Skip to content

Privacy Policy (Datenschutzerklärung)

Last updated: September 2026

1. Privacy at a glance

General information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator: Bassel Blal, Oppenhoffallee 143, 52066 Aachen, Germany. Contact: bassel@blal.de.

How do we collect your data?

Some data is collected when you provide it to us (e.g. when registering or in a support request). Other data is collected automatically by our IT systems when you visit the website (e.g. technical data such as browser, operating system or time of access).

Your rights

You have the right at any time to receive free information about the origin, recipients and purpose of your stored personal data (Art. 15 GDPR), as well as the right to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and to object to processing based on legitimate interests (Art. 21 GDPR).


2. Hosting

This website and the platform run on servers of a hosting provider in a data centre in Germany. Your account data, uploaded photos and generated content are stored there. Legal basis: Art. 6 (1) (b) GDPR (performance of contract) and Art. 6 (1) (f) GDPR (legitimate interest in reliable operation).


3. General information and mandatory information

Data protection

The operator of these pages takes the protection of your personal data seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

Responsible body

Bassel Blal, Oppenhoffallee 143, 52066 Aachen, Germany. Email: bassel@blal.de. We have not appointed a data protection officer; please send questions about data protection to this address.

Revocation of your consent to data processing

Many data processing operations are only possible with your express consent. You can revoke your consent at any time. The legality of the data processing carried out until the revocation remains unaffected by the revocation.

Right to lodge a complaint with the supervisory authority

If the GDPR is infringed, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW).

Right to data portability

You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.


4. Data collection on this website

Server log files

The provider of the pages automatically collects and stores information in server log files that your browser automatically transmits to us: browser type/version, operating system used, referrer URL, host name of the accessing computer, time of the server request, IP address. This data is not merged with other data sources. Basis: Art. 6 para. 1 lit. f GDPR.

Registration on this website

When you register we collect your email address, name and password (stored only as a hash), and later, if you provide one, a company name. We use this data to provide the account, for invoicing and for messages about your account. Legal basis: Art. 6 (1) (b) GDPR.

Contact, support chat and the "Product news" form

If you write to us by email or via the support chat in the signed-in area, we store your message and contact details to answer the request (Art. 6 (1) (b) GDPR). If you enter your email address in the "Product news" form, we store it together with the time, IP address and browser identifier to detect misuse of the form (Art. 6 (1) (f) GDPR). We send product news only after you have confirmed the sign-up by email (Art. 6 (1) (a) GDPR); you can unsubscribe at any time via the link in every email or by writing to bassel@blal.de.

Cookies

Our website uses only strictly necessary cookies (sign-in, protection against cross-site request forgery, language setting). Under § 25 (2) no. 2 TDDDG they are set without consent because the service cannot work without them. We do not use analytics, tracking or marketing cookies.


5. Usage analytics

We do not use any usage analytics or tracking tools. Should this change, we will update this privacy policy beforehand and obtain your consent where required.


6. Payment processing

We use Stripe (Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) for payments. Payment details such as the card number, the billing address and, where applicable, the VAT ID are entered directly on Stripe's payment page and are not stored on our servers. We transmit name or company name, email address and amount to Stripe; Stripe tells us the payment status and, where applicable, the payment method type and the last four digits of the payment instrument. Stripe issues and sends the invoice for every payment on our behalf. Stripe processes this data to execute the payment and to meet its own legal obligations (e.g. anti-money-laundering and fraud prevention); data may also be transferred to Stripe, Inc. in the USA. Privacy policy: https://stripe.com/privacy. Legal basis: Art. 6 (1) (b) GDPR.


7. Email delivery

We use Resend (Resend, Inc., USA) to send transactional emails (e.g. email address confirmation, password reset, notifications). Your email address and the message content are transmitted to Resend. Legal basis: Art. 6 (1) (b) GDPR (performance of contract).


8. AI processing

To edit your photos (e.g. virtual staging), recognise rooms and, on request, generate voice-over scripts, voice-overs, music and videos, we send the content required for each step (photos, texts, property details) to specialised AI services. The table below shows which. We do not use your photos to train our own AI models. Legal basis: Art. 6 (1) (b) GDPR (performance of contract).

Services we use

We use the following services to run the platform. Where data is transferred to countries outside the EU (in particular the USA), we base this on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

ServiceProviderPurposeLocation
Google Gemini APIGoogle Ireland Ltd., Gordon House, Barrow Street, Dublin 4, IrelandRoom recognition, image analysis and AI image editing (virtual staging)Processing also in the USA
Kling (image-to-video) and image editing via fal.aiFal Inc. (fal.ai), 2261 Market St #4733, San Francisco, CA 94114, USAGenerating video clips from photos; fallback for image editingUSA
OpenRouterOpenRouter Inc., 2261 Market St #4747, San Francisco, CA 94114, USARouting to AI models (including Google and Anthropic) for voice-over scripts, image editing and AI musicUSA
ElevenLabs (AI voice)ElevenLabs Inc., 169 Madison Ave STE 2484, New York, NY 10016, USAGenerating voice-overs from textUSA
ResendResend, Inc., 2261 Market St #5039, San Francisco, CA 94114, USASending emails (account, notifications)USA
SentryFunctional Software, Inc., 45 Fremont St, San Francisco, CA 94105, USAError monitoring (technical error data; IP and email addresses removed)USA
Stripe (payment processing)Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, IrelandPayment processingIreland (EU), processing also in the USA
HostingData centre operator in GermanyRunning the platform, storing your dataGermany
Telegram (internal admin alerts)Telegram FZ-LLC, Dubai, UAENotifying the operator of new events (e.g. a support request), without names, email addresses or message contentOutside the EU: no personal content is transmitted

EU AI Act: transparency obligations (Art. 50)

The transparency obligations of Art. 50 of Regulation (EU) 2024/1689 (AI Act) have applied since 2 August 2026. This is how we meet them:

  • Visible and machine-readable label. AI-edited photos carry a notice directly in the image (e.g. "Virtuell möbliert" – virtually furnished – or "KI-bearbeitet" – AI-edited) and a label in the file metadata (IPTC "Digital Source Type"); both remain after download.
  • Videos: downloaded videos carry the AI-generated label in their file metadata; the public page of a shared video also shows a visible notice. We expressly recommend labelling the listing accordingly.
  • No biometric identification. We do not process biometric data to identify natural persons. If people or licence plates are visible in uploaded photos, we recommend removing them before upload; otherwise we process them solely within the scope of your order.
  • No training of our own models. We use your photos only to carry out your order and not to train our own AI models.

9. Error monitoring

We use Sentry (Functional Software, Inc., USA) to detect technical errors. Error data such as the error message, browser version and operating system is transmitted; we remove IP and email addresses from this data. We do not record sessions. Legal basis: Art. 6 (1) (f) GDPR.


10. Data storage and deletion

We delete personal data as soon as the purpose of storage no longer applies. If you delete your account, it is first deactivated for 30 days; after that, the account, uploaded photos and generated content are permanently deleted or anonymised. Invoices and accounting records are kept for up to 10 years because of statutory retention obligations (§ 147 AO, § 14b UStG), at Stripe and in our bookkeeping.


11. Changes

We update this privacy policy when the law or the service changes. Last updated: September 2026.