← Back to UXI

Privacy Policy

Effective date: May 7, 2026

1. Who We Are

UXI Digital (“we,” “us,” “our”) operates the UXI platform at uxi.digital, an AI‑powered motion graphics and production management service for film and television. This policy explains what data we collect, why, and how we protect it.

2. Data We Collect

Account Information

When you create an account we store your name, email address, and optional avatar image. If you sign in with Google or Microsoft, we receive your name, email, and profile picture from the OAuth provider.

Production & Project Data

Content you create on the platform — productions, scenes, call sheets, scripts, animation projects, and related assets — is stored in our database so you can access and collaborate on it.

Crew & Contact Information

If you use the production management features, you may enter crew member details (name, email, phone, department, role, rates). This data is scoped to your productions and governed by row‑level security.

Gmail Integration (Optional)

You may optionally connect your Gmail account via Google OAuth. If you do, we access your inbox in read‑only mode to sync and classify production‑related emails, and use send access to let you reply from within the platform. Email content is stored encrypted and is only accessible to your account. You can disconnect Gmail at any time, which revokes our access and deletes all synced email data.

Mobile Phone Numbers & Messaging Data

If you provide a mobile phone number — for your own account, or when inviting crew, talent, vendors, or other recipients — we collect the number, your messaging consent status, message delivery metadata (timestamps, delivery state, opt‑in/opt‑out records), and the content of messages you send or receive through Luna. SMS, MMS, RCS, and WhatsApp messages are delivered through Twilio, which processes this data on our behalf.

We do not sell, rent, or share mobile phone numbers, SMS opt‑in data, or messaging consent information with third parties or affiliates for their own marketing or promotional purposes. We may share mobile information with service providers (such as Twilio) only as needed to operate Luna’s messaging services.

Payment Information

Payments are processed by Stripe. We never see or store your full credit card number, CVV, or bank account details — those are collected directly by Stripe via PCI‑DSS compliant payment forms. We store only your Stripe customer ID, subscription status, plan tier, billing email, last‑four digits of your payment method (for display), and invoice history. Stripe’s handling of cardholder data is governed by Stripe’s Privacy Policy.

Usage & Analytics

We use Vercel Analytics and Vercel Speed Insights to collect anonymous performance and page‑view data. We also log activity events (e.g., project opens, edits) internally to power your dashboard and collaboration features.

3. Cookies, Local Storage & Tracking

Strictly Necessary Cookies

We use a small number of essential cookies to keep you signed in and to make the platform function. These are set by our authentication provider (Supabase Auth) and contain encrypted session tokens — not personal data. Without them, you would need to log in on every page load and core features (autosave, real‑time collaboration, role checks) would break. These cookies cannot be disabled while using the service.

Local Storage & IndexedDB

We use your browser’s local storage and IndexedDB to cache UI preferences, draft content, and offline data for the Luna progressive web app. This data lives on your device and is not transmitted to us except when synchronizing with your account.

Analytics

We use Vercel Analytics and Vercel Speed Insights, which collect aggregated, anonymized performance and page‑view metrics. Vercel Analytics is cookie‑free by default.

What We Don’t Use

We do not use advertising cookies, cross‑site tracking pixels, third‑party marketing trackers, or session replay tools. We do not sell behavioral data to advertisers.

Browser Controls

You can clear cookies and local storage at any time through your browser settings. Doing so will sign you out of Luna and clear cached preferences.

4. How We Use Your Data

  • Provide the service — authenticate you, store your projects and productions, enable collaboration.
  • AI features — when you use AI‑powered features (script parsing, scheduling assistant, email classification), relevant content is sent to our AI providers (OpenAI, Anthropic) for processing. We do not use your data to train third‑party AI models.
  • Email integration — classify and surface production‑relevant emails within the platform.
  • Analytics — understand how the platform is used so we can improve it.
  • Communications — send invitation emails, call sheet distributions, and service notifications you have opted into.

5. Third‑Party Services

We share data with the following services to operate the platform:

  • Supabase — database hosting and authentication
  • Vercel — application hosting and analytics
  • Stripe — payment processing and subscription management
  • Twilio — SMS, MMS, RCS, and WhatsApp message delivery, plus opt‑in/opt‑out compliance
  • Resend — outbound transactional email (invitations, call sheets, notifications)
  • Google APIs — OAuth sign‑in and optional Gmail integration
  • Microsoft Graph — sending invitation emails on behalf of administrators
  • OpenAI & Anthropic — AI‑powered features (script parsing, scheduling assistant, email classification)

Each provider processes data under their own privacy policies. We do not sell your data to any third party.

6. Data Security

  • All traffic is encrypted in transit via HTTPS with HSTS enforced.
  • Gmail OAuth tokens are encrypted at rest using AES‑256‑GCM.
  • Database access is governed by row‑level security (RLS) — users can only access their own data.
  • Security headers (CSP, X‑Frame‑Options, X‑Content‑Type‑Options) are set on all responses.

7. Data Retention & Deletion

Your data is retained for as long as your account is active. If you delete your account, all associated profile data, projects, productions, and synced emails are permanently deleted via cascade. Backups may retain data for up to 30 days after deletion.

You can disconnect the Gmail integration at any time to immediately delete all synced email data while keeping your account.

8. Your Rights

You may:

  • Access your data through your account dashboard.
  • Correct your profile information in settings.
  • Delete your account and all associated data.
  • Disconnect third‑party integrations (Gmail) at any time.
  • Opt out of non‑essential emails via notification preferences.

For data export or other privacy requests, contact us at the address below.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via in‑app notification or email. Continued use of the platform after changes constitutes acceptance.

10. Contact

Questions about this policy, data export requests, or other privacy matters? Reach us at support@uxi.digital.