Privacy Policy
Cloud Creator LLC · preprompt.studio
Ozu: Privacy Policy
Effective Date: June 12, 2026 Last Updated: August 9, 2026 Version: 1.2
Table of Contents
- Who We Are
- What We Collect
- How We Use Your Information
- How We Share Your Information
- Data Retention
- Your Rights and Choices
- Cookies and Tracking
- Children’s Privacy
- AI-Specific Disclosures
- International Data Transfers
- Security
- Changes to This Policy
- Contact Us
1. Who We Are
Ozu is operated by Cloud Creator LLC, a Wyoming limited liability company.
For purposes of data protection law (including GDPR where applicable), we are the data controller of your personal information.
Privacy Contact: Email: [email protected] Mailing: Cloud Creator LLC, c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801
2. What We Collect
2.1 Information You Give Us
Account Information When you sign up, we collect:
- Name or display name
- Email address
- Profile information if you sign in with Google (name, email, profile photo, Google Account ID)
- Password (stored as a cryptographic hash, we never store plaintext passwords)
Payment Information Payments are handled by Stripe, Inc. We don’t collect or store full card numbers. What we receive from Stripe:
- Last four digits of your card
- Card type and expiration date
- Billing country
- Stripe Customer ID
- Subscription status and plan
Content You Create When you use the Service, we store in your account:
- Project names and descriptions
- Scripts and text you submit for analysis
- AI generation prompts and parameters
- Generated images and storyboard frames
- Canvas layouts and node configurations
- Audio metadata (file names, BPM data, lyric sync data)
BYOK API Keys (if you enable BYOK) Your third-party API keys are stored encrypted in our database. They are never stored in your browser, and are accessed only by our server infrastructure to make API calls on your behalf.
Support Communications Messages and feedback you send us.
2.2 Information Collected Automatically
When you use the Service, we and our service providers automatically collect:
Usage Data
- Features used and actions taken in the app
- Credits consumed and types of operations performed
- Session duration
- Error and performance data
Device and Technical Data
- IP address
- Browser type and version
- Operating system
- Referring URL
- Date and time of access
Authentication Session Data Firebase Authentication stores a secure session token in your browser’s local storage. This token is used to verify your identity and expires after 1 hour (auto-refreshed while you’re active).
2.3 Information from Third Parties
If you sign in with Google, we receive your name, email address, Google Account ID, and profile photo. We don’t receive access to your Google Drive, Gmail, or other Google services.
3. How We Use Your Information
We use your information to:
| Purpose | Why We’re Allowed (GDPR Basis) |
|---|---|
| Create and manage your account | Contract performance |
| Authenticate your identity each session | Contract performance / Legitimate interests |
| Process subscription payments | Contract performance |
| Deliver AI generation and analysis features | Contract performance |
| Track credit usage and subscription limits | Contract performance |
| Store your project data across sessions | Contract performance |
| Send transactional emails (receipts, account notices) | Contract performance |
| Respond to support requests | Contract performance / Legitimate interests |
| Detect and prevent fraud and abuse | Legitimate interests |
| Improve the Service (aggregate, de-identified analytics) | Legitimate interests |
| Comply with legal obligations | Legal obligation |
We do not sell your personal information.
We do not use your content to train AI models. Your scripts, prompts, and generated assets are yours. We may use content you provide to improve and develop the operational quality of the Service. If that ever changes we will tell you first, and nothing of yours is included without your explicit approval. Generating your outputs requires sending content to third-party AI providers (Section 4.1), whose own data-use practices vary. See Section 9 for a per-provider summary.
3.1 What we record to improve the app
When you generate or approve something, we store a short structural summary of what happened. An allowlist in our code controls this: anything not on the list is discarded before it reaches storage.
What we record
- Project shape: genre, script word count, scene, shot, and beat counts, how many characters, props, and sets
- Shot shape: shot type, camera direction, framing, whether it has dialogue, beat duration
- What ran: which provider and model, which prompt template version, how many reference images
- What happened: approved or reworked, which attempt, time to decide, credits to approval
What we never record
- Your script text, dialogue, or prompts
- Your images, video, or audio, in whole or in part
- Your name, email, or account ID in readable form. Project, user, and asset identifiers are one-way salted hashes that cannot be reversed.
Because these records cannot be linked back to you, we keep them indefinitely.
4. How We Share Your Information
We share your data only in the following circumstances:
4.1 Our Service Providers (Sub-Processors)
We work with trusted third-party providers who process data on our behalf:
| Provider | What They Do | Data Shared |
|---|---|---|
| Google LLC (Firebase) | Account authentication, database (Firestore) | Account info, project data, usage data |
| Cloudflare, Inc. | Hosting, CDN, API proxy, file storage (R2), KV store, D1 | Network traffic, IP addresses, user assets, subscription state |
| Stripe, Inc. | Payment processing (web) | Billing info, subscription status, Stripe Customer ID |
| Apple Inc. | App distribution and in-app purchases (iPad app) | Purchase/transaction identifiers |
| Anthropic, PBC | AI text analysis (Ozu assistant) | Scripts and text submitted for analysis |
| OpenAI, L.P. | Image generation, 360° panorama generation | Generation prompts, reference images |
| EvoLink | AI generation gateway. Routes our Midjourney, Kling, Seedance/Seedream, Suno, Qwen and VideoRetalk jobs | Generation prompts, parameters, reference images/audio |
| ElevenLabs, Inc. | AI voice generation and audio tools | Dialogue text and reference audio |
| Replicate, Inc. | Music structure analysis, dialogue/foley separation | Production audio |
| Google LLC | AI audio and speech models | Audio and text submitted for those features |
| Blockade Labs, Inc. | Skybox generation | Environment/scene text prompts |
| World Labs, Inc. | 3D environment generation (not currently reachable in the app) | Panorama image inputs |
Each provider is subject to its own privacy policy and terms. Where required by law (including GDPR), we maintain Data Processing Agreements with our processors. The set of AI model providers changes over time as models are released and retired.
Note on training practices: Providers differ on whether their terms permit training on what we send them. Midjourney and Kling, both reached through our generation gateway, and World Labs, permit it. Models reached through the gateway are operated by third parties whose practices we don’t control. Every model in the app carries a mark showing where its provider stands; Section 9 lists them provider by provider.
4.2 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or if we have a good-faith belief that disclosure is necessary to:
- Comply with a legal obligation
- Protect the safety or rights of Ozu, our users, or the public
- Prevent fraud or illegal activity
4.3 Business Transfers
If Ozu is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We’ll notify you before your information becomes subject to a different privacy policy.
4.4 With Your Consent
We may share information in other ways with your explicit consent.
5. Data Retention
We don’t keep your information longer than we need to.
| Data Type | How Long We Keep It |
|---|---|
| Account information (name, email, UID) | Duration of your account + 30 days after deletion |
| Project data (scripts, assets, canvas layouts) | Duration of your account + 30 days after deletion |
| Payment and subscription records | 7 years from transaction date (tax and financial law) |
| Subscription consent records | 3 years from consent, or 1 year after cancellation (whichever is longer) |
| Support communications | 3 years |
| Fraud prevention and security records | Up to 3 years from incident |
| BYOK API keys | Until BYOK is disabled + 30 days for cleanup |
| Aggregate de-identified analytics | Indefinitely (cannot identify you individually) |
When you delete your account:
- Your account info and project data are deleted from active databases within 30 days
- Payment and subscription records are retained as required by financial and tax law
- Aggregate, de-identified analytics data may be retained indefinitely
6. Your Rights and Choices
6.1 All Users
Account Management: You can review and update your account info at any time in Account Settings.
Account Deletion: Delete your account from Account Settings or by contacting [email protected].
Email Opt-Out: Unsubscribe from non-transactional emails via the unsubscribe link in any such email. Transactional emails (receipts, critical notices) cannot be opted out of while your account is active.
6.2 California Residents (CCPA)
California residents have the following rights under the California Consumer Privacy Act (CCPA):
Right to Know: Request information about what personal data we’ve collected about you, why we collected it, and who we’ve shared it with.
Right to Delete: Request deletion of your personal information (subject to exceptions required by law).
Right to Correct: Request correction of inaccurate information we hold about you.
Right to Opt Out of Sale/Sharing: We do not sell your personal information and do not share it for cross-context behavioral advertising. You can submit an opt-out request at ozu.studio/legal/privacy#do-not-sell or by emailing [email protected]. We’ll confirm and process your request within 15 business days.
Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
Global Privacy Control (GPC): We honor the GPC browser signal as a valid Do Not Sell or Share request.
To exercise any of these rights, contact [email protected].
6.3 EEA, UK, and Swiss Users (GDPR)
If you’re in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under GDPR or equivalent law:
Right of Access (Art. 15): Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16): Request correction of inaccurate data.
Right to Erasure (Art. 17): Request deletion of your data where we no longer have a compelling reason to keep it.
Right to Restriction (Art. 18): Request that we limit how we process your data in certain circumstances.
Right to Data Portability (Art. 20): Request your data in a machine-readable format for transfer to another service.
Right to Object (Art. 21): Object to processing based on our legitimate interests.
Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time.
Right to Lodge a Complaint: You have the right to complain to your local data protection supervisory authority.
To exercise GDPR rights, email [email protected] with “GDPR Request” in the subject. We’ll respond within 30 days (extendable by 2 months for complex requests).
7. Cookies and Tracking
What we use:
- Firebase Authentication token: a session cookie stored in your browser’s local storage. It’s essential for keeping you logged in and expires hourly. This is not an advertising cookie.
- Cloudflare analytics: anonymized, aggregate performance and traffic data. No individual tracking.
What we don’t use:
- Third-party advertising cookies
- Cross-site behavioral tracking cookies
- Social media tracking pixels
You can clear cookies and local storage from your browser settings, but this will log you out of the Service.
For full details, see our Cookie and Analytics Disclosure.
8. Children’s Privacy
The Service is not directed to children under 13, and we don’t knowingly collect personal information from anyone under 13 (consistent with COPPA). The Service also requires users to be at least 18 to create an account.
If we learn we’ve inadvertently collected information from a child under 13, we’ll delete it promptly. If you believe we may have a child’s information, contact us at [email protected].
9. AI-Specific Disclosures
You’re interacting with AI. Ozu’s Assistant Director (Ozu) is powered by Anthropic’s Claude. Image, video, voice, panorama, and 3D-environment features are powered by third-party AI models reached either directly or through our generation gateway (Section 4.1).
Your content goes to third-party AI providers. When you use AI generation features, your prompts, scripts, reference media, and related inputs are transmitted to the relevant third-party service to generate your output.
We do not train on your content. Ozu does not use your scripts, prompts, or generated outputs to train any AI model. We may use content you provide to improve and develop the operational quality of the Service. If that ever changes we will tell you first, and nothing of yours is included without your explicit approval.
On Studio+ BYOK, generation runs on your own API key instead of our credits. The request is still made by our servers rather than from your device, and we don’t log the content of those calls.
About third-party training practices. The bold mark opening each row below is exactly the mark shown beside that provider’s models in the app: the app reads this table, so the two can never disagree. They describe each provider’s published terms and the account settings we maintain with them, as of the Last Updated date. They are not behavior we can observe inside a provider or guarantee on its behalf.
| Provider | What we send | Training |
|---|---|---|
| Anthropic, Ozu, script analysis | Scripts, text | Rules out training. Their terms rule out training on API content |
| OpenAI, images, 360° panoramas | Prompts, reference images | Rules out training. Their terms rule it out unless we opt in, which we have not |
| Google, image, video, music, speech | Prompts, reference media, audio | Rules out training. Their paid-tier terms rule it out. We are on a paid tier |
| xAI, image, video, speech-to-text | Prompts, reference images, audio | Rules out training. Requests held 30 days for abuse auditing, then deleted |
| ElevenLabs, voice | Dialogue text, reference audio | Rules out training. Their terms permit it by default. We have turned it off at the workspace level, so nothing you send is used for training |
| Replicate, audio analysis, dialogue separation | Production audio | No commitment. Their terms license customer data to “train and generate Customer Derivative Models” without defining that scope |
| Seedance / Seedream, via gateway | Prompts, reference media | No commitment. Any no-training commitment runs to the gateway operator, not to Cloud Creator |
| Suno, music, via gateway | Prompts, lyrics | No commitment. Reached through the gateway, so any commitment runs to the gateway operator rather than to us |
| Qwen, speech, via gateway | Dialogue text | No commitment. Reached through the gateway, so any commitment runs to the gateway operator rather than to us |
| Blockade Labs, skyboxes | Prompts | No commitment. Silent on training |
| Midjourney, images, via gateway | Prompts, reference images | Allows training. Their terms take a perpetual, irrevocable license over prompts and reference images, with no opt-out at any tier |
| Kling, video, via gateway | Prompts, reference media | Allows training. An opt-out exists, but it belongs to the gateway operator’s account rather than ours |
| World Labs, 3D environments | Panorama images | Allows training. Their terms permit it. Not currently reachable in the app |
A note on the gateway. Models marked “via gateway” are reached through EvoLink rather than a direct contract with the provider. Our agreement is with EvoLink, so we cannot audit or warrant what the underlying provider does with a request.
AI outputs may not be copyright-protected. Under US law, purely AI-generated works are generally not eligible for copyright protection. See our Terms of Service (Section 6.2) for the full disclosure.
AI outputs are not guaranteed. Generated images, text analyses, and other outputs are AI-generated creative tools, not verified facts. Don’t rely on them for legal, financial, medical, or safety decisions.
10. International Data Transfers
Ozu is based in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the United States.
For users in the EEA, UK, or Switzerland: we rely on Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of your personal data to the US, or the UK International Data Transfer Agreement (IDTA) as applicable.
11. Security
We protect your information using:
- HTTPS encryption for all data in transit
- Firebase Authentication for secure identity management
- Firestore security rules restricting database access to authenticated users only
- API keys stored encrypted at rest (not in your browser)
- Cloudflare infrastructure with DDoS protection
No internet transmission or storage is 100% secure. While we take reasonable precautions, we can’t guarantee absolute security. In the event of a breach affecting your rights, we will notify you as required by law.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated Policy at ozu.studio/legal/privacy with a new “Last Updated” date
- Notify you by email or prominent in-app notice
We encourage you to review this Policy periodically.
13. Contact Us
For general privacy questions: Email: [email protected]
For California (CCPA) requests: Email: [email protected], Subject: “CCPA Request”
For EU/UK (GDPR) requests: Email: [email protected], Subject: “GDPR Request”
Mailing address: Ozu / Cloud Creator LLC c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801
Drafted by General Counsel, March 16, 2026 (CB-298) Revised June 12, 2026 (CB-758): Wyoming entity + registered-agent address, iPad/Apple, current sub-processor list (EvoLink gateway, ElevenLabs, Google audio), per-provider training summary, training claim scoped to Cloud Creator.
Revised July 25, 2026: provider data-use audit. Corrected four inaccurate statements, the ElevenLabs zero-retention claim (never enabled, and enterprise-gated), BYOK calls described as going directly to the provider (our servers make them), xAI described as zero-data-retention (they rule out training; requests are held 30 days for abuse auditing), and Blockade Labs credited with 360° panorama generation (that routes to OpenAI). Added OpenAI, Replicate, and Midjourney as disclosed providers. Rewrote Section 9 as a per-provider table matching the marks now shown beside every model in the app. Added Section 3.1 describing the structural learning signals we record, which the previous “aggregate, de-identified analytics” line under-described. Opted out of ElevenLabs workspace model training.