Privacy Policy (Consumers)
For consumers (B2C)Effective: 28.08.2026
1. Controller
The controller within the meaning of the GDPR is the operating company:
Provider / operating company (§ 2 DDG) / controller within the meaning of the GDPR:
Teaser-Factory UG (haftungsbeschränkt) i.G.
Fehrbelliner Straße 57, 10119 Berlin, Deutschland
Company register: Not yet entered in the German commercial register — the company is currently in formation (UG i.G.).
Represented by the managing director (CEO): Alexander Ratter
E-Mail: info@teaser-factory.de
Picco-AI was developed in collaboration with the film production company Picco-Studio (picco-studio.com).
2. Data processed, purposes & legal bases
We process personal data only to the extent necessary to provide and bill the software: account/license data (name, email, license key, plan, subscription status) for performance of the contract (Art. 6(1)(b) GDPR); technical usage/activation data for license verification and abuse prevention (Art. 6(1)(f) GDPR); and voluntary information (e.g. support requests, newsletter with consent, Art. 6(1)(a) GDPR).
3. License server, activation & heartbeat
For paid plans, the software contacts our license server to verify the key and entitlement. These requests never contain your project content. For license verification and abuse prevention we process your IP address, a device fingerprint (to bind the license to devices — not a biometric identifier), the app/browser version and activation/heartbeat timestamps. The legal basis is our legitimate interest in preventing misuse (Art. 6(1)(f) GDPR). IP addresses from heartbeats are automatically anonymised after no more than 30 days; administrators access them only on concrete suspicion of license misuse.
License keys are stored server-side to enable validation; in server logs they appear only as a shortened hash, and logs contain no project content.
Beyond license verification, no behavioural tracking or profiling takes place. The software does not transmit your project content, inputs or usage patterns to us for analytics or advertising purposes.
Connectivity check. If a connection to our server fails, the software performs a one-off check of general internet reachability against neutral connectivity endpoints (Cloudflare 1.1.1.1, Google DNS). No account, license or content data is transmitted; for technical reasons the respective operator sees the IP address of your connection.
Support diagnostics upload (only at your request). If you expressly trigger the sending of a support report in the app, the software transmits to our server: an excerpt of the technical application log, the most recent locally stored error records, your message, your account email address and a shortened identifier of your license key. We use this data exclusively to handle your support request (Art. 6(1)(b) GDPR) and delete it once it is no longer required for that purpose. No support report is transmitted without your express action.
4. Payment processing — Paddle or app store (Merchant of Record)
Purchases via our website are processed by Paddle.com Market Ltd. (United Kingdom) as Merchant of Record. In this respect Paddle is an independent controller for payment and order data and not our processor. Data transmitted during checkout (name, email, payment method, billing address, location for tax determination where applicable) is processed by Paddle under its own responsibility. From Paddle we receive order/subscription status and a customer and subscription identifier. The transfer to the United Kingdom is covered by the EU Commission's adequacy decision (renewed on 19 Dec 2025, valid until 27 Dec 2031). Paddle's privacy notice:
If the purchase is instead made via an app store (e.g. Apple App Store or Microsoft Store — intended for consumer/B2C plans), the respective store operator (e.g. Apple Distribution International Ltd., Ireland) is the Merchant of Record and an independent controller for the payment and order data under its own privacy terms. In that case we only receive a purchase/subscription status and a transaction/subscription identifier provided by the store to unlock the license — no payment data.
5. AI generation (managed / optional local) & local processing
The control and orchestration of the app run locally on your device. For the regular plans, the AI generation of video, stills, music and AI voice-over is provided as a managed service via your Picco-AI subscription: the inputs required for generation (e.g. your prompts, reference images and texts to be voiced) are transmitted from your device via our generation proxy (our license/web server) to the upstream AI services used, and are processed there under our accounts — currently: Google (video, image and music generation — Veo, Nano Banana, Lyria), Anthropic PBC (reasoning engine) and ElevenLabs Inc. (speech synthesis, see section 5a). Our API credentials remain server-side; you never receive them. We do not permanently store this generation content on our servers; for billing and quota purposes we process only usage metadata (e.g. the number and extent of generations), not the content itself. The legal basis is performance of the usage contract (Art. 6(1)(b) GDPR).
Optionally, in addition to the managed service, you can connect a local AI model via Ollama (for Phase 1 / concept steps). A local model runs fully offline on your device; this content never leaves your computer and we do not receive it.
Third-country transfer (managed service). Managed generation involves a transfer to the USA. We base it on appropriate safeguards under Art. 44 et seq. GDPR: Google LLC and ElevenLabs Inc. are certified under the EU-US Data Privacy Framework; for Anthropic PBC, Standard Contractual Clauses apply or — where certified — likewise the EU-US Data Privacy Framework. We provide the current, complete list of (sub-)processors and service partners used on request (info@teaser-factory.de); we notify B2B customers of changes as part of the data-processing relationship (see section 6 of the B2B version). The optional local Ollama model involves no transfer at all — processing stays entirely on your device.
If you include personal data of third parties in your briefs, reference images or other inputs (e.g. recognisable faces, names or other identifying features), you are generally responsible under data protection law for this as the uploader yourself. You warrant that you are authorised to process and pass on this content to our managed AI infrastructure (e.g. because the depicted individuals have consented) and that you are not infringing any third-party rights. Please do not upload special categories of personal data (Art. 9 GDPR, e.g. health, religious or political content of identifiable individuals) unless you have a separate, sufficient legal basis for doing so.
5a. AI voice output, voice clones & voice data (ElevenLabs)
Managed voice-over. In the regular plans, AI voice output is part of the managed service: the text to be voiced is transmitted from your device via our generation proxy to ElevenLabs Inc. (USA) and processed there under our account; in this respect ElevenLabs is our sub-processor. We do not permanently store the generated audio content on our servers and process only usage metadata for billing (e.g. the time and extent of a request). ElevenLabs Inc. is certified under the EU-US Data Privacy Framework (see section 5).
Voice clones (Professional Voice Cloning) — own ElevenLabs account only. Creating individual AI voices from uploaded audio material ("voice clone") is not part of the managed service. For this you connect your own ElevenLabs account; the uploaded audio material is transmitted directly from your device to ElevenLabs and processed there under your account, subject to the ElevenLabs terms and privacy notices. We receive neither your audio material nor your voice clones; we do not store your ElevenLabs key in plain text on our servers. Under its own terms, ElevenLabs permits Professional Voice Cloning exclusively for the verified own voice of the account holder; the app requires an express, logged consent confirmation before every cloning operation.
Voice data is personal data. Recordings of a human voice are personal data within the meaning of Art. 4(1) GDPR; in the view of the European Data Protection Board, voice data is in principle biometric data (EDPB Guidelines 02/2021, para. 31). Where it is processed for the purpose of uniquely identifying a natural person, it is additionally subject to the special protection of Art. 9 GDPR. The voice model generated from the recordings may itself be personal data as well.
You are responsible for third-party voices. If you upload another person's voice material, you are the controller for that processing under data protection law. The legal basis is as a rule the express consent of the voice owner under Art. 6(1)(a) and, where Art. 9 GDPR applies, additionally under Art. 9(2)(a) GDPR. You must obtain this consent yourself, inform the voice owner pursuant to Art. 13 or 14 GDPR and be able to demonstrate consent pursuant to Art. 7(1) GDPR; we cannot do this for you. If the voice owner withdraws consent (Art. 7(3) GDPR), cease use without undue delay and arrange for the voice clone to be deleted, including in your ElevenLabs account. Further details are set out in our Terms and the Terms for businesses.
Third-country transfer with your own account (BYOK). If you use your own ElevenLabs account (voice clones, optional BYOK operation), the lawfulness of that transfer to the USA and the safeguards applying to it are governed by the contractual relationship between you and ElevenLabs. Before use, please review the ElevenLabs privacy notices and terms of use (elevenlabs.io) — in particular their voice-cloning requirements. Section 5 applies to the managed path.
Abuse control. Upon reasonable suspicion of abusive use (e.g. cloning the voice of a real person without their consent) or upon a substantiated complaint by an affected person, we may block the speech-synthesis feature for the account concerned. The legal basis is our legitimate interest in preventing unlawful use and protecting the rights of third parties (Art. 6(1)(f) GDPR) and the performance of our contractual obligations (Art. 6(1)(b) GDPR).
7. Email & newsletter
License, trial and subscription confirmation emails are sent via our hosting provider's email server; transactional emails about payments (receipts, subscription changes) are sent by Paddle. A newsletter is sent only after express consent (double opt-in) and can be unsubscribed at any time.
8. Recipients & processors
Hosting of the web/license server (virtual server) by webgo GmbH, Wendenstraße 8–12, 20097 Hamburg (Germany), as processor within the EU; a data processing agreement under Art. 28 GDPR is in place. For managed AI generation we use the upstream AI services named in section 5 (Google, Anthropic PBC, ElevenLabs Inc.) as service partners or sub-processors; we provide the current list on request. Payments are processed — depending on the purchase channel — by Paddle.com Market Ltd. or the respective app-store operator as independent controllers (see section 4). We do not sell personal data.
9. Storage period
We store personal data only for as long as it is necessary for the respective purpose (Art. 5(1)(e) GDPR). The following periods are implemented in our automated deletion job and enforced daily:
- Account and license data — for as long as the account is active. After the contract ends we delete it once the standard limitation period expires (three years from the end of the year in question, sections 195, 199 German Civil Code).
- Trial data — 30 days after the trial period expires, if no conversion occurs.
- Web server logs (server access and error logs, containing the IP address) — 8 days; they are rotated daily and deleted after seven generations.
- Abuse-prevention logs (request counters, expired session data, geo lookup cache — each containing the IP address) — 7 days.
- Download logs — the IP address is removed after 7 days. The remaining row contains only date, platform and version and no longer relates to an identifiable person.
- Application error telemetry (error message, pipeline step, app version, operating system) — 90 days. This data contains no IP address; the license key appears only as a hash value.
- IP addresses from license heartbeats — anonymised after no more than 30 days (see section 3). The remaining heartbeat data is retained for license verification.
- Newsletter — profile data (email address and any stated interests) is deleted within 30 days of your unsubscription. A sign-up that is not confirmed via the confirmation link within 14 days is deleted in full. We keep the record of your consent separately and in pseudonymous form only (email address as a hash value, time of consent) — until the standard limitation period of three years from the end of the year in question expires. We do so because we must be able to demonstrate a consent that was given (Art. 5(2), Art. 7(1) GDPR). You cannot be contacted from this record.
- Usage and quota data (number and extent of productions, for billing your plan) — until the standard limitation period of three years from the end of the year in question expires.
- Administration log (which administrative actions were carried out and when — our accountability record) — until the end of the year following the entry.
Where a statutory retention obligation applies to us, it takes precedence over erasure (Art. 17(3)(b) GDPR). This mainly concerns accounting vouchers and invoices: accounting vouchers must be kept for eight years, commercial and business letters for six years, and commercial books and annual accounts for ten years — in each case from the end of the calendar year (section 147 German Fiscal Code, section 257 German Commercial Code, section 14b German VAT Act). Your invoices, however, are issued by Paddle as Merchant of Record, so voucher retention rests there (see section 4). While a retention obligation is running, we restrict processing of the affected data instead of deleting it (section 35 German Federal Data Protection Act): it is then kept solely for the retention purpose and no longer used for advertising, analysis or contract handling.
If you request erasure of your data (Art. 17 GDPR), we carry it out within one month at the latest (Art. 12(3) GDPR). An entry in the administration log remains as evidence that the erasure was carried out; your email address appears in it only as a hash value.
10. AI transparency
Outputs created with the software are AI-generated or AI-modified content. We mark exported media machine-readably as artificially generated (IPTC Digital Source Type, C2PA provenance — Art. 50(2) EU AI Act). Details: AI transparency.
11. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21), as well as the right to withdraw a given consent at any time. An email to info@teaser-factory.de is sufficient to exercise these rights.
You also have the right to lodge a complaint with a data-protection supervisory authority — e.g. the Berlin Commissioner for Data Protection and Freedom of Information (competent for the operating company's registered seat in Berlin), or the supervisory authority at your place of residence.
12. Cookies, security & changes
We use technically necessary session cookies (e.g. for login and CSRF protection); these are required for operation and do not require consent. For anonymous reach measurement we additionally use Google Analytics 4 (provider: Google Ireland Ltd., Ireland) — but exclusively after your express consent (Art. 6(1)(a) GDPR). Without consent, no analytics cookies are set and no contact with Google is made (Google Consent Mode v2, default "denied"). You can withdraw your consent at any time via the cookie settings with effect for the future. As part of the analysis, data may be transferred to Google, including to the USA; Google LLC is certified under the EU-US Data Privacy Framework.
If you reach us via the referral link of a sales or affiliate partner, we additionally set a first-party cookie "tf_ref" (stored for the duration of the browser session). It contains only a non-personal partner identifier and serves solely to correctly attribute a resulting purchase to the referring partner (commission accounting). The cookie contains no personal data, is only set when you arrive via such a partner link, and is not used for advertising or cross-site tracking.
We implement appropriate technical and organizational measures (TLS/HTTPS, password hashing, CSRF protection, prepared statements, rate limiting). Payment processing is handled exclusively by Paddle — raw payment data never reaches our servers. This notice may be adapted to the further development of the service; the current version is always available at this address.
The German version is authoritative; the English version is a non-binding translation.
© 2026 Picco-AI · Teaser-Factory UG (haftungsbeschränkt) i.G., Berlin