Privacy Policy
Version 2026-06-09-draft
1. Who we are
Scenematics ("we") operates this photo experience. Contact: support@scenematics.com. [Controller entity, address, and EU representative/DPO to be completed by counsel.]
2. What we collect
- Photos you upload, which contain biometric face data — see the separate Biometric Notice.
- Your email address (account and delivery).
- Payment metadata from Stripe (we never see card numbers).
- Device, usage, and IP data, plus funnel analytics events.
3. Why and on what basis
- Creating your images — your explicit consent (biometric data) and our contract with you.
- Payments, receipts, and delivery emails — contract.
- Security, fraud prevention, abuse and content moderation — legitimate interest and legal obligation.
4. Retention
- Original uploads: deleted automatically within 24 hours.
- Generated images: kept until you delete them or your account.
- Account data: until deletion request; payment and audit records as required by law.
- Face data is never stored as templates or embeddings and is never sold.
5. Processors
We use Stripe (payments), Supabase (database/storage), Vercel (hosting), fal.ai and/or Google (image generation), Anthropic (content moderation), and Resend (email). Each processes data under contract and none is permitted to train on your photos. [DPA and no-training confirmations tracked in the launch checklist.]
6. Your rights
You can access, export, correct, or delete your data at any time from the Account page or by emailing support. We respond within 30 days. California and other US state residents: we do not sell or share personal information; sensitive data (biometrics) is processed only with your opt-in consent — a "Do Not Sell or Share" request can be made via support. EU/UK: you may also lodge a complaint with your supervisory authority; international transfers rely on Standard Contractual Clauses.
7. Children
The service is directed to adults 18+. A parent or guardian must upload on behalf of any minor and consents to the minor's processing.
8. Cookies, security, and breaches
We use only essential cookies (session) and first-party analytics. Data is encrypted in transit and at rest. We will notify affected users and regulators of qualifying breaches within legally required timelines (72 hours where GDPR applies).