Legal · Privacy

Privacy Policy.

Last updated: August 21, 2026

The short version

We collect what’s needed to run your studio — your Google profile, your projects and media, and billing records — we send your prompts to AI providers to generate your shots, we never sell your data, and deleting your account purges it within 30 days.

See also our Terms of Service, or contact support with questions.

1. What this policy covers

This policy explains how SceneWeaver (“we”, “us”) collects, uses, shares, and deletes personal information when you use the SceneWeaver website and app (the “Service”). It applies to creators with accounts and to visitors watching the public feed. It doesn’t cover third-party sites we link to, or what other platforms do with videos you download from SceneWeaver and upload elsewhere.

2. What we collect

  • Account information. When you sign in with Google, we receive your name, email address, and profile picture from Google. We don’t receive your Google password.
  • Content you create and upload. Scripts, prompts, story settings, characters, scenes, generated images/video/audio, and media files you upload (images, audio, video).
  • Billing information. Your plan, credit balance and ledger (every credit grant and spend), and Stripe customer and subscription identifiers. Card details go directly to Stripe — we never see or store full card numbers.
  • Date of birth — only if you use the mature tier. If you choose to unlock adult content, we store the date of birth you enter. We do not ask for it, or store it, for any other reason. See Age verification & mature content.
  • Usage and technical data. Logs of requests to the Service (IP address, browser type, timestamps, pages and actions), generation and render job records, and view counts on published episodes.
  • Communications. Messages you send through the support form or by email, and your newsletter subscription status if you opt in.

3. How we use your information

  • To provide the Service — run your projects, generate and render your episodes, and sync your work across sessions.
  • To meter and bill — track credit spend, process subscriptions and credit-pack purchases, and prevent abuse of free tiers and trials.
  • To operate the public feed — host and stream the episodes you choose to publish.
  • To communicate — transactional email about your account and billing, support replies, and (only if you opt in) the newsletter.
  • To keep the Service safe — enforce rate limits, investigate abuse, and comply with legal obligations.
  • To improve the Service — debug problems and understand which features are used, based on usage data.

We do not sell your personal information, and we do not use your private projects to train our own AI models.

4. AI processing & model providers

Generation is the heart of the Service, and it runs on third-party AI providers. When you generate a script, image, shot, video, or voice line, the relevant prompts, text, and media are sent to the provider behind the model you’re using. Our current providers include:

  • Google (Gemini / Cloud AI) — text, image, and speech generation.
  • OpenAI — text and image generation.
  • Anthropic — text generation.
  • fal.ai — image and video generation.
  • ElevenLabs — voice synthesis.
  • Amazon Web Services (Remotion Lambda) — final video rendering; your episode’s assets are processed there during a render.

These providers process your content to fulfill your generation request under their own terms and data policies. The exact set of providers and models may change as we improve the Service; this section reflects the providers in use as of the “Last updated” date.

5. Where your data lives

Your account, projects, and structured data are stored in Google Cloud Firestore; your media files (uploads, generated images, audio, rendered video) are stored in Google Cloud Storage. The Service runs on Google Cloud, with video rendering on AWS as described above. Data is encrypted in transit and at rest.

6. Cookies & local storage

  • Session cookies. Signing in sets authentication cookies (via NextAuth) that keep you signed in and protect against cross-site request forgery. These are strictly necessary — the app can’t work without them.
  • Local storage preferences. Your browser’s localStorage holds small preferences — for example which sign-in method you last used, editor and UI preferences — so the app remembers how you like it. These stay on your device.
  • No third-party advertising cookies. We don’t run third-party ad trackers on the Service.

7. Email

We send email through Resend. Transactional messages (account, billing, support replies) are part of operating the Service. Marketing email — like the newsletter — is opt-in only, and every marketing message includes an unsubscribe link. Unsubscribing adds you to a suppression list so we don’t email you again; it doesn’t affect transactional messages you still need (like billing receipts).

8. Payments

Payments are processed by Stripe, which acts as its own controller of the payment data you give it (see Stripe’s privacy policy). On our side we keep your Stripe customer ID, subscription status, purchase history, and the credit ledger that records what your purchases granted and what your generations spent — that ledger is our billing record and is retained for accounting purposes (see Retention).

9. When we share information

We share personal information only with:

  • Service providers acting on our instructions: Google Cloud (hosting, storage, Firestore), the AI providers in Section 4, AWS (rendering), Stripe (payments), and Resend (email).
  • Your collaborators, if you join or create a team — teammates see the projects and assets shared with the team.
  • Legal and safety — when required by law, or to protect the rights, safety, or property of SceneWeaver, our users, or the public.
  • A successor — if SceneWeaver is part of a merger, acquisition, or asset sale, your data may transfer with it; this policy would continue to apply until changed with notice.

We never sell your personal information or share it for third-party advertising.

10. Published content is public

Episodes you publish to the Watch feed are visible to anyone on the internet, along with the show title and metadata you publish them under. Think before you publish; you can unpublish at any time, but we can’t recall copies others may have made while it was public.

11. Retention & account deletion

  • We keep your data for as long as your account is active, so your projects are there when you come back.
  • When you delete your account, it is disabled immediately — you’re signed out and the account can no longer be used — and your personal data, projects, and media are permanently purged within 30 days. Published episodes are taken down as part of the purge.
  • What survives the purge: the credit and payment ledger and related billing records, which we retain as required for accounting, tax, and fraud prevention, plus records we must keep to comply with law (e.g. handled DMCA notices). These are kept only as long as those obligations require.
  • Residual copies in encrypted backups roll off on the backup retention schedule shortly after the purge.

12. Your rights

Depending on where you live (for example under the GDPR or the CCPA/CPRA), you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, and the right not to be discriminated against for exercising those rights. You can exercise most of these directly — your projects and content are editable and exportable in-app, and account deletion is described above. For anything else, contact support@sceneweaver.ai and we’ll respond within the timeline your local law requires. If you’re in the EEA or UK, you also have the right to complain to your data-protection authority.

13. Age verification & mature content

SceneWeaver has an optional mature tier for adult-oriented storytelling. It is off by default, and if you never turn it on, nothing in this section applies to you — we hold no date of birth for you at all.

To unlock it you enter your date of birth and we check that it puts you at 18 or over. This is self-attestation: we accept what you enter and do not ask for a document, an ID, or a third-party identity check. If we ever move to a stronger method, we will say so here before it takes effect.

  • What we store. The date you entered, the fact that the check passed, and when. Nothing else — no document, no image, no scan.
  • What we use it for. One purpose: deciding whether to show you, or let you create, mature content. It is not used for advertising, profiling, age-based personalisation, recommendations, or analytics, and we do not derive anything else from it.
  • Who sees it. Nobody outside SceneWeaver. It is never sent to an AI provider, an advertiser, or any other third party, it is never shown on your public profile, and it is never displayed back to you — even the status endpoint returns only whether the check passed, never the date.
  • How long we keep it. On your account record for as long as the account exists. Deleting your account deletes it along with the rest of that record, within 30 days of the deletion request — see Retention & account deletion.
  • Changing it. The date can be entered once and is not editable from the app — that is deliberate, so the gate cannot be re-attested around. If you entered it wrongly, contact support@sceneweaver.ai and we will clear it.
  • If you state an age under 18. Access is refused and we record that the attempt happened, so that a stated-underage signal is not silently thrown away. That record is kept with our other audit logs.

Passing the check does not show you anything by itself: seeing mature work in your feed is a second, separate opt-in, and you can switch it back off at any time in Account settings.

14. Children

The Service is not for children under 13, and we don’t knowingly collect personal information from them. Users between 13 and the age of majority need a parent or guardian’s consent, as set out in the Terms of Service. If you believe a child under 13 has an account, contact us and we’ll delete it.

The mature tier is a separate, higher bar: 18+, with no guardian-consent route. It is off by default for every account, including accounts we hold no age information for, and no mature content is shown to anyone who has not passed the check described in Age verification & mature content and then opted in.

15. Security

We protect your data with encryption in transit and at rest, access controls that isolate your workspace, and server-side checks on every authenticated request. No system is perfectly secure — if we learn of a breach affecting your personal data, we’ll notify you as required by law.

16. International transfers

Our infrastructure runs primarily in the United States (Google Cloud and AWS US regions). If you use the Service from elsewhere, your data is transferred to and processed in the US and in the regions our providers operate. Where the GDPR or similar laws apply, we rely on our providers’ standard contractual clauses and equivalent safeguards for those transfers.

17. Changes to this policy

We’ll update this policy as the Service evolves — for example if we add or change providers. For material changes we’ll give notice by email or in-app before they take effect. The “Last updated” date at the top reflects the current version.

18. Contact

Privacy questions or requests: email support@sceneweaver.ai or use the support form. For the rules of using the Service, see the Terms of Service.