Draft. This text is version 2026-09-28-draft. The operating entity, governing law and contact details are being finalised; until then it describes how the service works, not a completed contract.

Privacy Policy

1. Who this covers

This policy describes what Genreline collects from studios, their crew, and their clients, and what it does with it.

2. What is collected

Account details a person provides (name, email address, password — stored only as a hash), the content a studio and its clients put into the service, usage records needed to bill and to keep the service safe (which features were used, by whom, and when), and technical records (IP address, browser, timestamps) needed to protect accounts and to rate-limit abuse.

3. Why

To provide the service; to keep accounts secure (sign-in protection, abuse controls, verification); to bill the studio; to produce the records the service exists to produce (approvals, signatures, the activity ledger); and to respond to a studio's own support requests.

4. Who else sees it

Infrastructure providers that process data on Genreline's behalf: database and authentication hosting, file storage, email delivery, SMS delivery, video conferencing, error reporting, and — only for content a person explicitly submits to an AI feature — the model provider named at the time. Passwords are checked against a public breach corpus by a method that never transmits the password itself.

5. Retention

Content is kept while the studio's account is open, then for a grace period of ninety days, then deleted. Approval records, signing records and the activity ledger are kept for seven years. An unverified studio that has made nothing is removed after seven days.

6. Your rights

A person may ask for a copy of their data, for correction, or for erasure. Erasure removes identifying details across the platform and is subject to the seven-year retention of records in section 5.

7. Contact

To be completed when the operating entity is named.

Version 2026-09-28-draft