Overview
Under Art. 17 GDPR (right to erasure) you have the right at any time to request the complete deletion of your personal data and your CastLoop account. This page describes two ways to delete your account, and which data is actually deleted when.
Self-service deletion in the dashboard
The fastest way: log in at app.castloop.de and navigate to Settings → Account → Delete account. After confirmation, all your data is removed from our active database within seconds. Logging in again is no longer possible afterwards.
Important: You can end an active subscription beforehand under Settings → Billing → Cancel subscription. Account deletion cancels existing subscriptions automatically — but you are explicitly notified of this for safety.
Deletion by email request
If you no longer have access to your account (e.g. forgotten password + lost email provider), send us an email to info@castloop.de with the subject “Data deletion under GDPR Art. 17”. We need the following details for identification:
- The email address you used to register with CastLoop
- Optional: tenant ID or invoice number (if available)
- A clear confirmation that you are the account holder
We reply within 72 hours (business days) and carry out the deletion after successful identity verification within a maximum of 30 days (GDPR deadline).
Which data is deleted
When an account is deleted, the following data is irrevocably removed:
- Account data — email, name, password hash, login history
- Tenant data — workspace configuration, brand settings
- Uploaded content — source videos, rendered clips, thumbnails (deleted from disk)
- Transcripts and AI analyses — Whisper transcripts, Gemini clip selection, hook suggestions
- OAuth tokens — connections to Instagram, Facebook, TikTok, LinkedIn, X, YouTube, Threads are revoked (where possible)
- Scheduled posts — all pending, not yet published publications are cancelled
- Analytics data — internal performance metrics, usage events
- Audit logs — security-relevant logs are anonymized (IP hashes are retained for 30 days for abuse prevention, then deleted)
Legally required retention
A few categories of data may not be deleted immediately under § 257 HGB (10 years) and § 147 AO (10 years), because we must retain them as accounting records:
- Invoices — we keep the PDF record + invoice data for 10 years.
- Payment IDs — Mollie payment IDs are anonymized (no longer linked to a person) but retained for 10 years.
This statutory retention cannot be overridden even by a legitimate data deletion request — it arises from German tax and commercial law. After the 10 years expire, this data is also deleted automatically.
Data on social media platforms
CastLoop publishes content on your behalf on Instagram, Facebook, TikTok, LinkedIn, X, YouTube Shorts and Threads. Posts already published on these platforms are NOT removed by account deletion — they reside in your own profile on the respective platform.
However, we do revoke the OAuth tokens, so that after deletion CastLoop no longer has access to your connected accounts. Content already posted must be deleted by you on the respective platform.
Deadlines at a glance
| Action | Deadline |
|---|---|
| Self-service deletion in the dashboard | Immediately (within seconds) |
| Confirmation of an email request | 72 hours (business days) |
| Complete deletion after email request | Max. 30 days |
| Backups (encrypted, then overwritten) | Max. 60 days |
| Accounting data (§ 257 HGB) | 10 years, then automatic deletion |
Contact
For questions about data deletion or your GDPR rights:
Daniel Ovadia · CastLoop
Eugen-Richter-Str. 159
76187 Karlsruhe
Email: info@castloop.de
You also have the right to lodge a complaint with the competent data protection supervisory authority: the State Commissioner for Data Protection of Baden-Württemberg .