Legal

Privacy Policy

Version 1.0
Effective date: September 8, 2026
Last updated: October 5, 2026

This policy is written to be read. If you only want one paragraph: we do not sell or rent your personal information to anyone, and we do not run advertising. We do not track you across other companies' sites or apps. Our products are paid for with money rather than with data, and much of what our software does happens on your own device or inside your own workspace. One thing we do measure, because our customers ask for it: when a studio sends a proposal or an invoice through Cutvey, that studio can see whether its client opened it. Section 10 explains that, and the result belongs to the studio, not to us.

On this page: who we are (1), what this covers (2), our role (3), what each product touches (4), what we collect (5), why, and our legal bases (6), AI (7), analytics, crash and diagnostic reports (8), cookies (9), email and messaging (10), sharing (11), international transfers (12), retention (13), security (14), children (15), your rights (16), regional information (17), privacy signals (18 and 19), changes (20), contact (21).

1. Who we are

Cutvey LLC is a Florida limited liability company. Our registered and notice address is Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA. Our principal place of business is Orlando, Florida, USA. In this policy, "Cutvey", "we", "us" and "our" mean Cutvey LLC.

For privacy questions, requests and complaints: [email protected], or write to us at the address above. One address reaches a person for everything: support, privacy, legal and copyright. If you are in the European Economic Area, the United Kingdom or Switzerland, section 17.1 tells you who to contact.

2. What this policy covers

This policy covers every Cutvey product and website. We keep it as one document on purpose, so that adding a product does not mean publishing a new policy. What a product does with data is in the table in section 4, not in the words around it.

Family What it is
The ServiceThe Cutvey subscription platform: the web app, a workspace's own domain pointed at it, the client and crew portals reached by a link, our APIs and integrations, and any free application we publish for the same account and the same workspace data
The AppsSoftware you install on a device you own, that does its work on that device. An App may be free, bought once, or licensed by the year, and it may come from a platform store or from us. Some Apps can sign in to a Cutvey account, and what they sync when you do is Service data
The SitesEvery website we publish, and the email we send from them: cutvey.com, cutveyoffload.com, cutveymeter.com, cutveyviewfinder.com, cutveyteleprompter.com and cutveysetrush.com, and any site we add, all listed at https://cutvey.com/legal

Four rules hold this together, so that new products fit without a new policy:

Where a rule applies to one family only, we say which. Otherwise read it as applying to all three. Where we say "Products" we mean all of them.

If we ever launch or acquire something that does not fit these three families, we will add it here or publish a separate notice for it and link it from this page.

This policy does not cover:

3. Our role: controller and processor

Privacy law separates the party that decides why data is processed (the "controller", or "business" in some US laws) from the party that processes data on someone else's instructions (the "processor", or "service provider").

We are the controller for:

We are a processor for the content a business customer puts into its Cutvey workspace about other people: its clients, leads, crew, talent, vendors and contacts. The customer is the controller of that data. It decides what to collect, why, how long to keep it, and whether it has the right to collect it. We act on that customer's instructions and on what the product's features do.

If you are a one-person company, both apply to you. We are the controller for you: your account, your billing, your sign-ins. We are the processor for everyone else in your workspace: your clients, your crew, your talent. You decide what happens to their details, and we act on your instructions.

Where we act for ourselves on the same systems. Even while we act as a processor for a customer's workspace, we are the controller of a narrow set of data we generate by running the service. That set is: security and request logs, abuse and fraud signals, usage statistics that are not linked to an individual, and billing records. This includes measuring how our own pages perform on the portal, review and gallery pages a studio's clients and crew see. We use that only to operate, secure, support and bill for the Products. We do not use it to build a profile of anyone. It never touches the content of the documents, comments, files or messages in a workspace, which we handle only on the customer's instructions. Everything in section 8 applies to that measurement.

If you are a client, crew member or talent of a studio that uses Cutvey, the studio is your first point of contact. If you send us a request about the studio's records, we will tell you who the studio is and how to reach them. With your agreement we will pass your request to them and help them answer it. We will not act on it ourselves, because the studio decides what happens to its records.

Our processor commitments to business customers, including the required processing terms and the transfer clauses in section 12, are in our Data Processing Addendum (DPA) at https://cutvey.com/legal/dpa. The DPA controls over this policy for the data we process on a customer's behalf.

4. What each product touches

This is the table to read if you want to know what a specific product does with data. New products get a new row here, not a new policy. "Sent to Cutvey" means data that reaches our servers.

What is true of every App, whatever its row says. These are limits, not features, so they hold for every App we have made and every App we will make:

  1. No App sends us your content, meaning anything you make, import or capture: footage, stills, recordings, scripts, readings, measurements, documents and files. The only exception is where an App's row says it does, and the row says exactly what.
  2. No App carries advertising, an advertising or attribution component, a third-party analytics or crash reporting component, or anything that follows you across other companies' apps and websites. That is why no App asks for permission to track you.
  3. No App sends us a biometric identifier and no App stores a biometric template. Section 5 sets this out in full.
  4. No App records your screen, your keystrokes or where you move your pointer.
  5. No App creates a Cutvey account. Where an App can sign in, it signs in to an account that already exists, made on the web.
  6. Where an App moves your files between your own devices or drives, that traffic does not pass through us unless its row says it does, and the row then says what we can see and for how long we hold it.

Everything else is off until a row turns it on. An App does not store your content in a cloud account, does not send us usage data or crash reports, does not sync with a Cutvey workspace and does not use a device permission, unless its row says it does. If a row does not mention something, the App does not do it.

What a row may change, and what it may not.

Push notifications. Where a Product can send push notifications and you allow them, they go through the platform owner's service. To do that we hold a device token that identifies the device, not you, and we delete it when you turn notifications off, sign out or remove the device. A notification can carry the subject of the thing it is about, for example a client name, a document title or an invoice amount, which may be visible on a locked screen. Turn them off, or hide previews, in your device settings, or turn off individual notification types in Cutvey Settings.

Device permissions. We ask for a device permission at or shortly before the point where the feature that needs it is set up or first used, and never for a feature you have not opened. You can refuse or revoke any permission in your operating system settings. The feature that needs it stops working, and the rest of the App carries on.

How to read the table. Each row's "Sent to Cutvey" cell starts with one of three answers, so you never have to interpret it: Nothing, Sign-in and entitlement checks only, or Sign-in, and what you sync. Anything else in that cell adds detail to one of those three.

Product On your device In your own cloud account Sent to Cutvey Device permissions Usage and crash reports
Cutvey Service (web)Session cookie, local cache of what you are working onNone: your workspace lives on our serversSign-in, and what you sync: everything you enter or upload into your workspace, plus account, billing, security and usage data (sections 5 and 8). This includes the coordinates of a shoot when a call sheet shows weather, which go to our weather provider with nothing that identifies youBrowser only (file picker, and notifications if you allow them)Yes, on the terms in section 8
Cutvey app (the Service on your phone, tablet or computer)Sign-in token, trusted-device record, local cacheNoneSign-in, and what you sync: this app is a window onto the same account and the same workspace, so the same as the row aboveNotifications (optional), camera and photo library only if you attach or capture media, location while you use it, only to show travel time to a call sheet location or to note where you are when you scoutOptional, one switch
Cutvey OffloadEverything by default: your footage, job history, checksums, logs and settings. Safe Erase can permanently erase a camera card once a copy is verified, and that cannot be undoneNoneSign-in, and what you sync: sign-in and entitlement checks, update checks, and, while the Cutvey dashboard is switched on, which it is unless you turn it off, the job status that dashboard shows: this Mac's name, the names of the cards, volumes and destinations in a job, the destination path, the camera model, counts, progress and any error text. Our servers remove every path from that status before anything is stored, so no path from it is ever kept. Turn the dashboard off in Settings and none of it is sent. Your footage is never sent to usFull disk and removable-volume access, so it can read a camera card and write to your drives. macOS calls this Full Disk Access, and it is the same permission every backup tool asks for. Administrator approval for the erase feature. Local network only if you use a network destinationOptional, one switch
Cutvey Offload for iOSSign-in record, settings, and the job status it reads from your Cutvey workspaceNoneSign-in and entitlement checks only, plus push and Live Activity tokens if you allow them (section 5)Notifications (optional), Live Activities (optional)Optional, one switch
Cutvey MeterSaved readings and the frames saved with them, your settings and calibrationNoneSign-in and entitlement checks only, and only if you sign in, and one read of the identifier your Apple Account gives the App, which we store only as a salted one way hash, so one activation covers the devices one person uses. Your readings, your camera images and your location are not sent to usCamera (color measurement), location while you use it (sun position and to tag a reading, and you can type coordinates instead), photo library, add only, when you choose to save an image. Motion sensors, which need no permissionOptional, one switch, and it asks everywhere
Cutvey ViewfinderSaved setups, framing presets, your gear list, and what you capture before you save it. Its companion for Apple Watch shows the same frame and is covered by this rowNoneSign-in and entitlement checks only, and only if you sign in, and one read of the identifier your Apple Account gives the App, which we store only as a salted one way hash, so one activation covers the devices one person uses. Your frames, your shot lists and your locations are not sent to usCamera (live viewfinder), microphone only when you record video with sound, location while you use it (sun path on a scouted shot), photo library, add only, to save what you export. Motion sensors, which need no permissionOptional, one switch
Cutvey TeleprompterYour scripts, folders and rundowns, and your settings. Its companion for Apple Watch controls the prompter and is covered by this rowYour scripts, folders and running orders, in the App's own private area of your iCloud account, while Sync scripts with iCloud is on. We cannot read itSign-in and entitlement checks only, and only if you sign in, and one read of the identifier your Apple Account gives the App, which we store only as a salted one way hash, so one activation covers the devices one person uses. Your scripts are not sent to us. When you run a session with other devices on the same local network, the script and the prompter's position go directly to the devices you paired, never through us, and when iCloud sync is on your scripts go to your own iCloud account and not to usMicrophone and speech recognition, only while voice-paced scrolling is turned on (optional, off by default). The audio is analyzed on your device to follow your place in the script. It is never recorded, never stored, and never sent to us or to anyone else for any processing. Local network, only while a session is running. On the Mac, USB access and the operating system's input monitoring permission if you use a jog wheel. iCloud, to keep your library the same on the devices you own, which you can switch off in SettingsOptional, one switch
Cutvey Set RushYour progress and your settings, in the game's own storage on the device. Deleting the game removes themNoneSign-in and entitlement checks only, and only if you sign in, and one read of the identifier your Apple Account gives the App, which we store only as a salted one way hash, so one activation covers the devices one person uses. Your progress, your scores and your settings are not sent to us, and the game makes no other connection of its own to us or to anyone elseNoneOptional, one switch
Future Cutvey appsEach gets its own row here before or when it launches. Until a row is published, nothing in this table is a statement about it
The SitesNothing beyond what your browser needs. No advertising or third-party analytics cookiesNoneWhat you type into a contact, support or lead form, plus the bot-protection check that guards itNoneNothing beyond our server's own request logs (section 5)

Each row has a permanent link: this page's address followed by the row's anchor, for example #p-meter for Cutvey Meter. A product keeps its link if we rename it.

What a sign-in and entitlement check is. It tells us who is asking and which device is asking, and it sends back a token that keeps the App unlocked. Some Apps ask you inside the App, and some open your browser so you sign in there. What is sent differs by App, and it is drawn from the account and device categories in section 5. We use it to sign you in, count the device against your plan's activations, and keep the App unlocked. That is all a check is. It is not a report on what you did in the App.

When you buy an App from a platform store instead, nothing is sent to us. The App asks the store on the device whether your store account owns the purchase, and unlocks on the answer. We receive no receipt, no identifier, no email address and no record that you bought anything, and we create no account for you. Optional usage data and crash reports still follow section 8, whichever way the App was unlocked.

Your own cloud account is yours, not ours. Where a row says an App stores your content in your own cloud account, that content sits in your account with that platform, under that platform's terms and privacy policy. On Apple's platforms it is your private CloudKit database in your Apple Account. We cannot read it and we cannot recover it for you. Deleting a record in the App deletes it in both places. Deleting the App removes the device copy but does not remove what is already in your cloud account. To clear that, delete the records in the App first, or manage the App's data in your platform account settings. Where a row says "None" in that column, the App puts nothing in any cloud account of yours.

Some of our apps can delete your files permanently, on purpose. Where a row says an App offers a destructive action, such as erasing a camera card after a verified copy, it happens only because you asked for it. We never trigger it, we never see the media, and we cannot recover anything erased.

5. What we collect, and where it comes from

We collect these categories. Not every category applies to every product: use the table in section 4 to see which.

Category Examples Where it comes from
Identifiers and account dataName, email address, company name, role, optional photo and phone number, workspace and user identifiers, and your workspace's time zone, which we take from the time zone your browser reports when you sign upYou, when you sign up or are invited
Signup details, before you confirm your addressWhat you type on the Service's signup form: your name, your workspace's name, your email address, the plan you picked, a referral code if you arrived through one, your answer to the product news question, and the page to take you to afterwards. With them, the record of what you agreed to: which version of each document, when, the IP address and browser user agent you agreed from, and the language the page was in. And the time zone your browser reports. We hold these only until you enter the code we email you, and we create your workspace only then, so that nobody can open a workspace in the name of an address they do not control. The form is also checked by the bot-protection service that guards our other forms, named on our subprocessor list. It sees your IP address and your browser's request, and to confirm the check we send it back the token it issued and your IP address, never what you typed. Section 13 says how quickly these details are deletedYou, on the signup form, and your browser
Free trial recordA set of one-way SHA-256 hashes recorded when a workspace starts a free trial of the Service, with the internal identifier of that workspace and when it was recorded: a hash of your email address, trimmed and lower-cased; a hash of the same address in its plain form, with any tag after a plus sign removed and, for mail providers that ignore them, dots and alternative domain names removed, so that different spellings of one inbox count as one; a hash of the domain of the address, unless it is a widely used public mailbox provider or a forwarding or relay service; a hash of a random identifier we place in your browser (the Cookie Notice describes it); and whether the address belongs to a forwarding or relay service. It is how we give each person and each business one free trial of the Service, and how we recognise free trials that appear to be connected. It does not hold your address, your domain or the browser identifier in a form anyone can read back, but it is not anonymous: it is pseudonymous. The same address, domain or identifier always produces the same hash, so anyone who already knows one can check it against the record. We treat it as personal data. Unlike almost everything else we hold, it is kept after your workspace is deleted (sections 13 and 16)Created when a workspace for your address starts its free trial
Checks made when you sign up or start a free trialWhen you ask to create a workspace or start a free trial of the Service, we compare the domain of your email address with lists of services that provide temporary or disposable addresses, and we may look up that domain's public mail records in the domain name system, which sends the domain name, and nothing else about you, to a domain name resolver. An address from such a service cannot create a workspace or start a free trial. When we refuse one, our technical logs record the domain and the reason, not the address. Staff who operate the Service can see free trials that appear to be connected, for example several from one organisation's domain or one browser, with the workspace and its owner's address, and can end a free trialWhat you type on the signup form, the address already on your account, and public domain name records
Authentication dataOne-time sign-in codes (stored hashed and briefly), session tokens, optional two-factor secret, trusted-device records, single sign-on identifiers for Enterprise seatsYou and your device
Device and installation dataDevice name and model, operating system version, app version, an installation or trusted-device identifier, push and Live Activity tokens if you allow them, and the number of devices counted against an activation. Not every Product sends all of these; each Product's row in section 4 says what it sendsYour device, when you sign in to or unlock an App
Hardware identifier for a licensed machineA one-way fingerprint of a Mac, which we cannot turn back into a serial number, used to count activations and so that a free trial can be limited to once per machine (section 16)Your device, when you activate or trial a desktop app
Customer contentEverything a workspace puts into Cutvey: leads, contacts, proposals and contracts, projects, crew records and call sheets, video files and review comments, invoices, documents, galleries, messages, templatesOur business customers (we are processor: section 3)
Commercial and billing dataPlan, subscription status, billing cycle, invoice history, payment-provider customer and subscription identifiers, App purchase and entitlement records, activation countsYou, and our payment provider or Apple
E-signature audit recordsSigner name and email, signature image, timestamp, IP addressThe signing process, as electronic signature law requires
Technical and security logsIP address, browser or app version, operating system, request paths and timestamps, error traces, rate-limit and abuse signalsAutomatically, when you use a Product
Usage data and diagnostic reportsCounts of which features are used and how often, how long sessions last, performance timings, what an app met while it worked (for example a camera format or a kind of destination, each taken from a fixed list), crash and diagnostic reports, the kind of device you use, OS version, app version, and the country you are in and nothing more precise. Section 8 sets stricter rules for this category than for the restAutomatically, on the terms in section 8
Email engagement dataDelivery, bounce, open and link-click events for messages sent through the platform. For a studio's own outgoing mail this is customer content and a product feature (section 10)Our email infrastructure
Communications with usSupport emails, contact and sales form submissions, feedback and bug reports. When you write to us through Help and feedback inside the Service, we also keep your message in your workspace's records, with the kind of message you chose, the page you were on, any error reference the page showed you, the app version, your browser's user agent and your workspace's planYou, and the Service when you send it
LocationCoordinates, used only by a feature that needs them. In the Apps, location stays on the device. In the Service, the coordinates of a shoot location go to our weather provider so a call sheet can show a forecast, with no name or account attachedYour device with your permission, or the address you typed

Card details. Card numbers are entered directly into our payment provider and are not sent to us. We see the last four digits, the card brand and the expiry. If you send us a card number by email we will delete it and ask you to use the payment page instead.

Biometrics. We do not collect, store, transmit or use a face scan, faceprint, fingerprint, voiceprint, retina or iris scan, hand or face geometry, or any other biometric identifier or biometric information, as those terms are used in the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act and Washington's biometric privacy law. No biometric identifier of any kind reaches our servers, from any product.

Some of our apps use your device's camera or its spatial sensors, and some features work by recognizing shapes: composing an image, measuring light, mapping a room, tracking where a device is in space, or grouping photographs that look like they show the same person. Where a feature does anything of that kind, three things are always true. It runs on your device. The result is not stored as a biometric template, and it is deleted when the feature closes or the grouping is cleared. And nothing derived from it is sent to us. The product table in section 4 says which apps use which sensors, and it names any feature that recognizes a person.

If your device offers Face ID, Touch ID or a fingerprint unlock as a way into an App, that check is performed by Apple on your device. We receive only a yes or a no from the operating system, never your face or fingerprint data.

If a future product ever needs to collect, store or transmit a biometric identifier, we will publish a separate written notice, obtain your written consent, and publish a retention and destruction schedule before collecting anything. We will update this policy before any of this stops being true.

No session recording. We do not use session replay, keystroke logging, mouse or scroll recording, capture of form fields before you submit them, or any comparable technology, in any Product. We do not embed any third-party script that does. Our logs record which page or endpoint was requested and when, not what you typed or where you moved your pointer.

Sensitive data. We do not ask you for health data, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or data about criminal matters, and we do not want any of it for our own purposes.

Your own paperwork is a different matter. Releases, crew documents and contracts sometimes contain details like these, and Cutvey is built to hold them. Ordinary production administration also includes contractor tax forms, so a taxpayer identification number can appear in a crew record or an uploaded document, and we do not pretend otherwise. When you put any of this in, you are the controller: it is your legal basis, your consent to obtain, and your responsibility to have the right to hold it. Meeting any state law that governs how a taxpayer identification number is stored is yours as well. We store it, we secure it with the same measures we apply to everything else in your workspace, and we do not read it or use it for anything of our own. We never use or disclose sensitive personal information for any purpose that would give someone an opt-out right under California law.

Health and education records. We are not a HIPAA business associate, we do not sign business associate agreements, and the Service is not designed to hold protected health information or student education records. Where a shoot for a healthcare or education client captures identifiable people, the consent, the authorization and the limits on use are your client's and yours. Keep material governed by those rules out of a Cutvey workspace, or hold only what the authorization you obtained permits.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in US state privacy laws. We have not done so in the preceding twelve months. There is no third-party advertising in any Cutvey product, and no data broker receives anything from us.

When your data reaches us from someone else. Sometimes we hold data about you that you did not give us directly. Most often a colleague invited you to a workspace and gave us your name and email address so we could send the invitation. In that case we hold your name, email address and the role you were invited into. We got it from the person or organization that invited you, and we use it to send the invitation and to run your seat if you accept. We tell you this in the invitation itself, and in any case within one month. Everything in section 16 applies, including your right to object and to have the data deleted if you do not want the seat.

6. Why we process data, and our legal bases

For people in the EEA, the UK and Switzerland, the "legal basis" column is the GDPR basis we rely on. Elsewhere, read the purpose column.

Purpose Data used Legal basis (GDPR)
Provide the Products, run your workspace, sync your account, deliver what you asked forAccount, authentication, device, customer content, technicalPerformance of a contract (Art. 6(1)(b))
Verify a purchase or entitlement, count activations, enforce plan limitsAccount, commercial, deviceContract (Art. 6(1)(b))
Hold your signup until you confirm your email address, then create your workspaceSignup details (section 5)Steps you asked us to take before entering into a contract (Art. 6(1)(b)), and our legitimate interest in never opening a workspace in the name of an address whose owner did not confirm it (Art. 6(1)(f))
Give each person and each business one free trial of the Service, including after a workspace is deleted, and detect, prevent and investigate repeat, automated, abusive or fraudulent signups and free trialsThe free trial record and the checks made when you sign up or start a free trial (section 5), the security and anti-abuse cookie (Cookie Notice), and technical and security logsOur legitimate interests in being able to offer a free trial at all, which we could not do if a new spelling of an address, a temporary address, or deleting a workspace and signing up again produced another one, and in protecting the Service, our customers and ourselves against abuse and fraud (Art. 6(1)(f)). Where you have asked to open a workspace, these checks are also steps we take before entering into a contract with you (Art. 6(1)(b))
Take payment, invoice and collectAccount, commercialContract (Art. 6(1)(b)), and legal obligation for tax records (Art. 6(1)(c))
Send transactional and service email (sign-in codes, receipts, call sheets, notifications, security alerts)Account, technicalContract (Art. 6(1)(b))
Secure the Products: authentication, rate limiting, bot protection, fraud and abuse detection, incident investigationAuthentication, device, technical, security logsOur legitimate interest in keeping a service safe for the people who pay for it and for the people whose data is in it (Art. 6(1)(f)), and legal obligation where breach law applies (Art. 6(1)(c))
Support you when you ask for helpCommunications, account, and the minimum content needed to answerContract (Art. 6(1)(b)), and legitimate interests (Art. 6(1)(f))
Know which parts of our own software are used, and where it breaks, so a small team spends its time on what mattersUsage data and diagnostic reports (section 8)Consent (Art. 6(1)(a)) in the Apps everywhere, and in the Service wherever collecting it means storing or reading anything on your device. Otherwise our legitimate interest in understanding our own product (Art. 6(1)(f))
Operate, meter and bill the Service accurately, which means counting some activity against your accountAccount, commercial, usage tied to the accountContract (Art. 6(1)(b))
Run AI features you invokeThe text or data you point the feature atContract (Art. 6(1)(b))
Keep an electronic signature audit trailE-signature audit recordsOur legitimate interest, and the interest of everyone who signed, in keeping a signed document provable and enforceable (Art. 6(1)(f)), and contract where you are our customer (Art. 6(1)(b))
Market our own products to our own users and subscribersAccount, email address, marketing preferencesConsent (Art. 6(1)(a)) where the law requires opt-in. Otherwise our legitimate interest in telling our own paying customers about products of the kind they already bought (Art. 6(1)(f)), relied on only where you were offered the chance to refuse when we took your address and in every message since
Measure whether our own announcements are readEmail address, open and click eventsConsent (Art. 6(1)(a)) where consent is required for that measurement, including in the EEA and the UK. Where you have not consented, we send the message without open measurement
Comply with law, respond to lawful requests, establish or defend legal claimsWhatever the request or claim requiresLegal obligation (Art. 6(1)(c)), and legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing assessment, weighing what we gain against what it costs you. In each case we concluded the processing is limited to what we need and is what you would expect from a company you pay for software. You can ask us for a summary of any of those assessments at [email protected] and we will send it. You can also object: see section 16.

Providing account and billing data is necessary to have an account. If you do not provide it, we cannot give you one. Everything marked optional in the Products is optional.

7. AI features

Some parts of the Service, and any App whose row in the section 4 table says so, can draft, summarize or reorganize text for you.

An assistant you connect yourself is different. If your plan includes it, you can connect your own AI assistant, such as ChatGPT or Claude, to your workspace. That is not one of our AI features, and this section's promises about our providers do not apply to it.

8. Usage data, crash and diagnostic reports

We want to know which features people use, and where our software breaks, so that a small team spends its time on the right things. We do not want to know what any particular person is doing, and we have built this so that we cannot.

Which Products this section is about. The ones whose row in section 4 says they send usage data or crash and diagnostic reports. Where a row says a Product sends none, none of this section applies to it: there is nothing collected, nothing to ask you about and no switch, because there is nothing to switch off.

Two kinds of data, where a Product sends anything at all.

Required service data is the minimum needed to provide what you bought and to keep the software honest: checking and counting your license or activation, checking for updates, telling our servers the app and system version so the right answer comes back, preventing abuse and fraud, and anything a feature you use needs in order to work, for example syncing with your Cutvey account when you sign in. This has no switch, because without it the App cannot do its job. It carries no usage statistics and no crash or diagnostic reports. An App that has no license check, no update check and no account sends none of this either.

Optional usage data and crash and diagnostic reports is what the rest of this section is about: which features you use and how often, what your App met while it worked, how long things took, and what went wrong when something failed.

Where we ask first, and where we do not. Optional data is on by default wherever the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, throughout Canada, and anywhere else whose law requires your agreement before software reads or stores this kind of information on your device, an App sends nothing unless you say yes. We ask before the first send, not after it. Saying no is exactly as easy as saying yes, there is no pre-ticked box, and nothing about the App changes if you decline. Some of our Apps ask everywhere, whichever country you are in, and none of them treats silence as a yes.

We ask everywhere in Canada. A device tells us the country it is in and never the province, so a Quebec resident cannot be told apart from anyone else in Canada by the signal we receive. The commitment in section 17.4, that privacy settings start at the highest level of confidentiality, is only keepable if we ask throughout the country, so we ask throughout the country.

If an App cannot tell where it is, it asks. An empty answer, or one we cannot read as a country, is treated as a place where we have to ask. We never read an unclear answer as permission.

That list can grow and does not shrink quietly. We add a place to it whenever a law or our own judgment says we should, and that needs no notice because it only ever means asking more people. We would not take a place off that list without telling you first under section 20.

Where the country comes from. From the region your device or its app store reports. That is a setting on your device, not a measurement of where you are, and we never work it out by looking up your network address. The request that carries usage data or a diagnostic report has your network address on it, as every request on the internet does. We do not store it. It becomes a fingerprint salted with a value that changes daily, used only to stop one sender flooding the endpoint.

The switch does what it says. Where a Product sends optional data, it has one switch for it in its own settings, and that switch is the whole of it. Off means off: from that moment the App sends no usage statistics and no crash or diagnostic reports, anywhere in the world, and anything already waiting to be sent is discarded rather than kept, including a crash report. It does not turn off required service data, and the screen says so.

Nothing is sent before you answer, and keeping is not sending. Where we ask, nothing leaves your device until you have answered. An App may keep a report of a failure that happened before you answered, in its own storage on your own device, so that the report is not lost with the crash. It is sent only if your answer is yes, and it is deleted unsent if your answer is no. Holding something on your own device is not collecting it, and we say so here rather than let you discover it.

In the Service, some measurement is how the product works. We record activity tied to your account where that is how we operate the Service, meter your plan allowances, count activations, bill you correctly, or detect and stop abuse and fraud. That is part of running your subscription, and it is described in section 6. Beyond that, we collect general usage data about our own web pages, which is not linked to your account. Measuring the web app may one day require us to store or read something on your device that is not necessary for the service you asked for. If that happens, we ask for your consent first in the European Economic Area, the United Kingdom and Switzerland, and you can withdraw it.

Usage data is counters, not records. We do not keep a record of what you did. Each thing an App reports is added to a counter that covers a whole day, on a key made up only of the app, the app version, the operating system and its version, the kind of device you use (for example a recent iPhone, not its serial number), the country and nothing more precise, and which item from a fixed list is being counted. No table holds a row for one thing you did, nothing records the order you did things in, and nothing records a time of day. Session lengths and performance timings are counted the same way, as totals and as counts inside coarse ranges rather than as individual measurements.

What the counters count. Three kinds of thing. Which features were opened and how often, including how far people get through first-run setup. How long the App took to do something. And what the App met while it was working: which camera format was on a card, which kind of destination a copy was written to, which wall a person hit (an unsupported format, a permission refused, a full disk, being offline), and which of our default settings people change.

Every value comes from a fixed list. Each thing we count is an entry in a list held in our own code, and no entry is added without a one-line reason for collecting it. Anything an App sends that is not on that list is discarded rather than stored. Nothing in this pipeline has a field that carries text you typed, so a file name, a folder name, a volume name, a path, a search term or a project name cannot travel in one. We add to that list as we build, and a new entry is always a count of a feature or of something an App met, in the same shape as the rest. If we ever needed to count something that does not fit that shape, we would tell you under section 20 before we did.

What a diagnostic report contains. A diagnostic report is what an App sends when something goes wrong: a crash, or a failure it handled and carried on from. It carries technical state: the app version, the operating system version, the kind of device, the country, whether the failure was fatal, the operation that failed, the error name and code the system gave, how much memory was free, the error message and the stack trace. A diagnostic report carries none of your own content and no Cutvey account details.

Breadcrumbs. A diagnostic report can also carry breadcrumbs: up to ten of the same fixed feature names the counters use, in the order they happened, so we can see what the App was doing in the moments before it failed. A breadcrumb is one of those names or it is nothing. Anything else an App puts in that list is discarded rather than cleaned up, so a file name, a path or a message cannot travel as a breadcrumb. Ten names in order is the most this pipeline ever holds about a sequence of actions, and it is not tied to you or to an account.

We design and filter these reports so that they do not carry your content. When a report reaches us, and before it is stored or sent anywhere else, we remove from its message and its stack trace everything under your home folder, everything under a mounted volume including the volume's own name, email addresses, access tokens, query strings, and long random-looking strings of the kind a link token or an identifier is made of. Only the system paths needed to identify the fault remain. That removal happens once, on our servers, so the report we keep and the report our provider receives are the same text. What it cannot do is guarantee that a piece of personal data never appears inside the text of an error message written by software, and we will not claim otherwise. Where one does, we treat that report as your data and handle it under this policy and, for a business customer's workspace, under our Data Processing Addendum.

Where reports go. A diagnostic report from an App is received by an endpoint we operate and is stored on our own servers. From there we forward the same scrubbed text to the crash and error reporting provider named on our subprocessor list, which is a third party: today Sentry (Functional Software, Inc.), on servers in the United States. Error reports from the Service reach the same provider from our servers as well. Because the forwarding happens from our servers rather than from your device, that provider does not receive your device's network address. That provider is contractually limited to providing the service to us and may not use the reports for its own purposes. If we add or change a provider for analytics, crash reporting or error reporting, it goes on the subprocessor list before it receives anything, under the advance-notice process on that page.

No Cutvey app contains a third-party crash reporting component. Crash and diagnostic reports from an App go only to an endpoint we operate, and we forward them onward from our own servers, which is why that provider never receives your device's network address. The Service's own server error reports reach that provider from our servers as well, because they arise on our servers and not on your device.

Your platform's own crash sharing is separate. Your phone, tablet or computer can share crash information with app developers through the platform owner's own channel. The platform asks you for that when you set up the device, the platform decides what it contains, and you turn it on or off in your device settings, not in ours. We see only what you have allowed the platform to share.

Keeping identity out of it. Usage and crash records carry no name, email address, account id or workspace id, and we do not try to link them to you. Sign-in, activation counting and billing are separate systems that do know who you are, and they are described in sections 5 and 6. We do not claim these records could never be re-identified by someone determined to try. We claim that we do not try, we do not permit a provider to try, and we do not join them to your account record.

One thing we do remember about a machine. Where an app is licensed per machine rather than per person, we keep a one-way fingerprint of that machine so that an activation is counted once, and so that we can make a free trial run once per machine (section 16 says whether we do today). We keep it for up to 365 days after we last see it, and then it is deleted automatically. Like the free trial record for an email address in section 5, it is not kept inside a single workspace, because otherwise the same machine could take a new trial in a new workspace every week. It carries no name, no email address and no network address, and we do not use it for anything else.

Our commitment on data that is not linked to you. Where we hold usage data that is not linked to an account, we take reasonable measures to keep it that way, we use and keep it only in that form, we do not attempt to re-identify it, and we contractually prohibit any provider who touches it from attempting to re-identify it. We make this commitment publicly so that you can hold us to it.

No third-party tracking. We do not embed advertising components, attribution components or cross-site or cross-app tracking technology in any Product, and we do not track you across other companies' apps or websites. No Product embeds a third-party crash reporting or diagnostics component either. That is why our Apps do not ask for permission to track you: the permission we would be asking for is about improving our own software, not about following you anywhere else.

9. Cookies and similar technologies

Short version: the app uses only what it needs to keep you signed in, and the Sites set nothing for advertising or third-party analytics.

The detail, category by category, is in our Cookie Notice, which is part of this policy: https://cutvey.com/legal/cookies.

10. Email, telephone and text messages

Transactional and service email (sign-in codes, receipts, invoices, call sheets, notifications, security alerts) is part of the Products. You cannot unsubscribe from it while you have an account: a sign-in code you did not receive is an account you cannot open. Closing your account stops everything.

Our own email to you about Cutvey. We email our own users about our own products, and about nothing else. We never send another company's offer, we never rent, sell or share our list, and no advertiser or data broker ever receives an address from us.

Who "our own users" means. The person who owns a Cutvey workspace or holds a seat in one, a person who bought something directly from us, and anyone who gave us their address on one of our own websites or asked us to keep them posted. It does not mean a client, a lead, a crew member or a talent whose details a studio put into its workspace. Those are the studio's contacts, not ours. We never market to them, and we never use a workspace's contacts for our own mail. As section 3 explains, we hold that data as a processor for the studio, and using it for something of our own would be a breach of what we promised the studio.

New products. Every Cutvey product is a tool for the same work, made and sold by the same company, and telling you about a new one is the only kind of message we send. So a message about something we have just released is a message of the kind you were given the chance to refuse when we took your address, and you can refuse it in that message as easily as you could in the first one. Where the law where you live requires your agreement before any commercial email, we ask for it when you sign up, we record your answer, and we send nothing until we have it.

Where local law instead lets us email an existing customer without asking again, we rely on that only in three conditions: the message is about products of the kind you already have, you were offered the chance to refuse when we took your address, and the relationship is recent enough for that law to allow it. In Canada that means 24 months from your last purchase or contract, and 6 months from an enquiry you made. Where the law where you live keeps a register of people who do not want unsolicited commercial email, we check it before we send.

Every marketing message identifies Cutvey LLC as the sender and carries our mailing address and contact details, valid for at least 60 days after we send it. Every message carries an unsubscribe link and a one-click unsubscribe, working for at least 60 days. We action an unsubscribe immediately in practice, and within 10 business days at the outside.

We may also tell you about something new inside the product itself. That is not email: it carries no measurement of any kind, and closing it is the whole of the choice.

If we ever offer support by telephone, we will call you only about something you asked us about, and never to sell you anything.

Our own announcements measure opens and clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So in the European Economic Area, the United Kingdom and Switzerland we ask for your agreement to that measurement when you subscribe, and we do not measure opens for anyone who has not agreed. You can withdraw at any time. Sign-in codes, receipts and other service email carry no measurement pixel at all.

Email a studio sends through the Service. A proposal, invoice, call sheet or gallery link that a studio sends to its own client can carry a small tracking image and click-tracked links, so the studio can see whether the client opened it. Here is how responsibility divides:

Telephone and text messages. We do not call you, we do not send you SMS or text messages, and we do not use an autodialer or prerecorded messages. A phone number you give us is used only to reach you about your account if you ask us to. A phone number a studio puts on a call sheet is that studio's data, used by that studio. If we ever add text messaging, it will be opt-in, the opt-in will be separate from signing up, and STOP will end it.

11. How we share data

We do not sell data. We share it in these situations and no others.

Subprocessors and service providers. A short list of vendors who run part of our infrastructure. Each is engaged under written terms that limit it to providing its service to us, with confidentiality and security obligations. None is an advertising network or data broker, and none may use the data for advertising. The current list, with what each one does and where it processes data, is at https://cutvey.com/legal/subprocessors and is part of this policy. That page also names the two companies that additionally act on their own account rather than only on ours, and says how we notify customers of changes.

Inside a workspace. Content in a workspace is visible to the members and invitees that the workspace authorizes, according to the roles and sharing links it configures. If you are a member of someone's workspace, the owner and administrators can see your activity in it.

Video viewing. When you watch a video in a review link, a gallery or a portal, that activity is recorded inside the workspace that sent it to you. That is so the studio can see whether its work was reviewed. We do not disclose video viewing records to any advertiser, analytics network, social platform or data broker, and we put no advertising or analytics pixel, tag or software development kit on any page. Cutvey's own video player is served from our own systems and reports to nobody but us. The studio that sent you the link decides what it does with that record, and it is the studio to ask about it. We treat video viewing records as customer content under section 3.

Video a studio embeds from somewhere else. A studio can paste a link to a video hosted on another company's service, for example a video sharing site, into a page it sends you. Where it does, we show you a still and the name of the company whose player it is, and we do not load that player until you press play. Until you do, nothing about you reaches that company. When you press play, that company receives your network address, sees the request and can set its own cookies under its own privacy policy. We do not choose those sites, we send them nothing about you, and we receive nothing back. The studio that pasted the link decided to put it there. Video we host ourselves plays with nothing from anyone else on the page.

At your direction. When you send a proposal, publish a review link, share a gallery or connect an integration, the data goes where you sent it. That includes an assistant you connect to your workspace: what it reads goes to the provider you chose.

Legal process and safety. We require valid legal process. We review each request, and where we believe a request is overly broad, defective or unlawful we object to it or ask for it to be narrowed. We cannot promise to litigate every request, and we comply where we are legally obliged to. We also disclose where we believe in good faith that disclosure is necessary to protect the rights, property or safety of Cutvey, our users or the public, or to establish or defend legal claims.

We tell you before we produce anything, unless we cannot. Our practice is to notify the affected user before production, so that the user can object. The exceptions are these, and only these: where the law or a court forbids us to tell you; where we may lawfully delay notice and a law enforcement agency asks us to, in which case we notify you when the delay ends; and where we believe in good faith that there is an emergency involving a risk of death or serious physical injury to someone, or a risk to a child, in which case telling you first could cost someone their safety. Where a bar on telling you lifts, we tell you then.

Emergencies. United States law lets us disclose to a governmental entity, without legal process, where we believe in good faith that an emergency involving danger of death or serious physical injury requires it. We use that narrowly, we record every time we do, and we tell the affected user afterwards unless one of the exceptions above still applies.

Requests we are forbidden to describe. Some requests, including certain national security process in the United States, come with a legal bar on saying anything about them at all, including to you and including in this policy. Where that happens we say nothing until the bar lifts. We do not publish a warrant canary, and we ask you not to read anything into our silence in either direction: the absence of a statement from us means nothing.

Subpoenas and civil cases. United States federal law, 18 U.S.C. 2702(a), prohibits us from disclosing the contents of a customer's files and communications to a private party in a civil case. That includes a civil subpoena, and we will not do it. If a private party wants the contents of a workspace, they must get them from the business that holds it, not from us. Where a civil subpoena seeks only basic account records, we tell the affected customer first and give them a reasonable chance to object, unless a court orders otherwise.

Requests from outside the United States. We are a United States company and our data is in the United States. A request from an authority elsewhere reaches us through United States legal process, through a mutual legal assistance treaty, or through an agreement the United States has entered into. We do not respond directly to a foreign authority's demand. This does not affect any obligation we have to a supervisory authority under a privacy law that applies to us, which is a different thing from a demand for your data.

Where there is nothing for us to produce. Much of what our software does happens on your own device or in your own cloud account, where we have no access and no copy. Where an App's row in section 4 says your content stays on your device, a request to us produces nothing, because we do not have it, and whoever wants it has to ask you or the platform owner.

Preservation. A letter from a private party demanding that we preserve something is not legal process. We forward it to the customer concerned and take no other action. We honor a preservation request from a governmental entity under 18 U.S.C. 2703(f), and a written instruction from the customer, for the period the request or the instruction covers and no longer, and we tell the customer where we are permitted to.

How to send us a request. Law enforcement and other authorities should email [email protected] with "Legal request" in the subject, from an official address, attaching the process and naming the account by email address or workspace name. We require valid process for content, and a subpoena or equivalent for account records. We may charge our reasonable costs of responding where the law allows it. We do not publish a periodic transparency report, and nothing in this policy is a promise to start. We keep a record of the requests we receive, and where the law allows us to answer, and where answering does not itself reveal something we are forbidden to reveal, we will tell a customer on request whether we have received one about them.

Business transfers. If Cutvey is involved in a merger, acquisition, financing or sale of assets, data may be transferred as part of that transaction. We will require the receiving party to continue handling it under this policy or a policy at least as protective. We will give account holders notice, and a chance to export and delete, before their data becomes subject to a materially different policy. If we ever wind the business down, we will give you as much notice as we reasonably can, at least 90 days where we are able to and never less than 30, we will keep export and file downloads working throughout, we will refund the unused part of anything you prepaid for the period after the shutdown date, and we will delete rather than sell what is left of your workspace. Terms of Service Section 34 binds us to the same.

Professional advisers. Our lawyers, accountants, auditors and insurers, under duties of confidentiality, where they need it.

With your consent, for anything else.

12. International data transfers

We process data in the United States. Our servers are in the USA, and that is where your workspace lives. If you use a Product from anywhere else, your data is transferred to and processed in the United States. The United States may have different data protection rules from your own country, and its public authorities may in some circumstances seek access to data. We reduce that risk with the measures in section 14, by challenging requests we consider overbroad or defective, and by telling you where we lawfully can. A small number of the providers on our subprocessor list operate elsewhere or globally, and that page says which and where.

How your connection reaches us. One of those providers, the network security provider named on our subprocessor list, stands in front of the Service: today Cloudflare (Cloudflare, Inc.). When you use the web app, or a page a studio serves from its own custom domain, your connection is first received on that provider's network, at a location near you, which may be in your own country or in another one. The provider helps protect the Service against attacks and abuse there and passes your request on to our servers in the United States. To do that it processes, on our behalf, your IP address and connection details and the content of what you send and receive while it is in transit. The subprocessor list says what that provider does for us and where.

Transfer mechanism. For personal data protected by EEA, UK or Swiss law we rely on the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914).

We have carried out a transfer impact assessment covering United States law, our exposure to it and the extra technical and contractual safeguards we apply. It is published, not hidden: it is Section 9.5 of our Data Processing Addendum, and you can read it now. You can also ask us for a copy of the clauses at [email protected].

We do not claim certification under the EU-US, UK Extension or Swiss-US Data Privacy Framework. If we certify in the future, we will say so here and on the Department of Commerce list, not by implication.

13. How long we keep data

We keep personal data only as long as we need it for the purpose we collected it for, plus any period the law requires.

Read this one before you cancel. If you cancel, a trial ends without a paid plan, or a subscription ends because it was not paid, we keep your workspace for 30 days so you can come back or export, and then we delete it permanently. We email you before that happens. Export your data first: Settings, then Export, gets you everything at any time, including after you have canceled and while the 30 days are running.

Data Retention
Workspace content and account data (active subscription)While the account is active
Workspace content and account data (after cancellation, trial expiry, or a subscription ended for non-payment)30 days, with reminder emails before deletion, so you can reactivate or export. After that we delete it, and it ages out of backups within a further 30 days. A subscription that is not paid is paused first and ended 30 days after the payment failed, as the Terms of Service describe; nothing is deleted while it is paused
Self-serve workspace deletion7-day cooling-off period after email-confirmed deletion, then workspace data is permanently erased
Individual client, lead, crew, talent or vendor record erased by the workspace with the per-record erasure tool, or by us on the workspace's written instructionErased when the workspace erases it or asks us to, then ages out of backups
BackupsRolling schedule, up to 30 days, after which deleted data is gone from backups too
Sign-in codesHashed, valid for minutes, deleted after use or expiry
Signup details, before you confirm your addressDeleted when you enter the code we emailed you, in the same step that creates your workspace. The record of what you agreed to is then kept as the row on accepting a legal document says. If you never enter a code, the details are deleted automatically once the last code we sent you has been expired for an hour. A code lasts 10 minutes and the deletion runs every 15 minutes, so that is within about an hour and a half of the last code. Starting a new signup with the same address replaces the earlier details at once
Sessions and trusted devicesUntil you sign out, revoke the device, or the session expires
Technical and security logs (request logs, rate-limit and abuse signals, error traces)Up to 90 days. We keep them longer only where a specific open security investigation needs the records, where we are required to preserve them by law or by a preservation request we must honor, or where they are needed to establish or defend a legal claim, and then only the records concerned and only for as long as the reason lasts
The audit log inside a workspace, which records significant actions in itThis is your workspace's own record and we do not age it out. It lives as long as the workspace does and is deleted with it
Usage data not linked to an accountKept in aggregated form for as long as it is useful for product decisions. Individual event records are deleted or aggregated within 12 months
Activity we record against your account to run, meter and bill your subscriptionWhile the account is active, then with the workspace under the rows above
Cutvey Offload dashboard status, sent while the dashboard is onThe current status is replaced by the next one the Mac sends. The job history derived from it is kept for 30 days or the most recent 500 entries per workspace, whichever is fewer, and it is deleted with the workspace. No file path is ever stored
Crash and diagnostic reports, including their breadcrumbsUp to 12 months from the failure itself, counted from when it happened and not from when we received the report
E-signature audit recordsFor as long as the workspace that holds them exists, and in no event more than 12 years from signature. They are deleted when the workspace is deleted, because the record lives inside the workspace. Download your copy of anything you sign, and its signing record, at the time you sign, and do not rely on us as your archive. We email a copy to every signer when a document is completed. Where a legal hold applies, we keep only the record it names, and only for as long as the hold lasts
Billing, invoice and tax records7 years, as US tax and accounting rules require
Support and other correspondenceWe aim to clear a thread 24 months after the last message in it, and we delete a thread sooner if you ask us to
Messages sent through Help and feedback in the ServiceDeleted automatically 24 months after you sent them, whether or not the request was closed, like the rest of our correspondence, and sooner if the workspace is deleted first. The email each message becomes in our support inbox is correspondence under the row above
Marketing contacts, and the record that you unsubscribedWhile you are subscribed. Your unsubscribe is kept for as long as we send any marketing at all, because keeping a record of your objection is the only way to honor it, and Article 21(3) of the GDPR requires us to
App license and entitlement recordsFor the life of the license, and afterwards as long as needed for accounting and abuse prevention
Contact, support and lead form submissions on our own sitesUp to 24 months from the last message, then deleted
Video and document viewing records inside a workspaceCustomer content: kept while the workspace keeps them, deleted with the workspace or when the customer deletes the record
Record that you accepted a legal document, and record of your consent to automatic renewalKept for as long as we may need to prove what you agreed to, and in no event less than 3 years after the agreement ends. These are records of what you agreed and when, not records of your business, they are not part of a workspace, and they are not deleted when a workspace is deleted
Record of a cancellation you asked forKept for at least 3 years after the cancellation, for the same reason
Free trial record (every part of it described in section 5)Kept for 3 years from when it was recorded, and then deleted automatically. That includes after the workspace it was recorded for is deleted and after your account is closed, because deleting it sooner would let the same person or business start another free trial. It holds no readable address, domain or browser identifier (section 5), and section 16 says what happens if you ask us to delete it. A refused signup is recorded only in our technical and security logs, by domain and reason, and is kept for as long as those logs are

Where we cannot delete something immediately, because it sits in a backup, we isolate it and delete it when the backup ages out.

Two things pause these clocks. If we receive valid legal process, or a written notice from someone with a genuine claim that identifies specific material and the proceeding it relates to, we may place that material on legal hold. Material on hold is left out of workspace deletion, out of the periods in this table and out of the ordinary backup expiry, and is kept only for as long as the hold requires.

Separately, we place a workspace on a bereavement hold if we are told in writing that a sole account owner has died or has lost capacity, and the claim is credible on its face. Billing, suspension and the deletion clock all stop for up to 12 months, while an executor or a court-appointed person proves their authority, and we extend the hold if we are told that probate or a guardianship is still running. Then the ordinary rules resume. Nobody gets access during either kind of hold.

14. Security

These are the security measures we maintain:

Support access is visible in the Service. If our support staff use the in-product support access feature to view your workspace, that is recorded in your audit log and shown to you with an on-screen banner while it is happening. Separately, a small number of people have administrative access to the underlying servers and database, which is necessary to operate and repair the service. That access is not surfaced as a banner, and we use it only to operate, secure and repair the Products. Where support access happens somewhere the banner cannot be shown, the audit entry is still written and you can see it in your audit log.

That administrative access is logged on the server, is granted individually rather than through a shared credential, is limited to the people who need it, and is removed when the need ends. We do not use it to read a workspace's content in the ordinary course, and where we ever have to, we record why.

Security is a moving target and we improve these measures over time. This list describes our practices. It is not a warranty that any particular measure will prevent every attack.

We do not currently hold a security certification such as SOC 2. If we earn one, we will name it here. Until then, take the list above as the whole of what we claim.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant regulators as and when the law requires, including Florida's Information Protection Act (Fla. Stat. 501.171), the GDPR's 72-hour regulator deadline where it applies, and the corresponding laws elsewhere. Where we are a processor, we notify the customer without undue delay, meaning as fast as we reasonably can, within the deadline set by our Data Processing Addendum and within any deadline the law sets, so it can meet its own.

15. Children

No Cutvey product is directed at children, and none is designed to appeal to them. None of our Apps is offered in the App Store Kids Category.

Where a Product is a game, the same rules apply to it as to everything else we make. It is made for adults who do this work, it is not in any store's children's category, it carries no advertising, the only purchase it offers is the one-time purchase that unlocks it, and its row in section 4 says what it collects. If we ever add a leaderboard, a score board or any other place where you can type a name that other people see, its row will say so before it ships, and we will not accept a name from anyone below the ages in this section.

We do not knowingly collect personal data from anyone below these ages. If we learn we have, we delete it promptly and close the account. A parent or guardian who believes a child has given us data should email [email protected] and we will act, without asking them to prove anything burdensome.

A studio may use Cutvey to handle a release, a booking or a call sheet involving a minor. If so, the studio is the controller and the parent or guardian is the person who consents and signs. The studio is responsible for collecting that data lawfully, and for any parental consent its law requires. We process it only on the studio's instructions and never for a purpose of our own.

16. Your rights, and how to use them

Where the law gives you these rights, we honor them. Where it does not, our practice is to honor a request anyway if we can do so without breaking a legal obligation, without affecting someone else's rights, and without unreasonable effort. Requests about a business customer's workspace records are handled as described at the end of this section.

Automated decisions, and getting a person. We do not profile you, and we make no automated decisions about you for marketing or pricing. Four things we do are automatic and can matter to you. If a payment fails, your subscription is suspended and eventually canceled by the system after the reminders we send. If our security systems see a strong signal of abuse or fraud, access can be blocked automatically while we look at it. If an email address has already had a free trial of the Service, a new workspace for that address, or for another spelling of it that reaches the same inbox, starts without one, automatically. And an email address from a service that provides temporary or disposable addresses cannot create a workspace or start a free trial: it is refused automatically, from lists of such services and from the public mail records of the address's domain, and you can use a permanent address instead. Separately, and not automatically, a person on our staff may end or refuse a free trial that we reasonably believe is a repeat of an earlier one or is otherwise abusive (the Terms of Service say so). The free trial record's other details, such as a shared domain or browser, are shown to that person and never refuse a free trial by themselves. We also keep a record of which machines have had a free trial of an App licensed per machine (section 8), so that we can refuse a second trial on the same machine in a different workspace. Today that refusal is switched off and no trial is refused on that ground. If we switch it on, the refusal will be automatic, and it will never take away a Mac that is already activated. Each of them is necessary to run the contract between us and to keep the Products safe. In each case, email [email protected]: a person will look at it, you can put your side of it, and we will reverse it if it was wrong. We will not leave an account suspended on an automated signal alone once you have asked us to look.

How to exercise your rights, fastest first:

  1. In the Product. Access, correct, export and delete are all built in. Sign in to your Cutvey account and go to Settings, where you can export everything at any time. If you own the workspace, that is also where you delete the workspace and everything in it. If you hold a seat in someone else's workspace, you can leave it and close your own seat yourself, in Settings, then Security. When you do, we delete your personal account data and revoke your devices and app activations, within the time set out below. We tell the workspace owner that you have left, because their workspace has lost a member. We do not delete the studio's own records about you, which belong to the studio: section 3 explains why. Ask the studio for those, and if you ask us instead we pass that part of your request to them and help them answer it. Each App that signs in with Cutvey links you straight to that page from its own settings, so you can start from wherever you are. We email you to confirm it is really you, there is a 7-day cooling-off period in case you change your mind, and then the account is permanently erased.
  2. Email [email protected] with what you want.

If you only bought an App from Apple, there is nothing for us to delete. Buying the one-time unlock through Apple does not create a Cutvey account. You give us no email address and no name, we hold no record of you, and there is no account for you to close. Your content stays on your device and, if you turned sync on, in your own iCloud, where you delete it in the App or in your Apple Account. Apple holds its own record of your purchase under Apple's privacy policy, and only Apple can act on that.

Deleting an App is not deleting your account. Removing an App from your device leaves your Cutvey account exactly as it was, if you have one. Signing out, or removing a device, only frees an activation.

Deleting a seat is not deleting a workspace. If you were invited into someone else's workspace, deleting your Cutvey account removes you and your personal account data, and removes you from that workspace. It does not delete the studio's workspace or the records the studio holds, which belong to the studio as controller. If you own a workspace, deleting your account reaches full workspace deletion, and we tell you that clearly before you confirm.

Deleting your account does not delete your free trial record. The record in section 5 that your email address has had its free trial, with the other hashes recorded beside it, is kept for 3 years from when it was recorded, even after your workspace and your account are gone, because deleting it sooner would let the same person or business start another free trial, and preventing and investigating that is the only thing it is for. Then it is deleted automatically. It holds no readable address. If you ask us to delete it, we will tell you that, and you can object under this section: a person will look at your objection, tell you the outcome and the reason, and delete the record if we agree.

What happens next. We aim to acknowledge within five business days. We respond within 45 days (US state laws), extendable once by a further 45 days where the request is complex, and within one month under the GDPR, extendable by two months for complex requests. We tell you if we need an extension and why. Unless you ask for something else, we answer electronically, to the address you wrote from, and we give any copy of your data in a structured, commonly used, machine-readable format.

Another format. If you need this policy, or any answer we give you, in another format, tell us and we will provide it.

Requests are free. The law allows us one exception, and we expect never to use it: a repetitive or excessive request, for example the same request sent over and over. There we may charge a reasonable fee, or decline and explain why.

Verifying who you are. We verify your identity before acting, in proportion to the sensitivity of the request. Usually that means responding from the email address on the account, or completing a sign-in. We will not ask you for a government identity document, a photo of yourself or a financial account number to verify a privacy request. If we genuinely cannot verify you any other way, and acting would hand over someone's data, we will explain what we would need and offer you another route rather than guessing.

Authorized agents. You may use an authorized agent, including under California law, to make a request for you. We will ask for written proof that you authorized them, and we may ask you to confirm directly. An agent acting under a signed power of attorney does not need the extra confirmation.

Appeals. If we refuse your request, we tell you why and how to appeal. Reply to our decision, or email [email protected] with "Privacy appeal" in the subject. We review and respond in writing within 45 days with our decision and our reasons. If we still say no, we tell you how to complain to your regulator. This appeal route is open to everyone, not only residents of the states that require it.

Complaints. You can always complain to your data protection authority or attorney general. In the EEA that is the supervisory authority where you live, work or where the issue arose. In the UK it is the Information Commissioner's Office (ico.org.uk). In Switzerland it is the Federal Data Protection and Information Commissioner. You also have the right to go to court. In the EEA and the UK that means an effective judicial remedy against us and against your supervisory authority, plus compensation for damage caused by a breach of the rules. We would rather you told us first, but you do not have to, and coming to us first costs you none of these rights.

If you are a studio's client or crew. Send your request to the studio. If you send it to us, we will tell you who the studio is and how to reach them, and with your agreement we will pass it on and help them answer it.

17. Regional information

This section adds region-specific detail. Everything above still applies.

17.1 EEA, United Kingdom and Switzerland

17.2 California

Under the California Consumer Privacy Act as amended by the CPRA:

17.3 Other US states

Residents of any US state with a comprehensive consumer privacy law in force have the rights described in section 16, exercised the same way, with the same 45-day response window and the same appeal route. That currently includes Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware and a growing list of others. We do not wait for your state to pass a law before honoring a reasonable request. Specifically:

Florida. We are a Florida company. Florida residents have the rights in section 16, exercised the same way, and we honor them whether or not a particular Florida statute obliges us to. Note that the Florida Digital Bill of Rights places its main obligations on companies far larger than us. You can contact the Florida Attorney General's office if you are not satisfied with our response.

Nevada. Nevada law (NRS 603A.340) lets residents tell a covered operator not to sell their covered information for money. We do not sell covered information. If you want to send the request anyway, email [email protected] and we will confirm.

Washington and Nevada health data laws. We do not collect consumer health data, and no Cutvey product is a health app.

17.4 Canada

We handle personal information in line with PIPEDA and, for Quebec residents, Quebec's Law 25:

17.5 Brazil

Under the Lei Geral de Protecao de Dados (LGPD) you have the rights to:

Our legal bases (Art. 7). Execution of a contract you are party to and preliminary steps at your request (Art. 7, VI), compliance with a legal or regulatory obligation (Art. 7, II), our legitimate interests for security, abuse prevention and telling our own customers about our own products (Art. 7, IX, limited to what those purposes need), and your consent (Art. 7, I) where we say so. You can ask us for the legitimate-interest report supporting any Art. 7, IX processing.

International transfers. Your personal data is processed in the United States. We make those transfers on the basis of the standard contractual clauses adopted by the ANPD under Resolution CD/ANPD No. 19/2024. Where a transfer falls outside them, we rely on the necessity of performing a contract you are party to (Art. 33, V), or on your specific and highlighted consent (Art. 33, VIII).

Data protection officer (encarregado). Our data protection officer for LGPD purposes is the Founder of Cutvey LLC, reachable at [email protected] and at the postal address in section 1, and available to receive your requests and communications from the ANPD.

Requests go to [email protected]. You may petition the Autoridade Nacional de Protecao de Dados (ANPD) against us at any time, and you may complain to a consumer protection body.

17.6 Australia

We handle personal information consistently with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

17.7 Japan

We handle personal information consistently with the Act on the Protection of Personal Information (APPI).

17.8 South Korea

We handle personal information consistently with the Personal Information Protection Act (PIPA). We collect the minimum necessary for the purposes in section 6, retain it for the periods in section 13, and destroy it without delay once the purpose is achieved.

Overseas transfer. We transfer personal information out of Korea and process it in the United States. We disclose the following under Article 28-8(2), so that a separate consent is not required for transfers necessary to perform our contract with you:

Chief Privacy Officer. Our Chief Privacy Officer under Article 30 of PIPA is the Founder of Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA, [email protected].

You may request access, correction, deletion, suspension of processing and withdrawal of consent at [email protected]. You may report a matter to the Personal Information Protection Commission (PIPC), or call the Korea Internet and Security Agency privacy call center on 118.

17.9 India

As India's Digital Personal Data Protection Act, 2023 comes into force, we handle personal data consistently with it.

17.10 Everywhere else

If your country gives you privacy rights not listed here, tell us what you want and we will do our best to honor it. Our default is to treat a reasonable request as valid regardless of where you live.

18. Global Privacy Control and other opt-out signals

We honor the Global Privacy Control (GPC) and other recognized universal opt-out preference signals where the applicable law makes them binding. We record the signal when your browser sends it, and we treat it as a request to opt out of sale and of sharing for cross-context behavioral advertising for that browser or device.

Today that request has nothing to act on, because we do not sell or share personal information for advertising in any Product. We honor the signal anyway, so that you do not have to take our word for it.

19. Do Not Track

Browsers can send a "Do Not Track" (DNT) signal. There is still no agreed standard for what a company must do in response, so like most operators we do not change our behavior based on DNT. We can say the thing DNT was invented to ask for: we do not track you across other companies' websites or apps, at all. The signal we do act on is Global Privacy Control (section 18).

20. Changes to this policy

Products change, so this policy will change too. We have written it so that routine change lands in the tables and in the referenced lists (the subprocessor list, the Cookie Notice) rather than requiring a new policy.

How we number these documents and when we tell you. Each document carries a whole number version and a last-updated date. The version number goes up by one only when we make a material change to that document's own words, and only for that document: the others keep the number they have. Everything else moves the date and nothing else: correcting a typo, making a sentence clearer, fixing a fact, or changing a row in a table or in a list this document points at, such as the product table in section 4, the app table in Schedule A of the App License Agreement, or the subprocessor list. A row change is one that stays inside the words the body already defines, adds no new kind of data reaching us, no new purpose and no new recipient, and makes no promise weaker. Anything else is a body change, and a body change that affects your rights or choices is material. When a version number goes up we tell account holders by email or by a notice inside the Product at least 30 days before it takes effect, saying what is changing and why, so you have time to object, export your data or close your account. Where a change needs your agreement, we ask for it rather than assuming it. The version a change replaces is kept in our archive, with the dates it was in force, at https://cutvey.com/legal/archive. We record what you accepted: which document, which version number, and when, against your account on the web and on the device in an App. An App asks you again when the version number of a document it shows you has gone up. It does not ask you again when only the date has moved.

When this policy, or a document it references, changes, the version it replaces will be kept at https://cutvey.com/legal/archive.

21. Contact

Email: [email protected]. Privacy requests, questions, complaints and appeals all go here, and reach a person.

Post: Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA.

In the EEA, the UK or Switzerland, section 17.1 says how to reach us.

We give the name of the person holding any of these offices to a regulator or to a data subject who asks for it at [email protected].

Referenced documents that form part of this policy: the Cookie Notice (https://cutvey.com/legal/cookies), the Subprocessor List (https://cutvey.com/legal/subprocessors), and, for business customers, the Data Processing Addendum (https://cutvey.com/legal/dpa).