English translation. Provided for your convenience only. Only the German version of this document is legally binding; in the event of any discrepancy or doubt, the German text prevails. Read the German version.
Privacy Policy
Last updated: September 2026
This Privacy Policy informs you about the processing of personal data in connection with the use of the software-as-a-service application "Pilot" (hereinafter the "App"), accessible at app.usepilot.de.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Carovo GmbH
Gesellschaft mit beschränkter Haftung (GmbH)
Am Juliusturm 31
13599 Berlin, Germany
Authorised managing director: Metehan Kartal
Telephone: 030 5858 19080
E-mail: info@usepilot.de
Please address data protection enquiries to: info@usepilot.de
A data protection officer has not been appointed, as there is no statutory obligation to do so.
2. General Information on Data Processing
2.1 We process personal data exclusively on the basis of statutory grounds for permission, in particular
- Art. 6(1)(b) GDPR (performance of a contract and pre-contractual measures),
- Art. 6(1)(c) GDPR (compliance with legal obligations),
- Art. 6(1)(f) GDPR (legitimate interest), and
- Art. 6(1)(a) GDPR (consent), insofar as expressly granted.
2.2 We process your data only to the extent necessary for the purposes set out in this policy. Processing for other purposes does not take place without a corresponding legal basis.
2.3 We employ technical and organisational measures in accordance with the state of the art in order to protect your data (Art. 32 GDPR).
3. Categories of Data Processed
In connection with the use of the App, we process in particular the following categories of personal data:
a) Account and master data
- e-mail address, and where applicable name and profile information,
- login and security information (e.g. one-time login codes, session information),
- language, time zone and display settings,
- in the case of registration via a third-party provider (e.g. Google or Microsoft login): the identifiers transmitted as part of the login procedure.
b) Calendar, task and content data
- appointments and calendar entries with title, description, location, participants and times,
- tasks, projects, notes, pages, focus tasks and work sessions,
- texts entered by you, voice inputs (insofar as you use this function) and the transcripts generated from them, as well as the results of AI-supported processing.
c) Connection data for external calendars
- authorisation/access tokens and scope of permissions of connected calendar or account services (e.g. Google Calendar, Microsoft Outlook), insofar as you authorise the connection.
d) Sharing data
- information as to whether and via which sharing link you have made individual content (e.g. pages) accessible to third parties.
e) Usage, device and log data
- IP address (as a rule only for a short time or in shortened/aggregated form),
- date and time of access,
- browser, device and operating system information, and where applicable the referrer,
- technical error and diagnostic data as well as aggregated usage statistics to ensure stability, security and reach measurement.
f) Billing and contract data
- invoicing and payment information, order and subscription history; the complete payment means data is processed exclusively by the payment service provider (see section 8).
g) Communication data
- content from e-mail, support or feedback communication, insofar as you contact us.
4. Purposes of Processing
We process personal data in particular for the following purposes:
- provision and operation of the App, including the display, synchronisation and editing of calendar, task, note and page content;
- AI-supported functions (see section 6), e.g. assistant, automatic daily planning, suggestions, classification, summaries, evaluation of voice inputs;
- authentication and administration of user accounts, including the connection to external calendar services;
- processing of contracts and payments;
- security, misuse and error analysis, including logging, monitoring, rate limiting and diagnostics;
- reach measurement and improvement of the App on an aggregated, statistical basis;
- compliance with legal obligations (e.g. retention obligations under commercial and tax law);
- communication with you (e.g. support, security and service notifications, onboarding information).
5. Legal Bases for Each Processing Operation
| Processing operation | Legal basis |
|---|---|
| Provision of the App, account, calendar/task/note functions | Art. 6(1)(b) GDPR (performance of a contract) |
| AI-supported processing of user content for the provision of the functions actively used | Art. 6(1)(b) GDPR |
| Processing of special categories of data that may be contained in user content by AI/transcription functions | Art. 9(2)(a) GDPR (explicit consent through active use) |
| Connection of external calendars (e.g. Google, Microsoft) | Art. 6(1)(b) GDPR in conjunction with your explicit authorisation |
| Public sharing of content by you | Art. 6(1)(b) GDPR (through your active use of the sharing function) |
| Security, stability, protection against misuse, logging | Art. 6(1)(f) GDPR (legitimate interest in secure operation) |
| Reach measurement (web analytics) | Art. 6(1)(f) GDPR (legitimate interest in stability, error analysis and product improvement) |
| Billing, accounting | Art. 6(1)(b) and (1)(c) GDPR |
| Onboarding/service e-mails | Art. 6(1)(b) or (1)(f) GDPR |
6. AI-Supported Processing of User Data
6.1 The App uses AI and language models in order to provide functions such as the AI assistant (chat and voice functions), automatic daily planning, task and appointment suggestions, the evaluation of voice inputs, classification, summarisation and rescheduling. In doing so, you are interacting with an AI system; we additionally point this out within the App.
6.2 In order to provide these functions, selected content data (e.g. task, appointment, note, page or voice input content) is transmitted to the providers named below and processed there, insofar as this is necessary for the respective function:
- OpenAI, L.L.C. (USA) – provision of the AI assistant, evaluation of inputs, generation of suggestions and summaries as well as transcription of voice inputs.
- OpenRouter, Inc. (USA) – routing of AI requests to model providers for the provision of the AI functions. The downstream model providers are sub-processors; we make an up-to-date overview of the model providers used available via the contact named in section 1.
- AssemblyAI, Inc. (USA) – transcription of voice recordings (voice inputs, meeting notes).
6.3 The legal basis for the transmission is Art. 6(1)(b) GDPR (performance of a contract), insofar as you actively use the respective function. Data processing agreements are in place with the aforementioned providers. Regarding transfers to third countries, see section 9.
6.4 No use for model training. We use the aforementioned services, in accordance with the agreements concluded with them, in such a way that the content you transmit is not used to train the providers' models. For routing via OpenRouter, we use a configuration without storage and without training use of the requests (zero data retention). Under these agreements, no permanent storage of the content takes place at the providers beyond the time required for processing; short-term storage for misuse and security controls for a period of up to 30 days remains unaffected by this.
6.5 Special categories of personal data. Freely entered texts and voice inputs may unintentionally contain special categories of personal data within the meaning of Art. 9 GDPR (e.g. health-related, religious or other sensitive information in notes or appointments). We recommend that you do not enter such content into the AI and voice functions. Insofar as you nevertheless actively enter such content into these functions and thereby cause it to be processed, the processing by the AI and transcription services used takes place on the basis of your explicit consent (Art. 9(2)(a) in conjunction with Art. 7 GDPR), which you grant through the active use of the respective function. You may withdraw this consent at any time with effect for the future by ceasing to use the function concerned.
6.6 AI outputs are probability-based and may be incorrect or incomplete. There is no solely automated decision-making within the meaning of Art. 22 GDPR producing legal effects or similarly significantly affecting you; AI suggestions can be reviewed, changed or discarded at any time.
7. Connection with Google and Microsoft Services
7.1 If you connect the App with your Google or Microsoft account – for login or for calendar integration – you grant, via the standard authorisation procedure (OAuth), the explicit permission to read profile and calendar information within the scope released by you and – if you activate this – to create, change or delete appointments. The providers involved are:
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google login, Google Calendar interface),
- Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft login, Outlook/calendar interface).
7.2 The legal basis is Art. 6(1)(b) GDPR (performance of a contract) in conjunction with your explicit authorisation.
7.3 You may revoke the permissions granted at any time via the settings of the App and/or directly in the account of the respective provider. The respective provider is independently responsible for the data processing within the respective account itself.
7.4 The processing of data from Google application programming interfaces (APIs) takes place in accordance with the applicable API user policies, including the requirements for limited use ("Limited Use"). Data from these interfaces is used only for the functions you have requested and is not made available for the training of AI models.
7.5 Data of other persons in your content. Your calendar and appointment data may contain personal data of other persons (e.g. names and e-mail addresses of participants or invitees). This data originates from the content entered by you or imported from the connected calendar. We process it exclusively for the provision of the functions requested by you (e.g. display and management of your appointments) as part of your content. You yourself are responsible, as the controller, for the lawfulness of including such third-party data in your content.
8. Recipients and Processors
8.1 We disclose personal data only where this is permissible for the performance of the contract, on the basis of a legal obligation, with your consent or on the basis of a legitimate interest. To provide the App, we use carefully selected service providers; data processing agreements pursuant to Art. 28 GDPR are in place with the service providers acting as processors.
8.2 We use in particular the following service providers:
| Service provider | Function | Registered office / place of processing |
|---|---|---|
| Supabase, Inc. | Hosting of the data storage (account and content data) | Data stored in the EU (Frankfurt am Main, Germany); company headquarters in the USA (access by the parent company safeguarded by the guarantees under section 9) |
| Vercel, Inc. | Operation and delivery of the web application (hosting) as well as cookieless reach measurement (see section 12) | USA / global content delivery network |
| Plausible Insights OÜ | Cookieless reach measurement on the website (see section 12) | Estonia (EU); according to the provider, processing and storage exclusively within the EU |
| OpenAI, L.L.C. | AI assistant, evaluation of inputs, transcription (see section 6) | USA |
| OpenRouter, Inc. | Routing of AI requests to model providers (see section 6) | USA |
| AssemblyAI, Inc. | Transcription of voice recordings (see section 6) | USA |
| Google Ireland Limited | Login and calendar integration, insofar as authorised by you (see section 7) | Ireland (EU) / USA |
| Microsoft Ireland Operations Limited | Login and calendar integration, insofar as authorised by you (see section 7) | Ireland (EU) / USA |
| Stripe Payments Europe, Ltd. | Processing of subscriptions and payments (see section 8.3) | Ireland (EU) / USA |
| Sendinblue SAS ("Brevo") | Dispatch of transactional, login and service e-mails | France (EU) |
| Redis Ltd. (Redis Cloud) | Technical caching infrastructure for the secure operation of the App | Processing in the EU (Frankfurt am Main); company headquarters outside the EU (access safeguarded by the guarantees under section 9) |
8.3 Payment service provider. For the processing of subscriptions and payments, we use Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland ("Stripe"). Stripe processes name, e-mail address, invoicing details, VAT identification number (if provided), payment means data (in particular card data or SEPA mandates), transaction history as well as technical connection data for fraud prevention. With regard to payment processing and fraud prevention, Stripe acts in part as an independent controller. The legal basis is Art. 6(1)(b) GDPR (payment processing) as well as Art. 6(1)(f) GDPR (fraud prevention, secure payment). The processing takes place primarily in the EU (Ireland); a transfer to Stripe, Inc. (USA) is safeguarded by the guarantees named in section 9. Further information: https://stripe.com/de/privacy.
9. Data Transfers to Third Countries
9.1 Some of the service providers named in sections 6 to 8 have their registered office in the USA or may transfer personal data to companies located there. Insofar as personal data is processed in a third country outside the European Economic Area (EEA), we ensure an adequate level of data protection by means of appropriate safeguards. The principal basis for such transfers are the
- Standard Contractual Clauses of the European Commission (Art. 46(2)(c) GDPR), supplemented where applicable by additional technical and organisational measures.
Insofar as the respective recipient is additionally certified under the EU-U.S. Data Privacy Framework, the transfer may additionally be based on the corresponding adequacy decision of the European Commission (Art. 45 GDPR). As the continued validity of this adequacy decision is currently not conclusively secured in legal terms, we do not treat it as the sole basis.
9.2 As a precaution, we therefore base transfers to the USA primarily on the Standard Contractual Clauses, irrespective of whether the respective recipient is additionally certified under the EU-U.S. Data Privacy Framework. Should the basis for third-country transfers change, we will amend this policy accordingly.
9.3 Transfers to third countries take place only to the extent necessary and only for the purposes named in this Privacy Policy. Details of the safeguards used in each case can be requested via the contact named in section 1.
10. Storage Period
10.1 We store personal data only for as long as is necessary for the respective purposes or for as long as we are legally obliged to do so.
10.2 Specifically, the following applies in particular:
- Account and content data (e.g. appointments, tasks, projects, notes, pages): for the duration of the existence of your user account and in accordance with the deletion and retention options offered in the App. After deletion of the account, this data is deleted or anonymised within 30 days, insofar as no statutory retention obligations conflict with this.
- Connection/authorisation tokens for external calendars: until the connection is revoked by you or until the account is deleted.
- Log and diagnostic data: as a rule up to 30 days to ensure security and stability, followed by deletion or anonymisation.
- Reach measurement data: beyond the measurement itself, only in aggregated form that cannot be traced back to you.
- Billing and accounting data: in accordance with retention obligations under commercial and tax law (in Germany regularly 6 or 10 years).
- Communication data (e.g. support): for the period necessary for processing, thereafter in accordance with statutory requirements.
10.3 After termination of the contractual relationship, personal data is deleted or anonymised, insofar as no statutory retention obligations or overriding legitimate interests conflict with this.
11. Public Sharing of Content
11.1 The App offers the possibility of making individual content (e.g. pages) accessible via a sharing link. If you create such a link, the content concerned can be accessed by persons who have the link.
11.2 In this case, the processing is based on your active use of the sharing function (Art. 6(1)(b) GDPR). You yourself are responsible for which content you share. Shared content is provided with an instruction to search engines that counteracts indexing; however, this does not entail a complete prevention of access by third parties who know the link. You can revoke a sharing at any time via the App.
12. Reach Measurement (Web Analytics)
12.1 To measure reach and to improve our offering, we use two cookieless analytics services: Plausible Insights OÜ on the website and the analytics function of Vercel, Inc. in the web application. According to the providers, both services work without cookies and without storing information on your end device; no cross-device or cross-site tracking and no creation of user profiles take place. Aggregated information such as pages accessed, referrer, approximate region of origin, device type used and browser type is processed.
12.2 According to the provider, Plausible does not store IP addresses. Your IP address is processed transiently only, in order to count repeat page views within a single day by means of a hash value that changes daily and cannot be reversed; it is not stored permanently. According to the provider, the analytics data is processed and stored exclusively within the European Union.
12.3 The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the statistical evaluation of usage to ensure stability, error analysis and product improvement. As no information is stored on or read from your end device in this context that would require consent pursuant to § 25(1) TDDDG, we do not use a consent banner for this purpose. You may object to the processing pursuant to Art. 21 GDPR.
13. Cookies and Comparable Technologies
13.1 The App uses technically necessary cookies and comparable technologies (e.g. local storage), insofar as this is necessary for authentication, security, language settings or the provision of the App. The legal basis for the storage of, or access to, information on the end device is § 25(2) no. 2 TDDDG in conjunction with Art. 6(1)(b) or (1)(f) GDPR.
13.2 We do not use any consent-requiring cookies or trackers for marketing or cross-device analytics purposes; this is why no cookie consent banner appears. Should we use consent-requiring technologies in the future, this will only take place after your explicit consent pursuant to § 25(1) TDDDG and Art. 6(1)(a) GDPR.
14. Your Rights as a Data Subject
Under the provisions of the GDPR, you have in particular the following rights:
- Right of access (Art. 15 GDPR) – upon request, this also includes the naming of the specific recipients of your data,
- Right to rectification (Art. 16 GDPR),
- Right to erasure (Art. 17 GDPR),
- Right to restriction of processing (Art. 18 GDPR),
- Right to data portability (Art. 20 GDPR),
- Right to object to processing operations based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- Right to withdraw consent with effect for the future (Art. 7(3) GDPR),
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For this purpose, you may in particular contact the supervisory authority of your habitual residence, your place of work or the place of the alleged infringement. The supervisory authority competent for the controller is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information), Alt-Moabit 59–61, 10555 Berlin.
To exercise your rights, please contact the data protection contact named in section 1. For identification purposes, it may be necessary for you to submit your request via the e-mail address stored in the App.
15. Obligation to Provide Data
The provision of the account and content data that is technically necessary for the use of the App is a prerequisite for the performance of the contract. Without this data, the App cannot be provided or can only be provided to a limited extent. Any provision of data going beyond this is voluntary.
16. Automated Decision-Making, Profiling
Solely automated decision-making producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR does not take place. AI-supported suggestions of the App are of a supporting nature; you can accept, reject or change suggestions at any time.
17. Security
We employ appropriate technical and organisational measures in order to protect your data against unauthorised access, loss or manipulation. These include in particular transport encryption (TLS), access-restricted storage, security measures during login as well as the careful selection and contractual binding of our service providers.
18. Validity and Amendment of This Privacy Policy
We may amend this Privacy Policy in order to adapt it to a changed legal situation, to changes to the App and its functions or to changes in the service providers used. The respective current version is available in the App as well as at app.usepilot.de. The date of the last update is set out in the "Last updated" information at the beginning of this policy.