This Privacy Policy explains how we process personal data in connection with Timmy, an AI-powered marketing automation tool.
1. Controller
The controller under the GDPR is Nuwis GmbH, Dannenkamp 17, 22869 Schenefeld, Germany, Managing Director: Mücahit Özcakir, email: info@nuwis.de.
2. Legal bases
We process personal data based on consent, contract performance, legal obligations and legitimate interests under Art. 6 GDPR.
3. Your rights
You have rights to access, rectification, erasure, restriction, data portability, objection and withdrawal of consent. You may also lodge a complaint with the competent supervisory authority.
4. Hosting
Timmy runs on Convex infrastructure in the EU region. Account, content, usage and technical access data are processed to deliver and secure the service.
5. Cookies and local storage
We use technically necessary session cookies and local storage. We currently do not use consent-based marketing or tracking cookies on public pages.
6. User account
Through Better Auth we process email address, name, password hash, session and verification information to provide the account.
7. AI content creation
To create text, images and scripts, we transmit inputs such as topics, instructions, brand details or URLs to specialised providers. By default, we generate text with the Kimi language models of Moonshot AI (Moonshot AI Pte. Ltd., Singapore); processing takes place on servers in Singapore. We use Google Gemini as a fallback model and for individual tasks. We generate images with OpenAI. We use Firecrawl to read websites and, in preparation, fal.ai. For transfers to third countries, see section 12. The legal basis is Art. 6(1)(b) GDPR. Please do not submit special categories of personal data.
8. Connected platforms
At your request, Timmy publishes to connected channels such as LinkedIn, Instagram, YouTube, WordPress, Payload CMS or custom blogs.
Google user data
Google user data is used only for enabled functions, not sold, not shared for advertising and not used to train general AI models. OAuth tokens are encrypted server-side and deleted or revoked when no longer needed, unless retention duties apply.
Publishing infrastructure bundle.social
To connect social media accounts, publish posts and retrieve statistics, comments and reviews (LinkedIn, Facebook, Instagram, YouTube, TikTok, X, Threads, Pinterest, Reddit) we use bundle.social (BUNDLE SP. Z O.O., ul. Hoża 86/410, 00-682 Warsaw, Poland) — as a processor under a data processing agreement, with processing on servers in the EU. The content and media to be published as well as platform metrics, comments and reviews are transmitted. Access tokens of connected social media accounts are stored by bundle.social, not in our database. bundle.social retains platform data for a limited period (statistics approx. 30 days); permanent archiving takes place in Timmy.
9. Email delivery
We use Brevo for transactional emails. Marketing emails are sent only with separate consent.
10. Free templates, tools and newsletter
On our website you can request free templates and tools, for example the social media content calendar. For this we process your email address, optionally your first name, the selected language, the requested template, the page where you requested it, and the time and number of downloads.
Purpose and legal basis: We email you the template with a personal download link. The legal basis is Art. 6(1)(b) GDPR, because you request the template from us. We store the link only as a non-reversible check value (hash); it is valid for 30 days. To prevent abuse, we limit the number of requests per email address and overall (Art. 6(1)(f) GDPR).
Newsletter: You only receive marketing tips by email if you tick the separate box and confirm the subscription through the link in our email (double opt-in). The legal basis is your consent under Art. 6(1)(a) GDPR in conjunction with Section 7(2) no. 2 of the German Act against Unfair Competition (UWG). You receive the template without the newsletter as well. We store the time of your confirmation as proof of consent.
Brevo: To send emails and manage newsletter recipients, we use Brevo (Sendinblue SAS, Paris, France) as a processor under an agreement pursuant to Art. 28 GDPR. After your confirmation, we transfer your email address, first name, language, template, source page and time of consent to Brevo.
Storage period: We automatically delete requests without a confirmed newsletter 90 days after the last request. With a confirmed newsletter, we store the data as long as you receive the newsletter, and the proof of consent beyond that where we need it under Art. 7(1) GDPR.
Withdrawal: You can withdraw your consent at any time with effect for the future, through the unsubscribe link in every newsletter email or by email to info@nuwis.de. This does not affect the lawfulness of processing carried out before the withdrawal.
Free AI tools: With our tools (hashtag generator, LinkedIn post generator and Instagram caption generator) you can generate text without an account. For this, we transmit the topic you enter (up to 500 characters), the options you select and the language once to Moonshot AI (Singapore), or alternatively to Google, so that the result can be generated. The legal basis is Art. 6(1)(b) GDPR, because you request the generation from us. We do not store your inputs or the results. We only count how often a tool was used per day and how often an error occurred, without any reference to you.
To prevent abuse, we limit usage to 10 runs per hour and browser as well as overall per day. For this, the page creates a randomly generated identifier in your browser's local storage (localStorage) that has no reference to you, and transmits it to us with every run. We use it solely for this limit. The page also stores there how many free runs you have used and whether you have unlocked the tools. The legal basis for the limit is our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). Storing and reading these values in your browser is strictly necessary under Section 25(2) no. 2 of the German Telecommunications and Digital Services Privacy Act (TDDDG) so that we can provide the service you have expressly requested. You can delete these values at any time in your browser settings.
After three free runs, we ask for your email address so you can keep using the tools. The procedure described above applies, including the optional newsletter; instead of a download link, you receive a link to the tools. Please do not enter personal or confidential data into the tools.
11. Analytics
We use PostHog via the EU cloud to improve product quality and stability without client-side tracking on public pages.
12. International transfers
Some providers may process data in the United States. Transfers rely on the EU-US Data Privacy Framework, standard contractual clauses or supplementary safeguards where applicable.
Moonshot AI processes the data transmitted to it on servers in Singapore. There is no adequacy decision of the European Commission for Singapore.
13. Storage and deletion
We store data only as long as necessary or legally required. Technical logs are usually deleted or anonymized within 30 days. Account and content data are generally deleted within 90 days after contract end unless retention duties apply.
14. Security
We use technical and organizational measures, TLS encryption and encrypted storage of credentials and tokens.
15. Processing on behalf
Where customers process personal data through Timmy, we act as processor on their behalf under a data processing agreement.
16. Updates
This Privacy Policy is currently valid and may be updated when the service or legal requirements change.