Privacy Policy

1. Data Controller

HERICAN eG Hegelstr. 18 39104 Magdeburg Email: [email protected] Phone: +49 175 1156451

2. Overview of Data Processing

We process personal data only to the extent necessary to provide our service, process payments, and improve our platform. Your data is treated confidentially and processed in accordance with the General Data Protection Regulation (GDPR).

3. Data We Collect

When using our service, we collect the following data:

  • Name (provided during registration)
  • Email address
  • Password (stored encrypted)
  • Payment information (processed by Stripe/PayPal, not stored by us)
  • Usage data (anonymized analytics)
  • Uploaded files (temporarily processed for prompt generation)

4. Purpose of Data Processing

We process your data for the following purposes:

  • Providing and operating the Prompt Generator service
  • Processing payments and managing access
  • Communication regarding your account and our services
  • Improving our platform and user experience
  • Sending information about new features, offers, and promotions (with your consent)

5. Legal Basis

Processing is based on Art. 6(1)(a) (consent), (b) (contract performance), (c) (legal obligation), and (f) (legitimate interest) GDPR. For marketing purposes, we obtain your explicit consent (Art. 6(1)(a) GDPR).

6. Marketing and Advertising

With your consent, we use your contact data (email address) to inform you about new features, special offers, and promotions. This may also occur via social media channels and email newsletters. You can withdraw your consent at any time by contacting [email protected] or using the unsubscribe link in our emails.

7. Third-Party Services and Data Transfer

We use the following third-party providers to deliver our services:

  • Stripe – Payment processing (Stripe, Inc., USA). Privacy policy: stripe.com/privacy
  • PayPal – Payment processing (PayPal (Europe) S.à r.l. et Cie, S.C.A.). Privacy policy: paypal.com/privacy
  • Umami Analytics – Privacy-friendly website analytics (no cookies, no personal data)

8. Cookies

We only use technically necessary cookies for session management and authentication. No tracking cookies or advertising cookies are used.

9. Data Storage and Deletion

Your personal data is stored only as long as necessary for the stated purposes or as required by legal retention periods. Uploaded files are automatically deleted after processing.

10. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)

To exercise your rights, please contact: [email protected]

11. Changes to this Privacy Policy

We reserve the right to update this privacy policy as needed to reflect changes in legal requirements or our services. The current version is always available on this page.

Last updated: February 2026