T6FV Privacy Policy
THE 6-FIGURE VIDEOGRAPHER LTD. Mississauga, Ontario, Canada
Last Updated: September 16, 2026
This Privacy Policy explains what personal information THE 6-FIGURE VIDEOGRAPHER LTD. ("T6FV", "we", "us") collects through the T6FV ecosystem — the T6FV / T6FV.io video production planning app for iOS, Android, macOS, and Windows, the t6fv.io website and hosted share pages, and the community features inside the app (together, the "Services") — how we use it, who we share it with, and the rights you have. It forms part of our Terms of Use.
The short version: the app is built local-first. Your footage, your location and your AI conversations stay on your device on every plan; on a plan without a cloud library, so do your projects, clients, finances and contacts. We only receive what you deliberately send to a cloud feature — your account details, your subscription status, content you choose to publish or share, and, where your plan includes one, the cloud library described in Section 3. We run no analytics, no advertising, no tracking, and we never sell your personal information or use your content to train AI models.
1. Who We Are and How to Reach Us
The organization responsible for your personal information is:
THE 6-FIGURE VIDEOGRAPHER LTD. Mississauga, Ontario, Canada Privacy Officer: info@t6fv.com
Contact our Privacy Officer for any question, access request, correction request, complaint, or concern under this policy.
2. What Stays on Your Device (Most Things)
The app stores your working data locally, in the app's own storage on your device. We do not automatically sync, upload, mirror, or back up this data, and we cannot see or recover it — with one exception, described in Section 3 under "Cloud library": some subscription plans include one, and while you hold such a plan your planning records — and the pictures, audio and files kept with them — are copied to our servers so your own devices can read the same work, and so that people you invite to a binder can read the parts of it you grant them. Locally stored data includes:
- Projects and binders: tasks, briefs, productions, shoot days, call sheets, schedules, scenes, shots, takes, and deliverables;
- Client records, contact lists, crew and cast lists (including anything you import from your device's address book);
- Financial data: pricing, quotes, budgets, invoices, and payment records you keep in the app;
- Captured footage and field audio takes — what the camera and recording tools capture stays on the device that shot it, including video, multicam, timelapse and stop-motion recordings and the takes from the audio field recorder. A picture you then file into a project — a still you keep as a reference, a frame you drop into a mood board — travels with the record that points at it if your plan includes a cloud library, as described in Section 3. Where one of your devices operates another's camera, the footage travels between your own devices and does not pass through us;
- Your email, if you connect a mailbox. The mail feature signs in to an email account you already hold, using an authorization or credentials you supply, which are kept in your device's own secure storage. Messages, attachments and folder structure it downloads are cached on your device so you can read and search them, and are filed against your binders there. Your messages do not reach our servers, and we cannot read them — the mailbox cache is deliberately excluded from the cloud library, so a device that syncs your planning records does not carry your correspondence with it. Mail you send goes from your account through your provider, not through us. The exception is one you make on purpose: if you save a message or an attachment into a binder, it becomes a project file like any other and follows the same rules as the rest of your project files, including travelling in a share or export link if you put it in one. Disconnecting the mailbox removes the stored authorization and the local cache;
- Scripts, notes, ideas, mood boards, storyboards, and generated documents (contracts, releases, and similar);
- Gear inventories, lighting diagrams, and tool settings;
- Your location — the sun-tracking and location-scouting tools compute sun position on the device; your coordinates are never transmitted to us;
- Your calendar — calendar sync writes events to a calendar you choose, using your device's calendar framework, and only ever touches events it created;
- AI chats — conversations with the on-device AI assistant are stored only on your device;
- Local backups the app makes of its own data (on iOS these live in a folder that your device's own iCloud device backup may include, under your Apple account and iCloud settings — that backup belongs to you, not to us).
Device permissions (camera, microphone, photo library, contacts, location, calendar, Bluetooth, local network, speech recognition, notifications) are each requested only for the feature that needs them, with an explanation shown at the time. The app also includes a Permissions overview in Settings describing what each permission is used for. Local network features (teleprompter remotes, on-air signs, Studio Link on your Wi-Fi, lighting control) communicate between your own devices on your own network and do not route through our servers.
Local data is protected by your operating system's app sandboxing and whatever device-level protections you enable (passcode, device encryption). The app's local database is not separately encrypted, and exported .t6fv_vault project archives are encrypted with a format-level key embedded in the app — suitable for keeping project files private in transit, but not a substitute for device security or a guarantee against a determined attacker with the file. Please use your device's security features, and see Section 8 for how Studio Link differs (it uses genuine end-to-end encryption).
3. What We Collect (Only When You Use Cloud Features)
We collect personal information only when you create an account or use a feature that is cloud-connected by design:
Account information. Email address (verified at sign-up), password (held by our authentication provider in hashed form — we never see or store it), unique username, display name, and your interface language (so account emails arrive in your language). Your subscription tier and a subscription event audit trail (event type, entitlement identifiers, timestamps) are recorded against your account.
Purchases. Subscriptions bought inside the mobile app are billed by Apple or Google. Subscriptions started on our website are billed through our billing partner's hosted checkout. In neither case do we receive or store your payment card details. Our subscription platform (RevenueCat) processes purchase and entitlement records linked to your account identifier so your subscription works across your devices. For a web purchase we also hold the billing records we need to answer refund and tax questions about that sale.
Payments you take from your clients. If you connect a Stripe account to the app (available on some plans), your clients' card payments are processed by Stripe on your own Stripe account under Stripe's terms and privacy policy; T6FV is not a party to those payments, holds none of the money, and never receives card numbers — your clients enter them on Stripe's own payment page. So that the app can record a payment on the right invoice, we hold the connection record (your Stripe account identifier, its capability flags, country and settlement currency) and, for each payment, refund or dispute, the identifiers Stripe assigns, the amount and currency, the invoice and link it was for, the time, and the payer's name and email address if Stripe collected them at checkout. A record that a payment event was processed is kept for idempotency (so a repeated notification is never recorded twice) and contains no card data. Your clients' own details entered at Stripe's checkout are Stripe's to protect under their policy, and yours under Section 3A.
Content you publish. Forum posts and replies, Connect listings (which may include a location and a rate you choose to state), your Directory profile, your public Portfolio page (tagline, bio, images, demo video links, rates, social links), a downloadable contact card if you publish one (name, organization, job title, phone number, email — published contact cards are downloadable by anyone who views your public page), Blueprints you upload to the community library (packaged project templates plus preview screenshots, associated with your account), and testimonials.
Messages to you through your Portfolio. If someone contacts you through your public Portfolio page, we hold their message (their name, email, phone number, and message text) so we can show it to you in your inbox.
Portfolio video you upload. If you upload a video to your Portfolio rather than pasting a link to one, we host that file so your public page can play it, and we hold it until you replace or delete it or delete your account. A hosted video is served to whoever views the page.
Push notifications. If you allow notifications, your device is issued a push token by Apple or Google, and we store it against your account so we can send the notification. Tokens are device identifiers for delivery, not tracking identifiers: we do not use them to profile you, and turning notifications off at the operating system level stops them. The content of a notification is generated for something you asked for — an invitation, a moderation notice, an inbox message.
Team features. If you invite someone to a shared binder, we process the invitee's email address to deliver and gate the invitation, and team activity logs record who did what in the shared binder.
Feedback reports. If you choose to submit a feedback report about an AI feature, we receive the feature name, your notes, and basic device diagnostics (device model, OS version, app version, AI model used, token counts). The report includes your prompt and the AI's reply only if you tick the box to include them. Reports are visible only to administrators.
Content reports. If you report a post, a profile or an AI answer, we receive the category you chose, any note you added, what you were looking at when you reported it, and which account it belongs to — together with your account name and email address, so a moderator can follow up. The person you reported is not told who reported them. What you saw is included so that a moderator can act on it even if it is edited or deleted afterwards, which means a report can contain another person's words. Reports are visible only to administrators, and we aim to look at every one within 24 hours.
Blocking. If you block someone, we store their account identifier and the time, under your account. It is not shared with them and it is not visible to anyone else.
Bug reports. If you send a bug report from inside the app, we receive what you typed, the area of the app you were in, basic device diagnostics (device model, OS version, app version), whether the app had ended abnormally, and — where the app caught one — the error and its stack trace together with a short trail of the actions immediately before it. That trail is a record of what you did, not of what your projects contain, but it can include names you have given things. Bug reports are sent only when you submit one; nothing is transmitted automatically. Reports are visible only to administrators.
Referrals. If you reach us through a referral link or QR code from someone in our affiliate programme, we record that your account arrived through that referral so the referrer can be credited. The commission ledger itself is kept without your identity: it holds the referral, the amounts and the rates, and not your name, email or account identifier.
Quota accounting. For metered features we keep counters: monthly Blueprint unlock counts, per-Blueprint view counts, Studio Link relay usage meters, the bytes your client links and hosted review video occupy against your plan's storage allowance, the number of client links and pay links you hold, and, for each link, the time its page was last opened — which is what decides whether it has gone unused under Section 9. These are billing/quota records, not behavioural analytics: the last-open time is a timestamp on the link, not a record of who opened it.
Studio Link relay. If you link devices over the internet (rather than your own network), our relay carries only end-to-end encrypted data between your devices (Section 8). We cannot read it.
Emails we send. We send transactional email only — verification, password reset and security notices, welcome messages, team invitations, moderation notices, and service digests relevant to content you published. We do not send third-party marketing.
Website and share pages. Our hosted share pages (for call sheets, scripts, and timers you deliberately share) serve the shared content to whoever holds the link, with referrer information suppressed and caching disabled. Our web pages contain no analytics or advertising scripts.
Cloud library (plans that include one). While you hold a plan that includes it, the app copies your work to our servers so that every device you sign in on shows the same work. What travels is:
- your planning records — projects, scenes, schedules, contacts, gear, scripts, notes, estimates and paperwork;
- the pictures those records refer to — your letterhead and logo, reference images and stills, the images, looks, models and renders held in the app's Maker libraries, and your portfolio;
- documents you file into a binder — a PDF, a saved email or attachment, a colour look-up table;
- audio you record in the app's music tools, which is filed alongside those libraries.
What does not travel is what the capture tools record: footage and field audio takes stay on the device that shot them, on every plan.
Records are stored in Google Cloud Firestore under your account. The pictures, documents and audio — and any record too large to be a database document, which is stored as an object rather than a row — are stored in Cloudflare R2 under names only our servers can sign a download link for. Both are encrypted in transit and at rest. We use the library to serve your own devices, and the people you invite to a binder, and for nothing else: not for training, not for analytics, not shared with anyone else.
The library also carries the addresses and the keys of the client links you publish, so that any device you sign in on can republish a link, collect what your clients have sent to it, or revoke it — rather than only the one device that created it. On a plan whose cloud library we serve, that means we hold those keys, in your library, under the same access controls as the rest of it. Our Security Overview sets out what that changes and what it does not. Retention when a plan ends is in Section 9.
Binders you share (plans that include a cloud library). You can invite named people to a project binder and give each of them an access level. Only the sections that level grants are sent to them — the rest is withheld by our servers and never reaches their device, so a person who may see the schedule but not the money does not receive the money. We hold that copy solely to serve it to the people you named, on the same terms as the rest of your cloud library. When you remove somebody, when they leave, or when you stop sharing a binder, we delete the copy we held for them and the app deletes the copy on their device; what they exported or copied while they had access is outside our reach, and yours. You are the one deciding to share, and about whom: see "You are the one who decides" below.
3A. Information About Other People That You Enter
Most of what you keep in the app is about somebody else — crew, cast, talent, clients and their contacts. Names, phone numbers and emails (including anything you import from your device's address book), rates, call times, images and footage of identifiable people, and free-text notes. Some fields invite genuinely sensitive information: a crew member's dietary requirement or allergy, a performer's measurements, an accessibility need. In some places, notably productions involving children, it will be information about a minor.
Two things follow from that, and they matter.
You are the one who decides. For the information you enter about other people, you decide what to collect and why, and you are the one responsible to them for it — under the GDPR you would be the controller and, for the copy the cloud library holds, we would be your processor. Inviting somebody to a binder is a disclosure you are making, not one we are making: choose who to invite, and what to grant them, with that in mind. That means having a lawful basis, giving whatever notice or getting whatever consent your law requires, keeping it accurate, answering the requests those people can make of you, and not collecting more than the job needs. Dietary, medical, accessibility and similar notes are treated as sensitive or special-category information in many places, and information about children more strictly again. Record it only where you actually need it. Our Terms of Use §7.9 says the same thing as an obligation.
We do not look at it. Where a plan includes the cloud library, we hold this information solely to serve it back to your own devices and to the people you have invited to your binders, encrypted in transit and at rest, and reachable by no account other than those. We do not read it, mine it, share it, sell it, or train models on it. If you need a written data processing agreement, ask us at the address in Section 1.
What our sharing tools do with it. Share links, export links, call sheets and published pages disclose whatever you put in them to whoever holds the link. The app is deliberately careful with the most sensitive of it: you choose which sections a link carries when you create it, and a section you leave out is absent from the published file rather than hidden inside it; and where a link goes to someone working on the job rather than to your client, the catering order detail is withheld regardless of what you chose, because a crew member reading a binder is not owed the room's dietary requirements. Beyond that, which link goes to whom is your decision, and the safest habit is to send the least the recipient needs.
4. What We Do NOT Do
- No analytics or telemetry SDKs. The app contains no product analytics, usage tracking, or behavioural profiling.
- No third-party crash or analytics SDKs. Nothing reports a crash to anyone automatically. The app can notice that it closed abnormally and offer you the chance to send a bug report, and that report goes only when you send it (Section 3).
- No advertising, ad networks, or attribution SDKs.
- No tracking identifiers. We do not access the advertising identifier (IDFA/AAID), do not fingerprint devices, and do not track you across apps or websites. Our iOS privacy manifest declares tracking as "false" with no tracking domains.
- No sale or sharing of personal information for advertising or any other consideration.
- No AI training on your content. Neither your local data nor content you publish is used by us to train AI or machine learning models, and our retention of archived content excludes AI training use by commitment in our Terms of Use.
- No collection from children. The Services require users to be 18 or older. See Section 11 for information about children, which is a different question.
- No reading of your mail. If you connect a mailbox, its messages are cached on your device. They are not sent to us, we hold no copy, and we cannot read them.
5. AI Features and Your Content
The app's AI features are designed so that you control where your content goes:
On-device AI. Optional AI models run entirely on your device. Prompts, project context, and outputs stay local. A model file reaches you one way and one way only: the app downloads it from our own content delivery network at models.t6fv.io, which runs on Cloudflare R2. That download reveals your IP address to us and to Cloudflare, as any download does, and carries none of your content. The app does not fetch model files from anywhere else and does not send you to any other site to get one. The repository each model was published in is named on its licence card, as text, so you can check where the bytes came from.
External AI hand-off. For some tasks the app prepares a prompt (which may include project details you've selected — scene lists, script text, gear lists, and similar) and copies it to your clipboard or opens the website of an AI service you have an account with (ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, DeepSeek, or Le Chat). You decide whether to submit it. What you submit is processed by that provider under its privacy policy, not ours — we are not a party to that exchange and receive nothing from it. Be careful not to paste content you owe confidentiality for.
Voice dictation and voice-follow. These use your device operating system's speech recognition. Depending on the device and OS settings, audio may be sent to Apple's or Google's speech recognition servers and handled under their policies. If you do not want dictation audio processed off-device, do not use the dictation features (or configure on-device dictation at the OS level where your platform offers it).
On-device machine learning. Text recognition (reading camera-body labels), face/pose detection (photo editing aids), and translation run on-device via Apple's and Google's on-device ML frameworks. Photos processed by these features are not uploaded. The app does not download a translation language pack. Interface translations come from catalogs shipped with the app itself, so nothing is fetched to translate it.
Optional AI web search. On desktop, larger on-device models can be allowed to search the web before answering. Off by default. When enabled, search queries composed from your prompt are sent to a third-party search service (DuckDuckGo), and result pages may be fetched. Leave it off if no part of your prompt should leave the device.
6. Service Providers and Other Recipients
We use a small number of service providers to operate the cloud features, each processing personal information on our behalf under their own security commitments:
| Provider | What it does | What it processes | Where |
|---|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, App Check) | Accounts, database, file storage, server logic, abuse protection | Account data, published content, uploaded files, encrypted relay data | United States (us-central1) |
| RevenueCat | Subscription management, and the hosted checkout for subscriptions bought on our website | Account identifier, purchase/entitlement records; for a web purchase, the payment details you enter at their checkout | United States |
| Stripe (Stripe Connect) | Processes card payments your clients make to you on client links, on your own Stripe account, if you connect one | Your Stripe account identifier and its status; for each payment, the identifiers Stripe assigns, amount, currency, the invoice and link it was for, and the payer's name and email if collected at checkout. Your clients' card details are entered on Stripe's page and never reach us | United States / Ireland (Stripe's regions) |
| Apple App Store / Google Play | Billing; app distribution | Your payment details (held by them, not us); purchase records | Per your store account |
| Google (Gmail SMTP) | Sending transactional email | Recipient email address and message content | United States |
| Cloudflare (R2) | Serves the AI model files you choose to download, from models.t6fv.io; stores the published copy of your client links — the encrypted payload and the media attached to it — the review video those links host; and, on a plan with a cloud library, the pictures, documents and recorded audio your records refer to, together with any record too large to be a database document |
The AI model download reveals the IP address of the request and carries no account content. Everything else on this row is account content: what you publish to a client link, in the form Section 8 describes (an encrypted payload, and media protected by unguessable URLs rather than encryption), and the files of your cloud library, stored under names only our servers can sign a download link for | Global CDN |
| OpenStreetMap Foundation | Map tiles in the location tools, and address lookup (geocoding) when you ask the app to find a place | Map viewport requests and IP address (standard for any map); the address or place name you type into a location search | EU |
| Google Fonts | Delivers a display font you pick for a slate, a presentation or a social post, and document faces for PDF export in some writing systems. The app's own interface font is built in and is never fetched. | IP address of font requests | Global CDN |
| YouTube / Vimeo | Plays embedded course and portfolio videos | Standard embedded-player data under their policies, when you play a video | United States |
| DuckDuckGo | Optional AI web search (off by default) | Search query text, IP address | United States |
Beyond service providers, we disclose personal information only: (a) to other users and the public, at your direction — content you publish is public by design (Section 3); (b) for legal reasons — where required by law, regulation, subpoena, or court order, or to protect the rights, safety, or property of users, the public, or T6FV; (c) in a business transaction — if T6FV is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy's commitments; and (d) with your consent in any other case.
We do not disclose personal information to data brokers, advertisers, or AI training aggregators.
7. International Transfers
We are a Canadian company, and our cloud infrastructure is located in the United States (Google Cloud region us-central1). If you use the cloud features, your account information and published content are stored and processed in the United States, where they are subject to lawful access under U.S. law.
- Canada (PIPEDA): we remain accountable for personal information transferred to service providers for processing, and use contractual and technical safeguards to require comparable protection.
- EEA / UK (GDPR / UK GDPR): where we process personal data of individuals in the EEA or UK, transfers to our processors outside those areas rely on the European Commission's Standard Contractual Clauses / the UK Addendum (our processors — Google, RevenueCat, Stripe — incorporate these in their data processing terms), together with supplementary technical measures.
- Quebec (Law 25): personal information communicated outside Quebec is assessed for adequate protection under the applicable factors before transfer.
8. Security
Proportionate to what we actually hold:
- All communication between the app and our servers uses TLS encryption in transit; data at rest with our cloud providers is encrypted by those providers.
- Access to your private account record is restricted server-side to you: our database security rules make account documents owner-only, and only an allowlisted subset of profile fields you choose to publish is ever publicly readable. Your email address, role, and subscription details are never in the public projection.
- Studio Link is end-to-end encrypted. When your devices link over the internet, they agree on a session key using ephemeral X25519 key exchange, and content is encrypted with AES-GCM. The key never leaves your two devices, and our relay stores only ciphertext we cannot read.
- Community Blueprint files are stored in closed storage and served through short-lived (15-minute) signed URLs.
- Server endpoints are protected by rate limiting, per address and per IP; our database has deletion protection, point-in-time recovery, and scheduled backups. Device attestation (Play Integrity / Apple DeviceCheck) is built into the app and is being rolled out — it is not yet enforced on our endpoints, so we do not count it as a protection here.
- We honestly describe the limits: local app storage relies on OS sandboxing and device encryption (Section 2), and vault exports use format-level encryption with an app-embedded key rather than a per-user secret — which obscures the file but does not keep it secret from us. Media attached to client export links is protected by unguessable URLs rather than encryption. A client link's content is encrypted before it is uploaded, and since September 2026 the key that opens it travels in your cloud library so that any of your devices can revoke the link — so on a plan whose library we serve, we hold that key as well as the encrypted page. Our full security posture, including what we do not have yet, is set out in our Security Overview.
No system is perfectly secure. If a breach of security safeguards involving your personal information creates a real risk of significant harm, we will notify you and the appropriate authorities (including the Office of the Privacy Commissioner of Canada and, where applicable, provincial and foreign authorities) as required by law.
9. Retention and Deletion
You control local data. It lives on your device; deleting the app (or using its own delete functions) removes it. We hold no copy.
Account data is retained while your account is active. When you delete your account (in-app: Profile → Delete Account, with password confirmation):
- Your account record, portfolio content (projects, services, specializations, testimonials), and inbound portfolio messages are deleted;
- Your uploaded portfolio and profile images are deleted from storage;
- Your username reservation is released;
- Your Forum, Connect, and community posts are anonymized — the content may remain, but your name, username, avatar, and profile links are removed from it;
- Your email address is removed from Blueprints you had published;
- Your authentication record is deleted last, ending your ability to sign in.
Cloud library (for plans that include one) is retained while the plan is active. The copy on our servers is the records and the pictures, documents and audio stored with them, and the client-link keys the library carries; wherever this section says the library is deleted, all of that is deleted with it. A file no record refers to any more — because you removed the picture, or deleted the record that pointed at it — is removed by a clean-up that runs weekly. The copy held for somebody you shared a binder with is deleted as soon as you remove them, they leave, or you stop sharing that binder. When paid access ends, syncing stops and the copy on our servers is held unchanged for 60 days so that resubscribing restores it; we email you when the hold starts and again before it ends, and at the end of that period the copy is permanently deleted. Deleting your account deletes it immediately, without the hold. Neither deletion touches the copies on your own devices, which remain yours.
Client links (for plans that include them) publish an encrypted copy of the content you choose to a page your client can open, and hold what your clients submit on that page (notes, task check-offs, signed approvals, and payment reports — the name, amount and reference a client enters when they tell you they have paid) until your app collects it. That content is retained while the link exists — and a link is not kept forever: a link that no client has opened for twelve (12) months is deleted, together with its published copy and any uncollected client submissions, and we email you at least thirty (30) days before that happens so you can open or republish it if you still need it. Republishing a link, or anyone opening its page, restarts the twelve months. A pay link (a client link that carries an invoice) is deleted on the same basis, and also as soon as you void or delete the invoice it was issued for. When your paid access ends, the pages close to clients immediately and everything clients sent is held for 60 days so you can save it to your devices and so resubscribing restores the links; we email you when the hold starts, and at the end of it the links and any uncollected client submissions are permanently deleted. Deleting a link yourself deletes its published copy and any uncollected client submissions at once — the app first saves what it can to your device and warns you about anything it cannot. Deleting your account deletes all of your client links, their published pages, and any uncollected client submissions immediately, without the hold. Copies already saved to your devices remain yours.
Backup copies held for disaster recovery cycle out on a fixed schedule (our database keeps point-in-time recovery for 7 days plus scheduled backups). Records we are legally required to keep (for example, subscription transaction records for tax purposes) are retained for the legally required period and then deleted. Unverified accounts are subject to scheduled cleanup. Deleting your account does not cancel an app-store subscription — cancel it in your store settings.
10. Your Rights
Everyone: you can access and correct most of your information directly in the app (profile, portfolio, published content), delete individual posts and content, and delete your account entirely in-app. For anything you cannot do in-app, contact the Privacy Officer (Section 1). We respond to access and correction requests within the time required by applicable law (30 days under PIPEDA, extendable as the law permits), and we do not discriminate against you for exercising any right.
Canada (PIPEDA and provincial laws): you may request access to the personal information we hold about you, request corrections, withdraw consent (subject to legal or contractual restrictions — withdrawing consent for account data means closing the account), and challenge our compliance. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).
Quebec (Law 25): you additionally have rights to data portability of computerized personal information you provided, to request de-indexing or cessation of dissemination in certain circumstances, and to complain to the Commission d'accès à l'information du Québec. We do not make decisions about you based exclusively on automated processing.
EEA / UK (GDPR / UK GDPR): where GDPR applies to our processing, we process personal data on these legal bases: performance of a contract (account, subscriptions, cloud features you use); legitimate interests (service security, abuse prevention, defending legal claims — balanced against your rights); consent (optional features that send data off-device where we ask first, such as translation pack downloads and including prompts in feedback reports); and legal obligation (tax and accounting records). You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office. We have not appointed an EEA/UK representative; we are a Canadian company and offer the Services globally through the app stores.
United States (state privacy laws, including California CCPA/CPRA): we do not sell personal information, do not share it for cross-context behavioural advertising, and do not use or disclose sensitive personal information for purposes requiring a right to limit. You have the rights to know, access, correct, and delete, exercisable in-app or through the Privacy Officer, and the right not to be discriminated against for exercising them. Because we do not sell or share personal information, no "Do Not Sell or Share" mechanism is required, and we treat universal opt-out signals as satisfied by default.
Verification: for requests made outside the app, we verify identity against the account email before acting, and we may decline requests that are manifestly unfounded or excessive, as the law allows.
11. Children
The Services are for adults. You must be at least 18 to use them (our Terms of Use, and in-app age confirmations, require this). We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete it. If you believe a minor has provided us personal information, contact the Privacy Officer.
That is a different question from information about a minor. Productions involve children, and the app will hold what you put in it — a young performer's name and call time, a guardian's contact details, footage of a child, a signed minor release. We do not solicit any of it and we do not use it. Where you record it, you are responsible for it under Section 3A, and the law protecting children's information is stricter than the rest; a guardian's consent is usually the least of what is required.
12. Changes to This Policy
We may update this policy as the Services evolve. Material changes will be announced by email and/or prominent in-app notice at least thirty (30) days before they take effect where feasible; the "Last Updated" date always reflects the current version. Continued use of the cloud features after the effective date constitutes acceptance of the updated policy, to the extent permitted by law. Prior versions are available on request.
13. Contact and Complaints
Privacy Officer, THE 6-FIGURE VIDEOGRAPHER LTD., Mississauga, Ontario, Canada — info@t6fv.com.
If we cannot resolve your concern, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376), your provincial privacy regulator, or — where GDPR or a U.S. state law applies to you — your local supervisory authority or attorney general.