1. Introduction
SunSlate ("we," "our," or "us") operates the web application at sunslate.app. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. By accessing or using SunSlate, you agree to this policy. If you do not agree, please discontinue use.
2. Information We Collect
We collect the following categories of personal data:
- Account Data: Name, email address, and authentication credentials when you create an account.
- Project Data: Scripts, locations, shoot schedules, crew information, budgets, and other content you input into the platform.
- Usage Data: How you interact with the platform, including pages visited, features used, and actions taken.
- Device & Technical Data: IP address, browser type, operating system, and device identifiers.
- AI Interaction Data: Natural-language commands and queries you submit to our AI features, including the command bar, location scout, and script parsing.
3. How We Use Your Information
- To provide, maintain, and improve the SunSlate platform and its features.
- To process your AI-powered requests (location scouting, script parsing, command bar actions).
- To send transactional communications such as call sheets, crew invitations, and weather alerts.
- To monitor usage patterns and prevent abuse or unauthorized access.
- To comply with legal obligations.
4. Third-Party Data Processing
We use the following third-party services that may process your data:
- Anthropic — We send text content (commands, scene descriptions, location notes) to Anthropic's Claude API to power the AI command bar, scene breakdown, location note enhancement, and location scouting features. Anthropic processes this data as a subprocessor. Anthropic does not use API traffic to train its models. See Anthropic's Privacy Policy.
- OpenAI — OpenAI's API is retained as a fallback provider. In the event of a primary provider outage, certain AI requests may be routed to OpenAI. OpenAI does not use API traffic to train its models. See OpenAI's Privacy Policy.
- Google (Firebase, Gemini, Google Ads) — We use Firebase for authentication and database, Google Gemini for certain AI features, and Google Ads for marketing measurement. Google Ads may set cookies (e.g.
_gcl_*) on the marketing site to attribute ad-driven signups. We also use Google Ads Enhanced Conversions, which sends a one-way SHA-256 hash of your email address to Google solely for matching ad clicks to signups — Google cannot reverse the hash to obtain your email, and we do not send any other personal data through this channel. See Google's Privacy Policy and Google Ads Enhanced Conversions documentation. - Vercel — Our platform is hosted on Vercel. See Vercel's Privacy Policy.
- Twilio — Used to send SMS notifications (call sheets, crew alerts). See Twilio's Privacy Policy.
- Resend — Used to send transactional emails. See Resend's Privacy Policy.
5. SMS & Mobile Messaging
SunSlate uses SMS (text messaging) to deliver transactional notifications related to your film productions, including call sheets, shoot-day reminders, weather alerts, crew announcements, and attendance confirmation links. The following disclosures apply to all SMS messaging.
- Opt-In. You provide your mobile phone number voluntarily by (a) saving it to your SunSlate profile at sunslate.app/dashboard/profile, or (b) entering it in the in-app SMS opt-in prompt shown after sign-in. By submitting your phone number through either path, you agree to receive SMS messages from SunSlate related to the productions you are part of.
- Message Types. Messages are transactional only: call sheet notifications, shoot-day reminders, weather alerts, crew announcements, and attendance confirmation links. SunSlate does not send marketing or promotional SMS.
- Message Frequency. Message frequency varies based on your production schedule. A typical active user receives approximately 0–10 messages per active shoot day. Users without active productions receive no SMS messages.
- Message and Data Rates. Message and data rates may apply, as set by your mobile carrier. SunSlate does not charge for SMS messages, but standard carrier rates may apply on your wireless plan.
- Opt-Out. You may opt out of SMS messages at any time by replying STOP to any SunSlate message. You may also remove your phone number from your account at any time via the Profile page.
- Help. Reply HELP to any SunSlate SMS to receive help information, or contact us at support@sunslate.app.
- Sharing. Mobile information and messaging consent are not shared with third parties or affiliates for marketing or promotional purposes. Your phone number is transmitted only to Twilio, our SMS carrier, solely for the purpose of delivering the messages described above. Twilio's handling of this data is governed by Twilio's Privacy Policy.
- Carrier Disclaimer. SunSlate is not responsible for delivery delays, undeliverable messages, or messaging fees imposed by your mobile carrier. Mobile carriers are not liable for delayed or undelivered messages.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide services. You may request deletion of your account and associated data at any time by contacting us. Upon deletion, we will remove your data within 30 days, except where retention is required by law.
7. Data Security
We implement industry-standard security measures including encrypted data transmission (TLS 1.2+), AES-256 encryption at rest via Google Cloud / Firebase, role-based access controls enforced server-side, and project-scoped Firestore security rules. No method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security. For a detailed explanation of our security practices, see our Security page.
8. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access and receive a copy of your personal data.
- Rectify inaccurate or incomplete data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Data portability — receive your data in a structured, machine-readable format.
To exercise these rights, contact us at legal@sunslate.app.
9. Cookies
SunSlate uses essential cookies for authentication and session management. On marketing pages (sunslate.app landing, /signup, /login, /privacy, /terms), Google Ads may set advertising cookies for ad attribution. Third-party services (Firebase, Vercel) may set their own cookies as described in their respective privacy policies. We do not use cross-site behavioral tracking or sell data to third parties.
10. Children's Privacy
SunSlate is not intended for use by individuals under 13 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date. Continued use of SunSlate after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or your data, contact us at: