Document 2 of 3

Privacy Policy

What personal data we collect, how we use it, and the rights you have under GDPR.

Version 1.0·Effective 28 May 2026·Governed by Swedish law

01Who we are

[LEGAL ENTITY NAME] AB, Swedish company registration number [ORG.NR], registered office [ADDRESS, STOCKHOLM], is the data controller for personal data processed through Cinematic Workshop. Cinematic Workshop is part of the CinematicShaper franchise.

Contact for privacy matters: privacy@cinematicworkshop.com.

02Data we collect

CategoryExamplesSource
Account dataEmail address, name, profile image, password hash, OAuth provider idYou
Project contentManuscripts, bible entries, worldmaps, screenplays, prompts, generated images/video/audio/meshesYou
Subscription dataPlan, billing dates, payment method last 4 digits, country, VAT id (if provided)Stripe
Usage dataPages visited, features used, render counts, MCP tool calls, timestampsYou / Service
Device dataIP address, browser type, operating system, approximate location (country)You / Service
CommunicationsEmail correspondence, support tickets, feedbackYou

03How we use it

  • To run the Service — host your projects, authenticate your account, render the images/video/audio you request, expose MCP tools.
  • To bill you — process subscription payments and credit purchases through Stripe.
  • To support you — answer support questions and operate the agent.
  • To improve the Service — measure feature usage and product health. We do not train AI models on your project content. We do not sell your data.
  • To prevent abuse — detect fraud, abuse and violations of these Terms.
  • To meet legal obligations — bookkeeping, tax, KYC where required.

04Legal basis (GDPR Article 6)

  • Contract (Art. 6(1)(b)) — to provide the Service you have signed up for.
  • Legitimate interest (Art. 6(1)(f)) — for product analytics, abuse prevention, and securing the Service. You can object at any time.
  • Legal obligation (Art. 6(1)(c)) — for tax, bookkeeping, and law-enforcement requests.
  • Consent (Art. 6(1)(a)) — for optional marketing emails. You can withdraw consent at any time.

05Third-party processors

We share personal data with the following processors, only as needed to run the Service:

ProcessorPurposeLocation
SupabaseDatabase, storage, authenticationEU (Frankfurt)
VercelHostingEU + US (CDN)
StripePayments, subscriptionsIreland / US
Google (Veo, Gemini)Video & text generation on requestEU / US
Black Forest Labs (Flux)Image generation on requestGermany / US
xAI (Grok)Image & video generation on requestUS
ElevenLabsVoice generation on requestUS
Meshy3D mesh generation on requestUS
Anthropic (Claude)Agent + MCPUS
Plausible AnalyticsPrivacy-friendly usage analyticsEU (Germany)

Data Processing Agreements (DPAs) are in place with each processor.

06Data retention

  • Account & project data — kept while your account is active. Deleted within 30 days after account closure, except for backups (further 60 days).
  • Billing data — kept for 7 years to comply with Swedish bookkeeping law (Bokföringslagen).
  • Usage logs — kept for 12 months, then anonymised.
  • Support emails — kept for 3 years from last interaction.

07International transfers

Some processors are located outside the EU/EEA (notably the US). Transfers happen under Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption in transit and at rest). Where a processor offers EU-only hosting, we use it.

08Your rights (GDPR)

You have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate data;
  • erase data (“right to be forgotten”), subject to legal retention duties;
  • restrict or object to certain processing;
  • port your data in a machine-readable format;
  • withdraw consent at any time;
  • lodge a complaint with the Swedish Privacy Protection Authority (IMY).

To exercise any of these rights, email privacy@cinematicworkshop.com. We respond within 30 days.

09Security

We use encryption in transit (TLS 1.3), encryption at rest, row-level security in the database, hashed bearer tokens, and least-privilege access controls. We will notify you and the IMY within 72 hours of becoming aware of a personal data breach affecting you.

10Children

The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us so we can delete it.

11Changes

We may update this policy. The current version, with the “Last updated” date, is always at this URL. We will email subscribers about material changes at least 14 days in advance.

12Contact & complaints

Email privacy@cinematicworkshop.com for any privacy question, data subject request, or to report a concern. If you remain dissatisfied, you can complain to the Swedish IMY at imy.se.

Version 1.0 · Effective 28 May 2026Next: Cookie Policy