Legal
Privacy Policy
Last updated: 12 August 2026. This notice describes how personal data is handled when you use Naga Films Studio (the “Service”), and how we disclose AI use under the EU Artificial Intelligence Act. It follows GDPR transparency rules and security expectations aligned with OWASP guidance (minimize data, protect credentials, limit processors, and avoid unnecessary retention or disclosure).
1. Controller
Maurice Holda
Bei Schuldts Stift 2
20355 Hamburg, Germany
Email: chosenfewrecords@hotmail.de
This is a small sole-trader operation (Kleinstunternehmer), not a registered GmbH/UG. No separate data protection officer is appointed. For privacy requests, contact the email above.
2. What we collect
We only collect data needed to run the Service:
- Account data — email address; password stored only as a one-way hash (never plaintext); optional name if provided via OAuth.
- Session data — authentication session / JWT cookies (httpOnly where applicable) to keep you signed in.
- Credits & billing metadata — wallet balance, credit transactions, and Stripe checkout / payment references. We do not store full card numbers; Stripe processes payments.
- Generation activity — prompts, parameters, status, and resulting media URLs or job IDs needed to fulfill generation requests and credit accounting.
- Technical logs — short-lived server logs (e.g. errors, request timing). We do not intentionally log passwords, API keys, or full payment payloads.
3. Why we process data (purposes & legal bases)
- Provide the Service (Art. 6(1)(b) GDPR) — create accounts, authenticate you, run generations, manage credit packs, and show balances.
- Payments (Art. 6(1)(b)) — process one-time credit pack purchases via Stripe.
- Security & abuse prevention (Art. 6(1)(f)) — protect accounts, detect fraud or misuse, and keep the platform available (OWASP: spoofing, tampering, elevation of privilege).
- Legal obligations (Art. 6(1)(c)) — retain limited records where bookkeeping or tax rules require it.
4. Processors & third parties
We use subprocessors only to operate the Service. They receive the minimum data required:
- Neon — PostgreSQL hosting for accounts, sessions, wallets, and generation records.
- Stripe — payment processing for credit packs. Card data is handled by Stripe under their terms; we store payment status and related IDs, not PAN/CVC.
- MuAPI (and underlying model providers) — generation requests (prompts / media inputs) are sent server-side using our operator API key so the Service can produce outputs. Do not submit secrets or unnecessary personal data in prompts.
- Optional OAuth providers (Google / GitHub, if enabled) — account email / profile fields they return when you choose to sign in that way.
- Hosting — the app may be deployed on infrastructure such as Vercel; request metadata is processed as part of delivery.
Server secrets (e.g. MUAPI_API_KEY, Stripe secret keys, database URL) stay on the server and are not exposed to the browser.
5. Cookies & similar technology
We use essential cookies / storage for authentication and session continuity. We do not use advertising trackers or third-party marketing pixels on the core Studio surfaces. You can clear cookies in your browser; doing so will sign you out.
6. Retention
- Account and wallet data — while your account exists, then deleted or anonymized on request where legally possible.
- Payment-related records — as long as required for accounting / dispute handling.
- Studio gallery (Image, Video, Lip Sync, Cinema, Marketing) — not stored on our servers; history is kept in your browser's local storage only. Download files you want to keep.
- Storyboard projects — held with our generation provider while the project exists; deleted when you remove the project.
- Security logs — short retention for operations and abuse investigation.
7. International transfers
Some processors may process data outside the EEA (for example US-based payment or hosting providers). Where that occurs, we rely on appropriate safeguards such as the provider’s standard contractual clauses or equivalent mechanisms described in their privacy documentation.
8. Your rights
Under the GDPR you may request:
- Access to your personal data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”), subject to legal retention
- Restriction of or objection to certain processing
- Data portability for data you provided
- Complaint to a supervisory authority (in Germany, typically your state data protection authority or the BfDI)
To exercise these rights, email chosenfewrecords@hotmail.de. We may need to verify your identity before acting on a request.
9. EU AI Act transparency
Naga Films Studio is a generative production tool. Image, video, cinema, and lip-sync outputs are produced by AI systems (third-party models accessed via our operator integration). We act as a deployer of those generative systems toward end users of the Service, and as the operator of the Studio application offered in the EU.
What this means for you
- AI-generated content — Content you create in the Studio is artificially generated or manipulated by AI. It is not a human-captured photograph or recording unless you separately supply one as an input.
- No chatbot impersonation — The Studio is an authoring tool. We do not operate a system that pretends to be a human in conversation with the public.
- Deepfakes & publishing — If you publish or share image, audio, or video that depicts real persons in a way that could constitute a deepfake, EU law may require you (as publisher/deployer of that content) to disclose that it was artificially generated or manipulated, except where a legal exemption applies (for example certain artistic/satirical contexts with appropriate disclosure).
- Public-interest text — If you use AI-generated text to inform the public on matters of public interest, disclose that it is AI-generated unless it has undergone human review and editorial responsibility.
- Machine-readable marking — Article 50(2) requires providers of systems that generate synthetic audio, image, video, or text to mark outputs in a machine-readable way where technically feasible. Upstream model providers and our generation pipeline are evolving toward these marks. Where a provider supplies watermarks, C2PA/manifests, or similar signals, we aim to preserve them; full coverage across every model is not guaranteed today. Obligations apply from 2 August 2026, with a limited grace period to 2 December 2026 for certain marking duties on systems already on the market before that date.
- Risk posture — The hosted Studio is intended for creative / production use. It is not offered as a prohibited AI practice under Article 5, and it is not marketed as a high-risk AI system under Annex III (e.g. employment, law enforcement, critical infrastructure). If your use case would classify as high-risk, you must not use the Service for that purpose without your own conformity assessment and legal review.
Contact for AI transparency questions: chosenfewrecords@hotmail.de.
10. Security practices (OWASP-aligned)
We design the Service to reduce common web risks, including:
- Password hashing (no plaintext passwords)
- Server-side authorization for admin and wallet actions
- Parameterized database access (no string-concatenated SQL)
- Secrets kept out of the client and out of routine logs
- Generic client error messages (no stack traces or secret leakage)
- Payment card data handled by Stripe, not stored in our database
No method of transmission or storage is perfectly secure. If you discover a vulnerability, please report it privately to the contact email above.
11. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has registered, contact us to remove the account.
12. Changes
We may update this policy when the Service or legal requirements change. The “Last updated” date at the top will change accordingly. Continued use after a material update constitutes acceptance of the revised notice where permitted by law.
13. Related
Provider identification (Impressum): /impressum