Legal

Terms of Service

Last updated: August 24, 2026 · Effective: August 24, 2026

1. Welcome

These Terms of Service (“Terms”) govern your use of IntiSafe, a secure operating system for intimacy coordination workflow. IntiSafe is operated by CINTIMA LLC, a California limited liability company (“IntiSafe,” “we,” “us,” or “our”).

By creating an account, accessing the platform, or using any IntiSafe service, you (“you” or “User”) agree to be bound by these Terms. If you do not agree, do not use the platform. We’ve written these Terms in plain language; where legal terms are necessary, we’ve kept them as direct as possible.

These Terms govern your access to and use of IntiSafe. They include the Data Processing Agreement set out in Schedule A, which forms part of these Terms and which you accept when you accept these Terms.

2. Who Can Use IntiSafe

To use IntiSafe, you must be at least 18 years old, have the legal authority to enter into binding agreements, provide accurate registration information, and comply with these Terms and all applicable laws.

IntiSafe is built for intimacy coordinators, production professionals, and authorized production stakeholders. While anyone meeting the above criteria may create an account, the platform is designed for professional use in film and television production contexts. By using IntiSafe, you represent that your use is for professional or educational purposes related to film, television, or live production, and not for any purpose that would constitute a misuse of performer or production information.

3. Your Account

You create your account through our authentication provider (Clerk), using an email verification code or by signing in with Google or Apple. When you create your account, you accept these Terms and our Privacy Policy.

You are responsible for maintaining the confidentiality of your account credentials and your recovery key, for all activity under your account, for notifying us immediately of any unauthorized access at support@intisafe.app, and for the accuracy of the information you provide.

About your recovery key. IntiSafe uses true end-to-end encryption. Your recovery key is the only way to access your encrypted data on a new device or after clearing your browser. We cannot recover your data if you lose your recovery key — there is no backdoor and no company-held copy we can unlock for you, under any circumstances, including at your own request. This is a deliberate feature of the encryption model, not a limitation we can override. Please save your recovery key somewhere durable, such as a password manager or a printed copy kept somewhere safe. See Section 5.3.

4. Membership and Billing

4.1 The Membership

IntiSafe is offered as a single membership: $69 USD per month, billed monthly. There are no annual contracts, no per-project fees, and no long-term commitments. Pricing is in US dollars.

4.2 Free Trial

New accounts start with a 14-day free trial. The trial requires no credit card and begins automatically when you create your account. During the trial you have full access to the platform.

At the end of the 14-day trial, if you have not started a paid membership, your account becomes read-only: you can still view your projects and export them (see Section 11.3), but you cannot create or edit until you subscribe. We do not automatically charge you when the trial ends, because we never collected a card to begin the trial. The free trial is available once per account.

4.3 How Billing Works

When you start a paid membership, billing is handled through Clerk Billing, which uses Stripe as the payment processor. Stripe securely collects and stores your card details; we never see or store your full card number. Your membership renews automatically each month until you cancel. CINTIMA LLC is the merchant of record for your membership.

4.4 Cancelling, Pausing, and Your Data

You may cancel or pause your membership at any time. When you cancel or pause, your membership remains active through the end of the current paid period and then stops renewing — we do not issue further charges after you cancel. You can resume at any time.

Your data is never deleted when you cancel, pause, or lapse. If your membership ends for any reason — cancellation, pause, non-payment, or an expired trial — your account becomes read-only. You keep view access to your projects and can export them at any time, at no charge, including from a closed account. Your records stay yours regardless of membership status. Section 11.3 describes what an export contains.

Fees already paid are not refunded for partial periods, except where the law requires.

4.5 Taxes

Prices are shown exclusive of tax. Because CINTIMA LLC is the merchant of record, we are responsible for collecting and remitting any sales tax, VAT, GST, or similar taxes where we are obligated to do so; where applicable, tax is calculated and added at checkout (via Stripe Tax) based on your location. You are responsible for any other taxes, duties, or fees imposed by your jurisdiction that are not collected by us.

4.6 Pricing Changes

We will provide at least thirty (30) days’ advance notice of any change to membership pricing before it affects your account.

5. Your Data and Content

5.1 You Own Your Content

You retain all rights to the content you upload to IntiSafe — including scripts, scene notes, rider documentation, performer information, production reports, and any other materials (“Your Content”). We do not claim ownership of Your Content. You represent and warrant to us that you have all legal right and authority to upload any and all of Your Content to IntiSafe.

5.2 What We Can Do With Your Content

To provide the service, you grant IntiSafe a limited license to store, process, and transmit Your Content as necessary to operate the platform. Because Your Content is end-to-end encrypted (Section 5.3), this license is in practice limited to storing and transmitting encrypted data we cannot read. Some features, such as script breakdown, can run an AI model inside your browser. When they do, nothing about your script leaves your device; the model itself is downloaded from a public host (currently Hugging Face). We do not use Your Content for marketing, advertising, or any purpose unrelated to providing the service to you, and we do not use it to train AI models, ours or anyone else’s.

5.3 End-to-End Encryption and No Backdoor

IntiSafe is built with true end-to-end encryption. Your Content is encrypted on your device before it reaches our servers. Encrypted files (such as scripts and other documents) are stored in Cloudflare R2, and associated records and metadata are stored in our Supabase database. In both cases, what leaves your device is encrypted with a key only you hold.

We cannot read the contents of your encrypted data, and we cannot recover it for you. There is no company-held key, no master key, and no backdoor. If you lose your recovery key, your encrypted data is permanently unrecoverable — by you and by us. We designed it this way on purpose: for a product whose promise is that your intimacy-coordination work is private even from us, any recovery path we controlled would make that promise false.

What we can and cannot see. Every field that names or describes a person is encrypted before it reaches us. We can see only structural information about a project — record identifiers, the links between records, timestamps, counts, and a small number of flags. That structural layer lets us operate and support the service; it does not tell us who anyone is or what they agreed to. Section 2.3 of our Privacy Policy sets this out in full and is the controlling description.

Because of this design, if we are ever compelled by legal process to produce data stored on our servers, we can produce only ciphertext (unreadable encrypted data), your account metadata (such as your name, email, and billing records), the structural information described above, and any support messages you have sent us — never the readable contents of Your Content, and nothing that identifies a performer or describes what a performer agreed to, regardless of any legal demand.

5.4 Data Accuracy and Lawful Use

You represent and warrant to us that:

• You have the authorization and consents required by law to upload and process all content you submit, including production materials received in the course of a professional engagement

• Your use of IntiSafe complies with all applicable laws, including data protection laws

• You have obtained any necessary consents from individuals whose information appears in Your Content (including performers, production personnel, and other parties)

• You will not upload content that is unlawful, infringes third-party rights, or violates the privacy rights of others

5.5 Sensitive Information

IntiSafe is designed to handle sensitive information related to intimacy coordination workflow. You acknowledge that:

• You are responsible for ensuring your use of the platform complies with any applicable employment agreements, union rules (including SAG-AFTRA standards), production contracts, and confidentiality obligations

• IntiSafe is a tool, not a replacement for professional judgment, legal advice, or compliance with industry standards

• You will not rely on IntiSafe as a substitute for proper consent processes, legal documentation, or production protocols

5.6 Support Messages Are Not Encrypted

Messages you send us — bug reports, feature requests, and support requests, whether from inside the app or by email — are not end-to-end encrypted. We store them in readable form, and the names of any files you attach, so that we can answer them, and we use an AI assistant to help triage inbound support email. The in-app form tells you this before you send. Please don’t paste project content, performer details, or your recovery key into a support message. See the Privacy Policy for details.

5.7 Security and Breach Notification

We implement and maintain reasonable technical and organizational security measures designed to protect Your Content. If we become aware of a security incident that results in unauthorized access to or disclosure of your personal information that is not protected by end-to-end encryption, we will notify you as required by applicable law, including California Civil Code § 1798.82, without unreasonable delay. Because Your Content is end-to-end encrypted and unreadable to us, a compromise of our storage would expose ciphertext, account metadata, the structural information described in Section 5.3, and any support messages you have sent us — not the readable contents of Your Content.

6. Acceptable Use

You agree not to:

• Use IntiSafe for any unlawful or unethical purpose

• Upload content you are not authorized to access or process, or that you have not received in the course of a legitimate professional engagement

• Attempt to reverse-engineer, decompile, or circumvent the platform's security

• Interfere with the operation of the platform or other users' use of it

• Use automated systems to access the platform except as expressly permitted

• Resell, sublicense, or redistribute access to your account

• Use the platform to harass, harm, or violate the rights of any person

• Misrepresent your identity or affiliation

We reserve the right to suspend or terminate accounts that violate these rules.

7. Intellectual Property

7.1 Our IP

IntiSafe — including the software, design, logo, name, documentation, and underlying technology — is owned by CINTIMA LLC and protected by copyright, trademark, and other intellectual property laws. These Terms do not grant you any rights to our IP except the limited right to use the platform as described in these Terms.

7.2 Feedback

If you send us feedback, suggestions, or feature requests, we may use them freely without obligation to you. You grant us a perpetual, royalty-free license to use such feedback to improve the platform. We do not acquire ownership of your feedback by virtue of this license.

7.3 Copyright and Infringement Concerns

IntiSafe is a private workspace, not a public or user-generated-content platform. Every account’s data is isolated to that account. Content is not published, shared with other users, or made available on any public surface, and it is end-to-end encrypted, which means we cannot view or assess what is stored. There is no mechanism by which a third party’s copyrighted work could be posted on IntiSafe where anyone else could see it.

If you believe someone is using IntiSafe to infringe your intellectual-property rights, contact us at support@intisafe.app with the details. Because we cannot read encrypted content, our response is necessarily limited to action at the account level, including suspending or terminating an account in appropriate circumstances. We will, in appropriate circumstances, terminate the accounts of repeat infringers.

Because IntiSafe does not host public or shared content, the notice-and-takedown framework under the Digital Millennium Copyright Act (17 U.S.C. § 512) does not apply to the service, and we do not maintain a designated agent under that section. If the service changes so that the framework becomes applicable, we will register a designated agent with the U.S. Copyright Office and update these Terms.

8. Privacy and Data Processing

8.1 Privacy

Our handling of personal information is governed by our Privacy Policy, which is incorporated into these Terms by reference. By using IntiSafe, you also agree to the Privacy Policy.

8.2 Data Processing

When you use IntiSafe to record personal information about performers, production personnel, or other third parties, you act as the data controller of that information and CINTIMA acts as your data processor. The terms governing that processing are set out in the Data Processing Agreement in Schedule A, which is incorporated into and forms part of these Terms. By accepting these Terms, you accept the Data Processing Agreement. A standalone, separately signable copy is available on request at support@intisafe.app.

9. Service Availability and Changes

9.1 Reliability

We work to keep IntiSafe available and functional, but we do not guarantee uninterrupted access. The platform may be unavailable due to maintenance, updates, technical issues, or causes beyond our control.

9.2 Platform Changes

We may add, modify, or remove features over time. We will provide reasonable notice of material changes that significantly affect your use of the platform.

9.3 Beta and Pre-Release Features

Some features may be offered as beta, preview, or pre-release. These features are provided "as is" and may be changed or removed without notice.

10. Force Majeure

Neither party is liable for any failure or delay in performance (other than payment obligations already due) caused by events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, government action, labor disputes, power or internet failures, epidemics or pandemics, or failures of third-party infrastructure or service providers. The affected party will notify the other promptly and resume performance as soon as reasonably practicable. If a force-majeure event affecting our performance continues for more than sixty (60) days, either party may terminate the membership on notice, and we will refund any prepaid, unused fees.

11. Termination

11.1 By You

You may stop using IntiSafe, cancel your membership, or close your account at any time. Cancellation is governed by Section 4.4.

11.2 By Us

We may suspend or terminate your account if you violate these Terms, fail to pay applicable fees, or engage in conduct that creates risk for IntiSafe or other users. Where reasonable, we will provide notice and an opportunity to address the issue first.

11.3 Your Records After Termination

Your records remain yours. IntiSafe treats your production documentation as legal records. If your membership lapses, is cancelled or paused, or your account is closed, whether by you or by us, your projects remain accessible to you in read-only mode and you can export each of them at any time, at no charge, including from a closed account. Exporting a project produces a zip file containing a generated PDF show binder and the documents you uploaded to that project, organized into folders. Scripts are deliberately excluded from exports: they belong to the production, not to us, and we do not redistribute them. You can also ask us at support@intisafe.app for a copy of the encrypted records we hold for you. We will not delete your project data unless you ask us to in writing, and you may ask us to return or delete it at any time.

If you ask us to delete, we will, within thirty (30) days, delete the encrypted content and records we hold for you, the stored files, your account record, your support messages, and your marketing record, and we will confirm in writing. We keep only what the law requires us to keep, such as billing records, and only for as long as it requires. Because your content is end-to-end encrypted, we delete it without ever having been able to read it.

You can resume a paid membership at any time to regain full editing access.

12. Disclaimers

THE PLATFORM AND ALL RELATED SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE,” WITH ALL FAULTS AND WITHOUT WARRANTY OF ANY KIND. TO THE FULLEST EXTENT PERMITTED BY LAW, CINTIMA LLC DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, COURSE OF PERFORMANCE, OR TRADE USAGE.

We do not warrant that the platform will be error-free, uninterrupted, secure against all threats, or that it will meet your requirements.

Encryption and data-loss risk. You acknowledge that IntiSafe uses true end-to-end encryption and that, as described in Sections 3 and 5.3, we have no ability to recover your encrypted data or your recovery key. We make no warranty against, and expressly disclaim responsibility for, loss of or inability to access Your Content caused by your loss of your recovery key or account credentials, by your clearing of browser data, or by any device you control. You are solely responsible for retaining your recovery key and maintaining your own backups where appropriate.

Third-party services. The platform relies on third-party providers (including our authentication, payment, hosting, storage, error-reporting, and email providers). We do not warrant the availability, security, or performance of those third parties and are not responsible for their acts or omissions except as required by law.

Some jurisdictions do not allow the exclusion of certain warranties, so some of the above exclusions may not apply to you; in that case, such warranties are limited to the minimum scope and duration permitted by law.

13. Limitation of Liability

13.1 Exclusion of certain damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, CINTIMA LLC AND ITS MEMBERS, MANAGERS, EMPLOYEES, AND AGENTS WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, OR DATA, ARISING OUT OF OR RELATING TO THESE TERMS OR YOUR USE OF (OR INABILITY TO USE) THE PLATFORM, WHETHER BASED IN CONTRACT, TORT, STRICT LIABILITY, OR ANY OTHER THEORY, AND WHETHER OR NOT WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

13.2 Data loss from lost keys or credentials. WITHOUT LIMITING SECTION 13.1, AND NOTWITHSTANDING ANYTHING TO THE CONTRARY, WE WILL HAVE NO LIABILITY FOR ANY LOSS OF, OR INABILITY TO ACCESS, YOUR CONTENT THAT RESULTS FROM YOUR LOSS OF YOUR RECOVERY KEY OR ACCOUNT CREDENTIALS, GIVEN THAT OUR END-TO-END ENCRYPTION MEANS WE CANNOT RECOVER THAT DATA FOR YOU.

13.3 Aggregate cap. OUR TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE PLATFORM WILL NOT EXCEED THE GREATER OF (A) THE TOTAL AMOUNT YOU PAID US FOR THE MEMBERSHIP IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS ($100).

13.4 Exceptions. Nothing in these Terms limits liability that cannot be limited by law, including liability for fraud, gross negligence, willful misconduct, or death or personal injury caused by negligence. Some jurisdictions do not allow the exclusion or limitation of certain damages, so some of the above may not apply to you; in that case our liability is limited to the maximum extent permitted by law.

13.5 Basis of the bargain. You acknowledge that the disclaimers and limitations in Sections 12 and 13 reflect a reasonable allocation of risk and are an essential basis of the bargain between you and us, and that our pricing reflects this allocation. These limitations apply even if a limited remedy fails of its essential purpose.

14. Indemnification

14.1 Your indemnity

You will defend, indemnify, and hold harmless CINTIMA LLC and its members, managers, employees, and agents from and against any third-party claims, and any resulting damages, liabilities, costs, and expenses (including reasonable attorneys’ fees), arising out of or relating to: (a) your breach of these Terms; (b) your violation of any law or any right of a third party; (c) Your Content, including any claim that it infringes, misappropriates, or violates the rights or privacy of any performer, production, or other third party; or (d) your use of the platform in connection with any production, performer, or third party.

14.2 Our indemnity

We will defend you against any third-party claim alleging that the platform, as provided by us and used by you in accordance with these Terms, directly infringes that third party’s U.S. patent, copyright, or trademark, and we will pay damages and costs finally awarded against you (or agreed by us in settlement) for such a claim. Our obligation is conditioned on you (a) promptly notifying us in writing, (b) giving us sole control of the defense and settlement, and (c) reasonably cooperating at our expense.

14.3 Exclusions and remedy

Section 14.2 does not apply to any claim arising from Your Content, from modifications not made by us, from combination of the platform with materials or services we did not provide, or from your use of the platform other than as permitted by these Terms. If the platform becomes, or in our opinion is likely to become, the subject of an infringement claim, we may at our option and expense (i) procure the right for you to continue using it, (ii) modify it to be non-infringing, or (iii) terminate the affected functionality and refund any prepaid, unused fees. Section 14.2 and this Section 14.3 state our entire liability and your sole remedy for any third-party intellectual-property claim. Our obligations under Section 14.2 are subject to the limitations in Section 13.

15. Disputes and Governing Law

15.1 Governing law

These Terms, and any dispute arising out of or relating to them or the platform, are governed by the laws of the State of California, without regard to its conflict-of-law rules, and (for arbitrability) by the Federal Arbitration Act.

15.2 Informal resolution first

Before starting an arbitration or court proceeding, you and we agree to try to resolve the dispute informally for at least sixty (60) days after written notice of the dispute (to support@intisafe.app for notice to us, or to your account email for notice to you). The notice must describe the dispute and the relief sought. This step is a condition to starting a formal proceeding; the limitations period is tolled while it runs.

15.3 Binding individual arbitration

Except for the matters carved out in Section 15.6, any dispute, claim, or controversy arising out of or relating to these Terms or the platform — including its formation, validity, breach, or termination — that is not resolved informally will be resolved by binding individual arbitration administered by JAMS under its Streamlined Arbitration Rules then in effect, before a single arbitrator. Arbitration will take place in Los Angeles County, California, or, at your election, by videoconference or (for claims of $10,000 or less) on documents only. The arbitrator decides all threshold questions of arbitrability except those reserved to a court by Section 15.4. Judgment on the award may be entered in any court of competent jurisdiction.

15.4 Class-action and jury-trial waiver

YOU AND WE AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY CLASS, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING. The arbitrator may not consolidate more than one person’s claims or preside over any representative or class proceeding. IF THE PRE-DISPUTE CLASS-ACTION WAIVER IN THIS SECTION IS FOUND UNENFORCEABLE AS TO A PARTICULAR CLAIM, THAT CLAIM (AND ONLY THAT CLAIM) WILL BE SEVERED AND HEARD IN COURT, AND THE REMAINDER WILL PROCEED IN ARBITRATION. WHERE ARBITRATION PROCEEDS, YOU AND WE EACH WAIVE ANY RIGHT TO A JURY TRIAL.

15.5 Arbitration fees; mass-arbitration

We will pay JAMS filing and arbitrator fees to the extent required by JAMS’ consumer-arbitration minimum standards; otherwise fees are allocated under the JAMS rules. If 25 or more similar demands are filed by or with the coordination of the same or coordinated counsel, the parties will follow JAMS’ mass-arbitration or batch procedures (if any) to stage and resolve them efficiently.

15.6 Carve-outs

Either party may (a) bring an individual claim in small-claims court if it qualifies, and (b) seek injunctive or other equitable relief in the state or federal courts located in Los Angeles County, California to protect intellectual-property rights or confidential information, without waiving arbitration for other claims. For any matter that proceeds in court, you consent to the exclusive jurisdiction and venue of those courts.

15.7 30-day opt-out

You may opt out of Sections 15.3 to 15.5 (arbitration, class-action waiver, and jury-trial waiver) by emailing support@intisafe.app within thirty (30) days after you first create your account, stating your name, account email, and that you opt out of arbitration. Opting out does not affect any other provision of these Terms. The acceptance timestamp recorded at your sign-up starts this 30-day window.

15.8 Consumers outside the U.S.

If you use IntiSafe as a consumer and the mandatory-arbitration, class-waiver, venue, or governing-law provisions of this Section are prohibited or unenforceable under the mandatory law of your country of residence, those provisions do not apply to you to the extent prohibited, and nothing in these Terms deprives you of the protection of mandatory consumer-protection rules or of the right to bring proceedings in your local courts where that right cannot be waived.

16. Changes to These Terms

We may update these Terms from time to time. When we make material changes, we will notify you via email or through the platform at least thirty (30) days before the changes take effect. Your continued use of IntiSafe after changes take effect constitutes acceptance of the updated Terms. If you do not agree to updated Terms, you must stop using the platform before the effective date.

How you accept. When you create your account you tick a box, unchecked by default, confirming that you have read and agree to these Terms, including Schedule A, and the Privacy Policy. The full text of both documents is presented on that page, each in its own scrollable panel, so you can read them before you agree. We record your account, the dated version of each document, the time you accepted, and the IP address and browser used to accept. When we publish a new version, the app asks you to accept it again before you can continue.

17. Miscellaneous

Entire agreement. These Terms (together with the Privacy Policy, the Data Processing Agreement in Schedule A, and any other documents referenced herein) constitute the entire agreement between you and IntiSafe with respect to the subject matter hereof.

Severability. If any provision is found unenforceable, the remainder of these Terms continues in full force and effect.

No waiver. Our failure to enforce any provision of these Terms does not waive our right to enforce it later.

Assignment. You may not assign these Terms or any rights under them without our prior written consent. We may assign these Terms in connection with a sale, merger, acquisition, or reorganization without your consent.

No agency. Nothing in these Terms creates a partnership, joint venture, employment relationship, or franchise between you and IntiSafe.

Headings. Section headings are for convenience only and do not affect interpretation.

18. Contact

Questions about these Terms? Contact us at:

CINTIMA LLC · support@intisafe.app

Schedule A — Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the IntiSafe Terms of Service (the “Terms”) between you (the Intimacy Coordinator, “you” or “Controller”) and CINTIMA LLC, operator of IntiSafe (“CINTIMA,” “IntiSafe,” or “Processor”). You accept this DPA when you accept the Terms. A standalone, separately signable copy is available on request at support@intisafe.app. Where the Terms and this DPA conflict on the subject of data processing, this DPA controls.

A1. Definitions

Terms not defined here have the meaning given in the Terms or in applicable Data Protection Law. “Data Protection Law” means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, and applicable US state privacy laws. “Controller,” “Processor,” “Personal Data,” “Processing,” “Data Subject,” “Special Category Data,” “Personal Data Breach,” and “Sub-processor” have the meanings given in the GDPR, and the equivalent terms under other applicable Data Protection Law.

A2. Roles of the Parties

A2.1 With respect to the Personal Data you enter into or process through IntiSafe (the “Controller Data”), you are the Controller and CINTIMA is the Processor. CINTIMA processes Controller Data only on your behalf and under your documented instructions.

A2.2 You determine what Personal Data is collected, from whom, for what purpose, and on what legal basis. CINTIMA does not determine the purposes or means of processing Controller Data and does not process it for its own purposes.

A3. Scope and Details of Processing

The subject matter, duration, nature, and purpose of the processing, and the categories of Data Subjects and Personal Data, are set out in Annex I.

A4. Your Instructions

A4.1 CINTIMA processes Controller Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law — in which case CINTIMA will inform you of that legal requirement before processing, unless the law prohibits it.

A4.2 Your instructions are: (a) the Terms and this DPA; (b) the configuration and use choices you make within IntiSafe; and (c) any further written instructions the parties agree.

A4.3 CINTIMA will inform you if, in its opinion, an instruction infringes Data Protection Law. CINTIMA has no obligation to monitor the lawfulness of your processing.

A5. The End-to-End Encryption Model

A5.1 IntiSafe applies true end-to-end encryption to Controller Data content. Controller Data content is encrypted on your device before it reaches CINTIMA’s systems, using a key held only by you. CINTIMA holds no key and no backdoor.

A5.2 As a result, CINTIMA processes Controller Data content only as ciphertext it cannot read, together with a limited layer of account and operational metadata described in Annex I.

A5.3 The parties acknowledge that this architecture shapes several obligations below. Where an obligation would require CINTIMA to access, read, produce in readable form, correct, or selectively delete the content of Controller Data, CINTIMA cannot perform it, because only you hold the key. In those cases CINTIMA’s obligation is limited to the assistance it can actually provide (for example, at the account, file-record, or metadata level), and you retain sole ability to action content-level requests using the export and management tools IntiSafe provides. For the avoidance of doubt, this Section does not limit CINTIMA’s obligation under Section A11 to return or delete Controller Data at your election.

A6. Confidentiality

CINTIMA ensures that persons authorized to process Controller Data are bound by appropriate confidentiality obligations and access such data only on a need-to-know basis. Because content is end-to-end encrypted, authorized personnel can in any event access only ciphertext and metadata, not readable content.

A7. Security

A7.1 CINTIMA implements and maintains the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk.

A7.2 You acknowledge that the measures in Annex II are appropriate for the processing under this DPA, and that you are responsible for your own device security and for safeguarding your recovery key, without which encrypted content cannot be recovered by anyone, including CINTIMA.

A8. Sub-processors

A8.1 You grant CINTIMA general authorization to engage the Sub-processors listed in Annex III to process Controller Data in connection with providing IntiSafe.

A8.2 CINTIMA imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and remains responsible to you for each Sub-processor’s performance.

A8.3 CINTIMA will give you at least thirty (30) days’ notice of any intended addition or replacement of a Sub-processor (by updating the published Sub-processor list and notifying you), during which you may object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, you may terminate the affected service as your sole remedy.

A9. Assistance to You

A9.1 Data subject rights. Taking into account the nature of the processing and Section A5, CINTIMA assists you by appropriate technical and organizational measures, insofar as possible, to respond to Data Subject requests. You acknowledge that, because content is end-to-end encrypted, you, not CINTIMA, action access, correction, portability, and content-level deletion requests using IntiSafe’s export and management tools; CINTIMA’s assistance is limited to account-, record-, and metadata-level actions.

A9.2 Security, breach, and impact assessments. CINTIMA assists you, taking into account the nature of processing and the information available to it, with security of processing, notification of Personal Data Breaches (Section A10), data protection impact assessments, and prior consultation with supervisory authorities.

A10. Personal Data Breach

A10.1 CINTIMA notifies you without undue delay after becoming aware of a Personal Data Breach affecting Controller Data, providing the information reasonably available to it to help you meet your own notification obligations.

A10.2 The parties acknowledge that, because Controller Data content is end-to-end encrypted and unreadable to CINTIMA, a compromise of CINTIMA’s storage would expose ciphertext, account metadata, and the structural information described in Annex I, not readable content.

A11. Return and Deletion of Controller Data

A11.1 Your election. On termination or expiry of the Services, and at any time during the term, you may instruct CINTIMA to (a) return the Controller Data, (b) delete the Controller Data, or (c) return and then delete it. CINTIMA will comply with your election. This election is yours alone, and nothing in this DPA, the Terms, or IntiSafe’s records-retention commitment limits your right to make it at any time.

A11.2 Return. CINTIMA effects return by making the Controller Data available to you for export, at no charge, including after account closure. Export is per project: exporting a project produces a zip file containing a generated PDF show binder and the documents you uploaded to that project, organized into folders. Scripts are deliberately excluded from exports: they belong to the production, not to us, and we do not redistribute them. On request at support@intisafe.app, CINTIMA will also provide a copy of the encrypted records it holds for you.

A11.3 Deletion. On your deletion instruction, CINTIMA will, within thirty (30) days, delete the encrypted content and records it holds for you, the stored files, your account record, your support messages, and your marketing record, and will instruct its Sub-processors to do the same. CINTIMA will confirm the deletion in writing. This applies whether or not you have first exercised your right of return. Because your content is end-to-end encrypted, CINTIMA deletes it without ever having been able to read it.

A11.4 Backups. CINTIMA’s database is backed up daily and each backup is kept for seven (7) days. Deleted Controller Data may persist in those backups after deletion from live systems, encrypted and subject to this DPA, until the seven-day cycle overwrites them; backups are not used to restore deleted Controller Data except where required by law. Stored files are not separately backed up, so their deletion is final.

A11.5 Default absent instruction. If you give no instruction under Section A11.1, the Controller Data remains available to you in read-only form, exportable at any time, consistent with IntiSafe’s records-retention commitment. This default reflects your standing preference for continued availability of your own professional records; it is not a limitation on, or a substitute for, your rights under Sections A11.1 to A11.3.

A11.6 Encryption. The parties acknowledge that Controller Data content is stored end-to-end encrypted and that CINTIMA holds no key and cannot render that content intelligible. To the extent CINTIMA therefore holds no Personal Data in intelligible form, CINTIMA’s obligations under this Section are satisfied by deletion or return (as elected) of the ciphertext and the associated records and metadata it holds.

A11.7 Legal retention. CINTIMA may retain Controller Data to the extent required by applicable law (for example, billing and tax records), in which case it will retain only what the law requires, for only as long as required, and will continue to protect it under this DPA.

A12. Audits and Information

A12.1 CINTIMA makes available to you information reasonably necessary to demonstrate compliance with its processor obligations and this DPA, and allows for and contributes to audits on reasonable prior notice, no more than once per year absent a Personal Data Breach or regulatory requirement, subject to confidentiality and CINTIMA’s security policies. CINTIMA may satisfy this obligation by providing a relevant third-party certification, attestation, or audit report where available.

A12.2 The parties acknowledge that, given the end-to-end encryption model, an audit can verify CINTIMA’s controls and metadata handling but cannot access readable content, which CINTIMA does not hold in readable form.

A13. International Transfers

CINTIMA processes Controller Data in the United States and in the regions where its Sub-processors operate. Where your use of IntiSafe involves the transfer of Personal Data subject to GDPR, UK GDPR, or Swiss law to a country without an adequacy decision, the parties will enter into the applicable Standard Contractual Clauses, Module Two (controller-to-processor), together with the UK International Data Transfer Addendum and/or the Swiss addendum as applicable. Those clauses are completed with the particulars in Annexes I to III and executed by the parties as and when applicable to you; they are addressed in Annex IV. The supplementary measures described in Annex II, including end-to-end encryption, apply to such transfers.

A14. Special Category Data

Controller Data may include information that could be classified as Special Category Data under GDPR/UK GDPR or sensitive personal information under applicable US state law. As the Controller, you are responsible for determining the applicable classification and for establishing a lawful basis and any required conditions for processing it. Because Controller Data content is end-to-end encrypted and CINTIMA holds no key, CINTIMA cannot and does not determine, verify, or have knowledge of whether any Controller Data falls within any such category. This allocation is consistent with the Privacy Policy.

A15. Your Obligations and Warranties

You warrant that you have a lawful basis for the processing you direct, that you have obtained all consents and provided all notices required from Data Subjects (including performers and production personnel), and that your instructions comply with Data Protection Law. This mirrors your representations in Terms Section 5.4 and the indemnity in Terms Section 14.1.

A16. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms (including the aggregate liability cap in Section 13), except to the extent Data Protection Law prohibits such limitation.

A17. Term

This DPA takes effect when you accept the Terms and continues for as long as CINTIMA processes Controller Data on your behalf. It is governed by the law and dispute-resolution provisions of the Terms, except where Data Protection Law requires otherwise (including, for EU/UK Data Subjects, mandatory local rules).

Annex I — Details of Processing

Subject matter. Provision of the IntiSafe intimacy-coordination workflow platform to you.

Duration. For the term of your IntiSafe account and as set out in Section A11.

Nature and purpose. Hosting, storage, encryption, transmission, and processing of Controller Data to enable you to run intimacy-coordination workflow, including script breakdown, director and actor calls, rider and consent documentation, shoot-day tracking, daily reports, and post-wrap records.

Categories of Data Subjects. Performers and actors; background performers; production personnel; and other individuals whose information you record.

Categories of Personal Data — Content (end-to-end encrypted; ciphertext only to CINTIMA): names and professional identifiers; contact details; contact photographs; body-exposure, garment, and consent records; rider language and status; scene and production documentation; medical and accessibility notes; minor status; and any other information you enter.

Categories of Personal Data — Account and operational metadata (accessible to CINTIMA): your name, email, sign-in method and the profile details you add; billing records; authentication events; the dated record of your acceptance of the Terms; support messages you send; in-app milestone events (event name and time); record identifiers, the links between records, timestamps, counts and a small number of flags (such as whether a scene is marked as requiring an intimacy coordinator and when a consent-related step occurred); and standard server and security logs.

Special Category Data. Content may include information that a controller could classify as sensitive or special category data. See Section A14.

Frequency. Continuous, for the duration of the account.

Annex II — Technical and Organizational Security Measures

• True end-to-end encryption of content — Controller Data content is encrypted on your device (client-side AES-256-GCM) before transmission; the encryption key is derived from a recovery key held only by you; CINTIMA holds no key and no backdoor.

• Encryption in transit — TLS/HTTPS for all connections.

• Access control — limited personnel access to systems holding Personal Data, on a need-to-know basis; content is in any event ciphertext to CINTIMA.

• Sub-processor controls — content stored with Sub-processors as encrypted blobs and records.

• Recovery-key model — you hold the sole recovery key; loss renders encrypted content permanently unrecoverable by any party.

• Security reviews — regular review of infrastructure and code.

• On-device storage (mobile): the local copy holds sensitive fields individually encrypted; the data key and recovery key are held in the device’s secure keystore; an optional biometric or passcode app lock is available.

• Content-free notifications: push notifications carry a title and a count only.

• Sub-processor minimisation: error reporting is configured to suppress user identifiers and IP addresses; the analytics endpoint refuses any encrypted column.

• Staff access: no impersonation capability; support and admin tooling reads account metadata and support messages only.

Annex III — Approved Sub-processors

CINTIMA engages the following Sub-processors in connection with providing IntiSafe:

• Clerk: Authentication and identity; membership and billing state. Data processed: name, email, sign-in method, profile details you add (such as a phone number, contact email, profile picture or device names), account and membership status, and push notification tokens.

• Stripe (via Clerk Billing): Payment processing. Data processed: name, email, billing address, payment details.

• Supabase: Database for project records and metadata. Data processed: encrypted content records and account metadata.

• Cloudflare: Application hosting, encrypted file storage (R2), and routing of support email replies. Data processed: encrypted file blobs; standard server and security logs (IP, request data); support replies you send by email.

• PowerSync: Data synchronization for the mobile app. Data processed: encrypted content records and your account identifier.

• Amazon Web Services (SES): Sending transactional and marketing email. Data processed: email address, name, message content, and delivery and engagement events.

• Convex: Backend for our support inbox, member and email records, in-app milestones, and admin tools. Data processed: support messages and the details in Privacy Policy Section 2.5; your member record, email engagement and milestone events.

• Google Workspace: Our support mailbox. Data processed: support email you send us and our replies.

• Sentry: Error and crash reporting. Data processed: stack traces, device or browser type, and app version; user identifiers and IP addresses are suppressed by configuration, and no session replay is enabled.

• OpenRouter, which routes to the model provider (currently Anthropic): AI triage of inbound support email (Privacy Policy Section 2.5). Data processed: the support message and its metadata.

• Expo: Delivering push notifications and updates to the mobile app. Data processed: push notification tokens and the technical device data needed to deliver updates.

• Framer: Hosting for our marketing website. Data processed: standard server logs and any details you submit through a form on that site.

Not sub-processors, but worth naming. Google and Apple act as sign-in providers if you choose to sign in with them. Hugging Face, GitHub and Google Fonts serve files your browser downloads (Privacy Policy Section 2.4) and receive only what any download reveals. Loops, our former email provider, no longer receives anything from us.

The Sub-processor list is kept current and published; changes are handled under Section A8.

Annex IV — Cross-Border Transfer Mechanism

Where Section A13 applies to you, the parties will complete and execute the Standard Contractual Clauses, Module Two (controller-to-processor), approved by the European Commission (Implementing Decision (EU) 2021/914), together with the UK International Data Transfer Addendum and/or the Swiss addendum, as applicable. The particulars required by those clauses are supplied by Annex I (details of processing), Annex II (technical and organizational measures), and Annex III (sub-processors). The operative clauses are not part of the standard online acceptance package; CINTIMA LLC provides and executes them on request at support@intisafe.app.