Last updated: August 13, 2026
Privacy Policy
Controller
Roman Gilg Kapfstr. 17 87538 Fischen Germany
Data We Process
We process contact details such as your email address, account and login data, technical usage data, credit and billing data, support communications, and project, file, job, and subtitle information that you upload or generate in SubFT.
Payment card and transaction data are not directly collected by SubFT. Payments are processed through Paddle.
Purposes and Legal Bases
We process data to provide SubFT, manage accounts, enable login and security, bill for credits and AI jobs, provide support, prevent abuse, and comply with legal obligations.
The legal bases are, in particular, contract performance and pre-contractual measures under Art. 6 (1) (b) GDPR, legitimate interests under Art. 6 (1) (f) GDPR, compliance with legal obligations under Art. 6 (1) (c) GDPR, and, where necessary, your consent under Art. 6 (1) (a) GDPR.
AI Processing
When you start transcription, OCR recognition, or translation, the files, texts, and metadata required for this are processed in our Modal-based processing environment.
Processing is performed solely for the subtitle processing you have ordered. Your content is not used to train models.
Storage and Deletion
We store account, project, subtitle, usage, and billing data for as long as necessary to provide SubFT, track credits, provide support, ensure security, or comply with legal obligations. There is currently no guaranteed automatic deletion after a fixed number of days.
You can request the deletion of your data. We will delete or anonymize data unless prevented by statutory retention periods, payment and tax records, security, fraud prevention, law enforcement, or technical backup reasons.
Cookies and Analytics
We use technically necessary cookies and similar technologies for login, security, and session features to work.
If analytics is enabled, we use self-hosted, privacy-friendly Umami Analytics without advertising cookies. We process aggregated pageviews and a small, predefined set of interaction events to understand whether important SubFT workflows succeed and to improve the website. We do not send project, media, track, operation, account, or payment identifiers, filenames or paths, subtitle content, email addresses, or other user-provided text to Umami. Session replay, heatmaps, performance collection, and account-level visitor identification are disabled.
Service Providers
We only use service providers to the extent necessary for operations, security, payments, authentication, storage, analysis, or AI processing.
Hetzner: Hosting of backend and infrastructure components. Cloudflare: Storage, delivery, and protection of public web and file resources. Modal: Execution of AI processing for transcription, OCR, and translation. Paddle: Payment processing, invoices, refunds, and fraud prevention. Umami: Privacy-friendly web analysis, if enabled. Neon Auth: Authentication and login features, if deployed in the production environment.
Payments
Purchases of credits are processed via Paddle. Paddle may process payment, invoice, tax, fraud prevention, and support data as an independent provider or payment service provider.
SubFT receives the transaction information necessary to assign and fulfill the credit purchase, but no full payment card details.
Your Rights
In accordance with the GDPR, you have the right to access, rectification, deletion, restriction of processing, data portability, and objection. If processing is based on consent, you can withdraw this consent with future effect.
You also have the right to lodge a complaint with a competent data protection supervisory authority.
Deletion and Access Requests
You can submit requests for access, copies, rectification, or deletion by email. Where possible, please use the email address associated with your SubFT account so that we can verify your request and prevent abuse.
Security
We take technical and organizational measures to protect personal data against unauthorized access, loss, alteration, and abuse. This includes role-based access, signed webhooks, segregated production secrets, and encrypted transmissions, where technically supported.
Business Customers and DPA
Business customers can request information on GDPR processing and, if necessary, a data processing agreement. We will only provide a public self-service document once it has been legally reviewed separately.
Privacy Contact
For privacy inquiries, deletion requests, or DPA requests, please contact us by email: