Scriptly Privacy Policy
Last updated: July 5, 2026
Scriptly (scriptlyai.app) is a chat-directed AI video studio. You upload photos, describe what you want, and Scriptly generates videos with consistent characters — often built from photos of you and your family. That makes privacy a core product concern, not a footnote, and this page explains plainly what we collect, what we do with it, and what we will never do with it.
The data controller for Scriptly is Boby AI Yazılım A.Ş., registered in Istanbul, Türkiye. You can reach us any time at [email protected].
This policy works together with our Terms of Service and our Refund Policy.
What we collect
- Google account basics. Scriptly sign-in is Google-only. When you sign in, we receive your email address and name from Google. We do not see or store your Google password.
- Photos you upload and prompts you write. The photos you upload (for casting characters) and the text prompts and chat messages you send to direct your videos.
- Generated media. The reference sheets, storyboards, images, clips, and videos Scriptly creates for you.
- Credit ledger and purchase history. A record of your credit balance, what each generation cost, and your purchases. Your card details never touch our servers. Payments are processed by Paddle, which acts as merchant of record (the seller of record for your transaction) and handles all payment data under its own buyer terms.
- Product analytics events. We use PostHog to record usage events — things like "render started," "render completed," "checkout started." These events record what happened, not what you made: they do not include your prompt text or your photos.
- Server logs and IP addresses. Standard server logs, including your IP address, used for abuse prevention and rate limiting.
- Safety and moderation records. When a generation is blocked by a safety system, that event is recorded against your account as a strike (your credits for the blocked generation are refunded automatically — see the Refund Policy). Three strikes within 30 days trigger the human account review described in our Terms of Service.
How your content is processed
When you generate something, here is exactly where your content goes:
- Google Cloud AI services. Your uploaded photos and prompts are sent to Google's AI models running in Google Cloud — Gemini, Veo, and Imagen, plus Google's text-to-speech and music models — to generate your video. This is the core of the product: your content has to reach these models for generation to happen.
- Bunny.net CDN. Your uploaded and generated media is stored on and served from Bunny.net's content delivery network.
- Neon Postgres. Our database — your account, projects, prompts, and credit ledger — runs on Neon Postgres in the United States.
Photos of real people (likeness)
Photos of real people get specific rules and specific handling:
- Consent is asserted at upload. By uploading a photo of a person, you assert that it is you, or that you have that person's permission to cast them. This is a condition of our Terms of Service.
- Minors. You may not cast anyone under 18 who is not your own child. Full stop.
- Deletion wins. When you delete an uploaded photo, the reference sheets derived from it are deleted on the same sweep — deleting the source deletes what was built from it.
- Their face, their call. If you are pictured in someone else's Scriptly content and want your likeness removed, email [email protected]. We honor likeness-removal requests from the person pictured without arguing about who uploaded what.
What we do NOT do
- We do not sell your data. To anyone, for anything.
- We do not train our own models on your photos, prompts, or generated media. Your content is sent to Google's AI models to generate what you asked for, and Google's handling of that content — including any use for model training — is governed by the Google Cloud terms under which we use those services.
- We do not run ads or share your data with advertisers.
Service providers we use
We use a small set of infrastructure providers to run Scriptly. Each processes your data only for the purpose listed:
| Provider | What it does with your data |
|---|---|
| Google Cloud | Runs the AI models (Gemini, Veo, Imagen, text-to-speech, music) that process your photos and prompts to generate your media; provides Google sign-in |
| Paddle | Merchant of record — processes your payments and handles all card and billing data; we never receive card details |
| Bunny.net | Stores and serves your uploaded and generated media via CDN |
| Neon | Hosts our Postgres database (account data, projects, credit ledger) in the United States |
| PostHog | Product analytics — usage events (what happened, not what you made) that do not include your prompt text or photos; US cloud |
| Cloudflare | Sits in front of our infrastructure for network security and traffic protection, and routes email to [email protected] |
Where your data lives
Scriptly is a US-focused product, but its infrastructure spans systems in the United States and the European Union. Rather than a vague blanket statement, here is where each system runs:
- Database (Neon Postgres) — United States (us-east-1). Your account, projects, prompts, and credit ledger.
- Product analytics (PostHog) — United States. Usage events run on PostHog's US cloud.
- AI generation (Google Cloud) — currently an EU region. Your uploaded photos and prompts are processed by Google's AI models in Google Cloud.
- Application servers — currently hosted in the European Union.
- Media (Bunny.net CDN) — global. Your uploaded and generated media is served through Bunny.net's content delivery network, which caches media at edge locations near the people viewing it.
Whichever country you use Scriptly from, your data is transferred to and processed in the United States and the European Union as described above.
Retention and deletion
- Account data is kept for as long as your account exists.
- Deletion requests are honored: email [email protected] and we will delete your account and your content. Requests are handled manually through support today; self-serve export and deletion tooling is planned.
- Deleted uploads take their derived reference sheets with them on the same sweep, as described above.
- Server logs and IP addresses are kept for abuse prevention and operations and are deleted on rotation after 30 days.
- Analytics events (PostHog) are retained for as long as your account is active; when your account is deleted, we delete the associated analytics identity and its personal data.
- Payment records held by Paddle as merchant of record are governed by Paddle's own terms and retention obligations.
Children
You must be at least 18 years old to hold a Scriptly account. Separately, and regardless of account age: no casting of minors who are not the user's own child (see the likeness section above and our Terms of Service).
Purchases and refunds
Purchase and credit questions — including our automatic-refund rules for failed generations — are covered in the Refund Policy. Payment data itself is handled by Paddle as described above.
Changes to this policy
If we change this policy, we will update it here and change the "Last updated" date at the top. For material changes — anything that changes what we collect or how we use it — we will tell users directly rather than relying on a silent edit.
Contact
Privacy questions, deletion requests, likeness-removal requests: [email protected].