CineMake Privacy Policy
Effective Date: October 10, 2026 Version: 0.10.0
Scope
- This Privacy Policy describes how CineMake processes personal data when you use our AI filmmaking services and related sites, and how we share data with Providers (OpenAI, Google Veo/Vertex AI, Supabase, Clerk, Vercel, and our Payment Processor) to operate the Service.
- Provider Privacy Policies: Your use of Provider services through CineMake is also subject to their respective privacy policies:
- OpenAI Privacy Policy (updated June 27, 2025) — governs how OpenAI collects and processes data when you use features powered by their models
- Google Cloud Privacy Notice (effective December 18, 2025) — governs Service Data processing for Google Cloud Platform services including Vertex AI/Veo
- Payment Processor Privacy Policy — governs payment data processing for checkout and billing (see your receipt for the current processor)
Categories of Data We Process
- Account & identity data (via Clerk): email, identifiers, authentication signals, and account status.
- Technical/log data: IP address, user agent, device/OS, timestamps, policy version accepted, consent surface (web/mobile), and in-app events required for security, fraud prevention, analytics, and audit. Supabase PostgreSQL stores audit logs with append-only retention policies.
- Rendering metadata: prompts, settings, model/provider selections, generation IDs, watermarks, output hashes, and related operational data.
- Billing/commerce metadata (via Payment Processor): transaction IDs, currency, amount, taxes, payment method type, subscription status, credit pack purchases, refund status, and break-the-seal timestamps. Our Payment Processor is Merchant-of-Record and handles payment card data securely—CineMake does not store payment card numbers.
- Credit usage data: Credit pack status (unopened/opened/refunded), refund window expiry dates, consumption timestamps, FIFO tracking, and usage snapshots for billing reconciliation.
- Hosting/analytics telemetry (via Vercel): privacy-forward analytics that do not use third-party cookies; visitors are identified by a request hash and session data is short-lived.
- AI interaction data: We collect the following data related to your interactions with AI systems in the Service:
- Prompts and inputs: Text descriptions you provide for project creation (Story Agent) and video render settings.
- AI model responses: Structured outputs from AI models, including generated screenplays, scene descriptions, and video generation metadata.
- LLM audit records: For each AI interaction, we record the prompt version identifier, prompt content hash, model requested and used, token usage (input/output/total), generation elapsed time, continuation and fallback metadata, structural and character-limit resolution outcomes, request correlation IDs, and provider response IDs. These records support transparency, quality assurance, and regulatory compliance (EU AI Act Art. 12).
- Prompt version metadata: We maintain a versioned registry of AI prompt templates used by the Service, including version labels, content hashes, activation timestamps, lifecycle status (draft, active, rollback, archived), changelog entries, and evaluation results.
- AI feedback data: If you choose to provide feedback on AI outputs, we collect your ratings (1-5 stars for Story Agent, thumbs up/down for renders), selected feedback tags, and optional free-text comments. Feedback is linked to your user ID and the associated project for quality improvement purposes.
- Content safety assessments: Per-scene safety ratings generated by AI models, including overall rating, flagged categories, confidence scores, and rationale.
- Organization membership data: If you are a member of an Organization, we collect your organizational role (e.g., team_admin, team_member), privilege assignments (e.g.,
can_manage_billing,can_manage_members), Organization association, and membership status. This data is used to enforce role-based access control and organizational policies. - Organization-level billing data: For Organizations, we collect and process billing data specific to the Organization entity, including the Organization's payment methods, invoices, subscription status, credit pool transactions, credit pack purchases and their status (unopened/opened/refunded), and org-level refund records. This data is maintained separately from individual members' personal billing data.
Purposes and Legal Bases
- We process data to:
- authenticate and manage accounts (Clerk) — Legal basis: contract performance;
- render outputs, deliver features, and moderate per Provider policies — Legal basis: contract performance, legitimate interest (safety);
- bill, track credits, and handle taxes/refunds (Payment Processor) including break-the-seal refund eligibility tracking for both personal and Organization-level purchases — Legal basis: contract performance, legal obligation (tax);
- secure, audit, and comply using Supabase PostgreSQL audit tables and immutable Ledger entries — Legal basis: legitimate interest (security, fraud prevention), legal obligation;
- measure and improve using privacy-forward, cookie-less analytics — Legal basis: legitimate interest (service improvement);
- maintain AI transparency and compliance including prompt versioning audit trails, LLM interaction records, and content provenance metadata as required by the EU AI Act (Regulation 2024/1689, Articles 12, 13, 50) and California AI Transparency Act (SB 942) — Legal basis: legal obligation (AI regulatory compliance), legitimate interest (system integrity and transparency); and
- improve AI quality using aggregated, anonymized feedback metrics (average ratings, tag frequency distributions) to evaluate and refine AI system performance — Legal basis: legitimate interest (service improvement). Individual feedback responses are not shared with AI providers in an individually identifiable form.
- We process data to:
Sub-Processors
We share personal data with the following sub-processors to the extent necessary to operate the Service:
Sub-Processor Purpose Location Transfer Mechanism Supabase Database, backend, audit logs, AI audit records US (AWS us-east-1) DPA with SCCs Clerk Authentication, identity, consent metadata US DPA with SCCs Vercel Hosting, edge network, serverless compute, analytics US/Global (edge) DPA with SCCs Google Cloud Platform (Vertex AI / Veo, Cloud Storage) Video generation, asset storage, SynthID watermarking US (us-central1) Google Cloud DPA with SCCs OpenAI AI model inference (prompt processing, story generation) US DPA with SCCs Payment Processor (Stripe) Payments, checkout, tax, refunds (Merchant-of-Record) for both personal and Organization-level transactions See receipt DPA with SCCs Each sub-processor publishes its own DPA and compliance materials. We maintain contractual safeguards with each sub-processor requiring them to process data only on our instructions and to implement appropriate technical and organizational security measures.
We will update this table when we add or replace sub-processors. Material changes to sub-processors will be communicated via email or in-app notification.
AI-Specific Data Processing
- No Training on User Data. CineMake does not fine-tune, train, or adapt any AI model using your data. We use base models as provided by OpenAI and Google. Your prompts and outputs are processed solely to deliver the Service.
- Provider Data Processing: When you use the Service, your prompts are sent to OpenAI (for story/scene generation) and Google Vertex AI (for video generation). Per Google Cloud Terms, Google does not use Customer Data to train models. Per OpenAI's data usage policies, API inputs and outputs are not used for training unless you opt in. CineMake's API access is configured to not contribute to training.
- AI Audit Data. We maintain detailed records of AI interactions (LlmResponse audit records) including model identifiers, token usage, prompt version hashes, and generation metadata. This data is used for: (a) transparency and compliance with EU AI Act Art. 12 record-keeping requirements; (b) monitoring AI system performance and reliability; (c) investigating and resolving service issues; and (d) quality assurance through prompt versioning. Audit records do not contain your raw prompts or outputs — they contain metadata about the AI interaction.
- AI Feedback. Feedback you voluntarily provide on AI outputs (ratings, tags, comments) is used to: (a) measure aggregate AI quality metrics; (b) identify areas for improvement in our AI pipeline; (c) support post-market monitoring as recommended by the EU AI Act. Feedback is linked to your user ID for data deletion purposes but is never shared with AI providers in an individually identifiable form.
- Content Provenance. AI-generated videos include invisible SynthID watermarks embedded by Google Veo for content provenance. CineMake adds visible "AI-Generated" badges. We are implementing C2PA Content Credentials for machine-readable provenance manifests. These measures support compliance with EU AI Act Article 50 and California SB 942.
International Transfers
- Your data may be transferred to and processed in countries outside your country of residence, including the United States. Where data moves across borders (specifically from the EEA, UK, or Switzerland to third countries), we rely on:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), incorporated into our DPAs with each sub-processor;
- UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs where applicable;
- Supplementary measures including encryption in transit (TLS 1.2+), encryption at rest, and access controls.
- You may request a copy of the relevant transfer mechanisms by contacting support@cinemake.ai.
- Your data may be transferred to and processed in countries outside your country of residence, including the United States. Where data moves across borders (specifically from the EEA, UK, or Switzerland to third countries), we rely on:
Retention
We retain personal data only as long as necessary for the purposes outlined below. Specific retention periods are:
Data Category Retention Period Justification Ledger/consent records, security logs Account lifetime + 7 years Legal obligation (audit, tax, compliance) Billing and transaction data Account lifetime + 7 years Legal obligation (tax reporting, financial records) Org-level billing and transaction data Organization lifetime + 7 years; anonymized upon org deletion Legal obligation (tax reporting, financial records) Credit pack and usage data Account lifetime + 3 years Billing reconciliation, dispute resolution Rendering metadata Account lifetime + 1 year (anonymized) Service improvement, moderation Rendering outputs (videos, images) Until you delete them forever or your account is erased Contract performance AI audit records (LlmResponse) Account lifetime + 3 years EU AI Act Art. 12 record-keeping, CA SB 942 Prompt version metadata Retained indefinitely (no personal data) Regulatory compliance, system integrity AI feedback data Account lifetime + 1 year (anonymized) AI quality monitoring, post-market monitoring Account and identity data Erased 30 days after account deletion — Analytics telemetry 90 days (Vercel-managed, no PII) Legitimate interest (service improvement) Deleted (archived) items Kept in your Archive until you delete them forever Contract performance (restore on request) Recovery copies of permanently deleted media Up to 90 days, then purged Disaster recovery only Post-Deletion Processing. When you delete your account, erasure is scheduled for 30 days later. Until then you may cancel it by contacting support@cinemake.ai. When erasure runs:
- Account data and rendering outputs (including archived items) are permanently deleted, and in-app notifications and product analytics events are deleted.
- Billing records are pseudonymized (user identifiers replaced with opaque hashes) and retained for the legally required period.
- Ledger entries are pseudonymized and retained for audit compliance.
- AI audit records are pseudonymized and retained for the regulatory compliance period.
- AI feedback is anonymized (de-linked from user identity) and retained in aggregate form.
- Anonymized, aggregated data (which cannot identify you) may be retained indefinitely for analytics.
Organization Deletion. When an Organization is deleted:
- Org-level billing records (payment history, invoices, credit pool transactions) are retained per regulatory requirements (tax reporting, financial records) but anonymized — Organization identifiers are replaced with opaque hashes and member associations are removed.
- Org-level Ledger entries are pseudonymized and retained for audit compliance.
- Organization content and data are erased 30 days after the Organization is deleted, on the same schedule and with the same cancellation window as account deletion.
- Individual members' personal accounts and billing records are not affected by Organization deletion.
Content Retention. Your projects, scenes, characters, assets and generated media — both the original files we receive from our video provider and the web-playable copies we create — are kept until you permanently delete them. We do not delete your content because of age or inactivity.
Archive. When you delete a project, scene, render, character, brand asset, or other entity, it moves to your Archive, where it is kept indefinitely and can be restored at any time. Nothing in the Archive is deleted automatically.
Delete Forever. Choosing "Delete forever" in your Archive removes the item and its associated data from the Service immediately and irreversibly. Media that is still used by another item you or your Organization keep (for example, a copy or a transferred project) is not removed. Our cloud storage keeps internal recovery copies of deleted media for up to 90 days solely to recover from operational incidents; these copies are not accessible through the Service, are not used for any other purpose, and are purged automatically after that period.
Storage Tiering. Media you have not accessed recently is automatically moved to lower-cost archival storage classes within Google Cloud Storage. Tiering does not delete, alter or reduce the quality of your content.
Legal and Compliance Removal. We may permanently remove content without placing it in your Archive when required by law or to address abuse — for example, in response to a valid copyright notice, a court order, a privacy request, or content involving child sexual abuse, non-consensual intimate imagery or terrorism. Each removal is recorded with its legal basis.
Your Rights
Subject to applicable law, you may exercise the following rights:
- Access: Request a copy of your personal data, including AI interaction records and feedback data.
- Rectification: Correct inaccurate personal data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations. AI audit records will be pseudonymized rather than deleted where retention is required by EU AI Act Art. 12.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Portability: Receive your data in a structured, machine-readable format, including your AI-generated projects, feedback history, and interaction metadata.
- Objection: Object to processing based on legitimate interest.
- Withdraw Consent: Where processing is based on consent, withdraw at any time without affecting the lawfulness of prior processing.
- AI-Specific Rights: You have the right to: (a) be informed that you are interacting with an AI system (we disclose this prominently in-product and in our AI Transparency Disclosure); (b) receive meaningful information about the AI systems used to generate your content (see
/legal/ai-transparency); (c) provide feedback on AI output quality; and (d) request human review of AI-generated content assessments.
To exercise any right, use your account settings or contact support@cinemake.ai. We will respond within 30 days (extendable by 60 days for complex requests, with notice).
Provider-Specific Rights:
- OpenAI: You can exercise rights through privacy.openai.com or dsar@openai.com per their Privacy Policy
- Google Cloud: Rights requests should be directed to your Google Cloud account settings or Google's data subject request process
- Payment Processor: For payment data inquiries, contact the Payment Processor directly (see your receipt) or submit requests through support@cinemake.ai
Right to Lodge a Complaint. If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local data protection supervisory authority. For EU residents, a list of supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Data Training Opt-Out
- CineMake: We do not train AI models on your data. There is no training to opt out of.
- OpenAI: Per OpenAI's data usage policies, API data is not used for training by default. CineMake uses the API pathway. You can verify this at openai.com/policies/how-your-data-is-used-to-improve-model-performance
- Google Cloud: Per Google Cloud Terms, Google does not train models on Customer Data by default for Google Cloud Platform services
Children's Privacy
- Our Service is not directed to children under 13. Per OpenAI's Privacy Policy, their Services are not directed to children under 13, and users under 18 must have parental permission.
Data Protection Contact
- For data protection inquiries, requests, or complaints, contact our Data Protection Officer at: dpo@cinemake.ai or support@cinemake.ai.
Changes to This Policy
- We may update this Privacy Policy from time to time. Material changes require re-acceptance via our consent flow. The Ledger records the version you accepted. We will notify you of material changes via email and/or in-app notification at least 14 days before the changes take effect.