← Back to home

Legal

Privacy Policy

Effective date: May 16, 2026

Summary

We use passwordless sign-in, process payments via Razorpay, and use AI providers to generate stories and images.

1. Introduction

CinematicTale ("we", "us", or "our") operates https://www.cinematictale.com. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the Service.

This policy is aligned with the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and the SPDI Rules, 2011. For users in the EEA / UK, the principles of the GDPR / UK GDPR are followed where applicable. By using the Service, you consent to the processing described here as a lawful basis under the DPDP Act.

2. What's New (March 2026)

  • Passwordless sign-in is now primary. We authenticate using secure email links and OAuth flows.
  • No password storage by default. Most users no longer create or manage passwords in-app.
  • Session handling improved. Server-side session cookies, CSRF protections, and logout invalidation were strengthened.
  • Policy wording clarified. This page now clearly separates authentication cookies from analytics cookies.

3. Information We Collect

3.1 Information You Provide

  • Account details: email address, display name, and provider identity (Google or email-link).
  • Profile information: optional avatar and public profile details.
  • Story content: prompts, generated story text, generated images, and related metadata.
  • Reference photos (optional "Feature Yourself"): if you upload a photo of yourself to feature as a character, we store it in private Cloud Storage and send it to our AI providers (Google Gemini / Kie.AI) for character generation only. Photos are not used for training, not shared with third parties beyond the AI provider for that specific generation, and are deleted when you remove them in the app or delete your account.
  • Payment information: processed by Razorpay. We do not store card numbers or UPI credentials.

3.2 Information Collected Automatically

  • Usage data: pages viewed, features used, and session-level interaction events.
  • Device data: browser, OS, approximate network details, and request metadata.
  • Cookies/local storage: session auth state, CSRF token, and UX preferences.
  • Analytics: aggregated product usage through Google Analytics and Vercel Analytics.

4. How We Use Information

  • Authenticate users and protect accounts.
  • Generate stories, images, and related media based on your prompts.
  • Process subscriptions, top-ups, invoices, and payment reconciliation.
  • Send transactional emails (sign-in links, billing, verification, support replies).
  • Prevent abuse, enforce rate limits, and monitor platform reliability.
  • Comply with legal and regulatory obligations.

5. Third-Party Services

We use third-party providers that may process your data only for required service functions.

Google FirebasePrivacy ↗

Authentication, Firestore database, and storage.

Google AI (Gemini)Privacy ↗

Text and image generation for stories and assets.

Provider for image and video (Veo 3 Fast) generation workloads.

RazorpayPrivacy ↗

Payment processing for plans and credit top-ups.

Hosting, deployment infrastructure, and edge/network logs.

Upstash RedisPrivacy ↗

Rate-limit state and anti-abuse request controls.

6. Data Storage and Security

  • TLS/HTTPS encryption for traffic in transit.
  • Server-side session cookies and CSRF checks for authenticated API actions.
  • Role-appropriate Firestore access controls and server-side validation.
  • Rate limiting and webhook signature verification on sensitive endpoints.

No transmission method is fully risk-free. We continuously improve controls, monitoring, and incident response.

7. Data Retention

We retain account and story data while your account is active. On account deletion, user data is removed from active systems within a reasonable operational window, except where legal obligations require retention (for example, payment/tax records).

8. Your Rights

Under the DPDP Act, GDPR, and similar laws, you have rights with respect to your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: update profile fields from account settings, or ask us to correct inaccuracies.
  • Erasure ("right to be forgotten"): delete your account and associated data. Use the Delete Account flow in settings, or email us.
  • Portability: request export of your story data in a structured, machine-readable format where feasible.
  • Grievance redressal: for any rights request or unresolved concern, email our Grievance Officer (see Section 12).
  • Withdrawal of consent: you may withdraw consent at any time by deleting your account; some processing for legal/tax compliance may continue.

We respond to verified rights requests within 30 days, in line with DPDP Act timelines. For any rights request, email saurabhjadhav.devstudio@gmail.com.

9. Cookies and Similar Technologies

  • Authentication cookies: keep signed-in sessions secure.
  • CSRF token cookie: protects state-changing requests from forgery attacks.
  • Preference storage: theme and experience settings.
  • Analytics cookies: aggregated usage metrics.

CSRF cookies are security tokens and can exist even when you are signed out; they are not proof of an active login.

10. Children's Privacy

CinematicTale is not intended for children under 13 years of age. Under the DPDP Act, processing personal data of children (under 18 in India) requires verifiable parental consent. Users between 13 and 18 should use the Service only with parental or guardian consent. If you believe a child has provided personal data without consent, contact us and we will investigate and delete the data promptly.

11. Changes to This Policy

We may revise this policy periodically. Material changes will be communicated through updates on this page and, when appropriate, account-level notices.

12. Contact & Grievance Officer

For any privacy concerns, rights requests, or grievances under the DPDP Act, contact our Grievance Officer. We aim to acknowledge within 48 hours and resolve within 30 days.

CinematicTale — Grievance Officer

Name: Saurabh Jadhav

Email: saurabhjadhav.devstudio@gmail.com

Website: https://www.cinematictale.com

Instagram: @cinematictale.studio

Jurisdiction: India