Privacy Policy
What we collect, how we use it, and your choices.
Last updated June 24, 2026
1. Overview
This policy explains what personal information Scenelit collects, how we use and share it with the processors that power the Service, and the controls you have. By using Scenelit you agree to this policy.
2. Information we collect
- Account information — your email and authentication details, managed via our auth provider (Supabase). Passwords are handled by the auth provider and stored hashed.
- Payment information — handled by Stripe. We receive limited billing metadata (e.g. plan, status, customer ID); we do not store your full card number.
- Content you create — topics and prompts you submit, and the scripts, voiceovers, visuals and videos generated for you.
- Connected-account credentials — when you connect a social account, the OAuth access/refresh tokens needed to publish on your behalf. These tokens are encrypted at rest (AES-256-GCM) and used only to publish to the account you connected.
- Usage & technical data — logs, approximate IP, and device/browser information used to operate, secure, and improve the Service.
3. How we use information
To provide the Service (generate and render videos, publish to your connected accounts), process payments, secure and maintain the platform, communicate with you, comply with legal obligations, and improve the product. We do not sell your personal information.
4. Service providers (sub-processors)
We share the minimum necessary data with providers who process it on our behalf:
- Anthropic — generates the video script from your topic/prompt.
- ElevenLabs — synthesises the voiceover from the script text.
- fal — generates AI images/video for scenes (when you choose an AI visual engine).
- Pexels — supplies stock footage based on scene search terms.
- Stripe — processes subscriptions and payments.
- Supabase — authentication and database (account and application data).
- Cloudflare — hosting, content delivery, and media storage (Cloudflare R2).
5. Social connections & publishing
When you connect a social account, we request permission to publish content to that account and store the resulting OAuth tokens encrypted at rest. We use this access only to publish the videos you create, at your direction. We never display your tokens or share them with third parties. You can disconnect and revoke access at any time from your Connections page, and from your account settings on the relevant platform.
Google / YouTube
When you connect a Google account to publish to YouTube, we request permission to upload and manage videos on your behalf. Scenelit’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide the publishing features you request (uploading the videos you create to your channel); we do not transfer or sell this data; we do not use it for advertising; and we do not allow humans to read it except as you authorise, for security, or as required by law. You can revoke access at any time from your Connections page or your Google Account permissions.
TikTok
When you connect TikTok, we request the content-publishing permission to post videos to your account. We use this access solely to publish the videos you create through Scenelit, at your direction. We do not sell or transfer your TikTok data, and you can disconnect at any time from your Connections page or your TikTok settings. Our use complies with the applicable TikTok developer terms and platform policies.
Instagram / Meta
When you connect Instagram (via a linked Facebook Page and an Instagram Business or Creator account), we request permission to publish content to that account. We use this access solely to publish the videos you create through Scenelit, at your direction. We do not sell or transfer your Instagram/Meta data, and you can disconnect at any time from your Connections page or your Meta settings. Our use complies with the applicable Meta platform terms and developer policies.
6. Data retention & deletion
We keep your information while your account is active and as needed to provide the Service. When you delete your account (or disconnect a social account), we delete the associated content and stored tokens, except where we must retain limited records for legal, security, or billing purposes. You can request deletion by contacting us.
7. Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You can exercise these by using in-product controls or by contacting us. You can disconnect social accounts and revoke publishing access at any time.
8. Security
We use technical and organisational measures to protect your data, including encryption of connected-account tokens at rest. No method of transmission or storage is completely secure, but we work to protect your information.
9. Children
Scenelit is not directed to children, and you must meet the minimum age in your jurisdiction (and on any platform you connect) to use it.
10. International users & changes
Your information may be processed in countries other than your own by the providers listed above. We may update this policy from time to time and will notify you of material changes.
11. Contact
Privacy questions? Email [email protected]. See also our Cookie Policy.