Privacy Policy for SoraToo
Effective date: September 10, 2025
Thank you for trusting SoraToo ("we", "us", or "our") with your collaborative video projects. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit soratoo.com or use any product, feature, or service offered through our Sora 2 text-to-video workspace (the "Service").
Our experience centers on prompt-based storyboarding, shared timelines, render queue automation, and delivery-ready exports. The data practices described below enable those capabilities while honoring your privacy choices.
1. Information We Collect
We collect the categories of information outlined below. Examples are illustrative rather than exhaustive.
1.1 Account and Contact Details
- What we collect: Name, email address, authentication credentials, profile photo, social or single sign-on identifiers.
- How we use it: Create and secure your workspace, send transactional notices, respond to support requests, and let you manage team settings or billing preferences.
1.2 Creative Inputs and Project Data
- What we collect: Prompt text, storyboard notes, uploaded reference imagery or video clips, generated previews, review comments, scene metadata, and render settings.
- How we use it: Process Sora 2 render jobs, provide version history, power collaborative feedback, and help you resume in-progress projects across devices.
1.3 Usage Analytics
- What we collect: Feature interactions (e.g., “Queue Render”, “Share Timeline”), clickstream events, timestamps, referring URLs, and aggregated telemetry.
- How we use it: Measure onboarding effectiveness, maintain render performance, detect misuse, and guide product improvements.
1.4 Device and Technical Data
- What we collect: Browser type, language preference, operating system, device identifiers, screen resolution, IP-derived region.
- How we use it: Optimize playback, deliver the correct locale and interface, and protect the Service against fraud or abuse.
1.5 Payment Information
- What we collect: Billing name, address, VAT or tax numbers, limited payment card details, transaction metadata. Full card numbers are processed by PCI-compliant payment providers and never stored on our servers.
- How we use it: Process purchases, manage invoices, and provide receipts or usage statements.
1.6 Cookies and Similar Technologies
- What we collect: Session cookies, analytics tags, authentication tokens, A/B testing identifiers, and other browser storage data.
- How we use it: Keep you signed in, remember preferences (such as locale and theme), run product experiments, and understand aggregate traffic patterns. You can control cookies via your browser settings; disabling them may limit certain features.
2. How We Share Information
We do not sell your personal information. We share data only in the situations below:
- Service Providers: Hosting, storage, analytics, payment processing, customer support, and infrastructure partners bound by confidentiality obligations and permitted to use data solely on our behalf.
- Collaboration Features: When you invite collaborators or share a review link, relevant project data becomes visible to the recipients you authorize.
- Legal Requirements: When required by law, subpoena, or governmental request, or to defend our legal rights, detect fraud, or ensure platform integrity.
- Business Transfers: If we engage in a merger, acquisition, or asset sale, your information may be transferred subject to this Policy and any successor safeguards.
3. How We Protect Information
- Data minimization: We collect only what is necessary to operate SoraToo and support your experience.
- Security controls: Encryption in transit, role-based access, audit logging, and infrastructure monitoring protect stored data.
- Retention: Project assets and account data remain until you delete them or request removal. Backups are purged on a rolling schedule consistent with business continuity needs.
- Your responsibilities: Choose strong passwords, keep access tokens secret, and promptly notify us if you suspect unauthorized activity.
4. Your Rights and Choices
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, as well as object to or restrict certain processing activities. To exercise these rights, contact us at support@soratoo.com. We may ask you to verify your identity before fulfilling a request.
If you reside in the European Economic Area, United Kingdom, or Switzerland, our legal basis for processing personal data typically includes performance of a contract, legitimate interests (such as securing and improving the Service), or consent for optional features like marketing communications.
5. International Transfers
We operate globally using cloud infrastructure. When data moves outside your home jurisdiction, we rely on approved safeguards—such as Standard Contractual Clauses or equivalent lawful transfer mechanisms—to protect your information.
6. Children's Privacy
SoraToo is not directed to individuals under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided data, please contact us so we can delete it.
7. Changes to This Policy
We may revise this Privacy Policy to reflect operational, legal, or regulatory changes. The updated version will be posted at soratoo.com/privacy-policy with a revised effective date. Material updates will be communicated through the product or via email when appropriate.
8. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our data practices, reach out any time:
- Brand: SoraToo
- Website: soratoo.com
- Email: support@soratoo.com
We appreciate your trust in SoraToo and remain committed to protecting the creative work you produce with Sora 2 video generation.