Privacy Policy
Last updated: 2026-05-22 · Version v0.3.0
StarReel (hereinafter "we") respects and is committed to protecting user privacy. This policy explains what information we collect, why we collect it, how we use it, who we share it with, and the rights you have.
1. Information We Collect
- Account information: email, display name, password hash (we do not store plaintext passwords), language preferences.
- Device information: operating system, app version, device model, device fingerprint generated from hardware (used for one-account-one-device policy).
- Usage data: feature call counts, number of generated shots, video durations, error logs (used for product improvement and quota calculations).
- Payment information: processed by Stripe. We do not access your card number; we only retain top up and order status and invoice numbers.
- Content data: when using the cloud online, your scripts, characters, storyboards, and assets are stored in your account space; when using the macOS client offline they are stored locally, with optional cloud sync.
2. How We Use Information
- To provide and maintain the service (accounts, top up, credits-based billing)
- To detect and prevent abuse (suspicious login alerts, quota bypass detection)
- Product improvement and feature optimization (based on aggregated anonymous metrics)
- Customer support and troubleshooting
- Legal and regulatory compliance as required
3. How We Share Information
Except as noted below, we do not sell or share your personal information:
- AI providers: when using platform Keys, your prompts are sent to the selected AI vendors (OpenAI / Volcano / MiniMax, etc.). Each vendor has its own privacy policy.
- Infrastructure providers: cloud databases, email services, Stripe (payments). These providers have minimal access to the data they receive.
- Legal requirements: when required by law (e.g., valid court subpoena).
4. Data Storage and Security
- Servers are located overseas (Tokyo / Singapore / Frankfurt) and access is accelerated via Cloudflare.
- Passwords are hashed using bcrypt (cost 12).
- Refresh token hashes are stored in the database; clients store encrypted tokens using the macOS Keychain.
- JWTs are signed with RS256 (asymmetric).
- All API communication is conducted over HTTPS.
5. Data Retention
- After account deletion: permanently deleted after 30 days (recoverable during this period).
- Usage data: retained for up to 18 months for product analytics.
- Payment records: retained as required by law (typically 5–7 years).
6. Your Rights
- Access, correct, and delete your account information
- Export your project data
- Delete your account (Settings → Account)
- Object to or restrict data processing
To exercise any right, contact [email protected].
7. Minors
This service is not directed at users under 14 years old. If we discover a minor has registered, we will immediately disable the account.
8. AI-Generated Content
Videos, audio, images, and other content you generate through the platform are owned by you. You are responsible for ensuring the content is lawful and does not infringe third-party rights.
9. Policy Changes
For material changes we will notify you by email + in-app banner 30 days in advance. Continued use of the service constitutes acceptance of the new policy.
10. Contact
Privacy questions: [email protected]
General support: [email protected]
This policy was drafted by the development team and will take effect after legal review. This is currently a v1 draft.