Legal

Privacy Policy

What we collect, who processes it, and what you can ask us to do about it.

Effective: January 1, 2025Last updated: August 28, 2026

1. Information We Collect

We collect what the service needs to run, and nothing beyond it.

Account information you give us

  • Email address
  • Password, stored only as a salted hash — we never see the plaintext
  • Your light or dark theme preference

What you create in the product

  • Creative projects: the document describing your video — scenes, layers, text, timing, transitions, audio and grade settings
  • Every revision of that document, kept so you can restore an earlier version
  • Assets attached to a project: images, audio and video files, whether you uploaded them, your assistant generated them, or SurgeScribe generated them
  • Prompts you or your assistant send to generate an image, a voiceover, a music bed or footage
  • Render jobs and their results, including the exported MP4 files and their history

Assistant connections

When you connect ChatGPT, Claude or another MCP client, we store the connection: the client's registered name and redirect URL, and an access token held only as a hash. We record when a token was last used so you can recognise a connection you no longer want. Revoking a connection in Settings deletes its token immediately.

Usage data collected automatically

  • Pages visited and actions taken in the app
  • Browser, device and operating system
  • IP address and approximate region
  • Error logs and performance diagnostics

Payment data

We never see or store your card details. Dodo Payments handles payment entirely; we receive a confirmation that a purchase succeeded and the number of credits to add.

2. How We Use Your Data

Only to run and improve SurgeScribe:

  • Authenticate you and keep your session
  • Store your projects, revisions, assets and export history, and give them back to you
  • Send your prompts to the generation models you asked us to use
  • Render your video and store the resulting file
  • Charge and refund credits, and process purchases
  • Send transactional email — confirming your account, resetting your password
  • Diagnose faults and improve reliability

We do not sell your data, use it for advertising, share your projects with other users, or train any model on your content.

3. Connected Assistants

Connecting an assistant is what makes SurgeScribe useful, and it is also the most consequential thing you can do with your account, so it is worth being precise.

A connected assistant holds a token scoped to SurgeScribe. With it, that assistant can read and change your creative projects, assets and export history, and can spend your credits on renders and generation. It cannot read your email address or password, change your account credentials, or see another user's data.

What you type into that assistant reaches us as the instructions it sends. Whatever else you discuss with it stays between you and the assistant's own provider, under their privacy policy, not ours.

Every connection is listed under Settings → Account → Connected apps, with when it was last used. Revoking one takes effect immediately and does not affect your other sessions.

4. Third-Party Services

Each service below receives only what it needs to do its job.

Supabase

Database and authentication

Your account, projects, revisions, asset records, render jobs, credit balance and session tokens.

Privacy policy →

Cloudflare R2

File storage

The actual files — images, audio, exported MP4s and preview frames. Files are served over HTTPS from storage URLs. Where R2 is not configured, the same files are stored in Supabase Storage instead.

Privacy policy →

Vercel

Hosting, and sandboxed rendering

Request logs and IP addresses for serving the app. Rendering runs in a Vercel Sandbox, which receives your project document and its assets for the duration of the render and is discarded afterwards.

Privacy policy →

OpenRouter

Generation models

Prompts and reference images you send for generation are routed to the model that fulfils them: OpenAI GPT Image for images, Google Gemini for voiceover, Google Lyria for music, and ByteDance Seedance, MiniMax and Alibaba Wan for footage. Your prompt text reaches the model provider. Do not put sensitive personal information in prompts.

Privacy policy →

Dodo Payments

Payments

Card and billing details, handled entirely on their side. SurgeScribe never receives raw payment data.

Privacy policy →

Google Tag Manager

Measurement

Loads on every page and receives your IP address, browser and the page you are viewing. It is a container: what it loads is configured on our side, and today that is limited to measuring how the site is used. We do not use it for advertising or to build a profile of you, and no measurement tag ever receives your project content.

Privacy policy →

5. Data Retention

  • While your account is open: projects, revisions, assets, exports and settings are kept until you delete them.
  • After you delete your account: personal data, projects, assets and stored files are permanently deleted within 30 days.
  • Payment records: transaction records may be kept longer where financial regulations require it.
  • Revoked tokens: deleted immediately when you revoke a connection.

To delete your account, email contact@surgescribe.com or use the deletion option in Settings. See our Data Deletion page for the full procedure.

6. Your Rights Under GDPR

If you are in the European Economic Area or the United Kingdom, you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your personal data deleted.
  • Portability — receive your data in a machine-readable format.
  • Restriction — limit how we process your data in certain cases.
  • Objection — object where we rely on legitimate interests.

Write to contact@surgescribe.com to exercise any of these. We respond within 30 days.

7. Your Rights Under CCPA

If you are a California resident, you have the right to:

  • Know what personal information we collected, used or disclosed about you in the last 12 months.
  • Delete the personal information we collected from you.
  • Opt out of sale — we do not sell personal information, so there is nothing to opt out of.
  • Non-discrimination — we will not treat you differently for exercising these rights.

Email contact@surgescribe.com with the subject line “CCPA Request”.

8. Cookies and Local Storage

The cookies the product itself sets are the two it cannot work without:

  • Session cookie — set by Supabase to keep you signed in. Cleared when you sign out.
  • Theme cookie — remembers light or dark mode. Contains no personal data.

Google Tag Manager, described above, also sets measurement cookies. We do not use advertising cookies and we do not sell or share what it collects. You can block these with any standard browser or extension setting without affecting how SurgeScribe works.

9. Security

Data is encrypted in transit. Access tokens are stored as hashes rather than in a form we could read back, and database rows are isolated per account so one user's query cannot reach another's projects.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as the law requires.

10. Children's Privacy

SurgeScribe is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has given us personal data, email contact@surgescribe.com and we will delete it promptly.

11. Changes to This Policy

When we make material changes we will:

  • Update the “Last updated” date at the top of this page
  • Email registered users if the change is significant

Continuing to use SurgeScribe after a change is posted means you accept the updated policy.

12. Contact Us

Questions about this policy or your data go to contact@surgescribe.com. We aim to reply within five business days.

Privacy Policy · SurgeScribe