Privacy

Privacy Policy

Effective date: November 11, 2025

Plain-English summary: We collect only what we need to run the service, improve
reliability (e.g., crash reports, session logs), and understand usage patterns in
aggregate to make better business decisions. We don’t sell personal information, and
we won’t spam you. The details below are the legally precise version.

Who we are

Controller / Provider: Tribeca Teleprompting (the “Company”)
Products covered: Tribeca Teleprompting and Promptosaurus (collectively, the “Service”).
Contact: Evan@TribecaTeleprompting.com
Mailing: Evan Brenner, 435 Washington Street #1, New York, NY 10013

What this policy covers

This Privacy Policy explains what data we collect when you use the Service, why we collect it,
how we use it, when we share it, and the choices you have. If any part of this policy conflicts with
local law, we will follow the law.

Information we collect

We collect the following categories of information:

1. Account information

  • Email address and name when you create an account or sign in (including via
    Google Sign-In).
  • Organization name (if you add one).

2. Authentication tokens

  • OAuth tokens/refresh tokens required to connect your account to integrated
    services (e.g., Google). We store only what’s necessary to keep you signed in
    and provide features you request.

3. Content you provide

  • Scripts, prompts, and other files you upload or link for use with the Service.
  • Support requests and any information you include when you contact us.

4. Device, usage, and diagnostics

  • Session data (e.g., timestamps, pages/features used, performance metrics).
  • Crash logs and diagnostics (e.g., stack traces, device/OS, app version).
  • Technical information sent by your device or browser (e.g., IP address, user
    agent, language, referrer/exit pages).
  • Where legally permitted and in aggregate, we may record event-level usage (e.g.,
    number of audience members or venue characteristics if you choose to enable
    such features) to understand demand and set pricing. We do not use this
    information to profile individuals.

5. Payment information

  • If you purchase a paid plan, payments are processed by our payment partner
    (e.g., Stripe). We do not store full payment card numbers. We keep limited billing
    metadata (e.g., last 4 digits, card brand, billing address) for receipts and
    accounting.

How we use information

We use information to:

  • Provide the Service you ask for, including authentication, syncing content, rendering
    teleprompting scripts, and customer support.
  • Maintain and improve reliability (e.g., detect, reproduce, and fix crashes; optimize
    performance).
  • Measure and plan (e.g., aggregated usage analytics to understand which features are
    used and to inform pricing and capacity planning).
  • Communicate with you about service changes, security alerts, and transactional emails
    (receipts, account notifications). We don’t send marketing emails without your consent,
    and you can opt out at any time.
  • Comply with law, prevent abuse, and protect the Service and our users.

No spam pledge: The email you use to sign up is used for login and essential notices.
We won’t sell it or use it for unrelated marketing without your permission.

Google user data

If you connect a Google account, we access only the Google APIs and scopes you authorize. Our
use of Google information adheres to the Google API Services User Data Policy, including the
Limited Use requirements:

  • We use Google data only to provide or improve user-facing features you request.
  • We do not sell Google user data.
  • We do not use or transfer Google user data for ads, including retargeting.
  • We only share Google user data with service providers as necessary to run the Service, under confidentiality and security obligations.

You can disconnect our access at any time from your Google account’s security settings.

When we access your content

  • By default, content (e.g., scripts, linked documents) is processed automatically to
    provide the Service.
  • Human access: Our team does not read your content except (a) if you ask us to for
    support, (b) to investigate a security or abuse issue, or (c) if required by law. We log
    limited audit events when human access occurs.
  • Aggregated venue usage (optional): If you enable features that estimate audience size
    or venue-level activity, we may collect event-level metadata to help you (and us)
    understand usage patterns. We use this in aggregate to plan capacity and set pricing.
    We do not attempt to identify individuals from this data.

 

Legal bases for processing (EEA/UK users)

Where GDPR/UK GDPR applies, our legal bases include Contract (to provide the Service),
Legitimate Interests (e.g., to maintain security and improve reliability), and Consent where
required (e.g., certain analytics or marketing).

Sharing and disclosures

We share data only with:

  • Service providers (processors) that help us run the Service (e.g., hosting, analytics,
    email delivery, payments). They must follow our instructions and protect your data.
  • Affiliates under common control, subject to this policy.
  • Law enforcement or legal requests when we’re required to comply with applicable law.
  • Business transfers (e.g., merger or acquisition), with appropriate protections and
    notice where required.

We do not sell personal information. If the law where you live defines “sale” to include sharing for
targeted advertising, we do not engage in that practice.

Data retention

  • Account profile and OAuth tokens are kept while your account is active.
  • Session and diagnostic logs are typically retained for [90] days unless needed longer
    for security or legal reasons.
  • Content you upload is retained until you delete it or your account, subject to
    reasonable backups.

Security

We protect data with administrative, technical, and physical safeguards, including encryption in
transit, restricted access, and monitoring. No system is perfectly secure; you are responsible for
using a strong password and keeping your account secure.

Your choices and rights

  • Access/Update/Delete: You can access and update your account information in the
    app. To delete your account or request deletion of content, Evan@tribecateleprompting.com.
  • Revoke integrations: You can disconnect Google access from your Google Account’s
    security settings.
  • Opt-out of analytics (where available): You can disable optional analytics features in
    settings or by contacting us.
  • EEA/UK/Swiss users: You may have rights to access, correct, delete, port, or object to
    processing. You also have the right to lodge a complaint with your local supervisory
    authority.

International transfers

We may process data in the United States and other countries. When transferring personal data
from the EEA/UK/Switzerland, we rely on appropriate safeguards (e.g., Standard Contractual
Clauses) where required by law.

Children

The Service is not directed to children under 13 (or the age required by local law). We do not
knowingly collect personal information from children.

Changes to this policy

We may update this policy from time to time. We will post the updated version and change the
“Effective date” above. If changes are material, we will provide additional notice.

Contact

Questions or requests? Evan@tribecateleprompting.com