Privacy policy
Information pursuant to Art. 13 and 14 GDPR
This is a translation for convenience. Projection-X is based in Germany; the German version of these terms is the binding one. Questions? Write to us via the support page.
Controller
Nicolas BauerPaullinerstr. 179848 Bonndorf im SchwarzwaldDeutschlandE-Mail: connect@projection-x.deA data protection officer has not been appointed, as this is not required by law; please address enquiries directly to the address given above.
What happens when you merely visit
When you call up the site, your browser transmits technically necessary data to our hosting provider: IP address, time, the address called up, and browser and operating system identifiers. This is necessary in order to operate the site (Art. 6(1)(f) GDPR — our legitimate interest in a functioning, secure service). This data is not combined with other sources.
Account and sign-in
For an account we need your email address and a password; you may voluntarily provide a name, a short description, a profile picture and a location. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).
For accounts with elevated rights, and on request for all others, we send a six-digit code by email when you sign in. We log sign-in times and security events in order to detect misuse.
Instead of waiting for the code you may register a passkey. For this we store your device’s public key, an identifier, a signature counter, the name you choose yourself and the times of creation and last use. The private key never leaves your device and never reaches our servers; we do not process biometric data — your fingerprint or face stays on your device. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). You can remove a passkey in your settings at any time; changing your password removes every passkey on your account.
Purchases, licences and tokens
When you make a purchase we process order data, the payment status and the entitlements arising from it. The payment itself is handled by Stripe; full card details do not reach our servers. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and, for the retention of accounting records, compliance with obligations under tax law (Art. 6(1)(c) GDPR).
Licence keys are bound to the devices on which you activate them. For this purpose we store a device identifier and the time of activation — necessary in order to enforce the agreed number of devices.
Purchase recommendations in the cart
When there are products in your cart, we show further products under the heading “Customers also bought” that other customers bought together with one of these products. To do this we evaluate the orders stored with us in aggregated form: we count how many different customer accounts bought a product in your cart and another product. Only paid and non-refunded purchases are taken into account; test purchases, credits, gifts and accounts of our team do not count.
A product only appears there once at least three different people have bought it together with the product concerned. Names, email addresses or other details of these people are neither read nor shown; who bought a product cannot be seen from the recommendation. We do not store the result permanently but recalculate it regularly; interim results remain in our server’s working memory for at most one hour.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is to show you products that suit your purchase. Using your order data for this purpose is compatible with the original purpose (processing your purchase) (Art. 6(4) GDPR): only counts are formed, the threshold of three people prevents conclusions about individual purchases, and no profiles about you are created.
You may object to your purchases being taken into account at any time (Art. 21 GDPR), informally by email to the address given above. Your purchases will then no longer be counted from that point on.
Trial versions (launcher)
If you start the 60-minute trial of an effect in the launcher, we store a device identifier permanently so that the trial runs only once per device. The legal basis is our legitimate interest in limiting the free trial version to one run per device (Art. 6(1)(f) GDPR).
Coaching: live sessions and recordings
One-to-one coaching sessions take place as a video call directly on the platform (camera, microphone and, if you wish, screen sharing). Your browser asks for the permissions itself; without your permission nothing is transmitted. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Files that you share in a session are accessible only to you and the coach.
For as long as the platform’s own video room has not been enabled, a session may alternatively take place via an external meeting service — you will receive the link in advance; the privacy policy of the provider concerned then additionally applies to that call. No recording takes place by this route.
A recording of the session (picture, sound and shared screen) is made solely where you have expressly consented beforehand (Art. 6(1)(a) GDPR) — we ask for that consent before the session, and you may change it at any time up to the start of a recording. The recording is stored privately (Cloudflare R2), can be accessed only by you and the coach and is streamed exclusively on the platform — it is not made publicly available. If you decline, the session simply takes place without a recording.
Community
Posts, comments, likes and the indication of whom you follow are visible to signed-in users. Your profile is public only if you have set it to be; the display of the effects you have purchased and of the courses you are taking can also be switched off individually.
If you place yourself on the creator globe, we store rounded coordinates (accurate to about 11 kilometres) and a place designation made up of town and country — deliberately not your address. You can remove yourself again at any time.
Posts by other users may embed images from third-party servers. When you view such a post, your browser retrieves the image directly from the server concerned — that server thereby sees your IP address and browser identifier. Which servers this applies to is determined by the person who wrote the post.
Reviews
You can write a review of the launcher and of products you have bought or hold a valid licence for. For this we store the star rating, an optional title, your text, the time of creation and of the last change, the kind of verification (purchase, licence or paired launcher) and the link to your account.
You can also review courses you have bought and paid for, and the coaching once you have booked and paid for a coaching session. In both cases we store “purchase” as the kind of verification.
Before publishing and on every change, we use data we already hold (orders, unlocks and licences, or launcher sign-ins and pairings) to check whether your account owns the product or has paired the launcher. Only the result of this check is stored.
For a course we use your orders and unlocks to check whether your account bought and paid for exactly this course. Single modules or episodes, a subscription or an unlock by us are not enough. For the coaching we check whether your account has booked and paid for a coaching session.
Your review is visible to every visitor of the page concerned — with star rating, title, text, date, the note “edited” after a change, the kind of verification and your display name. As the name we show your display name or username; if your profile is not public, only your initials; if no name is set, “Verified user”. Your email address never appears. You see which name will appear before submitting and can change it in the settings. From the reviews we calculate the average rating, which may appear on the page and in structured data for search engines.
We also show the average rating and the number of reviews on the tiles of the overviews in the shop and for courses. If you sort the shop by “Top rated”, we order the products by these two values. For this we only use the star ratings that are stored anyway.
We also show the most recently written reviews on the start page: with star rating, title, an excerpt of the text, date, the kind of verification and your display name, and a link to the page of the reviewed item.
The legal basis for storing and publishing is Art. 6(1)(b) GDPR (you use a platform feature you choose yourself). We base the authenticity check and the review of reported reviews on Art. 6(1)(f) GDPR; our legitimate interest is to show only genuine customer reviews and to remove illegal content. The statement of reasons we send you when deleting a review is based on Art. 6(1)(c) GDPR in conjunction with Art. 17 DSA.
You can edit or delete your review at any time while the reviewed product is offered in the shop. Deleting your account also deletes your reviews. If we take a product out of the shop, we stop showing its reviews; they remain stored until you delete your account or ask us to delete them, and they reappear if the product is offered again. If a review breaks our review rules, we delete it completely and tell you the reason by email. For such a deletion we keep a log entry (time, reason, star rating, kind of verification and internal IDs, not the text) as evidence of our decision.
The same applies to courses: while a course is offered, you can edit or delete your review. If we take a course off the offer, we stop showing its reviews; they remain stored as described and reappear if the course is offered again.
Where we rely on Art. 6(1)(f) GDPR, you can object (Art. 21 GDPR). Since a review cannot be published without the check, an objection will usually lead to the review being deleted.
Emails
Contract-related messages (purchase confirmation, licence key, password, support) are sent by us on the basis of performance of the contract. You receive notifications about posts by people you follow only because you follow those people — the legal bases are the performance of the user agreement and our legitimate interest in a functioning community (Art. 6(1)(b) and (f) GDPR). Every such email contains a way to unsubscribe, and you can change the setting at any time.
We send a newsletter solely after express consent (Art. 6(1)(a) GDPR), which you may withdraw at any time with effect for the future.
Cookies and local storage
We use technically necessary cookies for signing in (session), for your choice of language and for your choice of navigation layout (sidebar or header bar, entry “px_nav”). They are required in order to operate the service and do not require consent (Section 25(2) TDDDG (German Digital Services Data Protection Act)).
Before launch and when you register, four further necessary cookies are added. “px_hub” lets team members and testers into the hub before launch; it is valid for 12 hours, signed and holds the account ID. “px_ref” remembers the invitation code you register with until your account is created; “px_absicht” remembers that you chose to register with your Patreon email. Both last only for the session and are created only when you click “Register” or that option; opening an invitation link sets no cookie. “px_google_start” remembers for up to ten minutes that the security check was passed before signing up with Google; it contains no personal data and is deleted after returning from Google.
We store your choice in the cookie dialog for 12 months in the cookie “px_consent”. It holds no identifier, only the version, a checksum of the texts, the day of your decision and your choice — so that we can prove what you consented to (Art. 7(1) GDPR). You can change your choice at any time via “Cookie settings”.
Only after your decision in the cookie dialog do we store, in your browser’s local storage, settings you make yourself (for example display and subtitles), your notes on lessons and your cart (at most 30 days after the last change). Which notices you have dismissed and the progress of the initial tour (entry “px_wt_step”) are kept beyond the session only if you allow this in the cookie dialog. Likewise, only with your permission do we set up a service worker that makes the hub installable as an app and shows an offline page without a connection. These entries do not leave your device; you only transmit the cart when you go to checkout.
We deliver files from our storage — images, videos and uploaded media — via our own domain. Only when you download purchased files or files shared in coaching, and when you upload files in coaching or in the operator area, does your browser connect directly to our storage provider Cloudflare (R2) via a time-limited address; Cloudflare then sees your IP address.
The sounds of the card pick in Early Access come from our own server (hosted by Vercel). They load only after your click on the card page and only while the “Sound” switch is on; nothing is stored on your device in the process.
Anything beyond that — in particular the loading of external videos — happens only with your consent, which you give via the cookie dialog and can change at any time. We do not use any counting, analytics or advertising services.
Recipients and processors
We use the following service providers. In so far as they process personal data on our behalf, we conclude processing agreements with them pursuant to Art. 28 GDPR. We keep a record of the status of those agreements internally; on request we will provide information on an individual service provider.
Vercel
Vercel Inc., USA
Operation and delivery of the website (hosting).
Data: IP address, date and time, the address accessed, browser identifier.
Supabase
Supabase Inc., USA — database in the EU (Ireland)
Accounts, sign-in and database.
Data: Email address, encrypted password, sign-in times, your content.
Google (sign-in)
Google Ireland Ltd., Ireland / Google LLC, USA
Only if you choose “Continue with Google”: sign-in via your Google account. We do not load or display your Google profile picture.
Data: Email address and name from your Google account. We do not take the address of your profile picture, which Google also transmits, into your profile.
Stripe
Stripe Payments Europe Ltd., Ireland
Payment processing, invoices, subscriptions.
Data: Name, email, payment data, billing address, purchase history.
Cloudflare R2
Cloudflare Inc., USA
Storage of files: effects, images, uploaded media.
Data: The files themselves, access times.
Cloudflare Turnstile
Cloudflare Inc., USA
Protection against automated requests in forms, for example when registering and signing in, when resetting your password, for support, coaching and newsletter requests, community posts and the card pick in Early Access. The script loads only in forms that need it and only after your decision in the cookie dialog; according to Cloudflare, it sets no cookies on this website. The legal basis is our legitimate interest in protection against abuse (Art. 6(1)(f) GDPR); access to your device is strictly necessary for this (Section 25(2) no. 2 TDDDG). To improve its bot detection, Cloudflare also processes the data as an independent controller.
Data: IP address and the browser and device characteristics that the script collects in order to tell people from programs.
Resend
Resend Inc., USA
Sending of emails (sign-in, licence keys, support, notifications).
Data: Email address, content of the message, delivery status.
Mux
Mux Inc., USA
Delivery of the course and preview videos. They load only once you allow Mux in the cookie dialog or at the video’s placeholder; you can withdraw this at any time via “Cookie settings”.
Data: IP address, playback times, device type.
LiveKit
LiveKit Inc., USA — media server in the EU region chosen by us
Live video room for one-to-one coaching sessions (camera, microphone, screen sharing) — only if you join a session. The connection is encrypted; a recording takes place solely after your express consent.
Data: IP address, connection data, and during the session picture and sound streams.
YouTube
Google Ireland Ltd., Ireland / Google LLC, USA
Embedded videos in enhanced privacy mode (youtube-nocookie.com). The player and thumbnails (i.ytimg.com, img.youtube.com) load only once you allow YouTube in the cookie dialog or at the placeholder; a click on “Play” does not replace this permission.
Data: IP address, device data, playback behaviour (by YouTube).
Vimeo
Vimeo Inc., USA
Embedded videos with a “Do Not Track” parameter (player.vimeo.com). The player and thumbnails (vimeocdn.com) load only once you allow Vimeo in the cookie dialog or at the placeholder; a click on “Play” does not replace this permission.
Data: IP address, device data, playback behaviour (by Vimeo).
Instagram (Meta)
Meta Platforms Ireland Ltd., Ireland / Meta Platforms Inc., USA
Instagram posts and reels embedded in community posts. The thumbnail and the post load only once you allow Instagram in the cookie dialog or at the placeholder, and the post itself even then only on your click; before that there is only a placeholder from us. For the embedding, we and Meta are joint controllers (Art. 26 GDPR).
Data: IP address, device data, playback and interaction behaviour (by Meta).
VirusTotal
Chronicle LLC (Google), USA
Malware scanning of the download files we provide (plugins) before they are delivered. Only our own files are scanned — no user data.
Data: Only the program files themselves and their checksums.
OpenStreetMap (Nominatim)
OpenStreetMap Foundation, United Kingdom
Resolution of the location you enter yourself for the creator globe.
Data: Only the search term entered — the request is made by our server, your IP address is not passed on.
Google Maps Geocoding
Google Ireland Ltd., Ireland / Google LLC, USA
Resolution of the location you enter yourself for the creator globe — as an alternative to OpenStreetMap.
Data: Only the search term entered — the request is made by our server, your IP address is not passed on.
In so far as service providers process data outside the EU — in particular in the USA — we base the transfer for each service on the adequacy decision on the EU-U.S. Data Privacy Framework (DPF) and/or on the EU standard contractual clauses (SCC): for Vercel, Supabase, Google (sign-in, YouTube, Maps Geocoding, VirusTotal), Stripe, Cloudflare, Resend, Mux, LiveKit, Vimeo and Meta (Instagram), DPF and/or SCC apply in each case under the data processing agreement (DPA) which the provider concerned offers to its customers. Which of the two mechanisms applies in an individual case, and where the provider publishes the safeguards, we will tell you on request in relation to an individual service provider.
Retention periods
We store account data for as long as your account exists. After deletion we remove it — with two exceptions, which we name here expressly instead of hiding them behind a general formula.
- Statutory retention obligations: we keep invoices and accounting records for ten years (Section 147 AO (German Fiscal Code)). This also includes the token bookings and any remaining token balance: purchased tokens are credit paid in advance and are carried as a liability in the accounts; the booking lines bear the payment or order number to which they belong. Records of purchase consent, of account deletion and of the account recovery route are kept by us for three years (Section 195 BGB (German Civil Code)), as is the record of your newsletter consent.
- Prevention of misuse: the identifier of the device on which a free trial has been used up is kept by us permanently — otherwise the same trial could be repeated at will with a new account. Likewise a deletion marker for your account, so that it cannot be created again via the launcher. If you take part in the referral programme, an outstanding, uncollected chargeback debt together with a blocking flag also remains; the note we have written on the matter falls away upon deletion. These are technical identifiers and amounts, not master data; your name and your address are not among them.
We keep records of consent for the newsletter for as long as the consent applies and, in addition, for three years as evidence (Section 195 BGB); after that we delete them.
We delete technical logs automatically after fixed periods: security events after 180 days — with the exception of records of purchase consent, of account deletion and of the account recovery route, which we keep for three years for the defence of legal claims (Section 195 BGB) —, licence-check and download logs after 90 days, used sign-in codes after 30 days. The cache of the location search (search terms only, no personal data) is cleared after 90 days.
In addition: we delete unconfirmed newsletter sign-ups after 30 days, records relating to cancellation procedures after 3 years, coaching recordings after 12 months, and IP addresses from licence events and activations after 90 days.
Purchase recommendations: no separate storage; interim results for at most one hour in the server’s working memory.
Reviews: until you delete them, delete your account or we remove them for breaking the rules — also when the product is no longer in the shop (hidden, but stored); the log entry about such a removal remains as evidence (see “Reviews”).
Your rights
You have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18), to data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21 GDPR). Consent you have given may be withdrawn at any time with effect for the future.
Please contact connect@projection-x.de for this purpose. Irrespective of this, you have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg.
Clicks on product links in the community
Posts in the community may refer to products from our range. If you call up such a link, we log your account, the post, the item and the time.
Purpose: to establish whether a later purchase came about via a community post, and to settle the share due to the person who wrote it. Legal basis: Art. 6(1)(b) GDPR (performance of the user agreement including the referral programme) and Art. 6(1)(f) GDPR (legitimate interest in detecting abusive settlement).
Retention period: clicks not followed by a purchase are deleted after 45 days. If a click leads to a share, it is retained as part of the settlement record for as long as retention periods under commercial and tax law are running.
No cookies are set in the process and no information is read out from your device. Attribution takes place exclusively via your signed-in account; without signing in, nothing is logged.
Last updated: 3 October 2026 · Version 1.11.0