Privacy Policy
Last updated: September 8, 2026
This policy explains how SocialMint handles personal data when you visit our website, use an account, or review a client post.
A data processing agreement (DPA/AVV) is available on request via the contact address; a self-service version follows.
Who is responsible
productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenbergerstr. 2, 94036 Passau, Germany, is the controller for account administration, billing, security, and website operation. Contact: info@productivity-boost.com. See our Impressum for company representation and registration details.
When an agency uploads client content and manages approvals, we process that content on its documented instructions. The agency determines the purposes and lawful basis, either as controller or on behalf of its own client. Our data processing agreement governs that processing. If your agency sent you an approval link, contact it about the content or its use of your data; we help it respond to requests.
We have not appointed a data protection officer. Please direct privacy questions to the contact email above.
Data we use and why
| Data | Purpose | Legal basis for processing we control |
|---|---|---|
| Account email, name, workspace membership, and account settings | Create accounts, manage access, and provide the subscription | Article 6(1)(b) GDPR for an individual contracting with us; Article 6(1)(f) for business contacts and team members, to administer the customer relationship |
| Name, email, and profile picture, if you choose Google sign-in | Authenticate you using Google sign-in; we do not request access to Gmail, contacts, or other Google content | The same account-administration bases above |
| Subscription, invoice and payment status, billing contact/address, tax information, Stripe customer and transaction references | Take payments, administer subscriptions, and maintain accounting records | Article 6(1)(b), or Article 6(1)(f) for business contacts; Article 6(1)(c) for tax and accounting duties |
| IP address, request time, requested path, browser information, response status, and relevant account reference in server logs | Diagnose faults, prevent abuse, and protect access | Article 6(1)(f): our interest in a secure, functioning service |
| Session identifiers and session records | Keep you signed in and protect your session | Article 6(1)(b), or Article 6(1)(f) for team access |
| Support messages and related account information | Answer your questions and resolve problems | Article 6(1)(b), or Article 6(1)(f) for business contacts |
We also process drafts, media, brand and connected-account identifiers, schedules, approval decisions and comments, publishing results, and retry/error history on the customer's instructions. Reviewers can respond without creating an account; their responses are associated with the review link and post. Technical request data is still processed for security. Do not include confidential information in a review comment unless the agency needs it.
For API and n8n use, we process credentials and request metadata needed to authenticate requests and carry out the customer's workflow. Data sent to a separate n8n installation is also subject to that installation's operator and configuration.
Providing the information needed for an account or paid subscription is necessary to supply that service. Optional profile information is not required beyond the authentication method's needs. We do not use automated decision-making with legal or similarly significant effects, or profile people for advertising.
Social-network access tokens
When you connect a social account, the network supplies access tokens and, where applicable, refresh tokens. We store tokens encrypted and use them only to deliver the publishing service you request, including maintaining authorization and checking the result of a publishing attempt. We do not use them to browse unrelated private messages or for advertising.
You can revoke SocialMint's access in the network's settings. Disconnecting an account stops future publishing through that connection and removes its active tokens. Content already published remains on the network until you remove it there. Anyone with a review link may be able to view or respond to its post; share links only with intended reviewers.
Cookies and tracking
SocialMint uses only technically necessary session cookies. They support sign-in and session security. We use no advertising pixels, behavioral analytics, or cross-site tracking. Blocking session cookies can prevent sign-in. Necessary device storage is based on § 25(2)(2) TDDDG; the associated personal-data processing follows the bases described above.
Session cookies are first-party cookies on the SocialMint domain. Auth.js uses __Secure-authjs.session-token on HTTPS (authjs.session-token in local HTTP development); sessions expire after 30 days unless renewed. Necessary first-party authentication cookies include __Host-authjs.csrf-token and __Secure-authjs.callback-url (browser-session lifetime), plus __Secure-authjs.pkce.code_verifier and __Secure-authjs.state (up to 15 minutes during Google sign-in). Local HTTP development omits the secure prefixes. These cookies protect login requests and remember the callback destination; they are not used for tracking.
Providers and other recipients
- Hetzner hosts SocialMint's application data in Germany and processes hosted data on our instructions under a data processing agreement.
- Stripe handles checkout, subscription billing, and payments. Payment details are entered directly into Stripe; SocialMint does not store full card numbers or card security codes. Stripe acts as a processor for activities performed on our instructions and as an independent controller for its own purposes, including regulatory compliance and fraud prevention. See Stripe's Privacy Policy and data processing agreement.
- Google handles optional Google sign-in and receives login-related technical data. Its own processing is explained in Google's Privacy Policy.
- Connected networks receive the content, media, and account information needed to publish your posts. At launch these are X, Bluesky, Mastodon, Telegram, and Threads. The relevant provider includes your selected Mastodon server or Bluesky service provider. Their own privacy rules apply to data they receive and posts they host.
- Authorized personnel can access data where necessary to operate the service or provide support. We may disclose necessary records to professional advisers or authorities when required by law or needed to establish or defend legal claims.
We do not sell personal data or share it with advertisers.
Where data is processed
Our application data is hosted with Hetzner in Germany. This does not mean every recipient processes data only in Germany or the EU: Stripe, Google, and connected social-network providers may process data internationally.
Where we arrange a transfer outside the EEA, it must have a lawful transfer mechanism, such as a relevant adequacy decision or EU Standard Contractual Clauses with any necessary supplementary safeguards. Ask us for information about the applicable safeguards or a copy, with confidential information redacted where necessary.
The application, database, media, and backups run on our own infrastructure at Hetzner in Germany (Falkenstein/Nuremberg). Stripe Payments Europe, Limited (Ireland) provides payment services and may transfer data to Stripe, LLC in the United States. US transfers use EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Google and connected networks may also process data outside the EEA under the applicable transfer safeguards described above.
Retention and deletion
We retain account data while the account is active and as needed to close it. Customer content and approval/publishing history are retained according to the customer's instructions and the data processing agreement. Cancellation of a subscription does not by itself request immediate account deletion. You can request deletion at our contact email.
Server logs are retained for 30 days. Account data is retained until you request deletion by emailing info@productivity-boost.com. This also applies after trial expiry or subscription cancellation, subject to the statutory retention duties below. We process deletion requests under the GDPR and remove customer content according to the customer’s instructions.
Records needed for German tax and commercial accounting are retained for the statutory period applying to their category. Necessary evidence may also be retained for legal claims or binding preservation duties, with access restricted to that purpose. We delete or anonymize data when the applicable purpose and retention duty end. Deletion from SocialMint does not delete a post already held by a social network or records another controller must retain independently.
Your rights
Subject to the GDPR's conditions, you can request access, correction, erasure, restriction, and data portability. You can object to processing based on legitimate interests for reasons relating to your situation. If we rely on consent, you can withdraw it at any time without affecting earlier lawful processing.
Email info@productivity-boost.com. We may request proportionate identity verification. We normally respond within one month; if a lawful extension is necessary, we explain why within that first month. You can complain to a supervisory authority, including the Bavarian State Office for Data Protection Supervision (BayLDA), or the authority where you live or work.
Security, children, and changes
We use encrypted transport and encrypted token storage, and limit access to operational needs. No service can eliminate every security risk. SocialMint is intended for professional agency and freelance use, not for children. Contact us if a child has provided account data.
We update this policy when our processing changes and revise the date above. We notify account holders of material changes before they take effect where applicable. A policy update does not replace consent when consent is legally required.