◆ FilmForge

<!-- NOT YET REVIEWED BY A LAWYER. Every statement about app behaviour below

was verified against the code on 2026-08-17 (retention: jobs.py

RETENTION_BY_PLAN; collected data: store.py; cookie: main.py), but no

lawyer has seen this document. Have it reviewed before payments go live.

SUPPORT_EMAIL_TBD is a deliberate greppable token - substitute the real

support address everywhere it appears once the mailbox exists. -->

Privacy Policy

Effective date: 2026-08-17

This policy explains what FilmForge, operated as a California sole

proprietorship ("we", "us"), does with your information when you use the

FilmForge service (the "Service").

The short version: we collect the minimum an account needs to work, your

video is deleted on a fixed schedule enforced by the server, nothing you

upload is watched, shared, sold, or used to train anything, and there are no

ads, no analytics and no tracking.


What we collect

Video you upload. Held only to produce your output, then deleted - see

the retention table below. Renders are private to your account. Nothing you

upload or render is visible to any other user, and no content is shared

between accounts.

Preview frames. The look-preview feature processes a single frame in

memory and returns the result. The frame is not written to disk and is not

kept.

Account data.

Service without providing any contact detail, and an internal placeholder

identifier stands in until you choose to claim the account.

password itself.

JSON.

Job records. For each render: the uploaded file's name, the settings you

chose, timing, output size, and whether it succeeded or failed. Job records

are deleted together with the render they describe.

Technical data. IP address, browser type and request timestamps, in

server logs, for security and diagnosing faults.

Payments. There is nothing to buy today. When paid plans are offered,

payment will be handled by the app store or payment processor you buy

through; we will never see or store your full card number.

We do not use analytics or advertising trackers of any kind.

The one cookie

The Service sets exactly one cookie, ff_session, which keeps you signed in.

It holds a random session token and nothing else. It is marked HttpOnly, it

expires after at most 30 days, and it is removed when you log out. There are

no advertising cookies, no analytics cookies and no third-party cookies.

Do Not Track

We do not track visitors over time or across third-party websites or

services, and no third party collects personal information about you through

the Service. Because there is no tracking to switch off, the Service does not

respond to browser "Do Not Track" signals - a visitor with DNT enabled is

treated identically to any other visitor. This disclosure is made under the

California Online Privacy Protection Act.

What we do not do with your video

We do not:

suspected breach of the Content Policy.

learning. Your footage is never training data.**

below acting on our instructions.

How long we keep it

| What | Kept for |

|---|---|

| Uploaded video | Deleted when the render finishes, whether it succeeded or failed |

| Output video | 24 hours on the free plan, 72 hours on Standard and 7 days on Studio, then deleted automatically |

| Job records | Deleted with the output they describe, or sooner if you delete the render yourself |

| Account data (email, password hash, settings, recipes, plan, credit) | Until you delete your account |

| Server logs | Rotated automatically on a fixed budget; not kept indefinitely and never used for profiling |

Deletion is enforced by the server on a schedule, not by anyone remembering

to do it.

One narrow exception. Where the law requires it, we may preserve specific

content and account records beyond these windows - for example, material that

must be reported to the National Center for Missing and Exploited Children

(NCMEC) is preserved for the period federal law sets. Preserved material is

held solely for that legal purpose, is not restored to your account, and is

disclosed only to the authorities entitled to receive it.

Deleting your account

You can delete your account at any time, in the app or on the web. Deletion

is immediate: your uploads and renders are removed from the server, and your

account record - email, password hash, settings, recipes, plan and credit -

is deleted with them. There is no recovery period and no copy we can restore

from.

Who else is involved

your files.

through.

Each acts on our instructions and is not permitted to use your content for

its own purposes.

Where your data is processed

Your data is processed and stored in the United States.

Your rights

Depending on where you live, you may have the right to access, correct,

delete, port, or object to our use of your personal data, and to withdraw

consent.

Because uploads are deleted as soon as their render finishes and outputs

delete themselves within days, the fastest route to deletion is simply to

wait - or to delete the render, or your whole account, yourself; both take

effect immediately. To exercise any right, contact us at SUPPORT_EMAIL_TBD.

We will respond within 30 days.

Children

The Service is not directed at children under 13, and we do not knowingly

collect personal information from anyone under 13. If you believe a child

under 13 has created an account or uploaded to the Service, contact us at

SUPPORT_EMAIL_TBD and we will delete the account and its data.

Security

Files are held on access-controlled servers and transmitted over encrypted

connections. Passwords are stored only as salted hashes, and session tokens

are stored only as hashes, so a copy of the database alone does not expose

either. No system is perfectly secure, and we cannot guarantee absolute

security. If a breach affects your data we will notify you, and the relevant

authorities, where the law requires it.

Changes

Material changes will be posted here with a new effective date.

Contact

SUPPORT_EMAIL_TBD