Ptolemy Studio
PricingLanguagesSign inSign up

Privacy Policy

What Ptolemy Studio does with your screenplay, your crew’s information, and your account — described as the system actually works today.

Last updated 2 September 2026

This policy describes the running product, not a plan. Where a protection is not built yet, this page says so instead of staying quiet about it. If you find a sentence here that is not true of what the software does, that is a defect and we want to hear about it: ptolemy@omniatheatre.com.

Your script is yours. We do not train on it.

The short version. You own your screenplay. Uploading it here gives us no ownership of it and no right to use it for anything except running the features you asked for. We do not use your creative work to train, fine-tune or evaluate any AI model — not your script, not your treatment, not your characters. We do not sell it, publish it, show it to other customers, or add it to a dataset.

This is not a slogan; it is the rule the people who build this product work to, and it predates the product: production and logistical materials are ours to work with; creative and vision materials are not. Your screenplay is creative material. It is handled accordingly.

What actually happens to the words

To do the work you asked for — a rewrite suggestion, a script breakdown, a beat analysis, a draft shot list, a character profile — we send the relevant text of your script to Anthropic’s Claude API, receive the result, and give it to you. That is the only reason your script leaves our servers, and Anthropic is the only provider that sees it. When a feature needs only part of the script, only that part is sent.

Anthropic processes that text under their own API terms, which govern what they do with it and how long they hold it. We do not enable, and have never enabled, any option that would allow your content to be used to train their models. What we cannot do is make promises on their behalf: read their terms if that matters to you, and tell us if you need something stronger.

What we have not built. We do not have a signed zero-data-retention agreement with any AI provider, and we do not offer a mode that runs your script through a model with no third-party processing at all. If your production requires either, do not upload the script — talk to us first.

Who we are

Ptolemy Studio is operated by The Omnia Theatre, based in British Columbia, Canada. For anything in this policy — a question, an access request, a deletion request, or a complaint — write to ptolemy@omniatheatre.com. A person reads that address.

What we hold

Your OmniAccount

Your OmniAccount is one record per email address. You can open it with Google, with an email address and a password, or with a one-time email link — every door opens the same workspace. The record holds your email address, whether and when it was verified, when it was created and last changed, and which sign-in methods are attached to it.

If you set a password, we hold a salted scrypt hash of it — never the password itself. A hash cannot be turned back into the password; when you sign in, we hash what you typed the same way and compare the two. Nobody at Omnia Theatre can read your password, and we cannot send it to you if you forget it — only a link to choose a new one.

Signing in with Google gives us your email address, your name, your profile picture, and whether Google says your address is verified. Linking Google to your OmniAccount stores the Google account id and the Google email address, and nothing else from Google.

Verification, sign-in and password-reset links all work the same way: when one is requested, we generate a random one-time code, store only a one-way hash of that code together with your email address, a timestamp and what the link is for, and email you a link containing the code itself. Clicking the link proves you control that inbox, which is treated the same way Google’s verification is. Every such link is single-use and expires after 15 minutes; after that (or after it is used), a new one has to be requested. A link issued for one purpose cannot be used for another. We do not keep the code itself anywhere, only its hash.

Either way, your email address is the key your data is stored under, and you can set a different display name inside the product.

What you create

  • Script files you upload (Fountain, Final Draft, Movie Magic, Beat, Word, PDF, plain text) and the text parsed out of them.
  • Everything derived from that script: scenes, versions, your editing history, breakdown elements, budgets, schedules, stripboards, call sheets, sides, storyboards, annotations and project chat messages.
  • Scanned PDFs are read by optical character recognition that runs on our own servers. A scanned script is not sent to a third-party OCR service.

Information you enter about other people

Crew records — name, role, department, email address, phone number, deal-memo status, and the engagements, rates and hours attached to them. Production locations, including free-text street addresses and nearest-hospital details, together with the name of whoever recorded them. Organisation members and people you have invited, by email address. This has its own section below, because most of these people never signed up for anything.

Billing

Your Stripe customer identifier, which plan you are on, and your subscription status. Card numbers go from your browser directly to Stripe’s own checkout. They never touch our servers and we never see them.

Technical

A sign-in cookie, and the ordinary server logs our hosting produces. When you create an OmniAccount with a password, the browser you register from also receives a short-lived registration cookie; it exists only to bind your verification click to that browser (so a password typed before verification is kept only if the same browser verifies), it is sent only to our sign-in endpoints, and it expires in 15 minutes. We run no analytics, no advertising, no tracking pixels and no third-party cookies of any kind. There is no Google Analytics here, no product-analytics tool, no session recorder, no error-reporting service. That is verifiable in the source, not a stated intention.

Who else touches your data

This is the complete list, derived from the code rather than from memory. Nothing else receives your content.

ProviderWhat we use it forWhat it receives
Google Cloud PlatformHosting, the database your work is stored in, and secret storage.Everything you keep in Ptolemy Studio, because this is where it is stored.
Google — Sign in with GoogleSigning you in. It is the only way to sign in; there is no password.Your email address, your name, your profile picture, and whether Google says your address is verified.
Anthropic (Claude API)The writing assistant, script breakdown, beat analysis, shot-list generation and character profiles.The text of your script, or the portion of it the feature you ran needs. This is the one provider that sees your screenplay.
Google — Gemini image modelGenerating concept art for a scene.Only the scene description you ask us to illustrate, plus the project title. Your script is not sent to it.
StripeTaking subscription payments.Your email address and which plan you are on. Card details go from your browser straight to Stripe and never reach our servers.
ResendSending a deal memo to a crew member, when you press send.That crew member's email address and the text of the memo.

One clarification worth making explicitly, because it is the kind of thing a list like this usually blurs: an earlier version of this product used DeepSeek as its primary model until 11 July 2026. It is not called by any part of the running application and receives none of your content. It is not on the list because it is not a recipient.

We do not sell your data, and we do not share it with anyone for their own purposes. Every provider above is used to deliver a feature you asked for.

Information a production enters about people who never signed up

This product is built for productions, and a production keeps records about its crew. That means a person with an account here can type another person’s name, email address, phone number and rate into the system — someone who has no account, did not agree to anything, and may not know the record exists. We are not going to pretend otherwise.

If you are the production

Under Canadian privacy law — PIPEDA federally, and the Personal Information Protection Act in British Columbia — the organisation that collects someone’s personal information is responsible for having a proper basis to collect it, for using it only for the purpose it was collected for, and for keeping it no longer than that purpose needs. When you enter crew data here, that organisation is you. We supply the tool. We cannot obtain your crew’s consent on your behalf, and we do not try to.

  • Enter what the production actually needs, and not more.
  • Tell the people concerned that their details are held in a production system, and what it is used for.
  • Delete the records when the production no longer needs them. Deleting a crew member here is immediate and real.

If you are a crew member and your details are in here

The production controls that record and can correct or delete it themselves, so asking them is the fastest route and usually the only one needed. If you cannot reach them, or they will not act, write to us at ptolemy@omniatheatre.com and we will help. Be aware of two limits, stated in advance rather than discovered later: we will need to be reasonably satisfied that you are who you say you are, and because the record belongs to the production’s account we will normally have to involve them before removing it.

What is coming, and is not here yet. Work is planned that would let productions hold legal names, home addresses, Social Insurance Numbers and banking details for payroll. None of that is in the running product today, and this policy will be rewritten before any of it ships. Do not enter a SIN or bank account into a notes field: there is nowhere in this system built to hold that safely yet.

Where your data is

Ptolemy Studio runs on Google Cloud in us-central1 (Iowa, United States). Your script, your crew list and everything else you keep here is stored and processed in the United States, whichever country you are in. Anthropic and Stripe also process data outside Canada.

That matters and you are entitled to know it: while your information is in the United States it is subject to United States law, including lawful access requests by United States authorities, and those requests would not be governed by Canadian law. If your production cannot accept that, this is the point to stop and talk to us rather than upload.

How long we keep it

We do not currently delete anything automatically. There is no retention schedule in this product: your projects, versions and crew records stay until you delete them or ask us to. Setting real retention limits is work we have not done, and saying we had them when we do not would be the exact kind of claim this document refuses to make.

Deleting things

What you can delete yourself, right now

  • A project. Deleting a project removes the project and everything beneath it — scenes, versions, edit history, breakdown, budget, schedule, storyboard and annotations. It is a real deletion and it cannot be undone.
  • A crew member. Immediate and real.
  • Archiving is not deleting. Archiving a project puts it away reversibly and destroys nothing. It does suspend any public share link on that project; restoring the project makes that link live again.

Deleting your whole account

There is no button for this yet. Email ptolemy@omniatheatre.com and a person will delete your account and your organisation’s data, and will confirm to you when it is done. We are not going to describe a one-click deletion we have not built.

What a deletion does and does not reach

On our side a deletion is complete: this database has no scheduled backups and no point-in-time recovery, so there is no shadow copy for a deleted project to survive in. The same fact has an edge you should know about — we cannot restore something you deleted by mistake, so keep your own copies of your scripts. The product’s export feature exists for exactly that.

A deletion here does not reach the providers listed above. Content already sent to Anthropic or Google is held under their retention terms, not ours. Stripe keeps the payment and tax records it is required to keep. Email already delivered has already been delivered.

Your rights

Under PIPEDA and BC PIPA you can ask what personal information we hold about you, ask for a copy of it, ask us to correct it if it is wrong, and ask us to delete it. Write to ptolemy@omniatheatre.com. We will need to be reasonably satisfied of your identity before we answer.

What we can do today, honestly stated: your scripts can be exported from the product yourself, in Fountain, Final Draft, plain text or PDF. Everything else — an access request, a correction, a deletion — is handled manually by a person. There is no one-click “download everything you hold about me”, and we are not going to imply there is.

We are describing what we do. We are not claiming certification against any standard, we have not been audited, and nothing here should be read as a declaration that we are compliant with a regime we have not been assessed under. If you are unhappy with how we have handled your information you can complain to the Office of the Privacy Commissioner of Canada, or, in British Columbia, to the Office of the Information and Privacy Commissioner for BC.

Security — what is true, and what is not

  • If you choose a password, we store a salted scrypt hash of it and never the password itself. Google sign-in and emailed links involve no password at all.
  • Verification, sign-in and password-reset links are single-use and expire in 15 minutes.
  • Sessions are cookies with a hard 30-day ceiling, and a session can be revoked.
  • Every request for a document checks your organisation membership and role before answering. A browser receives short-lived credentials minted by the server for live updates and cannot widen its own permissions.
  • API keys and other secrets live in Google Secret Manager, not in the code.
  • Data is encrypted in transit, and encrypted at rest by Google Cloud as standard.
  • Share links are public by design. If you turn on a share link for a project, anyone with that URL can read it with no sign-in at all. Archiving the project suspends the link; turning sharing off revokes it.
What we do not claim. We have not had a third-party security audit. We do not hold SOC 2, ISO 27001 or any equivalent certification. We do not yet offer a signed data processing agreement. If your production requires any of those, ask us before you upload — the honest answer today is that we do not have them.

Children

Ptolemy Studio is a professional tool for making films. It is not directed at children, nothing in it is designed for them, and we do not knowingly collect information from them. To use it you must be old enough to enter a binding contract where you live — see the Terms of Service.

Changes to this policy

When what we do changes, this page changes with it and the date at the top moves. We do not currently run a mailing list, so we cannot promise to email you about it — that date is the honest signal, and it is why it is at the top rather than buried at the bottom.

Contact

ptolemy@omniatheatre.com — The Omnia Theatre, British Columbia, Canada.

© 2026 The Omnia Theatre · ptolemy.studioPrivacyTermsPress Kitptolemy@omniatheatre.com