Privacy Policy

Privacy policy under the EU GDPR.

1. Data controller

Lorenz Kutschka
twixb
Untere Teichstraße 38a
8010 Graz, Austria
Email: [email protected]

2. Personal data we collect

We collect and process the following data:

  • Email address (when you register)
  • Password in hashed form (when you register with email)
  • Google account ID (if you sign in with Google)
  • Usage data: newsfeeds you create, sources you add, reading activity
  • Business context and keywords (only when you provide them)
  • Email preferences (digest frequency, time zone)

3. Purposes of processing

Your data is processed for the following purposes:

  • Providing and operating the twixb service
  • Sending personalised email digests
  • Personalising content (key learnings based on your business context)
  • Account management and authentication
  • Service-related communication (e.g. password reset, invitations)

4. Legal basis

Processing is based on:

  • Article 6(1)(b) GDPR — performance of a contract: processing is necessary to provide the service.
  • Article 6(1)(a) GDPR — consent: for optional features such as marketing emails and analytics cookies.
  • Article 6(1)(f) GDPR — legitimate interest: to improve and secure the service.

5. Recipients and processors

Your data is transferred to the following third-party providers:

  • Resend (USA) — email delivery (digests, invitations, password resets)
  • Hetzner (Germany) — server hosting and data storage
  • Google (USA) — Google Sign-In (only if you choose it); Google Analytics 4 for web analytics (only with your consent)
  • OpenAI (USA) — analysing source content for relevance and generating key learnings
  • Apify (Czech Republic) — scraping public social-media profiles you add as sources
  • Stripe (Ireland / USA) — payment processing for paid plans
  • Cloudflare (USA) — CDN and edge caching of public pages

6. Transfers to third countries

Some of our processors (Resend, Google, OpenAI, Stripe, Cloudflare) are based in the United States. Transfers are made on the basis of Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR and/or the EU-U.S. Data Privacy Framework.

7. Cookies and web analytics

twixb uses Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) to analyse how the website is used. Google Analytics sets cookies to record and evaluate website usage statistically.

Information generated by these cookies is normally transferred to a Google server in the United States and stored there. We use IP anonymisation, so your IP address is truncated within the EU/EEA before transfer.

Consent (opt-in): Google Analytics is loaded under Google Consent Mode v2. Until you grant consent via the cookie banner, only cookieless pings are sent (no identifiers, truncated IP). You can withdraw your consent at any time by clearing your browser's localStorage or by contacting us at [email protected].

We additionally use Plausible Analytics (Plausible Insights OÜ, Estonia) for privacy-friendly aggregate analytics. Plausible does not use cookies and does not collect personal data.

Legal basis: Article 6(1)(a) GDPR (consent) for Google Analytics; Article 6(1)(f) GDPR (legitimate interest) for cookieless aggregate analytics.

We also store an authentication token (JWT) in your browser's localStorage to keep you signed in. This token is removed when you log out.

Your cookie preference is also stored in localStorage so we can respect your choice on future visits.

8. Retention

Your personal data is retained for the duration of your account. After you delete your account, all associated data is irreversibly deleted within 30 days.

9. Your rights

Under the GDPR you have the following rights:

  • Right of access (Article 15 GDPR) — you can request access to the data we hold about you.
  • Right to rectification (Article 16 GDPR) — you can request correction of inaccurate data.
  • Right to erasure (Article 17 GDPR) — you can request deletion of your data.
  • Right to restriction (Article 18 GDPR) — you can request restriction of processing.
  • Right to data portability (Article 20 GDPR) — you can request your data in a common format.
  • Right to object (Article 21 GDPR) — you can object to the processing of your data.

To exercise your rights, contact us at [email protected].

10. Right to lodge a complaint

You have the right to lodge a complaint with the supervisory authority:

Austrian Data Protection Authority (DSB)
Barichgasse 40-42
1030 Vienna, Austria
www.dsb.gv.at

11. Changes to this policy

We reserve the right to update this privacy policy as needed to reflect changes in the law or in the service. The current version is always available on this page.

Last updated: April 2026