Yönetmen · effective 6 August 2026
Nothing you shoot stays with us. You sign in with Apple or Google; we hold no password, and your sign-in details are never sent to our server. Your film, your photos and your notes live only on your phone, encrypted.
Signing in is only possible with Sign in with Apple or Sign in with Google. There is no other method, no email/password, no guest mode.
| what | from where | where it stays |
|---|---|---|
| The user ID issued by the provider | Apple / Google | on your device only, encrypted in secure storage |
| Name | if the provider shares it | on your device only |
| if the provider shares it | on your device only | |
| Identity token (JWT) | at sign-in | not stored — read once, then discarded |
On Apple's side you can choose "Hide My Email"; the app works in full either way. On Google's side the email is kept only when the provider reports it as verified.
None of this is sent to our server. Sign-in completes entirely on your device; on our side there is no account record and no user table. When you sign out, this record is deleted from your device; your film, your cast and your scenes stay where they are.
None of your content. No account either. Our server never sees the video and photo bytes: the file goes from your device directly to the production provider; we only broker the signed address.
The single thing kept on the server is a random identifier generated by your device inside the app, used only in case of a rules violation (see below). It is not tied to your name, your phone number or the platform's advertising identifier.
Only when you invite someone to a joint scene or accept an invite, and only for the life of that invite, we temporarily keep on our server: the name added to the invite, the short character note chosen, the temporary addresses of the frames at the provider, and (if you allowed notifications) a notification token. These are kept for at most 24 hours and then deleted — sooner once the invite is completed or cancelled. This data lives on Supabase (USA), together with our purchase ledger. If you never use joint scenes, none of this is created.
We use a small number of providers to run the app. All of the data lives in the USA, so to the extent you use them there is a cross-border transfer:
| provider | for what |
|---|---|
| fal.ai (USA) | scene/video production — frames go directly there |
| Supabase (USA) | purchase ledger and joint-scene invite records |
| Apple APNs | notification token (only if you allowed notifications) |
| Anthropic (USA) | turning the scenario TEXT you type (members-only custom scene) into cinematic language (text only; no face/photo) |
| Resend | forwarding your email to us when you write to support |
Scenes are produced on fal.ai infrastructure. This necessary processing step happens within these limits:
| what | how long it stays |
|---|---|
| The image/video you upload | at most 8 hours — served with a short-lived header |
| The produced scene | deleted once it has been downloaded to your device |
| Prompt and response logs | not retained — a no-storage header is sent |
Productions involving pornography, violence, murder, terrorism, gambling or child abuse are not permitted. When the provider reports such content you are warned; on the third report your device can no longer produce. The only things kept in that case are a device identifier and a counter — your prompt, your file and your footage are not kept.
None. No third-party analytics, no ad network, no cross-site tracking.
The app is not designed for children under 13. When you add someone else to your film — including your own child — obtaining their consent, or their guardian's, is your responsibility; the app asks you this explicitly.
Your data is on your device, so deletion is yours too: deleting the app deletes everything. There is no copy held by us, which is why you never have to ask us to erase your data.
To remove just the sign-in record, Settings → Your account → Sign out inside the app is enough. You can also revoke access at the source: on Apple, Settings → Apple Account → Sign-In & Security → Sign in with Apple; on Google, the Connected apps section of your account security page.
For questions: mail@yonetmen.app