← Mise en Scène

Privacy.

Last updated [[ OWNER: publication date ]]

This explains what Mise en Scène does with personal data — yours, and the data your business puts into the platform. It is written to be read, not to be survived. Where something is uncomfortable, such as the fact that nothing is deleted automatically, we say so rather than hide it in a clause.

If you only read one section, read section 7 on model training and section 10 on how long we keep things.


  1. 1. Who is responsible for your data

    The controller of the personal data described here is [[ OWNER: legal entity name, e.g. “Mise en Scène S.L.” ]], registered at [[ OWNER: registered address in Spain ]], tax ID (NIF) [[ OWNER: NIF ]], registered in [[ OWNER: Registro Mercantil details, or “not yet registered” ]].

    For anything about your data, write to [[ OWNER: privacy contact email — hello@miseen.studio unless you want a separate one ]]. We have [[ OWNER: appointed / not appointed ]] a Data Protection Officer.

    This page is also the information required of an information society service provider under Article 10 of Spanish Law 34/2002 (LSSI-CE).

  2. 2. Two different roles — read this first

    Mise en Scène is a business tool. We handle personal data in two quite different ways, and your rights differ depending on which one applies.

    • We are the controller for data about the people who use the product: account holders, workspace members, billing contacts, people who write to us. This policy is our notice to those people.
    • We are a processor for the content our customers put into their workspace — product photos, brand documents, actor likenesses, voice samples, reviewer email addresses. The customer decides why that data is there and for how long; we only act on their instructions. If your employer, agency or client uploaded data about you, they are the controller and you should contact them first. We will help them answer you.

    Business customers who need a written Data Processing Agreement under Article 28 GDPR can request one at the address above. [[ OWNER: Confirm a DPA exists and where it lives before publishing this sentence. ]]

  3. 3. What we actually store

    This is the real list, taken from the database schema rather than a template.

    • Account. Email address, display name and sign-in method. Authentication is handled by Supabase Auth; we do not store your password.
    • Workspace. Workspace name, the members in it and their roles, plan, credit balance and settings.
    • Invitations. The email address of anyone you invite — as a team member, or as an external reviewer who never creates an account — plus the invitation token, who sent it, and whether it was accepted. External reviewers who comment are stored with the email address they were invited under.
    • Content you upload. Brand documents, product images, logos, fonts and reference material, along with the filename, file type, size and who uploaded it.
    • Likeness data. If you add an actor, we store the source photograph, the generated character sheets, a face thumbnail, a written physical description of the person, and the demographic fields you supply (gender, age range, ethnicity). We also store an immutable consent record containing the time of acceptance, the version of the terms accepted, your IP address and your browser user-agent string.
    • Voice data. If you clone a voice, we store the consent recording of the spoken authorisation phrase, the written attestation, the time, your IP address and user-agent, and the identifier of the cloned voice held at our voice provider. This record cannot be edited after the fact, by design.
    • Work product. Projects, prompts, job records, generated images, video and audio, review comments and annotations, and search embeddings derived from them.
    • Billing. Your plan, credit ledger, and the customer and subscription identifiers issued by Stripe. We never see or store card numbers — card details go straight to Stripe.
    • Operational records. Audit events, usage events, error reports, and — for one public, unauthenticated endpoint — a stored IP address used purely to rate-limit abuse.
  4. 4. Face and voice data is special-category data

    Photographs of a person and a cloned voice can identify that person. We treat likeness and voice data as sensitive and we only process it on the basis of explicit consent (Article 9(2)(a) GDPR), captured and stored at the moment of upload. That is why the product makes you tick a consent box and records it.

    You may not upload a photograph or voice of a person who has not authorised it. The full rules are in the actor terms. Either you or the person depicted can ask us to delete it at any time.

    We do not use face or voice data for biometric identification, and the terms forbid you from doing so either.

  5. 6. We do not make automated decisions about you

    The product uses AI models heavily to generate content, but no automated process makes a decision about a person that produces legal effects or similarly significantly affects them, in the sense of Article 22 GDPR. We do not profile you and we do not score you.

  6. 7. Do you train AI models on our content?

    Short answer: we do not train our own models on your content. The longer, honest answer:

    • We train no general model. Nothing you upload feeds a model that we own, sell or share with other customers.
    • One exception, and it is yours. If you explicitly ask us to train a product LoRA, we send the product images from your own workspace to fal.ai to fit a small adapter. That adapter belongs to your workspace and is used only for your generations. It is started by you, never automatically.
    • Third-party model providers. Your prompts and reference images are sent to the AI providers listed below in order to produce the output you asked for. Whether a given provider retains those inputs, and for how long, is governed by that provider's own terms and our contract with them. [[ OWNER: Confirm the no-training / zero-retention position with each provider in writing and state it here — this is the first question every serious client asks ]].
  7. 8. Who we share data with

    We do not sell personal data and we do not share it for advertising. We use the service providers below. Each one is listed because code in this product actually sends data to it.

    ProviderWhat it doesWhat it receivesWhere
    VercelHosting and content deliveryAll requests to the site, including IP addressDeployed to the Paris (cdg1) region; Vercel is a US company
    SupabaseDatabase, authentication, file storage and invitation emailEverything stored by the productAWS eu-west-1 (Ireland)
    StripePayments and subscriptionsName, email, billing details and payment methodUS / global
    Anthropic (Claude)Text and vision AI — briefs, prompts, chat, quality checksPrompts, briefs, product descriptions and images sent for analysisUS
    Google (Gemini)Image generation, speech and textPrompts and reference imagesUS / global
    OpenAIImage generation and editingPrompts and uploaded imagesUS
    fal.aiThe main media generation gateway; routes to many underlying model vendorsPrompts, uploaded and generated images, video and audioUS
    HeyGenAvatar video, voice cloning and video translationVoice recordings, video and text to be spokenUS
    BytePlus (Ark)Seedance and Seedream image and video modelsPrompts, reference images and videoSingapore / Asia-Pacific endpoint
    HiggsfieldAdditional image and video models, and the ads pipelinePrompts and reference imagesNot verified
    Atlas Cloud, PiAPIAlternative routes to the same video models. Off unless a workspace opts inPrompts and reference imagesNot verified
    Voyage AITurns your outputs into embeddings so search worksOutput text and image URLsUS
    InngestRuns long jobs like video renders reliablyJob payloads, including prompts and asset URLsUS
    SentryError monitoringError reports, technical request context and IP addressDepends on the Sentry region chosen — [[ OWNER: confirm and state EU or US ]]
    Slack, Notion, Shopify, Meta, TikTok, Google AdsOptional integrations you connect yourselfOnly what that integration needs, and only if you connect itDepends on the provider

    We may also disclose data where the law requires it, or to protect our rights or someone's safety.

  8. 9. Sending data outside the EEA

    Our database and file storage sit in Ireland and the site is served from Paris. But most AI model providers are outside the EEA, so producing an image or a video means sending your prompt and reference material to the United States, and in the case of Seedance and Seedream models to a Singapore endpoint.

    Where a provider is certified under the EU–US Data Privacy Framework, that transfer relies on the European Commission's adequacy decision of 10 July 2023. Where it is not, we rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) together with a transfer impact assessment. [[ OWNER: Confirm, provider by provider, which mechanism actually applies and keep the signed clauses on file. The Data Privacy Framework is under appeal at the Court of Justice (Case C-703/25 P), so keep SCCs in place as a fallback even for certified providers. ]]

    You can ask us for a copy of the safeguards used for any specific transfer.

  9. 10. How long we keep it

    We would rather tell you the truth than quote a retention schedule we do not run:

    • Nothing expires on its own. There is no automatic deletion job. Your projects, generated outputs, uploads and account data stay until someone removes them. That is deliberate — creative work disappearing on a timer would be worse than keeping it — but it means retention is on request, not on a clock.
    • Deleting inside the product is reversible. Projects, outputs and clients you delete go to Trash and can be restored. They are not erased from storage at that point.
    • Deleting an actor is not reversible. Removing an actor deletes the record permanently.
    • Erasure on request. Ask us to delete an account, a workspace or a specific person's likeness or voice and we will do it manually, across storage as well as the database, within one month (Article 12(3) GDPR).
    • What we keep afterwards. Invoices and payment records, for the period Spanish tax and commercial law requires. Consent records for likeness and voice, because they are the evidence that the upload was authorised — kept for as long as the generated material may be in circulation, then deleted on request. Security and audit logs, kept in a reduced form. [[ OWNER: Set the exact retention periods you want for invoices, consent records and logs, with your accountant. ]]
  10. 11. Keeping it safe

    Every table is protected by row-level security in the database, so one workspace cannot read another's data even if the application layer were wrong. Data is encrypted in transit and at rest by our infrastructure providers. Administrative access is limited and audited. Sensitive operational tables are not readable by any customer-facing role at all.

    No system is perfect. If we suffer a breach that is likely to put your rights at risk, we will notify the Spanish Data Protection Agency within 72 hours and tell you where the law requires it.

  11. 12. Your rights

    Under the GDPR you can ask us to:

    • tell you what data we hold about you, and give you a copy (access);
    • correct anything wrong (rectification);
    • delete it (erasure);
    • pause our use of it while a dispute is resolved (restriction);
    • hand it to you or another provider in a machine-readable form (portability);
    • stop processing based on legitimate interests (objection);
    • withdraw consent at any time, which is as easy as giving it, and does not undo what was lawful before.

    Write to [[ OWNER: privacy contact email ]]. We answer within one month. There is no charge unless a request is clearly excessive.

    If you are unhappy with our answer you can complain to the Spanish Data Protection Agency, the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es — or to the supervisory authority where you live or work.

  12. 13. Providing your data

    You do not have to give us anything. But an email address and payment details are necessary to create an account and pay for it, so without them we cannot provide the service. Everything else is optional.

  13. 14. Children

    Mise en Scène is a business product and is not intended for anyone under 18. In Spain the age at which a person can consent to their data being processed is 14 (Article 7, Organic Law 3/2018). If we learn that we hold data about a child without proper authorisation, we delete it.

  14. 15. Cookies

    We use a small number of strictly necessary cookies and no tracking cookies at all. The detail is on the cookies page.

  15. 16. Changes to this policy

    If we change this policy we will update the date at the top, and tell account holders by email when the change is material — for example a new category of data, a new purpose, or a new provider receiving your content.


PrivacyTermsCookiesActor termsContact