This policy explains what ScriptSnap (“we,” “us”) collects when you use the app, why, who we share it with, and how you can export or delete it. It covers what the product actually does today — not generic boilerplate.
1. What we collect
- Account information: your email address, and a password (stored as a secure hash by our authentication provider, Supabase — we never see or store it in plain text).
- Content you create: script topics, generated scripts, context and keywords you provide, ideas, calendar entries, tone presets, categories, and script ratings.
- YouTube channel data (only if you connect it): your channel ID and title, and a short cached summary of your channel’s recent video performance (views, average watch time, subscriber gains) used to personalize script generation. Your Google access token is stored securely on our servers and is never sent to your browser or included in a data export.
- Payment identifiers: order, payment, and customer IDs from Razorpay, our payment processor. We never see or store your card details — Razorpay handles that directly.
- Subscription status: your current plan (Free, Basic, or Pro) and monthly usage count.
2. How we use it
- To generate scripts — your topic, context, keywords, and (if connected) channel performance summary are sent to Anthropic’s Claude API to produce the script.
- To personalize output using your own tone presets and generation history.
- To process payments and manage your subscription via Razorpay.
- To pull your channel analytics, only if you’ve connected your YouTube channel, via Google’s YouTube Data and YouTube Analytics APIs.
- To enforce your plan’s monthly script limit.
3. Who we share it with
We use the following service providers (“sub-processors”) to run ScriptSnap. We don’t sell your data to anyone.
- Anthropic — processes the text of your script requests to generate scripts.
- Google — only if you connect your YouTube channel, to read your channel’s public and owner-level analytics.
- Razorpay — processes subscription payments.
- Supabase — hosts our database and handles authentication.
- Vercel — hosts the application itself.
4. How long we keep it
We keep your data for as long as your account is active. If you delete your account, everything tied to it — scripts, ideas, calendar entries, tone presets, categories, and your YouTube connection — is permanently deleted, immediately and irreversibly.
5. Your rights
From Settings, you can:
- Export your data as a JSON file, at any time.
- Delete your account, which permanently removes all of the above with no recovery option.
6. Security
Passwords are hashed by Supabase Auth, never stored in plain text. Database access is scoped per-user with row-level security, so one account can never read another’s data. Your YouTube access token is stored server-side only and is never exposed to your browser.
7. Changes to this policy
If this policy changes materially, we’ll update the date above and, where required, notify you directly.
8. Contact
Questions about this policy or your data: [PLACEHOLDER: support contact email].
[PLACEHOLDER: business legal name and address].