Privacy Policy
Last updated: March 26, 2026
1. Information We Collect
Account information
When you create an account, we collect your email address and authentication credentials (managed by Supabase Auth). We do not store passwords directly.
Content you create
Scripts, voice audio, caption settings, and rendered videos are stored to provide the Service. This content is associated with your account and not shared with other users unless you explicitly make it public.
API keys (BYOK)
If you provide your own API keys for third-party services, they are encrypted at rest using AES-256 via pgcrypto and stored in our database. Keys are decrypted only at the moment of use and never logged or transmitted to any party other than the intended service provider.
Usage data
We collect basic usage metrics (render counts, feature usage) to improve the Service. We do not use third-party analytics trackers. No data is sold to advertisers.
2. How We Use Your Information
- To provide and improve the Service.
- To process your subscription and billing.
- To communicate about your account (billing, security, feature updates).
- To enforce our Terms of Service.
3. Data Storage and Security
- Data is stored on managed infrastructure (Supabase for database and auth, Cloudflare R2 for media files).
- All connections use TLS encryption in transit.
- API keys are encrypted at rest with a dedicated encryption secret.
- We follow OWASP security best practices for application development.
4. Third-Party Services
The Service integrates with third-party providers for specific features:
- AI/LLM: Google Gemini, OpenAI — for script generation.
- TTS: Kokoro (self-hosted), OpenAI, ElevenLabs — for voice synthesis.
- Stock media: Pexels, Pixabay — for B-roll sourcing.
- Billing: Paddle — for subscription payments.
- Auth: Supabase — for authentication.
Each provider has its own privacy policy. We only share the minimum data required for each service to function (e.g., script text to generate voice audio).
5. Data Retention
- Active accounts: data retained as long as your account is active.
- Cancelled accounts: data retained for 90 days after downgrade, then deleted.
- Deleted accounts: data permanently removed within 30 days of account deletion.
6. Your Rights
Under POPIA (Protection of Personal Information Act, South Africa), you have the right to:
- Access your personal data.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to processing of your data.
- Export your data in a portable format.
To exercise these rights, email support@simakk.co.za.
7. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party advertising cookies.
8. Children
The Service is not intended for use by individuals under 18 years of age. We do not knowingly collect data from minors.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email. Continued use after changes constitutes acceptance.
10. Contact
For privacy-related inquiries, contact us at support@simakk.co.za.