These policies are in draft for the launch of cineva.io. The effective date is pending.
Privacy policy
This policy explains what Cineva collects when you use cineva.io, why we need it, and who else sees it. Your scripts are the most sensitive thing you give us, so start with the section on training data.
Who is responsible
Cineva is run by ReadyTake, the company behind RolePilot. The controller of your personal data is [Registered entity name] of [Registered office address]. Privacy questions go to hello@cineva.io.
[Data protection officer and EU or UK representative, only if counsel says one is required]
What we collect
Account details
Your email address, your password credential, your plan, and your credit balance and credit history.
Billing details
Stripe collects and processes your card details. We never see or store your card number. We keep the record of what you bought, what you paid, and when.
What you submit
The scripts, scene text, notes, prompts and reference images you put into a tool, and the project names you give them.
What the models generate
The images and text produced by your runs, stored so you can come back to them.
Usage and log data
Which tools you ran, when, whether a run succeeded or failed, and standard server logs including IP address, browser type and time of request. Logs exist so we can keep the service up and investigate abuse.
Why we use it
- To run the tools you ask for and store the results.
- To keep you signed in and keep your projects separate.
- To count credits correctly, take payment, and refund failed runs.
- To send service email: receipts, failed payment notices, changes to these policies.
- To find bugs, fix them, and stop abuse of the service.
- To meet tax, accounting and other legal obligations.
We do not sell your data. We do not run advertising on Cineva, so nothing here feeds an ad profile.
Legal bases
If data protection law where you live requires a legal basis, these are ours.
| What we do | Basis |
|---|---|
| Run the tools, store your projects, keep you signed in | Performance of the contract with you |
| Take payment, count credits, issue refunds | Performance of the contract with you |
| Service email about your account | Performance of the contract with you |
| Server logs, fraud and abuse prevention, debugging | Our legitimate interest in a working, safe service |
| Keeping invoices and tax records | Legal obligation |
| Marketing email, if we ever send any | Your consent, which you can withdraw at any time |
Your scripts are not training data
We do not train models on the scripts, prompts or images you submit, and we do not let third party model providers train on them. Your material is sent to a model provider for one reason: to produce the output you asked for in that run. After the run it is stored in your account and nowhere else.
We also do not sell your material, publish it, or show it to other users. If we ever want to feature something you made, we will ask you first.
[Confirm the no training terms in writing with every model provider before launch, and name them below]
How long we keep it
- Account details, projects and generated output: while your account is open.
- After you delete your account: projects and outputs are removed within 30 days. That window exists so a deletion made by mistake can be undone.
- Server logs: [Log retention period, to be confirmed].
- Payment and tax records: kept as long as the law requires, even after the account is gone. [Financial record retention period, to be set by counsel].
Your rights
Depending on where you live, you can ask us to do the following. We do not charge for it, and we answer within [Response deadline, to be set by counsel].
- Access. Get a copy of the personal data we hold about you.
- Correction. Fix anything that is wrong.
- Deletion. Delete your account and its contents. You can do this yourself from your account.
- Export. Take your submitted material and generated output with you in a portable format.
- Objection and restriction. Object to processing we base on legitimate interest, or ask us to pause it while a dispute is sorted out.
- Withdraw consent. Where we relied on consent, take it back at any time.
Email hello@cineva.io to use any of these. If you are not happy with the answer, you can complain to your data protection regulator: [Supervisory authority, to be named by counsel].
International transfers
The services above run in several countries, so your data may be processed outside the country you live in, including in the United States. Where the law requires a transfer safeguard, ours is [Transfer mechanism, for example standard contractual clauses, to be set by counsel]. Ask us and we will tell you where a given piece of data sits.
Security
The site is served over HTTPS. Sign in credentials and stored data are handled by Supabase. Card details go straight to Stripe and never reach our servers. Access to production data is limited to the people who need it to run the service.
We hold no security certification and we claim none. No service is perfectly secure. If we ever have a breach that puts you at risk, we will tell you and the relevant regulator as the law requires.
Children
Cineva is not for children. We do not knowingly collect data from anyone under the minimum age set in the terms of service. If you believe a child has an account, email hello@cineva.io and we will delete it.
Changes to this policy
When this policy changes in a way that affects you, we email the address on your account before the change takes effect. The current version always lives at this address.
How to reach us about privacy
Email hello@cineva.io. Postal address: [Registered office address].