How Achtung.app processes data
Last updated 18 August 2026
Read the binding agreement (German, version 1.14)This page explains, in plain English, what Achtung.app does with personal data when you use the service: what we receive, who else sees it, where it is stored, how long we keep it, and what we have deliberately not done.
It is an overview, not a contract. The binding agreement is the German Auftragsverarbeitungsvertrag (data processing agreement under Art. 28 GDPR). It is published in full and takes precedence over anything summarised here.
Who is responsible for what
For the data you put into the service — your brands, keywords, competitors, reports and the user accounts on your team — you are the controller and we act as your processor. We use that data only to run the service and only on your instructions.
For a smaller set of processing we are the controller in our own right, and it sits outside the data processing agreement: billing and tax records, our own server and security logs, defending legal claims, and the aggregated, anonymised industry benchmarks described in our terms.
If you are an agency using Achtung.app for a client, you can enter into the agreement as a processor yourself; the contract covers that case explicitly.
What we process for you
| Category | Examples |
|---|---|
| Account details of your users | Name, email address, role, language, team membership |
| Credentials | Password hash, session identifier, linked SSO identity |
| Usage data in your account | Audit log entries with timestamp, IP address and user agent |
| Your content | Brand name, domain, keywords, competitors, notes, description fields, generated reports |
| Linked accounts | OAuth tokens and metrics from Google Search Console and Google Analytics 4, if you connect them |
Special categories of data under Art. 9 GDPR and criminal-offence data under Art. 10 must not be entered into the service.
Who else receives it
To measure how AI assistants and search engines talk about a brand, we send the brand name, domain, keywords, competitor names and any free-text details you store to the providers below. We never send them your contact details, credentials, IP addresses or payment data.
| Company | Service | Role | Safeguard |
|---|---|---|---|
| OpenAI Ireland Ltd., Ireland | OpenAI API | Processor | DPA for API customers; onward transfers on SCCs or an adequacy decision. We set store: false, so no retrievable application state is kept |
| Google Cloud EMEA Limited, Dublin, Ireland | Gemini Developer API | Processor | Google-as-processor DPA; prompts and responses are not used to improve the product |
| Anthropic Ireland, Limited, Ireland | Anthropic Messages API | Processor | DPA incorporated into the commercial terms, with SCCs, under Irish law |
| Perplexity AI, Inc., USA | Perplexity API | Processor | DPA part of the API terms; certified under the EU-US Data Privacy Framework, with SCCs as a fallback |
| X.AI LLC, USA | xAI API (Pro and Enterprise plans only) | Processor | DPA incorporating SCCs, under Irish law |
| Mistral AI SAS, France | Mistral API (Pro and Enterprise plans only) | Processor | GDPR-based DPA; stored in the EU by default, with temporary third-country transfers not ruled out depending on the feature |
| Brave Software, Inc., USA | Brave Search API | See the note below | DPA available; Brave does not treat search queries as processed on our behalf |
| STRATO AG, Berlin | Servers and data centre | Processor | Processing in Germany |
| Hetzner Online GmbH, Germany | Storage for the encrypted backups | Processor | Processing in Germany |
| HeiGIT gGmbH, Heidelberg | openrouteservice, catchment-area calculation | Independent controller | We send only a coordinate pair, travel mode and time span — no name, no identifier. Processing in Germany |
Payments run through Stripe Technology Company Limited, Dublin. That is our own contractual relationship rather than processing of your content, so it sits outside the agreement.
We use no external provider for sending email, for file storage during operation, or for web analytics. Those all run on our own infrastructure.
Where it is stored
Your account and measurement data is stored primarily with us in Germany, on servers operated by STRATO AG. The daily backup is encrypted and held at Hetzner Online GmbH, also in Germany, physically separate from the production system. The providers listed above process what we send them under their own terms, in some cases outside Germany.
How long we keep it
| Data | Retention |
|---|---|
| Account details | For the life of the account plus 30 days |
| Audit log | For the life of the account; deleted with the team |
| Visibility scores, sources and reports | For the life of the account plus 90 days |
| Backups | Two months |
Billing records, server logs and support correspondence fall under our own controllership and are covered by the privacy policy, not by the agreement.
How it is protected
Access to the application requires a personal login; passwords are stored only as bcrypt hashes and sessions are encrypted. SSO can be enforced for your team. Administrative server access uses key authentication only, restricted to a fixed list of IP addresses. Data for different customers is separated by tenant, enforced in the application and covered by automated tests. All traffic runs over TLS with HSTS and a content security policy; the database, queue and cache are reachable only from the server itself.
OAuth tokens for the accounts you connect are encrypted with AES-256 at application level, so read access to the database alone does not expose them.
For development and maintenance we use an AI coding tool whose database access is restricted column by column: personal fields are withheld by the database itself, and a filter rejects queries touching them.
Backups are taken daily and kept for two months. A full restore from the offsite encrypted backup was tested on 18 August 2026 and completed in 35 minutes with the data intact. The test is repeated quarterly and each run is recorded in the agreement.
What we have deliberately not done
We publish two decisions rather than leaving them implied.
No disk encryption at rest. The production disk is not encrypted at operating-system level. The disk sits in an access-controlled data centre, the database and cache are reachable only locally, and administrative access is key-based from fixed addresses. Full-disk encryption mainly defends against physical access to the disk while the key is in memory during operation anyway; against the realistic attack paths it does nothing. We judged the remaining risk acceptable and are telling you rather than staying silent about it.
Search queries at Brave. Brave provides a DPA but does not treat search queries as data processed on our behalf, and on standard plans it retains queries for up to 90 days. Zero Data Retention exists only on a custom enterprise plan. We considered both that and switching search provider and judged them out of proportion: only the query itself goes to Brave, with no account, contact or payment data and no identifier, so Brave cannot connect a query to a person. Where a brand is named after a person, that name remains personal data — but searching a name its owner published for exactly that purpose is the point of the service. What must not go into a keyword is anything beyond it: details about private individuals unrelated to the brand, contact details, addresses, identification numbers.
Getting the agreement
The full agreement, including the technical and organisational measures and the complete list of processors, is published in German and can be downloaded as a PDF. It forms part of our terms of service and is concluded together with them, so there is nothing to sign; we record which version was in force when your contract was concluded. If you need a countersigned copy, or if your data protection team needs changes to the wording, write to daten@martinkulawik.de.