Privacy policy
This policy explains what [Company legal name] (“we”, “us”) collects when you use Programmable, including the website, the studio, shared and embedded animations, presentations, our integrations and our apps for Shopify, WordPress and Webflow, and how we use it. We collect only what we need to run the service, we do not sell personal information, and we do not use your content to train AI models.
1. Information we collect
Information you give us
- Account details: name, email address, optional business name, and your password (stored only as a secure hash).
- Your content: chats, briefs, storyboards, animations and their versions, presentations, component sets, brand kits and site style profiles, characters, uploaded images and documents, transcripts and translations.
- Things you ask us to read: website addresses, RSS feeds, Shopify store addresses and live-data sources you add. We fetch these public pages and files to build your animations.
- Billing details: handled by Stripe. We receive your plan, credit purchases, invoices and payment status, but never your full card number.
- Support messages you send us.
Information collected automatically
- A sign-in cookie that keeps you signed in for up to 7 days. It is required for the service to work; we do not use advertising or cross-site tracking cookies.
- Usage and billing records: AI usage per generation (to bill credits at cost plus margin), credit ledger entries, and generation job status.
- Security and operations data: IP address and request information used transiently for rate limiting, abuse prevention and error logs.
Your own API keys
If you connect your own Anthropic or image-generation key, it stays in your browser and is sent only with your own requests; it is not saved to your projects or our database. Integration API keys you create are stored only as a secure hash, shown to you once.
2. Visitors to sites that embed our animations
When a site embeds a Programmable animation, we serve the animation and record aggregate statistics for its owner: views, plays, how much was watched, button clicks and the embedding site’s hostname.
- We set no cookies on visitors and store no IP addresses, user-agent strings or full page URLs.
- To count unique visitors per day we use a one-way hash of a random daily value, the animation, the IP address and the browser identifier. The daily value is deleted at the end of each day, after which only the count remains, so hashes cannot be linked across days.
- If the owner runs an A/B test, the embed stores which version the visitor saw in the visitor’s browser storage (localStorage) so they keep seeing the same version. Nothing is sent to us beyond the aggregate counts.
- Automated traffic and known bots are not counted.
The site owner is responsible for describing embedded content in their own privacy notice where their law requires it.
3. How we use information
- To provide the service: research, storyboards, animation generation, quality review, rendering, exports, sharing, embedding and presentations.
- To bill you: metering AI usage, charging and refunding credits, managing subscriptions and allowances.
- To communicate with you: account emails, password resets, “your animation is ready” notifications and service notices. You can turn off optional notifications in your account.
- To keep the service safe and working: security, abuse prevention, debugging and capacity planning.
- To meet legal obligations.
4. AI processing
To make animations, we send the relevant parts of your content (briefs, source text, screenshots, rendered frames and prompts) to AI providers, which process it on our behalf under their business terms. Under those terms, content sent through their APIs is not used to train their models. We do not use your content to train AI models either.
AI output can be inaccurate. Review animations before you publish them, especially facts, figures and depictions of real people.
6. How long we keep information
- Account data and content: for as long as your account is open. When you delete a project or your account, we delete it from the live service, and from backups within [30] days.
- Billing and credit records: as long as required for tax and accounting (typically [7] years).
- Embed analytics: aggregate daily counts for as long as the component exists; daily visitor hashes for one day.
- Security logs: up to [30] days.
7. Your choices and rights
You can view and edit your account and content in the studio, export your animations, unpublish shared content and delete projects. Depending on where you live, you may also have the right to access, correct, delete or port your personal information, to object to or restrict processing, and to withdraw consent. To exercise these rights, email [privacy@your-domain]. We will respond within the time the law requires. You may also complain to your local data protection authority.
California residents: we do not sell or share personal information for cross-context behavioural advertising.
8. Security
We use encryption in transit (HTTPS), hashed passwords and keys, per-account access controls, and a sandbox that runs every generated animation isolated from our site and yours. No system is perfectly secure; if we learn of a breach affecting your information, we will notify you as the law requires.
9. International transfers
We and our providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Children
Programmable is not intended for children under 16, and we do not knowingly collect their information.
11. Changes and contact
We will post changes here and, for material changes, notify you by email or in the studio. Questions: [privacy@your-domain], [Company legal name], [Registered business address].