Legal
Privacy Policy
Last updated: 26 July 2026
InteScene Ltd (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our production management platform at intescene.app.
1. Who We Are
InteScene Ltd is a company registered in England and Wales. We are the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
2. What Data We Collect
We collect the following categories of personal data:
- Account information: name, email address, and password (stored in hashed form).
- Profile information: display name and profile picture (if provided).
- Project data: scripts, breakdowns, schedules, budgets, storyboards, shot lists, cast and crew details, locations, production documents, task boards, and all other content you create within the Service.
- Payment information: processed securely by Stripe. We do not store your card number, CVC, or full card details on our servers.
- Usage data: pages visited, features used, timestamps, device type, browser type, and IP address.
- Communication data: support emails and feedback you send to us.
- Location data: coordinates and map interactions when you use location features (powered by Mapbox).
- Advertising attribution: if you arrive from a Google ad, an opaque Google click identifier travels in the signup link itself (nothing is stored on your device for this) and, if you create an account in that visit, is associated with your account for up to 90 days so we can understand which adverts lead to signups. It is reported to Google (to measure an account creation or free-trial start) only if you accepted advertising measurement on one of our two consent banners: the one on our marketing site (intescene.com) or the one in the app itself (intescene.app). Without an acceptance it is never shared and simply expires. Declining on either banner stops the marketing site attaching the identifier to signup links at all, and withdrawing consent later stops any further reporting to Google. The same applies, on the same two banners, to a Reddit click identifier if you arrive from a Reddit ad — kept for 30 days rather than 90, because Reddit will not accept a conversion older than that. Alongside either, and whatever you answer, we record the campaign labels the link itself carried (see section 11): they describe the advert, identify nobody, and are never sent to an advertising network.
- Consent records: timestamps of your acceptance of these terms at signup and of any optional consents you give (marketing, advertising attribution, AI photo analysis), which banner an advertising-measurement consent came from, and the time of any withdrawal.
- Cookies: essential authentication storage (see Section 11).
3. How We Use Your Data
- To provide, operate, and maintain the InteScene platform.
- To authenticate your identity and manage your account.
- To process subscription payments via Stripe.
- To send transactional emails via SendGrid (from noreply@intescene.com): account verification, password resets, project invitations, and calendar invites.
- To power AI features: scripts, breakdowns, images, and other content may be sent to the Google Gemini API and OpenAI API for processing when you use AI features.
- To enable real-time collaboration between project members.
- To display maps and location data when you use location features.
- To improve our service through aggregated, anonymised usage analytics.
- With your consent, to report an account creation or free-trial start to Google Ads, and an account creation to Reddit Ads, for campaign measurement.
- To respond to your support requests and feedback.
4. Legal Bases for Processing
Under GDPR Article 6, we process your data on the following bases:
- Contract performance (Art. 6(1)(b)): processing necessary to provide the service you signed up for, including account management, project data storage, collaboration features, and AI-assisted features you actively invoke on your own content (which can be disabled entirely in your account settings).
- Legitimate interests (Art. 6(1)(f)): service improvement, security monitoring, error diagnostics, fraud prevention, first-party measurement of our own advertising (the server-side storage of the opaque click identifier that arrives with an ad-led signup — up to 90 days for a Google one, 30 for a Reddit one: no device storage, no personal details attached beyond your account link, and never shared without the consent described below; and the campaign labels described in section 11, which identify nobody and are never shared at all), and the cookieless Google Analytics signal described in section 11, which stores and reads nothing on your device and tells us our total traffic rather than only the accepting share of it.
- Consent (Art. 6(1)(a)): (a) sending continuity reference photos that may contain people’s faces to our AI providers, requested in-app before first use and recorded; (b) reporting advertising attribution (account creations and trial starts) to Google, and account creations to Reddit; (c) Google Analytics cookies in the app, the Reddit pixel and its cookie, and the cross-session measurement they enable; (d) marketing emails, via the optional checkbox at signup. Consents (b) and (c) are given together, on either our marketing site’s cookie banner or the app’s own banner, whichever you are shown first (see section 11). You may withdraw consent at any time: marketing and Google measurement in your profile’s Notifications tab, which removes the Google Analytics cookies, returns Google’s permissions to denied, and stops any further advertising reporting, together in one action (or marketing via the unsubscribe link in any such email); the remainder by contacting us. Withdrawal does not affect the lawfulness of processing carried out beforehand, so a conversion already reported to Google cannot be recalled.
- Legal obligation (Art. 6(1)(c)): compliance with applicable laws, including financial record-keeping requirements.
5. AI and Third-Party Data Processing
When you use AI-powered features in InteScene:
- Content such as scripts, breakdowns, prompts, and reference images may be sent to the Google Gemini API and OpenAI API for processing. If you use AI read-through audio, script dialogue is sent to the ElevenLabs API for text-to-speech.
- These providers process your content solely to generate the requested output, and under our API terms with them it is not used to train their AI models. Providers may retain transient copies briefly for abuse monitoring (for example, OpenAI retains API data for up to 30 days) before deletion.
- Continuity reference photos that may contain people’s faces are only sent to an AI provider after you give explicit, recorded consent in-app.
- AI-generated images are stored in your project’s media library within Supabase and are subject to your project’s access controls.
- You can hide and disable AI features entirely from your account settings.
- For content guidelines relating to AI features, see our AI Prohibited Use Policy.
6. Third-Party Services
We use the following third-party services (subprocessors) to operate InteScene. Each has its own privacy policy governing how it handles your data. A maintained list, including each provider’s hosting region and transfer safeguard, is published at intescene.app/subprocessors.html:
| Service |
Purpose |
Data Shared |
| Supabase |
Database, authentication, file storage, real-time sync |
All account and project data |
| Google Gemini |
AI content generation |
Prompts, scripts, reference images |
| Google Ads |
Consented advertising conversion measurement |
Google click identifier, signup or trial timestamp, nominal conversion value, and an account-derived or Stripe-subscription deduplication ID |
| Google Analytics |
Consented usage measurement (loads only after acceptance of the intescene.com banner or the app’s own banner; ad personalisation always denied) |
Pseudonymous analytics identifiers and usage events (page views, signup and trial-start events); never your name or email |
| Reddit Ads |
Consented advertising measurement (the Reddit pixel loads only after acceptance of the intescene.com banner or the app’s own banner; account creations are reported from our servers) |
Reddit click identifier, page-visit events, signup timestamp, a deduplication ID derived from your account, and irreversible hashes of your email address and account ID as matching signals |
| OpenAI |
AI content generation |
Prompts, scripts, breakdowns |
| Stripe |
Payment processing |
Email, subscription and billing details |
| SendGrid |
Transactional email delivery |
Email addresses, message content |
| Mapbox |
Maps and location features |
Location coordinates, map interactions |
| Vercel |
Frontend hosting, web analytics |
IP address, page views, device information |
| Liveblocks |
Real-time collaboration |
Collaborative project content (scripts, documents, breakdown data, comments), collaborator name, email and avatar, presence data |
| HubSpot |
Marketing CRM (only if you opt in to marketing at signup or in your profile) |
Name, email, country, production role, how you found us |
| Sentry (EU-hosted) |
Error monitoring and diagnostics |
Error reports and technical context (browser, IP address); session replay is disabled |
| Cloudflare Turnstile |
Bot protection on sign-in and public forms |
IP address, browser signals used for the challenge |
| ElevenLabs |
AI read-through audio (text-to-speech) |
Script dialogue text and character names, when you use the feature |
| Open-Meteo |
Weather forecasts for shoot locations |
Location coordinates and dates only; no account identifiers |
| Google Firebase Cloud Messaging |
Push notifications for the Cast & Crew mobile app |
Device push tokens and notification titles (never message bodies) |
| Google favicon service |
Icons for link previews in documents |
The domain (not the full address) of links you paste |
7. Data Storage and Security
- Your data is hosted on Supabase infrastructure (powered by AWS).
- Row-level security policies enforce project-based access controls at the database level.
- Passwords are stored in hashed form and are never accessible in plain text.
- All connections are encrypted using TLS (HTTPS).
- We conduct regular reviews of our security practices and access controls.
8. Data Retention
- Account data: retained for as long as your account is active.
- Project data: retained until you delete the project or your account.
- Account deletion: you can delete your account from your profile settings; after a 30-day grace period (during which you can reactivate), your personal data is permanently removed, including project files in storage, collaborative content held at Liveblocks, and your marketing CRM contact.
- Anonymised analytics: aggregated, non-identifiable data may be retained indefinitely.
- Payment records: retained as required by applicable financial regulations (typically 7 years).
- Advertising attribution: unreported Google click identifiers are deleted after 90 days; successfully submitted records are deleted after a further 30 days. Reddit click identifiers are deleted 30 days after the signup, whether or not they were reported. The campaign labels described in section 11 carry no identifier and are kept as part of your account record.
9. Your Rights Under GDPR
You have the following rights in relation to your personal data:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate data.
- Right to erasure (Art. 17): request deletion of your personal data (“right to be forgotten”).
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
- Right to restriction of processing (Art. 18): request that we limit how we use your data.
- Right to object (Art. 21): object to processing based on legitimate interests.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
You can exercise the most common rights yourself, immediately: download a copy of your account data (Profile → Download my data), correct your profile details, change marketing consent (Profile → Notifications), and delete your account (Profile → Delete Account). For anything else, contact us at support@intescene.com. We will respond within one month of receiving your request.
10. International Data Transfers
Your data may be processed outside the United Kingdom by our third-party service providers, including in the United States and the European Economic Area. Where data is transferred internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The UK International Data Transfer Agreement (IDTA) where applicable.
- Adequacy decisions by the UK Secretary of State where available.
11. Cookies and Analytics
- Essential cookies: authentication session cookies are required for the Service to function. These cannot be disabled.
- Analytics: we use Vercel Web Analytics, a privacy-focused analytics service that does not use cookies or collect personal data.
- Google Analytics, before you choose: the Google Analytics 4 tag loads on intescene.app with every measurement permission switched off, which means that before you answer a consent banner we send Google Analytics a cookieless signal containing your IP address, browser type, the page you viewed and the time. No cookies are set, no identifier is stored on or read from your device, and you are not identified or tracked between sites or visits. We rely on our legitimate interest in knowing how much traffic the Service receives in total, rather than only the share of people who accept. It stops entirely if you block the tag in your browser or use an extension that does.
- Google Analytics cookies (only with your consent): the cookies (
_ga) are set, and journeys between sessions measured, only if you accepted measurement on one of our two banners. There are two, because they cover different people: the banner on our marketing site (intescene.com), whose acceptance is carried across to the app, and a banner in the app itself for anyone who never saw the first one (you arrived directly, followed a bookmark or an invite link, or came back through an email confirmation). You are asked at most once: an answer given on either banner, yes or no, is carried to the other, and a refusal is remembered rather than re-asked. Ad personalisation is always denied, accepted or not, and no advertising conversion is ever fired from the app. Declining leaves only the cookieless signal described above. You can withdraw at any time in your profile’s Notifications tab, which removes Google’s cookies (both the analytics ones and the advertising ones described in the next bullet), returns Google’s permissions to denied, and also stops any further advertising conversion being reported to Google.
- Google’s advertising container: because our Google Analytics property is linked to our Google Ads account, the Google tag that loads on intescene.app brings Google’s advertising container with it. Before you accept measurement it sets nothing on your device: every advertising permission is denied, so it sets no cookies and reads nothing from your device. It does send Google a cookieless signal of the same kind described above, containing your IP address, the page you viewed and the time. The same is true after a decline. If you accept measurement, advertising storage is permitted, and the container may then set Google advertising cookies (
_gcl_au, and where you arrived from an ad a _gcl_aw cookie holding that click identifier) on your device to attribute the visit. No advertising conversion is ever fired from your browser; conversions are reported from our own servers, as described below. Ad personalisation stays denied whether you accept or not: we never ask for it, so your activity is not used to target advertising to you. Withdrawing measurement in your profile’s Notifications tab removes these cookies along with the Google Analytics ones.
- The advertising click identifier: if you arrive from a Google ad, the click identifier is passed once in the signup link and kept on our servers for up to 90 days. If you accepted measurement on one of the banners described above, it is sent to Google when an account is created or Stripe confirms a trial. Unless you accept, nothing about that click is stored on your device by us or by Google. We record which banner the consent came from. We never send your name or email to Google, and we do not request ad personalisation.
- The Reddit pixel (only with your consent): Reddit has no equivalent of the permissions model described above — its pixel sets its cookie (
_rdt_uuid) as soon as it loads — so we do not load it at all unless you accepted measurement on one of the two banners. Before an acceptance, and after a decline, no Reddit code runs on either site and nothing is requested from Reddit. If you accept, the pixel records page visits and sets that cookie; withdrawing measurement in your profile’s Notifications tab expires it. As with Google, no conversion is ever fired from your browser: an account creation is reported from our own servers, described in the next bullet.
- The Reddit click identifier: if you arrive from a Reddit ad, an opaque Reddit click identifier is passed once in the signup link and kept on our servers. If you accepted measurement, it is sent to Reddit when an account is created, together with irreversible (SHA-256) hashes of your email address and account ID, which Reddit uses only to match the signup to the advert click. Reddit refuses a conversion more than seven days after the signup, so nothing is sent after that; unsent identifiers simply expire. Unless you accept, the identifier is never sent to Reddit. We never send your name or your email address itself, and we do not request ad personalisation.
- Campaign labels, whether or not you accept: separately from any identifier, we record what the link you arrived on said about itself — its campaign labels (
utm_*), the site that referred you, and the first page you landed on. These describe the advert or link, not you: they carry no identifier, are never sent to any advertising network, and are kept so we can tell which channels bring people to InteScene at all. We rely on our legitimate interest in that, which is why they are recorded for every signup including one where you declined.
- Fonts: all fonts are served from our own domain; no requests are made to third-party font services.
- Link previews: when you paste a link, the preview is fetched by our own server, or directly from the site you linked to (YouTube, Vimeo, Spotify). We do not route your links through third-party preview proxies.
- You can manage cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.
12. Children’s Privacy
InteScene is intended for users aged 16 and over. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child under 16 has provided us with personal data, please contact us at support@intescene.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be communicated via email or in-app notification. The “Last updated” date at the top of this page reflects the most recent revision.
If you have questions about this policy, please contact us at support@intescene.com.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.