Cinemagiq Privacy Policy
Effective date: June 16, 2026
Last updated: July 17, 2026
This policy explains how Cinemagiq handles your data. It covers two things:
- Our marketing website (cinemagiq.com), no advertising trackers and no profiling; we use only privacy-friendly, cookieless analytics (see §3.1 and §10).
- The Cinemagiq product (app.cinemagiq.com and related apps), the account-based application, which processes the data needed to run it.
We try to collect as little as possible. We never sell your data and never use it for advertising.
1. Scope
This policy applies to the Cinemagiq marketing website and the Cinemagiq product application. When you create an account and use the product, we process your account details, the content you upload and generate, your payments, and your conversations with our AI assistant, as described below.
2. Who is responsible for your data
Data controller: Cinemagiq, Inc., 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States.
Contact: support@cinemagiq.com
3. What data we collect
3.1 Marketing website
- Contact form: your name, email address, subject, and message, stored so we can respond to you.
- Website analytics: we use Umami (Umami Cloud), a privacy-friendly analytics service, to understand aggregate site usage (pages visited, referrer, country, browser and device type). Umami does not use cookies, does not build visitor profiles, and does not track you across other sites.
- Booking a call: if you use the "Book a call" page, the booking calendar is provided by Google (Google Calendar appointment scheduling) embedded on our page. Google processes the details you enter there (name, email, chosen time) under its own privacy policy and may set its own cookies.
- No advertising identifiers and no cross-site behavioral tracking.
3.2 Account and profile
- Email address and authentication credentials (or a Google account identifier if you sign in with Google).
- Profile information you provide (e.g. display name).
- Workspace and team membership, your role, and invitations you send or accept (which include the invitee's email address).
3.3 Billing and payments
- When you subscribe to a paid plan, payment is processed by Stripe. Stripe collects and processes your payment-method details, billing name/address, and any tax information. We do not store full card numbers.
- We store billing records associated with your workspace, subscription tier, seat count, invoices, payment status, and token-credit balances.
3.4 Content you upload and create
- Files and media you upload (images, video, audio, documents, scripts).
- Content you generate with our AI tools (images, video, voice, music, sound effects) and the prompts and settings used to create it.
- Production data you create, projects, episodes, sequences, shots, storyboards, asset metadata, and activity logs.
- This content is stored on our cloud infrastructure (see §6) in private, access-controlled storage, subject to the storage limits of your plan.
3.5 AI assistant ("Steve") conversations
- Your conversations with the Steve assistant are stored on our servers, private to your own user account within a project, so we can sync your history across devices and improve the product.
- Conversation content (your messages, attachments, and project context) is sent to our AI providers to generate responses (see §5).
- Conversation history is retained for 90 days by default (see §8). You can clear a conversation at any time.
3.6 Technical and diagnostic data
- To keep the product reliable, we use Sentry for error and performance monitoring. Sentry receives technical data during normal use of the product (not only when an error occurs), including your IP address, browser and device information, your user identifier, page and network timing data, and technical details about errors.
- We also use Sentry's session replay for a small sample of sessions (and for sessions where an error occurs) to diagnose problems. Replays are recorded in masked form: all text you type and all on-screen text content are redacted before leaving your browser, so recordings do not contain your content.
- We record product usage data: sign-in and last-active timestamps, feature and generation activity, and API/edge request logs. We use this to operate the service, measure aggregate usage, and produce internal business metrics. We do not use it for advertising.
- We process server and security logs needed to operate the service and prevent abuse. We do not use this data for advertising or behavioral profiling.
3.7 Cookies and local storage
- The product uses strictly necessary cookies and browser local storage to keep you signed in and to remember preferences (e.g. your selected AI model).
- Stripe sets its own cookies during checkout to process payments securely.
- Sentry uses client-side storage to support error reporting.
- See §10 for details.
4. How we use your data and our legal bases (GDPR)
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account | Account, profile, workspace data | Contract (Art. 6(1)(b)) |
| Store and process the content you upload/generate | Content, project data | Contract (Art. 6(1)(b)) |
| Provide AI generation and the Steve assistant | Prompts, content, conversations | Contract (Art. 6(1)(b)) |
| Process payments and subscriptions | Billing data via Stripe | Contract (Art. 6(1)(b)) |
| Send transactional email (confirmations, receipts, alerts) | Email address | Contract (Art. 6(1)(b)) |
| Keep the service secure, reliable, and prevent abuse | Technical/diagnostic data, logs | Legitimate interest (Art. 6(1)(f)) |
| Measure aggregate usage of the website and product | Cookieless analytics, product usage data | Legitimate interest (Art. 6(1)(f)) |
| Respond to your inquiries | Contact-form data | Consent / legitimate interest |
We do not use your data for advertising, profiling, resale, or third-party marketing.
5. AI processing and third-party models
Cinemagiq is an AI production tool, so generating content and using the Steve assistant means sending the relevant inputs to AI providers on your behalf:
- What is sent: the prompts, settings, reference images, project context, and (for Steve) your conversation messages and attachments needed to produce the requested output.
- Who receives it: Google (the Gemini API is our primary provider for the default Steve model, prompt assistance, document parsing, and Gemini-based image and video generation, including Veo; requests may alternatively be routed through the Lovable AI Gateway); OpenAI (image generation and the optional "ChatGPT" Steve model); Fal.ai and Runway (video generation); ElevenLabs (voice, sound effects, music). See §6 for the full list.
- Training: We do not sell your content, and we do not use your content to train our own models. We use the business/API tiers of these providers, which do not use content submitted through their APIs to train their models.
- Outputs: Generated content is stored in your project and is yours to use subject to our Terms and the providers' usage terms.
6. Subprocessors, who we share data with
We never sell your data. We share it with the service providers below only as needed to run Cinemagiq, and each is bound by a data-protection agreement.
| Provider | Purpose | Data processed |
|---|---|---|
| Lovable / Supabase | Cloud hosting, database, authentication, file storage | Account, content, all product data |
| Stripe | Payments and subscriptions | Payment, billing, tax data |
| OpenAI | Image generation; optional Steve model | Prompts, images, conversation content |
| "Sign in with Google" authentication; Gemini API (Steve, prompt tools, document parsing, image and video generation); appointment booking on the website | Account identifier; prompts, images, documents, conversation content; booking details | |
| Lovable AI Gateway | Alternative routing to Gemini models for Steve and prompt tools | Prompts, conversation content |
| Fal.ai | Video generation | Prompts, reference images |
| Runway | Video generation | Prompts, reference images |
| ElevenLabs | Voice, sound-effects, and music generation | Prompts/text |
| Sentry | Error and performance monitoring; masked session replay | IP, device/browser, user ID, error and performance data, masked session recordings |
| Mailgun | Transactional email delivery | Email address, message content |
| Umami (Umami Cloud) | Cookieless website analytics (marketing site) | Aggregate page views, referrer, country, browser/device type |
We may add or change subprocessors as the product evolves; we will keep this list updated and revise the "last updated" date.
7. Team workspaces and sharing within your team
If you use a team workspace, the projects, uploaded files, generated assets, production data, and other content in that workspace are visible to all members of that workspace. Workspace admins can invite members by email and manage access. Your individual Steve assistant conversations remain private to you and are not shared with other workspace members.
Our authorized personnel may access your workspace and its content when needed to provide support you have requested, investigate abuse or security issues, or operate the service, and only for those purposes.
Outside of your own workspace, we do not share your content with other customers.
8. Data retention
- Steve conversations: retained for 90 days, then automatically deleted. You can clear a conversation sooner.
- Deleted items (Trash): when you delete projects or content, they are soft-deleted and recoverable for 30 days, after which they are permanently removed.
- Account and project content: retained for the life of your account, or until you delete the content or your account.
- Contact-form inquiries: deleted after your request is handled.
- Billing records: retained as required by applicable tax, accounting, and legal obligations.
- Usage and API logs: product usage and API/edge request logs are retained for approximately 90 days.
- Error monitoring data: Sentry events and masked session replays are retained according to our Sentry retention settings, then deleted.
- Email delivery logs: records of transactional emails sent (recipient, template, status) are retained for operations and troubleshooting.
- Backups and logs: retained for a limited period for security and recovery.
When you withdraw consent or delete your account, we remove the associated personal data without undue delay, subject to legal retention obligations.
9. How we protect your data
- Content is stored in private, access-controlled storage; database access is governed by row-level security so users can only access data they're authorized to see.
- Data is encrypted in transit. Secrets and credentials are stored in secured secret management, not in our code.
- Access to production systems is limited to authorized personnel.
- No method of storage or transmission is 100% secure, but we take reasonable measures appropriate to the sensitivity of the data.
10. Cookies and tracking
- Marketing website: we do not set our own cookies. We use Umami, a cookieless analytics service that stores no identifiers on your device and does not track you across sites. If you open the embedded Google booking calendar, Google may set its own cookies for that feature.
- Product: strictly necessary cookies and local storage to keep you signed in and remember preferences.
- Third-party cookies in the product: Stripe (during checkout) and Sentry (error reporting) set their own cookies/storage for those functions.
We do not use advertising or cross-site tracking cookies.
11. International data transfers
Cinemagiq, Inc. is based in the United States, and some of our providers (§6) are located in the United States and the European Union. Where your personal data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and our providers' transfer mechanisms.
12. Your rights
Depending on where you live, you have rights over your personal data.
Under the GDPR (EEA/UK) you may: access your data; correct it; delete it; restrict or object to processing; request portability of data you provided; and withdraw consent at any time. You may also lodge a complaint with your local data protection authority.
Under US state laws (e.g. CCPA/CPRA), where applicable, you may: know what personal information we collect; access and delete it; correct it; and opt out of "sale" or "sharing", we do not sell or share your personal information for advertising. We will not discriminate against you for exercising these rights.
To exercise any right, contact support@cinemagiq.com. You can also access, export, and delete much of your content directly in the product.
13. Marketing and transactional email
- Transactional email (sign-up confirmation, receipts, payment alerts, low-balance notices) is part of operating your account and is sent via our email provider (§6). You can't opt out of essential service emails while you have an account, but you can unsubscribe from non-essential notifications, and we honor unsubscribe/suppression requests.
- We do not send advertising or sell your email address to third parties.
14. Children's privacy
Cinemagiq is not intended for children under the age of 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@cinemagiq.com and we will delete it.
15. Changes to this policy
We may update this policy as the product evolves or our providers change. We will revise the "last updated" date above, and for material changes we will provide a more prominent notice by email or in-app.
16. Contact
Cinemagiq, Inc.
131 Continental Drive, Suite 305
Newark, Delaware 19713, United States