50/50 Studio
Log inCreate account

Privacy Policy

Last updated: June 2, 2026

1. Controller

Controller under the GDPR:

Daniel Meier Eckersmühlener Hauptstr. 115 91154 Roth Germany Email: support [at] 5050studio [dot] com

2. Overview

5050 Studio processes personal data to provide accounts, authentication, AI workflows, prompt management, public and community prompts, reporting and moderation, media uploads, generated media, billing, support, security, and privacy-respecting analytics.

The application is hosted by netcup GmbH at Nürnberg, Germany. Uploaded and generated media are stored in private Cloudflare R2 object storage using the European Union jurisdictional restriction. Analytics use a privately hosted Umami instance at um.dnlmr.de without advertising tracking or profiling.

5050 Studio does not use User Content to train AI models operated by 5050 Studio.

3. Data Categories

Depending on how you use 5050 Studio, the following categories of data may be processed:

  • Account data: name, email address, password hash, email verification status, age eligibility confirmation through acceptance of the Terms, account settings.
  • Authentication and security data: sessions, IP address, user agent, CSRF and session cookies, remember tokens, two-factor authentication data, passkey data, security logs.
  • Billing data: Paddle customer identifiers, subscription identifiers, transaction identifiers, plan status, trial dates, invoice and tax-related metadata. 5050 Studio does not receive or store full payment card details; Paddle handles checkout and payment data.
  • User Content: prompts, prompt variables, workflow definitions, source URLs, tags, descriptions, uploaded files, generated images or videos, thumbnails, previews, public and community prompts, and related metadata. User Content may contain personal data if you include it.
  • Moderation and reporting data: reports, reporter and reported account identifiers, reported content, moderation status, reviewer notes, timestamps, enforcement actions, and content snapshots where necessary.
  • AI usage data: provider, model, operation type, input and output units, estimated cost, status, errors, timestamps, and workflow execution metadata.
  • Bring Your Own Key data: encrypted provider API keys, provider names, key hashes, default-key flags, and last-used timestamps.
  • Feedback and support data: messages, source path, user agent, accept-language header, and correspondence.
  • Analytics data: page views, referrers, browser, operating system, device type, country-level location, and events collected through the privately hosted Umami instance.

4. Purposes And Legal Bases

The legal bases under the GDPR may include:

  • Article 6(1)(b) GDPR: account creation, authentication, service delivery, workflows, media processing, trials, billing-related service features, and support requested by you.
  • Article 6(1)(c) GDPR: legal obligations such as tax, accounting, compliance, and lawful requests.
  • Article 6(1)(f) GDPR: security logging, fraud and abuse prevention, service reliability, moderation, reporting, rights enforcement, payment-provider policy compliance, provider-policy compliance, defense of legal claims, and privacy-respecting service analytics.
  • Article 6(1)(a) GDPR: optional consent-based processing, such as marketing emails or other non-essential processing that requires consent.

Account, authentication, billing, workflow input, media processing, and security data may be necessary to provide 5050 Studio. If you do not provide required data, some or all service features may not be available. Optional feedback, public prompt, and consent-based data can be withheld, but the related optional feature may not work.

Do not upload special-category personal data, biometric-identification material, children's data, government IDs, confidential third-party information, or other sensitive personal data unless you have a lawful basis, all required rights and consents, and the upload is permitted by these Terms.

5. Hosting And Storage

Application hosting: netcup GmbH, server location: Nürnberg, Germany

Media storage: Cloudflare R2 object storage using the European Union jurisdictional restriction. Media buckets are private, and access is mediated through authorized application routes unless content is intentionally made public by a supported feature.

Backups, logs, and operational data are stored according to the operator's infrastructure and retention configuration.

6. AI Provider Processing

When you run workflows or provider-powered features, prompts, inputs, uploaded media, generated media, workflow settings, source URLs, and metadata may be transmitted to selected AI providers. AI providers may include fal.ai, Replicate, kie.ai, WaveSpeedAI, and other providers where you select or configure them.

If you connect your own API keys, provider processing may occur under your direct relationship with that provider. The selected provider's own terms, privacy policy, data processing rules, usage restrictions, retention practices, and content policies apply.

Relevant provider privacy and data information may include fal.ai's Privacy Policy, Replicate's Privacy Policy and data retention documentation, kie.ai's Privacy Policy, and WaveSpeedAI's Privacy Policy.

7. Processors And Recipients

Personal data may be processed by or disclosed to the following categories of recipients where necessary:

  • Hosting provider: netcup GmbH
  • Cloudflare R2 for private object storage with European Union jurisdiction activated. Cloudflare's public privacy and data-processing information is available from Cloudflare.
  • Paddle as Merchant of Record / authorized reseller for billing, payment processing, tax handling, invoices, subscriptions, refund handling, fraud prevention, and buyer support. Paddle's public legal information includes its Privacy Policy, Buyer Terms, and Refund Policy.
  • Privately hosted Umami instance at um.dnlmr.de for privacy-respecting analytics.
  • AI providers selected by you or configured in workflows, including fal.ai, Replicate, kie.ai, and WaveSpeedAI where applicable.
  • Authorities, courts, advisors, payment processors, or claimants where legally required or necessary to defend rights.

No external transactional email provider is currently used. If 5050 Studio sends transactional email, it is sent through the operator's own configured infrastructure unless this Privacy Policy states otherwise.

8. Cookies, Local Storage, And Analytics

5050 Studio uses essential cookies and similar technologies needed for authentication, session management, CSRF protection, security, and preferences. These are required to provide the service.

Analytics use a privately hosted Umami instance at um.dnlmr.de. This analytics setup is used without advertising tracking, cross-site tracking, or analytics cookies.

Paddle checkout or billing pages may load Paddle scripts and may use cookies or similar technologies for payment, fraud-prevention, and checkout purposes.

9. Retention

Personal data is retained only as long as necessary for the purposes described in this Privacy Policy, unless longer retention is required by law or needed for legal claims, security, backups, billing, fraud prevention, or dispute handling.

Retention is determined by the relevant data category, legal requirements, account status, deletion requests, technical configuration, and processor limitations. In particular:

  • Account data is retained for the life of the account and then deleted or anonymized where technically and legally possible, subject to statutory retention duties, billing and tax records, security logs, backups, and dispute records.
  • User Content is retained until deletion by the user, account deletion, applicable cleanup logic, or another lawful retention endpoint, subject to backups, legal retention, moderation and reporting needs, and processor limitations.
  • Creations and media for expired, unconverted trial accounts are scheduled for deletion after a 7-day grace period after trial expiry.
  • Billing and tax records are retained for statutory periods, generally up to 10 years under German tax and commercial law where applicable.
  • Session records follow the configured session lifetime and related garbage collection. The current default session lifetime is 120 minutes.
  • Application logs currently use a 14-day daily log retention configuration.
  • Security logs, support correspondence, moderation records, API usage logs, analytics, and backups are retained for periods appropriate to the purpose, legal duties, operational security, and dispute handling. Specific internal retention periods are maintained by the operator and adjusted where required by law or service security.

10. International Transfers

The app server is hosted as stated above, and media storage uses Cloudflare R2's European Union jurisdictional restriction. Third-party providers such as AI providers, Paddle, Cloudflare, and support or operational tooling may process data outside the EU/EEA.

Where required, transfers rely on appropriate safeguards, such as adequacy decisions, standard contractual clauses, supplementary measures, or another lawful transfer mechanism.

11. Security

5050 Studio uses technical and organizational measures to protect personal data. These may include HTTPS, hashed passwords, encrypted stored API keys, private media storage, authorized media delivery routes, account authentication, rate limiting, moderation controls, and restricted operational access.

No system is completely secure. You should use strong passwords, enable available security features, protect API keys, and promptly report suspected unauthorized access.

12. Your Rights

Subject to the legal requirements of the GDPR, you may have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Delete your data.
  • Restrict processing.
  • Receive data portability.
  • Object to processing based on legitimate interests.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with a supervisory authority.

Competent supervisory authority: BayLDA

You can send privacy requests to support [at] 5050studio [dot] com. The operator may need to verify your identity or account ownership before responding. Requests are handled within the statutory GDPR response periods.

13. Minimum Age

5050 Studio is not for minors. The minimum age for account registration and use is 18 years. If you believe a minor has provided personal data, contact support [at] 5050studio [dot] com.

14. Automated Decisions

5050 Studio uses AI provider integrations to generate or transform creative content at your request. The service does not make legally significant automated decisions about users.

15. Changes To This Privacy Policy

This Privacy Policy may be updated to reflect legal, technical, or product changes. Material changes will be communicated in a reasonable way.

Personal data may be transferred where necessary for a business transfer, restructuring, merger, acquisition, or asset sale, subject to applicable law and appropriate notice where required.

16. Contact

Privacy questions and requests: support [at] 5050studio [dot] com

TermsPrivacyImprint