Privacy Policy
Effective 5 August 2026
This describes what SceneLab actually stores and sends, not a generic template. If the product changes, this page changes with it.
What we collect
- Account: your email address, and — if you sign in with GitHub — the account identifier GitHub returns. Passwords are handled by our authentication provider and are never visible to us.
- Project content: your script, cast and setting descriptions, prompts, and the generated images and clips.
- Token records: your balance and a ledger of every movement — what was spent, refunded, granted, or purchased, and when.
- Render jobs: which generations you started, their status, and any error, so work survives a closed tab.
- Server logs: operational diagnostics. These deliberately exclude prompt text, image URLs, and credentials.
We do not use analytics or advertising trackers. The only cookies are the ones that keep you signed in.
Who we send it to
Running SceneLab means passing some of your data to these processors:
- Supabase — authentication, database, and file storage. Your account, projects, and generated assets live here.
- Anthropic — receives your script and cast/setting text to produce the shot breakdown and refinements.
- fal.ai — receives image and video prompts, and image URLs, to run the FLUX and Kling models.
- Stripe — payments. Stripe collects your card details directly; they never pass through our servers. We store only the checkout session id, the token amount, and the amount paid.
- Vercel — hosting.
We do not sell your data or share it for advertising. These providers process data under their own terms; if that matters to you, review theirs as well.
How it is protected
Projects and token records are isolated per account by database row-level security. Generated assets are stored in a private bucket scoped to your account and served only through short-lived signed links — there is no public URL to guess. Nothing that credits tokens can be triggered from a browser.
How long we keep it
Projects and assets are kept until you delete them or your account. The token ledger and purchase records are kept for as long as we need them for accounting and tax purposes, even after an account closes — they are financial records.
Your choices
You can ask for a copy of your data, correction of it, or deletion of your account and content. Email support@urbnchld.com. Depending on where you live you may have further rights under the GDPR, UK GDPR, or CCPA — including objecting to processing or lodging a complaint with your data protection authority. We do not sell personal information.
Children
SceneLab is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
Contact
Privacy questions or requests: support@urbnchld.com