Privacy policy
What personal data Cutmap keeps, why, and what you can do about it.
Draft, last updated 8 October 2026. A lawyer has not checked this yet. Words in [square brackets] are placeholders or notes to fill in before launch.
01 Who we are
Cutmap (cutmap.co) is run by [Company legal name], a company registered in [England and Wales] with company number [Company number], at [Registered address]. Cutmap is a Framebox product.
We are the controller of the personal data described here. Our ICO registration number is [ICO registration number]. For anything about your data, email [Contact email].
02 The short version
- We keep only what we need to run accounts, teams, plans and agent access.
- You sign in with a code sent to your email. We don’t have passwords.
- We use cookies only to keep you signed in. We don’t use analytics, advertising or tracking cookies.
- We don’t sell your data, and we don’t send your account data to AI providers.
03 What we collect
Your account. Your email address. If you fill in the welcome questions: your name, your role, what you make, the tools you use, and the plan you picked. We also record which team you are working in and when you finished signing up. When you ask for a code for a new address, we create your account straight away (your email address and a personal Free space), even if the code is never used.
Sign-ins. Our sign-in provider, Supabase, records each sign-in session with its internet address, browser and times, and keeps a log of sign-ins, sign-ups and invites with your email address.
Teams. The team’s name, plan, status, seats and billing dates, who owns it, and each member’s role. For invites: the invited email address, who sent it, when, and whether it was accepted. When someone invites you, we email you a link to join. If your address has no Cutmap account yet, sending the invite creates one (your email address and a personal Free space) before you accept.
Usage. We record, with your account, your team and the time:
- each film you open on a paid plan, and each film request on the website;
- each breakdown your agents read, and each agent search and call.
We use these records to count your allowance, apply the fair-use limits and spot scraping. Your account page shows your recent views.
Agents and API keys. For each agent sign-in or API key: its name (the agent’s name, or the label you chose), a short prefix so you can tell keys apart, a hash of the token (never the token itself), and when it was created, last used, and when it expires or was revoked. When an agent registers with us, we keep its name, the addresses it asked us to return to, and a hash of the internet address it registered from, used to limit sign-ups. The hash can still identify an address, so we treat it as personal data.
Payments. Once payments are live, Stripe takes your card details. We never see or store your full card number. We keep your Stripe customer and subscription references, your plan and its status, and the top-ups you have bought.
Removal requests. Your name, email address, the film’s link, your relationship to the film, and your message.
Waitlist. If you joined our waitlist before sign-up opened: your email address, the page you joined from, and the plan you were interested in.
Emails you send us, and our replies.
Server logs. Our hosting providers keep short-lived logs of requests (internet address, browser, the page asked for and the time) for security and fixing faults. [Confirm log retention for our Vercel and Supabase plans.]
04 People in the films
The films in the library were posted publicly. A breakdown may include the name, handle and profile image (logo) of the account that posted the film, the maker and the brand where known, words spoken or shown in the film, and still frames in which people may appear.
We use this to describe and credit each film. Our lawful basis is legitimate interests: running a reference library and crediting the people who made the work. We don’t build profiles of the people in films.
To write a breakdown, we send the film’s frames, details and measurements to Anthropic (Claude). If a film has a voiceover, we may send its audio to OpenAI (Whisper) to transcribe it. We delete our downloaded copy of a film once its breakdown and frames are made: within minutes for most films, or when the analysis comes back (usually within a day) for films analysed in bulk. Films Framebox owns are kept.
If you appear in a film, or own one, and want its breakdown removed, use the form on our Source policy page or email us.
05 How we use it, and why
UK GDPR asks us to give a lawful basis for each use.
- To create your account, sign you in, and run your team, plan, allowance and payments. Basis: to perform our contract with you.
- To send sign-in codes, invites and messages about your account. Basis: contract.
- To apply fair-use and rate limits, stop scraping and abuse, and keep Cutmap secure. Basis: legitimate interests (protecting the service and the library).
- To understand who uses Cutmap, from your optional welcome answers, and decide which films to add. Basis: legitimate interests.
- To handle removal requests and messages. Basis: legitimate interests.
- To email you when payments open, if you picked a paid plan. Basis: legitimate interests (you asked us to hold your place).
- To keep billing records. Basis: legal obligation.
Fair-use and rate limits are applied automatically. They pause access for a short time and have no legal or similar effect on you.
We don’t send other marketing emails without your consent. [Owner: confirm whether any other launch or product emails are planned, and how people unsubscribe.]
08 Data outside the UK
Some of our providers are based in, or process data in, the United States. When personal data leaves the UK, we rely on [UK adequacy regulations (the UK–US data bridge) or the UK International Data Transfer Addendum, per provider]. Ask us for details.
09 How long we keep it
- Account, profile and team data: while your account is open. When you delete your account, we delete it within [30 days], apart from billing records.
- Accounts never signed in to: [e.g. deleted after 30 days].
- Sign-in records: [Confirm Supabase session and audit-log retention].
- Usage records: [24 months], then deleted.
- Agent access: access tokens expire after an hour. An agent sign-in ends after 90 days without use, or when you sign the agent out. API keys last until you revoke them. Records of ended sign-ins and revoked keys are kept for [12 months] for security.
- Agent registrations: removed if the agent never finishes signing in, after at least a day. Registrations that did sign in, with their hashed address, are kept until [e.g. 12 months after the agent’s last sign-in ends]. Agent sign-in codes expire after 10 minutes and work once.
- Invites: expire after 14 days. Kept for [12 months].
- Removal requests: [6 years], so we can show what we did.
- Waitlist: until you ask us to remove you, or [12 months] after payments open.
- Billing records: [6 years], as UK tax law requires.
- Downloaded films: deleted once the breakdown and frames are made (within a day for bulk imports). Framebox’s own films are kept.
10 Your rights
Under UK GDPR, you can ask us to:
- give you a copy of your personal data;
- correct data that is wrong;
- delete your data;
- limit how we use it;
- stop using it where we rely on legitimate interests;
- send your data to you or another service in a common format.
Where we rely on your consent, you can withdraw it at any time.
To use any of these rights, email [Contact email] from the address you sign in with. It’s free. We will reply within one month, and may ask you to confirm who you are. You can sign agents out and revoke API keys yourself on your account page.
If you are unhappy with how we handle your data, please tell us. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.
11 Children
Cutmap is not for children. You must be 16 or over to have an account. We don’t knowingly keep data about anyone under 16. If you think a child has signed up, email us and we will delete the account.
12 Security
- Sign-in uses one-time codes sent by email, so there are no passwords to leak.
- API keys, agent tokens and sign-in codes are stored only as hashes.
- The database only lets people read their own account and their own teams. Changes go through our server, which checks who is asking.
- Everything travels over encrypted connections (HTTPS). [Confirm encryption at rest with Supabase.]
If we have a data breach that puts you at risk, we will tell you and the ICO as the law requires.
13 Changes to this policy
We will post any update on this page with a new date. If a change matters, we will email account holders before it takes effect.
14 Contact
[Company legal name], [Registered address]. Company number [Company number].
Email: [Contact email]