Privacy Policy

Last updated: 10/8/2025

1. Information We Collect

Account information: When you sign up we store your email address, authentication identifiers, and optional profile details inside Supabase tables such as user_profiles and user_preferences.

Billing and payouts: Stripe processes subscription payments, credit purchases, and affiliate payouts. We receive transaction identifiers from Stripe but never store your full payment instrument.

Creative content: Media you upload or generate can live locally inside your browser (IndexedDB or OPFS) or in Supabase Storage buckets scoped to your account when you choose to sync collections.

Usage records: We log credit deductions, affiliate conversions, and usage queue events through Supabase functions so we can reconcile billing and diagnose issues.

2. How We Use Information

We use collected information to:

  • Authenticate you via Supabase before serving dashboard or API data
  • Manage credit balances and refunds through stored procedures
  • Generate, store, and organize creative assets at your request
  • Provide affiliate dashboards and process payout requests
  • Respond to support questions and troubleshoot incidents
  • Comply with legal obligations, including tax and accounting rules

3. Information Sharing and Disclosure

We share information with third parties only when necessary to deliver the product:

  • Supabase: Provides authentication, database, and storage infrastructure. User data stored in Supabase remains within your project’s secured tables and buckets.
  • Stripe: Handles subscription billing, credit purchases, and affiliate payouts. Stripe receives the minimal details required to process payments and remittances.
  • AI providers: When you request generation, we send prompts and relevant assets to the selected model adapters (for example Fal.ai, OpenRouter models, or ElevenLabs) so they can fulfill the request.

We do not sell or rent personal information.

4. Data Security

Sessions are managed through signed Supabase cookies, API routes verify the authenticated user before accessing data, and media uploads follow user-specific paths. While we work to protect your data, no storage or transmission method is completely secure.

5. Data Retention

We retain account records, credit history, and affiliate ledgers as long as your account remains active or as required for financial compliance. You can delete projects locally at any time, and removing synced assets from Supabase buckets will make them inaccessible to others.

6. Your Rights and Choices

You may have the following rights regarding your personal information:

  • Access and receive a copy of account or billing information we store
  • Update inaccurate profile or preference data via in-app settings
  • Delete your account, which removes associated Supabase records where possible
  • Request credit or affiliate ledger exports for your records
  • Object to certain processing by contacting support

7. Cookies and Local Storage

CutScene relies on Supabase session cookies to keep you signed in and uses IndexedDB/OPFS to store project data locally. We do not run advertising or social tracking pixels.

8. International Data Transfers

Supabase may store data in the region where your project is provisioned. AI providers you choose may process prompts on their own infrastructure, which can reside in other jurisdictions.

9. Changes to Privacy Policy

We will update this Privacy Policy if our data practices change. Material updates will be announced in-app or via email with the revised effective date.

10. Contact Information

If you have questions about this Privacy Policy or our data practices, contact us at support@cutsceneai.com.