Effective 27 September 2026
Privacy Policy
The short version
- We collect what it takes to run your account and make your videos — nothing for advertising, and we never sell personal information.
- Your content is used only to provide the service to you. We don’t train AI models on it.
- Payments are handled by our Merchant of Record; we never see or store your card details.
- You can see, export, correct or delete your data at any time. Ask us and we’ll do it.
- Only essential cookies: the ones that keep you signed in.
1. Who is responsible
Vivek Sharma, trading as SceneBranch, is the controller of the personal information described here. Contact details are at the end of this page. When you put personal information about others into SceneBranch (for example, a teammate you invite, or people who appear in your product), you decide what goes in, and we process it on your behalf.
2. What we collect
- Account information — your name, email, password (stored only as a salted hash), workspace name and role, and sign-in sessions.
- Your content — products you connect (website and repository addresses and what we capture from them), prompts, brand assets, generated scripts, voices, videos and their versions.
- Usage and billing records — generations, what each one used (credits, models, render time) and your credit balance. Paid plans are billed by Paddle, which receives your payment details directly; we receive the plan, amount, country and a customer reference.
- Developer data — API keys (we store only a one-way hash), webhook endpoints (their signing secrets are encrypted) and delivery logs.
- Device and log data — IP address, browser, request logs and error reports, used for security and to keep the service running. If you turn on device notifications, a push subscription for that browser.
- Communications — messages, emails and calls with us.
3. How we use it, and why
- To provide the service you asked for: making, storing and delivering your videos, running your API and webhooks (performing our contract with you).
- To keep accounts and the service secure, prevent abuse and fix problems (our legitimate interest in a safe, working service).
- To send the emails and notifications the service needs, and the ones you choose in Settings → Notifications — you can change those at any time.
- To meet legal, tax and accounting obligations.
We don’t use your content to train AI models, we don’t sell personal information, and we don’t use it for advertising. We use AI providers through their business APIs, under terms that don’t allow them to train on the data we send.
4. Who processes data for us
These companies process data on our behalf, only to provide the service and under contractual protections:
- Amazon Web Services — Application hosting, media storage and transactional email (United States)
- Neon — Database hosting (United States)
- Vercel — Website hosting and delivery (Global edge network)
- Paddle — Payments, tax and invoicing (Merchant of Record) (United Kingdom / global)
- Anthropic, OpenAI and Google — AI models that plan and write your videos, when a generation uses them (United States)
- ElevenLabs — Premium AI voices, when you choose them (United States / European Union)
- Twilio — Phone calls and text messages (United States)
- Grafana Labs — Service health monitoring (no customer content) (United States)
We’ll update this list before adding a new sub-processor that handles your content.
5. Where your data lives
Your data is stored and processed in the United States, where our servers are. Where data moves between countries, we rely on our providers’ standard contractual protections for international transfers.
6. How long we keep it
- Account information and your content, for as long as your account or workspace exists.
- When you delete content or a workspace, we delete it from the live service within 30 days and from backups within a further 35 days.
- Notifications are kept for 90 days; delivery and request logs for up to 90 days.
- Billing records, as long as tax and accounting law requires.
7. How we protect it
Everything travels over TLS. Data is encrypted at rest by our hosting providers; secrets such as webhook signing keys are additionally encrypted with AES-256-GCM, and API keys are stored only as hashes. Every workspace’s data is isolated at the database level, and access by our own systems is least-privilege and logged.
8. Your choices and rights
You can access, export, correct or delete your personal information, object to or restrict some processing, and withdraw consent where we rely on it — wherever you live. Email support@scenebranch.com and we’ll respond within 30 days. You can also complain to your local data protection authority.
California residents: we don’t sell or share personal information for cross-context behavioral advertising, and we don’t use sensitive personal information beyond what the service needs. You won’t be treated differently for exercising your rights.
10. Children
SceneBranch is a business tool and isn’t meant for anyone under 18. We don’t knowingly collect information from children.
11. Changes to this policy
If we make material changes, we’ll tell workspace owners by email or in the app before they take effect. This policy works together with our Terms of Service.
Who we are and how to reach us
SceneBranch is operated by Vivek Sharma, a sole proprietor based in India.
Postal address: 136 Shivlok Colony, Phase 1, Rani Pur Mode, Haridwar, Uttarakhand 249407, India
Email support@scenebranch.com or call +1 (786) 837-0641.