Skip to main content

Privacy Policy

Last updated: July 16, 2026

1. Information We Collect

We collect information you provide when creating an account, uploading media, and using Selexts:

  • Account information: name, email address, workspace details
  • Content: media files (video, images, audio) you upload for review
  • Usage data: review decisions, workspace activity, feature interactions
  • Communication preferences: notification settings, email opt-ins

2. How We Use Information

We use collected information to:

  • Provide and maintain the Selexts service
  • Process review workflows and deliver packages
  • Send service notifications (invites, delivery alerts, billing)
  • Improve product performance and reliability
  • Comply with legal obligations

3. Data Sharing

We share data only with subprocessors essential to service delivery:

  • Supabase — database, authentication, storage
  • Bunny.net — media streaming, CDN, storage
  • Resend — transactional email delivery
  • Sentry — error monitoring and performance
  • Railway — application hosting
  • PostHog — product analytics (pageviews and product events); only after you grant analytics consent
  • Lemon Squeezy — payment processing, subscription billing, and customer portal
  • Cloudflare — Turnstile captcha verification (token and remote IP) on authentication surfaces when enabled

Payment card data is processed by Lemon Squeezy. Selexts does not store full card numbers or other payment instrument details on our systems.

We do not sell personal data. We do not use customer content for training AI models.

4. Cookies & Analytics

We use a single first-visit consent control. Essential cookies always run the product (authentication and workspace preference). Accept enables optional product analytics; Decline keeps essentials only and does not enable analytics. Declining does not remove authentication cookies or your active workspace preference.

  • Essential: Supabase authentication session cookies; active workspace preference stored as cookie and localStorage key sr-active-workspace-id
  • Consent preferences: localStorage keys sr-cookie-consent (banner acknowledgment), sr-analytics-consent (analytics choice), and a versioned consent record at sr-consent-record. Choices are written together when you Accept or Decline, or when you change preferences in Settings.
  • Analytics: PostHog loads only after analytics consent is granted. Autocapture and session replay remain off. When consented, PostHog may receive a stable account identifier (user id) for cross-session product analytics; we do not send email or display name as identify traits. Event properties are sanitized to remove tokens and secrets. We do not use advertising pixels.

We do not sell personal data for advertising. You can withdraw or change analytics consent in Settings → Account → Cookie preferences without clearing all site data. You may also contact privacy@selexts.com.

5. Data Retention

We retain account and workspace data while your account is active and as needed to operate the service. Retention depends on the type of data:

  • Account deletion: When an account deletion request is finalized, we remove your account identity (auth user), scrub profile identifiers, revoke pending invites, and delete your workspace memberships. This ends your access to the product. Account deletion is identity erasure, not automatic media purge.
  • Shared workspace media: Media files, takes, decisions, and other workspace content are owned by the workspace. Account deletion does not automatically delete shared workspace content. Remaining members and workspace owners control that content until they delete it or the workspace is torn down.
  • Content soft-delete grace: When content is deleted through product workflows, it is soft-deleted first. Hard purge (including Bunny media objects) runs after a grace period of CLEANUP_GRACE_PERIOD_DAYS (default 30 days) via cleanup jobs.
  • Audit residual: After account deletion, actor_id on audit events is cleared where foreign-key policy sets null. Operational JSONB snapshots in audit rows may retain non-profile action context for up to the audit retention window (currently 365 days) and are not individual profile records.
  • Operational logs: Audit records and email outbox rows follow separate retention jobs (currently on the order of 365 days for audit and 90 days for email outbox terminal rows) and are not wiped solely because an individual account was deleted. Email suppressions are retained on the order of 180 days after last update unless re-suppressed.
  • Email delivery metadata: email_deliveries rows (recipient email + delivery status) are purged after approximately 12 months by a retention job that skips workspaces under legal hold.
  • Client review tokens & feedback pins: External client review tokens and their feedback pins are purged approximately 90 days after the token expires or is revoked, unless the workspace is under legal hold.
  • Account export packages: Generated export JSON objects in the private exports storage bucket are available via a signed URL for 7 days; objects are purged by lifecycle or cleanup within 30 days.
  • Backups: Infrastructure backups may retain residual copies for a limited period (typically up to 30 days) after primary deletion.

6. Your Rights

Depending on your jurisdiction, you may have rights to:

  • Access your personal data
  • Correct inaccurate data — update profile fields via Settings self-serve; other corrections via a tracked request in Settings → Account or privacy@selexts.com
  • Request deletion of your account access, profile identifiers, and workspace memberships (this does not automatically purge media or other content that remains in shared workspaces)
  • Export your data in machine-readable format
  • Object to processing via Settings → Account (tracked request) or privacy@selexts.com
  • Withdraw analytics consent where analytics processing relies on consent

To exercise these rights, visit Settings → Account or contact privacy@selexts.com. Unauthenticated subjects may email privacy@selexts.com; we target a 30-day response SLA. Where requests are complex or numerous, we may extend the response window by up to an additional 60 days and will notify you of the extension within the initial 30-day window.

7. Do Not Sell or Share

We do not sell personal data. We do not share personal data for cross-context behavioral advertising. California residents may use Cookie preferences (Settings → Account), the cookie banner controls, or email privacy@selexts.com to opt out of optional analytics. We honor browser Global Privacy Control (GPC) signals by treating them as a denial of analytics consent when no prior choice is stored.

8. Third-Party Links

The service may contain links to third-party sites (e.g., billing portal). We are not responsible for their privacy practices.

9. Changes to This Policy

We will notify users of material changes via email or in-app notification. Continued use after changes constitutes acceptance.

10. Contact

For privacy inquiries: privacy@selexts.com