Privacy Policy

Stand: August 2026

This is a translation for convenience. In case of any discrepancy, the German version at myhologram.ch/datenschutz prevails.

1. Controller

The controller for data processing on this platform is: Tanir Myhologram, sole proprietorship under Swiss law, owner Caglar Tanir, Schönbüelstrasse 6, 8304 Wallisellen, Switzerland. Email: info@myhologram.ch, phone: +41 76 776 71 80.

Data protection officer: not appointed (not legally required). Please address data protection requests to info@myhologram.ch.

2. General & legal bases

We process personal data in accordance with the GDPR and — where applicable — the Swiss FADP. The legal bases are in particular Art. 6(1)(b) GDPR (contract/account), (a) (consent, e.g. Google sign-in, optional cookies), (f) (legitimate interest, e.g. operation/security) and (c) (legal obligations).

3. Hosting & server log files

The platform is hosted by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany (Nuremberg data centre). When you access it, technically necessary access data (IP address, date/time, requested resource, user agent) are processed for delivery, stability and security (Art. 6(1)(f)). These logs are used solely for operation, error analysis and defence against attacks, are not combined with other data sources, and are deleted once they are no longer required for those purposes. A data processing agreement is in place with the host.

4. Cookies & local storage

We use no tracking cookies without consent. Technically necessary are: a sign-in token (login), the record of your cookie decision, and the light/dark mode (each in the browser’s local storage). Optional categories (statistics, marketing) are only activated after active consent via the cookie banner (Art. 6(1)(a)) and are currently not in use. Consent can be withdrawn at any time via “Cookie settings” in the footer.

5. Account & registration

For an account we process your email address and password (stored as a hash only). Depending on the operating configuration, an activation code issued by us and supplied with the hardware may additionally be required. Legal basis: performance of a contract (Art. 6(1)(b)).

6. Transactional emails

For account confirmation, password resets and email changes we send emails via the mail server of our provider IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (Art. 6(1)(b)). A data processing agreement is in place.

7. Contact form

If you use our contact form, we process the data you enter there (name, email address, optionally phone number and company, and your message) in order to answer your enquiry. The enquiry is delivered to us by email and is not stored in a separate database. The legal basis is our legitimate interest in answering enquiries (Art. 6(1)(f)) or pre-contractual measures (Art. 6(1)(b)). To protect against abuse, the sending IP address is evaluated briefly for rate limiting.

8. Payment processing

Payments are processed via Stripe (Stripe Payments Europe, Ltd.) and, where applicable, PayPal. Payment data (e.g. card details) are processed exclusively by the payment provider — we do not receive them. Their privacy notices apply. Legal basis: performance of a contract (Art. 6(1)(b)).

9. Sign in with Google (OAuth)

You may optionally sign in with Google. In doing so, your Google profile data (identifier, verified email address) are transmitted to us; Google’s own privacy policy applies in relation to Google. Legal basis: consent / pre-contractual measures (Art. 6(1)(a)/(b)). Provider: Google Ireland Ltd.

10. AI generation of media

For the AI features (AI images, AI videos, advertising-text suggestions) we work with a single processor: xAI (Grok), X.AI LLC, USA. We do not operate our own AI model and we do not use any other AI provider.

What is transmitted, and nothing else:

  • the text you enter — the prompt, or the industry, occasion and keyword fields for the advertising-text suggestions;
  • a photo or image only if you select one as a source yourself (the “image → image” and “image → video” features) — including photos you upload from your device’s photo library. People depicted in such images are covered by this;
  • technical generation parameters (model, aspect ratio, resolution, video length).

What is not transmitted: your email address, your name, your account or customer number, your device serial numbers, and your IP address. The request is made by our server; no end-user identifier is exposed to xAI. We fetch the results into our own storage (Hetzner, Germany) immediately after generation, so your content is not stored permanently at the provider.

The legal basis is your consent (Art. 6(1)(a) GDPR). We obtain it in the app and on the web before you generate anything with AI for the first time; without it, the AI features are blocked. You may withdraw it at any time with effect for the future — in the app under “Settings”, on the web under “Settings → Account”. Withdrawing is as easy as giving consent (Art. 7(3) GDPR) and does not affect media you have already generated. The transfer to the USA is based on the EU Standard Contractual Clauses.

Please do not generate personal or infringing content. In particular, do not upload photos of other people without their consent.

11. Media upload, processing & transfer to devices

Uploaded or generated media are stored (self-hosted object storage on the Hetzner server, Germany), prepared for the hologram devices (cropping/transcoding) and transferred to the devices assigned to you. In doing so we process device identifiers (serial numbers) and transfer status. Reported or removed content is deleted and its hash blocked (re-upload protection).

12. Retention

We retain data only for as long as necessary for the stated purposes or as required by statutory retention periods. In detail:

  • Account and media data: immediately upon account deletion — email address, password hash and Google identifier are removed or anonymised, uploaded and generated media files are physically deleted, device, group and schedule assignments are released, and the account is deactivated. How to delete your account — in the app or by email, also without the app — is described at myhologram.ch/konto-loeschen.
  • Order, subscription and payment records: retained for ten years due to statutory commercial and tax retention obligations.
  • Device connection logs (hologram devices signing on and off): deleted automatically after 90 days.
  • Confirmation and password links: expire automatically — account confirmation after 24 hours, password reset and email change after one hour.
  • Contact enquiries: deleted once your matter has been dealt with conclusively, at the latest after twelve months.

13. Your rights

  • Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18)
  • Data portability (Art. 20) and objection (Art. 21)
  • Withdrawal of consent given, with effect for the future (Art. 7(3))
  • Complaint to a supervisory authority — in Switzerland with the FDPIC (Federal Data Protection and Information Commissioner), for EU customers with the competent data protection authority

Please address requests to info@myhologram.ch.

14. Data security

Transmission is encrypted (TLS/HTTPS). Passwords are stored exclusively as a secure hash; access to account, device and media functions is authenticated and permission-checked.

15. Changes

We adapt this privacy policy when processing activities or the legal situation change. The version published here at the time applies.