Trust center
Updated: 2026-10-01
In short and in the open: where your data lives, who processes it, how we protect your account and how we use artificial intelligence. The binding details are in the Privacy Policy and the Data Processing Agreement (DPA).
Where data is processed
- Database: Neon (Postgres), EU region.
- Application: Vercel, server functions run in the EU (Frankfurt, fra1); static assets are served by Vercel's global network.
- AI providers (Anthropic, optionally OpenAI / Google) and some services (Stripe, Resend) may also process data outside the EU – mainly in the USA; such transfers rely on the European Commission's Standard Contractual Clauses (SCCs).
Sub-processors
| Provider | Purpose | Location | When |
|---|---|---|---|
| Vercel Inc. | hosting, file storage (videos) | EU (fra1) / global network | always |
| Neon Inc. | database | EU | always |
| Anthropic PBC | post drafts (Claude) | USA | always |
| OpenAI | voice-note transcription, image generation | USA | if you use it |
| Google (Gemini) | voice-note transcription, image generation | USA / global | if you use it |
| Resend | USA | always | |
| Stripe | payments, invoicing | USA / EU | when you subscribe |
| Postiz | scheduling and publishing | depends on the connected Postiz instance | if you publish via Postiz |
| Meta Platforms Ireland (WhatsApp Business Platform) | messages of the WhatsApp bot | EU / USA | if you use the WhatsApp bot |
Social platforms you publish to (Google – Business Profile too –, Meta – Facebook, Instagram, Threads –, LinkedIn, TikTok, YouTube, Bluesky): we publish to your account on your instruction; the platforms handle the content under their own terms as independent controllers. The same goes for sources and tools you connect – Microsoft 365 (Outlook, OneDrive, Teams), Zoom, Fireflies.ai, Google Meet, Telegram, Unsplash, Pexels, Zapier, Make, AI assistants (Claude, ChatGPT): we only exchange what you switch on, and only when you do. Meeting transcripts are read in memory only, never stored; a stock-photo search only sends the search words.
Security
- Encrypted transport (HTTPS) everywhere; access tokens and keys encrypted at rest (AES-256-GCM).
- Sign-in: Google / Microsoft, password (scrypt hash), passkeys (Face ID / Touch ID), two-factor authentication (TOTP).
- Access control: data isolated per workspace, owner / editor roles, two-step approval, activity log.
- Backups: continuous backups by our database provider; after deletion, data also leaves the backups within 30 days.
- Incidents: we notify you without undue delay, at the latest within 48 hours (DPA).
AI usage policy
- Post drafts are written by Anthropic's Claude, at your request, from your data. Anthropic does not train its models on API data by default.
- From your data we only derive style rules for your own workspace; we don't train any general model with it and no other customer sees them.
- Nothing is published without a person's approval. Every post has a provenance log: what the AI wrote, how much a person changed, who approved it and when – without storing prompts.
- Generated images carry a machine-readable marking (IPTC “trainedAlgorithmicMedia”, XMP). This is metadata, not a signed C2PA credential, and some platforms remove it on upload.
EU AI Act – transparency statement
Article 50 of the AI Act sets transparency obligations from 2 August 2026. AI-generated text published to inform the public has to be disclosed, unless it has undergone human review or editorial control and someone holds editorial responsibility for it.
Sayweek gives you the tools for this: mandatory human approval (lockable), a provenance log and a downloadable compliance report, and optional AI disclosure per brand and channel (a label, the #AIassisted hashtag, or the platform's own label where the API supports it: TikTok, YouTube).
Which rule applies to your content depends on the content and how you use it. This is information, not legal advice – please consult a lawyer.
Your GDPR rights
Access, rectification, erasure, portability (Settings → Data and privacy → Export), objection and withdrawal of consent. You can complain to the data protection authority where you live.
United Arab Emirates (PDPL)
The company operating the service is registered in Dubai. We handle our customers' data to the GDPR standard; for questions on how the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to you, write to us.
Documents
- Privacy Policy
- Terms of Service
- Data Processing Agreement (DPA)
- Sub-processors (full list)
- Security & vulnerability disclosure
- AI & Content Policy
- Cookie Policy
- Data deletion
- Legal notice
Contact
Privacy and security questions, signed DPA: hello@sayweek.com