DraftLight

Privacy Policy

Last updated: August 25, 2026

This Privacy Policy explains what information DraftLight collects, how we use it, and who we share it with. It applies to your use of draftlight.app. We don't sell your data to anyone, ever.

1. Information you provide

  • Account info: name, email address, and password (we store a one-way bcrypt hash, never the plaintext password) — or, if you sign in with Google, your Google account's name and email.
  • Optional profile info: avatar photo, phone number, and mailing address, if you choose to add them in Settings.
  • Project content: everything you create in the app — scripts, drafts, revisions, comments, breakdown tags, budgets, scheduling data, and any location photos or panoramas you upload.
  • Payment info: if you subscribe to a paid plan, Stripe collects your payment details directly on their own hosted checkout page. We receive a Stripe customer/subscription ID and your plan status — never your full card number.

2. Information collected automatically

Our servers log standard request information (IP address, timestamps, error details) for security and debugging, the same as most web services. We use one essential session cookie to keep you signed in — it's functional, not used for advertising or tracking. We don't run any analytics, advertising, or third-party tracking scripts on DraftLight.

3. How we use your information

  • To operate the app — store and serve your projects, scripts, and account data.
  • To send transactional email: collaborator invites, @mention notifications, password resets, and billing receipts.
  • To process payments and manage your subscription.
  • To secure the service — detect abuse, enforce rate limits and plan limits.
  • To respond when you contact support.

4. Who we share it with

We use a small number of third-party services to run DraftLight. Each only receives what it needs to do its job:

  • Stripe — payment processing and subscription billing.
  • Mailjet — delivery of transactional emails (invites, mentions, password resets).
  • Google — Google Sign-In, if you choose to use it, and the Google Maps/Geocoding API to place a pin on the map for any location address you enter.
  • Cloudflare — hosts uploaded images (avatars, location photos, panoramas) via Cloudflare R2, and provides the CDN and security protection in front of the app.

If you invite a collaborator or create a share link, the people you share with can see the project content covered by their role — that's a feature you control, not something we do on your behalf. We don't share your data with anyone else, and we don't sell it.

5. Data retention

We keep your account and project data for as long as your account is active. Deleted content (a removed photo, a deleted location) is removed from active storage; nightly database backups roll off over time rather than being purged individually. There's no self-serve account deletion yet — email support@vidaptic.com to request deletion or an export of your data, and we'll take care of it.

6. Security

All traffic to DraftLight is encrypted in transit (HTTPS). Passwords are hashed, never stored in plain text. Uploaded images are stored on Cloudflare R2, which encrypts data at rest. No system is perfectly secure, but we take reasonable, standard precautions to protect your data.

7. Children's privacy

DraftLight isn't directed at children, and we don't knowingly collect information from anyone under 18.

8. Your choices

You can view and update most of your account information directly in Settings. For anything else — a full data export, correcting something you can't edit yourself, or closing your account — email support@vidaptic.com.

9. Changes to this policy

We may update this policy from time to time. We'll update the “Last updated” date above when we do.

10. Contact

Questions about this policy or your data? Email support@vidaptic.com.