Serialoom Privacy Policy
| Field | Value |
|---|---|
| Version | 2026-08-05-draft.1 |
| Effective date | [EFFECTIVE DATE] |
| Last updated | 2026-08-05 |
| Previous version | none |
| Change summary | Initial counsel-ready draft from verified data map |
| Status | Counsel-ready draft — not legal advice |
Controller. [LEGAL NAME], individual operating as Serialoom, Israel.
Contacts: privacy@[DOMAIN] · legal@[DOMAIN] · support@[DOMAIN]
EU/UK representative: [NOT APPOINTED — counsel to advise]
DPO: [NOT APPOINTED unless required]
Language. English working draft; Hebrew translation provided. [Counsel:] Hebrew may control for Israeli data subjects where mandatory notice rules so require.
This Policy covers the Serialoom website, application, marketing pages, and support interactions.
Summary
- We process account, workspace, creative project, voice/likeness-related, billing-mirror, and technical data to run Serialoom.
- Paddle is Merchant of Record and processes payment data under its own notices.
- Creative content (prompts, scripts, media) is processed to provide generation and may be sent to AI providers outside Israel.
- We do not sell personal information as “sale” is commonly defined under CCPA, and we do not use cross-context behavioral advertising in the current product.
- You must be 18+. We do not knowingly offer accounts to children.
- Retention and deletion timelines marked PROPOSED are not fully automated yet — see launch blockers.
1. Data we collect
1.1 Data you provide
- Account: name, email, password (stored hashed), locale.
- Workspace: name, intended use, memberships, invitations, roles.
- Creative content: series concepts, bibles, scripts, characters, locations, prompts, references, images, video, audio, captions, comments, exports.
- Voice/likeness: voice profile settings, sample references, consent declarations (when enabled).
- Support and complaints: messages you send us.
- Marketing preferences (when collected).
1.2 Data from use of the service
- Generation jobs, provider job ids, usage and cost metrics.
- Review decisions, continuity/quality signals.
- Product events (first-party analytics stored in our database).
- Security/audit events; approximate technical logs (IP, device/browser as logged by infrastructure).
1.3 Data from Paddle
- Customer id, subscription status, transaction ids, amounts/currency metadata, tax-related metadata Paddle shares for fulfillment, refund/adjustment signals.
- We do not receive full card numbers.
1.4 Data from workspace admins / teammates
- Content and personal data they upload that may identify you or others.
1.5 Data from AI providers
- Generated text, audio, video, and status/error payloads returned to complete jobs.
1.6 Cookies and similar technologies
See Cookie Policy. Current first-party cookies are primarily authentication, CSRF, and workspace preference. Paddle may set cookies during checkout.
2. Creative content
We process prompts, scripts, media, and outputs to deliver the service you request. Avoid putting unnecessary personal data into prompts. Workspace admins can access workspace content. Authorized Serialoom personnel may access content for support, security, abuse, or legal reasons.
3. Voice and biometric / sensitive data
Voice recordings, voice models, facial images, and video of real people may be treated as sensitive or biometric data under some laws when used to identify a person.
- Purpose: generate speech/visual continuity for your productions, with your instructions.
- Sharing: AI/voice providers as needed (e.g., ElevenLabs TTS).
- Consent: real-person likeness/voice features require documented authorization (see Voice and Likeness Consent Policy). Unauthorized uploads are prohibited.
- Retention/deletion: follows project and account retention; consent records may be kept longer for dispute defense (PROPOSED).
4. Purposes and legal bases (jurisdiction-aware draft)
| Purpose | Examples | Draft bases (EEA/UK style) | Israel draft posture |
|---|---|---|---|
| Account & contract | Signup, login, workspaces | Contract | Consent / purpose disclosed for service |
| Service delivery & AI generation | Send prompts/media to providers; store outputs | Contract | Same |
| Billing entitlement | Apply Paddle webhooks; credit ledger | Contract / legal obligation | Same |
| Security & fraud | Auth, CSRF, abuse detection | Legitimate interests / legal obligation | Permitted security processing |
| Moderation & AUP | Block illegal content | Legitimate interests / legal obligation | Same |
| Support | Tickets | Contract / legitimate interests | Same |
| Product analytics | First-party product_events | Legitimate interests (minimize) | Disclose; prefer non-sensitive metrics |
| Marketing email | Newsletters | Consent (where required) | Consent / unsubscribe |
| Legal claims | Records for disputes | Legitimate interests / legal obligation | Same |
We do not use legitimate interests as a universal justification.
5. AI provider disclosures
Depending on configuration, content may be sent to:
- Luma — video generation inputs/outputs
- ElevenLabs — text-to-speech (voice_id + script text)
- NVIDIA NIM / Google Gemini — text generation
Identifiers such as job ids and workspace-scoped references may accompany requests. Processing typically occurs outside Israel. Whether providers use inputs for their own model training depends on provider terms and Serialoom’s account settings — currently not verified as permanently opted out for every provider. Ask privacy@[DOMAIN] for the current Subprocessor List.
6. Paddle
Paddle acts as Merchant of Record. Paddle collects payment method details and tax information under Paddle’s privacy notice. Serialoom receives fulfillment data described above. Refunds, invoices, and payment disputes are primarily handled by Paddle.
7. Sharing
We share personal data with:
- infrastructure providers (e.g., Hetzner hosting; Cloudflare R2 storage when enabled);
- AI providers you invoke through features;
- Paddle for paid transactions;
- email/support tools when enabled;
- professional advisers;
- authorities when legally required;
- successor entities in a corporate transaction (with notice where required).
We do not claim “we never share data.” Service providers receive data to operate Serialoom.
8. International transfers
Data is processed in locations including Germany (Hetzner example region fsn1), Cloudflare regions, and AI provider regions. Safeguards may include provider contractual clauses / SCCs where required. Israeli transfer requirements may also apply. Contact privacy@[DOMAIN] for current transfer information.
9. Retention (PROPOSED — align jobs before treating as hard promises)
| Category | Active retention | After delete request |
|---|---|---|
| Account profile | Life of account | Delete/anonymize within 30 days of verified request where feasible |
| Projects / media | Life of workspace / until user delete | Soft-delete 14 days then purge primary storage (PROPOSED) |
| Credit/billing mirrors | Per tax/accounting needs | Often 7 years or local legal minimum for transaction records |
| Consent / moderation evidence | As needed for disputes | Often retained beyond content delete |
| Logs / product_events | 90 days typical (PROPOSED) | Security logs may be longer |
| Backups | Rolling backups | May persist up to 90 days after primary delete (PROPOSED) |
We do not promise immediate erasure from immutable backups.
10. Security
Measures appropriate to risk include: HTTPS/TLS in transit; access controls and workspace tenancy; signed asset URLs; secrets via environment configuration; logging and monitoring; backups as configured.
At-rest encryption and formal certifications (SOC2/ISO) are not claimed unless independently verified. No method is perfectly secure.
11. Your rights
Depending on your location, you may have rights to access, correction, deletion, restriction, objection, portability, withdraw consent, opt out of marketing, appeal certain decisions, and lodge a complaint with a regulator (e.g., Israel Privacy Protection Authority; an EU/EEA supervisory authority; UK ICO; California CPPA/AG).
Sale / sharing / targeted ads: Serialoom does not sell personal information and does not currently engage in cross-context behavioral advertising. If that changes, we will update this Policy and required controls.
Sensitive data: processed only as needed for the service you request and with required consents for voice/likeness features.
Automated processing: we use automation for generation routing, abuse/fraud signals, and quality scoring. We do not make legally significant decisions about you solely by automated means without human involvement in the current product design.
12. Exercising rights
Email privacy@[DOMAIN]. We may verify identity. Authorized agents may apply where law allows. Workspace-owned content may require the workspace owner’s involvement. We will respond within applicable statutory timelines. Limits and exceptions (e.g., legal retention) may apply.
13. Cookies
See Cookie Policy. Non-essential cookies will not run before required consent in relevant regions once any non-essential tooling is added.
14. Marketing
Service/transactional messages are part of the service. Marketing messages require consent where required and include unsubscribe. Suppression lists are honored.
15. Children
Serialoom is for users 18+. We do not knowingly create accounts for children. If we learn we collected a minor’s data, we will delete or disable it promptly and may terminate the account. This statement alone does not guarantee COPPA compliance in every edge case — operational enforcement matters.
16. Changes
We will post updates with a new version date. Material changes will be notified as described in the Terms. Archived versions will be kept after first publication.
17. Complaints
You may contact privacy@[DOMAIN] and/or your local data protection authority. Listing authorities does not mean one regulator governs every user.
*Counsel-ready draft based on the verified Serialoom implementation and legal research as of 2026-08-05.*