Filmara
PRIVACY

What we hold.

Draft · 7 September 2026
This is a draft and has not been reviewed. It states only what can be verified in Filmara’s own code today. Anything that could not be verified is marked below rather than filled in. Do not rely on it, and do not treat it as a legal document until it has been through review.

Working offline holds nothing

Filmara runs on your machine. Writing, structure and planning need no account, and the files stay in your filesystem. If you never sign in and never turn on cloud sync, we hold nothing about you at all.

This website

filmara.org loads no analytics and no tracking script — there is no Google Analytics, no tag manager, no product-analytics SDK in the site’s source. It is served by Cloudflare Pages, which keeps its own request logs as our infrastructure provider.

If you sign in

Accounts are created through Google sign-in. What is stored against an account is your email address and the Google account identifier, plus your plan, your credit balance and any teams you belong to. The credit ledger is append-only: it records grants, purchases and spends, and is never rewritten.

If you turn on cloud projects

A cloud project is a project you have chosen to sync. Its content is stored in our infrastructure so it can reach your other devices and anyone you invite. Projects you do not sync never leave your machine. Free accounts can sync up to three.

When you generate something

Generation runs on our servers and reaches a model provider through them, so the prompt and any reference images you supply pass through our infrastructure and theirs.

There is one exception, and it is absolute. If you connect your own Higgsfield account, that request does not transit any Filmara server. We have no record it happened — no usage row, no log line. You are paying the vendor and we are not in the middle.

When the assistant fails

The assistant works in runs — a short plan it executes a step at a time. When a step fails repeatedly the run stops, and at that moment the app tells us, automatically and without asking you. This is the only thing Filmara sends on its own initiative, and we do it because a failed run is the one moment nobody stops to report.

What is sent is a pointer, not your writing: the identifiers of the project, chat session, task and step; the name of the operation that failed; how many times it was retried; the app’s own description of the failure; the version and platform you are running; and your account, if you are signed in. No part of your script travels with it — not the brief, not a scene, not a line of dialogue, not what the assistant was proposing, not anything you typed in the chat.

It is a pointer because it does not need to be anything more. When you use the cloud assistant your conversation with it is already stored on our servers, as the memory that lets it recall what you were doing; the failure report only marks which of those conversations went wrong so an engineer can look. It is used to fix the assistant and for nothing else — not advertising, not profiling, not resale.

Who else processes it

Cloudflare hosts the site, the application servers and the stored projects. Google provides sign-in. Model providers receive what you send them when you generate.

NOT WRITTEN — NEEDS A DECISION
The definitive list of processors, and what each one receives, has not been written down. It is knowable — it is the set of providers configured in the model catalog plus the infrastructure above — but it changes when a provider is toggled in the backoffice, so it needs an owner and a review cadence rather than a snapshot pasted here.

Training

NOT WRITTEN — NEEDS A DECISION
Whether script content is ever used to train models is an open question inside Filmara and has not been answered. It is the question this page most needs to answer and the one it cannot. It is named as unanswered on the homepage FAQ for the same reason. Until it is settled, no claim belongs here in either direction.

How long we keep it

NOT WRITTEN — NEEDS A DECISION
No retention policy is implemented, so any period stated here would be invented. What is true today: the credit ledger is append-only by design, and synced project content persists until deleted.

Who holds it

Filmara Studio SL, registered in Argentina, is the controller of the data described on this page. To ask what is held about you, to correct it, or to have it deleted, write to [email protected].

Your rights

NOT WRITTEN — NEEDS A DECISION
The entity and the contact route are settled; which law governs a given user’s rights is not. The company is registered in Argentina, so Argentine data protection law applies to it — but users elsewhere may hold rights under their own law that this page would then have to honour and describe. That is a question for a lawyer, and stating the wrong regime here would be worse than leaving it open.
← Back to Filmara