Privacy Policy
Service operator: spinevfxbuddy
Version date: September 20, 2026
This Policy sets out the scope, purposes, retention arrangements and rights-request procedures for personal information processed through the SpineVFXBuddy website, account center, online effects editor and cloud workspaces. The Operator means the actual operator of the service; Users are the individuals using it. Third-party authentication, payment and other independent services are also subject to their providers’ privacy policies.
1. Account and authentication information
The Operator processes email addresses, display names, avatars, account identifiers and verification status to provide accounts and authentication. Passwords are stored as hashes; two-factor authentication uses the security information needed for verification. Google sign-in provides the account identifier, email, name and avatar authorized by the User, without providing the Google password. Session records may include IP addresses, browser information and creation and expiry times for session management and security.
2. Projects, uploaded files and workspace information
When Users actively save or upload to the cloud, the Operator stores projects, files, thumbnails, file-size metadata, membership, roles and invitation records. Browser editing alone does not automatically create a cloud project. Shared content is accessible according to member roles and remains with the team after ownership transfer. Avatar processing standardizes size and removes original image metadata.
3. Server generation and export-license records
Some exports and previews submit project and emitter settings, skeletal animation data, layers and tracks, keyframes, duration, frame rate, export settings and resource metadata for server computation. Generation requests filter some original resources and interface state; this does not mean that all original content is excluded. Not saving a cloud project does not mean that no server processing occurs. Cloud saves, asset uploads and server generation are separate operations. Export licensing processes the workspace, declared purpose, file digest, policy version and issuance time. Licensing locally captured images or videos does not require uploading the media file itself. Users should avoid unrelated personal information in names or resource metadata.
4. Transaction and payment records
Creem handles checkout and payments. The Operator stores product, order, amount, currency, subscription, seat, transaction and refund records to reconcile transactions, grant access and handle billing. Payment providers process card and wallet credentials; the account database does not store full card numbers or wallet passwords. Alipay and other payment methods depend on the options Creem presents for the particular product, region and transaction.
5. Service notices and user communications
Verification, sign-in links, password resets, security notices and team invitations are service communications. Production email delivery uses Resend, which processes recipient addresses and necessary message content. Contact-form email, name and message fields are used to handle requests. Marketing subscriptions separately record subscription state, consent time and unsubscribe information; Users may end those subscriptions through the email unsubscribe link.
6. Purposes, grounds and access controls
The Operator processes information as necessary to provide and maintain the service, perform its arrangements with Users, authenticate accounts, enable collaboration, administer billing, address security issues, handle inquiries and meet legal obligations. Where consent is legally required, the applicable consent process is followed. Administrators access records only as necessary for support, security, financial or administrative duties. The Operator does not sell personal information or publish private cloud projects as public assets. Official assets and user projects are managed separately.
7. Cookies, browser storage and analytics
Necessary session cookies and browser storage support authentication, security checks and preferences. When Vercel Analytics is enabled, aggregate public-page visits, device and approximate location information support website operation and improvement, without advertising profiles. Blocking necessary cookies may prevent authentication and account functions. Storage and controls are further described in the Cookie and Browser Storage Notice.
8. Infrastructure, providers and cross-border processing
Vercel hosts the website; deployed databases and object storage hold business records and uploads. Google, Creem, Resend and infrastructure providers process necessary information according to their service roles. The location of development does not determine all storage locations. Depending on deployment and provider locations, processing may occur outside the User’s region. The Operator complies with applicable obligations for cross-border processing. Users may contact the Operator for actual storage locations, recipients and relevant safeguards.
9. Cloud projects after expiry or downgrade
Personal projects within the Free storage allowance remain available under Free rules after expiry or downgrade. For the first 30 days of excess personal storage, viewing, downloading and deletion remain available; new uploads and saves that increase usage pause. For the first 30 days after a Team plan expires, existing members can view and download according to their roles; cloud editing, uploading and invitations pause. Renewing or resolving excess usage during this period restores the corresponding functions when plan conditions are met. Unresolved projects freeze after 30 days and are retained until day 90 from expiry or downgrade, not 90 additional days after the first 30. After day 90, unresolved projects may enter cleanup, with email and an account notice identifying the scope at least 7 days before intended cleanup. Downloading an existing file does not grant a new commercial license; file retention and commercial licensing are separate.
10. Retention and account deletion
Account information is retained for the period necessary to provide the service. Account deletion requires prior transfer of teams owned by the User. After personal subscription renewal cancellation is confirmed, the account is deleted, sessions expire and personal files enter background cleanup; transferred team data remains. Records still necessary for finance, refunds, fraud prevention, audits, disputes or legal obligations are retained with restricted access for the relevant period. Backup copies are processed through rotation; deletion does not immediately clear all media. Information no longer needed is deleted or anonymized. The 30/90-day schedule applies only to the specified cloud projects, not uniformly to orders, logs, temporary export data or backups, whose retention follows their necessary purposes and applicable law.
11. Personal-information rights and procedures
Settings allow Users to edit profiles, manage sessions, enable two-factor authentication, disconnect eligible login methods and request deletion. To the extent provided by applicable law, Users may request access, correction, export, deletion or restriction of personal information, or withdraw consent for consent-based processing. The Operator may verify identity proportionately and handles requests or explains refusals under applicable law. Withdrawal does not affect prior lawful processing or processing necessary on another lawful basis.
12. Security measures and policy revisions
The Operator uses access controls and transport protection to reduce information-security risks, without guaranteeing absolute network security. Security incidents are handled, and notice obligations fulfilled, as required by applicable law. Material Policy changes are published through the website or an appropriate channel; renewed consent is obtained where legally required. This page identifies the applicable version date.
13. Minors and consent records
Registration and use are unavailable to children under 14. Users aged 14–17 require guardian consent and supervision, with separate guardian authorization for paid purchases; Users aged 18 or over must have the capacity required by applicable law. To verify eligibility and acceptance, the Operator processes age-group declarations, necessary guardian contact and confirmation records, policy versions and timestamps, rather than full birth dates. Purchases have specific authorization records; email confirmation alone does not establish an actual guardian relationship. Guardians may request verification, correction, withdrawal or handling of an ineligible registration. Functions requiring guardian consent cannot continue on that consent after withdrawal. Ineligible or unauthorized use should be reported through the contact channel.
Notices, inquiries and rights requests
Account, billing, personal-information and infringement matters should be submitted through the contact page. Users should provide the relevant account email, order reference or facts. The Operator may verify identity and relevant records to the extent necessary to handle the request. Passwords, verification codes and full payment credentials must not be submitted.
Contact the Operator