1. Data controller
Hart Studio Srl, Viale degli Astri 59, 00144 Rome (RM), Italy. VAT no. IT13918461008.
For any privacy question and to exercise your rights, write to info@hartstudio.it. We have not appointed a Data Protection Officer (DPO), as one is not mandatory for the processing described here: Hart Studio answers you directly.
2. What this policy covers
This policy, provided pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), covers:
- the CineRelay app for iPhone and Android, used to control a camera connected via USB-C, import photos and videos into a library on the phone and, if you choose, upload them to your own storage;
- the CineRelay account and the server that manages sign-ins and subscriptions;
- this website, cinerelay.it, including the Account area and purchases through Stripe.
For cookies and browser storage, see also the Cookie policy.
3. What stays on your phone
The following data is processed only on the device. Hart Studio does not receive it and cannot access it:
- photos and videos imported from the camera or from Files, and the proxies created by the app;
- the library list and upload status (file names, capture dates, progress);
- preferences: chosen destination, folders, FTP server address, port and username, the “Wi-Fi only” option;
- credentials: the access tokens for Google Drive or Dropbox, the FTP password and the CineRelay account session token. On iPhone they are stored in the Keychain; on Android they are encrypted with an Android Keystore key that never leaves the phone. In both cases they are excluded from backups and transfers to other devices;
- the name and email of the connected Google or Dropbox account, which the app shows only as a label.
You can delete individual files from the library at any time. If you uninstall the app, the system deletes the library, preferences and credentials. “Disconnect” in Destinations deletes the Google Drive or Dropbox token.
4. Services you choose: Google Drive, Dropbox, FTP
If you enable a destination, the app sends files directly from the phone to the chosen service, using your account or your server. These transfers do not pass through Hart Studio, which is not a recipient of those files. There, the data is processed by the service provider under its own terms and privacy policy:
- Google Drive (Google): policies.google.com/privacy. CineRelay requests only the drive.file scope, that is, access to the files created by the app: it cannot read the rest of your Drive. You can also revoke access at myaccount.google.com/permissions.
- Dropbox (Dropbox): dropbox.com/privacy. You can revoke access from your Dropbox account settings, in the connected apps section.
- FTP server: this is your own server or one managed for you by someone else. With unencrypted FTP, passwords and files travel in clear text, and the app warns you about this: use it only on networks you trust.
To sign in to Google and Dropbox, the app uses the service’s official sign-in page or the phone’s system window. Your account password never passes through CineRelay.
5. CineRelay account
The account is optional: the free features and a subscription bought in the app also work without one. It lets you restore your subscription on multiple devices and buy on the website. It is created with just your email, without a password: each time you sign in we send you a 6-digit code. On iPhone you can also use “Sign in with Apple”.
- Account data: email address, account identifier, creation date. With “Sign in with Apple” we receive an identifier and the email from Apple, including the anonymous relay address if you choose it.
- Sign-in: the 6-digit code (valid for 10 minutes, stored only in hashed form) and the session token that keeps the app and the website signed in, valid for up to 90 days or until you sign out.
- Subscription: purchase channel (website, App Store, Google Play), plan, status, start, renewal or expiry dates, use of the free trial and the technical identifiers of the purchase (Apple original transaction, Google purchase token, Stripe customer and subscription).
- Free trial register: to grant the free trial only once per person, we keep a fingerprint of the email (a keyed hash with a secret key, from which the address cannot be derived), even after the account is deleted.
- Abuse protection: to limit repeated sign-in attempts, we log code requests for 24 hours, linked to a fingerprint (hash) of the email and not to the plain-text address.
We write to your email only for sign-in and for service communications about your subscription, never for advertising.
Deletion: you can delete your account at any time from the app (Destinations tab › Account › “Delete account”), from the website’s Account page or by writing to us. All the steps are on the Delete account page.
6. Subscriptions and payments
In the app: App Store and Google Play
If you buy CineRelay Pro in the app, payment, billing, renewals and refunds are handled by Apple (Apple privacy policy) or Google (Google privacy policy), as independent controllers. Hart Studio does not receive your payment details. If you are signed in, the app sends our server the proof of purchase signed by the store (StoreKit transaction or Google Play token); the server verifies it with Apple or Google and links it to your account, so Pro also works on your other devices.
On the website: Stripe
Purchases on the website go through Stripe Payments Europe, Ltd. (Ireland), which processes payment data as an independent controller. You enter your card details directly on the Stripe Checkout pages and in the Stripe customer portal: Hart Studio neither sees nor stores them. From Stripe we receive the customer and subscription identifiers, the email, plan, status, dates, amounts and billing country, which we need to activate Pro and to meet our tax obligations. For payments and fraud prevention, Stripe acts under its own privacy policy and may transfer data outside the EU with the safeguards provided by the GDPR. Stripe’s pages, which are on Stripe’s domain and not on this website, use their own cookies for security and fraud prevention.
7. This website
- Technical logs: like any web server, the server hosting the website and API records technical data about requests: IP address, date and time, page or address requested, response code and browser type. These are needed to run the service, protect it from attacks and abuse, and detect faults. We keep them for 30 days, after which they are deleted, unless they are needed to establish an offence.
- Browser storage: the website does not use profiling cookies or analytics tools. When you sign in to your account, the browser keeps the session token and your email in its local storage, solely to keep you signed in. If you choose the language with the “IT | EN” switch, a technical cookie (
lang) remembers it for one year. Details in the Cookie policy. - Waiting list: the “Notify me” form currently neither sends nor saves any data. The email you type is only checked in the browser and does not reach us or any third party. If we enable sign-ups, we will first update this policy with the service used and the retention periods.
8. If you write to us
If you contact support or write to us about privacy, we use your email address and what you tell us only to reply to you. We keep the conversation for as long as needed to handle the request, and in any case no longer than 24 months from the last message, unless it is needed for longer to protect a right. If you send us a sample file, we delete it once the request is resolved.
9. Purposes, legal bases and retention
| Why | Legal basis | How long |
|---|---|---|
| Creating the account, signing you in, activating CineRelay Pro where you are signed in | Performance of a contract (Art. 6(1)(b) GDPR) | As long as the account exists. Codes: 10 minutes. Sessions: 90 days or until you sign out |
| Verifying App Store, Google Play and Stripe purchases and managing the subscription | Performance of a contract (Art. 6(1)(b)) | As long as the account exists |
| Granting the free trial only once per person | Legitimate interest in preventing abuse (Art. 6(1)(f)) | The email fingerprint is kept even after the account is deleted, for as long as we offer the free trial |
| Limiting repeated sign-in attempts, protecting the server and website (technical logs) | Legitimate interest in security (Art. 6(1)(f)) | Counters: 24 hours. Server logs: 30 days |
| Accounting and tax records for website purchases | Legal obligation (Art. 6(1)(c)) | 10 years (Article 2220 of the Italian Civil Code), without linking them to an account |
| Replying to your support or privacy requests | Performance of a contract or pre-contractual measures (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) | Up to 24 months from the last message |
| Defending our rights in the event of disputes | Legitimate interest (Art. 6(1)(f)) | For as long as strictly necessary |
When you delete your account, we immediately delete from the server your email, identifier, sessions, codes and links to purchases. Server backups are overwritten within 30 days. Providing your email is required only if you want an account: without it we cannot create one, but the app remains usable.
10. Who processes data with us
Data is processed by authorised and instructed Hart Studio staff. We also rely on the following providers, appointed as processors (Art. 28 GDPR), who process data only on our behalf:
- Aruba S.p.A. (Italy): dedicated server hosting the website, API and database, in a data centre in Italy;
- Resend Inc. (United States): sending the emails with sign-in codes, from the sender noreply@hartstudio.it. It receives your email address and the text of the message containing the code.
The following are instead independent controllers, each with its own privacy policy: Stripe Payments Europe, Ltd. for website payments, Apple for the App Store and “Sign in with Apple”, Google for Google Play, and the storage services you choose (Google Drive, Dropbox, your FTP). We do not sell or transfer data to third parties for advertising. We may disclose it to the authorities only when required by law.
11. Transfers outside the European Union
The server and database are in Italy. Our only provider outside the EU is Resend Inc., in the United States, for sending sign-in emails: the transfer is based on Resend’s participation in the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, in any case, on the Standard Contractual Clauses approved by the Commission (Art. 46 GDPR). You can ask us for a copy of the safeguards by writing to info@hartstudio.it. Stripe, Apple and Google may transfer data outside the EU as independent controllers, with the safeguards set out in their privacy policies.
12. No tracking, no analytics
- The app and the website contain no third-party analytics, advertising or tracking SDKs or scripts, and do not use the advertising identifier.
- We do not create profiles and do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
- If you have chosen in your phone settings to share analytics with developers, Apple or Google may send us anonymous crash reports. On iPhone you can turn this off in Settings › Privacy & Security › Analytics & Improvements; on Android, in the Google settings for usage and diagnostics.
13. Security
Communications between the app, the website and the server are encrypted (HTTPS). Sign-in codes and session tokens are stored on the server only as hashes. Credentials on the phone stay in the iOS Keychain or the Android Keystore. No measure is infallible: if we discover a breach affecting you, we will notify you as required by Articles 33 and 34 GDPR.
14. Your rights
For data processed by Hart Studio, you have the right of access, rectification, erasure, restriction, portability and to object to processing based on legitimate interest (Articles 15–21 GDPR). You can delete your account yourself from the app or from the Delete account page; for everything else, write to info@hartstudio.it. We reply within one month, and we may ask you to confirm the request from the same email as the account, to make sure it is yours.
If you believe the processing infringes the GDPR, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome) or with the supervisory authority of the EU country where you live or work.
For files uploaded to Google Drive, Dropbox or your FTP, contact the respective provider: we do not hold them. For data processed by Apple, Google or Stripe as independent controllers, you can contact them directly.
15. Minors
CineRelay is a professional tool for filmmakers. The account and subscriptions are not intended for children under 14, and we do not knowingly collect their data. If you believe a child under 14 has given us their data, write to us and we will delete it.
16. Changes
If the way we process data changes, for example with a new service or a new provider, we update this page and the date at the top before the change takes effect. If the change is significant and you have an account, we will also let you know by email.