Privacy Policy
Effective date: May 11, 2026
1. Who We Are
This Privacy Policy explains how Spooky House Studios UG (haftungsbeschränkt) ("Company", "we", "us", or "our") collects, uses, and protects your personal data when you use the Reel Zap service (the "Service").
Spooky House Studios UG (haftungsbeschränkt)
Otto-Schmidt-Str. 9, 04425 Taucha, Deutschland
Amtsgericht Leipzig, HRB 26050
Email: privacy@reelzap.app
We are the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) and applicable German data protection laws.
2. Information We Collect
2.1 Information You Provide
- Account information: When you create an account, we collect your name, email address, and authentication provider (Google, Apple, or email/password).
- User Content: Videos, audio files, and other media you upload for processing.
- Communications: When you contact us via email or in-app support.
2.2 Information Collected Automatically
- Usage data: How you interact with the Service (features used, pages visited, actions taken).
- Device information: Device type, operating system, app version, language settings.
- Analytics data: We use Firebase Analytics (Google) to collect anonymized usage statistics.
- Push notification tokens: Device tokens for delivering push notifications (FCM).
2.3 Information from Third Parties
- Authentication providers: When you sign in via Google or Apple, we receive your name and email address from the respective provider.
- Payment information: Subscription and payment data is processed by Apple App Store or Google Play Store. We do not receive or store your credit card or payment details.
3. How We Use Your Information
We use your personal data for the following purposes:
- Providing the Service: Processing your videos, generating clips, managing your account.
- Authentication: Verifying your identity and managing access to your account.
- Communications: Sending you push notifications about completed jobs, service updates, and important notices.
- Improvement: Analyzing usage patterns to improve the Service (using anonymized analytics data).
- Security: Detecting and preventing fraud, abuse, and security incidents.
- Legal compliance: Fulfilling our legal obligations under applicable laws.
4. Legal Basis for Processing (GDPR)
Under the GDPR, we process your personal data based on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR): Processing necessary to provide the Service you requested (account management, video processing, subscriptions).
- Legitimate interests (Art. 6(1)(f) GDPR): Analytics, service improvement, fraud prevention, and security.
- Consent (Art. 6(1)(a) GDPR): Push notifications (you can opt out at any time through your device settings).
- Legal obligation (Art. 6(1)(c) GDPR): Where we are required by law to process your data.
5. How We Share Your Information
We do not sell your personal data. We share your data only with the following categories of recipients:
- Cloud infrastructure providers: Google Cloud Platform (for data storage, video processing, and AI services). Data is processed in the EU/US under Google's GDPR-compliant data processing terms.
- AI service providers: Google Vertex AI (for video analysis and transcription). Your uploaded content is processed but not used for training AI models.
- Authentication providers: Firebase Authentication (Google) for user sign-in.
- Analytics: Firebase Analytics (Google) for anonymized usage statistics.
- Push notifications: Firebase Cloud Messaging (Google) for delivering notifications.
- Subscription management: RevenueCat for managing in-app subscriptions.
- Law enforcement: When required by law, court order, or to protect our legal rights.
6. Data Retention
- Account data: Retained as long as your account is active. Deleted when you delete your account.
- User Content (videos, clips): Automatically deleted 5 days after processing. You may also delete your content at any time through the app.
- Analytics data: Retained in anonymized form for up to 14 months (Firebase Analytics default).
- Logs: Server logs are retained for up to 30 days for debugging and security purposes.
7. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You can request a copy of your personal data.
- Right to rectification (Art. 16): You can request correction of inaccurate data.
- Right to erasure (Art. 17): You can request deletion of your data ("right to be forgotten"). You can delete your account through the app settings.
- Right to restrict processing (Art. 18): You can request that we limit how we use your data.
- Right to data portability (Art. 20): You can request your data in a machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us at privacy@reelzap.app. We will respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Sächsischer Datenschutzbeauftragter (Saxon Data Protection Commissioner).
8. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (Google Cloud infrastructure). Such transfers are protected by:
- EU-US Data Privacy Framework (where applicable);
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Google Cloud's GDPR-compliant data processing addendum.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (HTTPS/TLS) and at rest;
- Access controls and authentication;
- Regular security reviews;
- Automatic deletion of processed content after 5 days.
However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Children's Privacy
The Service is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16 without parental consent, we will delete that data promptly. If you believe a child under 16 has provided us with personal data, please contact us at privacy@reelzap.app.
11. Cookies and Tracking
The Reel Zap mobile app does not use browser cookies. We use Firebase Analytics for anonymized usage tracking within the app. You can opt out of analytics data collection through your device settings.
Our website (reelzap.app) may use essential cookies for basic functionality. We do not use advertising or tracking cookies on our website.
12. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the Service or by email. The "Effective date" at the top of this page indicates when the policy was last updated.
14. Contact
If you have questions about this Privacy Policy or your personal data, contact us at privacy@reelzap.app. Our full company details are listed in Section 1 above.