Privacy Notice
Version 2.0 — effective July 19, 2026
This notice explains what SceneFiend collects, why, which service providers process it, how long it is kept, and the choices you have. It is written to match what the product actually does.
Who operates SceneFiend
SceneFiend is built and operated by Vociferous.ai, based in New York, New York. In this notice, “we,” “us,” and “our” refer to the operator of the SceneFiend service. Contact: [email protected].
Scope
This notice covers the SceneFiend service at scenefiend.app, including its public pages, the waitlist, and signed-in account features. SceneFiend is for adults 18 and older and is currently in beta.
What we collect
- Account and sign-in data — your email address and a hashed password, managed through our authentication provider (Neon). The account record also holds a name field (set to your email address at signup unless you provide one), your email-verification state, and server-side session records. Signing in sets a first-party, secure session cookie.
- Actor profile — what you choose to tell us: display name, playing age range, experience level, training background, comedic/dramatic identity, aesthetic preferences, goals, tone preferences and content boundaries, union status, working markets, and the taste selections and profile chips you build during onboarding. You can edit these at any time from your Profile.
- Recommendation requests and results — the requests you make (including any free text and the boundaries you set) and the recommendations returned, stored in your account history so you can revisit them.
- Saved material and prep state — the pieces you save, your books and collections, notes, tags, prep checklists, and due dates.
- Feedback and suggestions — ratings, flags, and notes you leave on pieces, and any material you suggest for the catalog.
- Resume parsing (optional) — if you upload a resume, we extract its text and send an excerpt to OpenAI to propose profile fields. The original file and its raw text are not stored on our servers; only the structured fields you choose to apply are saved to your profile. You can remove parsed enrichment data from your Profile (the removal control can be used once per day).
- Credit search (optional)— if you use the film/TV credit search during onboarding, the name you type is sent to TMDb to look up public credits. This only happens after you tick that flow's consent box.
- Waitlist — email address, and optionally a display name and role. We do not store your IP address with a waitlist signup.
- Invites and email preferences — if you invite another actor, we store the address you provided so the invite can be sent and attributed. Email preference and unsubscribe links use unique tokens tied to your account.
- Legal acceptance ledger — when you accept the Terms and acknowledge this notice, we record your account ID, the document versions, your attestations, and a server-generated timestamp. We deliberately do not record your IP address or browser details in that ledger.
- Security and operations data — rate limiting uses your IP address transiently to compute a throttling key; we do not persist raw IP addresses in our database. Error and readiness ledgers are sanitized to exclude personal data. Our email delivery log stores a one-way hash instead of your address. Account-free counters record piece views, and an account-free log records the text of searches that returned no results (redacted and not linked to you).
What we do NOT collect
- Payment information — SceneFiend is free during beta.
- Precise location data.
- Social media credentials or account links.
- Data about minors — SceneFiend requires users to be 18 or older.
AI processing and your data
When you request recommendations, your profile and request are sent to the OpenAI API to generate results. If you use resume parsing, the resume text excerpt is sent the same way.
- No training:under OpenAI's API data controls, data sent via the API is not used to train OpenAI models by default, and we have not opted in to any data sharing. We do not use your data to train or fine-tune any model.
- Transient processing: we set the API's
store: falseoption on these requests, so OpenAI does not keep the request/response as a stored object. OpenAI generates abuse-monitoring logs for API usage which it retains for up to 30 days (longer only if OpenAI is legally required to); we cannot shorten that window (it is removed only under OpenAI's approval-gated zero-data-retention program, which we do not currently have). - Our storage: your recommendation requests and results are stored in your SceneFiend account history, for you.
Service providers (processors)
We use the following providers to run SceneFiend. Each processes data under its own privacy policy.
| Service | What it processes | Provider |
|---|---|---|
| Neon | Authentication and database storage (all account data above) | Neon, Inc. |
| OpenAI API | Recommendation generation; optional resume parsing | OpenAI, LLC |
| Vercel | Hosting, request logs, aggregate Web Analytics and Speed Insights | Vercel, Inc. |
| Postmark | Transactional email (verification, resets, digests, invites, waitlist) | ActiveCampaign, LLC |
| Cloudflare | DNS and inbound email routing for scenefiend.app addresses | Cloudflare, Inc. |
| PostHog (optional) | Product analytics — only if you turn it on (see below) | PostHog, Inc. |
| Upstash (when configured) | Short-lived rate-limit counters (throttling keys, no profile data) | Upstash, Inc. |
| TMDb (optional) | Credit search — the name you type, only after that flow's consent box | TiVo Platform Technologies LLC |
| Tally (external link) | The beta feedback form is an external Tally form; anything you enter there goes to Tally under its own policy | Tally BV |
Analytics
SceneFiend has two separate kinds of telemetry, and they work differently:
- Aggregate site telemetry (always on):Vercel Web Analytics and Speed Insights measure traffic and performance without cookies. Per Vercel's privacy documentation, visitors are counted with a request-derived hash that is discarded after 24 hours, and the data is not tied to any individual or IP address. Our own product events sent through this channel carry no names, emails, or free text; a few carry a random per-session identifier used only to sequence steps within a single visit. If you object to this aggregate measurement, contact us at [email protected].
- Optional account-linked product analytics (off by default):if — and only if — you turn on the optional analytics choice, we send a limited, fixed set of product events to PostHog (hosted in the United States) linked to your account's internal random ID. We never send your email, name, notes, request text, resume content, or share links. When enabled it runs without analytics cookies (memory-only), with session recording, autocapture, surveys, and heatmaps disabled. You can turn it off at any time from your Profile; turning it off stops collection immediately in your open tabs on that device, and other signed-in devices stop at their next page load. Leaving it off never affects your access to any feature.
Cookies, local storage, and session storage
- Session cookie (strictly necessary): signing in sets a first-party, secure session cookie so you stay signed in. It is not used for advertising or cross-site tracking.
- Local storage: your theme and reading-mode preferences, plus small markers used to avoid double-counting product events in a browser session.
- Session storage: per-tab markers for onboarding and session tracking.
- No advertising cookies, no cross-site tracking pixels, and no third-party ad technology.
Purposes and legal bases
- Providing the service you asked for (contract): account provisioning and sign-in, generating the recommendations you request, storing your saved material and history, invites and class features you use.
- Security and operations (legitimate interest): rate limiting, abuse prevention, sanitized error and uptime ledgers, email deliverability logging, and aggregate site telemetry as described above.
- Things you opt into (consent): optional product analytics, marketing and product-update emails, resume parsing, and TMDb credit search. You can withdraw each of these without affecting the rest of the service.
Accepting the Terms is a contract choice; acknowledging this notice records that you were shown it — we do not treat that acknowledgment as blanket consent to everything.
Retention
- Account-linked data (profile, history, saved material, feedback, preferences, acceptance ledger): kept while your account is active; erased when your account is deleted.
- Aggregate or pseudonymous operations data (email delivery hashes, no-result search text, piece-view counters, sanitized error ledgers): kept for operations and reviewed periodically; not linked to your account.
- Provider tails after deletion:deleted rows persist in our database provider's (Neon) encrypted backup and point-in-time-restore history until the project's restore window elapses; we do not restore deleted user data except for whole-system disaster recovery. OpenAI abuse-monitoring logs expire within 30 days; Postmark retains transactional email activity for roughly 45 days; Vercel retains standard infrastructure request logs for its platform-defined window. If you enabled optional analytics, deleting your account immediately clears the analytics state on the device you delete from; the associated PostHog person data is deleted on request (email us) and otherwise ages out under PostHog's project retention.
The full category-by-category retention schedule is maintained in our internal retention policy; ask us for details any time.
Your rights and choices
- Access and correction — your profile, history, and saved material are visible and editable in the app.
- Deletion — you can delete your account from your Profile page. This permanently erases your account and its data from our live database (subject to the provider tails above). Content and abuse reports you filed are kept for moderation history under a pseudonymous internal identifier that no longer links to your profile, email, or name in our live database. If you have contributed curation notes as a subject-matter reviewer, your deletion is completed by an operator (you keep access until then) and the curation notes you wrote about plays and characters are retained in de-identified form.
- Export — you can download a machine-readable JSON export of your profile, history, saved material, feedback, and preferences from your Profile page; a few operational records (for example, reports you filed) are available on request.
- Analytics choice — grant or withdraw optional analytics at any time from your Profile.
- Email choices — every non-essential email includes preference and unsubscribe links; marketing and product-update emails are opt-in.
- Complaints — if you are in the EU or UK you can lodge a complaint with your supervisory authority; California residents can ask what categories of information we collect and how they are used. We do not sell personal information.
To exercise a right you can't complete in the app, email [email protected] from your account address (that is how we verify the request). We aim to respond within 30 days.
International processing
SceneFiend is operated from the United States and our providers process data in the United States. If you use SceneFiend from the EU, UK, or elsewhere, your data is processed in the US as described in this notice.
Security
Passwords are hashed by our authentication provider; traffic is encrypted in transit; session cookies are secure, first-party cookies; sensitive operations are rate limited; and all account data access is scoped to your session server-side. No online service can promise perfect security, and we don't — but security issues are treated as top-priority defects. Reports: [email protected].
Adults only
SceneFiend is for users 18 and older. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete it promptly.
Changes to this notice
This notice is versioned. If we make a material change, we bump the version and ask you to acknowledge the new version the next time you sign in — continued silence is not treated as acceptance of a material change.
Contact
Questions or requests: [email protected]