This policy explains what personal data 60 Minute Creator collects, why, who receives it, and what rights you have. It is written to describe exactly what the product actually does, nothing more and nothing less.
Controller (the party responsible for your data):
60 Minute Creator, operated by Daniil Tiggemann and Samuel Naesen
Avenida São João de Deus 5, Lisbon, Portugal
Email: contact@60minutecreator.com
This policy covers the marketing site at 60minutecreator.com and the application at app.60minutecreator.com.
A quick orientation:
- No analytics data is stored on your device until you allow it. Personal analytics and session replay are strict opt-ins, each behind the cookie banner on 60minutecreator.com; that one choice covers both the marketing site and the app. Without your opt-in we only count page visits in a cookieless, anonymous way: no analytics cookies or storage, and no identifier linking one page view to another (Section 1.6). Essential cookies (keeping you signed in, remembering your cookie choice) work without consent because the service cannot function without them. Separately, if you reach our site through an affiliate's referral link, one first-party referral cookie is set so we can credit the affiliate (Section 3).
- AI generation runs on provider accounts you own. Your prompts and media go to an AI provider only when you run a workflow, only to the provider you chose, and under your own API key.
- We never train AI models on your content, and we never sell your data.
1. What data we process, and why
1.1 Account data
When you sign up, our authentication provider (a specialized, US-based identity service) collects your email address, your name, and your login credentials. Credentials are handled entirely by that provider; we never see your password. We store your email, name, and an internal account ID in our database.
Purpose: creating and securing your account, signing you in. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).
1.2 Billing data
Payments are processed by Stripe. Stripe collects your card details; we never see or store your full card number. We store your subscription status, plan, billing period, and Stripe customer reference, and we pass your email and name to Stripe when creating your customer record.
To prevent repeated use of the one-time free trial, we store a card fingerprint (a token Stripe derives from the card, not the card number) when a trial starts, and check it against previous trials. See Section 7 on how long we keep this.
Purpose: billing and subscription management; trial-abuse prevention. Legal basis: performance of contract; legal obligations (tax and accounting records); legitimate interest in preventing trial fraud (Art. 6(1)(f)).
1.3 Your content
Workflows, prompts, uploaded and generated media, influencer reference images, and workflow run history are stored so the product can function. Primary storage is in the EU: media files in EU-region object storage, everything else in our EU-hosted Postgres database. Separately from storage, content is processed outside the EU while workflows execute; Section 1.5 describes this.
Purpose: providing the product. Legal basis: performance of contract.
1.4 Provider API keys
API keys you add for AI providers (fal.ai, Kie AI, OpenRouter) are stored encrypted in a dedicated vault. They are decrypted only in memory at the moment a workflow needs them, every access is recorded in an access log, and they are never written to logs or sent to your browser after saving. Deleting a key removes it immediately.
Purpose: executing your workflows with your providers. Legal basis: performance of contract.
1.5 Workflow execution data
When workflows run, execution state is processed by our workflow orchestration provider in the United States. This includes identifiers (your internal account ID, workflow and run IDs, node status) and can include intermediate node results: prompts, generated text, and links to media involved in the run. Status updates stream to your browser from that provider's service. Your API keys never enter this execution state. Video rendering, compositing, and speech-to-text for caption timing run on our US-based rendering compute provider, which processes the media bytes of the workflows you run. Speech-to-text runs on that provider's machines directly; audio is not sent to any additional transcription service.
Purpose: reliably executing the workflows you start. Legal basis: performance of contract. The transfer status of both providers is stated per category in Section 4.1; for the workflow orchestration provider, GDPR data processing terms are still being completed, and the list says so openly until they are in place.
1.6 Analytics and session replay (only with your consent)
If you opt in via the consent banner, we use a product analytics service to understand how the product is used: page views, product events (for example "workflow created", "workflow run"), your account ID, email, and name. Separately and only with its own opt-in, session replay records how the app's interface responds during your session; all typed input is masked in recordings.
Consent is asked once, in the banner on the marketing site (60minutecreator.com). Your choice is stored in a cookie for our domain as a whole, so it applies to both the marketing site and the app; the app never shows a banner of its own, and until you opt in it treats you as having declined. With your opt-in, the same analytics service records page views on the marketing site and where your visit came from (referrer and campaign parameters in the link you clicked), and the analytics cookie is set for our domain as a whole. Because the same choice covers the app, the source of your first visit can then be linked to your account once you sign in (this tells us which marketing works); without the analytics opt-in no such link is made.
Without your opt-in (or after you withdraw it), we still count page visits, but in a cookieless, anonymous way: no analytics cookies or analytics storage are written to your device, sessions are not recorded, no product events are collected, and no identifier links one page view to the next; each page view is an anonymous count. This aggregate measurement tells us how many people visit and which pages they view, and nothing about any individual. Legal basis: legitimate interest in understanding aggregate usage of our sites (Art. 6(1)(f)); because nothing is stored on or read from your device, the ePrivacy consent rule for cookies does not apply to it. You can object (Section 6).
Two more things we state plainly:
- In the app, analytics traffic is routed through our own domain (path
/sixtyhub) and forwarded to the analytics provider; the marketing site sends directly to the provider. - Our analytics provider is US-based. The transfer is covered by its EU-US Data Privacy Framework certification (see Section 4.1).
Purpose: product improvement and marketing attribution. Legal basis: consent (Art. 6(1)(a)) for identified analytics and replay, withdrawable at any time (Cookie Settings in the site footer, or Settings, Privacy in the app) with effect for the future; legitimate interest for the anonymous aggregate counts described above.
1.7 Error reports
We use an error monitoring service to detect crashes and bugs. When an error occurs, the error details, the app state needed to debug it, and your internal account ID may be captured. We have configured it not to attach default personal metadata (IP address, headers, cookies), and we additionally scrub credential-bearing data before sending. Error data is hosted in Frankfurt, Germany.
Purpose: keeping the service working and secure. Legal basis: legitimate interest in detecting and fixing defects (Art. 6(1)(f)). You may object (Section 6).
1.8 Emails we send
We send service emails through a transactional email delivery provider: workflow completed or failed notifications, usage alerts, trial-ending reminders, and payment-issue notices. These are part of operating the service, and you can switch notification types off in Settings. We do not currently send marketing emails; if we ever introduce them, they will be strictly opt-in.
Purpose: service communication. Legal basis: performance of contract.
1.9 Support requests
If you contact support (in-app or by email), we receive your message and any attachments you include. In-app support tickets also include diagnostics that help us help you: your account ID, subscription tier, app route, browser and viewport details, locale and timezone, recent workflow run summaries, and references to related error reports. Support mail is delivered to our contact@60minutecreator.com inbox via the same email delivery provider.
Purpose: resolving your request. Legal basis: performance of contract; legitimate interest in keeping records of support communication.
1.10 Connected services you authorize
If you connect Google Drive or Dropbox, we store the connected account's email address and encrypted access tokens, and transfer only the files you explicitly import or export. If you connect an AI assistant through our MCP endpoint (for example Claude or Cursor), that assistant can access your account data within the scope you authorized, and what its operator does with it is governed by their terms. You can revoke all of these in Settings at any time.
Purpose: the integrations you request. Legal basis: performance of contract (at your instruction).
1.11 Technical logs and security
Our hosting and content delivery provider processes IP addresses and request metadata to deliver the site, defend against attacks, and enforce rate limits. Sign-in pages include its bot protection challenge. We keep an internal security audit log of sensitive actions (for example when an API key is added, used, or removed).
Purpose: operating and securing the infrastructure. Legal basis: legitimate interest in security and service delivery.
2. AI providers and your prompts
AI generation uses your own accounts with fal.ai, Kie AI, and OpenRouter. When you run a workflow, we transmit the prompts and media that workflow needs to the provider you selected, under your API key, on your instruction. The provider processes that data under its own privacy terms, as your provider:
We recommend reviewing your chosen provider's data and training settings. OpenRouter, for example, offers an account setting that excludes model providers that train on data. We do not send your data to any AI provider you have not connected, and we do not train models on your data ourselves.
3. Cookies and similar technologies
Apart from one case, the marketing site (60minutecreator.com) sets no cookies until you make a choice in its cookie banner; if you decline, the only cookie stored is the one remembering that choice. The exception is our affiliate referral cookie: if you reach the site through an affiliate's referral link, a single first-party cookie records which affiliate referred you, so that a later subscription can be credited to them (see the table below).
Across our sites we use:
| Purpose | Set by | Where | Consent needed? |
|---|---|---|---|
| Keeping you signed in (session cookies) | Our authentication provider | App | No, strictly necessary |
| Short-lived security tokens during OAuth connections | 60 Minute Creator | App | No, strictly necessary |
| Remembering your cookie choice | 60 Minute Creator | Both | No, strictly necessary |
| Product analytics (cookies and local storage; the analytics cookie spans our domain for attribution, see Section 1.6) | Our analytics provider | Both | Yes, off until you opt in |
| Session replay | Our analytics provider | App only | Yes, off until you opt in |
| Affiliate referral (set only if you arrive through an affiliate's referral link; records which affiliate referred you) | Our affiliate-tracking provider | Both | No, first-party; see note below |
The banner on 60minutecreator.com asks once for both the site and the app, lets you accept or reject with equal ease, and separates analytics and session replay as individual preferences. You can change your choice at any time: via Cookie Settings in the site footer, or in the app under Settings, Privacy.
Declining sets no analytics cookies and stores no analytics data on your device (only your choice itself is remembered, listed above). The anonymous, cookieless page counting described in Section 1.6 uses no cookies or similar technologies, which is why it is not listed in the table above.
The affiliate referral cookie is set only when you arrive through an affiliate's referral link. It is first-party, stores a referral identifier so a later subscription can be credited to the affiliate who referred you, does not track you across other websites, and does not change what you pay. Legal basis: our legitimate interest in operating an affiliate referral program (Art. 6(1)(f)). The cookie expires 60 days after your visit. You can object (Section 6), delete it in your browser at any time, or let it expire.
4. Who receives your data
We share personal data only with service providers that help us run the product, with services you yourself connect, and with authorities where the law requires it. We never sell personal data. Our service providers act under data processing agreements; for one of them (our workflow orchestration provider) those terms are still being completed, and Section 4.1 says so openly until they are in place.
- Our sub-processors are disclosed by category in Section 4.1 below, with each category's role, the data involved, location, and transfer safeguard.
- Services you connect (Section 1.10 and Section 2): AI providers under your own key, Google Drive, Dropbox, and AI assistants via MCP. These receive data only at your instruction and act under their own terms.
4.1 Sub-processors by category
These are the categories of service providers (processors) that handle personal data on our behalf. We update this section when providers change, and we disclose the actual provider behind any category on request via contact@60minutecreator.com or through a data access request.
Platform sub-processors
| Category | Purpose | Personal data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Authentication provider | Sign-in and account management | Email, name, login credentials, session data | United States | EU-US Data Privacy Framework; DPA with SCCs |
| Payment processor (Stripe, Inc.) | Billing and subscriptions | Email, name, payment details (card data held by Stripe only), card fingerprint for trial-abuse checks | United States | EU-US Data Privacy Framework; DPA with SCCs |
| Database hosting provider | Managed Postgres database and encrypted key vault | All application data: account, workflows, run history, subscription state, encrypted API keys and tokens | European Union | EU hosting; DPA |
| Hosting, delivery, and media storage provider | Application hosting, content delivery, media file storage, bot protection | IP addresses and request metadata (delivery); uploaded and generated media files (storage, EU region) | Global edge; media stored in the EU region | EU-US Data Privacy Framework; DPA with SCCs |
| Workflow orchestration provider | Durable execution of workflow runs | Account and workflow identifiers, workflow execution state including node results (may include prompts, generated text, and links to media) | United States | GDPR data processing terms being put in place; see note below |
| Rendering compute provider | Video compositing, background removal, speech-to-text for captions | Media files of workflows that use rendering nodes | United States | DPA with SCCs |
| Product analytics provider | Analytics and session replay (identified analytics with consent; replay requires its own separate opt-in; anonymous cookieless page counts otherwise) | With analytics opt-in: account ID, email, name, and product usage events. With the additional replay opt-in: session recordings with inputs masked. Without analytics opt-in: anonymous page view counts with no identifiers | United States | EU-US Data Privacy Framework; DPA |
| Error monitoring provider | Crash and defect detection | Error reports and app state needed for debugging, account ID; default personal metadata (IP, headers, cookies) disabled | Germany (EU data residency) | EU hosting; EU-US Data Privacy Framework for residual organizational data |
| Email delivery provider | Transactional email | Email address, name, notification content, support ticket content and attachments | United States | EU-US Data Privacy Framework; DPA |
| Affiliate program tracking provider | Referral attribution and commission accounting for our affiliate program | A referral identifier; for referred subscribers, subscription details received via Stripe (which may include your email and the plan amount) used to attribute and value the affiliate's commission | United States | GDPR data processing terms being put in place; see note below |
Note on the workflow orchestration provider: it is SOC 2 Type II audited and hosts data in the United States. We are completing GDPR data processing terms (Art. 28 DPA with Standard Contractual Clauses) with it; this row will be updated when countersigned. Until then, the data listed above is what its systems process.
Note on the affiliate program tracking provider: it is US-based and receives subscription-attribution data from Stripe to credit the affiliate who referred you. Payment card details are never shared with it (those stay with Stripe). We are completing GDPR data processing terms (Art. 28 DPA with Standard Contractual Clauses) with it; this row will be updated when in place.
Services that receive data at your instruction
These are not our sub-processors. They receive data only when you connect them and only on your instruction, and they process it under their own terms and your own account with them.
| Service | When it receives data | What it receives |
|---|---|---|
| fal.ai | You run a workflow with a fal.ai node, using your own API key | Prompts and media of that workflow run |
| Kie AI | You run a workflow with a Kie AI node, using your own API key | Prompts and media of that workflow run |
| OpenRouter | You run a workflow with an OpenRouter node, using your own API key | Prompts and media of that workflow run |
| Google Drive | You connect Google Drive and import or export files | The files you pick, plus your connected account email |
| Dropbox | You connect Dropbox and import or export files | The files you pick, plus your connected account email |
| AI assistants via MCP (for example Claude, Cursor) | You authorize the assistant to access your account | Account data within the scope you authorized |
5. International transfers
Your data is primarily stored in the EU (database in the EU, media in EU-region storage, error monitoring in Germany). Some sub-processors process data in the United States. Where that happens, transfers rely on an adequacy decision (the EU-US Data Privacy Framework, for certified providers) or on the European Commission's Standard Contractual Clauses; for the workflow orchestration provider, whose data processing terms are still being completed, the current status is stated openly there. The per-category mechanism is in Section 4.1. Data you send to AI providers or export services you connected is transferred at your instruction to that provider, wherever it operates.
6. Your rights
Under the GDPR you can, at any time:
- access the data we hold about you, and receive a copy;
- rectify inaccurate data (name and email can be changed in account settings);
- erase your data (you can delete your account yourself in account settings, see Section 7);
- restrict processing or object to processing based on legitimate interest, including error monitoring;
- receive your data in a portable format; your media can be downloaded or exported from the app at any time, and you can request a copy of the rest;
- withdraw consent (for analytics and replay: via Cookie Settings in the site footer, or in the app under Settings, Privacy) with effect for the future.
To exercise any right, use the in-app controls or email contact@60minutecreator.com. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in particular the Portuguese supervisory authority CNPD (cnpd.pt) or the authority of the EU country where you live or work.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data, workflows, media | Until you delete your account, subject to the subscription-end row below. Deletion removes your database records and purges your stored media files. |
| Provider API keys and connected accounts | Deleted immediately when you remove them in Settings, and with your account. |
| Content after a subscription ends | If your subscription ends and you do not resubscribe, your stored content becomes scheduled for deletion and we may permanently delete it any time from 30 days after the subscription ends. Deleting your account removes it sooner. |
| Trial card fingerprint | Kept after account deletion to prevent repeat free trials, unlinked from your deleted account but together with the payment processor's customer reference. Retention criterion: for as long as we offer a free trial; when we stop offering trials, these records are deleted. It is never readable in the app and cannot be used to charge you. |
| Workflow run history | Kept with your account, so you can review past runs. Deleted with your account, and covered by the subscription-end row above. |
| Technical logs of AI provider calls | When a workflow runs, we record the technical request we sent to the AI provider you chose and the response we received, so we can investigate failures you report. Credentials are stripped and long values are shortened before storage. Automatically deleted after 90 days. |
| Security audit log | Kept after account deletion in de-identified form (entries are unlinked from your identity). |
| Billing records | Kept as long as tax and accounting law requires. |
| Error reports | Automatically deleted after the error monitoring provider's retention window, currently 90 days. |
| Session recordings (consent-only) | Automatically deleted by the analytics provider after its retention window, currently one month. |
| Support correspondence | Kept as long as needed to handle the request and for a reasonable follow-up period. |
8. Automated decisions
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. One automated check exists that we want you to know about: when a free trial starts, the card fingerprint check (Section 1.2) automatically ends the trial if the card was already used for a previous trial, and regular paid billing applies. If you believe this was applied to you in error, contact us and a human will review the decision.
Generating content with AI at your request is not an automated decision about you; you control the prompts and what you do with the results.
9. Security
Traffic is encrypted in transit (TLS). Provider API keys and OAuth tokens are stored encrypted in a dedicated vault and decrypted only in memory when needed, with every access logged. Every database table enforces row-level security so your data is isolated from other users at the database layer. Media buckets are private; files are served only through short-lived signed links. Database connections are TLS-enforced and access is restricted to dedicated roles.
No system is perfectly secure. If a breach affects your personal data, we will notify the supervisory authority and affected users where and as the GDPR requires (Articles 33 and 34).
10. Children
The Service is for adults. You must be 18 or older to use it, and we do not knowingly process children's data. If you believe a minor has created an account, contact us and we will delete it.
11. Changes to this policy
When we change this policy, we update the date at the top. For material changes we notify you by email or in the app before they take effect. The current version is always at 60minutecreator.com/privacy.
12. Contact
60 Minute Creator, operated by Daniil Tiggemann and Samuel Naesen Avenida São João de Deus 5, Lisbon, Portugal contact@60minutecreator.com