Legal
Privacy policy
What we collect
- Account info: email address, name, and timezone you provide at signup or in your profile.
- Workspace and production data: everything you put into MyNiverse — scripts, schedules, breakdowns, budgets, contact lists, uploads.
- Usage analytics: if we enable product analytics (PostHog), we record page views and feature-usage events to understand how the app is used. No third-party ad cookies.
- Billing info: handled by Stripe. We store subscription status and the last 4 digits of your card; we never see or store the full card number or CVC.
How we use it
- To provide the Service and the features you configure.
- To process payments and send billing receipts.
- To send transactional email (sign-in links, invitations, important account notices). We don’t send marketing email today.
- To improve the product — we may look at anonymized, aggregated usage patterns to decide what to build next.
- To comply with law and to respond to lawful requests.
Subprocessors
We rely on the following third-party services to run MyNiverse. They only receive the data they need to do their job.
| Service | What it does for us | Their privacy policy |
|---|---|---|
| Stripe | Payment processing and billing | Link |
| Supabase | Authentication and Postgres database (hosted on AWS, US region) | Link |
| Anthropic | AI processing for script analysis, breakdowns, and chat features | Link |
| Resend | Transactional email delivery (sign-in links, receipts) | Link |
| Netlify | Web application hosting and CDN | Link |
| OAuth sign-in (if you choose to sign in with Google) | Link | |
| Apple | OAuth sign-in (planned; not yet enabled) | Link |
Where your data lives
Application data is currently stored in the United States via Supabase (hosted on AWS). Region may change as we grow — we’ll update this policy if it does.
How long we keep it
- Active accounts: retained indefinitely while you’re a customer.
- Canceled accounts: workspace data is planned to be retained for 30 days after cancellation, then deleted.
- Audit logs: security-relevant events (sign-in attempts, billing changes) are kept for 12 months.
Your rights
You can access, correct, or delete your account data at any time. Export is available from account settings. To make a request that isn’t self-serve (e.g., account deletion or a data portability request), email privacy@myniverse.app [email — TBD].
We don’t currently send marketing email, but if that changes you’ll be able to opt out with a link in every message.
Cookies
We use first-party session cookies to keep you signed in (via Supabase) and to remember preferences like theme and sidebar state. We don’t set third-party advertising or tracking cookies. If product analytics (PostHog) is enabled, it uses first-party cookies to identify returning sessions.
You can decline analytics via the cookie banner or clear your choice at any time.
Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children.
Security
We use TLS in transit for all traffic. Postgres row-level security policies enforce that users only see their own workspace data. Server-side credentials (Stripe secret key, Supabaseservice_role key, Anthropic key) are held on the server and never exposed to the browser.
Contact
Privacy questions or requests? Email privacy@myniverse.app [email — TBD].
For general product questions or bug reports, email support@myniverse.com.