Legal

English · Deutsch
In case of differences, the German version prevails.

Privacy Policy

Last updated: 6 October 2026. Applies to the website bumely.com and the Bumely Studio at studio.bumely.com.

Key points

  • The home page sets no cookies and uses no analytics or tracking services. It stores something in your browser only if you choose a language yourself at the bottom of the page: that choice is saved as “bumely-sprache” (localStorage) so that the page stays in your language. You can delete it through your browser’s website data. Fonts, images and video come from our own server, and we load no fonts from Google.
  • Your videos are stored on our server in Frankfurt am Main and are deleted automatically after 7 days.
  • For the subtitles, only the audio track of your video goes to our speech recognition provider, Groq (USA), and, for the suggested post text, the text taken from it. This happens only after you have consented before your first upload. Groq may not use either of them to train AI.
  • Optionally, you can connect TikTok, Instagram and YouTube to the Studio so that your finished video is published there for you. We are introducing this step by step; until a platform is enabled for your account, publishing goes through Buffer. Once you have connected a platform, we store the access tokens encrypted in Frankfurt, delete them when you disconnect or delete your account, and publish only what you confirm.
  • Your account is stored at Supabase in Frankfurt. We use Resend for emails, Cloudflare Turnstile against bots and Sentry for error reports, with data storage in the EU. Supabase, Resend and Sentry work only on our behalf; Cloudflare also uses the bot protection data as an independent controller.
  • We do not sell data, we show no advertising and we use no analytics or tracking services.

1. Who is responsible

tayger, owner Tayger Galster
Regensburger Straße 138
90478 Nürnberg, Germany
Email: galster@tayger.de
Phone: +49 176 66487375

We are not required to appoint a data protection officer. If you have any question about data protection, just write to us at the address above or at info@bumely.com.

2. Server and hosting

The home page and the Studio run on our own server in a data centre in Frankfurt am Main. We rent the server from Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaka, Cyprus. Hostinger processes the data only on our behalf. We plan to conclude a data processing agreement under Art. 28 GDPR with Hostinger.

When you open a page, the server needs your IP address to send the response to you. It does not keep general access logs with IP addresses. However, your IP address can appear in the server’s system log in the case of program errors, blocked connections and sign-in attempts at the server’s maintenance access. We delete this log after five weeks at the latest, and the list of sign-in attempts at the maintenance access after two months at the latest. In addition, there is the lockout after failed sign-in attempts in the Studio, see below. The legal basis is our legitimate interest in delivering the pages securely and reliably (Art. 6(1)(f) GDPR).

Before every update of the Studio, we briefly back up the account data (without your videos) on the same server. We usually delete these backups after 7 days, and at the latest at the next update after that. Our host also creates automatic backups of the whole server and overwrites them after three weeks at the latest; until then they can also contain videos that we have already deleted. We use these backups only to restore the server after an outage.

All connections are encrypted with HTTPS.

3. The home page bumely.com

The home page sets no cookies and uses no analytics or tracking services. It stores something in your browser only if you choose a language yourself at the bottom of the page: that choice is saved as “bumely-sprache” (localStorage) so that the page stays in your language. You can delete it through your browser’s website data. If you are signed in to the Studio, the home page forwards you straight to the Studio. For this, our server recognises the cookie “bumely_drin”, which the Studio sets when you sign in (see Section 4). If you do not have it yet, the home page asks the Studio once whether you are signed in; your browser then sends the Studio’s sign-in cookie along, if there is one. Fonts, images and the product video come from our own server; there is no embedded content from third-party providers.

4. The Bumely Studio

Access and sign-in

To use the Studio you need an account with your email address. You sign in with a code that we send you by email, with Google, with Apple if the Studio offers it, or, if you have set one, with a password. A password is not stored with us, only at Supabase (see below), and there only as an encrypted check value (hash). The exception is accounts that were created before our move to Supabase at the end of September 2026 and were not migrated: for these, such a check value may still be stored with us. We no longer use it, and we delete such a legacy account immediately when you write to us at info@bumely.com. When you create your account, you confirm that you are at least 16 years old and accept the Terms of Service by continuing after the notice below the button: “By continuing you accept the Terms of Service and confirm that you are at least 16.”

Stored on our server in Frankfurt are your email address, the date of registration, your plan (free or Pro), the number of your videos per day for the daily limit, and your settings, for example whether you want to receive emails or notifications. Which cookies the Studio sets for sign-in is listed below under “Cookies and browser storage”. For each sign-in, we also store only a checksum (hash) of the sign-in cookie and when it expires, but no IP address. A sign-in ends after 30 days, when you sign out, or when you choose “Sign out on all devices” in the settings; each account can have at most ten sign-ins at the same time.

Account and sign-in run through Supabase, a service of Supabase Pte. Ltd., 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. The database and the sign-in server are in Frankfurt am Main (AWS, region eu-central-1); your account data is stored there. For each sign-in, Supabase stores the IP address and the identifier of your browser (user agent) and logs sign-ins with the time, email address and IP address. There is no fixed retention period for these sign-in logs yet; for now they remain even after an account is deleted. Write to us at info@bumely.com and we will delete them. Supabase processes the data only on our behalf. We plan to conclude a data processing agreement under Art. 28 GDPR with Supabase. For support, Supabase can in individual cases access the system from third countries. These accesses are safeguarded by the standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).

The legal basis is providing the Studio that you want to use (Art. 6(1)(b) GDPR). We store your access data for as long as your account exists. You can delete your account yourself at any time in the Studio under “Account” > “Delete account”: this removes your account at Supabase and all your files on our server. Under “Download my data” you get a file with your account data (Art. 20 GDPR). You change your email address in the Studio under “Account” if you have set a password; the old and the new address must both confirm the change. If you have no password, write to us at info@bumely.com.

Your profile

In the Studio you have a username and a profile picture. The profile picture is either a randomly generated image or a photo that you upload yourself. When you set up your profile, you also choose a display name; you can postpone the setup with “Later”. We store username, display name and profile picture on our server in Frankfurt; for now, only you can see them. We delete an uploaded photo as soon as you remove it, and at the latest with your account. The legal basis is providing the Studio (Art. 6(1)(b) GDPR).

Cookies and browser storage

After you sign in, the Studio sets the cookie “bumely” so that you stay signed in (30 days or until you sign out) and the cookie “bumely_admin”, which only tells the interface whether a link for operators appears (30 days). It also sets the cookie “bumely_drin” for bumely.com and studio.bumely.com, which contains only “signed in: yes” so that bumely.com forwards you straight to the Studio (30 days or until you sign out). When you sign in with Google or Apple, the cookies “bumely_google” (Google) or “bumely_pkce” (Apple, and the fallback route for Google via Supabase) are added for 10 minutes to secure the process. In your browser’s storage (localStorage), the Studio remembers:

If you use the Studio as an app from your home screen or turn on notifications, it installs a background script (service worker). It stores only an offline page in your browser’s storage (“bumely-offline-1”), so that without a connection you see a notice instead of an empty page, and it delivers notifications. There are no advertising or analytics cookies. All of this stays on your device and is technically necessary for the features you have chosen (section 25(2) no. 2 TDDDG). You can delete it in your browser at any time; after that, you have to sign in again.

Signing in with Google (optional)

Instead of a code, you can sign in with your Google account. The Studio then redirects you to Google. Google asks whether Bumely may learn your email address and, once you agree, sends it to our server, which uses it to sign you in at Supabase. If the sign-in exceptionally runs directly through Supabase, Google also asks for your name and your profile picture and sends this information to Supabase. We use only the email address, for your account. There is no password with this sign-in. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Data can be transferred to Google LLC in the USA. Google is certified under the EU-US Data Privacy Framework (Art. 45 GDPR). What Google itself processes is described in Google’s Privacy Policy. The legal basis is providing the Studio in the way you have chosen (Art. 6(1)(b) GDPR). You disconnect from Google in your Google account under “Third-party apps and services”.

Signing in with Apple (optional)

If the Studio offers “Continue with Apple”, you can also sign in with your Apple ID. The Studio then redirects you to Apple through Supabase. Apple asks whether Bumely may learn your name and your email address; instead of your real address, you can choose a relay address from Apple there (“Hide My Email”). Once you agree, Apple sends this information to Supabase. We use only the email address, for your account. There is no password with this sign-in. The provider is Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Data can be transferred to Apple Inc. in the USA. What Apple itself processes is described in Apple’s Privacy Policy. The legal basis is providing the Studio in the way you have chosen (Art. 6(1)(b) GDPR). You disconnect from Apple in the settings of your Apple ID under “Sign in with Apple”.

Emails via Resend

We use Resend to send the sign-in codes, the confirmations when you register, change your email address or reset your password and, if you turn it on in the Studio, the email “Your videos are ready”. The “ready” email contains only the number of finished videos and a link to the Studio; you can turn it off again in the settings at any time. We send no advertising, and the emails contain no tracking pixels or click tracking. Resend is a service of Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA. Sending runs through Ireland. However, Resend stores the recipient address, the email content and the delivery log for 30 days on servers in the USA.

Resend works on our behalf. For this, we conclude a data processing agreement under Art. 28 GDPR with Resend; it is part of Resend’s terms. According to its own statement, Resend is certified under the EU-US Data Privacy Framework; for such companies there is an adequacy decision of the EU Commission (Art. 45 GDPR). You can check this in the Framework’s list. In addition, the standard contractual clauses of the EU Commission apply (Art. 46(2)(c) GDPR). The legal basis is providing your access (Art. 6(1)(b) GDPR) and, for the “ready” email, your consent through the checkbox in the Studio (Art. 6(1)(a) GDPR), which you can withdraw in the settings at any time.

Bot protection via Cloudflare Turnstile

When you register, sign in and reset your password, the Studio loads a small verification module (Turnstile) from Cloudflare. It detects whether a human or a program is filling in the form. For this, Cloudflare processes your IP address, characteristics of your browser (user agent, TLS fingerprint) and the identifier of our site. In the setting we use, Turnstile sets no cookie.

The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, represented in Europe by Cloudflare Germany GmbH, Rosenheimer Straße 143C, 81671 München. Cloudflare also uses these signals as an independent controller to improve Turnstile; Cloudflare’s Turnstile Privacy Policy applies to this. Cloudflare is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); in addition, the standard contractual clauses of the EU Commission apply (Art. 46(2)(c) GDPR). The legal basis is our legitimate interest in protecting the Studio from abuse and automated sign-ups (Art. 6(1)(f) GDPR). Access to your browser for this purpose is technically necessary (section 25(2) no. 2 TDDDG).

Lockout after failed attempts

If a sign-in with a password fails, the Studio stores the email address, the time and the IP address of the attempt on our server in Frankfurt and deletes them after 24 hours at the latest, usually after 20 minutes. After three failed attempts for one email address, or twenty from one IP address, within 10 minutes, sign-in is blocked for 10 minutes. The same applies to the password prompt when you change your email address. This protects accounts from someone trying out passwords. To counter mass account creation, the Studio also counts, per IP address (for IPv6 only the leading part), how many sign-ins per minute (limit: ten) and how many new accounts per day (limit: ten) come from there; we delete these counters after 24 hours at the latest. The legal basis is our legitimate interest in secure accounts (Art. 6(1)(f) GDPR).

Quota and usage figures

The Studio counts per account how many videos you create per day, to check the free quota. Only the counter is stored, not any content. The legal basis is providing the Studio (Art. 6(1)(b) GDPR). We also evaluate these counters without names and email addresses to see how Bumely is used, for example how many accounts create a second video. The legal basis for this is our legitimate interest in improving Bumely (Art. 6(1)(f) GDPR). We delete the counters after 90 days, and at the latest with your account.

For the “Overview” in the Studio, your account keeps its own statistics: how many videos were finished, how many seconds of pauses were cut out, the total length of your finished videos, how often you used which look and which detected language, and how many videos were finished on each of the last 30 days. Content, file names and texts are not part of it. The statistics remain even after your videos are deleted after 7 days, so that the Overview shows your overall result; we continuously delete daily values older than 30 days. They are included in “Download my data” and are deleted with your account. We do not evaluate them for other purposes. The legal basis is providing the Studio (Art. 6(1)(b) GDPR).

Error reports via Sentry

If a program error occurs on our server, the Studio sends an error report to Sentry: the error text, the time, the affected place in the program and technical details about the server. Beforehand, our server removes email addresses, account identifiers, long strings of digits and file paths from the error text. If your browser runs into an error in the Studio, or our server responds there with an error, the Studio sends a short report to our server: the error message (for program errors with the program file and line), the type of error and the page in the Studio without the part of the address after the question mark, at most five reports per page view. Your browser already removes text in quotation marks. Our server also removes email addresses, account identifiers and long strings of digits and passes the report on to Sentry without your IP address. To curb abuse, it counts only in memory how many reports come from one IP address (at most ten in ten minutes) and forgets this after ten minutes. Videos, texts from your videos, passwords and IP addresses do not go to Sentry. So that we can fix errors quickly, the operator also receives a short notification on their own device, without any information about you.

Sentry is a service of Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA. We have chosen data storage in the EU; the reports are stored in Frankfurt am Main and are deleted after 90 days at the latest. Sentry works on our behalf. We plan to conclude a data processing agreement under Art. 28 GDPR with Sentry. For support access from the USA, Sentry is certified under the EU-US Data Privacy Framework (Art. 45 GDPR); in addition, the standard contractual clauses of the EU Commission apply (Art. 46(2)(c) GDPR). The legal basis is our legitimate interest in a stable Studio (Art. 6(1)(f) GDPR).

Your videos

We store and process the videos you upload on our server in Frankfurt: we cut out pauses, create subtitles and render the finished video. This also includes the transcript, the still image and the look you choose.

We automatically delete every video 7 days after upload, together with the finished file. You can delete videos yourself at any time before that. We delete the name of the video file and the post text together with the video, at the latest a few hours after the 7 days have passed. Only for scheduled or published posts does the Studio remember both for longer (see “Publishing via Buffer” and “Publishing to TikTok, Instagram and YouTube”). We use your videos for nothing other than carrying out your request.

The legal basis is performance of your request (Art. 6(1)(b) GDPR).

Other people in your videos

If other people besides you can be seen or heard in your video, we also process their image, voice and spoken words. We do this only to carry out your request. This includes handing the video over, on your instruction, to the service through which you publish it (Buffer, TikTok, Instagram or YouTube); from then on, that service processes it under its own terms. On our side, we delete them together with the video after 7 days. The legal basis is our legitimate interest in editing the video as you requested (Art. 6(1)(f) GDPR). It is not possible for us to inform these people individually (Art. 14(5)(b) GDPR). We do not analyse voice and face to recognise anyone; no biometric data is created (Art. 9 GDPR). If your video shows other people, you make sure that you are allowed to use it.

If you use Bumely for your business, we process your videos as your processor. We are preparing a template for the agreement on this (Art. 28 GDPR); if you need it, write to us at info@bumely.com.

Speech recognition and post text via Groq (with your consent)

So that the subtitles are right word for word, we send the audio track of your video to our service provider Groq UK Limited, 3 Hammersmith Grove, London W6 0ND, United Kingdom. Groq recognises the spoken words and sends the text back with timings. The picture of your video does not go to Groq. For the suggestion of the post text, the transcript also goes to Groq, automatically for every video after speech recognition and once more when you ask for a new suggestion; an AI language model writes the suggestion.

Before you upload your first video, we ask you once whether you agree. Only after you agree does the Studio upload videos and send audio and transcript to Groq; our server also checks this before it sends anything to Groq. When you agreed and when you withdrew your consent, we store in your Studio on our server in Frankfurt, so that we can prove it. The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time with effect for the future: in the Studio under “Settings” with the switch “Allow sending audio and text to Groq”, or with a short message to info@bumely.com. After that, the Studio cannot create new subtitles for you. What was processed until the withdrawal remains lawful.

Groq works on our behalf. For this, we conclude a data processing agreement under Art. 28 GDPR with Groq; it applies together with Groq’s terms of use. For the United Kingdom, where our contractual partner is based, the EU Commission has determined that an adequate level of data protection exists there (Art. 45 GDPR). Groq processes the data in the USA and can also use data centres in other countries for this. These transfers are safeguarded by the standard contractual clauses of the EU Commission (Art. 46(2)(c) GDPR).

Groq may not use audio and text to train AI models. However, Groq can keep them in logs for troubleshooting and abuse control for up to 30 days and deletes them afterwards.

Publishing via Buffer (optional)

This route continues while we introduce direct publishing to TikTok, Instagram and YouTube step by step (see below). You can connect your own Buffer account to the Studio to schedule finished videos on your channels, for example Instagram, TikTok or YouTube. For this, we store the Buffer key that you paste into the Studio on our server in Frankfurt. If you disconnect Buffer in the Studio or delete your account, we delete it. When scheduling, we pass on to Buffer what is needed for it: the finished video, the post text and the send time. Buffer fetches the video from our server through a link with a random name. We delete the copy made for this after 7 days at the latest. So that nothing is posted twice, the Studio remembers for each scheduled post the file name, the post text, the channel and the send time; we delete this list with your account.

Buffer is a service of Buffer, Inc., 2443 Fillmore Street #380-7163, San Francisco, CA 94115, USA. Buffer is certified under the EU-US Data Privacy Framework; for such companies there is an adequacy decision of the EU Commission (Art. 45 GDPR). For everything Buffer does with your video, your own contract with Buffer and its Privacy Policy apply. The legal basis for passing it on is your request (Art. 6(1)(b) GDPR). Without a connected Buffer account, nothing goes to Buffer.

Publishing to TikTok, Instagram and YouTube (optional)

We are introducing direct publishing to TikTok, Instagram and YouTube step by step. Until a platform is enabled for your account, publishing goes through Buffer (see above). Without a connected account for the platform, nothing goes to it. Connecting is optional: without it, you can download your finished video and upload it yourself, or use Buffer.

When you connect a platform, the Studio redirects you to the platform’s sign-in page. There you see which permissions Bumely requests, and you decide for yourself whether to grant them. When publishing, you confirm in the Studio every time what will appear on which account; if you schedule a publication for later, you confirm it when you schedule it. We do not publish what you do not confirm.

For each connected platform, we store on our server in Frankfurt the access tokens that the platform gives us after your authorisation, your identifier there, where the platform provides one (TikTok, Instagram) and the details we need to match publications to your account. We store the tokens encrypted. They do not go to Sentry or Groq.

We store the tokens only for as long as the connection exists. For TikTok, Instagram and YouTube, we check at least every 7 days whether your authorisation on the platform is still valid. If the platform has ended the access, for example because you revoked it there or the token has expired, we delete the tokens as soon as we notice. What exactly is deleted when you disconnect is described below under “Disconnecting and deleting data”.

TikTok. We request the permissions “user.info.basic” (profile information) and “video.publish” (publish videos to your account) from TikTok. From TikTok we receive your TikTok identifier (“open_id”), your display name and, if we show it in the Studio, your profile picture, as well as an access token and a refresh token. Before each post, the Studio asks TikTok which settings your account offers, for example who may view the video; we do not store this information. After publishing, we store the identifier and the status of the post that TikTok returns.

Instagram. We can publish only to Instagram accounts of the type Business or Creator (professional accounts), not to personal accounts. We request the permissions “instagram_business_basic” and “instagram_business_content_publish”. From Instagram we receive your Instagram identifier, your username and an access token. It expires after 60 days if it is not renewed; as long as the connection exists, we renew it in good time. After publishing, we store the identifier of the post (media container) and the status that Instagram returns. Instagram fetches the video from us itself: for this, the Studio places a copy of the finished video under a link with a random name. The link works without signing in, but the name is random and cannot be guessed. We delete the copy as soon as Instagram has fetched the video, and after 7 days at the latest.

YouTube. Bumely uses YouTube API Services. When you connect YouTube, we request only one permission from Google: to upload videos to your own YouTube channel (youtube.upload). Google’s consent page may describe this permission more broadly, for example as managing your YouTube videos. We use it only for uploading and do not read, change or delete videos that are already on your channel. From Google we receive an access token and a refresh token and, after an upload, the identifier of the uploaded video and the status of the upload. For the upload, we send YouTube the video, the title, the description, the category, the visibility and the information whether the video is made for kids. You choose the title, the description, the visibility and the kids setting for it in the Studio; the Studio sets the category. You explicitly confirm every upload in the Studio, and for a publication that you schedule, when you schedule it. The YouTube connection is separate from signing in with Google: you need it only to upload to YouTube, and you can sign in to the Studio without it. In your Google account, Bumely can therefore appear with both permissions (email address and uploading videos). If you remove the access there, Bumely can no longer publish to YouTube.

When you connect YouTube, the YouTube Terms of Service and the Google Privacy Policy also apply. We use the information from Google only to publish your own video on your own channel. We do not sell it, we do not use it for advertising, and we do not use it to train AI. No one at our company reads it, unless this is necessary to investigate abuse, for security reasons or for legal reasons. Information received from Google APIs is also subject to the Google API Services User Data Policy; Google requires the following statement for this:

Bumely's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

We store the tokens for YouTube only for as long as you have YouTube connected. If you disconnect YouTube in the Studio, delete your account or ask us to delete your YouTube data, we delete the tokens immediately and all other information that we received from YouTube (for example the identifier of an uploaded video and the status of the upload), including the YouTube entries in the log of publications, within 7 days at the latest. Deleting data with us changes nothing on YouTube: videos on your channel stay there. If you have revoked your authorisation with Google, we delete the stored tokens and the information from Google as soon as we notice, and no later than 30 days after the revocation. While the connection exists, we store information that we receive from YouTube (for example the identifier of an uploaded video) for 30 days at most and then delete or refresh it.

When publishing, we pass on to the platform what is needed for it: the finished video, the title or post text, the settings you chose for it (for example who may view the video) and the time of publication. So that nothing is posted twice and you can see the status, the Studio remembers for each post the platform, the file name, the post text, the time, the status and the identifier that the platform returns. We delete each log entry 90 days after the time of publication, and at the latest with your account. Information from YouTube in it we delete or refresh earlier, as described above.

We use the information from the platforms only to publish your video and to manage the connection, for example to renew a token or to show the status of a post. We do not sell it, we show no advertising with it, we do not create profiles about you and we do not train AI with it.

The legal basis for connecting, for storing the tokens and for publishing at your request is providing the Studio that you want to use (Art. 6(1)(b) GDPR). We are responsible for the connection data that we store (tokens, identifiers, log) (see Section 1). As soon as a platform receives data from us or from you, it is itself responsible for its own processing.

Recipients are the platforms on which you publish, and our host for the stored tokens (see Section 2). For TikTok, according to TikTok’s privacy policy, these are TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland, and TikTok Information Technologies UK Limited, Kaleidoscope, 4 Lindsey Street, London EC1A 9HP, United Kingdom. For Instagram, it is the Irish company Meta Platforms Ireland Limited. For YouTube, it is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We transfer data to these companies only on your instruction. For the United Kingdom, the EU Commission has determined that an adequate level of data protection exists (Art. 45 GDPR). What the platform then processes under its own responsibility, and whether it transfers data to third countries, is governed by its privacy policy: TikTok, Instagram, Google. TikTok names servers in the USA, in Malaysia and in Singapore there.

You can disconnect each connection at any time, in the Studio and on the platform itself; the steps are below under “Disconnecting and deleting data”. You can also revoke Bumely’s access to your Google account here: https://security.google.com/settings/security/permissions.

Bumely is an independent product of tayger and is not affiliated with, sponsored or endorsed by TikTok, Meta Platforms, Instagram, Google or YouTube. TikTok, Instagram, YouTube and Google are trademarks of their respective owners.

Disconnecting and deleting data

This applies to Buffer and, as soon as we enable them for your account, to TikTok, Instagram and YouTube. Until then there is nothing to disconnect for these platforms. You can disconnect each connection at any time and have your data deleted, free of charge. There are four ways:

What this does not change: posts that are already published on TikTok, Instagram or YouTube, or scheduled through Buffer, stay there. Delete them on the platform itself. We cannot delete data that the platform itself holds about you; contact the platform for that (links above). Deleted connection data can remain in the backups described in Section 2 until their periods run out: for backups before updates usually 7 days, at the latest until the next update after that; for the host’s automatic backups up to three weeks. Where the platform offers revoking, we do that beforehand, so the tokens in the backups are then invalid. We use the backups only to restore the server after an outage.

Sending to your phone

When you send a finished video to your phone or share it, the Studio creates a link with a random name. It works for 24 hours and then expires.

Notifications on your device (optional)

If you turn on “Notifications” in the settings and your device allows it, your device registers with the push service of its manufacturer: Apple (iPhone, iPad, Safari), Google (Chrome, Android), Mozilla (Firefox) or Microsoft (Edge on Windows). On our server in Frankfurt, we store the delivery address that this service assigns, two technical keys, your language and the time you turned notifications on. When a video is finished, we send a short notification through this service, for example “Your video is ready.” The content is encrypted; the push service sees only the delivery address and the time. The providers are Apple Inc., Google LLC, Mozilla Corporation and Microsoft Corporation, all in the USA. They deliver the notification under their own responsibility.

The legal basis is your consent through the switch (Art. 6(1)(a) GDPR). The subscription on your device is technically necessary for the notification you want (section 25(2) no. 2 TDDDG). You can withdraw your consent at any time in the settings of the Studio or of your device. If you turn off notifications in the Studio or sign out on the device, we delete the delivery address of that device immediately; if the push service no longer delivers to a subscription, we delete it as well. At the latest, this happens with your account.

5. How long we store data

6. Contact

If you write to us by email, call us or write to us on WhatsApp, we process your details to answer your request (Art. 6(1)(b) or (f) GDPR). We delete them as soon as they are no longer needed and no statutory retention obligations stand in the way. With WhatsApp, the provider WhatsApp Ireland Limited also processes your data under its own terms. If you do not want that, please use email or phone instead.

7. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing that is based on our legitimate interest (Art. 21). A message to the address above is enough.

If you have given your consent, for example to speech recognition via Groq, to the “ready” email or to notifications, you can withdraw it at any time with effect for the future (Art. 7(3) GDPR). Without an email address we cannot create an account for you, and without your consent to speech recognition the Studio cannot create subtitles; all other information is voluntary. Bumely cuts and subtitles your videos automatically, but does not make decisions about you that have legal effect or similarly significantly affect you (Art. 22 GDPR).

You can also lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht, BayLDA), Promenade 18, 91522 Ansbach, Germany.

8. Changes

If something changes at Bumely or in the law, we adapt this policy. The version published here always applies.