Privacy Policy
Last updated: March 21, 2026
1. Information We Collect
Registration data:
- Email address
- Username
- Password (stored as a bcrypt hash — we never see your plaintext password)
- Display name (optional)
Automatic data:
- IP address (logged with each request for security and rate limiting)
- Request metadata (HTTP method, path, status code, response time)
- Session token (stored as an HttpOnly cookie in your browser)
User-generated content:
- Video prompts and scripts
- AI-generated images, audio, and video files
- Uploaded assets (character/object images)
Payment data:
- Razorpay subscription ID
- Plan and credit usage metadata
- Card details are handled entirely by Razorpay — we never see or store them
2. Third-Party Services
We use third-party services to power Sketchpen. Here is what data each service receives:
| Service | Data Shared | Purpose |
|---|---|---|
| Razorpay | Plan ID, user ID | Payment processing |
| Google Gemini | Text prompts, scene descriptions, reference images | Script & image generation |
| fal.ai | Text prompts, reference images | Image generation |
| ElevenLabs | Text scripts | Text-to-speech |
| Inworld AI | Text scripts | Text-to-speech |
| Cloudflare R2 | Generated files (images, audio, video) | File storage |
| Neon PostgreSQL | All account data and metadata | Database |
| Resend | Email addresses | Transactional emails |
3. Data Retention
- Account data: Retained until you request account deletion
- Completed videos: Auto-deleted after your plan's retention period (7 to 30 days depending on plan)
- Intermediate files: Scene images and audio are deleted after a successful video render. Only the final video and thumbnail are kept.
- Usage logs: Retained for service operation and billing
4. Data Security
We take security seriously:
- Passwords are hashed with bcrypt — we never store plaintext passwords
- Sessions use HttpOnly, Secure cookies — no plain text tokens
- File access uses time-limited presigned URLs
- Database and storage provide encryption at rest
- API keys are hashed before storage
5. Your Rights
You have the right to:
- Access: View your data through the dashboard
- Correction: Update your display name, username, and password
- Deletion: Delete individual videos or request full account deletion by emailing jay@sketchpen.app
- Download: Download individual video files from your dashboard
6. Children's Privacy
Sketchpen is not intended for users under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at jay@sketchpen.app.
7. International Data Transfers
Your data may be processed and stored in multiple locations:
- Singapore — Database (Neon PostgreSQL)
- United States — AI processing (Google, ElevenLabs, Inworld, fal.ai)
- Global — File storage and CDN (Cloudflare)
- India — Company operations
By using Sketchpen, you consent to the transfer of your data to these locations.
8. Cookies
Sketchpen uses only one cookie: a session token (access_token) that is HttpOnly, Secure, and SameSite=Lax. This cookie is used solely for authentication and is valid for 7 days. We do not use tracking cookies, analytics cookies, or advertising cookies.
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via email or posted on the site. We encourage you to review this page periodically.
10. Contact Us
If you have questions or concerns about this privacy policy, reach out at jay@sketchpen.app.