Programmable
PrivacyTerms

Draft for review. Bracketed details must be completed and the text reviewed by a lawyer before launch.

Privacy policy

Effective [Effective date]

This policy explains what [Company legal name] (“we”, “us”) collects when you use Programmable, including the website, the studio, shared and embedded animations, presentations, our integrations and our apps for Shopify, WordPress and Webflow, and how we use it. We collect only what we need to run the service, we do not sell personal information, and we do not use your content to train AI models.

  1. Information we collect
  2. Visitors to sites that embed our animations
  3. How we use information
  4. AI processing
  5. When we share information
  6. How long we keep information
  7. Your choices and rights
  8. Security
  9. International transfers
  10. Children
  11. Changes and contact

1. Information we collect

Information you give us

  • Account details: name, email address, optional business name, and your password (stored only as a secure hash).
  • Your content: chats, briefs, storyboards, animations and their versions, presentations, component sets, brand kits and site style profiles, characters, uploaded images and documents, transcripts and translations.
  • Things you ask us to read: website addresses, RSS feeds, Shopify store addresses and live-data sources you add. We fetch these public pages and files to build your animations.
  • Billing details: handled by Stripe. We receive your plan, credit purchases, invoices and payment status, but never your full card number.
  • Support messages you send us.

Information collected automatically

  • A sign-in cookie that keeps you signed in for up to 7 days. It is required for the service to work; we do not use advertising or cross-site tracking cookies.
  • Usage and billing records: AI usage per generation (to bill credits at cost plus margin), credit ledger entries, and generation job status.
  • Security and operations data: IP address and request information used transiently for rate limiting, abuse prevention and error logs.

Your own API keys

If you connect your own Anthropic or image-generation key, it stays in your browser and is sent only with your own requests; it is not saved to your projects or our database. Integration API keys you create are stored only as a secure hash, shown to you once.

2. Visitors to sites that embed our animations

When a site embeds a Programmable animation, we serve the animation and record aggregate statistics for its owner: views, plays, how much was watched, button clicks and the embedding site’s hostname.

  • We set no cookies on visitors and store no IP addresses, user-agent strings or full page URLs.
  • To count unique visitors per day we use a one-way hash of a random daily value, the animation, the IP address and the browser identifier. The daily value is deleted at the end of each day, after which only the count remains, so hashes cannot be linked across days.
  • If the owner runs an A/B test, the embed stores which version the visitor saw in the visitor’s browser storage (localStorage) so they keep seeing the same version. Nothing is sent to us beyond the aggregate counts.
  • Automated traffic and known bots are not counted.

The site owner is responsible for describing embedded content in their own privacy notice where their law requires it.

3. How we use information

  • To provide the service: research, storyboards, animation generation, quality review, rendering, exports, sharing, embedding and presentations.
  • To bill you: metering AI usage, charging and refunding credits, managing subscriptions and allowances.
  • To communicate with you: account emails, password resets, “your animation is ready” notifications and service notices. You can turn off optional notifications in your account.
  • To keep the service safe and working: security, abuse prevention, debugging and capacity planning.
  • To meet legal obligations.

4. AI processing

To make animations, we send the relevant parts of your content (briefs, source text, screenshots, rendered frames and prompts) to AI providers, which process it on our behalf under their business terms. Under those terms, content sent through their APIs is not used to train their models. We do not use your content to train AI models either.

AI output can be inaccurate. Review animations before you publish them, especially facts, figures and depictions of real people.

5. When we share information

We share information only with the service providers below, when you ask us to (for example by publishing a share link), or when the law requires it. We do not sell or rent personal information.

ProviderPurposeData involved
AnthropicAI writing, research, storyboards, code generation and quality review (Claude models)Prompts, briefs, imported source text, screenshots and rendered frames sent for review
OpenAIAI-generated character artwork and style imagesCharacter descriptions and reference images
Google (Gemini API)Optional video generation features, when enabledPrompts and reference frames
StripePayments, subscriptions and invoicesBilling details and payment information (card data is handled by Stripe, not stored by us)
ResendAccount and notification emailEmail address and message content
Hosting and database provider (e.g. Fly.io and a managed PostgreSQL provider)Running the service and storing dataAll data stored in the service
Firecrawl (optional)Enhanced reading of websites you ask us to import, when enabledWebsite addresses you submit
Wikimedia Commons and other public sourcesFinding openly licensed images and research sourcesSearch terms derived from your brief (no account data)

Anything you publish (share links, embeds, shared presentations) is visible to anyone with the link. You can unpublish it at any time.

6. How long we keep information

  • Account data and content: for as long as your account is open. When you delete a project or your account, we delete it from the live service, and from backups within [30] days.
  • Billing and credit records: as long as required for tax and accounting (typically [7] years).
  • Embed analytics: aggregate daily counts for as long as the component exists; daily visitor hashes for one day.
  • Security logs: up to [30] days.

7. Your choices and rights

You can view and edit your account and content in the studio, export your animations, unpublish shared content and delete projects. Depending on where you live, you may also have the right to access, correct, delete or port your personal information, to object to or restrict processing, and to withdraw consent. To exercise these rights, email [privacy@your-domain]. We will respond within the time the law requires. You may also complain to your local data protection authority.

California residents: we do not sell or share personal information for cross-context behavioural advertising.

8. Security

We use encryption in transit (HTTPS), hashed passwords and keys, per-account access controls, and a sandbox that runs every generated animation isolated from our site and yours. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you as the law requires.

9. International transfers

We and our providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

10. Children

Programmable is not intended for children under 16, and we do not knowingly collect their information.

11. Changes and contact

We will post changes here and, for material changes, notify you by email or in the studio. Questions: [privacy@your-domain], [Company legal name], [Registered business address].

© 2026 Programmable
HomePrivacyTerms