Legal

Privacy Policy

Last updated: September 2026

1. Controller

Tiki-Taka Media GmbH, Curschmannstraße 9, 20251 Hamburg, Germany ("we", "us") is the controller within the meaning of Art. 4(7) GDPR for all personal data processed through the CrunchJunkie platform (app.crunchjunkie.io) and the website crunchjunkie.io ("Service"). Contact: hello@crunchjunkie.io We have assessed our processing activities and have determined that, at the current scale of operations, the appointment of a Data Protection Officer is not mandatorily required under Art. 37 GDPR. We keep this assessment under review as the business grows. For all data-protection enquiries, please contact hello@crunchjunkie.io.

2. Data we collect and why

We process personal data for the following purposes and on the following legal bases: 2.1 Account management (Art. 6(1)(b) GDPR — contract performance) We process your name, email address, and (where applicable) a password hash in order to create and maintain your account and provide you with access to the Service. OAuth sign-in (Google) gives us your name, email, and profile picture; we do not receive your social-media password. 2.2 Delivery of the Service (Art. 6(1)(b) GDPR — contract performance) We store the advertising and analytics data you import (ad-account metrics, client names, campaign names, report content) and use it exclusively to render reports and provide the features you have subscribed to. This data originates from the advertising platforms you connect (e.g. Google Ads, Meta, LinkedIn) under OAuth authorisation you have granted. 2.3 Billing and invoicing (Art. 6(1)(b) GDPR — contract, Art. 6(1)(c) GDPR — legal obligation) We pass your payment information to our payment processor Stripe, Inc. We retain invoice-relevant data (plan, amount, date) for 10 years to comply with German commercial-law retention obligations (§ 257 HGB, § 147 AO). 2.4 Service improvement and security (Art. 6(1)(f) GDPR — legitimate interest) We collect page-view data, feature-interaction logs, and error reports. Our legitimate interest is to diagnose bugs, prevent abuse, and improve the product. This data is not used for advertising profiling. 2.5 Direct communication (Art. 6(1)(f) GDPR — legitimate interest, or Art. 6(1)(a) GDPR — consent where required) We send transactional emails (password resets, scheduled report delivery, critical service notices). Promotional emails are only sent with your explicit consent. You may withdraw consent at any time via the unsubscribe link or by emailing hello@crunchjunkie.io. 2.6 AI API keys (Art. 6(1)(b) GDPR — contract performance) If you optionally connect your own AI provider key (e.g. Anthropic, OpenAI, Google), we store that key in encrypted form and use it solely to fulfil AI-feature requests you initiate. We do not use this key for any other purpose.

3. Data sharing and sub-processors

We do not sell your personal data. We share data only with the following categories of recipients: 3.1 Infrastructure sub-processors As required by Art. 28 GDPR, we have concluded Data Processing Agreements with all sub-processors who handle personal data on our behalf. Some sub-processors receive only non-personal data — for example search vendors that receive brand, topic and competitor terms, not information about identifiable people — and for those a DPA is not required. Our sub-processor ledger (Settings → Data & residency, and the exportable Data Location & Subprocessor Report) states, per vendor, whether a DPA is in place and which transfer safeguard applies. Where a vendor publishes none, the ledger says so rather than implying one. The current list: • Vercel Inc. (USA) — Hosting, CDN, serverless function execution (application compute) and file/object storage (uploaded logos and generated report files). Data region: Frankfurt (fra1), EU. Transfer safeguard: EU–US Data Privacy Framework + Standard Contractual Clauses. DPA: vercel.com/legal/dpa • Neon Inc. (USA) — PostgreSQL database. Data region: Frankfurt (eu-central-1), EU. Transfer safeguard: Standard Contractual Clauses. DPA: neon.tech/dpa • Stripe, Inc. (USA) — Payment processing. Transfer safeguard: Standard Contractual Clauses. DPA: stripe.com/legal/dpa • Resend Inc. (USA) — Transactional email delivery. Transfer safeguard: Standard Contractual Clauses. 3.2 AI providers (AI features and AI Visibility scans) When you bring your own AI key, your query and relevant report data are sent to the API endpoint of the provider whose key you have configured (e.g. api.anthropic.com, api.openai.com). You are the controller of that processing; please review that provider's privacy policy and terms separately. When you enable Managed AI, CrunchJunkie runs the AI calls on its own provider keys and therefore engages the following AI sub-processors for the models/features you enable: OpenAI, L.L.C. (USA), Anthropic, PBC (USA), Google LLC (USA), Perplexity AI, Inc. (USA), X.AI LLC (USA), DeepSeek (China), Meta Platforms, Inc. (USA, used for Meta AI visibility scans), SerpAPI, LLC (USA, used to read Google AI Overviews, Google AI Mode and Microsoft Copilot), and Tavily (USA, used for supplementary web-search retrieval in research and content-brief features). For each, the prompt and the resulting AI response are processed to produce your visibility metrics. SerpAPI and Tavily receive only non-personal search terms (brand, topic and competitor keywords). DeepSeek and Meta AI are engaged only if you explicitly enable that model; DeepSeek processes data in China. Transfer safeguards vary by provider and are listed per provider in our sub-processor register (Settings → Data & Location, and the exportable Data Location & Sub-processor report): the EU–US Data Privacy Framework backed by Standard Contractual Clauses for DPF-certified US providers (e.g. OpenAI, Google), Standard Contractual Clauses for others (e.g. Anthropic, Perplexity, xAI), and — for providers that publish no Article 46 transfer mechanism (currently SerpAPI, Tavily, DeepSeek and Meta AI) — our register records that openly rather than asserting a safeguard that does not exist. In all cases CrunchJunkie sends data to AI providers only as a result of your action — configuring a key or enabling Managed AI. Training. CrunchJunkie does not use your content to train any AI or machine-learning model, and we build no models of our own. We engage AI sub-processors through their APIs. For the major providers (OpenAI, Anthropic, Google, Perplexity), data submitted via the API is not used to train their models by default. Some optional providers process API input under their own terms: per their published policies, DeepSeek and Tavily may use submitted input to train or improve their models — each is engaged only if you explicitly enable the relevant model or feature. When you bring your own key, your provider's API terms govern. Contractual specifics are set out in our DPA and in each provider's DPA. 3.3 Law enforcement We may disclose data if required by a valid legal order, court ruling, or applicable law. We will, where legally permitted, notify you before complying. 3.4 Business transfers If CrunchJunkie is sold, merged, or restructured, your data may transfer to the successor entity under the same privacy commitments.

4. International data transfers

Our primary infrastructure — application compute, file storage and database (Vercel, Neon) — is located in the EU (Frankfurt). Where data is transferred to sub-processors in third countries (primarily the United States, and — only if you explicitly enable the DeepSeek model — China), we rely on: • EU Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914. • The EU–US Data Privacy Framework (DPF) where the sub-processor is certified. Some optional sub-processors publish no Article 46 transfer mechanism; our sub-processor register (Settings → Data & Location) records this per provider rather than implying a safeguard that does not exist, and those providers receive only non-personal search terms or are engaged solely on your explicit opt-in. You may request a copy of the applicable transfer mechanism by emailing hello@crunchjunkie.io.

5. Data retention

• Account and workspace data: retained for the duration of your subscription and deleted or anonymised within 30 days of account deletion. • Ad-metric data you import: retained for up to 36 months, then deleted. • Billing records: retained for 10 years (§ 257 HGB, § 147 AO). • Server logs and error traces: retained for 90 days. • AI API keys: deleted immediately upon removal or account deletion. Where you request deletion before these periods expire, we will honour your request except where a longer retention period is required by law.

6. Cookies and tracking

CrunchJunkie uses cookies and similar storage technologies in three categories: • Strictly necessary: sign-in, security and remembering your cookie choice. These are required for the site to function and need no consent. • Analytics: Google Analytics, set only with your consent, to understand how the website and product are used. • Advertising measurement: cookies from Google Ads, Meta, Reddit and OpenAI (ChatGPT Ads), set only with your consent, to measure whether our own advertising campaigns on those platforms work. We do not run third-party ad networks on this site, and we do not sell personal data. The complete, always-current list of cookies — names, vendors, lifetimes and purposes — is shown in the table below. It is generated from the same registry that drives our consent banner, so it cannot drift from what the site actually sets. Consent is requested before any non-essential cookie is set, and server-side events (Conversions APIs) are gated on the same consent. You can change or withdraw your choice at any time via “Cookie settings” in the footer. We honour the Global Privacy Control signal by pre-setting advertising to off. A record of each consent (a random identifier, the choices, and the policy version — never your IP address) is kept for five years as required by Art. 7(1) GDPR, then deleted automatically.

7. Security and technical/organisational measures

We implement the following technical and organisational measures (TOMs) in accordance with Art. 32 GDPR: • Encryption in transit: all connections use TLS 1.2 or higher (HSTS enforced). • Encryption at rest: AI API keys and OAuth access/refresh tokens are encrypted with AES-256-GCM at the application layer before storage; the database itself is additionally encrypted at rest by our infrastructure provider. Passwords are hashed with bcrypt (cost factor 12) and never stored in plain text. • Tenant isolation: all database queries are scoped to the authenticated team ID at the application layer; cross-tenant data access is architecturally prevented. • Access control: production database access is restricted to a minimal set of authorised personnel; multi-factor authentication is required; access is logged and reviewed. • Rate limiting: authentication endpoints and critical API routes are rate-limited per IP to prevent brute-force and credential-stuffing attacks. • Incident response: a documented process is in place to detect, assess, and notify data breaches within 72 hours of discovery in accordance with Art. 33 GDPR. A detailed description of our TOMs is available in our Data Processing Agreement (see /legal/dpa).

8. Your rights

Under GDPR you have the following rights, exercisable at any time by emailing hello@crunchjunkie.io: • Access (Art. 15): obtain a copy of the personal data we hold about you. • Rectification (Art. 16): ask us to correct inaccurate or incomplete data. • Erasure (Art. 17): ask us to delete your data ("right to be forgotten") where no overriding legal basis applies. • Restriction of processing (Art. 18): ask us to restrict how we process your data while a dispute is resolved. • Data portability (Art. 20): receive your data in a structured, machine-readable format. • Objection (Art. 21): object to processing based on legitimate interest; we will stop unless we demonstrate compelling grounds. • Withdrawal of consent (Art. 7(3)): where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing. We respond to all verifiable requests within 30 days (extendable by 2 months for complex requests, with notice). You also have the right to lodge a complaint with your local supervisory authority. In Germany, the federal supervisory authority is: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) Husarenstraße 30, 53117 Bonn www.bfdi.bund.de

9. Automated decision-making

We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on you within the meaning of Art. 22 GDPR.

10. Links to third-party services

The Service integrates with third-party advertising and analytics platforms (Google Ads, Meta, LinkedIn, TikTok, etc.). When you connect these platforms via OAuth, their own privacy policies govern the data held within their systems. We are not responsible for their data-processing practices.

11. Google user data — Limited Use

When you connect a Google account (Google Ads, Google Analytics 4, or Google Search Console), CrunchJunkie requests read-only access to your own advertising and analytics data via Google APIs in order to display those metrics back to you inside the reports and dashboards you build. CrunchJunkie's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Specifically: • We only access the Google user data needed to provide and improve the reporting features you have requested. • We do not sell Google user data, and we do not use it for advertising. • We do not transfer Google user data to third parties except as necessary to provide or improve the Service (our sub-processors listed in section 3), to comply with applicable law, or as part of a merger/acquisition under equivalent commitments. • We do not allow humans to read your Google user data unless we have your affirmative agreement for specific data, it is necessary for security purposes (e.g. investigating abuse), to comply with applicable law, or the data is aggregated and anonymised for internal operations. • OAuth tokens are stored encrypted, used solely to fulfil the features you initiate, and can be revoked at any time from your Google Account settings or by disconnecting the integration in CrunchJunkie.

11a. Brand Ambassador Programme

If you apply to or take part in our Brand Ambassador Programme (governed by the separate Programme Terms), we process personal data about you as a programme participant — distinct from any data we process about you as a customer. This includes: the details you submit in your application (your name, email, website, the audience and channels through which you promote, your follower ranges, promotion methods and any message you provide); your ambassador account and referral link; the payout details you give us in order to be paid your commission; and records of the referrals attributed to you and the commission calculated. The legal basis is the performance of the ambassador agreement (Art. 6(1)(b) GDPR) and our legitimate interest in operating the programme and preventing fraud (Art. 6(1)(f) GDPR). We keep this data for as long as you participate and thereafter for as long as required for tax, accounting and legal purposes. We do not disclose a referred customer's identity to you: your portal and the programme emails show only an opaque referral reference and subscription status, never the customer's name. Referral attribution uses the first-party "cj_ref" cookie described in section 6 and in the cookie table below.

12. Changes to this policy

We may update this policy as our Service evolves or legal requirements change. Material changes will be communicated by email or in-app notice at least 14 days before taking effect. The "last updated" date at the top of this page indicates when the most recent revision was made. Continued use of the Service after the effective date constitutes acknowledgement of the updated policy.

Cookie inventory

CookieCategoryVendorDurationPurpose
cj-consentNecessaryCrunchJunkie12 monthsStores your cookie choices so we do not ask again on every visit.
cj_refNecessaryCrunchJunkie90 daysRemembers which ambassador or referral link brought you here (last-touch, 90 days), so a referral discount applies at checkout and the referrer is credited.
cj_currencyNecessaryCrunchJunkie30 daysRemembers whether prices are shown in EUR or USD (detected from your country, changeable any time). No tracking — the value is just the currency.
__Secure-authjs.session-tokenNecessaryCrunchJunkieSessionKeeps you signed in to the app.
__Host-authjs.csrf-tokenNecessaryCrunchJunkieSessionProtects forms against cross-site request forgery.
__Secure-authjs.callback-urlNecessaryCrunchJunkieSessionRemembers where to return you after signing in.
_ga*AnalyticsGoogle Analytics 4Up to 24 monthsDistinguishes visitors so we can understand how the site and product are used.
_gcl_*AdvertisingGoogle AdsUp to 90 daysMeasures which Google ad brought you here so we can attribute conversions.
_fbpAdvertisingMeta90 daysMeta pixel identifier used to measure our Facebook/Instagram campaigns.
IDEAdvertisingGoogle (DoubleClick)13 monthsSet by Google's ad services after consent to measure ad conversions.
_rdt_uuidAdvertisingReddit90 daysReddit pixel identifier used to measure our Reddit campaigns.
oai*AdvertisingOpenAIUp to 13 monthsOpenAI (ChatGPT Ads) identifiers used to measure our ChatGPT Ads campaigns.
__obrefAdvertisingOpenAI12 monthsStores the ChatGPT Ads click reference so a sign-up can be attributed to the ad that brought you here.