ArchivePatternsPricingFor agents

Privacy policy

What personal data Cutmap keeps, why, and what you can do about it.

Draft, last updated 8 October 2026. A lawyer has not checked this yet. Words in [square brackets] are placeholders or notes to fill in before launch.

Contents
  1. 01Who we are
  2. 02The short version
  3. 03What we collect
  4. 04People in the films
  5. 05How we use it, and why
  6. 06Cookies
  7. 07Who we share it with
  8. 08Data outside the UK
  9. 09How long we keep it
  10. 10Your rights
  11. 11Children
  12. 12Security
  13. 13Changes to this policy
  14. 14Contact

01 Who we are

Cutmap (cutmap.co) is run by [Company legal name], a company registered in [England and Wales] with company number [Company number], at [Registered address]. Cutmap is a Framebox product.

We are the controller of the personal data described here. Our ICO registration number is [ICO registration number]. For anything about your data, email [Contact email].

02 The short version

  • We keep only what we need to run accounts, teams, plans and agent access.
  • You sign in with a code sent to your email. We don’t have passwords.
  • We use cookies only to keep you signed in. We don’t use analytics, advertising or tracking cookies.
  • We don’t sell your data, and we don’t send your account data to AI providers.

03 What we collect

Your account. Your email address. If you fill in the welcome questions: your name, your role, what you make, the tools you use, and the plan you picked. We also record which team you are working in and when you finished signing up. When you ask for a code for a new address, we create your account straight away (your email address and a personal Free space), even if the code is never used.

Sign-ins. Our sign-in provider, Supabase, records each sign-in session with its internet address, browser and times, and keeps a log of sign-ins, sign-ups and invites with your email address.

Teams. The team’s name, plan, status, seats and billing dates, who owns it, and each member’s role. For invites: the invited email address, who sent it, when, and whether it was accepted. When someone invites you, we email you a link to join. If your address has no Cutmap account yet, sending the invite creates one (your email address and a personal Free space) before you accept.

Usage. We record, with your account, your team and the time:

  • each film you open on a paid plan, and each film request on the website;
  • each breakdown your agents read, and each agent search and call.

We use these records to count your allowance, apply the fair-use limits and spot scraping. Your account page shows your recent views.

Agents and API keys. For each agent sign-in or API key: its name (the agent’s name, or the label you chose), a short prefix so you can tell keys apart, a hash of the token (never the token itself), and when it was created, last used, and when it expires or was revoked. When an agent registers with us, we keep its name, the addresses it asked us to return to, and a hash of the internet address it registered from, used to limit sign-ups. The hash can still identify an address, so we treat it as personal data.

Payments. Once payments are live, Stripe takes your card details. We never see or store your full card number. We keep your Stripe customer and subscription references, your plan and its status, and the top-ups you have bought.

Removal requests. Your name, email address, the film’s link, your relationship to the film, and your message.

Waitlist. If you joined our waitlist before sign-up opened: your email address, the page you joined from, and the plan you were interested in.

Emails you send us, and our replies.

Server logs. Our hosting providers keep short-lived logs of requests (internet address, browser, the page asked for and the time) for security and fixing faults. [Confirm log retention for our Vercel and Supabase plans.]

04 People in the films

The films in the library were posted publicly. A breakdown may include the name, handle and profile image (logo) of the account that posted the film, the maker and the brand where known, words spoken or shown in the film, and still frames in which people may appear.

We use this to describe and credit each film. Our lawful basis is legitimate interests: running a reference library and crediting the people who made the work. We don’t build profiles of the people in films.

To write a breakdown, we send the film’s frames, details and measurements to Anthropic (Claude). If a film has a voiceover, we may send its audio to OpenAI (Whisper) to transcribe it. We delete our downloaded copy of a film once its breakdown and frames are made: within minutes for most films, or when the analysis comes back (usually within a day) for films analysed in bulk. Films Framebox owns are kept.

If you appear in a film, or own one, and want its breakdown removed, use the form on our Source policy page or email us.

05 How we use it, and why

UK GDPR asks us to give a lawful basis for each use.

  • To create your account, sign you in, and run your team, plan, allowance and payments. Basis: to perform our contract with you.
  • To send sign-in codes, invites and messages about your account. Basis: contract.
  • To apply fair-use and rate limits, stop scraping and abuse, and keep Cutmap secure. Basis: legitimate interests (protecting the service and the library).
  • To understand who uses Cutmap, from your optional welcome answers, and decide which films to add. Basis: legitimate interests.
  • To handle removal requests and messages. Basis: legitimate interests.
  • To email you when payments open, if you picked a paid plan. Basis: legitimate interests (you asked us to hold your place).
  • To keep billing records. Basis: legal obligation.

Fair-use and rate limits are applied automatically. They pause access for a short time and have no legal or similar effect on you.

We don’t send other marketing emails without your consent. [Owner: confirm whether any other launch or product emails are planned, and how people unsubscribe.]

06 Cookies

We set our own sign-in cookies (names start with sb-, set by Supabase’s sign-in library) only when you ask for a code or sign in. They keep you signed in and last up to 400 days, or until you sign out. They are strictly necessary, so we don’t ask for consent. If you just browse, we set no cookies.

We don’t use analytics, advertising or tracking cookies. Our fonts are served from our own site.

Video players. Film pages play films from where they were posted. YouTube films use YouTube’s privacy-enhanced player (youtube-nocookie.com), and Vimeo and X players are loaded with “do not track” turned on. Most films from X play X’s own video file in our player, loaded from X’s servers as soon as the page opens, so X receives your internet address. These platforms may still set cookies or store data on your device when the player loads or when you press play, and their own privacy policies apply. [Lawyer: confirm whether the embedded players need consent under PECR.]

07 Who we share it with

We use these providers to run Cutmap. They process data for us, under contract:

  • Supabase: database, sign-in and file storage. All account, team and usage data is stored here. Stored in [region].
  • Vercel: hosts the website and the MCP endpoint.
  • [Worker host: Railway or Fly]: runs the program that fetches and measures films.
  • Anthropic (Claude): analyses public films to write breakdowns. It receives film frames, details, measurements and transcripts, not your account data.
  • OpenAI (Whisper): transcribes the voiceover of some public films. It receives film audio only.
  • [Email provider]: sends sign-in codes and invites.
  • Stripe: takes payments, once payments are live. Stripe also uses some data for its own fraud checks, under its own privacy policy.

Your team. Members of a team can see each other’s names and email addresses, and the addresses of open invites.

We may also share data when the law requires it, to protect people or Cutmap, or with a buyer if the business is sold. We never sell personal data.

08 Data outside the UK

Some of our providers are based in, or process data in, the United States. When personal data leaves the UK, we rely on [UK adequacy regulations (the UK–US data bridge) or the UK International Data Transfer Addendum, per provider]. Ask us for details.

09 How long we keep it

  • Account, profile and team data: while your account is open. When you delete your account, we delete it within [30 days], apart from billing records.
  • Accounts never signed in to: [e.g. deleted after 30 days].
  • Sign-in records: [Confirm Supabase session and audit-log retention].
  • Usage records: [24 months], then deleted.
  • Agent access: access tokens expire after an hour. An agent sign-in ends after 90 days without use, or when you sign the agent out. API keys last until you revoke them. Records of ended sign-ins and revoked keys are kept for [12 months] for security.
  • Agent registrations: removed if the agent never finishes signing in, after at least a day. Registrations that did sign in, with their hashed address, are kept until [e.g. 12 months after the agent’s last sign-in ends]. Agent sign-in codes expire after 10 minutes and work once.
  • Invites: expire after 14 days. Kept for [12 months].
  • Removal requests: [6 years], so we can show what we did.
  • Waitlist: until you ask us to remove you, or [12 months] after payments open.
  • Billing records: [6 years], as UK tax law requires.
  • Downloaded films: deleted once the breakdown and frames are made (within a day for bulk imports). Framebox’s own films are kept.

10 Your rights

Under UK GDPR, you can ask us to:

  • give you a copy of your personal data;
  • correct data that is wrong;
  • delete your data;
  • limit how we use it;
  • stop using it where we rely on legitimate interests;
  • send your data to you or another service in a common format.

Where we rely on your consent, you can withdraw it at any time.

To use any of these rights, email [Contact email] from the address you sign in with. It’s free. We will reply within one month, and may ask you to confirm who you are. You can sign agents out and revoke API keys yourself on your account page.

If you are unhappy with how we handle your data, please tell us. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.

11 Children

Cutmap is not for children. You must be 16 or over to have an account. We don’t knowingly keep data about anyone under 16. If you think a child has signed up, email us and we will delete the account.

12 Security

  • Sign-in uses one-time codes sent by email, so there are no passwords to leak.
  • API keys, agent tokens and sign-in codes are stored only as hashes.
  • The database only lets people read their own account and their own teams. Changes go through our server, which checks who is asking.
  • Everything travels over encrypted connections (HTTPS). [Confirm encryption at rest with Supabase.]

If we have a data breach that puts you at risk, we will tell you and the ICO as the law requires.

13 Changes to this policy

We will post any update on this page with a new date. If a change matters, we will email account holders before it takes effect.

14 Contact

[Company legal name], [Registered address]. Company number [Company number].

Email: [Contact email]

Terms of service · Source policy

Give AI better prompts.
ArchivePatternsSource policyRequest removalTermsPrivacyA Framebox product