Legal
IntiSafe Privacy Policy
Last updated: August 23, 2026 • Effective: August 23, 2026
The short version
Your IntiSafe content is end-to-end encrypted. We can’t read it, and we can’t recover it if you lose your recovery key.
We collect only what we need to run the service: account info, billing details, and the communications you send us.
We don’t sell your data. Ever.
We don’t use your content to train AI or for advertising.
We don’t run third-party analytics or advertising trackers. We do record a few in-app milestones (the event, never the content) and measure whether our emails are opened.
Support requests are the one exception to our encryption — we have to be able to read them to answer them, and we tell you so in the app.
Your project records remain yours — accessible in read-only mode and exportable even if your membership lapses or your account is closed, until you ask us to delete them.
You have the right to access, correct, export, or delete your data — just ask.
This policy applies to you wherever you are in the world. If your local law gives you additional rights, we’ll honor them.
When you upload performer information, you are the data controller for that data. IntiSafe processes it on your behalf. Your local legal obligations as a controller are yours to meet.
1. Who We Are
This Privacy Policy explains how CINTIMA LLC, a California limited liability company (“IntiSafe,” “we,” “us,” or “our”), collects, uses, and protects information when you use the IntiSafe platform, website, or related services.
IntiSafe is available to users anywhere in the world. This policy applies regardless of where you are located, and we aim to honor applicable privacy rights under local law wherever you use the platform.
This policy applies to visitors to intisafe.app, people who sign up for our newsletter or contact us, members who start a free trial or a paid membership, and users of the IntiSafe application.
2. What We Collect
We collect different categories of information depending on how you interact with IntiSafe.
2.1 Information You Give Us Directly
Account information: your name, email address, and sign-in method (email code, Google or Apple), collected through our authentication provider, Clerk.
Profile details you choose to add in Settings: a phone number, a contact email, a profile picture, and the names you give your devices.
Push notification tokens: if you turn on notifications in the mobile app, so we can deliver them.
Your acceptance of our documents: the dated record of which version of the Terms of Service and of this Privacy Policy you accepted.
Billing information: billing details processed by Stripe, plus billing address and transaction history. We never see or store your full card number.
Communications: messages you send via our contact form, support requests, feedback, and survey responses (see Section 2.5).
Newsletter signups: email address, name, country, role (when you subscribe on our website).
2.2 Your Encrypted Content
When you use IntiSafe, you may upload content including scripts, scene notes, rider documentation, performer information, and production records (“Your Content”). Your Content is encrypted on your device before it reaches our servers. Encrypted files are stored in Cloudflare R2 and associated records are stored in our Supabase database; in both cases we store only encrypted data, which we cannot read. You alone hold the key that decrypts it. If you lose your recovery key, we cannot recover this content for you (see Section 11).
You represent and warrant to us that you have the authorization and consents required by law to upload and process all content you submit, including production materials received in the course of a professional engagement. We do not verify the ownership or licensing status of content you upload; that responsibility rests with you.
A note about performer data. Your Content typically includes personal information about third parties — performers, cast members, and production personnel. This may include information such as physical characteristics, body exposure consents, and health conditions relevant to intimacy work. Information of this kind can be treated as sensitive or special category personal data under privacy laws in many jurisdictions (including the GDPR in the EU and UK), carrying additional protections. As the controller of this data, you are responsible for determining its classification under applicable law and for meeting the additional protections that apply. Because every field that would carry that information is encrypted on your device, we hold it only in a form we cannot read, and we cannot determine or verify its classification ourselves.
When you upload and process performer data through IntiSafe, you are acting as the data controller for that data — you determine what is collected, why, and how it is used. IntiSafe acts as your data processor, handling that data on your behalf and under your direction. This relationship exists regardless of whether you are a US-based IC working domestically, a local IC hired by a foreign production, or a US IC on an overseas shoot. Your obligations as a data controller under applicable local law — including obtaining appropriate consent from performers and maintaining records in compliance with applicable regulations — are yours to meet. IntiSafe’s end-to-end encryption is designed to support those obligations, not substitute for them.
The terms governing our processing of this data as your processor are set out in the Data Processing Agreement, which is incorporated into the IntiSafe Terms of Service as Schedule A and applies when you accept those Terms. A standalone, separately signable copy is also available on request at support@intisafe.app.
2.3 What We Can and Cannot See
Because of how IntiSafe is built, it’s worth being precise about this.
What we cannot see. Every field that names or describes a person is encrypted on your device before it reaches us: performer and contact names, roles, phone numbers and email addresses, pronouns, body exposure and consent records, rider language and status, costume and choreography notes, allergies and medical notes, scene descriptions and notes, and whether a performer is a minor. We hold all of it as ciphertext and have no key to unlock it.
What we can see. We can see structural information about a project: record identifiers, the links between records, timestamps, counts, and a small number of flags — for example, whether a scene is marked as requiring an intimacy coordinator, and when a consent-related step happened. This lets us operate and support the service. It does not tell us who anyone is or what they agreed to.
2.4 Information Collected Automatically
When you use the platform, our infrastructure providers process basic technical data needed to deliver and secure the service — for example, IP address and standard server and security logs handled by our hosting and authentication providers (Cloudflare and Clerk), and diagnostic data from our error-reporting provider (Sentry) when something breaks. We do not run third-party analytics, advertising trackers, or behavioral profiling on our website. See Section 8 for cookies and for how we measure email.
In-app milestones. The web app records a small number of milestones as you use it, for example that you created a project, uploaded a script, generated a breakdown, or ran a call: the name of the event and the time, never the content or the title. These are tied to your account. We use them to understand how IntiSafe is adopted and to time onboarding email. You can ask us to delete them at any time.
Script parsing on your device. Script breakdown can run an AI model inside your browser. When it does, nothing about your script leaves your device. To do this your browser downloads the model from a public host (currently Hugging Face, with supporting files from GitHub), which sees your IP address the way any download does, and nothing else. Our web pages also load fonts from Google Fonts, with the same exposure. None of these hosts receives your content or your account details.
2.5 Support Requests and Feedback — Our One Exception to Encryption
When you send a bug report, feature request, or support message from inside the app or by email, that message is not end-to-end encrypted. We store it in readable form, along with your email address, the type of report, your browser and operating system, the screen you were on when you wrote it, and the names of any files you attach. The in-app form tells you this before you send.
We do this because support that we cannot read is support we cannot provide. Please don’t paste encrypted project content, performer details, or your recovery key into a support message.
We use an AI assistant to help triage inbound support email — sorting, summarizing, and routing messages so we can answer them faster. The message travels through OpenRouter to a model provider (currently Anthropic). It processes only the support message itself and never touches your encrypted project content. Support messages are not used to train AI models, ours or anyone else’s.
2.6 Information from Third Parties
We may receive information about you from Stripe (payment confirmation and basic transaction details), Clerk (authentication events and account status, such as sign-in method, email verification, and membership state), and Amazon SES (delivery, bounce, complaint, open, and click events for emails we send you — see Section 8.3).
3. How We Use Your Information
We use the information we collect to provide, operate, and improve the IntiSafe platform; authenticate your account and keep it secure; process payments and manage your membership; send service-related communications (account confirmations, billing receipts, security notices); record and review the in-app milestones described in Section 2.4, so we can understand how IntiSafe is adopted and time onboarding email; measure whether the emails we send are delivered, opened, and clicked so we can tell what’s useful and stop sending what isn’t; respond to your support requests and feedback, including with the AI triage assistant described in Section 2.5; detect, prevent, and address fraud, abuse, security issues, and technical problems; and comply with legal obligations.
Product updates. When you create an account, we add you to our member list for product updates about IntiSafe, the way most services keep their members informed. Every such email carries a one-click unsubscribe, and unsubscribing never affects the service emails your account needs (receipts, security notices, account confirmations).
What we don’t do: we don’t sell your personal information to anyone; we don’t use Your Content to train AI models; we don’t use your support messages to train AI models; we don’t share your data with advertisers; we don’t read or analyze the contents of your encrypted files; and we don’t run third-party analytics or advertising trackers.
4. Legal Bases for Processing (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, we process personal data on these bases:
Performance of a contract (Art. 6(1)(b)): to create your account, run your membership, and provide the platform.
Legitimate interests (Art. 6(1)(f)): to secure the platform, prevent fraud and abuse, respond to your support requests, and communicate about the service, balanced against your rights and freedoms. Legitimate interests also covers product-update email to members, and the engagement measurement described in Section 8.3, which you can stop at any time with one click. You may object to processing based on legitimate interests (Section 9).
Consent (Art. 6(1)(a)): for the newsletter you sign up for on our website. You may withdraw consent at any time, without affecting prior processing, by unsubscribing.
Legal obligation (Art. 6(1)(c)): to comply with law, valid legal process, and tax and accounting requirements.
Where you upload personal data about performers or other third parties, you are the controller and determine the legal basis for that processing; we act as your processor (Section 2.2).
5. Who We Share Information With (Subprocessors)
We share information only with the service providers below, and only for the purposes described. These are our subprocessors.
Clerk: Authentication and identity; membership and billing state. Shared: name, email, sign-in method, profile details you add (such as a phone number, contact email, profile picture or device names), account and membership status, and push notification tokens.
Stripe (via Clerk Billing): Payment processing. Shared: name, email, billing address, payment details.
Supabase: Database for project records and metadata. Shared: encrypted content records and account metadata.
Cloudflare: Application hosting, encrypted file storage (R2), and routing of support email replies. Shared: encrypted file blobs; standard server and security logs (IP, request data); support replies you send by email.
PowerSync: Data synchronization for the mobile app. Shared: encrypted content records and your account identifier.
Amazon Web Services (SES): Sending transactional and marketing email. Shared: email address, name, message content, and delivery and engagement events.
Convex: Backend for our support inbox, member and email records, in-app milestones, and admin tools. Shared: support messages and the details in Section 2.5; your member record, email engagement and milestone events.
Google Workspace: Our support mailbox. Shared: support email you send us and our replies.
Sentry: Error and crash reporting. Shared: stack traces, device or browser type, and app version; user identifiers and IP addresses are suppressed by configuration, and no session replay is enabled.
OpenRouter, which routes to the model provider (currently Anthropic): AI triage of inbound support email (Section 2.5). Shared: the support message and its metadata.
Expo: Delivering push notifications and updates to the mobile app. Shared: push notification tokens and the technical device data needed to deliver updates.
Framer: Hosting for our marketing website. Shared: standard server logs and any details you submit through a form on that site.
Not sub-processors, but worth naming. Google and Apple act as sign-in providers if you choose to sign in with them. Hugging Face, GitHub and Google Fonts serve files your browser downloads (Section 2.4) and receive only what any download reveals. Loops, our former email provider, no longer receives anything from us.
We keep this list current and will update it when it changes.
We may also share information when required by law (court orders, subpoenas, regulatory requests), to protect our rights and the safety of our users, or in connection with a business transfer (merger, acquisition, sale of assets) — in which case we’ll notify you and you’ll have the option to delete your account.
About law enforcement requests. Because Your Content is end-to-end encrypted, we cannot provide it in readable form to anyone — including law enforcement — even if compelled by court order. We can only produce what we hold: your account details (name, email, billing records), any support messages you’ve sent us, and encrypted content we cannot decrypt, together with the structural information described in Section 2.3. We cannot produce anything that identifies a performer or describes what a performer agreed to.
6. International Data Transfers
IntiSafe is operated from the United States. If you are using IntiSafe from outside the U.S. — whether you are an IC based abroad, a local IC hired by a foreign production, or a US IC working on an overseas shoot — your account information and metadata will be transferred to, stored, and processed in the United States and in the regions where our subprocessors operate.
For transfers of EEA, UK, or Swiss personal data, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum or Swiss addendum as applicable), together with supplementary measures including the end-to-end encryption described in this policy. We put a data processing agreement in place with each subprocessor that processes personal data on our behalf, and we make our Standard Contractual Clauses available on request at support@intisafe.app.
For users in Canada, we process personal information consistent with applicable Canadian privacy law, including PIPEDA and Quebec’s Law 25 where applicable. For users in Australia, we handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles. For users in all other countries, your data is processed in the U.S. in accordance with this policy; where your local law requires additional protections or transfer mechanisms, contact us at support@intisafe.app.
Data location. Our database currently operates from a single region. If your organization requires a specific data-residency arrangement, contact support@intisafe.app before purchase so we can tell you whether we can meet it.
Note: Your Content is end-to-end encrypted before it leaves your device. The transfer protections above apply to your account metadata, not to the encrypted content itself, which we cannot access regardless of where it is stored.
7. How Long We Keep Your Data
We retain personal information only as long as necessary for the purposes described in this policy.
Account information: while your account is active; account records retained as needed for legal and billing purposes following closure.
Encrypted content: retained (read-only) following membership lapse, cancellation, or account closure. We will not delete your project data without your affirmative written request. Upon request, deletion is completed within 30 days.
Support messages and feedback: up to 2 years, then deleted unless an ongoing matter requires retention.
Billing records: up to 7 years, as required by tax and accounting regulations.
Newsletter subscriptions and email engagement records: until you unsubscribe, then as needed to honor your unsubscribe.
Contact form submissions: up to 2 years, then deleted unless an ongoing matter requires retention.
In-app milestone events: while your account exists, or until you ask us to delete them.
Your records remain yours. IntiSafe treats your production documentation as legal records. If your membership lapses, is cancelled or paused, or your account is closed, whether by you or by us, your projects remain accessible to you in read-only mode and you can export each of them at any time, at no charge, including from a closed account. Exporting a project produces a zip file containing a generated PDF show binder and the documents you uploaded to that project, organized into folders. Scripts are deliberately excluded from exports: they belong to the production, not to us, and we do not redistribute them. You can also ask us at support@intisafe.app for a copy of the encrypted records we hold for you. We will not delete your project data unless you ask us to in writing, and you may ask us to return or delete it at any time.
If you ask us to delete, we will, within thirty (30) days, delete the encrypted content and records we hold for you, the stored files, your account record, your support messages, and your marketing record, and we will confirm in writing. We keep only what the law requires us to keep, such as billing records, and only for as long as it requires. Because your content is end-to-end encrypted, we delete it without ever having been able to read it.
8. Cookies, Tracking, and Email
We keep tracking to the minimum needed to run the service and to know whether the emails we send are useful.
8.1 Essential cookies
Our website and app use only the cookies and similar technologies necessary to make them work — for example, keeping you signed in (via our authentication provider) and remembering basic interface preferences. We do not use these for tracking or profiling.
8.2 No analytics or advertising cookies
We do not use website analytics cookies, advertising cookies, or third-party behavioral trackers, and we do not build advertising profiles. If we introduce website analytics in the future, we will update this policy and, where required by law, present a consent mechanism before any non-essential cookies are set.
8.3 Marketing email measurement
When we send you a marketing email, whether a newsletter you signed up for on our website or a product update we send members, we measure whether it was delivered, opened, and whether you clicked a link. This is done with a small tracking image and tagged links, through our email provider (Amazon SES), and the results are stored in our own systems. We use it to see which emails are useful, to stop sending ones that aren’t, and to decide what to send next. We do not use it to build advertising profiles, and we do not share it with advertisers.
Your choices. Every marketing email includes a one-click unsubscribe link, which stops both the emails and the measurement. Most email programs also let you block remote images, which prevents open tracking. Service emails you can’t unsubscribe from — receipts, security notices, and account confirmations — are sent because they’re necessary to your account.
8.4 Your other choices
You can configure your browser to block or delete cookies, though blocking essential cookies may break sign-in and other core functionality.
9. Your Privacy Rights
9.1 Rights for Everyone
Regardless of where you live, you can access the personal information we hold about you, correct information that’s inaccurate, request deletion of your account and associated data, export your data in a portable format, and unsubscribe from marketing emails (link in every email, or by emailing us). To exercise these rights, email support@intisafe.app. We’ll respond within 30 days.
9.2 Additional Rights for EU/UK/Swiss Residents (GDPR)
If you’re in the EEA, UK, or Switzerland, you also have the right to restrict or object to certain processing, to withdraw consent at any time (for processing based on consent), and to lodge a complaint with your local data protection authority.
9.3 Rights for Users in Other Jurisdictions
Privacy law is active in many countries and US states. If you are located in California, Canada, Australia, Brazil, South Africa, or anywhere else with applicable data protection law, your local law may give you rights similar to those described above — including rights of access, correction, deletion, and complaint.
We will honor reasonable requests made under applicable local law. Contact support@intisafe.app and identify the rights you are seeking to exercise. We’ll respond within 30 days.
10. Children’s Privacy
IntiSafe is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe we’ve collected information from a minor, contact us at support@intisafe.app and we’ll delete it.
Note that IntiSafe is a professional tool used to document work involving performers who may be minors. That information is entered by you as the controller, is encrypted on your device, and is not readable by us. Your obligations in handling it are described in Section 2.2 and in the Data Processing Agreement.
11. Security
Our protections include: true end-to-end encryption for content stored in IntiSafe — your data is encrypted on your device before it reaches us, and we hold no key to decrypt it (if you lose your recovery key, your encrypted content is permanently unrecoverable, by you and by us; there is no backdoor); encrypted connections (TLS/HTTPS) for all data in transit; limited employee access to systems containing personal data, on a need-to-know basis; and regular security reviews of our infrastructure and code.
In practice that means our staff can see your account details, membership state, and the support messages you send us, and can see counts and structural facts about projects; they cannot see your content, and no tool exists that would let them sign in as you.
No system is completely secure. If we become aware of a personal-data breach affecting your information that is not protected by end-to-end encryption, we will, without undue delay, notify affected users and the relevant authorities as required by applicable law (including, where applicable, California Civil Code § 1798.82 and, for EEA/UK personal data, the GDPR’s 72-hour supervisory-authority notification); describe the nature of the incident and the categories of data involved; and state the measures taken.
Because Your Content is end-to-end encrypted and unreadable to us, a compromise of our storage would expose ciphertext, account metadata, the structural information described in Section 2.3, and any support messages you have sent us — not the readable contents of Your Content.
12. The Mobile App and Your Device
The IntiSafe phone and tablet app keeps a copy of your projects on the device so it works on set without a signal. The sensitive fields in that copy are encrypted one by one, with the same key model as the rest of IntiSafe, before they are written to the device’s local database. The data key and your recovery key are kept in the device’s secure keystore (Keychain on iOS, Keystore on Android). You can add a Face ID, fingerprint or passcode lock to the app in Settings.
The app asks for the camera and photo library only to set a profile picture and to scan the QR codes used for signing in from the web and for moving your recovery key between devices. It asks for notifications to remind you of calls and unsigned riders and to tell you when a long script parse has finished; those notifications carry a title and a count, never content. It does not ask for your contacts, your location or your microphone, and it contains no analytics software. Crash reports go to Sentry without your identity or IP address. If you share a cast member’s contact details from the app, that opens your own mail app; nothing passes through our servers.
Account creation happens on the web. The app signs you in; it does not sell anything or collect anything the web app does not.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we’ll notify you via email or through the platform at least thirty (30) days before the changes take effect, and update the “Last updated” date at the top of this page. For minor changes (clarifications, formatting), we’ll update the date without separate notification.
14. Do Not Track
Some browsers offer a “Do Not Track” signal. There is currently no industry standard for how to interpret these signals, so we do not respond to them. We do not track you across the web or build advertising profiles. The measurement we do perform is limited to our own marketing emails, described in Section 8.3, and the in-app milestones described in Section 2.4.
15. Contact
Questions, concerns, or privacy requests? Reach out to:
CINTIMA LLC • support@intisafe.app
