Privacy and cookies
How personal data is used on the GamerCoin website and in GamerCoin Studio, including AI generation, browser storage and the community gallery.
Last updated: 1 October 2026
Operator and contact
CoinAxe Limited · C 94976
Dragonara Business Centre, 5th Floor, Dragonara Road, St. Julians STJ 3141, Malta.Privacy enquiries and rights: [email protected]
Who is responsible
CoinAxe Limited is responsible for the personal data described in this notice. Its company details and contact route are provided in the operator information on this page. This notice covers the GamerCoin website and GamerCoin Studio. Separate services reached through external links have their own notices.
Studio offers AI-assisted creation without requiring a Studio account. Information can still relate to an identifiable person without an account or a name. This includes online identifiers and personal information included in a creative idea, image, lyrics or other submitted content.
Information we handle
We process the content and choices you submit to operate a feature: creative ideas, prompts, lyrics, selected styles and presets, reference material and generation settings. Results may include generated text, images, music or video. Please avoid sensitive information, private material and personal details about others.
Operational records can include request and provider job identifiers, timestamps, status, selected model or preset, output references, error details, usage counters and moderation decisions. If you contact us, we receive the information you choose to send. Gallery submissions also involve the selected work, submission details and your publication choice.
Network information and abuse prevention
Your IP address is necessarily visible to systems handling the network request, including hosting, proxy or security infrastructure. Studio derives a keyed pseudonymous identifier from network information to enforce shared usage limits. Its application quota and job ledger uses this identifier rather than storing the raw IP address in that ledger.
This does not mean your connection is anonymous or that raw IP addresses never appear in infrastructure logs. Hosting, proxy, security-log and backup retention must be confirmed for the production environment. People using the same internet connection can share a usage limit.
Why we use information
We use the information needed to carry out the creation or download feature you request, manage jobs, return results and maintain a working session. Where necessary to provide the requested service, the proposed legal basis is performance of our agreement with you under Article 6(1)(b) GDPR.
Preventing misuse, enforcing proportionate limits, investigating failures and protecting the service may rely on our legitimate interests under Article 6(1)(f) GDPR, subject to your rights. Records required by law are processed under Article 6(1)(c). Optional tracking relies on your consent under Article 6(1)(a) where consent is required.
Public gallery publication relies on your separate consent under Article 6(1)(a) GDPR where the submitted work or related information contains personal data. This data-protection consent is distinct from the permission to use the work under the gallery licence in the Studio terms. Generating a work does not give either permission automatically.
AI processing and service providers
Studio uses Hetzner hosting in Germany and Cloudflare R2 object storage configured in the EU. When optional analytics and marketing are disabled, Google is used only for administrator authentication, including processing the administrator’s email address. If optional Google tags are enabled, they are subject to the separate consent choices described below. Visitors do not need a Google sign-in to create. Cloudflare DNS and CDN services are planned and are not currently enabled for this deployment. Gallery videos and posters stored in R2 can be served through temporary signed links. Following such a link sends a browser request to Cloudflare, which receives the network information needed to serve it.
A generation request sends the relevant input and settings through our server to the services needed for that request. Text assistance may use OpenRouter; generation may use deAPI and downstream model or computing providers. Which route is available depends on the feature and deployment configuration.
Inputs must be processed to produce a result even when saving prompts in our own job records is disabled. A setting that disables our prompt storage is not a promise that no provider processes, temporarily holds or retains the content.
Saving user inputs and provider prompts in the generation ledger for administrator review is optional and controlled by the operator’s configuration. Operational errors and processing notes are recorded independently of that prompt-storage choice. Disabling prompt storage does not remove the browser’s original video-idea snapshot or the scene text stored with an explicitly submitted gallery work.
deAPI publicly identifies CoinAxe as its operator. If the same legal entity operates Studio and deAPI, that step is internal processing rather than disclosure to a separate company. External model providers, distributed computing operators and other service providers still need to be identified and assessed. The actual contracts, recipients and settings require confirmation.
Provider retention and international transfers
Providers have their own retention and data-use rules. OpenRouter distinguishes its own logging and product-improvement options from the policies of the selected model endpoint. Disabling training and requiring zero retention are different controls. Neither can be assumed from a model name.
Processing may take place outside the European Economic Area, including in the United States, depending on infrastructure and routing. Before final publication, we must confirm the recipient list, processing countries, applicable data-processing agreements and transfer safeguards, such as an adequacy decision or Standard Contractual Clauses where applicable. This draft does not establish that a particular agreement has been signed or that EU-only routing or zero retention is enabled.
Cookies and storage in your browser
Studio uses a session cookie and browser storage to support requested features, protect requests and restore work after a reload. Tab-scoped session storage can include job identifiers, status, errors and retry information, selected presets, music or image work state, and a snapshot containing the full original video idea for the gallery submission flow.
Tab-scoped storage normally lasts for the browser tab session; browser restoration behavior can vary. It is separate from records on our servers and at providers. Clearing browser data does not delete those other records. The storage table explains the specific items and durations.
Nonessential analytics or marketing storage must remain disabled until you choose the relevant purpose. You can reject optional purposes and later change or withdraw your choice through Cookie settings. Withdrawal does not undo processing lawfully carried out before it.
Choosing to publish in the gallery
Generating a work and submitting it for public display are separate actions. Public gallery publication requires a specific submission choice and approval. A pending or rejected submission is not intended to appear in the public gallery. Automated intake of private previews must remain disabled in production.
An approved work can be viewed, downloaded and reused by other people within the permissions described in the Terms of use. Do not submit content that reveals private information or that you cannot authorize for public use. You may request removal and withdraw consent to future publication. Copies already downloaded or shared by others may remain outside our control.
How long information remains
Studio job and quota records become eligible for cleanup after 48 hours. Cleanup runs when a subsequent successful request reservation occurs, so 48 hours is a threshold, not a guaranteed deletion time. Provider records and output availability follow separate arrangements.
Gallery records and copied gallery media are durable and currently have no automatic expiry. They remain until deleted under an operational decision or removal request. Rejecting a submission or removing its public visibility does not itself erase stored records or media. Retention and deletion rules for pending and rejected submissions need an approved operational schedule.
A signed media link may expire after 15 minutes; that limits access through that link and does not delete the underlying object. Production retention for server logs, support correspondence, moderation records and backups must also be confirmed. We may retain information when a specific legal obligation or the establishment, exercise or defence of legal claims requires it.
Your choices and rights
Subject to the applicable conditions, you may request access, correction, erasure, restriction or portability of personal data, and object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.
Use the contact route in the operator information. Because Studio does not require accounts, a job or submission identifier can help locate relevant records; do not send unnecessary identity documents. We may need proportionate information to verify a request. GDPR requests are generally answered within one month, with any permitted extension explained to you.
Complaints, security and updates
You may complain to a competent supervisory authority, including the authority in the EU country where you live, work or believe an infringement occurred. In Malta, this is the Information and Data Protection Commissioner (IDPC). The official complaint link is provided with the sources on this page.
We use controls appropriate to the service and restrict administrative access, but no online service can guarantee absolute security. Studio is intended for adults aged 18 or over under the proposed Terms of use. If you believe a child has submitted personal data, contact us. We will update this notice when processing changes and identify material changes through an appropriate notice.
Cookies and browser storage
Essential cookies are set when the relevant Studio or admin function is used, not simply by visiting the landing page. Only optional categories you explicitly allow can run. Browser storage listed below is first-party.
| Name / technology | Purpose | Lifetime | Scope / category |
|---|---|---|---|
ghx_studio | Signed anonymous Studio session, ownership of jobs and abuse prevention. HttpOnly, SameSite=Strict; Secure on HTTPS. | 48 hours | Essential · cookie · /api/studio |
ghx_studio_admin | Authorised admin session. Google sign-in sessions also contain the admin email in the signed cookie. HttpOnly, SameSite=Strict; Secure on HTTPS. | 45 minutes | Essential · admin cookie · /api/studio-admin |
ghx_admin_oauth | Protects the Google admin sign-in flow. HttpOnly, SameSite=Lax; Secure on HTTPS. | 10 minutes | Essential · admin cookie · /api/auth |
gamercoin.cookie-consent | Your optional-category choices, policy version, configuration identifier, choice date and expiry. Written only when you save a choice. | 180 days | Essential · localStorage |
gamercoin:studio:* | Restore task IDs, status and limits in the current tab. Video recovery also keeps the scene description and selected settings, including the text later offered for gallery submission. | Browser tab session; browser session restoration may retain it until the session is cleared. | Essential · sessionStorage |
gamercoin:community:submission:* | Remembers that this tab submitted a particular video for review. | Browser tab session | Essential · sessionStorage |
_ga, _ga_* | Google Analytics visit measurement. | Up to 180 days; Google cookies may refresh on use. | Analytics — consent required |
Only the configured optional categories shown in Cookie settings are available. The Google tag is not requested before consent. Withdrawal clears supported first-party tracking cookies and reloads the page without the withdrawn tags.