← OnSetPilot

Privacy Policy

Effective August 15, 2026

ScriptSync™ is a product of OnSetPilot LLC. This policy explains how OnSetPilot LLC collects, uses, discloses, retains, and protects information when you use the ScriptSync app, website, and related services.

Information we collect

We collect account and profile information such as your email address, display name, department, job role, language preference, and account verification information. We also keep dated records showing which Terms of Service and Privacy Policy versions you acknowledged, your confirmation that you meet the minimum age, and any consent you give before using third-party AI processing. Passwords are stored only in hashed form.

ScriptSync stores production and collaboration content submitted by you or your team, including scripts, call sheets, sides, storyboards, character references, images, shot lists, scene data, comments, team messages, notifications, AI messages and prompts, and saved AI-generated results.

We also maintain plan, storage, feature-usage, AI-provider, billing, support, Team Messages content-report, direct-message block, security, and operational records needed to run the service. A content report preserves the reported message and related account, project, conversation, reason, timestamp, and review information so it can be investigated even if the original record later changes. Our hosting and security providers may process request information such as IP address, browser or device information, access time, and error data.

How we use information

We use information to provide and secure ScriptSync; authenticate users; enforce production membership, roles, document visibility, archive state, and plan limits; enable collaboration and requested AI features; process subscriptions; send transactional email; prevent abuse; diagnose failures; provide support; and comply with law. We do not sell personal information.

We also use limited records to document legal acknowledgements and AI-processing consent associated with an account.

Team Messages reports are used to notify support, investigate possible violations, enforce our Terms, and protect users. A project-scoped direct-message block prevents new one-to-one messages but does not remove either person from the project or shared group chats.

Service providers and AI processing

ScriptSync uses third-party providers for database and private file storage, application and job hosting, transactional email, payment processing, mobile application distribution, content delivery, and network security. Stripe is our payment processor.

Requested AI features may send AI messages, prompts, script or scene context, call-sheet or storyboard pages, shot descriptions, reference images, generated images, and art-style instructions to AI service providers. This processing supports assistant responses, shot lists, descriptions, structured extraction, character references, and storyboard image generation or editing.

OnSetPilot does not train its own AI models on your production content. Third-party providers handle submitted content under the agreements, account settings, and privacy or data-use terms applicable to the services OnSetPilot uses. Retention and handling may vary by provider and feature; we do not promise that providers delete content immediately after a request.

You may withdraw the current third-party AI-processing permission from Settings > Profile > Third-party AI processing. Withdrawal does not affect processing completed before withdrawal. Non-AI features remain available, and ScriptSync will ask for permission again before a later feature sends content to a third-party AI provider. We retain dated acceptance and withdrawal records as reasonably needed to document the account's choices and comply with law.

Workspace visibility

Authorized production members can access workspace content subject to ScriptSync membership, role, and document-visibility controls. Depending on those permissions, members may see your profile details, comments, team messages, production updates, and shared production content.

Legal requirements and business transfers

We may disclose information when reasonably necessary to comply with law, legal process, or valid requests from public authorities; protect the rights, safety, and security of OnSetPilot, our users, or others; investigate abuse; or establish or defend legal claims.

Information may also be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable law.

Payments

Stripe collects and processes payment details directly under its privacy policy. OnSetPilot does not receive or store your full card number. We retain limited customer and subscription references, plan, billing-period, and status information needed to provide paid plans and billing support.

Retention and account deletion

We retain information for as long as reasonably necessary to provide and secure ScriptSync, maintain required business and billing records, resolve disputes, and comply with law. Most workspace content remains until an authorized user deletes it or the production is deleted, subject to storage cleanup and backup cycles.

AI Assistant history availability follows the project's current effective plan: Free provides 7 days, Indie 6 calendar months, Pro 12 calendar months, and Studio has no age-based limit while Studio remains active. If a paid plan expires or changes, the newly effective plan's window applies, so older conversations can become unavailable.

These age windows apply only to AI Assistant conversations, not Team Messages or saved AI-generated production assets. When history becomes unavailable, it receives a 30-day recovery period before permanent deletion from the active application database. Upgrading the project before its scheduled deletion deadline automatically restores unavailable history covered by the new plan. History already deleted cannot be restored. Clearing history, deleting the account, or deleting the project removes it sooner. Limited copies may remain temporarily through backup cycles or where required for security, dispute resolution, or legal compliance. Provider retention is governed by each applicable provider arrangement and legal obligations.

How to request deletion

To delete your entire account, sign in to ScriptSync and go to Settings > Profile > Danger Zone > Delete Account, then follow the confirmation steps. If you cannot access your account, email privacy@onsetpilot.com and state that you are requesting account deletion. We may need to verify your identity and authority before acting on the request. Active billing, subscription, transfer, archive, or deletion workflows may need to complete or be canceled first. Subscriptions owned by the account are canceled before deletion completes.

To request deletion of specific data without deleting your entire account, use the applicable Delete or Clear control in ScriptSync when one is available, or email privacy@onsetpilot.com and state that you are requesting partial data deletion. Identify the relevant data category, production, conversation, or item so we can locate the requested data. We may need to verify your identity, authority, and access to a shared production. The retention limits and legal, security, billing, dispute-resolution, and shared-workspace exceptions described in this policy may still apply.

A production for which you are the sole administrator is deleted and its stored-file cleanup is queued. In a production with another administrator, your membership is removed, but shared production assets may remain for the team with creator or uploader fields removed or anonymized. Your account profile, credentials, comments, team messages, notifications, AI Assistant history, and ordinary feature-usage rows are deleted from the active application database. A limited plan-enforcement counter may remain without your user ID so account deletion cannot reset a shared project's consumed allowance.

Limited records may remain for billing, fraud prevention, security, backup recovery, dispute resolution, or legal compliance. Stripe, infrastructure providers, and other providers may independently retain records under their policies and legal obligations.

Legal-acceptance and AI-processing-consent records are retained while needed to document the notices and choices associated with the account and to comply with legal obligations.

Message-report evidence and review records may remain where reasonably needed for safety, disputes, enforcement, or legal compliance. Direct-message blocks remain until removed by the blocking user or the related project or account is deleted.

Security

We use safeguards including HTTPS, provider-managed encryption at rest, hashed passwords, signed and expiring sessions, private file storage, and backend checks for production membership, role, document visibility, archive state, and project locks. ScriptSync's application backend performs authentication and authorization, while third-party providers supply private database and file-storage infrastructure. No system can guarantee absolute security.

Your privacy rights

Depending on your location and applicable law, you may request access to, correction of, or deletion of personal information and may have additional rights concerning restriction, objection, portability, consent, or complaints. California residents may also request information about collected personal information. OnSetPilot does not sell personal information or share it for cross-context behavioral advertising.

You can create an account-scoped personal data export at onsetpilot.com/data-export or, in supported app versions, from Settings > Profile > Personal Data Export. The ZIP includes your profile, account and membership relationships, your own communications and notes, AI Assistant history still retained for you, including history temporarily unavailable under a project's plan, usage records, legal-acceptance and AI-processing-consent status and event records, metadata for Team Messages reports you submitted, your project-scoped direct-message block choices, and limited attribution metadata. It excludes shared production files and full shared production records, other members' data, credentials, payment identifiers, and internal provider details. Each download requires account authentication, and the export is automatically deleted after seven days.

For another privacy request, or if you cannot access your account, email privacy@onsetpilot.com to submit a request. We may need to verify your identity and authority, and exceptions permitted by law may apply.

Children's privacy

ScriptSync is not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information, contact us so we can review and delete it as appropriate.

International data transfers

OnSetPilot and its providers operate in the United States and other countries. Information may therefore be processed outside your state, province, or country, where privacy laws may differ. We handle international transfers as required by applicable law.

Changes to this policy

We may update this policy as ScriptSync changes. We will post the revised policy with a new effective date and provide additional notice when required by law.

Copyright complaints

Copyright notices and counter-notices may contain contact details and legal statements. We use that information to review the complaint, contact the affected parties, preserve the case record, and comply with applicable law. See our Copyright and Content Complaints page.

Contact us

For privacy questions or requests, contact OnSetPilot LLC, Seattle, Washington, United States, at privacy@onsetpilot.com.