Datenschutzerklärung · Privacy notice
Stand / last updated: 5 September 2026. Written in English because Askryn's users are; the German legal terms are given where they matter.
1. Controller (Verantwortlicher)
sydacos GmbH, Hasenböge 17, 21514 Klein Pampau, Germany. E-mail: hello@askryn.app. No data protection officer is required for a company of our size; write to the address above for anything about your data.
2. What Askryn does with data, and why
2.1 Your account
E-mail address, sign-in (handled by Clerk), your time zone and brief hour, your product description, example posts and search queries, your plan and billing state, and every card state you set. Legal basis: performance of the contract with you, Art. 6(1)(b) GDPR. Kept while your account exists; deleted when you delete the account (Settings → Delete), plus one anonymous line in our operations log.
2.2 Public posts by other people (Art. 14 GDPR notice)
Every morning Askryn searches public posts on X that were published in the last 24 hours and match your queries, scores them for buying intent, and shows you up to eight with the author's handle, a short excerpt, and a link to the post. The authors are not our customers; we obtain their data from X's public search. Legal basis: our and your legitimate interest in finding people who publicly asked for a product like yours, Art. 6(1)(f) GDPR. We keep the post's URL, the author's handle and the score; the text of the post is deleted from our database 24 hours after it was published, and the author's reply to you 24 hours after it was received. No post is shown to more than two Askryn users, ever. Authors can ask us at any time to remove their handle from our records (see section 6).
2.3 Drafted replies
Askryn drafts a reply for each card using an AI model. Drafts are labelled "(AI-drafted)" in the product and in the text you copy. Askryn never posts anything: you post from your own X account, by hand.
2.4 Reading your own X account (optional)
If you connect X in Settings, Askryn receives a read-only token (scopes tweet.read, users.read, offline.access) and reads your own recent replies and the replies to them, so that "sent" and "answered" are observed instead of typed. The token is stored encrypted and deleted when you disconnect. Legal basis: your consent, Art. 6(1)(a) GDPR, withdrawable any time by disconnecting.
2.5 E-mail
The daily brief, "they answered" notices, follow-up drafts, the weekly report and billing notices go to your account address through Resend. Legal basis: Art. 6(1)(b) GDPR. Change the hour or stop the mails in Settings.
2.6 Tracked links
If you create a tracked link for a card, clicks on it store the time, the user agent and the referrer for 90 days, and no IP address. Legal basis: Art. 6(1)(f) GDPR.
2.7 The public Demand Index
Weekly counts and the most common phrases per niche are derived from the pipeline's byproduct. Excerpts shown there are short, have handles and links removed, and are never older than 24 hours.
3. Processors and transfers
- Vercel Inc. (USA): hosting and functions. Vercel GmbH DPA with EU standard contractual clauses.
- Neon Inc. (USA): the database, hosted in an EU region. DPA with SCCs.
- Clerk Inc. (USA): sign-in and session. DPA with SCCs.
- Stripe Payments Europe Ltd. (Ireland): payments. We never see your card number.
- Resend (USA): transactional e-mail. DPA with SCCs.
- xAI Corp. (USA): the X search that finds the posts. Your queries and the returned public posts are sent there. DPA and SCCs; xAI's API terms apply to the search.
- Anthropic PBC (USA): scoring the posts and drafting the replies. Your product description, example posts and the candidate posts are sent there. DPA with SCCs; API inputs are not used to train models.
Transfers to the USA rest on the EU standard contractual clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, the EU-US Data Privacy Framework.
4. Cookies and analytics
Only strictly necessary and functional cookies: Clerk's session cookie; a short-lived cookie during the X connection flow; and, only if you arrive through a referral link (a URL with ?ref=), a 30-day askryn_ref cookie that remembers who sent you so that both of you get a free month when you pay (Art. 6(1)(f) GDPR, § 25(2) TDDDG). No advertising, no tracking pixels, no analytics cookies.
5. Retention
Account data: until deletion. Post excerpts: 24 hours after publication. Card metadata (URL, handle, score, state): with your account. Billing records: ten years, § 147 AO. Operations logs: 90 days.
6. Your rights
Access, rectification, erasure, restriction, portability and objection (Art. 15 to 21 GDPR). Export everything from Settings; delete your account from Settings; or write to hello@askryn.app. Authors of posts who want their handle removed from our records: same address, we act within a week. You may complain to a supervisory authority, for us the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein, Holstenstraße 98, 24103 Kiel.