Document 2 of 3
Privacy Policy
What personal data we collect, how we use it, and the rights you have under GDPR.
01Who we are
[LEGAL ENTITY NAME] AB, Swedish company registration number [ORG.NR], registered office [ADDRESS, STOCKHOLM], is the data controller for personal data processed through Cinematic Workshop. Cinematic Workshop is part of the CinematicShaper franchise.
Contact for privacy matters: privacy@cinematicworkshop.com.
02Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, name, profile image, password hash, OAuth provider id | You |
| Project content | Manuscripts, bible entries, worldmaps, screenplays, prompts, generated images/video/audio/meshes | You |
| Subscription data | Plan, billing dates, payment method last 4 digits, country, VAT id (if provided) | Stripe |
| Usage data | Pages visited, features used, render counts, MCP tool calls, timestamps | You / Service |
| Device data | IP address, browser type, operating system, approximate location (country) | You / Service |
| Communications | Email correspondence, support tickets, feedback | You |
03How we use it
- To run the Service — host your projects, authenticate your account, render the images/video/audio you request, expose MCP tools.
- To bill you — process subscription payments and credit purchases through Stripe.
- To support you — answer support questions and operate the agent.
- To improve the Service — measure feature usage and product health. We do not train AI models on your project content. We do not sell your data.
- To prevent abuse — detect fraud, abuse and violations of these Terms.
- To meet legal obligations — bookkeeping, tax, KYC where required.
04Legal basis (GDPR Article 6)
- Contract (Art. 6(1)(b)) — to provide the Service you have signed up for.
- Legitimate interest (Art. 6(1)(f)) — for product analytics, abuse prevention, and securing the Service. You can object at any time.
- Legal obligation (Art. 6(1)(c)) — for tax, bookkeeping, and law-enforcement requests.
- Consent (Art. 6(1)(a)) — for optional marketing emails. You can withdraw consent at any time.
05Third-party processors
We share personal data with the following processors, only as needed to run the Service:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, storage, authentication | EU (Frankfurt) |
| Vercel | Hosting | EU + US (CDN) |
| Stripe | Payments, subscriptions | Ireland / US |
| Google (Veo, Gemini) | Video & text generation on request | EU / US |
| Black Forest Labs (Flux) | Image generation on request | Germany / US |
| xAI (Grok) | Image & video generation on request | US |
| ElevenLabs | Voice generation on request | US |
| Meshy | 3D mesh generation on request | US |
| Anthropic (Claude) | Agent + MCP | US |
| Plausible Analytics | Privacy-friendly usage analytics | EU (Germany) |
Data Processing Agreements (DPAs) are in place with each processor.
06Data retention
- Account & project data — kept while your account is active. Deleted within 30 days after account closure, except for backups (further 60 days).
- Billing data — kept for 7 years to comply with Swedish bookkeeping law (Bokföringslagen).
- Usage logs — kept for 12 months, then anonymised.
- Support emails — kept for 3 years from last interaction.
07International transfers
Some processors are located outside the EU/EEA (notably the US). Transfers happen under Standard Contractual Clauses (SCCs) approved by the European Commission, plus supplementary measures (encryption in transit and at rest). Where a processor offers EU-only hosting, we use it.
08Your rights (GDPR)
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase data (“right to be forgotten”), subject to legal retention duties;
- restrict or object to certain processing;
- port your data in a machine-readable format;
- withdraw consent at any time;
- lodge a complaint with the Swedish Privacy Protection Authority (IMY).
To exercise any of these rights, email privacy@cinematicworkshop.com. We respond within 30 days.
09Security
We use encryption in transit (TLS 1.3), encryption at rest, row-level security in the database, hashed bearer tokens, and least-privilege access controls. We will notify you and the IMY within 72 hours of becoming aware of a personal data breach affecting you.
10Children
The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us so we can delete it.
11Changes
We may update this policy. The current version, with the “Last updated” date, is always at this URL. We will email subscribers about material changes at least 14 days in advance.
12Contact & complaints
Email privacy@cinematicworkshop.com for any privacy question, data subject request, or to report a concern. If you remain dissatisfied, you can complain to the Swedish IMY at imy.se.