Filmara
PRIVACY

What we hold.

Draft · 4 October 2026
This is a draft and has not been reviewed. It states only what can be verified in Filmara’s own code today. Anything that could not be verified is marked below rather than filled in. Do not rely on it, and do not treat it as a legal document until it has been through review.

Working offline holds nothing

Filmara runs on your machine. Writing, structure and planning need no account, and the files stay in your filesystem. If you never sign in and never turn on cloud sync, we hold nothing about you at all.

This website

filmara.org loads no analytics and no tracking script — there is no Google Analytics, no tag manager, no product-analytics SDK in the site’s source. It is served by Cloudflare Pages, which keeps its own request logs as our infrastructure provider.

If you sign in

Accounts are created through Google sign-in. What is stored against an account is your email address and the Google account identifier, plus your plan, your credit balance and any teams you belong to. The credit ledger is append-only: it records grants, purchases and spends, and is never rewritten.

If you turn on cloud projects

A cloud project is a project you have chosen to sync. Its content is stored in our infrastructure so it can reach your other devices and anyone you invite. Projects you do not sync never leave your machine. Free accounts can sync up to three.

When you generate something

Generation runs on our servers and reaches a model provider through them, so the prompt and any reference images you supply pass through our infrastructure and theirs.

If you connect your own provider account instead — Higgsfield, or your own Gemini or Imagen key — the render goes from your machine to that provider, on your account, and you pay them, not us. The render itself writes no usage record. What does reach us: when the app writes a shot's prompt for you first, it sends the shot's description and the references it uses to our servers, and records that step against your account, like any assistant action; if a render on a connected account fails, the app may report the failure to us, naming the provider and model; and, as for every render, the anonymous render-time statistic described next.

For every render, wherever it runs and whoever pays for it, Filmara keeps an anonymous statistic of how long it took, so the app can tell everyone how long the next one is likely to take. It holds only categories and numbers: whether it was an image, a video or a trained identity; which part of the app asked; the provider and model you chose and how it fared, and the one that served it; whether it ran through Filmara or straight from your machine, and on whose account; desktop or web; how many characters the prompt had, as given and as sent, and whether it was written for you; how many references were given and sent; the size, quality, settings, resolution and clip length asked for and applied, and the size of the request; whether it worked, how many attempts, fallbacks and repeated status checks it took, the time limit it ran under, and the kind of error if it failed; how long each step took, and how often the app checked on it; the app version and edition; the week; and a random id of its own. It holds no account, no project, no prompt text and no image, and nothing in it names you or your work.

When something goes wrong

Two kinds of problem are reported to us automatically, without asking you. The first is a failed assistant run: the assistant works in runs — a short plan it executes a step at a time — and when a step fails repeatedly the run stops, and at that moment the app tells us. The second is a problem the app notices on its own while you work: a check that contradicts what is on your screen, a task that finished without doing what it was for, a request you have had to repeat. When the app notices one it tells you in the same moment, where it happened, and offers the fix when it knows it. We send them because the moment something goes wrong is the one moment nobody stops to report. The app also sends, unasked, the anonymous render-time statistic described above.

Reports are sent this way during the beta. Before the beta ends, this page will say how they work afterwards.

What is sent is a pointer, not your writing: the identifiers of the project and chat session, and of the step, shot or task involved; a short code naming the kind of problem; the app’s own one-line description of it; for a failed run, how many times it was retried; the version and platform you are running; and your account, if you are signed in. No part of your script travels with it — not the brief, not a scene, not a line of dialogue, not what the assistant was proposing, not anything you typed in the chat.

When the app tells you about a problem, it may ask what you were trying to do. What you write there is sent only if you write it and send it, and it is the only part of a report that can carry your own words.

It is a pointer because it does not need to be anything more. When you use the cloud assistant your conversation with it is already stored on our servers, as the memory that lets it recall what you were doing; a report only marks which conversation, or which moment in your work, went wrong so an engineer can look. It is used to fix Filmara and for nothing else — not advertising, not profiling, not resale.

Who else processes it

Cloudflare hosts the site, the application servers and the stored projects. Google provides sign-in. Model providers receive what you send them when you generate.

NOT WRITTEN — NEEDS A DECISION
The definitive list of processors, and what each one receives, has not been written down. It is knowable — it is the set of providers configured in the model catalog plus the infrastructure above — but it changes when a provider is toggled in the backoffice, so it needs an owner and a review cadence rather than a snapshot pasted here.

Training

NOT WRITTEN — NEEDS A DECISION
Whether script content is ever used to train models is an open question inside Filmara and has not been answered. It is the question this page most needs to answer and the one it cannot. It is named as unanswered on the homepage FAQ for the same reason. Until it is settled, no claim belongs here in either direction.

How long we keep it

Render-time statistics are kept indefinitely. They are anonymous, and estimates only read recent ones.

NOT WRITTEN — NEEDS A DECISION
No retention policy is implemented, so any period stated here would be invented. What is true today: the credit ledger is append-only by design, and synced project content persists until deleted.

Who holds it

Filmara Studio SL, registered in Argentina, is the controller of the data described on this page. To ask what is held about you, to correct it, or to have it deleted, write to hello@filmara.tv.

Your rights

NOT WRITTEN — NEEDS A DECISION
The entity and the contact route are settled; which law governs a given user’s rights is not. The company is registered in Argentina, so Argentine data protection law applies to it — but users elsewhere may hold rights under their own law that this page would then have to honour and describe. That is a question for a lawyer, and stating the wrong regime here would be worse than leaving it open.
← Back to Filmara