Privacy Policy
Last updated: July 17, 2026
1. Information We Collect
We collect information you provide directly to us, such as when you create an account, upload scripts, or contact us for support. This includes:
- Name and email address
- Payment information (processed securely via Stripe — we never store card numbers)
- Script content and production documents you upload
- Usage data and feature interaction logs
- Correspondence sent to our support, sales, billing, privacy, or legal email addresses, including sender and recipient details, subject, plain-text body, selected headers, full raw MIME content, and attachment metadata
- Attachment bytes that our inbound-mail security controls quarantine for restricted operator review
2. How We Use Your Information
We use the information we collect to provide, maintain, and improve AppleBoxe, process transactions, send transactional emails (call sheets, notifications), and respond to support requests. We do not sell your personal data to third parties.
3. Script & Production Data
Your uploaded scripts and production documents are stored securely and are only accessible to you and members of your organization that you explicitly invite. We do not use your script content to train AI models without your explicit consent.
4. Data Retention
We retain account, script, and production data while your account is active and as needed to provide AppleBoxe. For inbound correspondence, our scheduled retention periods are 365 days for support, sales, and billing operations; 730 days for privacy requests; and 2,555 days for legal correspondence and inbound-mail audit records. A legal hold or another legal obligation may require us to retain relevant records longer. Inbound messages remain in access-controlled AppleBoxe systems and are not automatically forwarded to a personal inbox.
A confirmed account deletion removes the account identity and eligible AppleBoxe product data, subject to team-workspace transfer, billing-transfer, security, dispute, and legal requirements. File or payment-provider cleanup may complete asynchronously if a provider is unavailable. Minimal Stripe customer and subscription identifiers remain in the cleanup queue during automated retries and, if necessary, dead-letter review; completed cleanup records are retained for 30 days for reconciliation. Stripe may separately retain transaction records under its own legal obligations and privacy policy. You may contact [email protected] for privacy assistance.
5. Cookies
We use session cookies for authentication and essential platform functionality. We do not use third-party advertising cookies.
6. Third-Party Services
AppleBoxe integrates with the following third-party services, each with their own privacy policies:
- Supabase — Authentication and database storage
- Stripe — Payment processing
- Resend — Transactional email delivery, including replies from our operator inboxes
- Anthropic — AI-powered script analysis (data processed per its API terms)
- Cloudflare — Content delivery, application security, Turnstile bot detection, and inbound-mail processing through Email Routing, Workers, and Queues; mailbox content and audit data are stored in D1 and private R2 storage, with operator access controlled by Cloudflare Access
7. Security
We implement industry-standard security measures including TLS encryption in transit, row-level security in our database, and hashed credential storage. No method of transmission over the internet is 100% secure, but we take reasonable steps to protect your data.
8. Contact
Questions about this policy? Contact us at [email protected].