Privacy Policy

Last updated: February 9, 2026

This is an English translation provided for your convenience. Only the German version of this document is legally binding.

high5 ventures GmbH ("we", "us", "our") operates FilmFlow Pro. This privacy policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR).

1. Data Controller

The data controller responsible for processing your personal data is high5 ventures GmbH, Speicherstr. 1, 60327 Frankfurt, Germany. You can reach us at contact@filmflow.pro.

2. Data We Collect

Account Data

When you create an account, we collect your email address, name, and a hashed version of your password. We also store your preferred language and theme settings.

Project Content

Data you create within your projects, including scripts, storyboard images, shot coverage, schedules, budgets, locations, comments, and team memberships.

Activity & Security Data

We log security-relevant events such as login attempts, password changes, and email verifications, including IP addresses and timestamps. These audit logs help us detect unauthorized access.

UI Preferences

Certain interface preferences (e.g., playback speed, overlay toggles, sidebar state) are stored in your browser's localStorage. This data never leaves your device and is not personal data.

3. Legal Bases for Processing

Contract Performance (Art. 6(1)(b) GDPR)

Processing your account data and project content is necessary to provide the FilmFlow Pro service you signed up for.

Legitimate Interest (Art. 6(1)(f) GDPR)

We process security and audit data to protect our service, prevent fraud, and ensure system integrity.

Consent (Art. 6(1)(a) GDPR)

Optional AI-powered features (such as automatic scene title generation via Google Gemini) are only activated at your explicit request. You can use FilmFlow Pro without these features.

4. Third-Party Processors

Supabase

Cloud database and image storage (storyboard frames). Servers located in the EU.

Google Cloud / Gemini

AI scene analysis (scene title generation). Script text is sent to the Google Gemini API only when you explicitly trigger this feature.

Vercel

Application hosting and edge network. Requests may be processed at the nearest edge location.

SMTP Provider

Transactional emails (verification, password reset, call sheet delivery, team invitations).

5. Cookies & Local Storage

We use a single essential session cookie (NextAuth, HTTP-only, secure) to keep you logged in. We do not use tracking cookies, advertising cookies, or analytics. Browser localStorage is used only for non-personal UI preferences.

6. Data Retention

Account data is retained as long as your account is active. Audit and security logs are retained for 90 days. If you delete your account, all personal data is purged within 30 days. Project data shared with team members may be retained in the project context until the project owner deletes it.

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access — obtain a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure — request deletion of your data
  • Right to restriction — limit how we process your data
  • Right to data portability — receive your data in a structured format
  • Right to object — object to processing based on legitimate interest

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence or our registered office (Hessen, Germany).

8. Data Security

We protect your data with encryption in transit (HTTPS/TLS), bcrypt password hashing, short-lived JWT authentication tokens, rate limiting on sensitive endpoints, and security headers (CSP, X-Frame-Options, Referrer-Policy). We regularly review and update our security measures.

9. International Data Transfers

Our primary infrastructure is hosted in the EU. Some processors (Vercel, Google) may process data outside the EU. These transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Children

FilmFlow Pro is not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

11. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email or an in-app notification. The "last updated" date at the top reflects the most recent revision.

12. Contact

If you have questions about this privacy policy or wish to exercise your rights, please contact us at:

contact@filmflow.pro

© 2026 high5 ventures GmbH