Draft controller details
Controller/business: [LEGAL_ENTITY_NAME — REQUIRED BEFORE LAUNCH]; address: [LEGAL_BUSINESS_ADDRESS — REQUIRED BEFORE LAUNCH]; privacy contact: [PRIVACY_CONTACT_EMAIL — REQUIRED BEFORE LAUNCH]; jurisdiction: [LEGAL_JURISDICTION — REQUIRED BEFORE LAUNCH]. This is a development draft, not a verified statement of regional compliance.
Data we collect and sources
We collect information directly from users, connected services, payment/provider webhooks, and the product’s operation.
- Account and authentication: name, email, verification state, password hash, sessions, IP address and user-agent security data.
- Creator inputs: series settings, pasted scripts, RSS URLs, Drive references, uploaded footage, branding, music choices, voice settings, captions, and publication metadata.
- Generated and derived data: scripts, narration, timestamps, captions, previews, final videos, source/provenance records, AI-disclosure settings, hashes, and render status.
- Connected accounts: OAuth scopes, provider account identifiers, display names, encrypted access/refresh tokens, token expiry, and publication history.
- Billing: Stripe customer/subscription identifiers, checkout status, invoice/receipt links, amounts, currency, credit ledger and reservations; TwentyFour is not designed to store full card numbers.
- Operations: request/correlation identifiers, rate-limit state, audit events, error diagnostics, usage/cost metrics, queue state, and service health.
- Rights and safety: consent versions, asset attestations, reports, evidence supplied by reporters, case status, appeals, and legal holds.
Why we use data
We use data to create and secure accounts; provide previews, renders, storage, scheduling, billing, exports, deletion workflows and authorized publishing; attribute sources; prevent abuse; troubleshoot; measure service health and costs; handle reports; comply with law; and enforce agreements.
Providers and subprocessors
Depending on configuration and user choices, data may be sent to OpenAI, Google Gemini, Anthropic, ElevenLabs, Pexels, Google Drive, Cloudflare R2, Stripe, TikTok, YouTube/Google, Instagram/Meta, hosting, PostgreSQL, Redis, email delivery, analytics, monitoring, or support providers. Reddit content retrieval is disabled; the current mode generates fictional Reddit-style stories and does not use Reddit API data.
Storage, transfers, and security
Database records are stored in the configured PostgreSQL service; queues/rate limits may use Redis; generated media may be stored locally in development or in configured Cloudflare R2 buckets. Provider processing locations depend on the contracted account and configuration. We do not claim a storage region that has not been verified.
Controls include server-only credentials, encrypted social tokens, access checks, private media routes, signed provider webhooks, audit logging with hashed IPs, and restricted admin roles. No system is risk-free.
Retention and deletion
The technical retention schedule is documented separately and implemented through a dry-run-first cleanup job. Temporary previews default to 24 hours. Other periods are configurable and remain launch decisions. Account deletion is currently a protected request workflow, not instant erasure. Data may be retained for billing, security, disputes, reports, backups, or legal holds where lawful.
Cookies and similar technology
The current app uses essential authentication/session cookies and may use provider cookies during OAuth or Stripe-hosted flows. No advertising-cookie or cross-site behavioral advertising implementation was found in this codebase. If analytics, advertising, or nonessential cookies are added, update this notice and implement regional consent/opt-out controls before enabling them.
Rights and choices
The account area offers export and deletion requests and provider disconnection. Depending on location and applicable law, users may have rights to access, correct, delete, restrict, object, port, or appeal; to withdraw consent; and to opt out of certain sale, sharing, targeted advertising, or automated-decision uses. Requests may require identity verification and may be limited by lawful exceptions.
Children
The intended minimum age is not yet chosen: [LEGAL_MINIMUM_AGE — REQUIRED BEFORE LAUNCH]. TwentyFour is not presently designed for children or parental consent. The FTC explains COPPA obligations for services directed to children under 13 or with actual knowledge of collection from them, and OpenAI requires additional safeguards for under-18 API experiences.
Changes and contact
Material changes receive a new policy version and may trigger renewed acceptance. Contact [PRIVACY_CONTACT_EMAIL — REQUIRED BEFORE LAUNCH] for privacy requests and [LEGAL_SUPPORT_EMAIL — REQUIRED BEFORE LAUNCH] for product support.