Pallas
Legal
Deutsch

Privacy Policy

Last updated 22 September 2026

This page covers you as a Pallas user. Are you a creator who showed up in Pallas? Your notice, and a one-minute way to remove yourself, is at /creators.

01At a glance

  • We keep your email, your searches and their results so Pallas works. Nothing else about you.
  • No analytics, no advertising, no tracking cookies. The only cookies keep you signed in.
  • Payments go through Polar as the seller. We never see your card.
  • Your product page and public creator data go to language models to build the ranking. They are not used to train those models.
  • Data is stored in Frankfurt. Some service providers are in the USA; section 11 says how that is covered.

02Controller

Centaurio UG (haftungsbeschränkt), Dr.-Rohmer-Weg 11, 65719 Hofheim am Taunus, Germany, represented by the Managing Director Valentin Weinert. Email support@kairocalories.com, phone +49 152 24697434. We are not required to appoint a data protection officer (§ 38 BDSG).

03Your account

You sign in with Google or with a link we email you. We store:

  • Your email address and, if Google sends it, your name
  • Your plan, your search credits and the history of credits bought and used
  • The time you signed up and last signed in (kept by the sign-in service)

Sign-in runs on Supabase Auth. If you choose Google, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) confirms who you are and sends us your email address and name; for that step Google is its own controller (policies.google.com/privacy). We store no passwords.

Legal basis: Art. 6(1)(b) GDPR (performing our contract with you).

04Your searches

When you run a search we store:

  • The product link you entered, your budget, your goal and the markets you chose
  • The product profile we build from that page (what it is, where it sells, which creators fit)
  • The results: ranked creators, the reasons, estimated prices, draft messages, and the creators we excluded with the reason
  • What you add: contacted marks, notes and your do-not-contact list

The product profile is shared across users: if someone else searches the same link within 30 days, we reuse it. It holds facts about the product, never about you. A CSV you download is on your device; what you do with it is up to you (terms, section 7).

Legal basis: Art. 6(1)(b) GDPR.

05Payments

Plans are sold by Polar Software, Inc. (3500 South DuPont Highway, Dover, DE 19901, USA) as merchant of record. Polar collects your payment details, billing address and tax information, charges VAT or sales tax and issues the invoice, as its own controller (polar.sh/legal/privacy-policy). Card data is handled by Polar's payment processor Stripe; we never see it.

Polar tells us what we need to give you your searches: an order or subscription ID, the product, the amount and currency, the subscription status and period, and the email you paid with. We keep these records with your credit history.

Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR with § 147 AO for records we must keep for tax purposes.

06Language models (AI)

Pallas uses language models for three steps. We tell you which, in line with the transparency rules of the EU AI Act (Regulation (EU) 2024/1689):

  • Reading your product page and writing the product profile: a model from Anthropic receives the text of the page.
  • Scoring creators and checking brand safety: models from OpenAI receive public creator data (bio, captions, comment texts, numbers) and your product profile.
  • Matching creators to your product: an OpenAI embedding model turns the same texts into numbers.

We reach both through the Vercel AI Gateway, which may serve the same model from another host (for example Amazon Web Services for Anthropic models). We set the gateway to use only hosts that do not train on prompts. Your email and account data are never part of these requests. According to their commercial terms, OpenAI and Anthropic do not train models on this data; OpenAI keeps abuse-monitoring logs for up to 30 days, Anthropic deletes inputs within 30 days. The draft messages follow a fixed template we wrote; the model fills in one reference to the creator's content.

Model output can be wrong. Scores, reasons, prices and markets are estimates for you to check, not facts, and Pallas makes no decision about you with legal or similar effect (Art. 22 GDPR).

Legal basis: Art. 6(1)(b) GDPR (the search is what you ordered).

07Security and abuse protection

Bot check

When your browser starts a search, reads a product link or sends a creator opt-out, Vercel BotID runs a check in the browser and attaches its result to the request, so scripts cannot burn through searches. It reads technical browser signals, not your identity. This is strictly necessary for the service you request (§ 25(2) no. 2 TDDDG); legal basis for the processing is our legitimate interest in protecting Pallas and its costs (Art. 6(1)(f) GDPR).

Rate limits

We count requests per IP address and per account in Upstash, to stop scripts and mass sign-ups. The counters expire after at most two hours. Legal basis: Art. 6(1)(f) GDPR.

Error reports

When something breaks, Sentry receives the error message, the stack trace, browser and device type and the ID of the search. We turned off session recording, performance tracing and the sending of IP addresses and cookies. Reports are stored in Sentry's EU region and deleted after at most 90 days. Legal basis: Art. 6(1)(f) GDPR (a working service).

08Website, hosting and cookies

Pallas runs on Vercel, with functions in Frankfurt. Every request is processed by Vercel and logged with IP address, time, URL, status, referrer and browser; Vercel keeps these logs for a short time. Legal basis: Art. 6(1)(f) GDPR (delivering and securing the site).

Cookies: when you sign in, Supabase sets cookies starting with sb- that keep you signed in. They are strictly necessary (§ 25(2) no. 2 TDDDG) and end when you sign out. We use no analytics, advertising or tracking cookies, and fonts are served from our own domain.

09Emails

We send you the sign-in link you ask for. Polar sends receipts and subscription emails. We send no newsletter. If you email us, we keep your message and address to answer it and delete them when the matter is closed, at the latest after three years (§ 195 BGB). Legal basis: Art. 6(1)(b) or (f) GDPR.

10Service providers

These providers process data on our behalf, bound by our instructions under Art. 28 GDPR:

  • Vercel Inc. · 440 N Barranca Ave #4133, Covina, CA 91723, USA

    What for
    Hosting, serverless functions, the search workflow, bot check (BotID), AI Gateway
    Data
    Everything the app processes passes through Vercel's servers in Frankfurt (fra1); request logs with IP address
    Where
    USA, functions run in Frankfurt
    Transfer basis
    EU-US Data Privacy Framework, plus Standard Contractual Clauses
    Privacy policy
    vercel.com/legal/privacy-policy
  • Supabase Pte. Ltd. · 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513

    What for
    Database and sign-in (Supabase Auth, sign-in emails)
    Data
    Account, searches, results, credits, creator data
    Where
    Singapore, data stored in Frankfurt (AWS eu-central-1)
    Transfer basis
    EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Privacy policy
    supabase.com/privacy
  • Web Scraping Guy LLC (ScrapeCreators) · Austin, TX, USA

    What for
    Reads public TikTok and Instagram profiles, posts and comments for us
    Data
    Search keywords and creator handles we ask about
    Where
    USA
    Transfer basis
    EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Privacy policy
    scrapecreators.com/privacy
  • OpenAI (OpenAI OpCo, LLC, via the Vercel AI Gateway) · 1455 3rd Street, San Francisco, CA, USA

    What for
    Language models: scoring, brand-safety check, embeddings
    Data
    Public creator data (bio, captions, comment texts, numbers) and your product description; no user account data
    Where
    USA
    Transfer basis
    EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Privacy policy
    openai.com/policies/eu-privacy-policy
  • Anthropic (Anthropic PBC, via the Vercel AI Gateway) · 548 Market St, PMB 90375, San Francisco, CA 94104, USA

    What for
    Language model: reads your product page and writes the product profile
    Data
    Text of the product page you entered; no creator or account data
    Where
    USA
    Transfer basis
    EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Privacy policy
    anthropic.com/legal/privacy
  • SideGuide Technologies, Inc. (Firecrawl) · USA

    What for
    Fetches product pages that need a browser to render
    Data
    The product URL you entered
    Where
    USA
    Transfer basis
    EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
    Privacy policy
    firecrawl.dev/privacy-policy
  • Upstash, Inc. · 6202 Vía De Adrianna, San Jose, CA 95120, USA

    What for
    Rate limits
    Data
    IP address and user ID as counters, expired after at most two hours
    Where
    USA, data stored in Frankfurt
    Transfer basis
    EU-US Data Privacy Framework, plus Standard Contractual Clauses
    Privacy policy
    upstash.com/trust/privacy.pdf
  • Functional Software, Inc. (Sentry) · 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA

    What for
    Error reports
    Data
    Error message, stack trace, browser and device type, the search ID; can contain a creator handle. No session recording
    Where
    USA, data stored in Frankfurt (EU region)
    Transfer basis
    EU-US Data Privacy Framework, plus Standard Contractual Clauses
    Privacy policy
    sentry.io/privacy/

OpenAI and Anthropic are reached through the Vercel AI Gateway and work as Vercel's sub-processors. Polar and Google (for Google sign-in) act as their own controllers, as described above.

11Transfers outside the EU

Our database and functions are in Frankfurt, but several providers are companies in the USA or Singapore that can access the data. For providers certified under the EU-US Data Privacy Framework (Vercel, Upstash, Sentry), the transfer relies on the adequacy decision of 10 July 2023 (Art. 45 GDPR); you can check their status at dataprivacyframework.gov. For the others, it relies on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR). You can ask us for a copy.

12How long we keep data

  • Account, searches, results and notes: until you delete your account
  • Creator data inside your results: at most 12 months after we last read the creator's profile, or earlier if the creator removes themselves
  • Purchase and credit records: 10 years where tax law requires it (§ 147 AO), otherwise with your account
  • Working data of a running search: deleted when the search ends, at the latest after 7 days
  • Rate-limit counters: at most two hours. Error reports: at most 90 days. Server logs: as long as Vercel keeps them, a short time
  • Emails with us: until the matter is closed, at most three years

13Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21 GDPR). Where you gave consent, you can withdraw it at any time with effect for the future (Art. 7(3)). An email to support@kairocalories.com is enough, including to delete your account. We answer within one month.

You can also complain to a data protection supervisory authority. Ours is The Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany, datenschutz.hessen.de.

14Age

Pallas is for businesses and people aged 18 or over. If you learn that a minor gave us data, write to us and we delete it.

15Changes

We update this page when Pallas, our providers or the law change. The date at the top shows the last update. For changes that affect you, we email you.