← Back to Home

Privacy Policy

Last Updated: January 2025

1. Introduction

Welcome to GenScript! This Privacy Policy explains how GenScript, Inc. ("GenScript," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our AI-powered YouTube script generation platform and related services (the "Service").

We are committed to protecting your privacy and being transparent about our data practices. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

Quick Summary:

  • We collect information you provide and usage data
  • We use data to provide and improve our Service
  • We don't sell your personal information
  • You have rights to access, correct, and delete your data
  • We use industry-standard security measures

2. Information We Collect

2.1 Personal Information You Provide

We collect information you directly provide to us, including:

Account Information:
  • Name and email address
  • Username and password
  • Profile picture (optional)
  • Company name and role (for business accounts)
Payment Information:
  • Billing address
  • Payment method details (processed securely by Stripe)
  • Transaction history
Content and Communications:
  • Script inputs, prompts, and generated content
  • Channel information and analytics you choose to connect
  • Voice profile data and preferences
  • Support messages and feedback
  • Survey responses

2.2 Information Automatically Collected

When you use the Service, we automatically collect:

Usage Information:
  • Features you use and how you interact with the Service
  • Scripts generated, credits used, and export activity
  • Search queries and research activity
  • Time, frequency, and duration of your activities
Device and Technical Information:
  • IP address and approximate location
  • Device type, operating system, and browser
  • Language preferences and time zone
  • Referring/exit pages and URLs
  • Cookies and similar tracking technologies
Performance and Error Data:
  • Error reports and crash data
  • Performance metrics and diagnostics
  • API response times and system health

2.3 Information from Third Parties

We may receive information from:

  • YouTube: Channel data, analytics, and video information when you connect your account
  • Authentication Providers: Profile information from Google, GitHub, or other OAuth providers
  • Payment Processors: Transaction verification from Stripe
  • Analytics Providers: Aggregated usage statistics and performance metrics

3. How We Use Your Information

We use the collected information for the following purposes:

3.1 Provide and Maintain the Service

  • Generate AI-powered scripts based on your inputs
  • Store and manage your content and preferences
  • Process payments and maintain billing records
  • Provide customer support and respond to inquiries
  • Enable team collaboration features

3.2 Improve and Optimize

  • Analyze usage patterns to improve features and performance
  • Train and refine our AI models using aggregated, anonymized data
  • Develop new features and services
  • Conduct research and analytics
  • Test and optimize user experience

3.3 Communicate with You

  • Send transactional emails (receipts, confirmations, notifications)
  • Provide product updates and feature announcements
  • Send marketing communications (with your consent)
  • Request feedback and conduct surveys
  • Respond to your comments and questions

3.4 Security and Compliance

  • Detect and prevent fraud, abuse, and security incidents
  • Enforce our Terms of Service and Acceptable Use Policy
  • Comply with legal obligations and regulatory requirements
  • Protect the rights, property, and safety of GenScript and users

3.5 Personalization

  • Customize content and recommendations
  • Remember your preferences and settings
  • Provide relevant tips and guidance
  • Optimize quality tier and script length suggestions

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We share data with trusted third-party service providers who help us operate the Service:

  • AI Model Providers: Anthropic, OpenAI (for script generation)
  • Cloud Infrastructure: AWS, Vercel (for hosting and storage)
  • Payment Processing: Stripe (for billing and subscriptions)
  • Analytics: Vercel Analytics, PostHog (for usage insights)
  • Email Services: Resend (for transactional emails)
  • Customer Support: Support ticketing systems

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

4.2 Business Transfers

If GenScript is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to:

  • Valid legal processes (subpoenas, court orders, warrants)
  • Government requests or investigations
  • Requests to protect rights, property, or safety
  • Enforce our Terms of Service

4.4 With Your Consent

We may share your information with third parties when you explicitly consent, such as:

  • Connecting your YouTube channel
  • Sharing generated scripts publicly (if you choose)
  • Participating in case studies or testimonials

4.5 Aggregated Data

We may share aggregated, anonymized data that does not identify you personally for industry analysis, research, marketing, or other business purposes.

5. Data Security

We implement appropriate technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction.

5.1 Security Measures

  • Encryption: Data encrypted in transit (TLS/SSL) and at rest (AES-256)
  • Authentication: Password hashing with bcrypt, multi-factor authentication support
  • Access Controls: Role-based access, principle of least privilege
  • Infrastructure: Secure cloud hosting with regular security audits
  • Monitoring: 24/7 system monitoring and intrusion detection
  • Backups: Regular encrypted backups with disaster recovery procedures

5.2 Your Responsibility

While we implement strong security measures, you are responsible for:

  • Keeping your password secure and confidential
  • Enabling two-factor authentication
  • Not sharing your account credentials
  • Reporting any suspicious activity immediately

5.3 Data Breach Notification

In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of discovery.

6. Your Data Rights

Depending on your location, you may have the following rights regarding your personal information:

6.1 Access and Portability

  • Request a copy of your personal data
  • Export your scripts and content in portable formats
  • Receive information about how we process your data

6.2 Correction and Update

  • Update your account information at any time
  • Correct inaccurate or incomplete data
  • Request correction of data we hold about you

6.3 Deletion

  • Delete your account and associated data
  • Request deletion of specific information
  • Note: We may retain certain data as required by law or for legitimate business purposes

6.4 Restriction and Objection

  • Restrict how we process your data
  • Object to processing for direct marketing
  • Withdraw consent for optional data uses

6.5 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@genscript.io or through your account settings. We will respond within 30 days of receiving your request.

You also have the right to lodge a complaint with a data protection authority in your jurisdiction if you believe we have violated your privacy rights.

7. Data Retention

We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy.

7.1 Retention Periods

  • Account Data: While your account is active and for 30 days after deletion
  • Scripts and Content: While your account is active and for 30 days after deletion
  • Billing Records: 7 years for tax and accounting purposes
  • Support Communications: 3 years
  • Analytics Data: Aggregated data retained indefinitely
  • Backup Data: Up to 90 days in encrypted backups

7.2 Deletion After Retention

After the retention period expires, we securely delete or anonymize your data. Some information may be retained longer if required by law or for legitimate business interests (e.g., fraud prevention).

8. International Data Transfers

GenScript is based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States and other countries where our service providers operate.

We ensure appropriate safeguards are in place for international data transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for transfers to certain countries
  • Privacy Shield certification (where applicable)
  • Binding Corporate Rules for service providers

9. Children's Privacy

The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@genscript.io. We will delete such information from our systems.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

10.1 Right to Know

You have the right to request:

  • Categories of personal information we collect
  • Sources from which we collect information
  • Business purposes for collecting information
  • Categories of third parties we share information with
  • Specific pieces of personal information we hold about you

10.2 Right to Delete

You can request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, fraud prevention).

10.3 Right to Opt-Out of Sale

We do not sell your personal information. If our practices change, we will update this policy and provide an opt-out mechanism.

10.4 Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights.

10.5 "Shine the Light" Law

California residents can request information about personal information disclosed to third parties for direct marketing purposes. Since we don't share for this purpose, this doesn't apply.

10.6 How to Exercise CCPA Rights

Email privacy@genscript.io with "CCPA Request" in the subject line. We may verify your identity before processing requests.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

13.1 Notification of Changes

We will notify you of material changes by:

  • Updating the "Last Updated" date at the top of this policy
  • Sending an email to your registered email address
  • Displaying a prominent notice on the Service
  • Requiring you to accept the updated policy

13.2 Your Acceptance

Continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy. If you do not agree to changes, you should discontinue use and delete your account.

14. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

GenScript, Inc.

Privacy Officer

Email: privacy@genscript.io

General: legal@genscript.io

Support: support@genscript.io

Website: genscript.io

We will respond to your request within 30 days. For urgent privacy concerns, please indicate "Urgent" in your subject line.

15. Supplemental Terms for Specific Regions

15.1 European Economic Area (EEA) and UK

If you are located in the EEA or UK, we process your data in accordance with the General Data Protection Regulation (GDPR) and UK GDPR.

Legal Basis for Processing:
  • Contract Performance: To provide the Service per our Terms
  • Legitimate Interests: To improve and secure the Service
  • Consent: For marketing communications and optional features
  • Legal Obligations: To comply with laws and regulations
Your GDPR Rights:
  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

15.2 Canada

We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. Canadian residents can contact our Privacy Officer for data access requests.

15.3 Australia

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988. Australian residents can contact the Office of the Australian Information Commissioner (OAIC) for complaints.

15.4 Brazil

We comply with Lei Geral de Proteção de Dados (LGPD). Brazilian residents have rights to access, correct, delete, and port data, as well as request information about data sharing.

Data Processing Summary

Data CategoryPurposeLegal BasisRetention
Account InformationService provision, authenticationContractActive + 30 days
Payment DataBilling, tax complianceContract, Legal7 years
Generated ScriptsService delivery, storageContractActive + 30 days
Usage AnalyticsService improvementLegitimate InterestIndefinite (anonymized)
Marketing DataCommunicationsConsentUntil withdrawal

This Privacy Policy was last updated on January 1, 2025.

© 2025 GenScript, Inc. All rights reserved.