Last updated: July 20, 2026
Carve Studio GmbH
Cosimastr. 121
81925 München
Germany
Email: [email protected]
Phone: +49 171 8263725
This policy applies to our website at replicato.app and the associated web application at use.replicato.app (together, “Replicato”). It describes how we process personal data when you visit our pages, create an account, or use Replicato.
Personal data is any information relating to an identified or identifiable person. We process such data only where necessary for the purposes described below.
Depending on the processing, our legal bases are in particular:
Where service providers process data solely on our instructions, we have entered into data processing agreements with them under Article 28 GDPR. Within our company, access is limited to people who need the data for their respective tasks.
When you access Replicato, technically required data is processed. This may include your IP address, date and time, requested URL, referrer URL, browser and operating system information, amount of data transferred, and HTTP status. We process this data to deliver the service, maintain stability, diagnose errors, and prevent abusive or malicious access.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of Replicato. Log data is deleted when it is no longer needed for these purposes. In the event of a specific security incident, it may be retained until the incident and related legal claims have been fully resolved.
Our systems run on servers provided by STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO processes data required for hosting, network operation, and backups as our processor.
More information: STRATO privacy information
We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, for DNS, TLS encryption, content delivery, and attack protection. Connections to Replicato pass through Cloudflare. In addition to the log data listed above, Cloudflare may process security characteristics of a request and use technically necessary cookies or similar identifiers to detect automated and malicious access.
The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the secure and performant delivery of our service. Cloudflare relies on the EU-US Data Privacy Framework adequacy decision and, additionally, the EU Standard Contractual Clauses for transfers to the United States.
More information: Cloudflare Privacy Policy
During registration and sign-in, we process in particular your name, email address, a password hash, internal user and account identifiers, sign-in timestamps, session data, IP address, and user agent. Passwords are not stored in plain text. This data is required to provide your account, enable sign-in, and prevent misuse.
The legal basis is Article 6(1)(b) GDPR. We also process security-related logs and session data under Article 6(1)(f) GDPR based on our interest in protecting accounts and systems. We generally retain account data for the duration of the user relationship and afterwards only where statutory retention duties or the establishment, exercise, or defense of legal claims require it.
If you choose Google or Microsoft sign-in, you are redirected to the selected provider. At least the technical data required for the sign-in and the account data you release through that provider are processed. We generally receive a provider identifier, your name, and email address. The legal basis is Article 6(1)(b) GDPR; use of these sign-in options is voluntary.
Google and Microsoft may also process data in third countries, in particular the United States. They rely in particular on the EU-US Data Privacy Framework adequacy decision and, where necessary, EU Standard Contractual Clauses for such transfers.
If you contact us, we process your contact details, message content, attachments where applicable, and timing and technical delivery data to handle your request. The legal basis is Article 6(1)(b) GDPR where the request concerns a contract or pre-contractual matter, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is answering and documenting requests.
We use Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) for magic links, password resets, and other transactional emails. In particular, the email address, message content, and technical delivery data are transferred. Processing is necessary for our user agreement under Article 6(1)(b) GDPR. Resend is certified under the EU-US Data Privacy Framework and its processing agreement also incorporates EU Standard Contractual Clauses.
More information: Resend Privacy Policy
When you use Replicato, we process uploaded PDF templates and CSV/XLSX data, filenames and file metadata, extracted form fields, mappings you create, and job and output data. This data may contain personal data of third parties. You are responsible for ensuring that you are authorized to process and transmit this data and, where required, have informed the individuals concerned.
The sole purpose is the creation, mapping, filling, and delivery of PDF documents you request and the storage of your templates. The legal basis is Article 6(1)(b) GDPR. Where you process data on behalf of another controller, we process the content according to that controller's documented instructions.
Templates and related configurations are associated with your account and stored while you keep them available for use or we need them to perform the contract. Input files for completed or cancelled processing jobs are removed after completion. Input files for failed jobs are kept for a possible retry for no more than seven days. Output archives remain available for download for no more than 24 hours. Metadata for completed, failed, or cancelled jobs is generally deleted after 30 days. Local working copies in the processing service are removed after the respective job.
Some spreadsheet data and file metadata is temporarily stored in your browser's IndexedDB so it remains available when moving between editing and filling. These entries are cleaned up after 24 hours. A local job identifier may be stored in Local Storage to associate a download with the correct job; it is removed after use. This data generally remains on your device.
When you expressly start AI-assisted mapping, we send your input file's column headings and the names, labels, types, and page numbers of PDF form fields to the OpenAI API. The PDF file's content and row values from your spreadsheet are not sent for this feature. Suggestions are assistance only and are not used for a solely automated decision that produces legal or similarly significant effects.
The provider is OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. The purpose and legal basis are the feature you request and therefore Article 6(1)(b) GDPR. Under its business terms, OpenAI processes API content as a processor and does not use it to train general models unless expressly agreed otherwise. OpenAI may use subprocessors outside the EEA; transfers are safeguarded by EU Standard Contractual Clauses or an adequacy decision.
More information: OpenAI Data Processing Addendum
In the web application, we use Sentry by Functional Software, Inc., 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA, to identify, analyze, and fix technical errors. When an error occurs, data may include the time, requested page, browser and device information, IP address, technical request information, error stack, and an internal user identifier. We do not intentionally send the contents of uploaded documents or spreadsheets to Sentry.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the stability, security, and reliability of our service. Error data is deleted when no longer required for analysis and remediation and no security or evidentiary need requires further retention. Sentry acts as our processor. Transfers to the United States rely on the EU-US Data Privacy Framework and, additionally, EU Standard Contractual Clauses.
More information: Sentry Privacy Policy
We operate Umami on our own infrastructure hosted in Germany. Umami records page views and selected interaction events. The requested page, referrer, timestamp, browser, operating system, device type, and country derived from the IP address may be processed. The IP address is used for the analysis but is not stored. We do not use persistent user IDs or create cross-site profiles. Form, PDF, and spreadsheet content is not transmitted to Umami.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is privacy-conscious, aggregated usage measurement to improve content, usability, and stability. You may object to this processing at any time on grounds relating to your particular situation.
We use only storage access required for features you request. The legal basis for storing or accessing information on your device is Section 25(2)(2) TDDDG; subsequent processing relies on the respective GDPR legal bases stated in this policy.
| Storage | Purpose | Duration |
|---|---|---|
| better-auth.session_token or __Secure-better-auth.session_token | Secure sign-in and session assignment | Up to 7 days; may be extended during active use |
| Short-lived authentication cookies | Protection of OAuth, magic-link, and sign-in flows | Until completion or expiry of the process |
| Language preference | Display of the selected language | According to the configured cookie lifetime or until deletion |
| IndexedDB / Local Storage | Local spreadsheet data and processing-job association | Spreadsheet data up to 24 hours; job identifier until use or manual deletion |
Replicato embeds YouTube videos in privacy-enhanced mode via youtube-nocookie.com. Loading a player establishes a connection to YouTube or Google servers. In particular, your IP address, browser and device information, the requested page, and, where applicable, information from your Google account may be processed, and information may be stored on or read from your device. The provider is Google Ireland Limited; processing by Google LLC in the United States is possible.
Loading is based on your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw consent at any time with future effect. For transfers to the United States, Google relies in particular on the EU-US Data Privacy Framework adequacy decision and, where necessary, EU Standard Contractual Clauses.
More information: Google Privacy Policy
In addition to the providers expressly named above, IT, hosting, communications, and professional advisers may receive data where necessary for operations, support, or compliance with legal duties. Authorities, courts, or other bodies receive data only where required by law or necessary for legal claims.
For transfers outside the European Economic Area, we assess whether an adequacy decision under Article 45 GDPR applies. Otherwise, we use in particular the European Commission's Standard Contractual Clauses under Article 46(2)(c) GDPR and assess any required supplementary measures. You may request a copy of the relevant safeguards using the contact details above.
Unless this policy states a fixed period, we retain personal data only for as long as required for the respective purpose. We then delete or anonymize it unless statutory retention duties apply. Commercial and tax records may in particular need to be retained for six, eight, or ten years. Data required for the establishment, exercise, or defense of legal claims may be retained until the applicable limitation periods expire.
You are not legally required to provide personal data to us. Without the data required for an account, authentication, and a feature you select, however, we cannot provide Replicato or that feature. Google or Microsoft sign-in, AI mapping, and YouTube are optional.
Subject to the legal requirements, you have the right to:
Where processing is based on consent, you may withdraw that consent at any time with future effect. Processing carried out before withdrawal remains lawful.
Objection to legitimate interests: You may object at any time, on grounds relating to your particular situation, to processing based on Article 6(1)(f) GDPR. We will then stop processing the data unless we demonstrate compelling legitimate grounds or the processing is required for the establishment, exercise, or defense of legal claims.
To exercise your rights, email [email protected]. You also have the right to lodge a complaint with a data protection authority. Our lead authority is generally the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany: www.lda.bayern.de.
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
We update this policy when our processing, service providers, or the law changes. The version published on this page is the current version.