Privacy Policy
Last Updated: July 11, 2026
This Privacy Policy is designed to comply with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Introduction
This Privacy Policy explains how Cine Power Planner collects, uses, stores, and protects your personal data when you use our application. We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR/DSGVO).
2. Data Controller
For any privacy-related inquiries, please contact us at the address above or through the Help section of the application.
Luca Zanner
Email: support@cine-power-planner.com
Website: https://cine-power-planner.com
For any privacy-related inquiries, you can reach us via the email address above, through the Help section of the application, or by postal mail to the address listed above.
3. Data We Collect
Local Data (Stored on Your Device):
- Project names, client information, and gear lists
- Contact names, roles, phone numbers, email addresses, and — where you enter them — postal and billing addresses, VAT identification numbers, bank details (IBAN), and agreed day rates
- Template data and device library items
- User preferences (theme, language, settings)
Cloud Data (When Signed In):
- Email address
- Profile information (display name, photo)
- Device identifier (for multi-device sync)
- Active session information
- Synchronized project and template data
- Subscription status and plan information (payment details are processed exclusively by Stripe)
- Shared project data, collaborator roles, presence indicators, and chat messages exchanged within shared projects
- Browser geolocation coordinates (only when you explicitly grant permission for weather or location features)
- Push notification subscription endpoint (if you opt in to browser notifications)
- Hashed password history (stored server-side to prevent password reuse; we never store plaintext passwords)
- Email notification preferences (whether you have opted in or out of transactional emails)
- Anonymous usage data: If you use the application without signing in, a one-way hash of your browser fingerprint and a project count are stored server-side to enforce free-tier limits. This hash cannot be used to identify you personally.
- Accessories store order history and shipping details (if you make purchases)
- Bank Transactions (if you use the Banking module): When you import bank transactions via CSV or camt.053, or enter them manually, we process: IBAN and BIC (your own bank account and counterparty), booking date, value date, signed amount and currency, purpose text (SEPA-Verwendungszweck), counterparty name, optional receipt attachment, source (manual / CSV preset / camt.053), and the link relationships you create between transactions and your invoices / Mahnungen / expenses. This data is necessary to reconcile payments against the invoices you issue and to fulfil the 10-year GoBD retention obligation under § 147 AO. You can provide it either by importing a CSV / camt.053 file your bank exports, or by using the optional direct bank connection (FinTS/HBCI), which retrieves your balance and transactions from your bank on your behalf (see Section 7).
- Accounting & Tax Data (if you use the business features): When you create quotes, invoices, order confirmations, delivery notes, expenses and receipts (including scanned receipt images and text extracted from them by on-device OCR), cash-book (Kassenbuch) entries, vendor bills, fixed-asset records, or recurring documents, we store these records. They embed personal data of your clients and suppliers (such as name, postal and billing address, email, VAT identification number, and — where you enter it — bank details / IBAN) as well as your own business and tax identifiers (Steuernummer, USt-IdNr, responsible tax office, and small-business / Kleinunternehmer status). This data is processed to produce your invoices and bookkeeping, to generate statutory tax reports and exports (EÜR, advance VAT return, DATEV, ELSTER), and to meet the 10-year GoBD retention obligation under § 147 AO.
- Electronic signatures: When you or a counterparty sign a contract, quote, or delivery / return note electronically, we store the drawn signature image together with the signer's name, the time of signing, and the IP address from which it was signed, as evidence of the agreement. Signing is performed entirely on our own infrastructure; no third-party e-signature provider is involved.
- Crew network & availability (if you use the crew-networking features): the connections you establish with other users, the professional contact details those users choose to share with you (name, email, photo), and any availability information and private scheduling notes you record about your contacts.
- Public rental catalogue & gear requests (if you publish a rental catalogue): when someone — with or without an account — submits a rental request through your public catalogue link or the in-app rental network, we store the requester's name, email address and, where provided, phone number, company, address and VAT ID, together with the requested items and rental period. We use these details to deliver the request to the catalogue owner and to send the requester the owner's quote and status updates by email (legal basis: Art. 6(1)(b) GDPR — steps taken at the requester's own request prior to entering into a contract). Requests that do not result in a rental (declined, expired or cancelled) are automatically deleted 90 days after they close.
- AI Agent Access (if you enable the Agent access feature): The access keys you issue to connect an AI agent are stored only as a salted hash, never in plaintext. We also keep a metadata-only activity log of the actions an agent performs on your behalf — the tool name, status, and timestamp only, never the content of your data. See Section 7 for how this feature exposes your data to the AI provider you choose.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR:
- Performance of a contract (providing the gear list service)
- Your explicit consent (for optional cloud synchronization)
- Legitimate interests (app functionality, security, technical maintenance)
- Legal obligations (compliance with applicable laws)
5. Data Storage and Security
Local-First Architecture: By default, all your data is stored locally on your device using IndexedDB and the Origin Private File System (OPFS). Your data never leaves your device unless you explicitly choose to sign in and enable cloud synchronization.
Cloud Storage: When you sign in, your data is synchronized to our self-hosted Supabase instance, hosted on Hetzner Cloud in Nuremberg, Germany. Data is encrypted in transit (TLS) and, on our servers, is protected by strict per-user access controls (row-level security). See the encryption note below for how data is protected at rest.
Encryption: On your device, sensitive records — including contacts, billing and invoicing data, expenses, your user profile, and rental and collaboration data — are encrypted at rest in IndexedDB using AES-GCM-256 with a key derived from your account, and remain encrypted in the corresponding cloud-sync payloads. If you use the optional direct bank connection, your bank-access credentials are additionally encrypted before storage. Other data stored on our servers is protected by transport encryption (TLS), strict per-user access controls (row-level security), and hosting exclusively in Germany.
Retention Period: We retain your data for as long as your account is active. Local data remains on your device until you delete it or perform a factory reset. When you delete an individual record such as a contact, its personal data is removed from cloud storage on the next synchronization; copies embedded in legally-retained documents (for example issued invoices, kept for 10 years under § 147 AO) are anonymized once that retention period ends.
Server Logs: Our web server records access logs (requested URL with sensitive query parameters redacted, HTTP status, user agent, and IP address) for security, abuse prevention, and technical troubleshooting. Logs are retained for a maximum of 52 days and then automatically deleted. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).
Data Deletion: You can request complete deletion of all your personal data by deleting your account through Settings or by contacting support@cine-power-planner.com. We will confirm deletion in writing upon completion.
Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the competent supervisory authority without undue delay, and in any case within 72 hours of becoming aware of the breach, in accordance with Art. 33 and Art. 34 GDPR.
6. Your Data Protection Rights
Under GDPR, you have the following rights:
Right to Lodge a Complaint: You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR. The competent supervisory authority is the data protection authority of the German state in which the data controller is established.
To exercise these rights, use the data management features in Settings or contact us through the Help section.
7. Third-Party Services
Supabase: We use a self-hosted Supabase instance (located in Germany) for cloud authentication and data synchronization. Data is processed on our own server and is not shared with Supabase Inc.
Hetzner Cloud: Our self-hosted Supabase infrastructure runs on Hetzner Cloud (Hetzner Online GmbH, Germany) in the Nuremberg data center. All synced user data is stored on this server. Hetzner acts as a hosting provider and does not access your data. Privacy Policy: https://www.hetzner.com/legal/privacy-policy/. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in reliable infrastructure).
Stripe: We use Stripe (Stripe Payments Europe, Ltd., Ireland) for payment processing and subscription management. When you subscribe to a paid plan, Stripe processes your payment information (email, card details, IP address) in accordance with their Privacy Policy: https://stripe.com/privacy. Legal basis: Art. 6(1)(b) GDPR (contract performance).
Transactional Email: We send transactional emails using our self-hosted SMTP server (hosted on the same Hetzner infrastructure as the application). Email types include: account welcome, collaboration invites, comment mentions, and subscription lifecycle notifications (started, renewal reminder, renewed, canceled). Your email address is used solely for these service-related communications. You can opt out of non-essential emails in Settings. No email data is shared with third-party email marketing services. Legal basis: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest in service communication).
Cloudflare Turnstile: We use Cloudflare Turnstile as a bot protection mechanism during sign-in and sign-up. Cloudflare may process your IP address and browser metadata to verify you are human. No cookies are set. Privacy Policy: https://www.cloudflare.com/privacypolicy/. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse).
Open-Meteo: We use Open-Meteo (Open-Meteo GmbH, Germany) for weather forecast data in the calendar and shoot planning features. When you use these features, GPS coordinates and your IP address are transmitted. Privacy Policy: https://open-meteo.com/en/terms. Legal basis: Art. 6(1)(a) GDPR (consent through voluntary use of the feature).
Nominatim / OpenStreetMap: We use the Nominatim geocoding service (OpenStreetMap Foundation, UK) to convert addresses into coordinates for location-based features. When you use these features, the queried address and your IP address are transmitted. Usage Policy: https://operations.osmfoundation.org/policies/nominatim/. Legal basis: Art. 6(1)(a) GDPR (consent through voluntary use of the feature).
OpenRouteService: We use OpenRouteService (HeiGIT gGmbH, Germany) for optional route planning and location features. When you use these features, your queried coordinates and IP address are transmitted. Privacy Policy: https://openrouteservice.org/privacy-policy/. Legal basis: Art. 6(1)(a) GDPR (consent through voluntary use of the feature).
Push Notifications: If you opt in, we use the Web Push API to send browser notifications about project updates, sync events, and maintenance reminders. Your push subscription endpoint and device information are stored in our Supabase database. To deliver each notification, the encrypted payload is relayed to your device through the push service operated by your browser vendor (e.g. Google for Chrome / Android, Mozilla for Firefox, Apple for Safari, Microsoft for Edge); some of these providers are located outside the EU (see Section 8). You can revoke push notification permissions at any time through your browser settings or the application's notification preferences. Legal basis: Art. 6(1)(a) GDPR (explicit consent).
Bank Connection (FinTS/HBCI): If you choose to connect a bank account for automatic transaction retrieval, the application connects directly to your bank's FinTS interface on your behalf through an encrypted gateway operated on our own server in Germany. The access credentials you provide are encrypted and used solely to retrieve your account balance and transactions at your request. We are not a payment service and cannot initiate payments or transfers. Your bank is the recipient of the connection under your existing banking relationship. Legal basis: Art. 6(1)(a) GDPR (explicit consent) and Art. 6(1)(b) GDPR (contract performance).
EU VAT Number Validation (VIES): When you validate a customer's VAT identification number, that VAT ID is transmitted to the European Commission's VIES service for verification. No other personal data is sent. The service is operated by the European Commission (EU). Legal basis: Art. 6(1)(c) GDPR (correct VAT treatment) and Art. 6(1)(f) GDPR (legitimate interest in accurate invoicing).
Electronic Tax Filing (ELSTER): If you use the electronic tax-filing feature, the tax data you choose to submit (such as the EÜR income statement or the advance VAT return) is transmitted to the German tax authority (Finanzamt) through the official ELSTER interface (ERiC), which runs on our own server in Germany. Your data is sent only to the tax authority and only when you actively submit a filing. Legal basis: Art. 6(1)(c) GDPR (legal tax obligation).
Malware Scanning: Receipt and document files you upload are scanned for malware on our own server before they are stored. File content is not shared with any third party. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service and data security).
Other Reference-Data Services: For convenience features the application retrieves public reference data — link previews for media you add to mood boards (via noembed) and public-holiday dates (via the OpenHolidays API). These requests are routed through our own server so that your IP address is not exposed to the upstream provider, and they carry no personal data beyond the content you supply (for example a media link). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in providing the feature).
AI Agent Access (Model Context Protocol): If you enable Agent access — an optional, subscription-gated feature — and issue an access key, you can connect a third-party AI agent of your choice (for example Claude Desktop or another MCP-compatible client) to Cine Power Planner. When you instruct that agent, our server, acting on your explicit consent (the separate “mcp_access” consent), exposes to it the data the agent requests, which may include your projects, gear, sub-rentals, contacts, and read-only accounting and banking records. The agent acts on your behalf: that data is transmitted to the AI provider that operates the agent you connect. This provider is an independent third party and a separate data controller whom we neither select nor control; its processing of your data is governed by that provider's own terms and privacy policy, and — depending on the provider you choose — may involve a transfer outside the EU/EEA (see Section 8). Access is strictly opt-in, requires an active subscription, is technically limited to your own data by per-user access controls (an agent can never reach another user's data), and you can revoke any key at any time under Settings → Account → Agent access. We retain a metadata-only audit log of agent actions (tool name, status, and timestamp — never the content of your data) for security and abuse prevention; it is automatically deleted after 180 days and immediately upon account deletion. Legal basis: Art. 6(1)(a) GDPR (explicit consent).
No Tracking: We do not use Google Analytics, Facebook Pixel, or any other tracking services.
No Advertising Cookies: We do not use cookies for advertising or profiling purposes.
8. International Data Transfers
Your data is processed predominantly within the European Union (Germany). Transfers to third countries outside the EU/EEA occur only in these cases: (1) Cloudflare Turnstile (USA — processes only your IP address and browser metadata on the sign-in and sign-up forms); and (2) if you opt in to browser push notifications, the encrypted notification payload is relayed to your device through your browser vendor's push service (e.g. Google, Apple, Microsoft, Mozilla), some of which are located in the USA. These transfers are covered by EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Stripe (Ireland) and all other services (Supabase self-hosted, Hetzner Germany, Open-Meteo Germany, OpenRouteService Germany, EU VIES, Nominatim UK under Art. 45 adequacy) are based in the EU/UK.
AI Agent Access: If you connect a third-party AI agent via the optional Agent access feature (Section 7), the data the agent requests is transmitted to the AI provider you choose to operate it. Where that provider is located outside the EU/EEA (for example in the USA), this is an international transfer that you initiate by connecting the agent and that is based on your explicit consent pursuant to Art. 49(1)(a) GDPR. Because you select the provider, you are responsible for choosing one whose level of data protection you consider adequate.
9. Data Processing Agreements
Where required under Art. 28 GDPR, we have entered into Data Processing Agreements (Auftragsverarbeitungsverträge / AVV) with our third-party data processors, including Stripe, Hetzner, and Cloudflare. Our Supabase infrastructure is self-hosted on a server in Germany (Hetzner Cloud, Nuremberg), minimizing third-party data transfers.
10. Cookies and Local Storage
We use browser localStorage, sessionStorage, and IndexedDB to save your data locally. A device identifier is stored to enable multi-device synchronization when you choose to sign in. An encryption salt is stored in localStorage to protect sensitive data at rest. sessionStorage is used for temporary data such as form drafts, conflict resolution history, and dismissed alerts — this data is automatically cleared when you close the browser tab. To enforce free-tier project limits for visitors who are not signed in, a single first-party cookie that stores only a usage counter (no personal data) is set and may persist up to 10 years. No third-party cookies are used.
11. Children's Privacy
Cine Power Planner is not directed at children under the age of 16. At sign-up, every user must actively confirm they are at least 16 years old (Art. 8 GDPR). We do not knowingly collect personal data from children under 16. If you become aware that a child under 16 has provided us with personal data, please contact us at support@cine-power-planner.com. If we become aware that we have collected personal data from a child under 16, we will take steps to delete such data promptly. Parents or legal guardians who believe their child has registered an account without their consent may request immediate account deletion via the same address.
12. Automated Decision-Making
Cine Power Planner does not use automated decision-making or profiling as defined by Art. 22 GDPR. No decisions with legal or similarly significant effects on you are made based solely on automated processing of your personal data.
13. Optional AI Features (Bring Your Own Key)
Cine Power Planner offers optional AI-assisted features (parsing rental quotes, reading expense receipts) that are disabled by default. They only become active after you explicitly enable them in the settings, acknowledge a consent notice (legal basis: your consent, Art. 6(1)(a) GDPR), and connect your own API key for an AI provider of your choice. You can withdraw this consent at any time with effect for the future by disabling the features or removing your key in the settings.
When you actively use an AI feature, the content you submit (for example quote text or a receipt image, which may itself contain personal data) is transmitted directly from your device to the provider you selected — Anthropic PBC (Claude), OpenAI (GPT), or Google (Gemini) — under your own account and contract with that provider. The chosen provider’s own privacy policy and terms apply to this processing; we have no access to your provider account, and the AI request itself does not pass through and is not stored on our servers. Sole technical exception: requests to OpenAI are relayed in-flight through our server because browsers cannot reach the OpenAI API directly — the content and your key are forwarded immediately and are never stored or logged. The results returned by the provider (for example extracted quote items or receipt fields) — and, for receipt scans, the receipt file you attach — then become part of your normal application data: they are stored locally on your device and, if you have enabled cloud synchronization, also on our servers as described in Sections 3 and 5. Alternatively, in the native apps you can run an on-device model (Gemma), in which case no content leaves your device for the AI processing itself.
Your API keys are encrypted on your device with your account password (AES-256-GCM; the password never leaves your browser) before being stored — our server only ever holds ciphertext it cannot decrypt. You can delete stored keys at any time in the settings, which also removes the server-side ciphertext.
14. Contact Information
For any privacy-related questions or to exercise your data protection rights, please contact us through the Help section in the application, email support@cine-power-planner.com, or write to the postal address listed under Section 2.
- Email: support@cine-power-planner.com
- In-App: Help section within Cine Power Planner
We aim to respond to data protection requests within 30 days as required by Art. 12(3) GDPR.
Identity Verification: Before fulfilling requests for access, rectification, erasure, or data portability, we may need to verify your identity to prevent unauthorized disclosure — typically by asking you to submit the request from the email address associated with your account. This additional processing is based on Art. 6(1)(c) GDPR in conjunction with Art. 12(6) GDPR.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any significant changes by updating the "Last Updated" date at the top of this policy. Please review this policy periodically.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after update constitutes acceptance of the revised policy.
