Legal

Privacy policy

Last updated: 21 August 2026

This policy explains how we process personal data on mantral.app, in connection with contact and appointment requests, and within the Mantral platform.

01

Controller

MANTRAL UG (haftungsbeschränkt)
Am Lindenbaum 11
53639 Königswinter
Germany

Email: info@mantral.app

02

Accessing the website and hosting

When you access our website, technically necessary connection data is processed. This may include the IP address, date and time of access, URL accessed, referrer, browser, device and operating-system information, and status codes. Processing is necessary to deliver the website, defend against attacks and ensure stability.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and economical operation of our digital offering. The website is provided through Netlify. Netlify processes technical access data on our behalf.

We operate the Mantral platform itself (database, authentication, file storage, server functions) with Supabase Inc. in the eu-central-1 region (Frankfurt am Main) on Amazon Web Services infrastructure. Platform customer data is stored there within the EU. Supabase is bound as a processor; EU standard contractual clauses apply to support and emergency access from third countries.

03

Contact form and email

If you contact us through the contact form or by email, we process the information you provide. This includes, in particular, your name, email address, company, website, topic and message. Required fields are marked in the form.

Processing takes place to handle your request and for pre-contractual communication under Article 6(1)(b) GDPR. For general business enquiries, we also rely on Article 6(1)(f) GDPR. Our legitimate interest lies in the structured handling and documentation of incoming enquiries.

Enquiries via the website contact form are received through Netlify Forms. The contact form inside the platform stores your request in our database (Supabase) and sends a confirmation via Resend. We do not use the information for newsletters or promotional messages unless you have expressly consented elsewhere, and we delete enquiries once they have been fully processed and no contractual or statutory retention obligations remain.

04

Demo bookings and onboarding calls

You can request a demo or an onboarding call. We process your name, email address, company, time preferences and any contextual information you provide voluntarily. The legal basis is Article 6(1)(b) GDPR.

For demo bookings, the contact page embeds the Google Calendar booking page (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). The calendar loads only after you actively open it there — before that, your browser establishes no connection to Google. When it loads, Google processes in particular your IP address, browser data and the booking details you enter; this may involve a transfer to the USA. The legal basis for loading it is your consent under Article 6(1)(a) GDPR, which you give by actively opening it and can withdraw at any time with future effect. You can always use the form on this page or email instead.

05

Account, contract and platform use

When you register for and use Mantral, we process in particular account and profile data, company and team assignments, login and security data, contract and plan information, usage and credit entries, and support histories. Processing serves to set up and manage the account, provide the functions booked, handle billing and secure the platform.

If you voluntarily sign in with Google, Google provides us with your verified email address, name, profile image, and a provider identifier. We use this data only for sign-in, account linking, and profile pre-filling. Google Ireland Limited or Google LLC processes the sign-in under its own responsibility; Google's privacy information also applies. The legal basis for our processing is Article 6(1)(b) GDPR.

The legal basis is Article 6(1)(b) GDPR. Security and misuse checks are additionally carried out on the basis of Article 6(1)(f) GDPR. We process data required under commercial and tax law pursuant to Article 6(1)(c) GDPR.

06

Brand, store and marketing data

For analysis and production, Mantral processes data that you provide, connect through approved integrations or instruct us to retrieve. This may include store URLs, publicly accessible website content, brand and product information, uploaded files, campaign and creative data, competitor information, briefs, prompts and generated results.

Please do not submit special categories of personal data under Article 9 GDPR or personal data that is not necessary for the relevant marketing purpose. You are responsible for ensuring that you are authorized to provide content and data.

For competitive and market analyses we also process publicly available third-party information, in particular publicly viewable advertisements, website and shop content, and public customer reviews. Retrieval is carried out via specialized providers; the providers used are listed in the section "Sub-processors and service providers". Where this includes personal data, such as names in ads or reviews, we process it on the basis of Art. 6(1)(f) GDPR to analyze the advertising and market activities of companies; we do not create profiles of natural persons. Individual notification under Art. 14 GDPR is omitted where it proves impossible or would involve disproportionate effort (Art. 14(5)(b) GDPR). Data subjects may object to the processing at any time.

07

AI-supported functions

For analysis, text, image, video and voice functions we transmit the inputs and context required for the specific request to specialized AI providers. Depending on the function these are in particular Google (Gemini) for analyses, texts and images, OpenAI for text and image functions, Perplexity for web research, fal.ai for image and video generation, ElevenLabs for speech synthesis and TopView for avatar videos.

Transmission is limited to the context required. Do not process confidential personal data in prompts, uploads and briefs unless it is strictly necessary for the result. The legal basis for order-related processing is Art. 6(1)(b) GDPR; for quality assurance and abuse prevention Art. 6(1)(f) GDPR.

We use these providers exclusively via their business or API interfaces, whose terms exclude use of the transmitted data for training foundation models. We do not train models with your content either. Where providers process data in the USA, we base the transfer on the EU-US Data Privacy Framework or EU standard contractual clauses.

08

Optional integrations, in particular Meta

You can voluntarily connect Mantral with third-party platforms, such as Meta, shop systems (Shopify, WooCommerce, Shopware), newsletter services (Klaviyo, Brevo, Mailchimp, MailerLite, ActiveCampaign) or publishing systems (WordPress). Only after your decision to connect do we process the required account, object, campaign, performance and access data. Scope and purposes are explained in the respective connection dialog.

You can disconnect integrations within the platform and additionally revoke permissions with the relevant third-party provider. The third party's privacy information applies to its independent processing.

When you optionally connect Meta, we process the Meta user ID, granted permissions, access token and expiry, business and ad account IDs and names, Facebook Pages, and linked Instagram professional accounts. For the features you use, we also process campaign, ad set, ad, creative, status, budget, and performance data such as spend, impressions, clicks, and conversion metrics.

We use this data only to display the Meta assets you select, publish and manage campaigns, ads, stories, or reels on your instruction, and analyze the related performance in Mantral. Publications and changes on Meta are triggered only by a product action you start or schedule; newly created ads are initially created as paused.

We store the connection and its access data until you disconnect it, revoke it at Meta, or submit a confirmed deletion request. When you disconnect, we remove tokens, account, Page, and Instagram bindings, derived Meta caches, and open Meta publish jobs. Meta is responsible for processing data when you authorize and use its APIs.

For more information about processing by Meta, see the Meta Privacy Policy.

09

Payments and contractual communications

We use Stripe for paid plans and payments. Stripe processes the payment and transaction data required for checkout, payment processing, invoicing and fraud prevention. We do not receive complete card details.

Transaction and contract emails may be sent through Resend. The legal bases are Article 6(1)(b) GDPR and, where statutory records are concerned, Article 6(1)(c) GDPR.

10

Error analysis and security

We use Sentry to identify technical errors and secure the platform. Error details, technical device and browser data, IP address, user or account identifiers and interaction data may be processed. In the US sign-in area, Sentry may also capture a masked session recording so we can understand drop-offs and usability problems. Page text and form entries are masked, media is blocked, and recording ends when the visitor leaves this area.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in troubleshooting, system security and the traceability of technical disruptions.

11

Reach measurement

We measure the use of our public pages and the signed-in application to evaluate reach, technical usage and drop-off points. This is a first-party measurement within our platform infrastructure operated by Supabase. We do not use an additional external analytics service for this purpose.

On public pages, this measurement does not set cookies or store an identifier in local storage or session storage. The server derives a pseudonymous visitor value from your IP address, the browser identifier and a secret that changes daily; the raw IP address is not written to the measurement tables. Daily secrets whose calendar date is more than two days in the past are removed by the nightly deletion run. For new sessions, the value changes daily and is not designed to link visits across multiple days. To classify device, browser and country, we process device and runtime information provided by the browser, including the browser identifier and time zone. To exclude your own visits, the measurement reads exactly one voluntary note (“mantral_ignore”) you can set in your browser yourself; visits carrying that note, or made from automated browsers, are not counted as visitors.

For signed-in users, measurement records also contain the account user ID so that in-app usage can be reported as aggregate counts of unique users. Recorded fields include the requested and referring page, campaign parameters, device type, browser, derived country and events; the underlying session and event records, including the user ID, are deleted after no more than 400 days. We rely on Article 6(1)(f) GDPR for this processing; our legitimate interest is a data-minimizing, aggregate analysis of reach and usage. Section 25 TDDDG separately governs storing information in terminal equipment and accessing information stored there. This measurement does not set cookies or store an identifier in browser storage; the legal assessment of the browser and device information used, in particular the browser identifier and time zone, is being conducted separately. Under Article 21(1) GDPR, you may object on grounds relating to your particular situation; we will then continue processing the affected data only if we demonstrate compelling legitimate grounds or need it for legal claims.

With your consent to statistics cookies, we also record interactions in the initial onboarding form directly in MANTRAL to identify usability problems. Form labels, clicks, scrolling and error messages are visible; personal inputs are masked before transmission. Recordings are stored in our Supabase infrastructure and are accessible only to authorized administrators. They remain available for no more than seven days and are then deleted automatically. You can withdraw statistics consent at any time in cookie settings.

12

Advertising conversion measurement

We run ads on Google Ads and on Reddit. To see which ad led to a registration or a paid subscription, we use the conversion measurement of both providers. What is transmitted is only that a particular step was reached, never your content from the platform.

For visitors in the European Economic Area, the United Kingdom and Switzerland, we activate Google and Reddit only after consent to the marketing category. Without consent, no measurement data is sent to these providers and no advertising cookies are set. For confirmed access from the United States, we use conversion measurement unless a privacy choice has been exercised. Enhanced matching through your email address remains off until you expressly allow marketing.

If your browser has Global Privacy Control enabled or you turn off advertising measurement through Your Privacy Choices, both providers remain blocked. This also applies if marketing consent was previously stored. Your choice applies going forward and can be changed at any time through the footer link.

When measurement is allowed, the event, time, address accessed, referrer, and browser, device and network data including your IP address may be transmitted. Only after express marketing consent may a SHA-256 checksum of your email address be created in the browser and sent to Google for enhanced conversions. Your email address itself never leaves your browser in plain text. We do not send an email address to Reddit. Reddit's automatic collection of addresses from form fields is disabled in our advertising account.

13

Cookies and local storage

We use technically necessary cookies and local browser storage for login, security, session control, language settings and essential product functions. Their use is necessary for the service expressly requested.

For visitors in the European Economic Area, the United Kingdom and Switzerland, analytics, convenience or marketing services that require consent are activated only after you consent. You can change your selection at any time through “Cookie settings” in the footer.

14

Recipients and international transfers

We disclose data only where this is necessary for the purposes described, a legal obligation exists or you have consented. Recipients may include hosting, infrastructure, communications, payment, error-analysis, integration and AI service providers.

Where providers process data outside the European Economic Area, we base the transfer on an adequacy decision – for US providers in particular certification under the EU-US Data Privacy Framework – or on appropriate safeguards such as the EU standard contractual clauses. Details on a specific provider are available on request.

15

Sub-processors and service providers

We use the following service providers, which may process personal data on our behalf. Location refers to the provider's registered seat; platform data is processed in the EU where stated.

Supabase Inc. (USA) – database, authentication, file storage, server functions; processing in Frankfurt (EU).
Netlify Inc. (USA) – hosting of the website and web app, website forms.
Stripe Payments Europe Ltd. (Ireland) – payment processing and invoices.
Resend Inc. (USA) – transactional and contract emails.
Functional Software Inc. (Sentry, USA) – error analysis.
Google Ireland Ltd. / Google LLC – AI analysis, text and image generation (Gemini); demo appointment booking (Google Calendar).
OpenAI Ireland Ltd. / OpenAI LLC – AI text and image functions.
Perplexity AI Inc. (USA) – AI-assisted web research.
fal.ai Inc. (USA) – AI image and video generation.
ElevenLabs Inc. (USA) – speech synthesis.
TopView (Singapore) – avatar videos.
Apify Technologies s.r.o. (Czech Republic) – retrieval of public ad and web data.
Firecrawl / SideGuide Technologies Inc. (USA) – retrieval of public website content.

Meta Platforms Ireland Ltd. and the shop, newsletter and publishing providers you connect process data within your integration under their own responsibility. We publish changes to this list here; we announce material changes to customers with a data processing agreement at least 30 days in advance.

16

Retention and deletion

We store personal data only for as long as necessary for the relevant purpose, ongoing contractual relationships, security and statutory documentation or retention obligations. The data is then deleted or anonymized.

Account and project data may be deleted within the product functions provided or deletion may be requested. Invoices and contractual records that must be retained by law remain stored in restricted form until the relevant periods expire.

Specifically: we generally delete server and security logs after 30 days and error reports after 90 days. After an account is deleted we remove account and project data from production systems within 90 days; backups are overwritten in rotation within a further 30 days. We retain invoicing and accounting records for up to ten years under German tax and commercial law (§ 147 AO, § 257 HGB).

17

Your rights

  • Access to your personal data that is being processed
  • Correction of inaccurate data or completion of incomplete data
  • Erasure where no statutory or overriding grounds prevent it
  • Restriction of processing
  • Data portability where the statutory requirements are met
  • Objection to processing based on legitimate interests
  • Withdrawal of consent with effect for the future

To exercise your rights, a message to info@mantral.app is sufficient.

18

Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. The authority responsible in particular for our registered office is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia:

LDI NRW
Kavalleriestraße 2–4
40213 Düsseldorf
www.ldi.nrw.de

19

Changes to this policy

We update this Privacy Policy when functions, service providers or legal requirements change. The version published on this page is authoritative.