Our giving pledge: 10% of profits committed to SOS Børnebyerne, Land of Hope, Løkkefonden & Psykiatrifonden — learn more

Privacy Policy

Version 1.1 — Last updated: September 2026

1. Who We Are

MyAvatar ApS ("we", "us", "our") is the data controller for personal data processed through the MyAvatar platform. We are registered in Denmark, CVR DK46477944.

2. Data We Collect

Category Examples Purpose
Account dataName, email, passwordAccount management
Payment dataBilling address, last 4 digits of cardPayment processing (via Stripe)
Usage dataVideos created, features used, session logsService improvement, billing
Content dataScripts, uploaded images, generated videosService delivery
Technical dataIP address, browser type, deviceSecurity, analytics

We do not store full payment card numbers — these are handled by Stripe (PCI-DSS compliant).

3. Legal Basis for Processing (GDPR)

Processing Legal Basis
Account managementContract (Art. 6(1)(b))
Payment processingContract (Art. 6(1)(b))
Service improvementLegitimate interest (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))
Marketing (if opted in)Consent (Art. 6(1)(a))

4. Data Sharing

We share data with the following categories of processors (last reviewed 7 September 2026):

We do not sell your personal data to third parties.

Google User Data & Google API Services

If you choose to connect your Google Ads account, MyAvatar requests access to the Google Ads API using the https://www.googleapis.com/auth/adwords scope. This connection is optional and is always initiated by you.

We use this access solely to let you create, review, and manage your own advertising campaigns from within MyAvatar's Campaign Engine, acting on your behalf and at your direction. We access only the Google Ads account(s) you explicitly authorise.

MyAvatar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:

We do not use data obtained through Google APIs to develop, improve, or train generalized AI or machine learning models.

You can disconnect your Google Ads account at any time from your MyAvatar connection settings, which revokes MyAvatar's stored access and refresh tokens. You may also revoke access directly at myaccount.google.com/permissions.

Google Calendar (read-only)

What we access

If you choose to connect Google Calendar, MyAvatar requests a single permission: https://www.googleapis.com/auth/calendar.events.readonly. This is a read-only permission. It lets MyAvatar read events from your calendar so it can identify the people you have met with. It does not allow MyAvatar to create, edit, move, or delete any event, and we do not do so.

How we use it

When you click "Sync Calendar" in MyAvatar's Lead Generation feature, we read events from the period you select and extract the attendees' names and email addresses, so you can turn people you have met into leads in your own CRM. We read your calendar only when you initiate a sync; no background process reads your calendar.

What we store

We store the meeting title, time, and attendee name and email address for the events you sync, as contacts in your own CRM. We store an encrypted OAuth token so we can perform the sync you request. We do not store event descriptions, attachments, or meeting contents. Contacts imported from Google Calendar are kept separately from other CRM data and are never shared with data enrichment providers or AI services.

How to revoke

You can disconnect Google Calendar at any time from your MyAvatar connection settings, which revokes MyAvatar's access at Google and deletes the stored token. You can also revoke access directly at myaccount.google.com/permissions.

Limited Use

MyAvatar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Gmail (send-only access)

What we access

If you choose to connect your Gmail account, MyAvatar requests a single Google permission: https://www.googleapis.com/auth/gmail.send. This is the narrowest Gmail permission Google offers. It allows MyAvatar to send an email on your behalf. It does not allow MyAvatar to read, search, modify, or delete any message in your mailbox, and we do not do so.

At the moment you connect your account, we make one call to Google to retrieve the email address associated with it, so we can show you which account is connected.

How we use it

We send an email only when you explicitly click send on a message you have reviewed, to a recipient you have specified. No background process, scheduled job, or automated agent sends email from your account. Messages sent this way come from your own address and appear in your own Gmail Sent folder.

What we store

We store your connected email address and an encrypted OAuth token that allows us to send on your behalf. Tokens are encrypted at rest. We do not store the contents of messages you send beyond what is required to display your own sending history within MyAvatar.

How to revoke

You can disconnect your Gmail account at any time from within MyAvatar, which revokes MyAvatar's access at Google and deletes the stored token. You can also revoke MyAvatar's access directly through your Google Account at myaccount.google.com/permissions.

Limited Use

MyAvatar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

YouTube

MyAvatar's YouTube features use YouTube API Services.

By using MyAvatar's YouTube integration, you agree to be bound by the YouTube Terms of Service. Any personal data processed by Google in connection with these features is handled in accordance with the Google Privacy Policy.

What we access

If you choose to connect your YouTube channel, MyAvatar requests two permissions:

We do not request permission to edit or delete your videos, manage playlists, change thumbnails, moderate comments, or otherwise modify your channel, and MyAvatar does not perform any of these actions.

How we use it

We upload a video only when you initiate publishing — either by clicking publish directly, or by scheduling a publication that you have set up yourself. We read channel information at the time you connect, so we can show you which channel is linked. We read video statistics in order to display performance data for your own published videos inside MyAvatar.

What we store

We store your channel ID and channel title, an OAuth token allowing us to publish on your behalf, and performance statistics for videos published through MyAvatar. We do not store copies of videos already on your channel, and we do not access videos that were not published through MyAvatar.

How to revoke

You can disconnect your YouTube channel at any time from within MyAvatar, which revokes MyAvatar's access at Google, deletes the stored token, and stops all further access. You can also revoke MyAvatar's access directly through your Google Account at myaccount.google.com/permissions.

If you wish to have stored YouTube data deleted, contact us at the address in the Contact section of this policy.

Limited Use

MyAvatar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect your data

This section explains how MyAvatar protects the data described above, including all data obtained through Google APIs (Google Ads, Google Calendar, Gmail, and YouTube).

Encryption in transit

All traffic between your browser and MyAvatar is protected with TLS (HTTPS). The connection between the MyAvatar application and its database is also encrypted with TLS.

Encryption of tokens at rest

The OAuth access and refresh tokens for every connected Google service (Google Ads, Google Calendar, Gmail, and YouTube) are encrypted before they are written to the database, using authenticated symmetric encryption (Fernet / AES-128-CBC with HMAC-SHA256). The encryption key is held in a restricted server configuration file, separate from the database and readable only by the MyAvatar service account, so access to the database alone is not sufficient to read your tokens.

Access to your data

Your tokens are decrypted only in memory, only for the moment needed to perform an action you initiated (such as sending an email you clicked send on, or syncing the calendar period you chose). The decryption key is never stored in the database. Access to the production systems holding this data is limited to authorized MyAvatar personnel and contractors who are bound by confidentiality obligations, for the purpose of running and maintaining the service.

Where your data is stored

The MyAvatar application is hosted with Hetzner Online GmbH in Germany. The database is a managed PostgreSQL service hosted with Scalingo in France. Both are within the European Union.

How long we keep it, and how to delete it

5. California Residents (CCPA)

If you are a California resident, you have the right to:

We do not sell your personal information.

To exercise your rights, contact: privacy@myavatar.dk

6. Your Rights (GDPR)

You have the right to:

To exercise your rights: privacy@myavatar.dk

You may also lodge a complaint with the Danish Data Protection Authority (Datatilsynet): www.datatilsynet.dk

7. Data Retention

Data type Retention period
Account dataUntil account deletion + 30 days
Billing records5 years (legal requirement)
Generated videosUntil deleted by user or account termination
Usage logs12 months

8. International Transfers

We operate from Denmark (EU). Some third-party providers are located outside the EU/EEA. For such transfers, we rely on Standard Contractual Clauses approved by the European Commission.

9. Cookies

We use essential cookies for authentication and session management. Analytics cookies require your consent. See our Cookie Policy for details.

10. Children

MyAvatar is a B2B SaaS platform intended exclusively for business users aged 18 and over. Our Service is not directed at children, and we do not knowingly collect personal data from minors.

MyAvatar is a tool for creating video content. Users who produce content targeting children's audiences are solely responsible for ensuring their content complies with applicable regulations (including COPPA, GDPR-K, and advertising standards) in their respective jurisdictions. MyAvatar does not assume liability for the end use or distribution of user-generated content.

11. Changes

We will notify you of material changes to this Privacy Policy by email or prominent notice on the platform at least 30 days before they take effect.

Report content · Report content that misuses someone's likeness, is fraudulent, or otherwise violates our terms.