Privacy Policy

v3.1 · August 19, 2026

Your script is not used to train AI models

What you write in Telos — projects, characters, scenes, authorial voice, comments — is yours, and stays yours. We do not use your material to train models of our own, and we do not pass it to third parties for them to train theirs. The provider Telos calls (Anthropic, Claude models) undertakes not to train its models on content sent through the API, under its published commercial terms.

Under the API’s published retention policy, content sent is deleted within 30 days — subject to the exceptions Anthropic itself states: a submission flagged by its automated trust and safety systems may be retained for up to 2 years, and the classification score for up to 7 years; retention may be longer to comply with the law or enforce its Usage Policy. Telos holds no zero-retention (ZDR) agreement with Anthropic; that arrangement is approved by Anthropic on a case-by-case basis.

You can export everything you created in Telos at any time, as structured JSON, or delete your account — irreversible after a 30-day recovery window.

This policy describes what personal data Telos processes, for what purpose and on what legal basis, with whom it is shared, how long it is kept, and how you exercise your rights. The LGPD (Law 13.709/2018), the GDPR (Regulation (EU) 2016/679) and applicable U.S. state privacy laws (CCPA/CPRA and equivalents) apply.

1. Who the controller is

Telos is operated by Oger Sepol Produção e Comércio Audiovisual Ltda., a company incorporated in Brazil under registration (CNPJ) no. 07.567.854/0001-01, with establishment at R. Saint-Hilaire, 380, apto. 102 — Água Verde — Curitiba/PR — CEP 80.240-140 — Brasil. The company is the controller of the personal data processed in the product (GDPR art. 4(7) / LGPD art. 5, VI).

Data Protection Officer: privacidade@telos.guru. You may lodge a complaint with the ANPD (Brazil) or, if you are in the European Union, with the supervisory authority of your country of residence.

2. What data we collect

Waiting list (before an account exists):

  • E-mail — what lets us tell you when access opens
  • The language of the page where you signed up, so the invitation arrives in your language
  • Truncated IP address (e.g. 200.158.xxx.xxx) and browser, only to tell a person from a bot and to see where sign-ups come from
  • Whether and when you were invited, and whether you asked to leave the list

Access to Telos is by invitation: joining the list is the first and, for a while, the only data we hold about you. The invitation we send stores the same e-mail, an expiry date and a record of use — never the link itself, which exists only in the message you receive.

Account and authentication:

  • Name and e-mail (required)
  • Tax registration (CNPJ, VAT, EIN or equivalent) — only if you declare that you are contracting on behalf of a legal entity. That number determines which of the two tracks of the Terms governs the contract; without it, the consumer track applies. We do not collect an individual taxpayer number (CPF); the field rejects one.
  • Password, stored as a bcrypt hash — never in plain text

Authorial content:

  • Projects, characters, scenes, hooks, comments, analyses and compiled authorial voice — everything you write or generate with AI inside Telos.
  • Project versions and branches, with change history preserved for authorship auditing.

Usage and billing:

  • Credit usage history (operation, date and cost), processed for fraud prevention and support.
  • Payment data is processed directly by Stripe. Telos receives only the Stripe customer identifier and subscription status; we do not store card numbers.

Technical:

  • Application access records — date, time and source IP, kept for six months under confidentiality and in a controlled environment, under art. 15 of Law 12.965/2014 (Brazilian Internet Civil Framework). Legal basis: compliance with a legal obligation (LGPD art. 7, II). After that period, the record is deleted.
  • In the product’s other records (account auditing), the IPv4 address is truncated at write time — the last two octets are discarded and cannot be reconstructed. IPv6 addresses are truncated equivalently, keeping only the prefix.
  • User-agent (browser and operating system), processed for error diagnosis and compatibility checks.
  • Cookies and browser local storage — the full list, with the purpose of each, is in section 11.

What is required, and what happens if you do not provide it. Name, e-mail and an access credential are a contractual requirement: without them the account cannot be created and we cannot perform the contract. Access records are imposed by law and do not depend on your choice. Tax registration is optional, and not providing it means the consumer track of the Terms governs your contract (GDPR art. 13(2)(e) / LGPD art. 18, VIII).

3. Why we collect it (legal bases)

  • Performance of a contract (LGPD art. 7, V / GDPR art. 6(1)(b)): without an account there is no way to deliver the tool you subscribed to.
  • Compliance with a legal obligation (LGPD art. 7, II / GDPR art. 6(1)(c)): tax records, retention of access logs, and responses to lawful requests from public authorities.
  • Legitimate interests (LGPD art. 7, IX / GDPR art. 6(1)(f)): fraud prevention, platform security, and product usage measurement — the latter from events carrying a pseudonymous identifier and no authorial content, to establish which features are used and where in the writing flow use stops. You may object at any time, through the control in section 11.
  • Consent (LGPD art. 7, I / GDPR art. 6(1)(a)): marketing communications and, in the European Union, the United Kingdom and Switzerland, usage metrics. Consent may be withdrawn at any time, and withdrawal does not affect the lawfulness of processing carried out before it (GDPR art. 13(2)(c)).

4. Who we share with

Only with the processors strictly necessary for the service to work. Each processes data under its own published data-processing terms, which bind whoever contracts its service — and those terms are what we are subject to as a customer. Some of those terms are incorporated automatically into each service’s agreement; others require a separately signed instrument. For the status of a specific processor, write to privacidade@telos.guru.

  • Anthropic PBC (Claude API, USA): processes prompts and returns responses, on the terms described in the highlight above.
  • Stripe Payments Inc. (USA): processes charges. Telos receives only the customer identifier and subscription status; the card number stays entirely within Stripe’s domain.
  • Vercel Inc.(USA): web application hosting. The functions that run the product execute in the default region of our Vercel account; Vercel’s delivery network serves static files from points of presence in several countries, with no authorial content.
  • Neon, LLC, a subsidiary of Databricks, Inc. (USA, AWS US East region): managed Postgres database, running on Amazon Web Services infrastructure. AES-256 encryption at rest and TLS in transit.
  • Upstash Inc. (USA): used for two distinct purposes. For abuse control, the counting keys leave us hashed: your account identifier, the request’s IP address and the e-mail entered in the password-reset flow are converted into an irreversible code before being sent, and expire with the rate-limit window. For caching, we keep already-computed analysis results for a few minutes — the key identifies the project, and the value may contain material derived from your work, such as diagnostics and quoted evidence.
  • PostHog Inc. (USA, US Cloud): product usage measurement. See section 5.
  • Functional Software, Inc. (Sentry) (USA): error monitoring, with personal-data scrubbing enabled on both client and server.
  • Resend, Inc.(USA): delivery of the product’s transactional e-mail (order confirmation, password reset, account notices). It receives your e-mail address and the message content.
  • Cloudflare, Inc. (USA): authoritative DNS for the domain and routing of inbound e-mail. If you write to an @telos.guru address, the message passes through it before reaching our mailbox.
  • OpenAI, L.L.C. (USA): two functions, and both receive material of yours. Semantic search turns your scene text into numerical representations, so the AI can find the relevant scene instead of re-reading the whole project. And voice transcription in the Creation Room receives the audio you record and returns text — what travels there is your recording.

Requests from authorities. We disclose data to third parties only under a court order or a lawful request from a competent authority, within the limits the law authorises.

Who answers for what. We determine the purposes and means of the processing, and it is us you hold accountable. The processors above handle your data on our behalf and on our instructions, within the limits of what we contracted, and may not use it for their own purposes (LGPD art. 9, VI).

International transfer mechanisms are set out in section 9.

5. Usage metrics (PostHog)

We collect usage events to establish which features are used and at what point in the writing flow use stops. Collection is done through PostHog, on the following terms:

  • Identifier: your account’s internal code, random and meaningless outside Telos. It is pseudonymous, not anonymous — because it is linked to your account it remains personal data, and every right in section 7 applies to it. We do not send your e-mail, your name or any text from your work.
  • Events: project creation, scene writing, acceptance or rejection of an AI suggestion, credit consumption and payment. Metadata only — date, time, identifiers, format and amounts — never scene text.
  • IP address: used to derive the approximate country and region of the visit, then discarded — PostHog is configured not to store the address. What remains is the derived location and the event, not the IP.
  • Cohort: sign-up week, for aggregate retention analysis.
  • Off by default: autocapture of clicks, session recording, form-field capture, and cross-site tracking cookies.
  • GPC and DNT, and how far the signal reaches: browsers sending Global Privacy Control or Do Not Track turn collection off — both the events from the browser and those our server records during your use. Events originating outside a visit of yours (the payment confirmation Stripe sends us, for example) carry no signal from your browser, and the signal does not apply to them. To reach those events as well, use the e-mail request described below.
  • Prior consent in the European Union, the United Kingdom and Switzerland: in those territories nothing is collected until you allow it. In other countries collection starts on and you switch it off whenever you want.

To switch usage metrics off, choose Do not allow in the footer notice, or use the control in section 11 at any time — both take effect immediately, in this browser. To record your objection in writing, or to reach the events that originate outside your browser, write to privacidade@telos.guru (LGPD art. 18, § 2 — objection to processing carried out on a basis that dispenses with consent; GDPR art. 21(1)).

6. How long we keep it

  • Account and authentication (name, e-mail, password hash, tax registration): for as long as the account exists and for 30 days after a deletion request, after which it is erased — except what the tax obligation below requires us to keep.
  • Waiting list and invitations: 12 months from sign-up, after which they are erased automatically, whether or not they became an account. If you asked to leave the list, we keep only your e-mail and the date of that request, for an indefinite period — that is what stops a new sign-up, or a batch send, from bringing you back against your wishes. Deleting your account also takes you off the list.
  • Authorial content: while your account is active. After a deletion request, a 30-day recovery window and then irreversible erasure.
  • Tax and billing data: 5 years after the end of the contract, under Brazilian tax law. Survives account deletion.
  • Access records (date, time and IP): six months, as a legal obligation (art. 15 of Law 12.965/2014). Then deleted.
  • Account audit records: kept with the IP already truncated. They survive account deletion with the link to the user severed, because they document operations that must remain verifiable.
  • Backup copies: up to 30 days. They are encrypted before leaving our systems and replaced on the following cycle. Data erased from the live database remains in that day’s copy until it expires — that is the safety net against accidental loss, and it is why the definitive erasure period in section 7 counts those 30 days on top of the recovery window.
  • PostHog usage events: for PostHog’s standard retention period for our account. Withdrawing consent stops collection; to erase history already sent, use the contact in section 5.
  • Technical logs: for the standard periods of the providers that host them (Vercel, for execution logs; Sentry, for error reports). We set no period of our own and do not control those periods.

7. Your rights

This section sets out the rights granted to you by art. 18 of Law 13.709/2018 (LGPD) and arts. 15 to 22 of Regulation (EU) 2016/679 (GDPR). Exercising them is free of charge and requires no justification.

  • Confirm whether we process data about you and obtain access to it, including by exporting everything as structured JSON (LGPD art. 18, I and II; GDPR arts. 15 and 20).
  • Rectify incomplete, inaccurate or out-of-date data.
  • Delete your account. After a 30-day recovery window we erase your authorial content and account data from the live systems. The backup copies from those days expire on their own retention cycle, within up to 30 further days — after that the erasure is irreversible. Only the following remain: tax data, for the 5 years of the tax obligation; audit records, with the link to the user severed; and access records, for the six months that art. 15 of Law 12.965/2014 imposes on the provider — deleted once that period ends. All as described in section 6.
  • Request restriction of processing, or the blocking, anonymisation or erasure of data that is unnecessary, excessive, or processed in breach of the law (LGPD art. 18, IV; GDPR art. 18).
  • Object to processing carried out on the basis of legitimate interests, stating your reason (LGPD art. 18, § 2; GDPR art. 21).
  • Know which public and private entities we share your data with — section 4 carries the full list (LGPD art. 18, VII).
  • Withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
  • Lodge a complaint with the ANPD (Brazil) or with the supervisory authority of your country of residence (EU).

Direct marketing. You may object at any time, and without giving a reason, to the use of your data for direct marketing. Once you object, we stop that use immediately. Use the unsubscribe link in any promotional e-mail, or write to privacidade@telos.guru (GDPR art. 21(2) and (3)).

If you reside in California or another U.S. state with a privacy law, see section 8 — there are additional rights and a specific response deadline.

8. Your U.S. privacy rights (CCPA/CPRA and other states)

If you are a resident of California or another U.S. state with a consumer privacy law, you have the right to know what personal data we collect and why, to access and correct that data, to request its deletion, to portability, and to opt out of the "sale" or "sharing" of your personal data.

We do not sell your personal data and we do not share it for cross-context behavioral advertising. Our usage analytics is first-party and is not used for ad targeting. We honour the Global Privacy Control (GPC) signal as a valid opt-out request.

We use any sensitive information only to provide the service you request and never to infer characteristics about you. We will not discriminate against you for exercising these rights. To make a request, contact privacidade@telos.guru; you may use an authorised agent. We respond within 45 days, extendable once. California residents may also request the disclosures under California Civil Code § 1798.83 ("Shine the Light").

Residents of other U.S. states with equivalent laws — including Virginia, Colorado, Connecticut, Texas and Oregon — have equivalent rights and may contact us in the same way.

9. International data transfers

Our infrastructure and processors are located in the United States. There is no European Commission adequacy decision for Brazil or for the United States generally; for the U.S. there is only the partial adequacy of the EU–US Data Privacy Framework, which covers certified entities alone.

The mechanism applicable to each processor is as follows:

  • Stripe, Upstash, PostHog and Sentry (Functional Software) — certified and active under the EU–US Data Privacy Framework; each one’s agreement adopts the Framework as the primary mechanism and the Standard Contractual Clauses as a fallback.
  • Anthropic— not certified under the Framework; the transfer is governed by the European Commission’s Standard Contractual Clauses (Decision 2021/914, Modules 2 and 3) in its data processing addendum.
  • Vercel — certified under the Framework, but its data processing addendum governs the transfer through the Standard Contractual Clauses; those are what we rely on.
  • Neon / Databricks— the transfer is governed by the Standard Contractual Clauses in Databricks’ data processing addendum.
  • OpenAI — not certified under the Framework; the transfer is governed by the Standard Contractual Clauses in its data processing addendum.

For transfers out of Brazil, the basis is LGPD art. 33, II, (a) — transfer-specific contractual clauses, in the processing agreements entered into with each processor — and, for payment processing, performance of a contract at the data subject’s request (art. 33, IX). We have not entered into the standard clauses of Annex II of ANPD Resolution CD/ANPD no. 19/2024 with our processors: those require adoption in full and unaltered, agreed with each importer, and none of our processors offers them in its standard agreement.

The safeguards are the standard clauses in each processor’s data processing addendum, published by them and available at any time (GDPR art. 13(1)(f)): Anthropic, Stripe, Vercel, Neon/Databricks, Upstash, PostHog, Sentry Resend and OpenAI.

10. Security

  • HTTPS required, with two-year HSTS including subdomains.
  • Passwords stored with bcrypt, cost factor 12.
  • Database encrypted at rest (AES-256).
  • Access to personal data restricted and recorded in an audit log.
  • In the event of a security incident that may result in relevant risk or damage, we notify the ANPD and, where applicable, the competent supervisory authority in the European Union, within the statutory deadlines, and inform affected data subjects without undue delay.

Found a security flaw? Write to privacidade@telos.guru. We take no legal action against anyone who researches in good faith and tells us before disclosing.

11. Cookies and local storage

Strictly necessary (always on, not subject to choice): the authentication session and CSRF protection written by NextAuth (next-auth.session-token, next-auth.csrf-token and next-auth.callback-url, with the __Secure- or __Host- prefix over HTTPS); the temporary cookies that protect external-provider sign-in against interception (next-auth.state and next-auth.pkce.code_verifier, deleted as soon as sign-in completes); the record of your acceptance of the Terms in transit during that sign-in (telos-aceite-pendente, valid for 10 minutes); the language preference (telos-locale); and the record of your choice in this section (telos-consent and telos-consent-regime).

We keep interface preferences in the browser’s local storage rather than in a cookie: distraction-free writing mode, the list of most recently opened items, and the data you type into long forms so it is not lost on reload. That storage is strictly necessary to provide the service you request, under the second exception in art. 5(3) of Directive 2002/58/EC, and is not transmitted to our servers.

Usage metrics (subject to your choice): when you allow it, PostHog writes its own first-party cookies (ph_*) to distinguish sessions. They hold a random identifier — not your name, e-mail or any text from your work. See section 5.

We do not use advertising cookies, cross-site tracking cookies, or social network pixels.

How you choose: in the European Union, the United Kingdom and Switzerland no usage metric is collected before you allow it. In other countries collection starts on. The footer notice asks once; after that, the control below turns it on and off whenever you want, for this browser. In every case, your browser’s Global Privacy Control and Do Not Track signals turn collection off on their own and prevail over any choice recorded here. Clearing site data in your browser removes all of these cookies, and the choice is asked again.

Métricas de uso estão desligadas neste navegador.

12. Children and adolescents

Telos is a professional tool and is not directed at children. You must be at least 18 to create an account. We do not knowingly collect personal data from children under 13 (USA, COPPA) or below the applicable digital consent age in the EU (16, unless a Member State sets a lower age). In Brazil, processing data of children (under 12) requires specific and prominent consent from a legal guardian, and processing data of adolescents follows their best interest. If we identify an account held by a minor without qualified guardian consent, we remove the account and the data.

13. Changes to this policy and corporate succession

Each version of this policy carries a number and an effective date. Substantial changes are announced on this page before they take effect, and you may object to the change and close your account at no cost until the effective date.

In a merger, acquisition, corporate reorganisation or sale of assets, personal data may be transferred to the successor, which is bound by this policy until it replaces it. In that case you are notified by reasonable advance notice and may, within that period, export your content and close your account at no cost. If operations cease, we give the same notice so that you can export your content before erasure.

Contact and DPO

Questions, requests or complaints: privacidade@telos.guru. Requests to confirm processing and for access are answered within 15 days of the request (LGPD art. 19, II). Other requests are answered without undue delay and within one month at the latest (GDPR art. 12(3)). Requests from U.S. residents are answered within 45 days (CCPA/CPRA). Handling is free of charge; we charge a reasonable fee, or refuse the request, only where it is manifestly unfounded or excessive, in particular because of its repetitive character, and the burden of demonstrating that is on us (GDPR art. 12(5); LGPD art. 18, § 5).