appfellas Social

Privacy Policy

Last updated: October 8, 2026

1. Controller

Codefellas GmbH, Mühlenhagen 130, 20539 Hamburg, Germany
Managing directors: Birger Krah, Daniel Sosa
Email: mail@codefellas.io · Phone: +49 (0)40 228 512 74 0

2. Scope

This policy covers the website appfellas.io and the application appfellas Social at social.appfellas.io (the "App"). The App is an internal tool used by the appfellas team of Codefellas GmbH to schedule and publish content to the official social media accounts of our own apps.

3. Data we process

The website appfellas.io uses no cookies, tracking or third-party resources. The App only uses cookies strictly necessary for login.

4. Purposes and legal basis

We process this data only to provide the App's functionality: authenticating team members, publishing scheduled content to the connected accounts and displaying post metrics. Legal basis is Art. 6(1)(b) GDPR (employment relationship with team members) and Art. 6(1)(f) GDPR (legitimate interest in efficient management of our own social media accounts and secure operation). We do not sell data, do not use it for advertising and do not share it with third parties except as described below.

5. Recipients

6. Platform-specific information

Meta (Facebook, Instagram, Threads): We access only the pages and accounts you explicitly authorize, to publish content and read post metrics. See the Meta Privacy Policy.

YouTube / Google: The App uses YouTube API Services to upload videos and read channel and video information. By connecting a YouTube channel you agree to the YouTube Terms of Service; Google's handling of data is described in the Google Privacy Policy. You can revoke access at any time via Google security settings. The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

TikTok, LinkedIn, X, Pinterest: We use the official APIs of these platforms solely to publish content and read post metrics for the accounts you connect. Their own privacy policies apply to data processed on their platforms.

7. Retention

Access tokens and account data of a connected social media account are stored until the account is disconnected in the App and deleted within 30 days afterwards. Team user accounts are deleted when access ends. Server logs are deleted after 14 days.

8. Data deletion

To delete data stored about a connected social media account:

  1. Disconnect the account in the App, or email mail@codefellas.io with the subject "Data deletion request appfellas Social" and the name of the account.
  2. Optionally revoke the App's access directly on the platform (e.g. Facebook: Settings → Apps and Websites; Google: security settings; TikTok/LinkedIn/X: connected apps settings).

We delete all data related to the account within 30 days and confirm the deletion by email.

9. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Contact us at the address above. You may also lodge a complaint with a supervisory authority, e.g. the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).

10. Changes

We update this policy when the App or legal requirements change. The current version is always available on this page.