Skip to main content
Your Material. Your Rights.

Privacy Policy

Last updated: 1 September 2026

1. What we collect

We collect only what is necessary to deliver the Plenza service:

  • Account information (name, email) for authentication and billing.
  • Scripts and scene lines you upload to generate AI reader tracks.
  • Audio/video recordings you create using our off-camera reader.
  • Usage data (e.g., shot-type preferences, pacing settings) to improve performance.

2. How we use your data

Your material is used solely to operate Plenza for you:

  • Generating adaptive AI reads with action and cut cues.
  • Exporting audition-ready audio balanced for self-tape.
  • Storing your personal vault of past scenes and settings.

We do not sell, rent, or share your scripts or recordings with third parties for marketing or advertising.

3. Encryption & security

Everything you upload is encrypted at rest using industry-standard AES-256 encryption. Data in transit is protected with TLS 1.3. Access to production systems is restricted to authorized engineers and monitored with audit logging.

4. Retention & deletion

You control retention for your own material: scripts, audio, and video stay in your personal vault until you delete them or close your account. We do not run a background timer that auto-deletes your creative content while your account is active. When you delete an item, or your account, the data is purged from active storage immediately and from backups within 30 days.

Data typeActive retentionBackup purge
Account profile (email, name)Until account deletion+30 days
Scripts (PDF text)Until you delete+30 days
Audio/video recordingsUntil you delete+30 days
Auth logs (sign-in IPs, devices)90 days+30 days
Payment records (Stripe metadata)7 years (tax/legal obligation)+30 days
Marketing consent logUntil withdrawn + 3 years (proof of consent)+30 days
Support emails2 years from last reply+30 days
GetResponse marketing syncWhile account active+30 days after deletion
Request immediate data deletion

Wipes scripts, recordings, vault items, and account data. Typical time-to-complete: under 24 hours. Backup purge follows within 30 days. A confirmation email with your request ID is sent when complete.

5. AI training & third-party models

Your material is yours alone. Plenza never uses your scripts, audio, or video to train any model of ours, and we don't sell, licence, or publish them. Your pages are used for one thing: building and running your rehearsal — reading the lines aloud, and the notes you ask for. Nothing else.

To do that, your material passes through these AI providers. Their published terms, as of 1 September 2026, are:

  • Google (Gemini API, paid tier) — reads script pages you import by photo or scan, and generates rehearsal notes. Google's Gemini API Additional Terms state that for paid use "Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products," and that prompts and responses are processed under Google's Data Processing Addendum for Products Where Google is a Data Processor. We have used the paid tier since 12 August 2026. Before that date the project ran on the free tier, whose terms permit Google to use inputs to improve its products, so script pages imported before 12 August 2026 fall under those terms.
  • ElevenLabs — two separate flows:
    • The reader. We send the text of the lines to be spoken, and nothing else. Your delivery notes and direction are never sent.
    • Pro performance conversion. When you ask to convert a take into a catalog voice, we send that take's recording — the recorded file as it is stored, of which ElevenLabs uses the audio track — so the performance can be re-voiced.
    ElevenLabs publishes a DPA (last updated 8 April 2026) that applies to our account without separate signature. Their terms provide an account-level opt-out from use of customer content for training their models. We have operated as opted out since 1 September 2026, and that opt-out covers both flows above. Conversions made before that date (17–20 August 2026) ran under the account default.
  • Resend — sends account email (confirmations, sign-in codes, password resets). Resend's DPA binds on acceptance of its terms and limits it to processing your data only "as necessary for the specific purpose of performing the Services," and prohibits selling it. Its DPA contains no dedicated model-training clause, so we make no training claim on its behalf beyond that purpose limit. Script and take content is never sent to Resend.
  • Lovable AI Gateway — when you import a script by reading it aloud, we send that recording of your voice to Lovable's AI gateway so it can be turned into script text. No script text, take video, or delivery notes are sent with it, and the audio is not stored by us after transcription. The gateway is a routing layer operated by Lovable, our hosting provider: we address it with the model identifier openai/gpt-4o-mini-transcribe, which names OpenAI's transcription model. Beyond that identifier, we cannot confirm from Lovable's documentation which entity actually serves the request, what that provider's training terms are, or whether a DPA covers the onward transfer — so we make no claim about it rather than guess. We have asked Lovable to confirm the chain in writing and will state it here when we have it. If you would rather no recording of your voice leave the app, import your script by photo, file, or paste instead of reading it aloud.

Spoken cues during rehearsal are different. When you rehearse hands-free and speak your cue, the recognition is done by your own browser or phone. That audio is not sent to Plenza or to any of the providers above; it is handled by your browser or device vendor under their terms, not ours.

We do not make automated decisions that produce legal or similarly significant effects on you (UK GDPR / GDPR Art. 22). The AI reader is a creative tool: it generates audio from your scripts. It does not score, rank, profile, or gate access to anything based on your material.

6. Cookies & tracking

We distinguish two types of cookies and similar storage:

  • Essential (cannot be disabled): authentication session (browser localStorage, not a cookie), CSRF protection, and Cloudflare's __cf_bm bot-management cookie. Without these the app can't keep you signed in or block abuse.
  • Analytics (optional, off by default in the EU/UK/California): first-party event tracking via PostHog to help us improve the product. No third-party ad pixels, no cross-site tracking. You can change your choice anytime from the cookie banner or from /preferences.

7. Your rights (GDPR & CCPA)

EU / UK (GDPR & UK GDPR): you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, to withdraw consent, and to lodge a complaint with your supervisory authority. The legal bases we rely on (GDPR Art. 6) are contract performance (running your account and billing), legitimate interest (security, opt-out product analytics), and consent (marketing emails, optional cookies).

UK supervisory authority: if you are in the UK and believe we have mishandled your personal data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. EU users can complain to their national data protection authority.

California (CCPA / CPRA): you have the right to know, delete, and correct your personal information, to opt out of any sale or sharing (we don't sell or share), to limit use of sensitive personal information, and to be free from discrimination for exercising these rights.

How to exercise: submit access, portability, or deletion requests at /privacy/data-requests, manage email preferences at /preferences, or email privacy@plenza.io. We respond within 30 days (GDPR) or 45 days (CCPA).

8. Sub-processors

These are the providers that deliver Plenza, what each one touches, and the exact data-protection status of each as of 1 September 2026. We state this per provider rather than as a blanket claim, and Standard Contractual Clauses apply to international transfers where required.

ProviderWhat it handlesData-protection status
Supabase (US / EU)Database, authentication, private storage of scripts and takesProvider DPA in place
Cloudflare (global edge)CDN, DDoS protection, bot managementProvider DPA in place
Stripe (global)Payments and subscription billingProvider DPA in place
Google — Gemini API, paid tier (US)Reading imported script photos and scans; rehearsal notesGoogle's processor DPA (business.safety.google/processorterms) is incorporated by the Gemini API Additional Terms for paid use, in effect for us since 12 August 2026; imports before that date ran on the free tier; a countersigned copy is being executed
ElevenLabs (US)AI reader voices (line text); take recordings (Pro conversion)Published DPA (8 Apr 2026) applies to our account without separate signature; a countersigned copy is being executed
Resend (US)Account email only — confirmations, codes, password resetsPublished DPA binds on acceptance of its terms; a countersigned copy is being executed
Lovable — AI gateway (routing; serving provider not disclosed to us)Speech-to-text for spoken script import: a recording of you reading your script aloudProcessing covered by our hosting agreement with Lovable; the onward serving provider and its DPA status are not disclosed to us — see section 5
Lovable — connector gatewayCredential broker for our own Stripe and internal-ops calls: payment and account data in transitProcessing covered by our hosting agreement with Lovable
GetResponse (Poland / EU)Marketing email, opt-in onlyProvider DPA in place
PostHog (US)Product analytics, only if you opt inProvider DPA in place

We give 30 days' notice before adding a material new sub-processor. Scripts and takes go only to Supabase, Cloudflare, Google (Gemini API) and ElevenLabs — never to the email, payment, or analytics providers. A recording of you reading a script aloud goes only to Lovable's AI gateway, and only when you import a script that way; spoken cues during rehearsal are recognised by your own browser or phone and are not sent to us at all.

9. Children's data (18+ product)

Plenza is an 18+ product. The minimum age to create an account is 18, regardless of jurisdiction. We require explicit age attestation at signup and on every protected request; accounts that don't meet this requirement are not created.

For reference, the digital-consent age under each privacy regime is: 13 in the UK (UK GDPR / DPA 2018 s.9) and the US (COPPA); 13–16 across EU member states (GDPR Art. 8). Our 18+ floor sits above all of these.

  • If we learn that someone under 18 has created an account, we delete the account and all associated data within 7 days.
  • Parents or guardians who believe their child created an account can email privacy@plenza.io and we'll delete it on receipt, with confirmation.

10. Your rights — quick reference

To exercise any right, email privacy@plenza.io from your account email, or use the controls at /preferences and the "Delete my data" button above.

11. Changes to this policy

If we make material changes, we will notify you by email or via an in-app alert at least 30 days before they take effect. Continued use of Plenza after the effective date constitutes acceptance of the updated policy.

Changelog

  • 1 September 2026 — sections 5 and 8: corrected Lovable AI Gateway's purpose (speech-to-text for spoken script import; previously misdescribed as text generation); disclosed three existing processors (Google Gemini API, ElevenLabs, Resend) and Lovable's connector gateway; corrected the description of AI-provider training terms.

12. Contact

Questions about this policy? Reach out at privacy@plenza.io.