Deutsch
← Zurück

Datenschutzerklärung

Version 2026-08-01 — derzeit gültig.

Maßgeblich ist die englische Fassung dieser Dokumente; andere Sprachen dienen nur der Verständlichkeit.

Nutzungsbedingungen Datenschutzerklärung Kontakt

What this policy covers

This document explains what data Vistaria collects about you, why, who it is shared with, how long it is kept, and what control you have over it. The controller is the operator of the service published at vistaria.app.

Plainly: we do not sell your data, we do not hand it to third-party advertisers, and we never receive your card details at all.

What we collect

Data you give us:

  • The addresses of the websites you submit for analysis.
  • Your email (web flow) or Telegram ID and username (Telegram flow) — used for sign-in and to deliver results.
  • The brand and business details you enter to personalize generated content.
  • The content of support tickets and messages you send us.

Data collected automatically:

  • IP address, browser type and request time — for security, abuse prevention and rate limiting.
  • Service-usage events (what ran, when, with what result) — for support and improvement.
  • The public content of the website you submit — the same thing a search engine sees.

Data that comes from another service with your permission: for example Google Search Console statistics, or publishing access to Instagram and WordPress — only after you explicitly connect them, and only to the extent that feature needs.

Why we process it

We process personal data to:

  • Perform the contract you signed up for: analysis, reports and content generation, topic delivery, publishing.
  • Manage your account, sign you in securely, and provide support.
  • Bill you, track payments, and meet accounting and tax obligations.
  • Keep the service secure: detect abuse, fraud and malicious automation.
  • Improve service quality, in aggregate and statistical form.

Where the GDPR applies, our legal bases are performance of a contract (the first three), our legitimate interest in a secure and improving service (the last two), and legal obligation for billing records. We do not use your data for unrelated marketing, and you can turn off non-essential notifications at any time.

Use of AI models

To produce analysis and content, part of your data is sent to AI model providers. What is sent is limited to your site's public content, the brand information you entered, and the instruction for that generation — not your email, not payment data, and not your customer lists.

This processing may run on servers outside your country. If you would rather something never travel this path, do not enter it in your brand profile.

Who we share it with

Data is shared only with the processors the service needs to work, and only to that extent:

  • Stripe — to take payment. Card details are entered directly with Stripe and never reach our servers; we receive only the transaction id, amount, status and card metadata.
  • AI model providers — as described above.
  • Email and Telegram delivery — to send sign-in codes, results and notifications.
  • Services you connect yourself (Instagram/Meta, WordPress, Google) — only for that feature.

We may have to disclose data where the law or a competent authority requires it. Beyond that, we do not sell your data and do not give it to advertisers.

International transfers

Vistaria serves customers worldwide and the providers above operate in several countries, so your data may be processed outside the country you live in, including outside the EEA. Where that happens we rely on those providers' own transfer safeguards, and we limit what is sent to what the feature needs.

Cookies and measurement

We use cookies to keep you signed in and to remember simple preferences such as dark mode; without them, signing in is not possible. Traffic measurement, where enabled, is aggregate and exists to tell us which pages are useful.

How long we keep it

  • Account data and generated content: while the account is active, and deleted within 30 days of a deletion request.
  • Payment and invoice records: kept as long as accounting and tax law requires, even after the account is deleted.
  • Technical and security logs: normally up to 12 months.

Security

Traffic runs over encrypted HTTPS, access to operational data is limited to the people who need it, tokens for connected services are stored encrypted, and sign-in is passwordless with one-time codes — so there is no password to leak.

No system is perfectly secure. If a breach puts your data at risk, we will tell you as soon as we can.

Your rights

Depending on where you live — and in full if you are in the EU, the EEA or the UK — you have the right to:

  • Access: ask what data we hold about you.
  • Rectification: correct data that is wrong.
  • Erasure: ask for your account and data to be deleted, except financial records the law requires us to keep.
  • Portability: receive a copy of the content generated for you.
  • Objection and restriction: object to processing based on legitimate interest, or ask us to restrict it.
  • Disconnection: unlink any third-party service you connected; our access ends immediately.

To exercise any of these, contact support or email us; we normally reply within one working week. If you are in the EEA or the UK and are not satisfied, you may also complain to your local data-protection supervisory authority.

Children

The service is built for businesses and is not intended for anyone under 18. If we learn an account belongs to a minor, we delete it.

Changes to this policy

This policy may be updated. The current version is always published here with its date, and after a material change you are asked to accept it again at your next purchase.

Contact

For any question, access request or deletion request, reach us through the channels listed on the contact page.

Fragen zu diesem Dokument oder Löschung Ihrer Daten: Ticket eröffnen · noreply@vistaria.app
Aktuelle Version: 2026-08-01. Wesentliche Änderungen werden als neue Version veröffentlicht und beim nächsten Kauf erneut bestätigt.