A Film of Her Life is the studio name. The operator is responsible for deciding how personal data is used to provide the service.
Legal operator
[Legal name and, if applicable, company representative — to be confirmed]
Business address
[Business address and country — to be confirmed]
Privacy contact
[Privacy email and alternative contact — to be confirmed]
The operating base is currently Japan. The first paying markets and any country-specific notices must be confirmed before the final policy is published.
What we save and why
When you begin or sign in
We save your name, verified email, room access records and conversation allowance. Resend receives your email address and a temporary sign-in link to deliver the email. Sign-in emails are not marketing subscriptions. Verification links expire after 15 minutes; new email sign-ins return you to the same room.
When you buy a film
Stripe handles payment details on its checkout page. We keep order references, payment status, film length and upgrade credit to fulfil your purchase. We do not store your card number. Your family stories, recordings and private room link are not sent to Stripe for checkout. These integrations are prepared for launch and are not active in this review draft.
When you enquire
We save your name, email, film preference and the message you send so the studio can consider your project and contact you. An enquiry does not create a paid account, start an interview or send the enquiry to an AI service. Please leave private family stories out of this first form.
When you use your room
We save submitted recordings and transcripts, written memories, photos, videos, documents, and any names, dates or descriptions you add. We also save sharing choices, permissions, topic connections, film preferences, comments, review submissions and generated working plans. Earlier versions and unfinished work may also remain in our systems. Family stories can include sensitive details such as health, religion or relationships; only share what is needed and what you are entitled to provide.
We use this information to organise your material, prepare suggestions, make and review the agreed film, and keep your room working. Descriptions for photos are optional. You can use photos without filling every field. Optional AI photo analysis can produce unverified descriptions; it does not establish people’s identities or confirm facts.
When you ask for help
AI Help sends the question you submit to Anthropic to select a task guide. It does not send your full family collection or add the question to June’s story memory. A problem report you deliberately send is saved for the team. Optional dictation sends a short recording to OpenAI so it can be turned into editable words.
To operate the service safely
We keep access records, permission and request records, usage information, and technical diagnostics. Some conversation diagnostics may contain story excerpts. These records support security, troubleshooting and service administration; they are not all anonymous.
Who can see your material?
Your private link gives access to a particular room and role. Keep it safe. Anyone who obtains a working link may be able to use that access.
The project organiser can review the project’s conversations. Contributor access and reuse depend on the sharing choices shown beside each kind of material. “Private” does not always mean “only me”: read the audience description before saving.
The studio operator needs access for editing, support and administration. AI, hosting and backup providers process the information needed for their part of the service. This is not a service where only the family holds the decryption keys.
Family material is not published as a public example without separate permission. Buying a film does not give the buyer automatic authority over another adult’s participation or personal data. Tell us if family members disagree about use or access.
[Confirm the final commitments on no sale, no advertising reuse, and no general-purpose training, including supplier account settings, before publication.]
Which services help us?
The service named on the interview or permission screen matters. Different features send different information. These providers may process data outside your country, including in the United States.
ElevenLabs — voice interviews and narration
The current June voice pilot sends microphone audio and a permission-filtered story brief to ElevenLabs Agents. ElevenLabs handles the spoken conversation and its transcript. Film narration sends narration text to ElevenLabs to create audio.
Provider-held conversations are separate from the recording saved in your room. The current voice-agent settings have no automatic expiry for conversation history, and zero-retention mode is off. Provider-side audio saving is disabled, but ElevenLabs still processes audio to run the conversation. Removing a file here does not delete a provider-held conversation.
Eligible story text helps prepare the notebook and film plan. With the relevant permission, document text, photo previews and sampled video frames can be analysed. Some interview configurations also use Anthropic for the conversation. AI Help sends only the question you choose to submit.
OpenAI — selected speech and illustration features
Optional dictation sends a short audio clip for transcription. Certain interview configurations use OpenAI speech processing, as explained before starting. Supported atmospheric illustration features use restricted prompts; the current illustration path does not send family photos or transcripts to make those images.
The temporary dictation file on our server is removed after processing. Provider retention is a separate matter.
The hosted pilot keeps saved material on a DigitalOcean server in the United States. Backups are stored in an encrypted repository in a private Backblaze bucket. The operator can access the backup with its key. Backups are not the same as copies you download.
AI can make mistakes. Please check transcripts, names, dates and the meaning of suggested chapters. A suggestion is not a confirmed fact or proof that a picture is already in your finished film.
The current pilot does not automatically create a clone of your voice.
[Before publication: confirm supplier account training choices, actual retention periods, subprocessors/countries, contracts and the applicable overseas-transfer safeguards. A link to a supplier’s policy is not a substitute for these checks.]
How long do we keep it?
Current pilot: saved story material is kept for the ongoing project. There is not yet an automatic permanent-deletion schedule for completed projects or expired removals. A 30-day restore window does not mean a file is erased on day 31.
Prepared download ZIPs are temporary and expire after 24 hours. Their expiry does not remove your original memories. Dictation uses temporary server files, removed after processing.
Backups, old working versions, diagnostic records and provider-held copies have their own lifecycles. We cannot yet promise that all of them expire after a fixed number of days.
[Final schedule to approve and implement: active and completed projects, unfinished projects, enquiries, help messages, diagnostics, permission/request records, temporary work and backup expiry. Include notice and export arrangements before scheduled closure.]
There is no public Family Archive subscription at present and no promise of permanent or lifetime hosting. Do not rely on the room as your only copy.
Your choices and privacy requests
Get a copy: open Settings in your room, choose “Download my memories”, then “Prepare my download”. It includes accessible saved material and available films, not every internal record or unreleased draft. Ask us if you need a wider personal-data access response.
Correct information: edit the descriptions you can change in your room, or ask the team to correct a transcript, name or other personal information. Tell us if the change also affects a notebook or film.
Stop a use: change relevant sharing or optional AI choices, or ask the team to stop a particular use. This cannot recall information already sent to a provider or erase a delivered family copy.
Ask for deletion: you can request deletion of your personal data without being the buyer or holding a room link. We will check identity, authority and scope before acting.
Raise a concern: ask a privacy question, complain or ask us to review a response. Depending on the law that applies, you may also have rights to restriction, objection, portability, an appeal or a complaint to a regulator.
We explain the outcome, any lawful limits and the applicable response timeframe. We ask only for information needed to verify and handle the request. Please do not send a passport, password or private room link in an initial message.
A request is not permission to publish, train a model or start an interview. You do not need to buy a film or an archive plan to make a privacy request.
[Confirm the request owner, monitoring routine, applicable deadlines, secure verification, response/appeal process and any lawful access fee before launch.]
Removal and permanent deletion are different
Remove from the room
Removing a photo, video or document hides it from the active collection and new use. “Recently removed” in Settings lets you restore eligible items for 30 days. Removal does not erase backups, old outputs or downloaded copies. An existing notebook or film may need a new review.
Request permanent deletion
Organisers can request whole-project deletion in Settings. Other contributors, people mentioned in a story and people without access can contact the team about their own personal data. Whole-project requests must account for other contributors’ material and rights.
The team confirms who is asking and what should be deleted or restricted.
It identifies related originals, transcripts, working copies, hosted films and relevant provider copies.
It handles live storage, backups and provider requests separately, with any justified exceptions explained.
It reports what was completed, what remains and why.
Current limitation: there is no verified, automatic end-to-end erasure tool covering every copy. A saved request or a dashboard status is not a deletion receipt.
We cannot erase a film or document already downloaded by relatives or remove copies held independently by someone else. Limited records may need to remain for a specific legal duty or dispute; this is not a reason to keep an entire story indefinitely.
[Complete and test the live-store, backup, provider and operator-copy erasure procedure before promising a deletion deadline or “all copies deleted”.]
How the pilot protects access
The hosted website uses HTTPS. Private links have role-based access, and the operator dashboard requires separate access. Backups use an encrypted repository. Download requests follow the room’s access permissions. These measures reduce risk, but no service can promise that a security incident is impossible.
If you think a private link has been shared or someone has gained access, contact the team. We need to check access and arrange the appropriate response. If a breach requires notification, the final operating process must notify affected people and authorities under the law that applies.
[Verify operator/device access controls, diagnostic minimisation, supplier safeguards, incident response and the complete backup/restore process before final sign-off.]
Your browser and downloaded copies
The room can keep unsaved film comments in temporary browser-tab storage to help recover them after a connection problem. Shared devices, browser history and downloads can also retain private information. Close the tab when finished on a shared device and store downloaded files carefully.
The reviewed public website does not include advertising trackers or an analytics script. Its current application does not change behaviour in response to a browser’s “Do Not Track” setting. Some existing pages load fonts from Google, which receives the ordinary connection information needed to deliver them. Links to external sites are governed by those sites’ policies. These new policy pages use your device’s fonts.
[Confirm the final cookie/browser-storage inventory and any future analytics or embedded media before launch. Adding a tracker needs a separate notice and any legally required choice.]
Stories about other people
Only upload material you have permission to use. Avoid adding another living person’s sensitive information unnecessarily. Historic family photos can include children; that does not give permission for public use, identification or voice cloning.
Someone mentioned in a story can raise a concern about their own personal data. If a storyteller dies or cannot decide for themselves, we need to verify the authority of the person asking; the buyer does not automatically gain every right over everyone’s material.
[Confirm participant-age rules, guardian/representative procedures and disputed or deceased-person material before paid launch.]
How to contact us
Use “Contact the team” in your room for a saved message, or the privacy request page if you do not have access. The current request system saves messages for operator review; it does not provide a live response or send an automatic email.
[Privacy email, business postal address and alternative contact — to be confirmed]
The final policy will identify the relevant complaint and appeal routes for the countries and states we serve. You can contact the appropriate data-protection authority where applicable.
The final notice will show its effective date. Changes to purposes, providers, sharing or retention need clear notice and any new permission required by law. A policy update is not blanket permission to use earlier material for a new purpose.
[Effective date and customer-notification process — to be confirmed]