Privacy Policy
How Sundream collects, uses, shares, and protects account, project, and creative-production data.
Last updated: August 11, 2026
Who we are and the roles we have
Sundream is a service operated by Smith & Johnson, Inc., a Delaware corporation. You can reach us at support@sundream.studio or by post at Smith & Johnson, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
This Privacy Policy explains how Sundream collects and uses personal information when you visit our website, create an account, join a team workspace, upload creative materials, generate AI media, or contact us for support.
Smith & Johnson, Inc. is the controller for personal information we use for our own purposes, including account administration, billing, security, support, service analytics, and legal compliance. When a business or other customer puts personal data into a workspace and directs us to process it through the service, that customer is the controller and Smith & Johnson, Inc. acts as its processor or service provider. Our Data Processing Addendum governs that customer-directed processing where applicable.
Information we collect
- Account information, such as your email address, username, authentication identifiers, team membership, and account settings.
- Creative workspace content, such as scripts, prompts, shot descriptions, cast details, reference media, uploaded files, generated outputs, and project history.
- Voice data, such as recorded or uploaded voice samples, cloned or designed voice profiles, provider voice identifiers, preview audio, consent or permission confirmations, and provenance metadata. Depending on the processing and applicable law, voice data may be treated as biometric or sensitive personal information.
- Usage and device information, such as log data, browser type, pages viewed, feature activity, approximate location from IP address, and diagnostic events.
- Billing and commercial information, such as plan selection, invoices, payment status, credit transactions, tax information, and limited payment metadata from our payment processor. We do not store full payment card numbers.
- Assistant conversations: when you chat with the Sundream assistant, we store the conversation — your messages, the assistant's replies, and the actions it performed — linked to your account and workspace.
- Support communications, including messages, attachments, and information needed to resolve requests.
Where information comes from
We collect information directly from you; from workspace owners, administrators, and collaborators; automatically from your browser, device, and use of Sundream; and from service providers such as authentication, payment, analytics, security, and AI providers. Workspace content may contain information about people who do not have Sundream accounts. The customer or user who submits that content is responsible for providing any required notice and having an appropriate legal basis or permission.
How and why we use information
- Provide, secure, troubleshoot, maintain, and improve Sundream.
- Authenticate users, maintain sessions, manage team workspaces, and preserve project state.
- Send prompts, references, and related project context to AI, storage, hosting, database, authentication, and infrastructure providers as needed to operate requested features.
- Create and store generated media, including cloning a voice from a sample when an authorized user requests it, synthesizing speech, and preserving the sample and provider identifiers needed to reuse or rebuild the voice.
- Communicate about product updates, account issues, security notices, and support requests.
- Analyze product reliability and usage patterns — including reviewing stored assistant conversations — so we can improve workflows, assistant quality, and performance.
- Detect, investigate, and prevent fraud, security incidents, prohibited content, rights violations, and other abuse; enforce our Terms and AI Safety Policy; and protect users, Sundream, and the public.
- Comply with law, respond to lawful requests, establish or defend legal claims, and keep required business records.
Legal bases for processing
Where the GDPR, UK GDPR, or a comparable law requires a legal basis, we rely on the bases below. The basis depends on the information and why we use it.
- Contract: to create and administer your account, provide workspace and generation features you request, process payments, and deliver support connected to the service.
- Legitimate interests: to secure and operate Sundream, prevent fraud and abuse, diagnose failures, understand service performance, improve product reliability, and establish or defend claims, where those interests are not overridden by your rights.
- Consent: where required for analytics or session replay, marketing communications, or particular uses of voice or other sensitive data. You may withdraw consent prospectively at any time, although another legal basis may still apply to necessary processing.
- Legal obligation: to comply with tax, accounting, sanctions, law-enforcement, regulatory, and other obligations that apply to us.
AI processing, voice cloning, and model training
When you request generation, analysis, speech, or voice cloning, Sundream transmits the prompts, scripts, references, voice samples, generated media, and project context needed for that request to the AI provider identified on our Subprocessors page.
We do not use private customer workspace content, assistant conversations, or voice samples to train Sundream-owned foundation models or authorize our AI subprocessors to train general-purpose models on that content, unless the affected customer expressly opts in or we enter a separate written agreement that says otherwise. Providers may retain submitted data for the limited service-operation, security, and abuse-monitoring periods described by their applicable business or API terms.
You may clone a voice only if it is your voice or you have valid permission and any legally required consent from the person whose voice it is. A confirmation in the product records the user's representation of permission; it does not transfer another person's rights or replace notice or consent required by law.
How we share information
We publish the third-party services that process customer data on our behalf, what each handles, and where, on our Subprocessors page.
- Service providers and subprocessors that help us run hosting, storage, databases, authentication, analytics, billing, support, security, AI generation, speech synthesis, and voice cloning.
- Workspace members on your team, according to your role, permissions, and project-sharing choices.
- Professional advisors, regulators, law enforcement, or courts when legally required or necessary to protect rights, safety, and security.
- Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.
Cookies and similar technologies
We use necessary cookies and local browser storage to keep you signed in, remember workspace preferences, route you to the right team, record legal and analytics choices, and secure the application.
With your consent where required, PostHog provides product analytics, error monitoring, and session replay. Session replay can capture how you move through and interact with the interface. We mask form-input values, but other text rendered in the interface may appear in a replay. Without analytics consent, we limit collection to error diagnostics without a persistent analytics identifier. You can withdraw analytics consent prospectively by clearing the Sundream site data in your browser or contacting us.
Sundream does not currently use advertising cookies on the landing page. If we add advertising, retargeting, or cross-context behavioral advertising technologies, we will update this policy and provide legally required choices.
Retention and deletion
Account, workspace, project, assistant-conversation, uploaded-media, generated-media, voice-sample, and cloned-voice records are kept while the relevant account or workspace is active and until the user or authorized workspace owner deletes them, subject to the account-erasure process below. A provider may keep a voice identifier or request data for its limited operational retention period; our Subprocessors page identifies the provider.
Security, fraud, generation, and diagnostic logs are kept on a rolling basis for the shortest period reasonably needed to investigate reliability, billing, safety, and security events. A record connected to an incident, dispute, or legal obligation may be kept until that matter and the applicable limitation period end.
Support communications are kept while a request is open and afterwards for continuity and dispute resolution. Contract, consent, and Terms-acceptance records are kept for the account term and the period reasonably needed to establish the parties' agreement. Stripe retains invoices and transaction records for tax, accounting, fraud-prevention, and payment-network requirements.
You can delete your account yourself from Settings. Deleting cancels your subscription immediately and schedules erasure 30 days later; during that window you can cancel the request and keep your account. The delay exists so a mistaken or unauthorised deletion can be undone. Closing your account instead deactivates it and retains your content.
When the erasure runs we permanently delete your account record, workspaces you solely own, projects, uploaded references, voice samples, cloned-voice records, and generated media, including the underlying files in active storage. It cannot be reversed afterwards. Residual backup copies are isolated from ordinary use and overwritten on their normal rotation.
Limited records may survive erasure where law requires retention or where reasonably necessary to prevent fraud, document consent or a contract, resolve a dispute, enforce our agreements, or protect legal rights. We restrict those records to those purposes and delete or de-identify them when the reason for keeping them ends.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including authentication, access controls, transport security, logging, and vendor review. No online service can guarantee perfect security, so you should protect your credentials and promptly report suspected account compromise.
Your privacy choices and rights
- You may access, update, export, or delete certain account and workspace information through the product where available.
- You may request access, correction, deletion, portability, restriction, or objection by emailing support@sundream.studio. You may use an authorized agent where applicable; we may ask for proof of authority and may verify your identity before acting.
- You may opt out of marketing emails by using unsubscribe links or contacting us.
- Depending on your location, including California, Colorado, Connecticut, Virginia, Utah, the EEA, the UK, and other jurisdictions, you may have additional rights to know categories and sources, withdraw consent, limit certain uses of sensitive information, opt out of targeted advertising or profiling, or appeal a denied request. To appeal, reply to our decision or email us with the subject “Privacy appeal.” We will not discriminate against you for exercising applicable rights.
- You may complain to the data-protection regulator where you live or work. EEA and UK residents may also contact their competent supervisory authority.
- Sundream does not sell personal information or share it for cross-context behavioral advertising as those terms are defined by California law, and did not do so during the preceding 12 months. We do not use personal information for targeted advertising. If that changes, we will update this policy before the new processing starts and provide legally required opt-out controls, including support for applicable browser preference signals.
Children
Sundream is not directed to children. You must be old enough to create a binding account under our Terms of Service, and at least 18 unless a separate agreement allows otherwise. We do not knowingly collect personal information from children.
International transfers
We process information in the United States and in other countries where our service providers operate. Those countries may have privacy laws different from the laws where you live.
For restricted transfers from the EEA, we use the European Commission Standard Contractual Clauses, normally Module Two for customer-controlled workspace data. For UK transfers, we use the UK International Data Transfer Addendum. Our Data Processing Addendum incorporates those safeguards and our Subprocessors page identifies relevant locations. Contact us to request a copy, subject to necessary redactions.
Changes to this policy
We may update this Privacy Policy as the service, providers, and law change. We will update the date above and give notice through the service or by email when a change materially affects how we use personal information or your rights. Where consent is required for a new use, we will request it before that use begins.
Contact
Questions or requests about this Privacy Policy can be sent to support@sundream.studio, or by post to Smith & Johnson, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States. We may need to verify your identity before completing certain requests.