This policy is written to be read. If you only want one paragraph: we do not sell or rent your personal information to anyone, and we do not run advertising. We do not track you across other companies' sites or apps. Our products are paid for with money rather than with data, and much of what our software does happens on your own device or inside your own workspace. One thing we do measure, because our customers ask for it: when a studio sends a proposal or an invoice through Cutvey, that studio can see whether its client opened it. Section 10 explains that, and the result belongs to the studio, not to us.
On this page: who we are (1), what this covers (2), our role (3), what each product touches (4), what we collect (5), why, and our legal bases (6), AI (7), analytics and crash reports (8), cookies (9), email and messaging (10), sharing (11), international transfers (12), retention (13), security (14), children (15), your rights (16), regional information (17), privacy signals (18 and 19), changes (20), contact (21).
Cutvey LLC is a Florida limited liability company. Our registered and notice address is Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA. Our principal place of business is Orlando, Florida, USA. In this policy, "Cutvey", "we", "us" and "our" mean Cutvey LLC.
For privacy questions, requests and complaints: [email protected], or write to us at the address above. One address reaches a person for everything: support, privacy, legal and copyright. If you are in the European Economic Area, the United Kingdom or Switzerland, contact us at the same address: we have not yet appointed a local representative, and section 17.1 explains why and what it does not affect.
This policy covers the Cutvey products and websites in the table below. We keep it as a single document on purpose, so that adding a product does not mean publishing a new policy. Products are described in the tables, not in the body.
| Family | What it is | Examples |
|---|---|---|
| The Service | The Cutvey software-as-a-service platform: the web app, workspace custom domains pointed at it, the client and crew portals reached by link, our APIs and integrations, and our companion app for iPhone, iPad and Mac (same account, same data) | Cutvey SaaS, Cutvey companion app |
| The Apps | Our standalone native applications for macOS, iOS and iPadOS, bought once and run mainly on your own device. Some of them can also sign in to your Cutvey account, and when they do, the data they sync is Service data | Cutvey Offload (Mac), Cutvey Offload for iOS, Cutvey Meter, Cutvey Viewfinder, Cutvey Teleprompter, and any future Cutvey app |
| The Sites | Our marketing and product websites, and the emails we send from them | cutvey.com, cutveyoffload.com, and future product sites |
Where a rule applies to only one family, we say which one. Otherwise, read a rule as applying to all of them. Where we say "Products" we mean all of them.
If we ever acquire or launch something that works differently, we will either add it here or publish a separate notice for it and link it from this page.
This policy does not cover:
Privacy law separates the party that decides why data is processed (the "controller", or "business" in some US laws) from the party that processes data on someone else's instructions (the "processor", or "service provider").
We are the controller for:
We are a processor for the content a business customer puts into its Cutvey workspace about other people: its clients, leads, crew, talent, vendors and contacts. The customer is the controller of that data. It decides what to collect, why, how long to keep it, and whether it has the right to collect it. We act on that customer's instructions and on what the product's features do.
If you are a one-person company, both apply to you. We are the controller for you: your account, your billing, your sign-ins. We are the processor for everyone else in your workspace: your clients, your crew, your talent. You decide what happens to their details, and we act on your instructions.
Where we act for ourselves on the same systems. Even while we act as a processor for a customer's workspace, we are the controller of a narrow set of data we generate by running the service. That set is: security and request logs, abuse and fraud signals, usage statistics that are not linked to an individual, and billing records. This includes measuring how our own pages perform on the portal, review and gallery pages a studio's clients and crew see. We use that only to operate, secure, support and bill for the Products. We do not use it to build a profile of anyone. It never touches the content of the documents, comments, files or messages in a workspace, which we handle only on the customer's instructions. Everything in section 8 applies to that measurement.
If you are a client, crew member or talent of a studio that uses Cutvey, the studio is your first point of contact. If you send us a request about the studio's records, we will tell you who the studio is and how to reach them. With your agreement we will pass your request to them and help them answer it. We will not act on it ourselves, because the studio decides what happens to its records.
Our processor commitments to business customers, including the required processing terms and the transfer clauses in section 12, are in our Data Processing Addendum (DPA) at https://cutvey.com/legal/dpa. The DPA controls over this policy for the data we process on a customer's behalf.
This is the table to read if you want to know what a specific product does with data. New products get a new row here, not a new policy. "Sent to Cutvey" means data that reaches our servers.
Four things are true of every App, present and future, so we state them once rather than in every row. First, every App can store your own content in your own private iCloud database if you turn iCloud on. That content is held by Apple in your Apple Account, where we cannot read it. Second, every App can send us usage data and crash reports, and every App gives you one switch for them: they are on by default where the law allows a default, and in the European Economic Area, the United Kingdom, Switzerland and anywhere else whose law requires your agreement first, the App asks you on first run and collects nothing until you say yes. Wherever you are, you can change your answer in the App's Settings. Section 8 has the detail. Third, an App may sync with your Cutvey account when you sign in to it. From that point, the data it syncs is Service data: section 3 decides whether we are controller or processor for it, and section 13 sets how long we keep it. Fourth, no App sends your footage, stills or recordings to us unless its row in this table says it does. Where an App moves media between your own devices, the table says whether that traffic passes through a Cutvey server, and if it does, what we can see and how long we hold it, which today is nothing and no time.
Push notifications. If you allow them, our apps send push notifications through Apple's service. To do that we hold a device token that identifies the device, not you, and we delete it when you turn notifications off, sign out or remove the device. A notification can carry the subject of the thing it is about, for example a client name, a document title or an invoice amount, which may be visible on a locked screen. Turn them off, or hide previews, in your device settings, or turn off individual notification types in Cutvey Settings.
We ask for a device permission at or shortly before the point where the feature that needs it is set up or first used, and never for a feature you have not opened. You can refuse or revoke any permission in your operating system settings. The feature that needs it stops working, and the rest of the app carries on.
| Product | On your device | In your iCloud | Sent to Cutvey | Device permissions used |
|---|---|---|---|---|
| Cutvey Service (web) | Session cookie, local cache of what you are working on | None: your data lives in your workspace on our servers | Everything you enter or upload into your workspace, plus account, billing, security and usage data (sections 5 and 8). This includes the coordinates of a shoot when a call sheet shows weather, which go to our weather provider with nothing that identifies you | Browser only (file picker, and notifications if you allow them) |
| Cutvey companion app (iPhone/iPad/Mac) | Sign-in token, trusted-device record, local cache | Its own app settings, if you turn iCloud on | Same as the Service: this app is a window onto the same account and the same workspace, plus crash reports and usage data (section 8) | Notifications (optional), camera and photo library only if you attach or capture media |
| Cutvey Offload (Mac) | Everything by default: job history, checksums, logs, settings and your footage. Safe Erase can permanently erase a camera card once a copy is verified, and that cannot be undone | Its own settings and job history, if you turn iCloud on | Sign-in and entitlement checks, update checks, crash reports (section 8; Offload collects no usage data), and any workspace data you sync after signing in. Your footage is never sent to us | Full disk and removable-volume access, so it can read a camera card and write to your drives. macOS calls this Full Disk Access, and it is the same permission every backup tool asks for. Local network only if you use a network destination |
| Cutvey Offload for iOS | Job status received from your paired Mac, pairing record, settings | Its own settings and pairing, if you turn iCloud on | Sign-in and entitlement checks, crash reports and usage data (section 8). Job status is exchanged with your own Mac | Local network (to find your Mac), notifications (optional) |
| Cutvey Meter (universal) | Saved readings, settings | Your readings, if you turn iCloud on | Sign-in and entitlement checks, crash reports and usage data (section 8). Your readings, your camera images and your location are not sent to us | Camera (color measurement), location (sun position and golden hour), motion sensors (device orientation). Camera images and location stay on the device |
| Cutvey Viewfinder (universal) | Saved setups, framing presets, images you export | Your setups, if you turn iCloud on | Sign-in and entitlement checks, crash reports and usage data (section 8). If we add Cutvey project sync to this app, this row will say so before it ships | Camera (live viewfinder), photo library (only to save what you export) |
| Cutvey Teleprompter (universal) | Your scripts, settings | Your scripts, if you turn iCloud on | Sign-in and entitlement checks, crash reports and usage data (section 8). If you sign in, the scripts you pull from and save back to your Cutvey projects are workspace data, covered by section 3 | Microphone, only while voice-paced scrolling is turned on (optional, off by default). The audio is analyzed on your device to follow your place in the script. It is never recorded, never stored, and never sent to us or anyone else for any processing |
| Future Cutvey apps | Documented in this table before or at launch | Same | Same | Same |
| The Sites | Nothing beyond what your browser needs. No advertising or third-party analytics cookies | None | What you type into a contact, support or lead form, plus the bot-protection check that guards it | None |
What "sign-in and entitlement checks" means. When you sign in to an App with your Cutvey account, the App sends us your email address, the one-time code we emailed you, and the name, model and operating system version of the device. We use that to sign you in, count the device against your plan's activations, and send back a token that keeps the App unlocked. That is all a check is. It is not a report on what you did in the App.
When you buy an App from Apple instead, nothing is sent to us. The App checks the purchase with Apple on the device, and it keeps working with no Cutvey account and no connection to us at all. Optional usage data and crash reports still follow section 8, whichever way the App was unlocked.
iCloud is yours, not ours. When an App syncs through iCloud it writes to your private CloudKit database in your own Apple Account. Apple holds it, under Apple's terms and Apple's privacy policy. We cannot read it, and we cannot recover it for you. Deleting a record in the App deletes it in both places. Deleting the App removes the device copy but does not remove what is already in your iCloud. To clear that, delete the records in the App first, or manage the app's iCloud data in your Apple Account settings.
Some of our apps can delete your files permanently, on purpose. Where an App offers a destructive action, such as erasing a camera card after a verified copy, it happens only because you asked for it. We never trigger it, we never see the media, and we cannot recover anything erased. The table says which App can do this.
We collect these categories. Not every category applies to every product: use the table in section 4 to see which.
| Category | Examples | Where it comes from |
|---|---|---|
| Identifiers and account data | Name, email address, company name, role, optional photo and phone number, workspace and user identifiers | You, when you sign up or are invited |
| Authentication data | One-time sign-in codes (stored hashed and briefly), session tokens, optional two-factor secret, trusted-device records, single sign-on identifiers for Enterprise seats | You and your device |
| Device and installation data | Device name and model, operating system version, app version, an installation or trusted-device identifier, a push notification token if you allow notifications, and the number of devices counted against an activation | Your device, when you sign in to or unlock an App |
| Customer content | Everything a workspace puts into Cutvey: leads, contacts, proposals and contracts, projects, crew records and call sheets, video files and review comments, invoices, documents, galleries, messages, templates | Our business customers (we are processor: section 3) |
| Commercial and billing data | Plan, subscription status, billing cycle, invoice history, payment-provider customer and subscription identifiers, App purchase and entitlement records, activation counts | You, and our payment provider or Apple |
| E-signature audit records | Signer name and email, signature image, timestamp, IP address | The signing process, as electronic signature law requires |
| Technical and security logs | IP address, browser or app version, operating system, request paths and timestamps, error traces, rate-limit and abuse signals | Automatically, when you use a Product |
| Usage data and crash reports | Which features are used and how often, performance timings, crash reports, the kind of device you use, OS version, app version, and the country you are in and nothing more precise. Section 8 sets stricter rules for this category than for the rest | Automatically, on the terms in section 8 |
| Email engagement data | Delivery, bounce, open and link-click events for messages sent through the platform. For a studio's own outgoing mail this is customer content and a product feature (section 10) | Our email infrastructure |
| Communications with us | Support emails, contact and sales form submissions, feedback and bug reports | You |
| Location | Coordinates, used only by a feature that needs them. In the Apps, location stays on the device. In the Service, the coordinates of a shoot location go to our weather provider so a call sheet can show a forecast, with no name or account attached | Your device with your permission, or the address you typed |
Card details. Card numbers are entered directly into our payment provider and are not sent to us. We see the last four digits, the card brand and the expiry. If you send us a card number by email we will delete it and ask you to use the payment page instead.
Biometrics. We do not collect, store, transmit or use a face scan, faceprint, fingerprint, voiceprint, retina or iris scan, hand or face geometry, or any other biometric identifier or biometric information, as those terms are used in the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act and Washington's biometric privacy law. No biometric identifier of any kind reaches our servers, from any product.
Some of our apps use your device's camera or its spatial sensors, and some features work by recognizing shapes: composing an image, measuring light, mapping a room, tracking where a device is in space, or grouping photographs that look like they show the same person. Where a feature does anything of that kind, three things are always true. It runs on your device. The result is not stored as a biometric template, and it is deleted when the feature closes or the grouping is cleared. And nothing derived from it is sent to us. The product table in section 4 says which apps use which sensors, and it names any feature that recognizes a person.
If your device offers Face ID, Touch ID or a fingerprint unlock as a way into an App, that check is performed by Apple on your device. We receive only a yes or a no from the operating system, never your face or fingerprint data.
If a future product ever needs to collect, store or transmit a biometric identifier, we will publish a separate written notice, obtain your written consent, and publish a retention and destruction schedule before collecting anything. We will update this policy before any of this stops being true.
No session recording. We do not use session replay, keystroke logging, mouse or scroll recording, capture of form fields before you submit them, or any comparable technology, in any Product. We do not embed any third-party script that does. Our logs record which page or endpoint was requested and when, not what you typed or where you moved your pointer.
Sensitive data. We do not ask you for health data, racial or ethnic origin, religious beliefs, union membership, sexual orientation, or data about criminal matters, and we do not want any of it for our own purposes.
Your own paperwork is a different matter. Releases, crew documents and contracts sometimes contain details like these, and Cutvey is built to hold them. Ordinary production administration also includes contractor tax forms, so a taxpayer identification number can appear in a crew record or an uploaded document, and we do not pretend otherwise. When you put any of this in, you are the controller: it is your legal basis, your consent to obtain, and your responsibility to have the right to hold it. Meeting any state law that governs how a taxpayer identification number is stored is yours as well. We store it, we secure it with the same measures we apply to everything else in your workspace, and we do not read it or use it for anything of our own. We never use or disclose sensitive personal information for any purpose that would give someone an opt-out right under California law.
Health and education records. We are not a HIPAA business associate, we do not sign business associate agreements, and the Service is not designed to hold protected health information or student education records. Where a shoot for a healthcare or education client captures identifiable people, the consent, the authorization and the limits on use are your client's and yours. Keep material governed by those rules out of a Cutvey workspace, or hold only what the authorization you obtained permits.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in US state privacy laws. We have not done so in the preceding twelve months. There is no third-party advertising in any Cutvey product, and no data broker receives anything from us.
When your data reaches us from someone else. Sometimes we hold data about you that you did not give us directly. Most often a colleague invited you to a workspace and gave us your name and email address so we could send the invitation. In that case we hold your name, email address and the role you were invited into. We got it from the person or organization that invited you, and we use it to send the invitation and to run your seat if you accept. We tell you this in the invitation itself, and in any case within one month. Everything in section 16 applies, including your right to object and to have the data deleted if you do not want the seat.
For people in the EEA, the UK and Switzerland, the "legal basis" column is the GDPR basis we rely on. Elsewhere, read the purpose column.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Provide the Products, run your workspace, sync your account, deliver what you asked for | Account, authentication, device, customer content, technical | Performance of a contract (Art. 6(1)(b)) |
| Verify a purchase or entitlement, count activations, enforce plan limits | Account, commercial, device | Contract (Art. 6(1)(b)) |
| Take payment, invoice and collect | Account, commercial | Contract (Art. 6(1)(b)), and legal obligation for tax records (Art. 6(1)(c)) |
| Send transactional and service email (sign-in codes, receipts, call sheets, notifications, security alerts) | Account, technical | Contract (Art. 6(1)(b)) |
| Secure the Products: authentication, rate limiting, bot protection, fraud and abuse detection, incident investigation | Authentication, device, technical, security logs | Our legitimate interest in keeping a service safe for the people who pay for it and for the people whose data is in it (Art. 6(1)(f)), and legal obligation where breach law applies (Art. 6(1)(c)) |
| Support you when you ask for help | Communications, account, and the minimum content needed to answer | Contract (Art. 6(1)(b)), and legitimate interests (Art. 6(1)(f)) |
| Know which parts of our own software are used, and where it breaks, so a small team spends its time on what matters | Usage data and crash reports (section 8) | Consent (Art. 6(1)(a)) in the Apps everywhere, and in the Service wherever collecting it means storing or reading anything on your device. Otherwise our legitimate interest in understanding our own product (Art. 6(1)(f)) |
| Operate, meter and bill the Service accurately, which means counting some activity against your account | Account, commercial, usage tied to the account | Contract (Art. 6(1)(b)) |
| Run AI features you invoke | The text or data you point the feature at | Contract (Art. 6(1)(b)) |
| Keep an electronic signature audit trail | E-signature audit records | Our legitimate interest, and the interest of everyone who signed, in keeping a signed document provable and enforceable (Art. 6(1)(f)), and contract where you are our customer (Art. 6(1)(b)) |
| Market our own products to our own users and subscribers | Account, email address, marketing preferences | Consent (Art. 6(1)(a)) where the law requires opt-in. Otherwise our legitimate interest in telling our own paying customers about products of the kind they already bought (Art. 6(1)(f)), relied on only where you were offered the chance to refuse when we took your address and in every message since |
| Measure whether our own announcements are read | Email address, open and click events | Consent (Art. 6(1)(a)) where consent is required for that measurement, including in the EEA and the UK. Where you have not consented, we send the message without open measurement |
| Comply with law, respond to lawful requests, establish or defend legal claims | Whatever the request or claim requires | Legal obligation (Art. 6(1)(c)), and legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have carried out a balancing assessment, weighing what we gain against what it costs you. In each case we concluded the processing is limited to what we need and is what you would expect from a company you pay for software. You can ask us for a summary of any of those assessments at [email protected] and we will send it. You can also object: see section 16.
Providing account and billing data is necessary to have an account. If you do not provide it, we cannot give you one. Everything marked optional in the Products is optional.
Some parts of the Service, and any App whose row in the section 4 table says so, can draft, summarize or reorganize text for you.
We want to know which features people actually use, and where our software breaks, so that we build and fix the right things. We do not want to know what any particular person is doing.
Two kinds of data in the Apps. Every Cutvey app sends two kinds of data, and it is important to know which is which.
Required service data is the minimum needed to provide what you bought and to keep the software honest: checking and counting your license or activation, checking for updates, telling our servers the app and system version so the right answer comes back, preventing abuse and fraud, and anything needed to make a feature you use work (for example syncing with your Cutvey account when you sign in). This has no switch, because without it the App cannot do its job. It carries no usage statistics and no crash reports.
Optional usage data and crash reports is what this section is about: which features you use and how often, performance, and what went wrong when something crashed. It is on by default wherever the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, and any other place whose law requires your agreement before an app reads or stores this kind of information on your device, the App asks you on first run and sends nothing until you say yes. Saying no is exactly as easy as saying yes, there is no pre-ticked box, and nothing about the App changes if you decline.
The switch does what it says. Every App has a single switch in its Settings for optional usage data and crash reports (some Apps collect crash reports only; the table in section 4 says which). Off means off: from that moment the App sends no usage statistics and no crash reports, anywhere in the world. It does not turn off required service data, and the screen says so.
In the Service, some measurement is how the product works. We record activity tied to your account where that is how we operate the Service, meter your plan allowances, count activations, bill you correctly, or detect and stop abuse and fraud. That is part of running your subscription, and it is described in section 6. Beyond that, we collect general usage data about our own web pages, which is not linked to your account. Measuring the web app may one day require us to store or read something on your device that is not necessary for the service you asked for. If that happens, we ask for your consent first in the European Economic Area, the United Kingdom and Switzerland, and you can withdraw it.
What a usage record contains. Which features were used and how often, performance timings, the kind of device you use (for example a recent iPhone, not its serial number), the operating system version, the app version, and the country you are in and nothing more precise.
What a crash report contains. Technical state: the app version, the operating system version, the kind of device, the operation that failed, how much memory was free, and the stack trace. A crash report carries no footage, no scripts, no readings and no Cutvey account details. Where a report contains a file path, we remove everything under your home folder and everything under a mounted volume, including the volume's own name. Only the system paths needed to identify the fault remain.
We design and filter these reports so that they do not carry your content, and we remove account names, volume names and access tokens on the paths we control. We cannot promise that a piece of personal data will never appear inside the text of an error message written by software. Where one does, we treat that report as your data and handle it under this policy and, for a business customer's workspace, under our Data Processing Addendum.
Where reports go. Crash reports from the Apps, and error reports from the Service, go to the crash and error reporting provider named on our subprocessor list and, where a product supports it, to our own servers. That provider is contractually limited to providing the service to us and may not use the reports for its own purposes. If we add or change a provider for analytics, crash reporting or error reporting, it goes on the subprocessor list before it receives anything, under the advance-notice process on that page.
Apple's own crash sharing is separate. Your iPhone, iPad or Mac can share crash information with app developers through Apple's own channel. Apple asks you for that when you set up your device, Apple decides what it contains, and you turn it on or off in your device settings under Privacy and Security, not in ours. We see only what you have allowed Apple to share.
Keeping identity out of it. Usage and crash records carry no name, email address, account id or workspace id, and we do not try to link them to you. Sign-in, activation counting and billing are separate systems that do know who you are, and they are described in sections 5 and 6. We do not claim these records could never be re-identified by someone determined to try. We claim that we do not try, we do not permit a provider to try, and we do not join them to your account record.
Our commitment on data that is not linked to you. Where we hold usage data that is not linked to an account, we take reasonable measures to keep it that way, we use and keep it only in that form, we do not attempt to re-identify it, and we contractually prohibit any provider who touches it from attempting to re-identify it. We make this commitment publicly so that you can hold us to it.
No third-party tracking. We do not embed advertising SDKs, attribution SDKs or cross-site or cross-app tracking technology in any Product, and we do not track you across other companies' apps or websites. Some Products include a component from a service provider to deliver crash reports or diagnostics. That provider is on our subprocessor list, is contractually limited to providing that service to us, and receives nothing that identifies you. That is why our Apps do not show an App Tracking Transparency prompt: the permission we ask for is about improving our own software, not about following you anywhere else.
Short version: the app uses only what it needs to keep you signed in, and the Sites set nothing for advertising or third-party analytics.
The detail, category by category, is in our Cookie Notice, which is part of this policy: https://cutvey.com/legal/cookies.
Transactional and service email (sign-in codes, receipts, invoices, call sheets, notifications, security alerts) is part of the Products. You cannot unsubscribe from it while you have an account: a sign-in code you did not receive is an account you cannot open. Closing your account stops everything.
Our marketing email goes only to our own users and to people who asked for it, and is only ever about Cutvey products and features. We do not send other companies' offers, and we never rent, sell or share our list. Every marketing message identifies Cutvey LLC as the sender and carries our mailing address and contact details, valid for at least 60 days after we send it. Every message carries an unsubscribe link and a one-click unsubscribe, working for at least 60 days. We action an unsubscribe immediately in practice, and within 10 business days at the outside.
Where local law requires opt-in consent before commercial email, we obtain it. In some places the law instead lets us email an existing customer without asking again. We rely on that only in three conditions: the message is about products of the kind you already have, you were offered the chance to refuse when we took your address, and the relationship is recent enough for that law to allow it. In Canada that means 24 months from your last purchase or contract, and 6 months from an enquiry you made.
Our own announcements measure opens and clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So in the European Economic Area, the United Kingdom and Switzerland we ask for your agreement to that measurement when you subscribe, and we do not measure opens for anyone who has not agreed. You can withdraw at any time. Sign-in codes, receipts and other service email carry no measurement pixel at all.
Email a studio sends through the Service. A proposal, invoice, call sheet or gallery link that a studio sends to its own client can carry a small tracking image and click-tracked links, so the studio can see whether the client opened it. Here is how responsibility divides:
Telephone and text messages. We do not call you, we do not send you SMS or text messages, and we do not use an autodialer or prerecorded messages. A phone number you give us is used only to reach you about your account if you ask us to. A phone number a studio puts on a call sheet is that studio's data, used by that studio. If we ever add text messaging, it will be opt-in, the opt-in will be separate from signing up, and STOP will end it.
We do not sell data. We share it in these situations and no others.
Subprocessors and service providers. A short list of vendors who run part of our infrastructure. Each is engaged under written terms that limit it to providing its service to us, with confidentiality and security obligations. None is an advertising network or data broker, and none may use the data for advertising. The current list, with what each one does and where it processes data, is at https://cutvey.com/legal/subprocessors and is part of this policy. That page also names the two companies that additionally act on their own account rather than only on ours, and says how we notify customers of changes.
Inside a workspace. Content in a workspace is visible to the members and invitees that the workspace authorizes, according to the roles and sharing links it configures. If you are a member of someone's workspace, the owner and administrators can see your activity in it.
Video viewing. When you watch a video in a review link, a gallery or a portal, that activity is recorded inside the workspace that sent it to you. That is so the studio can see whether its work was reviewed. We do not disclose video viewing records to any advertiser, analytics network, social platform or data broker, and we do not embed a third-party pixel, tag or SDK on a page where a video plays. The studio that sent you the link decides what it does with that record, and it is the studio to ask about it. We treat video viewing records as customer content under section 3.
At your direction. When you send a proposal, publish a review link, share a gallery or connect an integration, the data goes where you sent it.
Legal process and safety. We require valid legal process. We review each request, and where we believe a request is overly broad, defective or unlawful we object to it or ask for it to be narrowed. We cannot promise to litigate every request, and we comply where we are legally obliged to. We also disclose where we believe in good faith that disclosure is necessary to protect the rights, property or safety of Cutvey, our users or the public, or to establish or defend legal claims. We notify the affected user before we produce anything, where we are lawfully able to do so and are not subject to an order forbidding it, so that the user can object. Where a bar on telling you lifts, we tell you then.
Subpoenas and civil cases. United States federal law, 18 U.S.C. 2702(a), prohibits us from disclosing the contents of a customer's files and communications to a private party in a civil case. That includes a civil subpoena, and we will not do it. If a private party wants the contents of a workspace, they must get them from the business that holds it, not from us. Where a civil subpoena seeks only basic account records, we tell the affected customer first and give them a reasonable chance to object, unless a court orders otherwise.
Requests from outside the United States. We are a United States company and our data is in the United States. A request from an authority elsewhere reaches us through United States legal process, through a mutual legal assistance treaty, or through an agreement the United States has entered into. We do not respond directly to a foreign authority's demand.
Preservation. A letter from a private party demanding that we preserve something is not legal process. We forward it to the customer concerned and take no other action. We honor a preservation request from a governmental entity under 18 U.S.C. 2703(f), and a written instruction from the customer, for the period the request or the instruction covers and no longer, and we tell the customer where we are permitted to.
How to send us a request. Law enforcement and other authorities should email [email protected] with "Legal request" in the subject, from an official address, attaching the process and naming the account by email address or workspace name. We require valid process for content, and a subpoena or equivalent for account records. We may charge our reasonable costs of responding where the law allows it. We do not publish a periodic transparency report. We keep a record of the requests we receive and, so far as the law allows, we will tell a customer on request whether we have received one about them.
Business transfers. If Cutvey is involved in a merger, acquisition, financing or sale of assets, data may be transferred as part of that transaction. We will require the receiving party to continue handling it under this policy or a policy at least as protective. We will give account holders notice, and a chance to export and delete, before their data becomes subject to a materially different policy.
Professional advisers. Our lawyers, accountants, auditors and insurers, under duties of confidentiality, where they need it.
With your consent, for anything else.
We process data in the United States. Our servers are in the USA, and that is where your workspace lives. If you use a Product from anywhere else, your data is transferred to and processed in the United States. The United States may have different data protection rules from your own country, and its public authorities may in some circumstances seek access to data. We reduce that risk with the measures in section 14, by challenging requests we consider overbroad or defective, and by telling you where we lawfully can. A small number of the providers on our subprocessor list operate elsewhere or globally, and that page says which and where.
Transfer mechanism. For personal data protected by EEA, UK or Swiss law we rely on the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914).
We have carried out a transfer impact assessment covering United States law, our exposure to it, and the extra technical and contractual safeguards we apply. You can ask us for a copy of the clauses, and a summary of that assessment, at [email protected].
We do not claim certification under the EU-US, UK Extension or Swiss-US Data Privacy Framework. If we certify in the future, we will say so here and on the Department of Commerce list, not by implication.
We keep personal data only as long as we need it for the purpose we collected it for, plus any period the law requires.
Read this one before you cancel. If you cancel, or a trial ends, we keep your workspace for 60 days so you can come back or export, and then we delete it. We email you before that happens. Export your data first: Settings, then Export, gets you everything at any time, including after you have canceled and while the 60 days are running.
| Data | Retention |
|---|---|
| Workspace content and account data (active subscription) | While the account is active |
| Workspace content and account data (after cancellation or trial expiry) | 60 days, with reminder emails before deletion, so you can reactivate or export. After that we delete it, and it ages out of backups within a further 30 days |
| Self-serve workspace deletion | 7-day cooling-off period after email-confirmed deletion, then workspace data is permanently erased |
| Individual client, lead, crew or talent record deleted with our per-record erasure tool | Erased on request from the workspace, then ages out of backups |
| Backups | Rolling schedule, up to 30 days, after which deleted data is gone from backups too |
| Sign-in codes | Hashed, valid for minutes, deleted after use or expiry |
| Sessions and trusted devices | Until you sign out, revoke the device, or the session expires |
| Technical and security logs | Up to 90 days. We keep them longer only where a specific open security investigation needs the records, where we are required to preserve them by law or by a preservation request we must honor, or where they are needed to establish or defend a legal claim, and then only the records concerned and only for as long as the reason lasts |
| Usage data not linked to an account | Kept in aggregated form for as long as it is useful for product decisions. Individual event records are deleted or aggregated within 12 months |
| Usage data tied to your account (where section 8 permits it) | Up to 12 months, or until you withdraw consent, whichever is sooner |
| Crash reports | Up to 12 months from the crash |
| E-signature audit records | For as long as the workspace that holds them exists, and in no event more than 12 years from signature. They are deleted when the workspace is deleted, because the record lives inside the workspace. Download your copy of anything you sign, and its signing record, at the time you sign, and do not rely on us as your archive. We email a copy to every signer when a document is completed. Where a legal hold applies, we keep only the record it names, and only for as long as the hold lasts |
| Billing, invoice and tax records | 7 years, as US tax and accounting rules require |
| Support and other correspondence | Up to 24 months from the last message in the thread |
| Marketing contacts | Until you unsubscribe |
| Unsubscribe and suppression records | Kept permanently, because keeping a record of your objection is the only way to honor it, and Article 21(3) of the GDPR requires us to |
| App license and entitlement records | For the life of the license, and afterwards as long as needed for accounting and abuse prevention |
| Contact, support and lead form submissions on our own sites | Up to 24 months from the last message, then deleted |
| Video and document viewing records inside a workspace | Customer content: kept while the workspace keeps them, deleted with the workspace or when the customer deletes the record |
Where we cannot delete something immediately, because it sits in a backup, we isolate it and delete it when the backup ages out.
Two things pause these clocks. If we receive valid legal process, or a written notice from someone with a genuine claim that identifies specific material and the proceeding it relates to, we may place that material on legal hold. Material on hold is left out of workspace deletion, out of the periods in this table and out of the ordinary backup expiry, and is kept only for as long as the hold requires.
Separately, we place a workspace on a bereavement hold if we are told in writing that a sole account owner has died or has lost capacity, and the claim is credible on its face. Billing, suspension and the deletion clock all stop for up to 12 months, while an executor or a court-appointed person proves their authority, and we extend the hold if we are told that probate or a guardianship is still running. Then the ordinary rules resume. Nobody gets access during either kind of hold.
These are the security measures we maintain:
Support access is visible in the Service. If our support staff use the in-product support access feature to view your workspace, that is recorded in your audit log and shown to you with an on-screen banner while it is happening. Separately, a small number of people have administrative access to the underlying servers and database, which is necessary to operate and repair the service. That access is not surfaced as a banner, and we use it only to operate, secure and repair the Products.
That administrative access is logged on the server, is granted individually rather than through a shared credential, is limited to the people who need it, and is removed when the need ends. We do not use it to read a workspace's content in the ordinary course, and where we ever have to, we record why.
Security is a moving target and we improve these measures over time. This list describes our practices. It is not a warranty that any particular measure will prevent every attack.
We do not currently hold a security certification such as SOC 2. If we earn one, we will name it here. Until then, take the list above as the whole of what we claim.
No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant regulators as and when the law requires, including Florida's Information Protection Act (Fla. Stat. 501.171), the GDPR's 72-hour regulator deadline where it applies, and the corresponding laws elsewhere. Where we are a processor, we notify the customer without undue delay, meaning as fast as we reasonably can, within the deadline set by our Data Processing Addendum and within any deadline the law sets, so it can meet its own.
No Cutvey product is directed at children, and none is designed to appeal to them. None of our Apps is offered in the App Store Kids Category.
We do not knowingly collect personal data from anyone below these ages. If we learn we have, we delete it promptly and close the account. A parent or guardian who believes a child has given us data should email [email protected] and we will act, without asking them to prove anything burdensome.
A studio may use Cutvey to handle a release, a booking or a call sheet involving a minor. If so, the studio is the controller and the parent or guardian is the person who consents and signs. The studio is responsible for collecting that data lawfully, and for any parental consent its law requires. We process it only on the studio's instructions and never for a purpose of our own.
Where the law gives you these rights, we honor them. Where it does not, our practice is to honor a request anyway if we can do so without breaking a legal obligation, without affecting someone else's rights, and without unreasonable effort. Requests about a business customer's workspace records are handled as described at the end of this section.
Automated decisions, and getting a person. We do not profile you, and we make no automated decisions about you for marketing or pricing. Two things we do are automatic and can matter to you. If a payment fails, your subscription is suspended and eventually canceled by the system after the reminders we send. If our security systems see a strong signal of abuse or fraud, access can be blocked automatically while we look at it. Both are necessary to run the contract between us and to keep the Products safe. In either case, email [email protected]: a person will look at it, you can put your side of it, and we will reverse it if it was wrong. We will not leave an account suspended on an automated signal alone once you have asked us to look.
How to exercise your rights, fastest first:
If you only bought an App from Apple, there is nothing for us to delete. Buying the one-time unlock through Apple does not create a Cutvey account. You give us no email address and no name, we hold no record of you, and there is no account for you to close. Your content stays on your device and, if you turned sync on, in your own iCloud, where you delete it in the App or in your Apple Account. Apple holds its own record of your purchase under Apple's privacy policy, and only Apple can act on that.
Deleting an App is not deleting your account. Removing an App from your device leaves your Cutvey account exactly as it was, if you have one. Signing out, or removing a device, only frees an activation.
Deleting a seat is not deleting a workspace. If you were invited into someone else's workspace, deleting your Cutvey account removes you and your personal account data, and removes you from that workspace. It does not delete the studio's workspace or the records the studio holds, which belong to the studio as controller. If you own a workspace, deleting your account reaches full workspace deletion, and we tell you that clearly before you confirm.
What happens next. We aim to acknowledge within five business days. We respond within 45 days (US state laws), extendable once by a further 45 days where the request is complex, and within one month under the GDPR, extendable by two months for complex requests. We tell you if we need an extension and why. Unless you ask for something else, we answer electronically, to the address you wrote from, and we give any copy of your data in a structured, commonly used, machine-readable format.
Another format. If you need this policy, or any answer we give you, in another format, tell us and we will provide it.
Requests are free. The law allows us one exception, and we expect never to use it: a repetitive or excessive request, for example the same request sent over and over. There we may charge a reasonable fee, or decline and explain why.
Verifying who you are. We verify your identity before acting, in proportion to the sensitivity of the request. Usually that means responding from the email address on the account, or completing a sign-in. We will not ask you for a government identity document, a photo of yourself or a financial account number to verify a privacy request. If we genuinely cannot verify you any other way, and acting would hand over someone's data, we will explain what we would need and offer you another route rather than guessing.
Authorized agents. You may use an authorized agent, including under California law, to make a request for you. We will ask for written proof that you authorized them, and we may ask you to confirm directly. An agent acting under a signed power of attorney does not need the extra confirmation.
Appeals. If we refuse your request, we tell you why and how to appeal. Reply to our decision, or email [email protected] with "Privacy appeal" in the subject. We review and respond in writing within 45 days with our decision and our reasons. If we still say no, we tell you how to complain to your regulator. This appeal route is open to everyone, not only residents of the states that require it.
Complaints. You can always complain to your data protection authority or attorney general. In the EEA that is the supervisory authority where you live, work or where the issue arose. In the UK it is the Information Commissioner's Office (ico.org.uk). In Switzerland it is the Federal Data Protection and Information Commissioner. You also have the right to go to court. In the EEA and the UK that means an effective judicial remedy against us and against your supervisory authority, plus compensation for damage caused by a breach of the rules. We would rather you told us first, but you do not have to, and coming to us first costs you none of these rights.
If you are a studio's client or crew. Send your request to the studio. If you send it to us, we will tell you who the studio is and how to reach them, and with your agreement we will pass it on and help them answer it.
This section adds region-specific detail. Everything above still applies.
Under the California Consumer Privacy Act as amended by the CPRA:
Residents of any US state with a comprehensive consumer privacy law in force have the rights described in section 16, exercised the same way, with the same 45-day response window and the same appeal route. That currently includes Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Delaware and a growing list of others. We do not wait for your state to pass a law before honoring a reasonable request. Specifically:
Florida. We are a Florida company. Florida residents have the rights in section 16, exercised the same way, and we honor them whether or not a particular Florida statute obliges us to. Note that the Florida Digital Bill of Rights places its main obligations on companies far larger than us. You can contact the Florida Attorney General's office if you are not satisfied with our response.
Nevada. Nevada law (NRS 603A.340) lets residents tell a covered operator not to sell their covered information for money. We do not sell covered information. If you want to send the request anyway, email [email protected] and we will confirm.
Washington and Nevada health data laws. We do not collect consumer health data, and no Cutvey product is a health app.
We handle personal information in line with PIPEDA and, for Quebec residents, Quebec's Law 25:
Under the Lei Geral de Protecao de Dados (LGPD) you have the rights to:
Our legal bases (Art. 7). Execution of a contract you are party to and preliminary steps at your request (Art. 7, VI), compliance with a legal or regulatory obligation (Art. 7, II), our legitimate interests for security, abuse prevention and telling our own customers about our own products (Art. 7, IX, limited to what those purposes need), and your consent (Art. 7, I) where we say so. You can ask us for the legitimate-interest report supporting any Art. 7, IX processing.
International transfers. Your personal data is processed in the United States. We make those transfers on the basis of the standard contractual clauses adopted by the ANPD under Resolution CD/ANPD No. 19/2024. Where a transfer falls outside them, we rely on the necessity of performing a contract you are party to (Art. 33, V), or on your specific and highlighted consent (Art. 33, VIII).
Data protection officer (encarregado). Our data protection officer for LGPD purposes is Vipul Bindra, Founder of Cutvey LLC, reachable at [email protected] and at the postal address in section 1, and available to receive your requests and communications from the ANPD.
Requests go to [email protected]. You may petition the Autoridade Nacional de Protecao de Dados (ANPD) against us at any time, and you may complain to a consumer protection body.
We handle personal information consistently with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
We handle personal information consistently with the Act on the Protection of Personal Information (APPI).
We handle personal information consistently with the Personal Information Protection Act (PIPA). We collect the minimum necessary for the purposes in section 6, retain it for the periods in section 13, and destroy it without delay once the purpose is achieved.
Overseas transfer. We transfer personal information out of Korea and process it in the United States. We disclose the following under Article 28-8(2), so that a separate consent is not required for transfers necessary to perform our contract with you:
Chief Privacy Officer. Our Chief Privacy Officer under Article 30 of PIPA is Vipul Bindra, Founder, Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA, [email protected].
You may request access, correction, deletion, suspension of processing and withdrawal of consent at [email protected]. You may report a matter to the Personal Information Protection Commission (PIPC), or call the Korea Internet and Security Agency privacy call center on 118.
As India's Digital Personal Data Protection Act, 2023 comes into force, we handle personal data consistently with it.
If your country gives you privacy rights not listed here, tell us what you want and we will do our best to honor it. Our default is to treat a reasonable request as valid regardless of where you live.
We honor the Global Privacy Control (GPC) and other recognized universal opt-out preference signals where the applicable law makes them binding. We record the signal when your browser sends it, and we treat it as a request to opt out of sale and of sharing for cross-context behavioral advertising for that browser or device.
Today that request has nothing to act on, because we do not sell or share personal information for advertising in any Product. We honor the signal anyway, so that you do not have to take our word for it.
Browsers can send a "Do Not Track" (DNT) signal. There is still no agreed standard for what a company must do in response, so like most operators we do not change our behavior based on DNT. We can say the thing DNT was invented to ask for: we do not track you across other companies' websites or apps, at all. The signal we do act on is Global Privacy Control (section 18).
Products change, so this policy will change too. We have written it so that routine change lands in the tables and in the referenced lists (the subprocessor list, the Cookie Notice) rather than requiring a new policy.
When this policy, or a document it references, changes, the version it replaces will be kept at https://cutvey.com/legal/archive.
Email: [email protected]. Privacy requests, questions, complaints and appeals all go here, and reach a person.
Post: Cutvey LLC, 7901 4th St N, Ste 300, St. Petersburg, FL 33702, USA.
In the EEA, the UK or Switzerland, use the same address. We have not yet appointed a representative under Article 27 of the GDPR or of the UK GDPR, and section 17.1 explains what that does and does not change for you.
Referenced documents that form part of this policy: the Cookie Notice (https://cutvey.com/legal/cookies), the Subprocessor List (https://cutvey.com/legal/subprocessors), and, for business customers, the Data Processing Addendum (https://cutvey.com/legal/dpa).