- create and use an AxonCraft account;
- submit Inputs and generate AI Outputs;
- communicate with us; and
- subscribe to or pay for our services.
Where we link to third-party websites or services, this policy does not apply to those third parties; their own privacy notices govern their processing.
"Personal data" means any information relating to an identified or identifiable natural person, as defined in Art. 4(1) GDPR.
3. Categories of Personal Data We Collect
We process the following categories of personal data:
- Account data — your email address, display name, and the workspace(s) you belong to or create.
- Authentication data — information needed for passwordless email magic-link sign-in and, where you choose it, Google Single Sign-On (e.g. the email address and basic profile information your Google account makes available to us).
- Usage and log data — technical information generated when you use the platform, such as IP address, device and browser type, pages and features accessed, timestamps, referring URLs, and diagnostic or error logs.
- Inputs and AI Outputs — the briefs, prompts, text, files, and other content you submit, together with the ideas, boards, decks, and other AI Outputs generated for you. These may contain personal data if you choose to include it.
- Payment and subscription data — your subscription plan, billing status, transaction history, and the billing details needed to process payments. Card and bank details are handled by our payment processor; we generally do not store full payment-card numbers.
- Communications data — the content of, and metadata about, your correspondence with us (e.g. support requests, emails).
- Cookies and device data — identifiers and information stored in or read from cookies and local storage, including session identifiers and, where applicable, analytics identifiers (see Section 7).
- Abuse-prevention signals — when you request access, sign in or verify your account, or join our waitlist: your IP address, your browser's user-agent string, and a hashed identifier derived from basic device properties (see Section 4.8).
You are not legally obliged to provide your personal data. However, certain data (such as account and authentication data) is necessary to provide the service, and without it you may be unable to create an account or use AxonCraft.
4. Purposes of Processing and Legal Bases
We process your personal data only where we have a legal basis under Art. 6(1) GDPR. The following table sets out each purpose and its legal basis.
4.1 Providing the service and your account
We process account, authentication, usage, and Inputs/AI Outputs data to create and maintain your account, authenticate you, operate the platform, generate AI Outputs, and provide related features and support.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); where you use AxonCraft on behalf of an organisation, also our legitimate interest in delivering the contracted service (Art. 6(1)(f) GDPR).
4.2 Authentication and account security
We process authentication, usage, and log data to verify your identity (including via magic-link and Google SSO), prevent unauthorised access, detect and investigate abuse or fraud, and keep the platform secure.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in the security and integrity of our service and the protection of our users (Art. 6(1)(f) GDPR).
4.3 Billing, subscriptions, and payments
We process payment and subscription data to manage your subscription, take payment, issue invoices, and prevent payment fraud.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); compliance with statutory accounting and tax obligations (Art. 6(1)(c) GDPR, in conjunction with German retention duties — see Section 8).
4.4 Communications and support
We process communications and account data to respond to your enquiries and provide customer support.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to enquiries and supporting our users (Art. 6(1)(f) GDPR).
4.5 Service improvement, troubleshooting, and security analytics
We process usage and log data (and, where strictly necessary, technical information about how features are used) to diagnose problems, fix bugs, maintain stability, and improve and protect the service. Where we draw on Inputs and AI Outputs for this purpose, we use anonymised or aggregated data wherever possible.
Legal basis: our legitimate interest in operating, securing, and improving our service (Art. 6(1)(f) GDPR).
4.6 Optional product analytics and marketing
Where you have given consent, we process usage and device data through optional product-analytics tools to understand how the product is used, and we may send you product or marketing communications.
Legal basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future (see Sections 7 and 9). Where we send marketing to existing customers about our own similar services, we may instead rely on our legitimate interest and applicable provisions of the German Act Against Unfair Competition (§ 7 UWG), subject to your right to object at any time.
4.7 Legal compliance and defence of claims
We process personal data where necessary to comply with legal obligations to which we are subject, and to establish, exercise, or defend legal claims.
Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR) and our legitimate interest in the establishment, exercise, or defence of legal claims (Art. 6(1)(f) GDPR).
4.8 Preventing free-trial and referral abuse
When you request access, sign in or verify your account, or join our waitlist, we record your IP address, your browser's user-agent string, and a hashed identifier derived from basic device properties (such as platform, language, timezone and screen size). We process this information for one purpose: detecting when free trials or referral rewards are claimed repeatedly by the same person under different email addresses.
The device identifier is produced by a salted cryptographic hash designed to be one-way; we do not store the underlying device property values. We do not use this information for advertising or profiling, and we do not disclose it to third parties for their own purposes. It is processed only by the infrastructure providers that host our service, acting on our instructions as processors (see Section 6).
These records are deleted automatically after 180 days (see Section 8). You can request access to or erasure of this data at any time, as described in Section 9.
Legal basis: our legitimate interest in preventing abuse of free services (Art. 6(1)(f) GDPR).
5. AI Processing of Your Inputs and Outputs
When you submit Inputs, we and our AI subprocessors process that content to generate AI Outputs for you.
- Your Inputs and AI Outputs are processed by third-party AI model providers acting as our subprocessors under data processing agreements pursuant to Art. 28 GDPR.
- We do not use your Inputs or AI Outputs to train general-purpose AI models. We have configured our use of AI subprocessors so that your content is used to provide the service to you, not to train their general-purpose models.
- We may create anonymised or aggregated data from usage of the service. Once data is anonymised so that it no longer relates to an identifiable person, it is no longer personal data and falls outside this policy.
Legal basis for AI processing: performance of a contract (Art. 6(1)(b) GDPR), because generating AI Outputs is the core service you have requested.
Because AI Outputs are generated automatically, you should review them before relying on them. We do not use your personal data to make decisions that produce legal or similarly significant effects about you solely by automated means within the meaning of Art. 22 GDPR.
6. Recipients and International Transfers
6.1 Categories of recipients
We share personal data only as necessary and with the following categories of recipients, who act either as our processors (Auftragsverarbeiter) under data processing agreements pursuant to Art. 28 GDPR, or as independent controllers where required:
- Cloud hosting and infrastructure providers that operate the platform on our behalf.
- AI model providers that process Inputs and AI Outputs as our subprocessors.
- Payment processor(s) that handle subscription billing.
- Product-analytics providers, where you have consented.
- Authentication providers, in particular Google, where you use Google Single Sign-On.
- Communication and support tool providers used to operate our helpdesk and email.
- Professional advisers (e.g. lawyers, auditors, tax advisers) and public authorities, where required by law.
We do not sell your personal data.
6.2 Our processors and subprocessors
The following table names the providers we actually use, what each is used for, and where the processing takes place. "Third country" means outside the EU/EEA.
| Provider | What it is used for | Where personal data is processed |
|---|---|---|
| Supabase (Supabase, Inc.) | Account database, sign-in / magic-link identity service, and the private storage bucket that holds board images and custom deck templates | Project database hosted in an EU region; provider incorporated in the United States (third country) — SCCs |
| Render (Render Services, Inc.) | Application hosting: the servers that run the platform and its API | Provider incorporated in the United States (third country) — SCCs. Our deployment manifest declares Frankfurt as the intended region; see the review note below |
| Anthropic | Claude models that generate and refine ideas, routes and creative reasoning from your Inputs | United States (third country) — SCCs |
| OpenAI | Image generation for boards, plus text embeddings used to retrieve comparable reference campaigns | United States (third country) — SCCs |
| Google (Google Ireland Ltd / Google LLC) | Gemini models used for image generation and evaluation; "Continue with Google" single sign-on; optional export of a deck to Google Slides using your own Google account | United States (third country) — SCCs / EU-US Data Privacy Framework |
| Cohere | Re-ranking retrieved reference material against your brief | Canada (adequacy decision) and/or the United States — see the review note below |
| Resend | Transactional email: sign-in links, verification and account email | United States (third country) — SCCs |
| PostHog (EU Cloud) | Optional product analytics and session replay, used only with your consent (Section 7) | European Union — our configuration sends analytics to PostHog's EU ingest endpoint only |
| Sentry | Error and crash reporting, configured not to send request bodies or default personal data | Region depends on the project endpoint — see the review note below |
| Paddle (Paddle.com Market Ltd) | Checkout, invoicing and subscription billing. Paddle acts as Merchant of Record, meaning it is the seller of record for the transaction and an independent controller of the payment data you give it | United Kingdom (adequacy decision) |
We also use a trend-discovery integration (Apify) that queries publicly trending social content by category keyword. It receives category keywords only and is not sent your personal data, your Inputs or your account identifiers.
6.3 International transfers (Art. 44–49 GDPR)
As the table above shows, several of our processors process personal data outside the European Union / European Economic Area — principally in the United States, and for Paddle in the United Kingdom. Where we transfer personal data to a country that has not received an adequacy decision from the European Commission, we safeguard the transfer using the EU Standard Contractual Clauses (SCCs) adopted under Art. 46(2)(c) GDPR, together with supplementary technical and organisational measures where appropriate. Transfers to the United Kingdom and to Canada rely on the European Commission's adequacy decisions for those countries.
You may request a copy of the relevant safeguards by contacting us at privacy@axoncraft.ai.
7. Cookies and Tracking
We use cookies and similar technologies (such as local storage). We distinguish between essential and optional technologies, in line with the German Telecommunications-Digital-Services-Data-Protection Act (Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
7.1 Essential cookies and storage
These are strictly necessary to operate the platform — for example, to keep you signed in, maintain your session, and ensure security. They are set on the basis of § 25(2) TDDDG and our legitimate interest (Art. 6(1)(f) GDPR) and do not require consent.
7.2 Optional cookies and analytics
We use exactly one optional tool, and only where you have given consent (§ 25(1) TDDDG and Art. 6(1)(a) GDPR):
- PostHog product analytics (PostHog EU Cloud). When enabled it sets analytics identifiers in your browser and records which screens and features you use, along with automatically captured interaction signals such as rage clicks and dead clicks, and session replay. Session replay is configured to mask all form inputs and any element we have marked as private, so the text you type is not recorded. Analytics data is sent to PostHog's EU ingest endpoint.
We do not use advertising cookies, cross-site tracking pixels, or any third-party marketing tags.
7.3 Managing and withdrawing consent
How we obtain consent. Analytics is switched off by default in your browser: the analytics client starts in an opted-out state and captures nothing until consent is given. We ask for consent at the agreement step when you set up your account, and we record the fact of that agreement — the purpose, the exact version of the text you were shown, and the time — so we can demonstrate valid consent under Art. 7(1) GDPR. No optional technology runs before that point.
How to withdraw consent. Email privacy@axoncraft.ai and ask us to switch optional analytics off for your account; we will do so and confirm. You can also block or delete cookies and local storage through your browser settings, which stops the analytics client from working. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
8. Retention
We keep personal data only for as long as necessary for the purposes set out in this policy, and then delete or anonymise it, unless a longer retention period is required or permitted by law.
- Account, Inputs, and AI Outputs data — retained for the duration of your account. After your account is closed, we delete or anonymise this data within a reasonable period, unless we must retain it to comply with legal obligations or to establish, exercise, or defend legal claims.
- Usage and log data — the periods we enforce automatically are: marketing and enquiry records (leads) 730 days; abuse-prevention signals 180 days (Section 4.8); the internal quality-evaluation log 90 days; and the API cost ledger 90 days. These are deleted by a scheduled job that runs every six hours. Application and request logs written to our hosting platform's log stream are not subject to a fixed period set by us: they are kept only as long as needed for security monitoring and troubleshooting, and are then removed under the hosting provider's own log-retention policy.
- Billing and invoice data — retained to meet German statutory retention obligations. Invoices and accounting records are generally kept for up to 10 years (§ 147 of the German Fiscal Code, Abgabenordnung — § 147 AO) and commercial records for the periods required under § 257 of the German Commercial Code (Handelsgesetzbuch, HGB) (commonly 6–10 years).
- Communications data — retained as long as needed to handle your enquiry and for a reasonable period afterwards, subject to any statutory retention duties.
- Consent records — retained as long as needed to demonstrate that valid consent was given, and for the duration of any related limitation periods.
- Abuse-prevention signals (Section 4.8) — deleted automatically after 180 days. Referral records are retained for the lifetime of the associated account as entitlement history and are erased with the account.
Where data is retained solely to meet statutory retention duties, its processing is restricted to that purpose until the retention period expires.
9. Your Rights as a Data Subject
Subject to the conditions in the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — to obtain confirmation of whether we process your personal data and, if so, a copy of it and information about the processing.
- Right to rectification (Art. 16 GDPR) — to have inaccurate personal data corrected and incomplete data completed.
- Right to erasure (Art. 17 GDPR) — to have your personal data deleted where one of the grounds in Art. 17 applies ("right to be forgotten").
- Right to restriction of processing (Art. 18 GDPR) — to have processing restricted in certain circumstances.
- Right to data portability (Art. 20 GDPR) — to receive personal data you provided to us in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21 GDPR) — to object, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 6(1)(f) GDPR), and to object at any time to processing for direct marketing purposes.
- Right to withdraw consent (Art. 7(3) GDPR) — where processing is based on your consent, to withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing before withdrawal.
How to exercise your rights
To exercise any of these rights, contact us at privacy@axoncraft.ai. We will respond within the time limits set out in Art. 12 GDPR (generally within one month). We may need to verify your identity before acting on your request.
10. Right to Lodge a Complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Aufsichtsbehörde) under Art. 77 GDPR, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority competent for the controller is:
- Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)
- Postfach 3163, 65021 Wiesbaden, Germany
- Website: https://datenschutz.hessen.de
- Email: poststelle@datenschutz.hessen.de
11. Security Measures
We implement appropriate technical and organisational measures (technische und organisatorische Maßnahmen, TOMs) to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, in accordance with Art. 32 GDPR. Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, these measures include encryption of data in transit, access controls and authentication, network and application security, logging and monitoring, and regular review of our safeguards.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security; however, we work to maintain a level of security appropriate to the risk.
12. Children
AxonCraft is intended for use by businesses and professionals. Our service is not directed to children, and we do not knowingly collect personal data from children under the age of 16. If you believe a child has provided us with personal data, please contact privacy@axoncraft.ai and we will take appropriate steps to delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our service, our processing activities, or legal requirements. We will publish the updated version with a revised effective date and, where the changes are significant, take appropriate steps to inform you. The version in force is the one published on our website.