01 / Overview
Privacy at a glance
POSTHIVE is a post-production workspace operated by Dignified Media GmbH. When you use the website, web app, desktop software, companion apps, or infrastructure apps, we process personal data. This page explains what that means in practice.
Who is responsible?
Dignified Media GmbH is the controller for accounts, billing, security, and consented analytics. For personal data you put in a workspace (media, comments, reviewer names, scripts), you are the controller and we are the processor — see the Data Processing Agreement. Contact details are in the next section and in the imprint.
How do we collect data?
Some data you give us directly (account, uploads, scripts, comments, support messages). Other data is created when you use the product (workspace activity, file metadata, device tokens, logs) or, with your consent, for analytics and marketing.
What do we use it for?
To run the service you signed up for, host and deliver your media, operate on-set infrastructure apps, process payments, keep the platform secure, and — only with consent where required — understand how the product is used and send updates.
Your rights
You can request access, correction, deletion, restriction, portability, and object to certain processing. You can withdraw consent at any time. You can also lodge a complaint with a supervisory authority.
02 / Controller
Who we are
The controller for account and platform data is:
Dignified Media GmbH
Herzogstandstr. 6
83673 Bichl
Germany
Phone: +49 160 6271848
Email: lorenz@dignified.media
Managing directors: Lorenz Schäfer, Nicholas di Napoli. VAT ID: DE456778123. Register: Amtsgericht München HRB 303664.
Legal bases
We process personal data only when we have a legal basis:
- Your consent (Art. 6 (1)(a) GDPR)
- Performance of a contract (Art. 6 (1)(b) GDPR)
- A legal obligation (Art. 6 (1)(c) GDPR)
- Legitimate interests (Art. 6 (1)(f) GDPR)
Storage duration
We keep personal data only as long as needed for the purpose, unless a longer retention period is required by law (for example tax records). If you delete your account or withdraw consent, we delete or anonymize the data unless we must keep it. Workspace content stays until the workspace owner deletes it or the account is closed, subject to backups that expire on a rolling schedule.
03 / Products
What this policy covers
This policy applies to every POSTHIVE-branded surface that connects to your account or workspace, including products we ship later under the same account system, unless a specific app publishes a short supplement.
Workspace products
- POSTHIVE web — projects, deliverables, review, transcripts, transfers, billing, and team administration.
- POSTHIVE Desktop — the macOS app that wraps the workspace and handles local file access for uploads and on-set transfers.
- POSTHIVE Companion — the iOS and Android app for review, notifications, and on-the-go workspace access.
- Resolve panel — the DaVinci Resolve integration that syncs review and optional work-session timing with your workspace.
Infrastructure apps
These are production-day tools. They sign in with the same POSTHIVE account and attach data to a workspace or project. They may process files and device data locally, and they send only what is needed to keep a shoot, transfer, or prompt in sync with POSTHIVE.
- Bay — macOS catalog, drive ingest, transfers, proxies, and timecode apply on local media.
- Timecode — on-set check-in and jam/sync against a shoot day (device labels, frame rate, timecode values, optional slate or monitor images).
- Teleprompter — script and prompter display tied to a workspace or project, including pairing a prompter device.
04 / Collection
Data we collect
Account
When you register or sign in we process:
- Name and email address
- Password (stored hashed) or a passkey / WebAuthn credential on your device
- Optional Google sign-in (name and email shared by Google)
Legal basis: Art. 6 (1)(b) GDPR (contract). Passkeys stay on your device; we store only the public credential needed to verify the next sign-in.
Workspace content
To provide the service we process:
- Workspace, project, client, and deliverable names and settings
- Files and media you upload or transfer
- Comments, review marks, approvals, tasks, and calendar items
- Transcripts, translations, captions, and related editorial text
- Team membership, roles, and invite emails
- Client CRM fields you enter (for example a client phone number)
Legal basis: Art. 6 (1)(b) GDPR.
Payments
Paid plans and add-ons are billed through Stripe. We do not store full card numbers. Stripe processes payment method, billing address, and transaction history. We keep subscription status and invoices as needed for the contract and tax law. See Stripe's privacy policy.
Server logs and security
Hosts automatically receive technical data: browser or app version, operating system, referrer, timestamps, and IP address. We use this to operate, debug, and protect the service (Art. 6 (1)(f) GDPR).
Review and transfer links
When someone opens a client-review or transfer link we may record that the link was opened or downloaded, plus a coarse location derived from the IP address (country / region / city) so you can see delivery activity. Legal basis: Art. 6 (1)(b) or (f) GDPR.
Contact and sales forms
If you email us or submit a walkthrough / contact form, we store name, email, optional company, and your message to reply (Art. 6 (1)(f) or (b) GDPR).
Desktop download and marketing email
If you request the Mac installer we collect your email and a privacy-policy acknowledgement. Marketing email is optional and starts only after you confirm a link in the download message (double opt-in, Art. 6 (1)(a) GDPR). You can unsubscribe in every message. We may keep the unsubscribe timestamp to prove the opt-out.
05 / On set
Infrastructure apps
Bay, Timecode, and Teleprompter are infrastructure apps. They exist to keep production media, clocks, and scripts aligned with a POSTHIVE workspace. More apps in this family may ship later; they will use the same account and the same rules in this section unless we publish a supplement.
Device permissions (camera, photos, local network, microphone, and similar) are requested only when a feature you use needs them. The system dialog on that device is the short form of what this policy describes.
Bay (macOS)
Bay works primarily on your machine. It may process:
- Local volume names, folder trees, and file metadata for the catalog
- File paths, sizes, and a local move / transfer audit log
- Media probes (for example start timecode, frame rate, codec)
- Uploads you start into POSTHIVE storage, using your signed-in workspace
- Timecode corrections written back to files you select, after you confirm
A background helper may notice newly mounted drives so Bay can index them without you reopening the app. Catalog and move logs stay on the Mac unless you upload or sync a specific job to POSTHIVE.
Timecode
Timecode connects an on-set device to a shoot-day session in POSTHIVE so Bay and the workspace can line up clips. Depending on the features you use, we may process:
- Device or camera labels you enter
- Frame rate, drop-frame flag, and timecode values
- Check-in time and a host-clock offset
- Optional photos or frames of a slate or monitor, and on-device recognition used to read the displayed timecode
- Workspace and project association for the session
Images you choose to send are stored with the workspace like other media. Legal basis: Art. 6 (1)(b) GDPR.
Teleprompter
When Teleprompter is available it will process scripts and related production text you enter or import, scroll / display settings, and the identifiers needed to pair a prompter device with a workspace or project. Scripts often contain names of talent or crew — treat them as personal data and only put in what the job needs.
Legal basis: Art. 6 (1)(b) GDPR.
06 / Companion
POSTHIVE Companion
The companion app uses the same account and workspace data as the web app. On the device it may also process:
- Push token — so we can send notifications through Apple Push Notification service or the Android equivalent when you enable them.
- Photo library (save) — only when you save media from POSTHIVE to the device.
- Files you pick — when you upload from the device into Drive or a transfer.
- Clipboard (write) — when you copy a transcript or similar text out of the app.
- Widgets — a short status summary synced through an App Group on the device. Background refresh may update that summary while the app is not open.
Sign-in opens POSTHIVE in an in-app browser view so the session can return to the app. Session tokens are stored on the device. You can delete your account from Profile → Delete account when workspace-ownership rules allow it.
We do not use the companion for advertising tracking. Optional voice commands may use the microphone and on-device speech recognition when you start that feature; audio is used to run the command, not to advertise. Face ID is not collected. If a later feature needs a new permission, the device will ask at that time.
07 / Cookies
Cookies and analytics
Essential
We use strictly necessary cookies and similar storage for sign-in, security, and load balancing (Art. 6 (1)(b) or (f) GDPR). These do not require consent.
Anonymous aggregate counters
We count landing-page loads, whether the page was scrolled at least 25%, and whether the pricing section became visible. We store only hourly totals grouped by page and a limited campaign category. We do not store an IP address, browser identifier, user id, user agent, referrer, or an individual event row for these counters, and they do not use cookies or browser storage. Legal basis: our legitimate interest in measuring whether the public website works (Art. 6 (1)(f) GDPR).
PostHog (consent)
If you accept analytics we load PostHog to understand product and marketing use (pages and events). Session replay may record page interactions and visible page content; form inputs are masked. After you sign in we may attach those events to your user id and email. You can change your choice under Cookie settings in the footer. Rejecting analytics also clears PostHog storage on this browser. Legal basis: Art. 6 (1)(a) GDPR. See PostHog's privacy policy.
Google Analytics (consent)
If you accept analytics we also load Google Analytics (GA4) to measure marketing and site usage (pages and events). Google may process this data in the United States. Rejecting analytics stops further collection and clears Google Analytics cookies on this browser. Legal basis: Art. 6 (1)(a) GDPR. See Google's privacy policy.
First-party events
With the same analytics consent we may record product and marketing events in our own database (for example that a visitor opened pricing, or a daily activity mark for retention). Location is added only with that consent. If you choose essential only, these events are not sent. Legal basis: Art. 6 (1)(a) GDPR.
08 / Language
AI and media analysis
Some features send content you choose to a processor so we can return a result. We do not use that content to advertise to you.
- Transcription — audio/video you submit is sent to AssemblyAI.
- Translation, transcript search, and assistants — relevant text (and embeddings for search) are sent to OpenAI, and may be sent to another model provider if we configure one for a feature.
Legal basis: Art. 6 (1)(b) GDPR for features included in your plan, or Art. 6 (1)(a) if we ask for a separate consent. Do not submit special-category data unless you have a lawful reason and the people involved expect it.
09 / Processors
Hosting and third parties
We use specialist providers to run POSTHIVE. They process data only on our instructions. Several are outside the EEA; we rely on adequacy decisions or EU Standard Contractual Clauses.
- Vercel — website, APIs, and edge hosting (privacy policy).
- Supabase — authentication, database, and realtime (privacy policy).
- Backblaze B2 — primary object storage for uploads and drive assets (privacy policy).
- Cloudflare — Stream encoding/playback and additional object storage (privacy policy).
- Bunny.net — CDN and media delivery (privacy policy).
- Stripe — payments (privacy policy).
- Resend (and fallback SMTP) — transactional and consented marketing email (privacy policy).
- PostHog — consented product analytics.
- Google Analytics — consented marketing and site analytics (privacy policy).
- AssemblyAI — speech-to-text (privacy policy).
- OpenAI — translation, search embeddings, and assistants (privacy policy).
- Google — optional sign-in, and optional Calendar sync on Pro plans (calendar events and OAuth tokens) (privacy policy).
- Slack — if you connect a workspace webhook, notification content you choose to send (privacy policy).
- Apple / Google — push delivery when notifications are enabled.
Short-lived mobile sign-in handoff codes may be stored in an ephemeral key-value cache (for example Vercel KV / Upstash) and expire automatically.
10 / Rights
Your rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent (Art. 7 (3) GDPR)
If processing is based on Art. 6 (1)(e) or (f) GDPR you may object on grounds relating to your particular situation. We will stop unless we have compelling legitimate grounds or the processing is for legal claims.
To exercise these rights, email lorenz@dignified.media. Signed-in users can also delete their account from the user menu (web) or Profile → Delete account (companion) when workspace-ownership rules allow it. You also have the right to lodge a complaint with a supervisory authority — for us, typically the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA).
11 / Safeguards
Security and contact
We use technical and organizational measures appropriate to a media workspace (access control, encryption in transit, hashed passwords, scoped review links). No method of transmission or storage is completely secure.
You are responsible for access data, for who you invite, and for how widely you share review or transfer links.
Contact
Questions about this policy or data protection:
Email: lorenz@dignified.media
Phone: +49 160 6271848