JoltiHow it worksDemoPricing
Sign inStart your event

© 2026 Jolti

ImprintPrivacy PolicyTermsWithdrawalDPASupport

Privacy Policy

This policy describes how Jolti (Snackbits UG i. Gr., Heinrich-Wildung-Weg 8, 21224 Rosengarten, email: support@jolti.app) processes personal data. Version: 24 September 2026.

1. Controller and two roles
Account and billing data vs. guest photos during an event

The controller within the meaning of the GDPR is Snackbits UG i. Gr., Heinrich-Wildung-Weg 8, 21224 Rosengarten, Deutschland, email: support@jolti.app. No data protection officer has been appointed, as the statutory conditions for a mandatory appointment are not met.

Jolti provides a platform through which organizers (also referred to as "hosts"; user accounts that book a pass) create their own events and let guests upload photos via a QR code or link, from which AI-generated videos are created automatically and displayed live on the event screen. From a data-protection perspective there are two separate roles:

  • For an organizer's account, billing, and usage data (sign-up, pass purchase, login, support), Jolti itself is the controller (Art. 4 (7) GDPR).
  • For photos guests upload during a specific event, and the videos generated from them, the respective organizer is the controller. Jolti processes this content on the organizer's behalf as a processor (Art. 28 GDPR). The details, in particular the sub-processors used, are set out in the Data Processing Agreement (DPA).

Guests uploading photos to a specific event also see a short first-visit notice directly on the upload page, naming that event's organizer.

2. What data is processed?
Categories of personal data processed on the platform
  • Account data (organizers): name, email address, password (hash only), user identifier, registration time, language preference, session data (login time, IP address and browser of the session).
  • Order and payment data: booked pass, amount, time, payment status, billing address and, where provided, VAT identification number; when purchasing without an existing account, additionally the email address entered at checkout, with which the account is created after payment. Card payment itself is handled by Stripe; we never receive full card details.
  • Record of withdrawal consent: the wording confirmed at checkout, text version, time, and link to the purchase (§ 356 (4) BGB, Art. 7 (1) GDPR).
  • Event and guest content data: photos uploaded by guests, AI images and videos generated from them, the generation settings chosen by the organizer, a signed device identifier issued by the server (cookie, no user account), the IP address at upload (section 8), processing time and status, and the guest's confirmation before upload (section 9).
  • Credit and usage data: reservations and charges of credits per processing step, counters for uploads and videos per event.
  • Reports and support: name, email address and content of a report of unlawful content (section 10) or of a request via the contact form or email.
  • Technical data: server log data (IP address, timestamp, requested address, browser), error logs, and counters for abuse prevention (section 7).
3. Purposes and legal bases (Art. 6 GDPR)
  • Art. 6 (1)(b) GDPR (contract): providing the platform and the user account, processing pass purchases including purchases without an existing account, running the image and video generations you trigger, sending contract-related emails (e.g. email verification, purchase confirmation, notice when credits are nearly used up, restoring a deleted account), answering support requests.
  • Art. 6 (1)(a) GDPR (consent): where separately obtained, such as the consent to early performance at checkout (see the Right of Withdrawal page). Consent can be withdrawn at any time with effect for the future.
  • Art. 6 (1)(c) GDPR (legal obligation): tax and commercial retention of billing records, handling of reports under the Digital Services Act (DSA).
  • Art. 6 (1)(f) GDPR (legitimate interest): IT security, abuse and spam prevention (rate limiting, device identifier, IP address at upload), platform stability, proof of consent given, asserting and defending legal claims.
4. Recipients, processors, and AI providers
Who processes data on our behalf

We use the following service providers:

  • Hetzner Online GmbH, Gunzenhausen, Germany (hosting): The platform runs on Hetzner servers located in Germany. We operate the database, cache, and object storage for photos and videos ourselves on this infrastructure; Hetzner is a processor (Art. 28 GDPR) for all data stored there.
  • xAI (SpaceXAI LLC, AI image and video generation, USA): Under the Standard Service, Jolti generates the AI images and videos through xAI's API (model "Grok Imagine") using Jolti's own access. For this, the uploaded photo or the intermediate image generated from it and the chosen generation settings are transmitted to xAI, which returns the result. xAI is a sub-processor of Jolti for the organizer's guest content. The transfer goes to the USA (section 5). Jolti does not transmit names, email addresses, or account data to xAI. The basis is xAI's Data Processing Addendum, which forms part of the terms for the xAI API. Jolti uses the API in "Zero Data Retention" mode: xAI holds the photo, settings, and result only for the duration of the generation, does not store them permanently, keeps no logs or backups of them, and deletes them no later than one hour after processing. xAI uploads the finished video directly to Jolti's storage. xAI does not use the content to train AI models.
  • Stripe (payment processing): Sales are handled via Stripe Managed Payments. The merchant of record toward you is the Stripe subsidiary Sold through Link, LLC (USA); payments are processed by its affiliated Stripe companies, in Europe by Stripe Payments Europe, Ltd., Dublin. Sold through Link collects the payment, issues the invoice, calculates and remits VAT, and handles refund requests and payment disputes. The charge appears on your bank or card statement with the prefix “link.com” and the name Jolti. Stripe is itself the controller for the data you provide to Stripe during checkout (in particular payment method, billing address and, where applicable, tax ID); the “Sold through Link” terms (link.com/terms) apply. Jolti receives your name, email address, billing country, amount, and payment status from Stripe. Stripe's privacy notice (stripe.com/privacy) applies in addition.
5. Transfers to third countries (USA)
Safeguards under Chapter V GDPR

AI generation by xAI (SpaceXAI LLC) takes place in the USA. The safeguard for this transfer is the Standard Contractual Clauses adopted by the EU Commission (Art. 46 (2)(c) GDPR, Implementing Decision (EU) 2021/914), Module 3 (processor to sub-processor). They form part of xAI's Data Processing Addendum, are governed by Irish law, and the courts of Ireland have jurisdiction. You can obtain a copy of the Standard Contractual Clauses on request at the address given in the legal notice. Where a recipient is certified under the EU-US Data Privacy Framework (DPF), we additionally rely on the EU Commission's adequacy decision (Art. 45 GDPR). Stripe processes data in the EU and the USA; Stripe, Inc. is certified under the DPF, and Standard Contractual Clauses apply in addition. Stripe collects the data you provide to Sold through Link, LLC during checkout as an independent controller; the transfer to the USA is governed by Stripe's privacy notice.

6. Retention periods
Concrete, technically enforced periods

Account data: If you delete your account, it is first deactivated and can be restored for 30 days via a confirmation link sent by email. After that period your personal data is automatically deleted or anonymized; we keep billing records for the statutory period (generally ten years, § 147 AO, § 257 HGB). Accounts with no activity and no running event receive a notice by email after twelve months of inactivity. If you do not sign in within 30 days of that notice, the account is deleted as described above (including the 30-day restoration period).

Event content (guest photos and the AI images and videos created from them): remains stored while the event is running and for 30 days after it has ended, provided the online gallery has been booked for the event or is included in the pass or subscription; it is then deleted automatically. This applies to all events, including events under a subscription. Without the online gallery, the content is deleted automatically 24 hours after the event ends. The organizer can delete the event or individual content at any time before that; at the latest, the content is deleted together with the account. The organizer receives an email reminder seven days before deletion.

Online gallery: the online gallery is a password-protected web page per event. Anyone who has the link and the password can view and download the photos, AI images and videos it contains. The organizer decides with whom to share the link and password and can exclude individual files from the gallery. Copies that have been downloaded are no longer subject to our deletion.

Guest confirmations and withdrawal consents: are kept as evidence for the duration of the statutory limitation periods (generally three years from the end of the year).

IP address at upload: 30 days (section 8). Server log data: is deleted or anonymized on a rolling basis after 30 days at the latest, unless a specific security incident requires longer retention. lapse twelve months after purchase; the related data is then handled under the rules for account data.

7. Abuse prevention and rate limiting
Device identifier, counters, and spam protection

So that an event cannot be disrupted by mass uploads or reports, the server issues a signed random device identifier as a cookie on the first visit to an event page and counts uploads and reports per device and per event using time-limited counters. The contact form and the report form are protected against automated submissions by a server-side time token. The legal basis is Art. 6 (1)(f) GDPR (protection of the platform and the organizers). The device identifier does not allow any inference about your person and is not shared with other services.

Access to the event. If the organizer has restricted access, your device confirms before the first upload that you are on site – depending on the setting, with a code shown on the screen in the room, a PIN, approval by the organizer, or your location. We only store that, and by which method, this device identifier was admitted; this record is deleted together with the event. For the “location” method your browser asks for your permission; the coordinates are compared once with the venue and are neither stored nor logged. If you do not share your location, a code or PIN is available where the organizer has provided one. For the “approval by the organizer” method, the organizer can require or allow you to enter your name and/or email address; only the organizer sees these details – in the request and in their email or push notification – together with a rough device hint (such as “iPhone · Safari”). They are deleted together with the event. The legal basis is Art. 6 (1)(f) GDPR (protecting the organizer against uploads by outsiders at their expense).

8. IP address at photo upload
Preservation of evidence; automatic deletion after 30 days

When a photo is uploaded, we store the full IP address of the uploading device in addition to the upload metadata. The legal basis is Art. 6 (1)(f) GDPR (legitimate interest in preventing abuse, preserving evidence in the event of legal infringements, and fraud prevention). The IP address is deleted automatically and irreversibly 30 days after the upload, unless in an individual case it is needed longer to pursue a specific incident that has already been reported. You have the right to object to this processing under Art. 21 GDPR.

9. Guest confirmation and depicted persons
Confirmation before upload; documented per Art. 7 GDPR

Guests uploading a photo to an event actively confirm before the upload (via a mandatory checkbox that is never pre-ticked) that they are at least 18 years old and have obtained the express consent of every person depicted; for depicted minors, the consent of their legal guardians and, for minors aged 14 or over, additionally that of the minor themselves.

This confirmation is stored per upload together with the time and the exact text version confirmed, so that the consent can be demonstrated pursuant to Art. 7 (1) GDPR. The uploading guest is responsible for inaccurate statements and may in particular be liable under §§ 22, 33 KunstUrhG (German Art Copyright Act) and Art. 82 GDPR.

Depicted persons who do not agree with the processing or display of a piece of content can have it removed from the screen immediately via the second QR code on the screen or the reporting procedure in section 10; consent once given can be withdrawn at any time with effect for the future (Art. 7 (3) GDPR).

10. Reporting unlawful content (notice and takedown)
Procedure under Art. 16 DSA; generally immediate hiding, review within 72 hours

Reports of unlawful content can be submitted via the report form (the "report content / request deletion" link on the respective event page), stating your name and email address (Art. 16 DSA). Upon receipt you immediately receive a confirmation by email. Reported content is generally made invisible to the public without delay; if one and the same sender reports numerous items of an event, further items remain visible until reviewed. The review takes place within 72 hours by the event's organizer or by us. If it shows that the report was manifestly unfounded, the content is restored or remains visible; otherwise it is permanently deleted. Content is deleted only on the basis of such a decision, never automatically when a deadline expires. You will be informed of every decision and of available remedies (Art. 16 (5), (6) DSA). Our point of contact under Art. 11 and 12 DSA is listed in the Legal Notice.

11. Your rights
Data subject rights under Art. 15 to 22 GDPR

Subject to statutory requirements, you have the right to:

  • access (Art. 15 GDPR),
  • rectification (Art. 16 GDPR),
  • erasure (Art. 17 GDPR),
  • restriction of processing (Art. 18 GDPR),
  • data portability (Art. 20 GDPR); organizers can download an export of their data in their account at any time,
  • object to processing based on Art. 6 (1)(f) GDPR (Art. 21 GDPR),
  • withdraw any consent given, with effect for the future (Art. 7 (3) GDPR).

Two-track deletion path for guest content: since the respective organizer is the controller for event photos and videos, please direct deletion requests about that content primarily to that event's organizer (contact details on the event page). If the organizer is unreachable or does not respond adequately, the reporting function on the event page or an email to support@jolti.app is also available to you.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection of Lower Saxony (Die Landesbeauftragte für den Datenschutz Niedersachsen), Prinzenstraße 5, 30159 Hannover, Germany. You may also contact the supervisory authority of your place of residence.

12. Cookies and local storage
Technically necessary only; no tracking, no advertising

We use only cookies and browser storage that are required to operate the platform (§ 25 (2) no. 2 of the German TDDDG). These do not require consent. We do not use cookies for advertising, tracking, or analytics, nor third-party services that set cookies. The cookie notice on your first visit informs you of this; the choice you make there is likewise stored in a cookie so the notice does not appear again.

  • Session (organizer login): our sign-in session cookie so you stay logged in to your account; valid for the session and extended on use.
  • Language ("NEXT_LOCALE"): remembers the chosen language (German/English).
  • Device identifier (event pages): signed random identifier for rate limiting uploads and reports (section 7).
  • Cookie notice ("jolti_cookie_consent"): stores that you have seen the notice; valid twelve months.
  • Browser local storage: acknowledgement of the first-visit notice on event pages, the waiting time between two uploads, and on the TV screen the list of clips already shown. This data never leaves your device.

The legal basis for the associated processing of personal data is Art. 6 (1)(b) GDPR (session, language) or Art. 6 (1)(f) GDPR (abuse prevention). You can delete cookies in your browser at any time; the platform keeps working, you may need to sign in again.

13. Security and changes

All connections are encrypted with TLS, passwords are stored as hashes only, stored API keys are encrypted at rest, and administrative functions are protected by role-based access control. We update this policy when the processing changes; the version published on this page with the date stated above applies.

  • Own mail server: We send contract-related emails through a mail server we operate ourselves on the Hetzner infrastructure mentioned above; no external email service provider is used.
  • Agreements pursuant to Art. 28 GDPR are in place with all processors. Data is disclosed to authorities only where legally required or ordered by an authority or court. No third-party scripts, fonts, or analytics services are loaded on the platform; the fonts used are served from our own servers.

    Never-started passes: