Privacy Policy
Last updated: June 17, 2026
1. Introduction
Cortavid respects your privacy. This policy explains what personal data we collect, why we collect it, and what rights you have. We apply the standards of the EU General Data Protection Regulation (GDPR) to all users, regardless of where you are located.
2. Data Controller
The data controller is Adam Borjila Rila, sole proprietor (autónomo) operating Cortavid, based in Spain (NIE/NIF available on request). You can contact us about privacy matters at hello@cortavid.com.
3. What We Collect
- Account data: your email address (used for magic-link sign-in). No password is needed or stored.
- Payment data: handled directly by Stripe. We store only your Stripe customer ID and subscription ID — never your card details.
- Usage data: the prompts you submit, the outputs we generate, render counts, and timestamps.
- Technical data: your IP address (for anti-abuse), browser type, and basic logs.
We do not collect your real name unless you choose to provide it, and we do not collect your phone number, social media profiles, or location beyond the country level needed for compliance.
4. Why We Collect (Legal Basis under GDPR)
- Service delivery (Art. 6.1.b — contract): managing your account, processing payments, and generating videos.
- Legitimate interest (Art. 6.1.f): security, anti-abuse, and basic analytics.
- Legal obligation (Art. 6.1.c): keeping tax records, and anti-money-laundering checks for high-volume users where applicable.
- Consent (Art. 6.1.a): used only for marketing communications, which are opt-in.
5. Third-Party Processors
We share data with the following processors only as needed to run the Service:
- Stripe (US/EU): payment processing.
- Fal.ai (US): AI video rendering — we send prompts and storyboard images.
- Google Gemini API (US): storyboard image generation — we send prompts.
- ElevenLabs (US): voice generation — we send scripts only if you use Narration mode.
- Anthropic (US): script generation — we send your idea.
- Resend (US): transactional emails such as magic links and receipts.
- Cloud hosting: to be confirmed (likely Vercel/Render) in a future phase.
All processors are engaged on a GDPR-compliant basis, using Standard Contractual Clauses where applicable.
6. Data Retention
- Account data: kept until you delete your account.
- Generated videos: retained for as long as your account is active. You can download them at any time, and may request deletion of specific videos by contacting us.
- Payment records: retained for 7 years, as required by Spanish law.
- Logs: 30 days.
When you delete your account, we delete your personal data within 30 days, except payment records that we are legally required to retain.
7. Your GDPR Rights
You have the right to access, rectify, delete, restrict, and port your data, to object to certain processing, and to withdraw consent at any time. To exercise any of these rights, contact hello@cortavid.com. We respond within 30 days.
9. Children's Privacy
Cortavid is not intended for anyone under 16, and we do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact hello@cortavid.com and we will delete it.
10. International Transfers
Some of our processors (Fal, Gemini, ElevenLabs, Anthropic, and Stripe) process data in the United States. These transfers are protected by Standard Contractual Clauses or applicable adequacy decisions.
11. Security
We protect your data with encryption in transit (HTTPS), encryption at rest for sensitive data, and regular security reviews. No system is ever 100% secure, but we work to keep your data safe.
12. Changes
We may update this policy occasionally. We will notify you of material changes by email, and the effective date at the top of this page will always reflect the latest version.
13. Complaints
If you believe your data rights have been violated, you have the right to lodge a complaint with the Spanish Data Protection Authority (AEPD) at aepd.es.
14. Contact
For any privacy question, reach us at hello@cortavid.com.
Note: This policy is based on GDPR requirements and our specific product. It has not yet undergone formal legal review. Please contact hello@cortavid.com with any concerns.