Privacy Policy — TAHA STUDIO AI ScriptForge
Last updated: July 22, 2026
Website: tahastudiolabs.com
This Privacy Policy explains what information TAHA STUDIO AI ScriptForge ("ScriptForge," "we," "us") collects, how it is used, and the choices available to you.
1. Our Data Minimization Commitment
ScriptForge is built to collect and retain as little personal data as possible. In particular:
- We do not store your scripts, generated segments, or any content you create in the tool. All saved content ("Save to Library") is stored only in your own browser, on your own device, and is never transmitted to us for storage. Your script text is relayed through our server for the single moment it takes to call Anthropic's API on your behalf (see below) — it is never written to a database, file, or log.
- We do not store your Anthropic, Google Gemini, or Groq API key. ScriptForge's "Format" feature works with any of three providers — Anthropic Claude, Google Gemini, or Groq — so you can use whichever you have a key for, including Gemini's and Groq's free tiers if you'd rather not pay for one. Whichever you choose, you provide your own API key, and to make the feature work reliably for every visitor — including those whose browser, antivirus, or network would otherwise block a direct browser-to-provider request — your key is relayed through our server to that provider's API for that single request only. It is held in server memory just long enough to make that one call, is never written to a database, file, or log, and is discarded immediately after the response is returned.
- We do not store your Google, xAI, or HeyGen API keys. The optional video generation feature works the same way: if you choose to generate a video clip from a formatted segment, your own Veo, Grok Imagine, or HeyGen API key and the segment's visual prompt are relayed through our server to that provider's API for that single request only, held in memory just long enough to make the call, and discarded immediately after — never written to a database, file, or log.
- We do not store your ElevenLabs API key. The optional Voice ID picker works the same way: if you connect your ElevenLabs account to browse your voices, your API key is relayed through our server to ElevenLabs' API for that single request only, held in memory just long enough to fetch your voice list, and discarded immediately after. ScriptForge does not use ElevenLabs to generate audio — it only fetches your voice list so you can select a Voice ID, which is written into your own script output for you to use downstream.
2. Information We Do Collect
To provide and secure your account and license, we collect:
| Data |
Purpose |
| Email address |
Account identification, login, communication about your purchase/subscription |
| Authentication credential (securely hashed) |
Logging you into your account |
| Subscription/license status |
Determining which features you're entitled to use |
| Transaction/license redemption record |
Preventing misuse of a single license across multiple users |
We do not collect payment card details directly — these are handled by our payment processor under their own security and compliance standards (see §5).
3. Information We Do Not Store
- Script content, prompts, or generated video segments — not written to any database, file, or log
- Your Anthropic, Google Gemini, or Groq API key — not written to any database, file, or log; held in server memory only for the moment it takes to relay a single "Format" request to whichever provider you chose (§1)
- Your Google, xAI, or HeyGen API keys — not written to any database, file, or log; held in server memory only for the moment it takes to relay a single video generation or download request (§1)
- Your ElevenLabs API key — not written to any database, file, or log; held in server memory only for the moment it takes to relay a single voice-list request (§1)
- Individual browsing behavior or content-based analytics (we do not track what you do on the site beyond an anonymized aggregate visit count — see §3a)
- Any data beyond what's listed in §2, unless you separately provide it (e.g. contacting support)
3a. Anonymized Visit Counting
To understand how many people visit our site, we record a one-way, salted cryptographic hash of your IP address (never the IP address itself), together with a first-seen date, last-seen date, and a running visit count. This is aggregate-only data: the hash cannot be reversed back to an IP address, and it is never linked to your account, email address, or any script or content you create. Only the site owner can view the resulting totals (unique visitor count and total visits); no individual visitor record is ever displayed or exported.
4. Where Your Content Lives
Your saved library ("Save to Library") is stored using your browser's local storage on your own device. This means:
- We have no copy of it and cannot recover it if you clear your browser data, switch browsers, or switch devices.
- You can export your library to a file for your own backup, and import it later, using the export/import feature in the app.
- Because this data never reaches us, it is not part of any account deletion process — it is entirely within your control at all times.
5. Third Parties We Use
We rely on a small number of third-party services to operate ScriptForge, each of which processes limited data on our behalf:
- Authentication provider — manages secure login and session handling.
- Payment provider (Merchant of Record) — handles checkout, billing, tax compliance, and license key issuance.
We do not sell or share your data with advertisers or data brokers.
6. Cookies
We use only strictly necessary cookies required for login sessions to function. We do not use tracking or advertising cookies. If this changes in the future, we will update this policy and request your consent before any such cookies are set.
7. Your Rights
Depending on your location, you may have the right to:
- Request a copy of the personal data we hold about you (limited to the items in §2)
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Withdraw consent or object to processing, where applicable
To exercise any of these rights, contact us at [SUPPORT EMAIL]. Because we hold very little data about you, most requests can be fulfilled quickly.
8. Data Retention
We retain your account, authentication, and subscription data for as long as your account is active. If you request account deletion, we will remove your email, credentials, and subscription records within [30] days, except where our payment provider is required to retain transaction records for tax or legal purposes independently of us.
9. Security
We use industry-standard practices to protect the limited data we hold, including encrypted connections (HTTPS), secure credential storage, and restricted internal access. No system is perfectly secure, but our architecture is deliberately designed so that even in the event of a breach, no script content or API keys could be exposed from storage, since we never write them to a database, file, or log — the only point at which either value exists on our servers is in memory, in transit, for the single "Format" request that uses it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected with an updated "Last updated" date at the top of this page.
11. Contact
Questions about this policy or your data can be sent to: [SUPPORT EMAIL]