Privacy Policy
Last updated: 2. Juli 2026
This privacy policy explains how personal data is processed when you use Vistova (vistova.de).
1. Controller
Timm Ehlbeck, Willy-Brandt-Allee 31, 23554 Lübeck, Germany.
Email: info@timmehlbeck.de · Phone: +49 15120137619.
2. General
We process personal data only in accordance with the GDPR. Depending on the purpose, the legal basis is Art. 6(1)(a) (consent), (b) (contract) or (f) (legitimate interest).
3. Hosting
Vistova runs on servers located within the EU (Germany). When you access the service, technically necessary server logs (IP address, timestamp, requested resource, user agent) are processed for delivery and IT security (Art. 6(1)(f)).
4. Account and contract data
To provide the service we process registration and account data (name, email, organization, role) as well as the projects, brands and prompts you create. The legal basis is performance of the contract (Art. 6(1)(b)).
5. Web analytics (own, cookieless tracking)
On our public pages we use our own privacy-friendly analytics. We record page views, referrer and a pseudonymous visitor/session identifier stored in your browser's local storage. We do not build cross-site profiles and do not sell data. The legal basis is our legitimate interest in measuring reach (Art. 6(1)(f)).
6. Cookies and local storage
We use:
- a technically necessary session cookie for login,
- a token cookie for API access when Google Search Console is connected,
- browser local storage for settings (e.g. active project) and the pseudonymous analytics IDs.
7. Processing of content for SEO/AI features
For the SEO and GEO features, content you enter (e.g. domains, keywords, prompts) is transmitted to external services to deliver the respective feature: OpenAI, Perplexity, Google (Gemini) and Serper (SERP data). The legal basis is performance of the contract (Art. 6(1)(b)).
8. Google user data (Google Search Console)
If you connect your Google Search Console, Vistova accesses your Search Console performance data read-only (scope "webmasters.readonly") with your explicit authorization via OAuth 2.0, solely to display it to you within Vistova.
Vistova's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. This data is not used for advertising, not sold to third parties, and processed only to provide the feature.
You can revoke the connection at any time — in Vistova by disconnecting the integration and in your Google account under "Security → Third-party access".
9. Payments
For paid plans we use Stripe. Payment data is processed directly by Stripe; we do not store full payment credentials. The legal basis is performance of the contract (Art. 6(1)(b)).
10. Email communication
We send system- and contract-related emails (e.g. invitations, notifications, digests). The legal basis is performance of the contract or our legitimate interest (Art. 6(1)(b)/(f)).
11. Recipients / processors
To provide the service we use carefully selected providers, including: hosting (EU), OpenAI, Perplexity, Google, Serper, Stripe and our email delivery provider. Data processing agreements are in place where required.
12. Transfers to third countries
Some services (e.g. OpenAI, Google) also process data in the USA. Transfers are based on appropriate safeguards (EU Standard Contractual Clauses) or an adequacy decision.
13. Retention
We retain personal data only as long as necessary for the stated purposes or as required by law. Raw analytics data is deleted after at most 365 days.
14. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21). You may withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority (Art. 77).
To exercise your rights, simply email info@timmehlbeck.de.