1. Introduction
Welcome to Tarr (also known as "Trelby Web App"), a modern pageless screenplay editor. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our web-based screenplay writing application and related services.
By using Tarr, you agree to the collection and use of information in accordance with this Privacy Policy. If you disagree with any part of this policy, please do not use our service.
2. Information We Collect
2.1 Personal Information
When you create an account, we collect:
- Email address - for account creation and communication
- Password - securely hashed for authentication
- Payment information - processed through secure payment providers for paid plans
2.2 Content and Usage Data
- Screenplay content - your scripts, projects, and creative work stored securely
- Project metadata - project names, creation dates, modification times
- File organization data - folder structures and file arrangements
- Title page information - author names and contact details you provide
- Usage analytics - feature usage, session duration, and performance metrics
- Device information - browser type, operating system, and device specifications
2.3 Third-Party Integration Data
When you connect third-party services:
- Google Drive data - file metadata and backup information (with your explicit consent)
- Spotify data - playlist information and listening preferences (when using music features)
- Voice recordings - temporary audio data for AI transcription features
2.4 Automatically Collected Information
- IP address - for security and service delivery
- Browser cookies - for session management and preferences
- Log data - server logs for troubleshooting and security
- Real-time collaboration data - cursor positions and editing activity during collaborative sessions
3. How We Use Your Information
3.1 Primary Uses
- Service delivery - providing screenplay editing and management features
- Account management - user authentication and profile maintenance
- Data synchronization - syncing your work across devices and sessions
- Collaboration - enabling real-time collaborative editing features
- Backup and recovery - protecting your work through automatic backups
3.2 Secondary Uses
- Customer support - responding to inquiries and technical issues
- Service improvement - analyzing usage patterns to enhance features
- Security - detecting and preventing unauthorized access
- Communication - sending important service updates and notifications
- Legal compliance - meeting legal obligations and protecting rights
4. Data Storage and Security
4.1 Storage Infrastructure
- Primary storage - Supabase cloud infrastructure with enterprise-grade security
- Local storage - browser-based storage for offline functionality
- Backup storage - optional Google Drive integration for additional backup
- Geographic location - data stored in secure data centers with appropriate protections
4.2 Security Measures
- Encryption - data encrypted in transit (TLS/SSL) and at rest
- Authentication - OAuth 2.0 and secure password handling
- Access controls - row-level security ensuring users can only access their own data
- Regular backups - automated backup systems to prevent data loss
- Security monitoring - continuous monitoring for threats and vulnerabilities
4.3 Data Retention
- Active accounts - data retained while your account remains active
- Deleted accounts - data permanently deleted within 30 days of account deletion
- Backup data - backup copies retained for 90 days for recovery purposes
- Legal requirements - some data may be retained longer for legal compliance
5. Data Sharing and Disclosure
5.1 We Do Not Sell Your Data
We never sell, rent, or trade your personal information or screenplay content to third parties for commercial purposes.
5.2 Limited Sharing Circumstances
We may share information only in these specific situations:
With Your Consent:
- When you explicitly authorize sharing (e.g., collaborating on projects)
- When you connect third-party services (Google Drive, Spotify)
Service Providers:
- Supabase - for database and authentication services
- Payment processors - for billing and subscription management
- Cloud storage providers - when you choose to use backup services
- AI service providers - for transcription and writing assistance features
Legal Requirements:
- To comply with applicable laws and regulations
- To respond to valid legal requests from authorities
- To protect the rights, property, and safety of our users and service
5.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may be transferred as part of that transaction, subject to the same privacy protections.
6. Your Rights and Choices
6.1 Access and Control
- Data access - request a copy of your personal data
- Data correction - update or correct inaccurate information
- Data deletion - permanently delete your account and associated data
- Data portability - export your screenplay content in standard formats
6.2 Privacy Controls
- Third-party connections - control which services you connect to your account
- Collaboration settings - manage who can access your projects
- Communication preferences - opt out of non-essential communications
- Analytics - disable usage analytics collection (where technically feasible)
6.3 Exercise Your Rights
To exercise these rights, contact us at privacy@tarr.app or through your account settings.
7. Third-Party Services
7.1 Integrated Services
Tarr integrates with several third-party services:
Google Drive:
- Used for optional backup and file storage
- Governed by Google's Privacy Policy
- Requires explicit user consent for access
Spotify:
- Used for music player functionality
- Governed by Spotify's Privacy Policy
- Optional feature requiring user authorization
AI Services (ElevenLabs, Gemini):
- Used for voice transcription and writing assistance
- Voice data processed temporarily and not stored
- Governed by respective service provider policies
7.2 Third-Party Responsibility
We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies before connecting these services.
8. International Data Transfers
If you are located outside the country where our servers are located, please be aware that your information may be transferred to, stored, and processed in countries with different data protection laws. We ensure appropriate safeguards are in place for such transfers.
9. Children's Privacy
Tarr is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If we discover we have collected such information, we will delete it immediately.
10. Cookies and Tracking
10.1 Cookie Usage
We use cookies and similar technologies for:
- Session management - keeping you logged in
- Preferences - remembering your settings
- Analytics - understanding how you use our service
- Security - protecting against unauthorized access
10.2 Cookie Control
You can control cookies through your browser settings, though some features may not function properly if cookies are disabled.
11. Data Breach Notification
In the unlikely event of a data breach affecting your personal information, we will:
- Notify affected users within 72 hours
- Provide details about what information was involved
- Explain steps we're taking to address the breach
- Offer guidance on protecting yourself
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will:
- Post the updated policy on our website
- Notify users of significant changes via email
- Provide a 30-day notice period for material changes
- Update the "Last Updated" date at the top of this policy
14. Regional Privacy Rights
14.1 European Union (GDPR)
If you are located in the EU, you have additional rights under GDPR:
- Right to access, rectify, and erase personal data
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with supervisory authorities
14.2 California (CCPA)
If you are a California resident, you have rights under CCPA:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale (note: we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
14.3 Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate.
15. Data Processing Legal Basis
We process your data based on:
- Contract performance - to provide our services
- Legitimate interests - for service improvement and security
- Consent - for optional features and marketing
- Legal obligations - to comply with applicable laws