Introduction
film360 ("the App", "we", "us", or "our") is a film production management platform operated by Bookstars LLC, a company registered in the State of Delaware, United States.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use film360 — whether through our web application at film360.co or our iOS app.
By creating an account or using film360, you agree to the practices described in this policy. If you do not agree, please do not use the App.
Data We Collect
We collect the following categories of information:
Full name, email address, and password (hashed — never stored in plain text).
If you sign in with Google, we receive your name, email address, and profile photo from Google.
Your production role (Producer, Director, 1st AD, DP, etc.) as selected by you or assigned by a project owner.
All content you create inside film360, including:
- Project names, loglines, schedules, and production details
- Crew and cast member names, phone numbers, email addresses, and day rates
- Budget line items and financial figures
- Call sheet information including locations, emergency contacts, and parking details
- Shot lists, storyboard notes, and shooting schedules
- Chat messages sent within production chat rooms
- Script supervisor notes and daily checklists
- Document vault files uploaded by you or your team
PDF, FDX, Fountain, or TXT script files you upload for AI-powered breakdown. These files are stored securely in Supabase Storage and the extracted text is sent to Anthropic's Claude API for processing. See Section 5 for full details.
IP address, device type, browser or app version, and general usage patterns. This data is used only for security, debugging, and service improvement.
If you subscribe to a paid plan, Paystack (our payment processor) collects your card details and billing information directly. film360 only stores your subscription status (Free or Pro) and Paystack customer ID — never your full card number or banking details.
Email addresses you provide when inviting collaborators to a project. We use these only to send invitation emails on your behalf.
How We Use Your Data
We use your data to:
- Create and manage your film360 account
- Provide and operate all features of the App — dashboard, budgets, crew management, call sheets, script breakdown, chat rooms, and more
- Sync your production data across devices (web and iOS) in real time
- Send transactional emails — project invitations, admin access notifications, and team updates
- Process your script files through our AI breakdown tool (Claude by Anthropic)
- Process subscription payments and manage your plan (Free or Pro) via Paystack
- Respond to support requests
- Maintain the security and integrity of the platform
- Improve the App based on aggregate, anonymised usage patterns
We do not use your data for advertising, profiling, or any purpose beyond operating and improving film360.
Third-Party Service Providers
We use the following trusted third-party services to operate film360. Each processes your data only as necessary to provide their service. All are based in or transfer data to the United States.
When you subscribe to a paid plan, Paystack collects and processes your payment card details, billing name, and billing address. film360 only receives a subscription status confirmation — we never see or store your full card number, CVV, or banking details.
Your subscription status (Free or Pro) is stored in our database to determine which features you can access.
We do not sell data to any of these providers or any third party. These providers are contractually prohibited from using your data for their own purposes.
AI Features & Script Processing
film360 uses Claude by Anthropic to power two features: the AI Script Breakdown tool and the AI Assistant (the floating ✦ button).
Anthropic processes script text and assistant queries in accordance with their Privacy Policy. Anthropic does not use inputs to Claude's API to train their models by default.
AI-generated breakdowns and assistant responses are returned to you and stored in your film360 project data on Supabase. They are never shared with other users unless you explicitly share your project.
Data Storage & Security
All production data is stored in Supabase infrastructure, which is hosted on AWS in the United States. This includes:
- Your account information and production data — stored in a PostgreSQL database with Row Level Security (RLS) enforced
- Script PDFs and vault files — stored in Supabase Storage with access controls
- Chat messages — stored per-project and accessible only to invited collaborators
We implement the following security measures:
- All data in transit is encrypted using TLS/HTTPS
- Passwords are hashed and never stored in plain text
- Row Level Security policies ensure users can only access their own data or projects they are invited to
- API keys for third-party services are stored as server-side environment variables — never exposed to the browser or app client
- File uploads are restricted by type and size
While we implement industry-standard security practices, no system is 100% secure. We encourage you to use a strong, unique password and enable two-factor authentication where available.
Data Sharing & Collaboration
film360 is a collaborative platform. When you invite someone to a project:
- They gain access to project data based on their assigned role
- Crew and cast members see their relevant call sheet, schedule, and chat rooms
- Producers and directors have full project access
- You can remove a collaborator at any time from the Crew & Cast page
We do not share your data with:
- Advertisers or marketing companies
- Data brokers
- Any third party for their own commercial purposes
We may disclose data if required by law, court order, or to protect the rights and safety of users or the public. We will notify you of such requests where legally permitted to do so.
Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Deleted projects: Projects moved to trash are permanently deleted after 30 days.
- Account deletion: If you delete your account, your personal data and all associated projects are permanently deleted within 30 days. Collaborator data shared with other project owners may be retained by those owners.
- Uploaded files: Script PDFs and vault files are deleted from Supabase Storage when the associated project is permanently deleted or when you manually delete them.
- Email logs: Transactional email records held by Resend are subject to Resend's own retention policy.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and associated data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to certain uses of your data.
- Withdrawal of consent: Where processing is based on consent, you may withdraw it at any time.
These rights apply to users in the European Union (GDPR), United Kingdom (UK GDPR), California (CCPA), and Nigeria (NDPA — Nigeria Data Protection Act 2023).
To exercise any of these rights, contact us at hello@bookstars.co. We will respond within 30 days.
Children's Privacy
film360 is intended for use by professional filmmakers and production teams. The App is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13.
If you believe a child under 13 has provided us with personal information, please contact us at hello@bookstars.co and we will delete the information promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and, for significant changes, notify you by email or in-app notification.
Continued use of film360 after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us: