Privacy Policy
This English version is provided for information only. The German version is legally authoritative.
This Privacy Policy provides information pursuant to Articles 13 and 14 of the General Data Protection Regulation (GDPR) about the processing of personal data by Cinemura. It applies to the marketing website, web app, iOS app and Android app as well as support and administrative activities (together, the “Service”).
1. Controller and privacy contact
The controller within the meaning of Article 4(7) GDPR is:
【AUSFÜLLEN: vollständige Firma】 UG (haftungsbeschränkt) i. G.
【AUSFÜLLEN: Straße und Hausnummer】
【AUSFÜLLEN: Postleitzahl und Ort】
Germany
Email: 【AUSFÜLLEN: Datenschutz-Kontakt-E-Mail-Adresse】
Telephone: 【AUSFÜLLEN: Telefonnummer】
【PRÜFEN: Vor Launch und danach bei organisatorischen Änderungen feststellen, ob nach Art. 37 DSGVO oder § 38 BDSG ein Datenschutzbeauftragter zu benennen ist. Falls ja, Kontaktdaten hier ergänzen und die zuständige Aufsichtsbehörde informieren.】
2. Principles and sources of data
We process only data required for the relevant purpose and restrict access based on roles. Data originates in particular
- directly from you, for example when you register, enter information, upload content, request support or make a payment;
- from your browser or device, such as technical connection, session and device information;
- from identity providers when you choose Apple or Google;
- from Stripe in connection with checkout, subscriptions, invoices or payment status;
- from technical service providers in connection with storage, email delivery and AI generation;
- from other users or automated checks when content is reported; and
- in the case of depicted or otherwise affected third parties, from media and information uploaded by a user or business customer.
Where data is required for registration, entering into a contract or carrying out a requested generation, we cannot provide the relevant service without that data. Marketing consent and optional profile settings are voluntary.
3. Marketing website, hosting and log data
The Service is intended to run on infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, at a location in Germany or the EU. Hetzner provides server and object storage services.
When the Service is accessed, the following data may be processed in particular: IP address, time, method and target of the request, status code, amount of data transferred, referrer, user agent and security- or error-related events.
- Purposes: delivering the Service, stability, troubleshooting, and preventing attacks and abuse.
- Legal basis: Article 6(1)(f) GDPR; our legitimate interest is a secure and functional Service. Where processing is required to perform a contract, Article 6(1)(b) GDPR also applies.
- Retention: 【AUSFÜLLEN: produktiv konfigurierte Aufbewahrungsdauer für Zugriffs-, Sicherheits- und Fehlerprotokolle】. Where a specific security incident occurs, relevant data may be preserved until the incident has been investigated and claims have been enforced or defended.
【PRÜFEN: Vor Launch Hetzner-Standort, gebuchte Produkte, AVV, Unterauftragsverarbeiter, Backup-Konfiguration, Log-Inhalte und tatsächliche Löschfristen dokumentieren. Die öffentliche Erklärung muss der produktiven Konfiguration entsprechen.】
4. Account, authentication and security
4.1 Registration and user account
When you register and use an account, we process in particular your name, email address, password hash, language, theme, notification settings, email verification, the accepted contract version and timestamps, role, plan status, budget information, and account and activity timestamps.
- Purposes: creating and managing the account, performing the contract, verifying the email address, synchronising settings, preventing abuse, and demonstrating acceptance of the contract terms.
- Legal bases: Article 6(1)(b) GDPR; Article 6(1)(c) GDPR for legally required evidence; and Article 6(1)(f) GDPR for account security and the establishment, exercise or defence of legal claims.
4.2 Password, passkeys and sessions
Passwords are stored as cryptographic hashes, not in plain text. With passkeys, the private key remains on your device or in your chosen keychain. Cinemura processes the public key, credential identifier, device label, technical transport information, counters and usage timestamps. Biometric characteristics used locally by your device to approve access are not transmitted to Cinemura.
For sessions, we process token hashes or tokens, session and device identifiers, creation, expiry, revocation and last-use timestamps. Web access tokens are held in memory; the refresh token is currently stored in the browser’s local storage (localStorage). On iOS, authentication tokens are stored in the device-bound Keychain. On Android, secure preferences are excluded from cloud backup and device transfer.
- Purposes: authentication, session management, token rotation and detection of abusive reuse.
- Legal bases: Articles 6(1)(b) and 6(1)(f) GDPR.
【PRÜFEN: Vor Launch die produktive Web-Token-Speicherung und ihre Schutzmaßnahmen gegen XSS/Token-Diebstahl im Sicherheitsreview bestätigen; bei Änderung diese Erklärung aktualisieren.】
4.3 Sign in with Apple or Google
If you actively choose “Sign in with Apple” or “Sign in with Google”, you transmit an identity token to Cinemura. Depending on what you authorise, we receive in particular a provider identifier, name and email address; Apple may provide a relay address. The relevant sign-in process begins only after you make that choice.
- Recipients/independent controllers: 【PRÜFEN: Vor Launch die tatsächlich eingebundenen Vertragsgesellschaften, SDKs, Datenfelder, Datenschutzinformationen und Übermittlungsmechanismen für Apple und Google je Plattform bestätigen.】
- Purpose and legal basis at Cinemura: authentication and performance of the contract, Article 6(1)(b) GDPR.
5. Local storage, cookies and device access
Under Section 25(1) TDDDG, storing or accessing information on an end device generally requires consent. Under Section 25(2) no. 2 TDDDG, no consent is required to the extent that this is strictly necessary to provide a digital service expressly requested by the user.
The current product design provides for the following local storage:
| Storage/access | Purpose | Duration/control |
|---|---|---|
Web refresh token in localStorage |
Maintaining and renewing a signed-in session | Until logout, revocation or expiry |
| Web language and theme settings | Displaying the selected presentation | Until changed or browser storage is cleared |
| iOS Keychain / Android secure preferences | Authentication | Until logout, account deletion or expiry |
| Native app settings | Language, theme and local notification preference | Until changed, app data is deleted or operating-system backups are deleted |
The marketing website is intended not to use analytics, advertising or tracking technologies or externally hosted fonts. On the basis of the current functionality, no consent banner is therefore planned.
【PRÜFEN: Vor jedem Launch mit einem Netzwerk- und Storage-Audit bestätigen, dass keine weiteren Cookies, SDKs, Pixel, externen Medien, Telemetrie- oder Trackingzugriffe stattfinden. Sobald nicht unbedingt erforderliche Technologien hinzukommen, müssen Einwilligung und Auswahlmöglichkeit vor deren Aktivierung umgesetzt und diese Erklärung ergänzt werden.】
When selecting reference media, the apps access only the photos or videos selected by the user. Access to the media library when saving a result occurs at the user’s request. Android may display notifications after you grant operating-system permission. Cinemura currently requires no access to location data or contacts.
6. Uploads, prompts, videos and 3D views
6.1 Data processed and purposes
For the core service, we process in particular
- uploaded photos and video clips and file, size, format, duration and image metadata;
- prompts, titles and generation parameters;
- status, model identifier, error messages and technical job identifiers;
- generated videos, thumbnails, 3D models and related download information; and
- budget, cost and billing entries.
The purposes are to receive uploads, carry out the requested generation or 3D reconstruction, provide the result, handle errors, manage allowances and prevent abuse. The legal basis is Article 6(1)(b) GDPR; security and abuse-prevention measures are additionally based on Article 6(1)(f) GDPR.
6.2 Third-party data and special categories
Property media may contain people, licence plates, name or address signs, voices, interiors or other information about third parties. Upload only content that you may lawfully use for this purpose. In particular, avoid data covered by Article 9 GDPR where it is not required for the Service.
Where a business customer instructs Cinemura to process third-party personal data on its behalf, the parties must enter into an agreement under Article 28 GDPR before that processing begins.
【PRÜFEN: Vor B2B-Launch einen Kunden-AVV einschließlich Gegenstand, Weisungen, Unterauftragsverarbeitern, Drittlandtransfers, Löschung und TOMs bereitstellen und technisch mit der jeweils akzeptierten Fassung versionieren.】
6.3 AI and 3D service providers
Video and 3D jobs are intended to transmit the required reference media, prompts and parameters to fal.ai / Features & Labels, Inc. and models made available there. The current design identifies a Seedance model for video and a Tripo3D multiview model for 3D. Results and technical status information are transmitted back and stored by Cinemura.
【PRÜFEN: Vor Launch die korrekte Vertragsgesellschaft und Anschrift, den abgeschlossenen fal.ai-DPA, Weisungsbindung, TOMs, vollständige Subprozessorliste, Verarbeitungsorte, SCC-Module bzw. einen gültigen DPF-Eintrag, Transfer Impact Assessment, Löschfristen für Ein- und Ausgaben sowie vertraglichen Ausschluss der Nutzung von Kundendaten zum Training belegen. Solange dies nicht vollständig belegt ist, darf der betroffene Generierungsdienst nicht produktiv mit personenbezogenen Daten angeboten werden.】
【PRÜFEN: Schriftlich klären, ob und welche Referenzmedien, Prompts oder Ergebnisse bei Seedance an ByteDance-Gesellschaften und beim 3D-Modell an Tripo AI oder weitere Modellanbieter übermittelt werden. Für jede Weiterübermittlung – insbesondere in Staaten ohne Angemessenheitsbeschluss – Rechtsgrundlage, SCC-Unterauftragskette, zusätzliche Maßnahmen und Löschung dokumentieren; andernfalls Modell oder Anbieter wechseln.】
Cinemura does not intend to use reference media, prompts or results to train its own AI. A corresponding commitment concerning external providers will be published only after it has been verified and contractually secured.
7. Payments and subscriptions
Paid plans are intended to use externally hosted Stripe Checkout and Stripe Customer Portal for management. Cinemura processes in particular Stripe customer and subscription identifiers, plan and interval, status, terms, invoice identifiers, amount, currency and payment timestamp. Full card details are not stored by Cinemura.
Depending on the payment method and checks performed, Stripe processes contact, invoice, payment, device, IP and fraud-prevention data. Depending on the activity, Stripe acts either as a processor or as an independent controller.
- Contracting entity for an EEA account: generally Stripe Payments Europe, Limited; 【PRÜFEN: konkrete Stripe-Vertragsgesellschaft und aktuelle Anschrift des produktiven Kontos vor Launch eintragen】.
- Purposes/legal bases at Cinemura: contract and payment, Article 6(1)(b) GDPR; commercial and tax-law obligations, Article 6(1)(c) GDPR; fraud prevention and defence of claims, Article 6(1)(f) GDPR.
- International transfers: Stripe states that transfers to Stripe, LLC rely first on the EU-U.S. Data Privacy Framework and, as a fallback, the relevant EU Standard Contractual Clauses. The current certification and account configuration must be documented before launch.
Further information: https://stripe.com/privacy, https://stripe.com/legal/dpa and https://stripe.com/legal/dta.
8. Email, support and notifications
The following SMTP service is to be used for email verification, password reset, security, generation, subscription and deletion notices:
【AUSFÜLLEN: SMTP-Anbieter, vollständige Vertragsgesellschaft, Anschrift und Datenschutzlink】
Depending on the message, this involves processing in particular the email address, name, language, message type, technical delivery information and necessary message content.
- Legal bases: Article 6(1)(b) GDPR; Article 6(1)(f) GDPR for security; Article 6(1)(c) GDPR for legally required communications.
- Marketing: If marketing email is offered in future, it will be sent only with voluntary consent under Article 6(1)(a) GDPR and the applicable unfair-competition rules. Consent may be withdrawn at any time with future effect.
【PRÜFEN: Vor Aktivierung Anbieter, AVV, Unterauftragsverarbeiter, Versandregion, Drittlandmechanismus, Löschfrist und Double-Opt-In-Nachweis festlegen.】
For support requests, we process your contact and account data, the content of the request and necessary technical information. The legal basis is Article 6(1)(b) GDPR and, for general enquiries, Article 6(1)(f) GDPR. Support records are deleted when no longer required and where no statutory or evidential reason requires continued storage: 【AUSFÜLLEN: Support-Aufbewahrungsfrist】.
9. Content reports, moderation and administration
Users may report content, and technical checks may additionally flag anomalies. Data processed includes in particular target type and identifier, reason, reporter identifier where available, preview, status, internal note, decision, staff member and timestamps. Authorised support and admin roles may access user, subscription, budget, generation and cost information to the extent required and may record actions taken.
- Purposes: protecting users and third-party rights, enforcing the Terms, handling complaints, preventing abuse and maintaining system security.
- Legal bases: Articles 6(1)(b) and 6(1)(f) GDPR; Article 6(1)(c) GDPR where a statutory obligation applies in a particular case.
- Retention: 【AUSFÜLLEN: Aufbewahrungsfrist für Meldungen, Moderationsentscheidungen und Admin-Auditdaten, differenziert nach abgelehntem Hinweis, Maßnahme und Rechtsstreit】.
Decisions producing legal or similarly significant effects are not taken solely by automated means. An automated flag may trigger human review.
10. Retention, deletion and backups
Unless an overriding statutory obligation or legal dispute requires otherwise, the following product-related periods apply:
| Data category | Standard retention period |
|---|---|
| Reference media, videos and 3D views during an active subscription | Until deleted by the user, the account is deleted or the contractually intended availability ends; accessible without a fixed product period while the subscription is active |
| Media and generations after a subscription ends | 90 days; a warning is generally sent 7 days before scheduled deletion |
| Media and generations in the Free Tier without a subscription | 30 days after creation |
| Account data | Until account deletion or contract completion; then deleted or restricted where obligations or claims continue |
| Sessions and security tokens | Until expiry, revocation or logout; evidence relating to compromise for a defined security period |
| Invoices and accounting records | Generally eight years; certain ledgers, financial statements and organisational records ten years; business correspondence generally six years, subject to longer tax-related necessity |
| Consent, contract and evidence records | During use and then in accordance with applicable limitation and accountability periods |
| Logs, support and moderation | The periods to be entered in Sections 3, 8 and 9 |
The periods of 90/30/7 days originate from the central product configuration. Users may delete individual media and results earlier unless retention or preservation is required for legal claims.
Backups are overwritten according to a documented rotation and deletion plan. Deletion from active systems may therefore take effect later in backups; backed-up data is not restored for ordinary purposes before it is overwritten.
【PRÜFEN: Vor Launch Retention-, Warn-, Export- und Löschjobs einschließlich Object Storage, Datenbank, Such-/Cache-Systemen, Anbieter-Queues und Backups end-to-end testen; Backup-Frist und Wiederherstellungszugriffe hier konkret ergänzen.】
11. Recipients and transfers outside the EEA
Only internal roles and service providers receive access to the extent required for the stated purposes. Intended recipient categories are hosting/object storage, AI/3D computation, payment processing, identity providers, email delivery and, where applicable, legal, tax and public authorities.
Transfers outside the EEA take place only under Articles 44 et seq. GDPR, in particular on the basis of an adequacy decision or the EU Standard Contractual Clauses combined with a transfer assessment and any necessary supplementary measures. Certification under the EU-U.S. Data Privacy Framework applies only to the specifically certified US entity and covered data.
| Recipient/processing | Intended mechanism | Pre-launch status |
|---|---|---|
| Stripe, LLC, USA | DPF, with the relevant SCC modules as fallback | Document certification and account data flow |
| Apple/Google entities where a US transfer occurs | DPF or another demonstrated mechanism | Verify contracting entity, certification and data flow |
| fal.ai / Features & Labels, Inc., USA | According to the publicly indexed DPA, fal.ai names the EU Standard Contractual Clauses as the default mechanism; no DPF listing for Features & Labels, Inc. could be identified as at the research date of 2 September 2026. 【PRÜFEN: SCC-Modul, TIA und Zusatzmaßnahmen anhand des verbindlichen Vertragstexts belegen; DPF-Register unmittelbar vor Launch erneut prüfen】 | Launch blocker |
| Model/subprocessors including possible ByteDance/Tripo entities | 【PRÜFEN: Land, Rolle, SCC-Unterauftragskette, TIA und Zusatzmaßnahmen】 | Launch blocker |
| SMTP provider | 【AUSFÜLLEN: Mechanismus nach Anbieter und Region】 | Launch blocker |
Copies of or information about the relevant safeguards may be requested through the privacy contact, to the extent this does not prejudice third-party rights or trade secrets.
12. Your rights
Subject to the statutory conditions, you have the right to
- access and a copy of your data (Article 15 GDPR),
- rectification (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- notification of recipients (Article 19 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR),
- withdraw consent with future effect (Article 7(3) GDPR), and
- protection against solely automated decisions under Article 22 GDPR.
Objection: Where we process data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. You may object to direct marketing at any time without stating specific grounds.
To exercise a right, contact the privacy address. To protect your data, we may request proportionate proof of identity. An intended in-app data export and account-deletion function supplement this contact route; statutory rights do not depend on self-service availability.
【PRÜFEN: Datenexport, Kontolöschung, Einschränkung, Empfängerbenachrichtigung und Fristenmanagement vor Launch end-to-end testen und Verantwortlichkeiten dokumentieren.】
You may lodge a complaint under Article 77 GDPR with a data protection supervisory authority, in particular at your place of residence, place of work or the place of the alleged infringement. The authority expected to be competent for the controller is:
【AUSFÜLLEN: nach endgültigem Firmensitz zuständige Datenschutzaufsichtsbehörde mit Anschrift und Website】
13. Automated decisions and AI results
Cinemura uses AI to generate media at the user’s instruction. This generation does not decide on rights, access to services, creditworthiness, employment or comparable personal matters. Based on the current functionality, no decision producing legal or similarly significant effects is made solely by automated means within the meaning of Article 22 GDPR.
AI results may be inaccurate, implausible or similar to third parties. Under the product design, they are identified as AI-generated. This labelling is not an automated assessment of depicted individuals.
14. Users in the United States
Cinemura is also intended for users in the United States. The applicability of the California Consumer Privacy Act, including the CPRA amendments, depends in particular on whether a for-profit entity does business in California and meets at least one statutory threshold. Based on the inflation-adjusted amounts effective since 1 January 2025, these include annual gross revenue exceeding USD 26,625,000, handling personal information of 100,000 or more California consumers or households per year, or deriving at least 50 per cent of annual revenue from selling or sharing personal information.
【PRÜFEN: Vor US-Launch und danach jährlich CCPA/CPRA sowie die Datenschutzgesetze aller aktiv bedienten US-Bundesstaaten anhand Nutzerzahlen, Umsatz, Geschäftstätigkeit, Datenverwendung und jeweils aktueller Schwellen bewerten. Bis diese Prüfung abgeschlossen ist, keine pauschale Nichtanwendbarkeit behaupten.】
Cinemura does not plan to sell personal data or share it for cross-context behavioural advertising. If that practice changes, the required notices and choices must be implemented in advance. Irrespective of statutory applicability, US users may use the contact routes described in Section 12.
15. Security
Measures intended for the Service include TLS-encrypted transmission, password hashing, short-lived access tokens, refresh-token rotation, role-based access, signed webhooks, access-controlled object storage, logging of security-relevant activity and regular backups. Security measures are reviewed and adjusted based on risk.
No transmission or storage is absolutely secure. In the event of a personal data breach, the statutory assessment, documentation and notification processes under Articles 33 and 34 GDPR apply.
16. Changes to this Policy
We update this Policy when functions, recipients, retention periods or the law change. The published version states its revision date. Material changes affecting an existing contractual or consent basis will be communicated in an appropriate manner.
Last updated: 【AUSFÜLLEN: Datum der Veröffentlichung】
The German version is legally authoritative. This English version is provided for information only.