Privacy policy
Last updated October 4, 2026
Privacy policy
This policy explains what information Inkreel collects, what it is used for, who receives it, how long it is kept and what choices you have. Inkreel is operated by Blackbox Entertainment ("we", "us"). Questions and requests go to contact@inkreel.app.
1. What we collect
Account details
- Your email address and your role in a workspace.
- Your password, stored only as a one-way hash that cannot be turned back into the password.
- Two-factor sign-in data: the authenticator secret and hashed backup codes.
- If you sign in with Google: your Google account identifier and email address. We do not receive your Google password or contacts.
- Sign-in records: when you signed in, failed sign-in attempts, and sessions.
- Which version of the terms you agreed to, and when.
What you put into the service
- Studio and project material: IP bibles, scripts, lyrics, descriptions, storyboards and settings.
- Files you upload: songs, images, video and reference sheets.
- What the service generates for you: stills and other media, with the instructions (prompts) used to make them.
- Marks and notes you add when asking for changes.
Keys
- AI provider API keys you save. These are stored encrypted. After saving, only the last four characters are displayed.
Usage and cost records
- A log of each paid generation: what kind, which model, its cost, when, and which team member started it.
- An activity log of important actions in a workspace (for example invitations, approvals, key changes).
Billing
- Your subscription status, plan, renewal date, and the customer and subscription identifiers given to us by the payment provider. We do not receive or store your card number.
Safety checks
- The result of the automatic safety check on each picture and video in a workspace (see section 2), and, for anything it locks, a record of the file, who made or uploaded it and when, how it was made, and what our staff decided.
Support
- Messages you send through Contact support and our replies, with your email address, workspace name and role.
Waitlist
- The email address you enter, what you said you make (if you chose to), and whether you confirmed the address.
Site traffic
- A count of how many pages were opened in each hour, and how many of those by signed-in users. This count does not include IP addresses, device identifiers or any way of telling one visitor from another.
- Our hosting provider keeps short-lived technical logs that include IP addresses, as needed to run and protect the service.
Cookies
- One cookie that keeps you signed in, and a short-lived cookie used only during Google sign-in. We do not use advertising or tracking cookies and do not use third-party analytics.
2. What we use it for
- To provide the service: storing your work, generating what you ask for, showing it to your team.
- To keep accounts secure: sign-in, two-factor checks, detecting misuse.
- To handle subscriptions, access and billing questions.
- To send service emails: confirming your address, password resets, team invitations, notices that access or data is about to end, and replies to support requests. We send waitlist emails only to addresses that were confirmed. We do not send marketing email without your agreement.
- To answer support requests. Staff may use an AI model to draft a reply; the model is given the text of the request and thread, not your email address or workspace name.
- To understand overall use of the platform through counts and totals (number of workspaces, storage used, page views per hour).
- To keep the service safe. An automatic safety check looks at the pictures and videos in every workspace (stills, Cast pictures, clips and uploads; a few frames of each video) for sexual content and anything sexual involving minors, which the Content rules forbid. It runs every few hours, and each file is checked once. Anything it finds is locked straight away so it can't be opened, downloaded, exported, published or reused, and our staff review it.
- To meet legal obligations and enforce our terms.
We do not sell personal information, do not use your content to train AI models, and do not use it for advertising.
3. Who receives information
We share information only with the companies that help us run the service, and only as needed for that:
- Hosting and storage: Fly.io hosts the application and stores the data, in the United States.
- AI model providers: when you generate something, your instructions and the reference images for that request are sent to the provider whose key you connected (currently OpenRouter, which routes to the model you chose). That provider's own privacy terms apply to what it receives.
- Safety checks: for the automatic safety check, each picture (or a few frames of each video) and its description are sent, through our own OpenRouter account, to the safety model we choose. That provider's own privacy terms apply to what it receives.
- Child safety reports: if we find apparent child sexual abuse material, we report it, with the account details and information needed for the report, to the National Center for Missing & Exploited Children (NCMEC), as US law requires. NCMEC may pass reports to law enforcement.
- Payments: Stripe processes subscriptions as seller of record and receives your payment details directly.
- Email: Resend delivers our emails and receives the recipient address and the email content.
- Sign-in: Google, if you choose to sign in with Google.
- Network services: Cloudflare provides domain and network services for inkreel.app.
Our staff can see account facts and usage totals in order to give support (for example your email address, plan, sign-in dates, storage used, and whether a key is connected). They cannot view saved keys, and the administration tools do not open the studios inside a customer workspace. The only media from inside a workspace that staff can see are files the safety check has locked, shown blurred so staff can decide whether it was a false alarm, and videos published to or reported in the public gallery.
We may disclose information if the law requires it, or to protect the rights, safety or property of our users, the public or ourselves. If the business is sold or merged, information may transfer to the new owner under this policy.
The service is run from the United States. If you use it from another country, your information is processed in the United States.
4. How long we keep it
- While a workspace is active: for as long as it exists.
- When access ends (a subscription is cancelled or lapses, a trial or beta ends, or a free sign-up never subscribes): the workspace becomes read-only and can still be viewed and downloaded. We email the owner the date its data will be removed, 30 days later by default, and send reminders 7 days and 1 day before. Subscribing again within that time keeps everything.
- Removal: on that date the workspace is closed. Its files, database and accounts are then permanently erased 7 days later.
- On request: an owner can ask us to erase a workspace sooner; we will do so without the waiting period.
- Individual files you delete from the Library are moved to a holding area inside the workspace and are erased when the workspace is erased, or sooner on request.
- Support requests are kept while the workspace exists and are erased when the workspace is erased. We may remove individual requests sooner.
- Waitlist entries are removed when you are invited, when you use the link in any waitlist email to leave, or on request.
- Payment records are kept by Stripe under its own policy, and by us as long as tax and accounting rules require.
- Backups may hold erased data for up to 30 days before they expire.
- Files the safety check locks stay locked until our staff decide. A false alarm is unlocked; sexual content is removed. Apparent sexual content involving a minor is not deleted: it is preserved, separately from the workspace and even if the workspace is erased, for as long as the law requires after it is reported.
5. Security
- Connections to the service are encrypted.
- Passwords are stored as one-way hashes. AI provider keys are encrypted with a master key that is held separately from the database, and are never displayed in full to anyone.
- The service has to be able to use your AI provider key in order to make what you ask for, so it is protected by encryption and restricted access rather than being unreadable to the service itself. Use a key made only for Inkreel, set a spending limit on it at your provider, and revoke it there if you stop using Inkreel.
- Two-factor sign-in is required for password accounts and for all staff.
- Each workspace's data is stored separately from every other workspace's.
- Staff access is limited by role and their actions are logged.
No system is perfectly secure. If we learn of a breach affecting your information we will tell you as the law requires.
6. Your choices and rights
- See and change: your account page shows your email address and lets you change it and your password.
- Download: everything your workspace has made can be downloaded from the Library.
- Delete: an owner can ask us to erase the workspace; a team member can leave a workspace from their account page.
- Leave the waitlist: use the link in any waitlist email.
- Depending on where you live, you may have further rights, such as to ask for a copy of your personal information, to have it corrected or erased, or to object to or limit certain uses. Write to contact@inkreel.app and we will respond within the time the law requires. We will not treat you differently for using these rights.
7. Children
Inkreel is for adults. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, tell us and we will delete it.
8. Changes
We may update this policy. If a change is significant we will email workspace owners and show a notice in the service before it takes effect. The date at the top shows when it was last changed.
9. Contact
Blackbox Entertainment contact@inkreel.app