Privacy Policy
This policy explains what Home 7 Inc. ("we") collects when you use Cinevas, why, and what your choices are. The short version: your creative work stays on your computer; our servers only know who you are, what plan you're on, and how many generation credits you've used.
1. What we collect
| Data | Why | Kept for |
|---|---|---|
| Email address, password (stored only as a salted hash) | Sign-in, password reset, service emails | Until you delete your account |
| Subscription plan, status, billing period, Stripe customer ID | To know what you're entitled to | Until account deletion; Stripe keeps invoices as required by tax law |
| Generation ledger: which workflow, credit cost, provider task ID, timestamp | Credit accounting, refunds for failed jobs, reconciling provider bills | Until account deletion |
| Sign-in tokens (stored as hashes) | Keeping you signed in across restarts | 30 days or until you sign out |
| IP address and request metadata in server logs | Security, abuse prevention, rate limiting, debugging | Up to 30 days |
2. What passes through our servers but is not stored
When you use a cloud generation feature, your prompt, settings and any reference media you attach are sent through our server to the generation provider (currently RunningHub). We relay them and do not keep copies beyond transient logs. The generated result is downloaded by the app directly from the provider.
3. What never leaves your computer
Your projects, canvases, timelines, local media files, and locally generated exports. Cinevas has no cloud sync. If you use the "local ComfyUI" or "bring your own key" modes, generation requests go from your computer straight to that service and do not touch our servers at all.
4. Third parties we share data with
- Stripe — payment processing. Stripe receives your email and billing details; we never see your card number. Stripe's privacy policy.
- RunningHub — cloud generation. Receives your prompts and reference media for the duration of the job.
- Resend — sends our transactional emails (password reset). Receives your email address.
- Hosting providers that run our servers.
We do not sell personal data, and we do not use it for advertising.
5. Emails
We send only emails needed to run the Service: password reset codes, receipts and payment problems (via Stripe), and notices about changes to terms or prices. No marketing emails unless you separately opt in.
6. Cookies and tracking
Cinevas is a desktop application and uses no cookies, analytics SDKs or tracking pixels. These web pages set no cookies either.
7. Your rights
Depending on where you live (including under the GDPR and UK GDPR), you can ask us to access, correct, export or delete your personal data, or object to certain processing. Email support@onepbdc.com — we respond within 30 days. Deleting your account removes the data in section 1, except records we must keep for tax or fraud-prevention purposes. If you're in the EU/UK you also have the right to complain to your local data-protection authority.
8. Security
Passwords are hashed with scrypt; sign-in tokens are stored only as hashes and rotate on every use; all traffic to our servers is encrypted with TLS. No system is perfectly secure; if we learn of a breach affecting you, we will tell you.
9. International transfers
Our servers and providers may be located outside your country, including in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards.
10. Children
The Service is not directed at children under 16. If you believe a child has created an account, contact us and we will delete it.
11. Changes and contact
We will announce material changes to this policy by email or in the app. Questions or requests: support@onepbdc.com.