Privacy Policy
At ScenoraEdits, creator privacy is a fundamental architectural requirement. We believe your creative ideas, scripts, and production assets belong to you alone.
In Plain English (Key Takeaways)
- Strict Zero-Training Pledge: We DO NOT train, fine-tune, or feed public or proprietary AI models with your scripts, character bibles, or videos.
- Your BYOK keys (OpenAI, Gemini, Replicate, Fal.ai) are encrypted at rest using AES-256 and never logged or exposed in client bundles.
- Local NVIDIA RTX GPU rendering keeps video frames and intermediate diffusion weights entirely on your local machine.
- We collect minimal operational data necessary for authentication, entitlement verification, and error diagnostics.
- Full creator sovereignty: You can export your Video Bibles and delete your account and projects at any time with zero retention residual.
01Our Zero-AI-Training Pledge
Unlike legacy platforms that quietly harvest user creations to train internal diffusion or generative foundation models, ScenoraEdits is engineered strictly as an orchestration client. When you type a script or create a recurring character in the Video Bible™, that data belongs solely to your project database.
02Information We Collect
We deliberately minimize the personal information collected from creators:
- Account Information: Your email address, display name, and authentication identifiers provided through Firebase Authentication (or Google Sign-In).
- Project Metadata: Project titles, scene prompt timelines, character visual references, and timeline tracks necessary to persist your work across sessions.
- Payment Reference Records: For pass activations, we store transaction identifiers (UPI reference numbers, BuyMeACoffee verification codes, or Stripe checkout session IDs). We do not store credit card numbers directly.
- Operational Telemetry: Error logs, latency metrics, and crash dumps to maintain platform reliability and monitor system health.
03Bring-Your-Own-Key (BYOK) Encryption
When you enter your third-party API keys (e.g., OpenAI, Google Gemini, Replicate, Fal.ai, ElevenLabs, Cloudflare Workers AI) into ScenoraEdits:
- Keys are encrypted using AES-256-GCM encryption before being written to persistent storage.
- Decryption keys are isolated in restricted server-side environments and never transmitted back to browser runtime scripts.
- Requests to third-party model endpoints are executed over encrypted TLS 1.3 tunnels directly from the backend dispatch worker or client proxy.
04Local GPU & Desktop Privacy
When utilizing our local NVIDIA RTX GPU background engine:
- Video frame buffers, ComfyUI workflows, and local diffusion weights remain strictly on your local physical drive.
- The local worker daemon communicates with your browser timeline via a local WebSocket or loopback interface (`localhost`), preventing intermediate video frames from ever uploading to external servers.
05Third-Party Processors & Infrastructure
We partner only with vetted infrastructure providers adhering to enterprise security standards:
- Google Cloud / Firebase: Secure user authentication, database persistence, and CDN file delivery.
- Payment Processors: Stripe, Razorpay/UPI gateway, and BuyMeACoffee for checkout handling.
- Third-Party Model APIs: Only contacted when you explicitly instruct the studio to synthesize prompts using connected BYOK providers.
06Creator Rights (GDPR, CCPA & Global)
Regardless of your physical location, ScenoraEdits grants all creators universal privacy rights:
- Right of Access: You can view all project data, account logs, and metadata in your dashboard.
- Right to Portability: Export your complete Video Bible, timeline sequences, and project manifests as portable JSON packages.
- Right to Erasure: Delete any project, timeline, or your entire account with immediate cascade deletion across databases.
07Data Retention & Permanent Deletion
When you click “Delete Project” or delete your account in Account Settings, our systems execute a permanent purge within seventy-two (72) hours from active production databases and thirty (30) days from cold encrypted disaster backups.
08Contact our Privacy Engineering Team
For questions, data export requests, or privacy inquiries, reach our dedicated Data Protection Officer through our Support & Contact Desk.
Questions about our legal terms or commercial licenses?
Our creator relations and legal engineering team is available to assist with custom enterprise agreements, indemnification inquiries, or license verification.