Privacy Policy
Last updated: 6 October 2026
This policy explains what personal data HeyCaveman collects, why, who we share it with, and the choices and rights you have. The short version: we use your data to make your videos, we don't sell it, and analytics only run if you say yes.
1. Who we are
Spacenos Technologies Private Limited operates HeyCaveman and is the controller of the personal data described in this policy. Contact us about privacy at support@heycaveman.com.
2. What we collect
- Account data: your email address and account identifiers. Sign-in is by emailed code or magic link; we do not use or store passwords.
- Content: scripts, project settings and the video timeline you create, plus generated media such as narration audio, AI drawings and rendered MP4s.
- Usage data: plan, quotas and usage counters (for example renders and AI calls), and timestamps.
- Billing data: subscription status and payment history from Razorpay. We never see your full card number, UPI or bank credentials.
- Your own API keys if you add them (stored encrypted with AES-256-GCM).
- Technical data: IP address, browser, device and error traces (via Sentry), and server logs.
- Analytics data (only if you consent): pages visited, interactions and session recordings via Google Analytics and Microsoft Clarity.
Photos for "character from photo" are analysed in memory to design a character and are not stored.
3. How we use it and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Create your account, sign you in, and provide the studio, AI direction, narration and rendering | Performance of our contract with you |
| Process payments and manage subscriptions | Contract; legal obligation (tax and accounting records) |
| Send service emails (sign-in codes, deletion reminders, billing notices) | Contract; legitimate interests |
| Keep the Service secure, prevent abuse of the Free plan, and fix errors (Sentry) | Legitimate interests |
| Analytics and session replay (Google Analytics, Microsoft Clarity) | Consent — you can withdraw it at any time |
| Comply with law and respond to lawful requests | Legal obligation |
4. AI processing
To make your video, your script is sent to Anthropic (Claude), which directs the video. In illustrated mode, image prompts derived from your script are sent to an image provider (OpenAI, Google Gemini or Cloudflare). Narration text is converted to speech by our self-hosted Kokoro model and, where needed, a third-party text-to-speech service.
We use these providers through their APIs, and where a provider offers the option we use settings that do not allow your inputs to be used to train its models. Each provider may retain inputs for a limited time under its own terms (for example for abuse monitoring). If you add your own API keys (BYOK), those requests run under your account with that provider and its terms and privacy policy apply.
Background photos, videos and icons are fetched from Openverse, Wikimedia Commons, Pixabay and Iconify. Search terms derived from your script may be sent to those services.
5. How long we keep data
- Projects are deleted automatically after a set period from creation — currently 15 days on Free and 45 days on Pro, as shown in your dashboard. We email you about 3 days beforehand (you can turn this off).
- Generated media (narration audio, rendered MP4s, AI drawings) is kept for up to about 46 days, then deleted. Please download your MP4s.
- Account data is kept while your account exists and deleted when you delete your account, except where we must keep limited records (for example billing records for tax law).
- Error data in Sentry and analytics data are kept according to those services' retention settings (typically 90 days for errors and up to 14 months for analytics).
8. International transfers
Some providers process data outside your country, including in the United States. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK Addendum, or the EU-US Data Privacy Framework.
9. Security
We use encryption in transit (HTTPS), httpOnly session cookies, encryption of stored API keys (AES-256-GCM), access controls and least-privilege service accounts. No system is perfectly secure; if a breach affects your data we will notify you and regulators as required by law.
10. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or CCPA/CPRA), you have the right to:
- Access and portability — use Settings → Download my data.
- Deletion — use Settings → Delete account, which removes your account and projects.
- Correction of inaccurate data.
- Objection or restriction of processing based on legitimate interests.
- Withdraw consent for analytics at any time via Cookie settings.
- Non-discrimination for exercising your rights (California).
For anything else, email support@heycaveman.com. We respond within 30 days (45 days under the CCPA). You may also complain to your local data protection authority.
11. Children
HeyCaveman is not intended for children under 13 (or under 16 in the European Economic Area, the UK and Switzerland). We do not knowingly collect their data; if you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy. If changes are material, we will notify you by email or in the Service before they take effect. The "Last updated" date above shows the latest version.
13. Contact
Privacy questions or requests: support@heycaveman.com.