Legal
What we collect, why we have it, who processes it on our behalf, how long it stays, and how to have all of it erased. The short version: an email address, what you write, and what you generate. No advertising, no data sold, and a delete button that means it.
TheBoringApp LLC, a Delaware limited liability company operates theboringapp.com and is the controller of the personal data described here. You can reach us at admin@theboringapp.com.
This policy covers the website and the product behind sign-in. It does not cover any third-party site you reach from a link here.
Only what the product needs to work. In four groups:
We do not collect special category data, we do not build advertising profiles, and there are no third-party advertising or social trackers on this site.
Under the GDPR and the UK GDPR, each purpose has a lawful basis. Ours are:
We do not make decisions with legal or similarly significant effects about you by automated means, and we do not profile you for advertising.
This is the part that matters most in an AI product, so it is set out plainly.
We do not train models on your content, and we do not permit our providers to train their models on content we send them under our commercial terms. We do not sell your content or share it with anyone for their own purposes.
Generated clips are stored by the video provider, not by us. They are available for 13 days and are then deleted at source. We never hold a second copy of the video file.
These are our sub-processors. Each is bound by a data processing agreement and may use your data only to provide its service to us.
We will also disclose data where the law requires it, to respond to a valid legal demand, to enforce our terms, or to protect the rights and safety of people. If we are ever part of a merger or acquisition, data moves with the business and we will say so before it does.
Encrypted backups of the database may hold a copy of deleted rows briefly until the backup ages out of rotation. Nothing is restored from a backup to reinstate deleted data.
Settings has a delete button. It is not a request queued for review - it runs immediately, and there is no grace period and no undo.
When you confirm it, in this order: your reason for leaving is recorded without anything that identifies you; every image you have uploaded is removed from storage; your sign-in is deleted at our authentication provider so the account can never be signed into again; and your database rows go, taking your projects, clips, scripts, credit history and support tickets with them.
What survives is the anonymous deletion feedback, and the payment records that tax law obliges us and Stripe to keep. Nothing in either can be joined back to you through our systems.
Unused credits are forfeited on deletion. If you have a balance and want it refunded rather than lost, email us before you delete.
Depending on where you live, you have some or all of these rights. We honour them for everyone, wherever you are:
Use the delete button for erasure. For anything else, email admin@theboringapp.com from your account address and we will respond within thirty days.
For California residents: in the twelve months before this policy's date we collected the categories described above, for the business purposes described above. We do not sell personal information, and we do not share it for cross-context behavioural advertising - so there is nothing to opt out of. We do not knowingly collect data from anyone under 16.
For residents of the EEA and the UK: you may lodge a complaint with your local supervisory authority. We would rather you told us first.
We are based in the United States and our processors operate there. If you use the Service from outside the United States, your data is transferred to and processed in the United States.
Where data leaves the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses and the UK Addendum in our agreements with the processors involved, together with the technical measures described below.
Data is encrypted in transit with TLS and at rest by our database and storage providers. Access to production data is limited to the people who need it and is authenticated individually.
Provider callbacks are authorised per resource with signed URLs, webhooks are signature-verified, and generated media URLs are checked against an allowlist before they are stored.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant regulator within the time the law requires.
If you have found a vulnerability, email admin@theboringapp.com and we will work with you. Please do not test against other people's accounts.
The Service is not for anyone under 18, and we do not knowingly collect personal data from children.
If you believe a child has given us data, email admin@theboringapp.com and we will delete the account and its contents.
We will update this policy as the product changes. The version and date at the top always identify the current one.
If a change materially affects how we handle your personal data, we will tell you by email or in the product before it takes effect.
Questions about any of this go to admin@theboringapp.com. You can delete your account and everything on it at any time from Settings.