VERSION DRAFT-2026-07-20

Privacy Policy

A product-grounded description of data TwentyFour currently handles and the choices still requiring review.

Effective date: [LEGAL_EFFECTIVE_DATE — REQUIRED BEFORE LAUNCH]

Draft controller details

Controller/business: [LEGAL_ENTITY_NAME — REQUIRED BEFORE LAUNCH]; address: [LEGAL_BUSINESS_ADDRESS — REQUIRED BEFORE LAUNCH]; privacy contact: [PRIVACY_CONTACT_EMAIL — REQUIRED BEFORE LAUNCH]; jurisdiction: [LEGAL_JURISDICTION — REQUIRED BEFORE LAUNCH]. This is a development draft, not a verified statement of regional compliance.

Review requiredCOUNSEL REVIEW REQUIRED: confirm the legal entity, age gate, regions served, governing law, dispute terms, consumer-rights disclosures, and contact details before publication.

Data we collect and sources

We collect information directly from users, connected services, payment/provider webhooks, and the product’s operation.

  • Account and authentication: name, email, verification state, password hash, sessions, IP address and user-agent security data.
  • Creator inputs: series settings, pasted scripts, RSS URLs, Drive references, uploaded footage, branding, music choices, voice settings, captions, and publication metadata.
  • Generated and derived data: scripts, narration, timestamps, captions, previews, final videos, source/provenance records, AI-disclosure settings, hashes, and render status.
  • Connected accounts: OAuth scopes, provider account identifiers, display names, encrypted access/refresh tokens, token expiry, and publication history.
  • Billing: Stripe customer/subscription identifiers, checkout status, invoice/receipt links, amounts, currency, credit ledger and reservations; TwentyFour is not designed to store full card numbers.
  • Operations: request/correlation identifiers, rate-limit state, audit events, error diagnostics, usage/cost metrics, queue state, and service health.
  • Rights and safety: consent versions, asset attestations, reports, evidence supplied by reporters, case status, appeals, and legal holds.

Why we use data

We use data to create and secure accounts; provide previews, renders, storage, scheduling, billing, exports, deletion workflows and authorized publishing; attribute sources; prevent abuse; troubleshoot; measure service health and costs; handle reports; comply with law; and enforce agreements.

Review requiredCOUNSEL: map each purpose to applicable legal bases by region; the app does not yet present a complete GDPR/UK-GDPR legal-basis matrix.

Providers and subprocessors

Depending on configuration and user choices, data may be sent to OpenAI, Google Gemini, Anthropic, ElevenLabs, Pexels, Google Drive, Cloudflare R2, Stripe, TikTok, YouTube/Google, Instagram/Meta, hosting, PostgreSQL, Redis, email delivery, analytics, monitoring, or support providers. Reddit content retrieval is disabled; the current mode generates fictional Reddit-style stories and does not use Reddit API data.

Review requiredBUSINESS + PRIVACY COUNSEL: complete vendor contracts, DPAs, regions, transfer mechanisms, security review, and the live subprocessor list before launch.

Storage, transfers, and security

Database records are stored in the configured PostgreSQL service; queues/rate limits may use Redis; generated media may be stored locally in development or in configured Cloudflare R2 buckets. Provider processing locations depend on the contracted account and configuration. We do not claim a storage region that has not been verified.

Controls include server-only credentials, encrypted social tokens, access checks, private media routes, signed provider webhooks, audit logging with hashed IPs, and restricted admin roles. No system is risk-free.

Review requiredSECURITY + COUNSEL: verify production regions, encryption/key management, incident-response notices, international-transfer mechanisms, and vendor settings.

Retention and deletion

The technical retention schedule is documented separately and implemented through a dry-run-first cleanup job. Temporary previews default to 24 hours. Other periods are configurable and remain launch decisions. Account deletion is currently a protected request workflow, not instant erasure. Data may be retained for billing, security, disputes, reports, backups, or legal holds where lawful.

Review requiredBUSINESS + COUNSEL: approve each retention period and ensure deployed cleanup, backup expiry, provider deletion, and legal-hold release are tested.

Cookies and similar technology

The current app uses essential authentication/session cookies and may use provider cookies during OAuth or Stripe-hosted flows. No advertising-cookie or cross-site behavioral advertising implementation was found in this codebase. If analytics, advertising, or nonessential cookies are added, update this notice and implement regional consent/opt-out controls before enabling them.

Rights and choices

The account area offers export and deletion requests and provider disconnection. Depending on location and applicable law, users may have rights to access, correct, delete, restrict, object, port, or appeal; to withdraw consent; and to opt out of certain sale, sharing, targeted advertising, or automated-decision uses. Requests may require identity verification and may be limited by lawful exceptions.

Review requiredCOUNSEL: determine applicable rights and response periods. Regional choices placeholder: [LEGAL_REGIONAL_PRIVACY_CHOICES — REQUIRED BEFORE LAUNCH].

Children

The intended minimum age is not yet chosen: [LEGAL_MINIMUM_AGE — REQUIRED BEFORE LAUNCH]. TwentyFour is not presently designed for children or parental consent. The FTC explains COPPA obligations for services directed to children under 13 or with actual knowledge of collection from them, and OpenAI requires additional safeguards for under-18 API experiences.

Review requiredBUSINESS + COUNSEL: set and technically enforce the age threshold before launch. See https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions.

Changes and contact

Material changes receive a new policy version and may trigger renewed acceptance. Contact [PRIVACY_CONTACT_EMAIL — REQUIRED BEFORE LAUNCH] for privacy requests and [LEGAL_SUPPORT_EMAIL — REQUIRED BEFORE LAUNCH] for product support.

Review requiredCOUNSEL REVIEW REQUIRED: confirm the legal entity, age gate, regions served, governing law, dispute terms, consumer-rights disclosures, and contact details before publication.