Privacy Policy
Draft for review. Do not publish this policy until these fields are finalized. Complete the legal provider, contact, data-retention periods, international-transfer safeguards, cookie details, and jurisdiction-specific rights with legal review.
1. Scope
This policy explains how Verseframe processes personal data when you visit the service, create an account, upload media, generate outputs, or contact us.
2. Data we process
- Account data: account identifiers, name, email address, and authentication information supplied through our identity provider.
- Content data: audio, video, lyrics, fonts, configuration choices, timing information, and the outputs you create.
- Service data: job status, device/browser information, IP address, logs, and security events needed to operate and protect the service.
- Support data: messages and information you send when requesting support or reporting a problem.
3. Why we use data
We use personal data to provide the requested service, authenticate users, process uploads and renders, maintain security, troubleshoot problems, communicate about the service, comply with legal obligations, and improve reliability and product functionality. We do not use uploaded media or generated outputs to train general-purpose models unless a future published policy clearly says otherwise and gives any legally required choice or consent.
4. Service providers
Verseframe uses service providers to run the product. Depending on the feature, these may include Clerk for authentication, Railway for application hosting and databases, private object storage for media files, and Modal or other processing providers for background media work. Providers may process data only on our instructions and for the purposes described in this policy, subject to applicable agreements and safeguards.
5. Storage, access, and security
We use access controls intended to keep account data and private media available only to authorized users and service providers. Saved-font objects are stored under non-reversible owner-specific prefixes; access is limited through owner authorization and short-lived signed access paths. No security measure is perfect, and you should avoid uploading material you cannot lawfully share or risk losing.
6. Retention and deletion
We retain account and service data for as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. The final policy must state actual retention periods for source uploads, generated outputs, backups, logs, and deleted accounts. You can remove saved fonts through the service; account and broader deletion requests should be directed to the final published privacy contact.
7. Sharing
We do not sell personal data. We share data with service providers supporting Verseframe, when required by law, to protect rights or safety, or in connection with a merger, acquisition, financing, or sale of business assets. We may share de-identified or aggregated information that does not reasonably identify you.
8. International transfers
Your data may be processed in countries other than where you live. Before publication, this section must identify the relevant transfer mechanisms and safeguards, such as contractual protections where required by applicable law.
9. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data, and to withdraw consent where processing is based on consent. You may also have the right to complain to a data-protection authority. The final published policy must explain how to exercise these rights and how we verify requests.
10. Cookies
The final policy must describe the cookies or similar technologies used by Verseframe and its providers, including any required consent controls. Do not make claims about analytics, advertising, or cookie preferences until the production configuration is confirmed.
11. Children
Verseframe is not intended for children below the minimum age required to use the service under applicable law. The final policy should state the service’s intended minimum age and any regional requirements.
12. Changes and contact
We may update this policy as the service changes. The final published version must include the legal provider, privacy contact, mailing address, effective date, and notice process for material changes.