Privacy Policy
Last updated 13 July 2026
FilmKit ("we", "us") provides client-delivery software for video studios: project management, file delivery, tokenized client galleries, revision review, bookings, and invoicing. This policy explains what we collect and why, for studios ("Operators") and their clients using FilmKit.
What we collect
- Account details: name, email, password (hashed), organization.
- Project content you or your clients upload: video files, documents, messages, and revision comments.
- Client contact details entered by an Operator (name, email, phone).
- Billing details processed by our payment provider (Stripe) — we do not store card numbers.
- Standard technical data: IP address, browser, and access logs, for security and abuse prevention.
How we use it
To operate the service: authenticate you, deliver and store your files, send the notification emails you or your Operator trigger (uploads, revision requests, invoices), process payments, and keep the platform secure. We do not sell personal data.
Client galleries
Tokenized gallery links let a client view or download delivered files without an account. Anyone with the link can access it until it is revoked or expires — Operators are responsible for sharing links only with intended recipients.
Data storage & retention
Files and data are stored on our infrastructure providers (including S3-compatible object storage) for as long as your account or project is active, or as needed to provide the service. You can request deletion of your account and associated data by contacting us below.
Google user data
If you connect a Google account, FilmKit requests access to create and edit Google Docs/Sheets it creates on your behalf (via the Drive, Docs, and Sheets APIs), and to read your name/email for sign-in. We only ever access files FilmKit itself creates — never your existing Drive.
Who we share it with:a Google-backed document is shared, using Google's own sharing permissions, only with other members of your organization who have access to the same project. We do not share your Google data with any other third party, and we do not use it for advertising.
How we protect it: Google access and refresh tokens are encrypted (AES-256-GCM) before being stored in our database and are only decrypted in-memory to make an API call on your behalf. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Third parties
We use Stripe for payments, an email provider for transactional notifications, and standard cloud hosting/storage providers. These providers process data only as needed to deliver the service.
Your rights
You may request access to, correction of, or deletion of your personal data by contacting us at [email protected].
Changes
We may update this policy as the product evolves during beta. Material changes will be reflected by updating the date above.
FilmKit is currently in beta. This policy is a plain-language summary, not a substitute for legal advice.