ObjectCinema
Terms Privacy
Back to site

Object Cinema · Dream Reels LLC

Privacy Policy

Effective 6 September 2026 · Version 1.0

This policy explains what Object Cinema collects, why, who else sees it, how long we keep it and what you can ask us to do about it. Object Cinema is operated by Dream Reels LLC, a Kansas limited liability company. Questions and requests: [email protected].

This is a notice, not a consent form. Agreeing to our Terms of Service is not agreement to every use of personal data described here; where the law requires your consent for something specific, we ask for it separately.

The short version. We collect what we need to run your account and make your images. To make them, your product photographs are sent to three AI providers — OpenAI, Google and fal.ai — because that is where the generation happens. We do not run advertising trackers or analytics. We do not sell your data. We use one cookie, to keep you signed in.

1. What we collect, and why

Account information — your name, email address and a password. The password is stored only as a salted scrypt hash; we cannot read it. We need this to identify you, sign you in and contact you about your account. We do not currently verify email addresses, so an address in our records is the one that was typed in, not one we have confirmed.

Subscription and transaction information — your plan, billing period, renewal date, credit balance and a complete history of every credit granted, spent, returned or expired. We also store the identifiers Stripe gives us for your customer record and subscription. We never see or store your card number; card data goes directly to Stripe.

Uploaded photographs and reference materials — the product photographs you upload, and any inspiration or reference images. These are the raw material the Service works from.

Product descriptions and creative instructions — what you type about your product, your creative brief, the things you ask us to avoid, and your saved visual directions and brand notes. The Service also stores what the AI reads off your product label — a transcription of the text printed on the packaging — because it is used to check that generated frames reproduce the label correctly.

Generated images and video — everything the Service produces for you, including intermediate concept frames and per-shot files, and the full history of earlier versions of a piece. The Service does not currently produce audio.

Technical data — our web server (nginx) and Cloudflare record standard request logs, which include IP addresses. The application itself writes a small operational log containing internal record identifiers and provider request identifiers; it does not log email addresses, passwords, prompts, briefs or image content. There is no product analytics or event-tracking system.

Support communications — if you email [email protected], we keep the message so we can answer it and refer back to it.

We collect all of this because it is necessary to provide the Service you have asked for and to bill you for it. Where the GDPR or UK GDPR applies, our legal bases are performance of a contract (running your account and generating your images), legal obligation (tax and accounting records) and legitimate interests (security, fraud prevention and keeping the Service working).

2. Who else receives it

We use the following providers. Each receives only what it needs.

Generation providers — these receive your photographs

OpenAI (United States) — image generation. Receives your uploaded product photographs and the prompt text built from your brief. OpenAI's published API terms state that it does not train on API inputs or outputs unless the customer opts in, and that it may retain inputs and outputs for up to 30 days for abuse detection.

Google (Gemini API) — used to check photo coverage, propose creative directions and verify that generated frames reproduce your label correctly. Receives your product photographs, your inspiration images and your text. Google's Gemini API terms distinguish a paid tier, on which Google states it does not use prompts or responses to improve its products, from an unpaid tier, on which it does. Google's abuse-monitoring documentation describes retention of request data for 55 days. We have not independently verified which tier our project is billed under, so we are not making a training claim on Google's behalf. We will update this page when we have confirmed it.

fal.ai (United States and other countries) — runs the video model and hosts the files the model needs. Your product photographs are uploaded to fal's storage and referenced by URL for as long as the Service uses them. Two facts about fal that we think you should know rather than have buried: files on fal's CDN are, by fal's own documentation, publicly accessible to anyone who has the link unless access controls are configured, and fal transmits your content onward to the third-party model provider whose model is being run. fal's API terms state that it does not use customer content to train its own products, with an exception for models it marks as not yet enterprise-ready. fal retains request payloads for 30 days by default; retention of generated media is a per-request setting rather than a fixed period.

Kling / Kuaishou — the video model itself, reached through fal. Your product photographs reach this model as part of running it. We do not have a direct contract with the model developer and cannot make representations about its retention or training practices.

Infrastructure and business providers

Amazon Web Services — hosting. All of your account data, uploads and generated files are stored on a server in the AWS us-east-1 region in the United States. This server is shared with another product operated by the same company, Dream Reels; the two applications run under separate system users, with separate files, separate databases and separate credentials, but they are on the same machine. That is process separation, not infrastructure isolation, and we would rather say so than imply more than is true.

Cloudflare — sits in front of the site providing DNS, TLS and protection against attack. Cloudflare sees the metadata of every request, including IP addresses.

Stripe — payments. Stripe receives your name, email address and our internal account identifier, and it collects your payment details directly. Stripe acts in two capacities: as our processor when handling a transaction on our instruction, and as an independent controller for its own fraud prevention, regulatory compliance and service improvement. Stripe publishes its own privacy notice and sub-processor list.

Google Fonts — the site loads its typefaces from Google's font servers. This means your browser makes a request to Google on every page load, which necessarily discloses your IP address and browser user-agent to Google. We are looking at hosting the fonts ourselves to remove this.

What we do not use

There is no analytics platform, no advertising pixel, no Meta Pixel or Conversions API, no error-monitoring service, no session recording, no A/B testing tool, no chat widget and no third-party marketing tool anywhere in the Service. We have checked the code rather than assumed. There is also currently no email-sending service, which means we cannot send you transactional or notification email; if you need to reach us, email [email protected].

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We run no advertising technology that would make such a disclosure necessary.

We may also disclose information if we are legally required to, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to it.

3. International processing

Our servers are in the United States. Our providers are US-headquartered and may process data in the United States and elsewhere; fal's privacy policy states its servers are located in the United States and other countries. If you are in the EEA or the UK, using the Service therefore involves transferring your data to the United States. We rely on our providers' standard contractual clauses and equivalent transfer mechanisms where they offer them. We have not completed a formal transfer-impact assessment, and we say that plainly rather than implying a compliance posture we have not built.

4. How long we keep things

WhatHow long
Account record, plan, credit historyWhile your account is open
Uploaded photographs and reference imagesWhile your account is open
Generated images and video, and version historyWhile your account is open
Saved products, directions and brand notesWhile your account is open
Server and application logsApplication log rotates at 7 days; Cloudflare and nginx logs follow their own retention
Billing recordsAs long as tax and accounting law requires
Backups of the database14 nightly snapshots, then overwritten
Support emailWhile needed to answer, and for our records

Backups contain account records — including email addresses, password hashes, Stripe identifiers and credit history — but not uploaded photographs or generated media. They are held on the same server and are not encrypted beyond compression; access to the server is restricted to key-based administrator login.

5. Deleting your data

Cancelling a subscription is not the same as deleting your account. Cancelling stops billing and ends access at the end of the paid period; your data stays until you ask for it to go.

To delete your account and content, email [email protected] from the address on the account and say so. We will confirm and remove your uploads, generated results and account record from our live systems within 30 days.

There is no self-service delete button in the Service yet; the request is handled by hand. That is a real limitation and we would rather state it than describe a feature we have not built. You can, today, delete individual uploaded photographs, individual inspiration images and saved directions from within the Service.

What deletion does not reach: backups roll off on their own 14-night cycle rather than being individually edited; billing records are kept as the law requires; and content already sent to OpenAI, Google, fal and the model providers is subject to their retention, which we cannot shorten on your behalf.

6. Your rights

Depending on where you live you may have the right to know what we hold, get a copy of it, correct it, delete it, restrict or object to processing, withdraw consent, and not be discriminated against for exercising any of these.

If you are in California, you have the rights to know, delete, correct and opt out of sale or sharing under the CCPA/CPRA. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of; the other rights are exercised through the channel below.

If you are in the EEA or the UK, you have the rights of access, rectification, erasure, restriction, objection and portability under the GDPR/UK GDPR, and the right to complain to your supervisory authority.

How to make a request: email [email protected] from the address on your account, and tell us what you want. Because there is no automated pipeline behind this, requests are handled by a person. We aim to respond within 30 days and will tell you if we need longer. We may need to confirm your identity before acting on a request.

We do not currently offer a self-service data export.

7. Children

The Service is for people aged 18 and over. We do not knowingly collect personal information from children. If you believe a child has given us information, email [email protected] and we will delete it.

8. Cookies and similar technologies

We set one cookie, named oc_sess. It holds a signed session identifier and exists solely to keep you signed in. It is marked HttpOnly, SameSite=Lax and Secure, and lasts up to 30 days. It carries no personal information and is not used for analytics or advertising. It is strictly necessary for the Service to work, so there is no consent banner — there is nothing optional to consent to.

The Service does not use browser local storage, session storage or IndexedDB. There are no third-party cookies. The only third-party request your browser makes is to Google's font servers, described in Section 2.

Cloudflare may set its own security cookies as part of protecting the site.

9. Security

Passwords are stored as salted scrypt hashes and never in readable form. Sessions are held server-side, and the session cookie is signed and verified in constant time. Every request for a file or record checks that it belongs to your account before returning anything. Traffic between your browser and our site is encrypted, and the connection from Cloudflare to our server is encrypted with a certificate issued to the site. Secrets are held in files readable only by the account that runs the application, and are never sent to the browser.

Being straightforward about the limits: data at rest on the server is not separately encrypted beyond the disk it sits on; backups are compressed, not encrypted; there is no automated intrusion alerting; there is no formal security certification, and we do not claim SOC 2, ISO 27001 or any equivalent. No service can promise perfect security. If a breach affects your personal data we will notify you as the law requires.

10. Changes to this policy

The version and effective date are at the top of this page and previous versions remain available. For material changes we will give notice in the Service before they take effect. Because we do not currently have email sending, we cannot notify you by email; in-product notice is what we can actually do.

11. Contact

Dream Reels LLC, doing business as Object Cinema [email protected]

Dream Reels LLC · [email protected]

Terms · Privacy · Home