Skip to content
Director's Canvas
Back home

Legal

Privacy Policy

How Director's Canvas handles account information, creative work, AI requests, private media, and optional site measurement.

Effective: August 3, 2026

01

Scope and operator

This Privacy Policy explains how Director's Canvas collects, uses, discloses, and protects personal information when you visit or use the website, private-beta workspace, AI features, and related services (the “Service”). Director's Canvas is operated by Joshua Levine, an individual based in Florida, United States (“Director's Canvas,” “we,” “us,” or “our”).

This policy applies globally. Local law may give you additional rights that this policy does not limit. The Service is intended only for people who are at least 18 years old.

02

Information we collect

We may collect the following categories of information:

  • Account information: your name, email address, authentication identifiers, verified-email status, and security or session information supplied through Clerk.
  • Creative and project content: project titles, ideas, lyrics, audio, images, talent and style references, treatments, visual bibles, timelines, scenes, shot directions, prompts, Copilot messages, AI outputs, approvals, and exports.
  • Service and usage data: feature activity, timestamps, model and token usage, generation status, internal user and project identifiers, support messages, and diagnostic or security logs. Hosting and authentication providers may also process IP address, device, browser, and request information to deliver and secure the Service.
  • Optional measurement data: if you choose “Allow all,” aggregate page-visit and performance measurements from Vercel Web Analytics and Speed Insights. We exclude sign-in and sign-up paths, remove query strings and fragments, and replace UUID path segments before these events are sent.
03

Where information comes from

We collect information directly from you, automatically from your browser or device when necessary to operate the Service, and from service providers that help us authenticate users, host the application, store data, deliver AI features, and respond to support or security issues. If another person or organization provides content about you, they are responsible for having the right to do so.

04

How and why we use information

We use personal information to:

  • provide accounts, projects, private media, AI-assisted drafts, generation, exports, and support;
  • authenticate users, enforce the invite list, prevent abuse, and protect the Service;
  • maintain project history, approvals, usage limits, reliability, and troubleshooting records;
  • improve features and performance using feedback and optional aggregate measurements; and
  • comply with law, enforce our terms, and establish or defend legal claims.

Where a legal basis is required, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your consent for optional analytics, and compliance with legal obligations. You may withdraw analytics consent at any time through Cookie settings.

05

AI processing and model providers

When you use an AI feature, Director's Canvas sends the material needed for that request through Vercel AI Gateway to a configured model provider, currently including OpenAI, Anthropic, or Google. Depending on the feature, this material can include your instructions, lyrics, project context, live editor content, Copilot history, shot specifications, and up to four relevant image references. Gateway also receives internal user and project identifiers and operational tags used for budgets, reliability, and usage tracking.

Every application-initiated Gateway request asks the provider not to use prompt data for model training by setting Vercel's disallowPromptTraining option. This request is not the same as zero data retention and does not guarantee that Gateway or an upstream provider retains no data. They may process or retain request data under their applicable terms for delivery, safety, abuse prevention, or legal compliance. Do not submit regulated or highly sensitive information to AI features.

Director's Canvas does not use your project content or AI conversations to train a Director's Canvas model. We may retain prompts, outputs, and usage records as part of your project and operational history so the Service can function and you can revisit your work.

06

How we disclose information

We disclose information only as needed for the following purposes:

  • Service providers: Clerk for authentication; Turso/libSQL for application data; Vercel for hosting, private Blob storage, AI Gateway, and—only with consent—Web Analytics and Speed Insights; and the AI model providers described above.
  • Legal and safety reasons: when reasonably necessary to comply with law, protect people or rights, investigate misuse, or secure the Service.
  • Business changes: in connection with a financing, reorganization, acquisition, or transfer of the Service, subject to appropriate confidentiality and notice where required.
  • At your direction: when you export, download, or otherwise ask us to provide content to you or a third party.

We do not sell personal information or share it for cross-context behavioral advertising.

07

Cookies and browser storage

Necessary cookies and local storage operate the site without analytics consent. Optional measurement tools load only after you choose “Allow all.” Your choice stays on this device and browser; it is not synchronized to your account.

ItemPurposeDuration
director_canvas_cookie_consentRecords “necessary only” or “allow all” on this device.365 days
Clerk cookiesAuthentication, session continuity, fraud prevention, and security.Session or provider-defined
themeKeeps your light, dark, or system theme preference in local storage.Until changed or browser storage is cleared
Vercel Web Analytics and Speed InsightsOptional aggregate audience and performance measurement.Loaded only while “allow all” is selected

You can reopen Cookie settings from the site footer or workspace topbar. Changing from “allow all” to “necessary only” reloads the page so optional measurement scripts are removed immediately.

08

Retention and deletion

We generally retain account data and project content while your account is active and for as long as needed to provide the Service, meet legal obligations, resolve disputes, prevent abuse, and maintain appropriate operational records. Retention by authentication, infrastructure, and AI providers is also governed by their terms and configurations.

Deleting a project removes that project's active application records and its project-specific private Blob media through the in-product deletion process. It does not delete your Clerk identity, account-level support records, or reusable library items. Limited backups, security logs, failed-job records, or information that law requires us to keep may persist for a reasonable period.

Director's Canvas does not currently offer self-service account deletion. To request closure of your entire account and deletion of associated application data, email joshuaalevine3@gmail.com. We may need to verify your identity before completing the request.

09

Security and international transfers

We use reasonable administrative and technical safeguards, including authenticated owner checks and private media delivery. No system is completely secure, and we cannot guarantee that information will never be lost, misused, or accessed without authorization.

The Service is operated from the United States and uses providers that may process information in the United States and other countries. Those countries may have different privacy laws from where you live. Where required, we and our providers rely on recognized transfer mechanisms and contractual safeguards.

10

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal a denied request or complain to a privacy regulator. You may withdraw optional analytics consent at any time without affecting earlier lawful processing.

Submit a request to joshuaalevine3@gmail.com. Describe the request and the email associated with your account. We may verify your identity and may decline or limit a request where permitted by law. Authorized agents should include proof of authority.

11

Adults only

The Service is not directed to children or anyone under 18, and we do not knowingly collect personal information from them. If you believe a person under 18 has provided information, contact us so we can investigate and delete it where appropriate.

12

Changes and contact

We may update this policy as the Service, providers, or law changes. We will post the revised policy with a new effective date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

Questions, complaints, account-deletion requests, and privacy requests may be sent to Joshua Levine at joshuaalevine3@gmail.com. For the rules governing use of the Service, see the Terms of Service.