Privacy policy

Effective date: October 4, 2026

1. What we collect

Google Sign-In

Cinematix uses Google Sign-In through Supabase. The requested OAuth scopes are email and profile only. Supabase receives your Google account identifier, email address and basic profile information, such as your name and profile picture. It also stores email-verification information and, for some Google Workspace accounts, the associated domain. Cinematix’s account-access checks use your account identifier and email.

Account and membership information

We store your account profile, access permissions, membership status, Stripe customer and subscription identifiers, and AI credit and request records. If we invite you before you sign up, we may enter your email address into an invitation record. That address is cleared when the invitation is claimed.

For Pro members, we also store Pro Vault progress: the rewards you have earned and the paid periods that count toward them (Stripe invoice and subscription identifiers, their dates, and any refund or dispute).

Payments

Stripe is our payment processor. You enter payment information directly on Stripe’s Checkout or customer-portal pages. Cinematix stores billing identifiers and subscription information, not your card number.

Projects and media

Ordinary editing, decoding, rendering and exporting happen in your browser. Your beats, clips and cover images are not uploaded for those activities. Saved local projects, including their media, use your browser’s IndexedDB storage. Images you explicitly submit to an AI feature are an exception, described below.

AI features

When you use AI image features, we send the prompt and any selected reference image needed for that request to Google Gemini. When you use AI words or prompt enhancement, we send the relevant text and instructions to Anthropic. These requests pass through Cinematix’s server. We temporarily store AI responses to support retries and prevent duplicate charges, alongside request identifiers, request fingerprints, status, timestamps and credit accounting.

Account-linked usage telemetry

In our application database, we record four kinds of product events: project creation, export start, export completion and rejected media. Events are associated with your account and include a per-page session identifier, timestamp, browser family and operating-system family.

Depending on the event, the record includes preset and workflow choices; export dimensions, frame rate, duration, media type, plan, watermark status, outcome and processing time; or a rejected file’s type, extension, size and technical rejection or codec classification.

Usage telemetry never includes file names, email addresses, raw IP addresses, raw user-agent strings, media contents or free text you type.

While you are signed out, up to 20 events may be queued in the tab’s sessionStorage. They are sent and associated with your account if you subsequently sign in. If you never sign in, that queue is not sent to our usage database. This account-linked system is separate from Vercel Web Analytics, which also counts signed-out visitors as described below.

Visitor and product analytics

We use Vercel Web Analytics on app.cinematixaudio.com to understand visits, campaign performance and how people use the app, including while signed out. It does not use cookies. Vercel distinguishes visits using a hash derived from the incoming request and discards that visitor identifier after 24 hours.

Vercel receives page-view and product-event data to provide aggregated statistics. The app’s page address is limited to its domain and page path, plus approved campaign or referral tags; other query parameters and fragment identifiers are removed before it is sent. Vercel may also process the referring page, event time, approximate location (such as country, region or city), device type, browser and operating system, including version information and the analytics script version.

Product events record actions such as adding a beat, finishing an export or starting checkout. The details we add to these events are limited to fixed product labels, such as a plan, resolution, preset identifier or outcome. These event details never include names, email addresses, file names or text you type.

Support

If you email us or submit an in-app support report, we receive your message and any contact information you choose to provide. In-app support reports also include a report and session identifier, browser and operating-system categories, app version, whether you are signed in, the area of the app affected and, when relevant, the type of export problem. Media and project contents are not automatically attached. Information you choose to type into a support message is separate from the automatic crash reports described below.

Automatic crash and error reports

When the app shows an error screen, it automatically attempts to send us a technical error report. It also reports certain background errors associated with our app’s code, even if the page continues running. Reports include the error category and type, a scrubbed error message, code locations within our own app bundle, browser and operating-system categories, the app version and the area of the app affected. Technical identifiers, such as a report identifier, a per-page session identifier when available, an error reference and a derived error identifier, help control duplicate reports and investigate problems.

Before an automatic report is sent, the app replaces recognized web addresses, email addresses and file names in the error message with placeholders. File-name filtering covers every file type the app accepts, plus common project and document types. It also replaces quoted text, except for short code-style names such as “bpm,” and sequences of six or more digits. Scrubbing happens in your browser, and our server checks the report before using it. Media files and project files are never attached to automatic reports. Locations in our own app code are distinct from the names of your files. Reporting is limited to reduce repeated reports and abuse, and a report may not reach us if the browser cannot send it or a limit is reached.

2. Why we use this information

We use this information to sign you in, provide access to Cinematix, manage memberships and payments, send billing emails, deliver AI features, account for credits, prevent duplicate requests and abuse, deliver support and crash alerts to our team, diagnose and fix technical problems, measure visits and campaign performance, understand how people use the app, improve project and export workflows, and respond to support and privacy requests.

3. Where information goes

Supabase provides authentication and stores account, invitation, billing, credit, AI request, usage and in-app support-report records.

Stripe processes payments and manages subscriptions, invoices, refunds and the customer portal.

Resend is our email provider for billing emails and for support and automatic error-report alerts sent to our support inbox. It processes the email addresses, message content, technical identifiers and delivery information needed to provide those emails. Billing emails may include your plan, payment amount, renewal or access dates and cancellation information. Support alerts include the message and optional contact email you submit, along with technical context about the report. Automatic error alerts contain the error type, scrubbed message, app code locations, browser and operating-system categories, app version, app area and error references described above.

Google provides Google Sign-In and processes prompts and selected images for Gemini image features. Our Gemini image requests disable storage for later request-and-response retrieval. This setting does not promise that Google keeps no records.

Anthropic processes text submitted for AI words and prompt enhancement. Google and Anthropic process submitted content under their applicable service terms and privacy practices.

Upstash Redis stores short-lived rate-limit counters and request-control markers using HMAC-hashed identifiers. These controls also limit and deduplicate automatic error reports.

Vercel hosts the application, handles the network requests needed to serve it and processes the visitor and product analytics described in Section 1. Cinematix’s server-side application error logs use technical classification strings rather than prompts, images, file names or full provider error bodies. Hosting providers may separately process network and operational information to run their services.

4. Cookies and browser storage

We use Supabase authentication cookies to maintain your sign-in session. Where beta access is enabled, a beta-access cookie supports that access. Vercel may use cookies for hosting and security. Vercel Web Analytics does not use cookies. If your browser blocks or fills its site storage, a first-party cookie may briefly hold an opaque account identifier (never your name or email) so your other open Cinematix tabs know when you sign in, sign out or switch accounts, and clear the previous account’s information. It expires within a day.

Your browser also stores local project information and media, interface preferences, and temporary sign-in, checkout and usage-queue state. You can manage cookies and site storage through your browser. Clearing site storage may sign you out and remove locally saved projects.

5. Retention

Account profiles, membership records and AI credit and request-accounting records remain while needed to operate your account. Unclaimed invitation addresses remain until the invitation is claimed or manually removed, including when we resolve a verified deletion request.

We aim to clear saved AI response content within a day of request creation. This is a scheduled expiry target, not a guaranteed deadline: the cutoff is one day from request creation, and cleanup runs every five minutes. A healthy run may therefore clear a response around 24 hours and five minutes after creation, plus processing time; failures or downtime can extend this. Clearing the response does not erase its credit-accounting record, immediately erase underlying database bytes or backups, or delete copies held by providers or on your device.

Account-linked usage events in our application database currently have no automatic age-based expiry. They are removed when we delete your account. Vercel’s visitor identifier is discarded after 24 hours; this does not mean its aggregated analytics statistics are deleted after 24 hours. Those statistics are retained separately under Vercel’s analytics retention practices.

Rate-limit counters and request-control markers expire automatically after their short operating windows.

Local projects remain on your device until you remove them or your browser clears its storage. Account deletion does not erase those local files.

We retain necessary support records, including technical error reports, and payment/accounting records for the purposes of resolving requests, diagnosing and fixing technical problems, handling payment disputes and meeting applicable legal obligations. Stripe may retain payment records under its own obligations and retention practices.

In-app support reports are saved in our application database and may also be emailed to our support inbox. Automatic crash and error reports are not saved in our application database. Alert copies are retained in our support inbox and Resend’s email logs; short-lived rate-limit and duplicate-report markers are stored separately. Resend retains email records under its own retention practices.

Backup copies can remain after information is removed from the live application. Backup retention schedule: Hosted database backups are kept for 7 days. Operator backup copies made during maintenance are deleted within 7 days.

6. Your rights and account deletion

You may contact us to request access to, correction of, or an export of the personal information we hold about you. We verify ownership before providing account information or making changes.

To request deletion of your Cinematix account, email clayhbeats@gmail.com from the Google email address you used to sign up and reply to our verification email; we will complete deletion within 30 days of your verified request unless you expressly choose to retain access until your paid term ends and delete the following day, subject to records we must retain by law and backup copies that expire under the retention schedule above.

Deletion removes your account and associated application profile, access, billing, credit, AI request and usage records, including unclaimed invitations for your signup address. It does not erase your Google account, browser-local projects, independently retained provider records or required payment/accounting records.

7. Cancellation, deletion and refunds

Memberships automatically renew at the price and interval shown before checkout until cancelled. You can cancel renewal from Membership in the app.

By default, cancellation preserves access through the paid term. If you also request account deletion, deletion occurs the following day without an unused-term refund. If that deletion date is more than 30 days after your verified request, we require your explicit agreement to the later date.

You may instead request immediate deletion. Access ends when deletion begins, and unused credits and account history are removed. After the first-payment refund window, monthly plans forfeit the unused remainder without refund; annual plans receive a refund for unused whole months of the paid annual term, measured from your original request date.

An immediate-deletion request within 14 days of your first successful membership payment receives a full refund of that payment. This overrides the monthly and annual rules. Renewals do not restart the 14-day window. Refunds are issued through Stripe to the original payment method; bank processing may take additional time. These rules apply except where law requires otherwise.

8. Children

Cinematix is not intended for children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and address it.

9. Changes

We may update this policy as Cinematix changes. We will publish the revised policy on this page and provide any additional notice required by applicable law.

10. Contact

For privacy questions, support, access, correction, export or deletion requests, email:

clayhbeats@gmail.com