1. Information We Collect
We collect what the service needs to run, and nothing beyond it.
Account information you give us
- Email address
- Password, stored only as a salted hash — we never see the plaintext
- Your light or dark theme preference
What you create in the product
- Creative projects: the document describing your video — scenes, layers, text, timing, transitions, audio and grade settings
- Every revision of that document, kept so you can restore an earlier version
- Assets attached to a project: images, audio and video files, whether you uploaded them, your assistant generated them, or SurgeScribe generated them
- Prompts you or your assistant send to generate an image, a voiceover, a music bed or footage
- Render jobs and their results, including the exported MP4 files and their history
Assistant connections
When you connect ChatGPT, Claude or another MCP client, we store the connection: the client's registered name and redirect URL, and an access token held only as a hash. We record when a token was last used so you can recognise a connection you no longer want. Revoking a connection in Settings deletes its token immediately.
Usage data collected automatically
- Pages visited and actions taken in the app
- Browser, device and operating system
- IP address and approximate region
- Error logs and performance diagnostics
Payment data
We never see or store your card details. Dodo Payments handles payment entirely; we receive a confirmation that a purchase succeeded and the number of credits to add.
2. How We Use Your Data
Only to run and improve SurgeScribe:
- Authenticate you and keep your session
- Store your projects, revisions, assets and export history, and give them back to you
- Send your prompts to the generation models you asked us to use
- Render your video and store the resulting file
- Charge and refund credits, and process purchases
- Send transactional email — confirming your account, resetting your password
- Diagnose faults and improve reliability
We do not sell your data, use it for advertising, share your projects with other users, or train any model on your content.
3. Connected Assistants
Connecting an assistant is what makes SurgeScribe useful, and it is also the most consequential thing you can do with your account, so it is worth being precise.
A connected assistant holds a token scoped to SurgeScribe. With it, that assistant can read and change your creative projects, assets and export history, and can spend your credits on renders and generation. It cannot read your email address or password, change your account credentials, or see another user's data.
What you type into that assistant reaches us as the instructions it sends. Whatever else you discuss with it stays between you and the assistant's own provider, under their privacy policy, not ours.
Every connection is listed under Settings → Account → Connected apps, with when it was last used. Revoking one takes effect immediately and does not affect your other sessions.
4. Third-Party Services
Each service below receives only what it needs to do its job.
Supabase
Database and authenticationYour account, projects, revisions, asset records, render jobs, credit balance and session tokens.
Privacy policy →Cloudflare R2
File storageThe actual files — images, audio, exported MP4s and preview frames. Files are served over HTTPS from storage URLs. Where R2 is not configured, the same files are stored in Supabase Storage instead.
Privacy policy →Vercel
Hosting, and sandboxed renderingRequest logs and IP addresses for serving the app. Rendering runs in a Vercel Sandbox, which receives your project document and its assets for the duration of the render and is discarded afterwards.
Privacy policy →OpenRouter
Generation modelsPrompts and reference images you send for generation are routed to the model that fulfils them: OpenAI GPT Image for images, Google Gemini for voiceover, Google Lyria for music, and ByteDance Seedance, MiniMax and Alibaba Wan for footage. Your prompt text reaches the model provider. Do not put sensitive personal information in prompts.
Privacy policy →Dodo Payments
PaymentsCard and billing details, handled entirely on their side. SurgeScribe never receives raw payment data.
Privacy policy →Google Tag Manager
MeasurementLoads on every page and receives your IP address, browser and the page you are viewing. It is a container: what it loads is configured on our side, and today that is limited to measuring how the site is used. We do not use it for advertising or to build a profile of you, and no measurement tag ever receives your project content.
Privacy policy →5. Data Retention
- While your account is open: projects, revisions, assets, exports and settings are kept until you delete them.
- After you delete your account: personal data, projects, assets and stored files are permanently deleted within 30 days.
- Payment records: transaction records may be kept longer where financial regulations require it.
- Revoked tokens: deleted immediately when you revoke a connection.
To delete your account, email contact@surgescribe.com or use the deletion option in Settings. See our Data Deletion page for the full procedure.
6. Your Rights Under GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your personal data deleted.
- Portability — receive your data in a machine-readable format.
- Restriction — limit how we process your data in certain cases.
- Objection — object where we rely on legitimate interests.
Write to contact@surgescribe.com to exercise any of these. We respond within 30 days.
7. Your Rights Under CCPA
If you are a California resident, you have the right to:
- Know what personal information we collected, used or disclosed about you in the last 12 months.
- Delete the personal information we collected from you.
- Opt out of sale — we do not sell personal information, so there is nothing to opt out of.
- Non-discrimination — we will not treat you differently for exercising these rights.
Email contact@surgescribe.com with the subject line “CCPA Request”.
9. Security
Data is encrypted in transit. Access tokens are stored as hashes rather than in a form we could read back, and database rows are isolated per account so one user's query cannot reach another's projects.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.
10. Children's Privacy
SurgeScribe is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has given us personal data, email contact@surgescribe.com and we will delete it promptly.
11. Changes to This Policy
When we make material changes we will:
- Update the “Last updated” date at the top of this page
- Email registered users if the change is significant
Continuing to use SurgeScribe after a change is posted means you accept the updated policy.
12. Contact Us
Questions about this policy or your data go to contact@surgescribe.com. We aim to reply within five business days.