Privacy Policy
Last updated: August 5, 2026
This policy explains what Unstill collects, why, and who touches it. Short version: we collect the minimum needed to run accounts, payments, and generation — and we don't sell any of it.
1. What we collect
- Account data — email address, optional name, phone number (phone sign-in only). Passwords are stored as scrypt hashes; SMS codes and email tokens as SHA-256 hashes. We never store plaintext secrets.
- Your content — prompts, briefs, uploaded reference images (processed for generation, not retained as originals), saved projects, and pieces you explicitly share.
- Usage records — an append-only log of billable actions and purchases (action type, video, timestamp) for billing integrity and abuse prevention.
- Payment data — handled entirely by Razorpay. We receive only your email, the plan purchased, and payment status — never card numbers.
- Cookies — a signed session cookie for login, a first-party referral cookie when you arrive from a shared piece, and Google Analytics' own first-party measurement cookies. No advertising or cross-site tracking cookies.
- Site analytics — Google Analytics 4 records page views, referrer, approximate location and device type. It is not linked to your account, and Google's advertising and cross-site features are switched off everywhere.
Analytics consent. In the EEA, the UK and Switzerland, analytics cookies are blocked until you accept them — until then Google receives only anonymous, cookieless pings. Elsewhere they are on by default. Either way you can change your mind at any time with the link in the footer of any page.
2. How we use it
- Operating the Service: authentication, billing, saving and sharing your work.
- Generation: your prompts and reference images are sent to the AI providers below to produce your output.
- Transactional messages only — verification links, password resets, OTP codes, receipts. No marketing without separate opt-in.
- Safety: rate limiting and abuse detection using IPs and usage patterns.
- Understanding, in aggregate, which pages people reach and where they came from, so we know what to build next.
3. Processors we rely on
- Supabase — database (accounts, purchases, projects, shares).
- Razorpay — payments and subscriptions.
- Google AI — text/vision generation of briefs and
.unstillfiles. - Google Analytics — aggregate site traffic measurement (pages viewed, referrers, device, coarse location).
- ElevenLabs — narration text-to-speech.
- MSG91 — SMS delivery of sign-in codes (phone number + code only).
- Resend — transactional email delivery.
- Hosting infrastructure (e.g. Vercel) — request logs including IP addresses.
Each processes data only to provide its function, under its own privacy terms. If you bring your own API keys, your prompts go to those providers under your agreements with them.
4. Sharing & publicity
Pieces you publish via share links or the community gallery are public — title, view count, and the playable file. Everything else is private to your account. We disclose data only if legally compelled, and we'll tell you unless prohibited.
5. Retention & deletion
- Account data and projects: kept while your account exists.
- OTP codes and email tokens: minutes to hours (single-use, short expiry).
- Usage logs: up to 24 months, for billing disputes and abuse prevention.
- Email vd@frugalfounder.in to export or delete your data — we complete deletion within 30 days (Razorpay records are retained as required by financial law).
6. Security
Transport is TLS everywhere. Database access is server-side only with row-level security enabled. Passwords are scrypt-hashed, API keys and one-time codes SHA-256-hashed, protected downloads AES-256-GCM encrypted. No system is perfect; report vulnerabilities to the email below.
7. Children
The Service is not directed at children under 13, and we don't knowingly collect their data.
8. Changes & contact
We'll announce material changes on the site or by email. Data controller and contact for all privacy matters: vd@frugalfounder.in.