Drafts

Privacy Policy

Last updated: 15 September 2026

1. Controller

The controller for the processing of personal data on this website and in the “Drafts” application (https://drafts.social) is:

Arnonym OÜ, a private limited company (OÜ) under Estonian law
Registered office: Tallinn, Estonia
Registry code: 16938498
VAT ID: EE102703498
Managing director: Arno Melicharek
E-mail: hello@arnonym.at
Support for Drafts: drafts@arnonym.at

We have not appointed a data protection officer because the legal conditions for doing so are not met. For any privacy matter, please contact us at the addresses above.

2. Overview

Drafts is a social-media planning tool for hospitality and events businesses. Teams use Drafts to plan, approve and publish Instagram posts. We only process the data required to run the service: your e-mail address for signing in, the content you create in your workspace, and technical log data.

We use no analytics or tracking cookies, run no advertising and sell no data. We do not use your content to promote our own products or to train models.

3. Registration and sign-in

Sign-in is passwordless: you enter your e-mail address and receive a one-time sign-in link (“magic link”). We process your e-mail address, the time of sign-in and the session information set in the process.

To keep you signed in we set strictly necessary session cookies. They are essential to operate the service and require no consent. We set no other cookies.

Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(f) GDPR (legitimate interest in secure access).

4. Data in your workspace

Within your workspace we process the content you and your team create, in particular:

  • posts, titles, captions and hashtags,
  • uploaded or imported images and other media,
  • brand voice settings (tone, language rules, example texts),
  • schedules, publishing status and approval notes,
  • names, e-mail addresses and roles of workspace members.

This data is processed solely to provide the service. Legal basis: Art. 6(1)(b) GDPR.

5. Publishing to Instagram

When you publish a post we transmit the image, caption and hashtags to our publishing provider Outstand (Unified API), which hands them over to Meta’s Instagram Graph API. The connection data of your Instagram account (account identifier, access token) is processed as well.

Meta’s own privacy terms apply in addition to this policy for the processing carried out by Meta. Legal basis: Art. 6(1)(b) GDPR.

6. AI features

Drafts offers AI-assisted features for captions, hashtags and week planning. For these we transmit the required content to Anthropic PBC (Claude API): post titles, captions, hashtags and brand voice settings and — for features that analyse images — the images you select.

Under Anthropic’s API terms this data is not used to train models. Legal basis: Art. 6(1)(b) GDPR (providing the feature you use).

7. Google Drive integration

The Google Drive integration is optional and only takes effect if a workspace admin explicitly connects it.

Drafts' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. https://developers.google.com/terms/api-services-user-data-policy

Legal basis: the processing of Google user data is based on your consent under Art. 6(1)(a) GDPR, given by the workspace admin when connecting the Google account. You can withdraw that consent at any time — via “Disconnect” in the Drafts settings or via the permissions of your Google account. Withdrawal does not affect the lawfulness of processing carried out before it.

Scopes: we request the scope drive.readonly as well as openid email.

What we read: we read only the folder the admin selects — the file list, file names, creation dates and the image bytes of the photos in that folder. We do not read other files in your Google account.

What we store: we copy the images imported from Google Drive into our media storage at Cloudflare Inc. (Cloudflare R2) so that posts can be published. We also store the connected account’s e-mail address for display and an encrypted refresh token.

AI image analysis: when you use an AI feature that analyses an image (for example caption suggestions), we transmit the image imported from Google Drive to Anthropic PBC (Claude API). Under Anthropic’s API terms this data is not used to train models.

No sharing: we do not share Google user data with third parties beyond the processors named in section 9 (“Processors and service providers”) that are needed to provide the service (storage, AI features, publishing). We do not sell this data and do not use it for advertising.

Disconnecting and revocation: the admin can disconnect Google Drive at any time in the Drafts settings. Disconnecting revokes the token and removes unused imported photos. Independently of that, you can withdraw access at any time in your Google account: https://myaccount.google.com/permissions

8. Server logs and error diagnostics

When the application is called up, our hosting provider Vercel Inc. automatically records access logs (server logs). These contain the IP address, the user agent (browser and device identification), the requested path and the time of the request.

If an error occurs, we additionally transmit an error report to Functional Software Inc. dba Sentry (EU data region). Such a report contains the error stack trace, the requested path, the time, the user agent and the IP address.

The purpose is the secure and stable operation of the service and the detection and repair of faults and abuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and stability). This data is deleted after 90 days at the latest.

9. Processors and service providers

We work with carefully selected providers. With these providers data processing agreements under Art. 28 GDPR are in place, or the processing takes place on the basis of their respective data processing terms:

  • Vercel Inc. (USA) — hosting and compute; an EU data-processing addendum is in place.
  • Supabase Inc. (USA; the project is hosted in the EU) — database (Postgres) and authentication.
  • Cloudflare Inc. (USA) — media storage (Cloudflare R2).
  • Functional Software Inc. dba Sentry (USA; EU data region) — error monitoring.
  • Sendinblue SAS dba Brevo (France) — transactional e-mail (sign-in links, invitations).
  • Outstand (USA) — publishing to Instagram; the posts are handed over to Meta Platforms Ireland Ltd. (Ireland) via the Instagram Graph API.
  • Anthropic PBC (USA) — AI features for captions, hashtags and week planning (Claude API).

10. Transfers to third countries

Vercel Inc., Supabase Inc., Cloudflare Inc., Functional Software Inc. dba Sentry, Outstand and Anthropic PBC are based in the United States. Sendinblue SAS dba Brevo is based in France and Meta Platforms Ireland Ltd. in Ireland; for these two no transfer to a third country takes place. Supabase hosts our project in the EU and Sentry processes in the EU data region.

Where personal data is transferred to a third country, we rely on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) and — where the provider is certified — on the adequacy decision for the EU-US Data Privacy Framework (Art. 45 GDPR), in each case supplemented by appropriate technical and organisational measures.

11. Retention

  • Account data: for as long as the account exists.
  • Posts and media: until deleted by the workspace.
  • Log and error data: up to 90 days.
  • Beyond that we retain data only as long as statutory retention obligations require.

12. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to certain processing (Art. 21). You may withdraw any consent given at any time with effect for the future.

To exercise your rights, a message to drafts@arnonym.at is sufficient.

13. Right to lodge a complaint

Under Art. 77 GDPR you have the right to lodge a complaint with a supervisory authority. The competent authority is the Estonian Data Protection Inspectorate:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
https://www.aki.ee

Users in Austria may also contact the Austrian Data Protection Authority:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
https://www.dsb.gv.at

14. Changes to this policy

We update this privacy policy when the service or the legal situation changes. The version published on this page applies; the “last updated” date shows when it was last changed. We inform workspace admins by e-mail about material changes.