Legal information
Privacy policy
Which data we process on splatastic.com and in the app, why, where it is stored, who receives it and how long we keep it.
Last updated: 16 September 2026
Controller
The controller responsible for processing personal data on splatastic.com and in the Splatastic app is:
Schuhegger Ventures GmbH
Grünbeckstraße 6
93049 Regensburg
Germany
Managing director: Lukas Schuhegger
Amtsgericht Regensburg, HRB 22443
Email: hallo@splatastic.com
We have not appointed a data protection officer because the legal requirements for doing so are not met. You can reach us with any data protection question at the address above. The supervisory authority responsible for us is theBavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach.
Scope and our two roles
This policy covers everything that runs under splatastic.com:
- the public pages, such as this one
- the Splatastic app (sign-in, captures, administration), which is available at the same address
- shared views under
splatastic.com/s/…and the API through which partners commission captures
We keep two roles apart:
For your account, sign-in and contact data, we are the controller. We decide ourselves why and how we process this data. Most of this policy is about this role.
For content uploaded on behalf of a company or through a partner, we are a processor. This includes videos, images and everything created from them — including people who happen to be visible in a capture. The commissioning party decides about this data; we process it only on their instructions and on the basis of a data processing agreement under Art. 28 GDPR. If you appear in such a capture and want to exercise your rights, please contact the commissioning party. On request, we will tell you who to contact.
Your rights
You have the following rights towards us, provided the legal requirements are met:
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability in a common, machine-readable format (Art. 20 GDPR)
- Objection to processing based on a legitimate interest (Art. 21 GDPR)
Your right to object: where we process data on the basis of a legitimate interest (Art. 6(1)(f) GDPR), you may object to this processing at any time on grounds relating to your particular situation. We will then stop processing the data concerned unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.
You can delete captures, versions and sites yourself in the app. We delete your account on request; for this and any other concern, an informal message to the email address above is enough.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your habitual residence.
Public pages
Hosting and server logs
splatastic.com runs on servers of Hetzner Online GmbH in Germany. When you open a page, the web server processes technically necessary connection data, in particular your IP address, the requested address, date and time, browser type and the referrer sent by your browser. We need this data to deliver the pages and protect them against attacks; we only analyse the logs to investigate faults and abuse.
The legal basis is our legitimate interest in a secure and available website (Art. 6(1)(f) GDPR).
Contact by email
If you write to us, for example to request access, we process the information in your message in order to reply. The legal basis is Art. 6(1)(b) GDPR if your request aims at a contract, otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). We delete your enquiry once it has been dealt with, unless statutory retention obligations apply; business correspondence is subject to commercial and tax retention periods of six and ten years.
What the public pages do not do
- They set no cookies and keep no visitor statistics.
- They embed no third-party services — no analytics tools, no maps, no Google fonts. We serve all fonts from our own server.
- We carry out no profiling and no automated decision-making within the meaning of Art. 22 GDPR.
If you switched between light and dark mode in the app, the page reads that choice from your browser’s local storage to display itself accordingly. The setting is not sent to us; reading it is strictly necessary to provide the service you asked for (§ 25(2) no. 2 TDDDG).
The app
Account and sign-in
Splatastic is invitation-only: an account is only created through an invitation. For your account we store your email address, your role, who invited you, when the account was created and when you last signed in, your settings (for example whether you want status emails) and — if you set one — your password, exclusively as an irreversible hash (Argon2id). We do not ask for names.
You sign in with your password or with a six-digit one-time code that we send you by email. A code is valid for ten minutes and becomes invalid after five failed attempts. We store it only as a checksum.
After you sign in, we set a technically necessary session cookie. It is valid for 30 days from sign-in or until you sign out, and it serves only to recognise you during your session; there is no tracking. With each session we store your browser’s identifier (user agent) and the time of last use, so that you and we can recognise open sessions. We delete expired sessions at the next sign-in to the service.
To prevent passwords and codes from being guessed, we count sign-in attempts per email address and per IP address. These counters exist only in the server’s memory and are not stored permanently. The service clears them continuously: an entry disappears at the latest about an hour after the last counted attempt, without waiting for a restart.
The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR) and, for protection against abuse, our legitimate interest in secure operation (Art. 6(1)(f) GDPR). If a company provides your account, we process your data on its behalf to that extent.
Invitations
When someone invites you, we store your email address, the intended role and who invited you. The invitation email tells you the inviting person’s address. The link in it is valid for seven days and can be used once; we store it only as a checksum. The legal basis is our legitimate interest in adding people at the request of an existing user (Art. 6(1)(f) GDPR).
Emails from the app
The app sends only functional emails: sign-in codes, invitations and status emails about your captures (a review step is waiting for you, a splat is ready, a run has failed). You can switch status emails off at any time in the user menu. We do not send newsletters, and the emails contain no open or click tracking; the preview image in the “ready” email is loaded from our own server. If we engage an email service provider for sending, we name it below in the list of recipients. We keep no separate delivery log; we only remember which status email has already been sent for which capture, so that it does not arrive twice.
Captures and processing
When you upload a video, images or a finished point cloud, we store the file unchanged, together with its file name, size, duration and resolution, as well as device model, manufacturer and lens where your device wrote them into the file — we use them to check the capture before computing. Other metadata in the file, such as a capture location recorded by the device, remains in the stored file; we do not read it.
This is how processing works:
- Your browser uploads the files through short-lived signed links directly into our object storage at Hetzner in Nuremberg. All results are stored there too: splats, collision meshes, delivery packages and preview images.
- The first check of a capture runs on our server at Hetzner in Nuremberg, which also holds the database.
- GPU servers from RunPod in a data centre in the Netherlands compute the splat. They receive the files through signed links that expire after a few hours and have no access of their own to our storage. Their working copies are removed right after the run, any leftovers after 14 days at the latest.
The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR); for captures on behalf of a company or partner, we act as its processor (see above).
Deletion
We delete the source video, images and the working data of a computation (such as the frames extracted from the video and the camera path) once nobody has accessed them for 90 days; a new export resets the period. Individual runs that we explicitly keep to measure the quality of our service are exempt. The results — splat, collision mesh, delivery package — remain until you delete the capture.
When you delete a capture, we remove it together with all versions, files, share links and related database entries; the files in object storage are deleted immediately afterwards. What remains is a record of each deleted computing run, which we use to review the quality of our checks. At first it also contains the names of the capture and the site and the file name of the source; we replace those names with identifiers after 90 days, after which only the measurements remain. If we delete your account, we immediately replace your account identifier in these records with an irreversible pseudonym. Deleted data disappears from our server backups when the backup is overwritten, after seven days at the latest.
Shared views
You can share a capture via a link or embed it in another website. Anyone who knows the link sees the scene, its name and — only if you allow it — the downloads; no account is needed. We count how often a link was opened and when it was last opened, but store no data about viewers. You can revoke a link at any time; it also expires if you chose a period when creating it. After that the link’s preview image — the picture a chat app shows for it — is no longer available either; with the last open link of a capture we delete it.
API for partners
Partners can commission, track and collect captures through our API. For these captures we act as the partner’s processor. We notify the partner about the status of a capture at an address the partner provides; we keep these notifications until the capture is deleted.
Local storage in your browser
The app stores some settings and work states only in your browser: light or dark mode, how the library is grouped, whether you want desktop notifications, expanded details of a review step and — while an upload is running — its progress including the file name, so that an interrupted upload can resume. In addition, a service worker keeps the app shell (start file, icons, fonts) available so that the app starts even on a weak connection. Storing and reading this data is strictly necessary to provide the functions you asked for (§ 25(2) no. 2 TDDDG). This data is not sent to us; you can delete it at any time in your browser’s site data settings.
Your browser only shows desktop notifications if you switch them on in the user menu and allow them; they are created in your browser, without a third-party push service.
Logs
So that we can detect faults and investigate abuse, the app logs technical events. These include sign-ins and invitations with the email address concerned, and the course of every computing run. Sign-in codes and invitation links are not written to the log in clear text.
The web server’s and the app’s logs rotate: per service we keep at most three files of 10 MB each, overwriting older lines. At our volume that corresponds to a few weeks.
The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
Recipients and transfers to third countries
We only pass personal data to carefully selected service providers acting as our processors:
| Recipient | Purpose | Place of processing |
|---|---|---|
| Hetzner Online GmbH | servers for the pages and the app, database, object storage for captures and results, backups | Germany (Nuremberg, Falkenstein) |
| RunPod, Inc. | GPU servers for computing splats | Netherlands; provider based in the USA |
RunPod is based in the United States. Although processing takes place in a data centre in the European Union, access from the USA cannot be ruled out. For this case we rely on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR).
Retention at a glance
| Data | Retention |
|---|---|
| Account (email address, role, invitation, timestamps, password hash, settings) | until the account is deleted |
| Sign-in sessions | 30 days from sign-in or until sign-out; then deleted at the next sign-in to the service |
| One-time codes | valid for ten minutes; deleted at the next code request |
| Invitation links | valid for seven days, usable once |
| Sign-in attempt counters (with IP address) | in memory only, at most about an hour after the last attempt |
| Source video and images of a capture | 90 days without access, at most until you delete the capture |
| Working data of a computation (frames, camera path) | 90 days without access; a new export resets the period; runs we keep for quality measurement are exempt |
| Results of a capture (splat, collision mesh, delivery package, preview images) | until you delete the capture |
| Working copies on the GPU servers | until the end of the run, leftovers at most 14 days |
| Share links (including the preview image) | until revoked, until the chosen expiry or until the capture is deleted |
| Notifications to partners | until the capture is deleted |
| Record of deleted computing runs | measurements with no fixed period; names and file names in them replaced by identifiers after 90 days, the account identifier pseudonymised when the account is deleted |
| Server and application logs | rotating, at most three files of 10 MB each per service |
| Backups of our server | seven days |
| Enquiries by email | until dealt with, subject to statutory retention periods |
Security
We transmit all data encrypted (HTTPS). We store passwords, session identifiers, one-time codes and invitation links only as hashes, uploads and downloads use signed links with a short validity, and the GPU servers have no access of their own to our storage.
Changes to this policy
We update this policy when our processing or the legal requirements change. The version published here applies; the date at the top shows when it was last updated.