Legal
Privacy Policy
Effective date: May 16, 2026
Summary
We use passwordless sign-in, process payments via Razorpay, and use AI providers to generate stories and images.
1. Introduction
CinematicTale ("we", "us", or "our") operates https://www.cinematictale.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Service.
This policy is aligned with the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the SPDI Rules, 2011. For users in the EEA / UK, the principles of the GDPR / UK GDPR are followed where applicable. By using the Service, you consent to the processing described here as a lawful basis under the DPDP Act.
2. What's New (March 2026)
- Passwordless sign-in is now primary. We authenticate using secure email links and OAuth flows.
- No password storage by default. Most users no longer create or manage passwords in-app.
- Session handling improved. Server-side session cookies, CSRF protections, and logout invalidation were strengthened.
- Policy wording clarified. This page now clearly separates authentication cookies from analytics cookies.
3. Information We Collect
3.1 Information You Provide
- Account details: email address, display name, and provider identity (Google or email-link).
- Profile information: optional avatar and public profile details.
- Story content: prompts, generated story text, generated images, and related metadata.
- Reference photos (optional "Feature Yourself"): if you upload a photo of yourself to feature as a character, we store it in private Cloud Storage and send it to our AI providers (Google Gemini / Kie.AI) for character generation only. Photos are not used for training, not shared with third parties beyond the AI provider for that specific generation, and are deleted when you remove them in the app or delete your account.
- Payment information: processed by Razorpay. We do not store card numbers or UPI credentials.
3.2 Information Collected Automatically
- Usage data: pages viewed, features used, and session-level interaction events.
- Device data: browser, OS, approximate network details, and request metadata.
- Cookies/local storage: session auth state, CSRF token, and UX preferences.
- Analytics: aggregated product usage through Google Analytics and Vercel Analytics.
4. How We Use Information
- Authenticate users and protect accounts.
- Generate stories, images, and related media based on your prompts.
- Process subscriptions, top-ups, invoices, and payment reconciliation.
- Send transactional emails (sign-in links, billing, verification, support replies).
- Prevent abuse, enforce rate limits, and monitor platform reliability.
- Comply with legal and regulatory obligations.
5. Third-Party Services
We use third-party providers that may process your data only for required service functions.
Authentication, Firestore database, and storage.
Text and image generation for stories and assets.
Provider for image and video (Veo 3 Fast) generation workloads.
Payment processing for plans and credit top-ups.
Hosting, deployment infrastructure, and edge/network logs.
Rate-limit state and anti-abuse request controls.
6. Data Storage and Security
- TLS/HTTPS encryption for traffic in transit.
- Server-side session cookies and CSRF checks for authenticated API actions.
- Role-appropriate Firestore access controls and server-side validation.
- Rate limiting and webhook signature verification on sensitive endpoints.
No transmission method is fully risk-free. We continuously improve controls, monitoring, and incident response.
7. Data Retention
We retain account and story data while your account is active. On account deletion, user data is removed from active systems within a reasonable operational window, except where legal obligations require retention (for example, payment/tax records).
8. Your Rights
Under the DPDP Act, GDPR, and similar laws, you have rights with respect to your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: update profile fields from account settings, or ask us to correct inaccuracies.
- Erasure ("right to be forgotten"): delete your account and associated data. Use the Delete Account flow in settings, or email us.
- Portability: request export of your story data in a structured, machine-readable format where feasible.
- Grievance redressal: for any rights request or unresolved concern, email our Grievance Officer (see Section 12).
- Withdrawal of consent: you may withdraw consent at any time by deleting your account; some processing for legal/tax compliance may continue.
We respond to verified rights requests within 30 days, in line with DPDP Act timelines. For any rights request, email saurabhjadhav.devstudio@gmail.com.
10. Children's Privacy
CinematicTale is not intended for children under 13 years of age. Under the DPDP Act, processing personal data of children (under 18 in India) requires verifiable parental consent. Users between 13 and 18 should use the Service only with parental or guardian consent. If you believe a child has provided personal data without consent, contact us and we will investigate and delete the data promptly.
11. Changes to This Policy
We may revise this policy periodically. Material changes will be communicated through updates on this page and, when appropriate, account-level notices.
12. Contact & Grievance Officer
For any privacy concerns, rights requests, or grievances under the DPDP Act, contact our Grievance Officer. We aim to acknowledge within 48 hours and resolve within 30 days.
CinematicTale — Grievance Officer
Name: Saurabh Jadhav
Email: saurabhjadhav.devstudio@gmail.com
Website: https://www.cinematictale.com
Instagram: @cinematictale.studio
Jurisdiction: India