Legal
Privacy Policy
Last Updated: July 28, 2026
1. What We Collect
Awundra collects only the data necessary to operate the platform:
- Account data: Email address and username, collected when you create an account. If you sign up or sign in with Google, we also receive basic profile information from your Google account: your email address, name, and profile picture.
- Profile data: Optional fields you choose to provide, display name, bio, country, primary role, social links, and avatar. This information is shown publicly on your creator profile page at
awundra.com/u/<username>so other visitors can see who made the films. - Uploaded images: Profile pictures and film thumbnails you upload are stored as files in Awundra's Supabase storage (see Section 4) and are served from public addresses. A profile picture appears on your public creator profile; a thumbnail appears wherever its film is shown. Anyone who has the file address can open it, so do not upload an image you would not want seen publicly.
- Referral attribution: If you arrived through a referral link, we record the referring username on your profile so the platform can credit the referrer toward founding-member status. This is used for internal attribution only and is not displayed publicly.
- Submission data: Video files, titles, AI model attribution, prompt metadata, tags, optional invite codes, director statements, and an optional phone number submitted through the platform. Series applications additionally include your name, contact details, and the pitch you write.
- Notify list: If you join the notify list ("Get notified when the next season drops"), we collect your email address and, optionally, a phone number. No account is required. We also store campaign attribution with that signup: UTM parameters from the link you arrived through and the referring page address.
- Activity data: Votes cast, films saved, submissions filed, and interactions with platform features.
- Product analytics: Usage events and pageviews (for example sign-ups, votes, submissions, and film views) and device/browser metadata, collected via PostHog (see Section 4). When you are signed in, these events are associated with your account ID. Crash reports are described separately below.
- Crash reports and diagnostics: When the site or the app hits an unhandled error, a crash report is captured automatically through PostHog (see Section 4). A crash report contains the error message, a stack trace identifying which code failed, and device and browser metadata such as operating system, browser version, and screen size. A stack trace is generated by the browser and can incidentally include values present at the moment of the failure, such as the page address or the identifier of the film being viewed. When you are signed in, the report is associated with your account ID. We use crash reports only to find and fix defects.
- IP addresses: Client IP addresses are processed to enforce rate limits and prevent abuse on write endpoints (submissions, applications, signups). Rate-limit counters keyed by IP are stored briefly in Upstash (see Section 4) and expire automatically.
- Operational logs: Server-side logs including request metadata (such as IP addresses), error events, and upload diagnostics. These are used to maintain platform reliability and investigate issues. Operational logs do not contain passwords or authentication tokens, and are not used for marketing.
- Watch and engagement data: For signed-in members we record playback and engagement events, including watch duration, completion rate, and playback starts, linked to your account ID. This is pseudonymous data used to power the platform's ranking and recommendation systems; it is never displayed publicly. For signed-out visitors, we collect lightweight session and playback signals (such as which films were opened or started) under a rotating anonymous session identifier that is not tied to any account. None of this data is sold or shared.
- Site feedback: When you send feedback through the site, we store your note with basic technical context: the page you came from and your browser type, and your account identity if you are signed in. We use this only to read and act on the feedback.
- Invitation links: When we invite a filmmaker to Awundra personally, the link we send may include a unique code. If that link is opened, we record that it was used and when. This tells us our invitation reached the person we sent it to; the code identifies the invitation, not your account, and is not used for any other tracking.
- Reports and moderation records: When a film is reported through the in-app Report button or by email, Awundra collects the report itself, including the reporter's account or contact information (when available), the reported content, the reason and any notes, timestamps, and internal moderation notes generated during review. These records are used to evaluate the report, communicate with the parties involved, and maintain platform trust and safety.
- Payout details: If you choose to give us payout information so we can send you a prize or other payment, we collect the payout method you select, the account identifier for that method (for example a Venmo, Zelle, or PayPal handle), your full legal name, a contact email address for payment questions, and any notes you add. Your full legal name is collected for this purpose only, and for no other. Payout details are optional, are stored apart from your public profile, are never displayed publicly, and are used solely to pay you.
- Contact messages: When you write to us through the contact form, we store your message, the page you wrote from, your browser type, your account identity if you are signed in, and the reply address you give us. That reply address is optional and is not verified. We use this only to read and answer what you sent.
2. How We Use Your Data
Data is used to:
- Operate and authenticate your account.
- Process and review content submissions.
- Power ranking, discovery, and curation features.
- Send transactional emails, submission confirmations, approval or rejection notices, and contest notifications. We may also send periodic platform announcements or curated drops, typically once or twice a week, if you have opted in. You can opt out at any time.
- Maintain platform integrity, investigate abuse, and enforce these Terms.
- Improve the platform based on aggregate usage patterns.
We do not sell your personal data. We do not use it for advertising.
3. Authentication
Account creation and sign-in are handled by Supabase, which manages authentication tokens and session data. Email delivery for magic links and OTP codes is handled by Supabase's auth infrastructure. Awundra does not store your password. Your session is managed via secure, HTTP-only cookies. Supabase's privacy practices apply to authentication data and are governed by their own policies.
You can also sign in with Google (OAuth). If you choose Google sign-in, Google shares your email address, name, and profile picture with us to create and identify your account. Google sign-in is optional (email sign-in remains available), and data Google itself processes is governed by Google's own privacy policy.
4. Third-Party Services
Awundra uses the following services to operate the platform:
- Supabase: Database, authentication, file storage, and server infrastructure. Profile pictures and film thumbnails you upload are stored in Supabase storage and served from public addresses.
- Vercel: Application hosting, edge delivery, and server-side rendering.
- PostHog: Product analytics and error monitoring. PostHog collects usage events, pageviews, and exception reports, which include the error message, a stack trace, and device and browser metadata, together with identifiers it stores in cookies and browser storage (keys beginning
ph_) to recognize your browser across visits. When you are signed in, analytics events, including some sent from our servers, are associated with your account ID. Analytics requests are routed through our own domain (/ingest) to PostHog's US cloud. This data is used only to understand and improve the platform, never for advertising. - Vercel Analytics: Secondary, aggregated telemetry. Vercel Analytics collects cookieless pageview and custom-event counts and does not build a cross-site advertising profile.
- Upstash: Managed Redis used for rate limiting and abuse prevention. Briefly stores rate-limit counters keyed by client IP address; entries expire automatically.
- Google: Optional sign-in (OAuth). When you choose Google sign-in, Google provides us your email address, name, and profile picture (see Section 3).
- Bunny Stream: Primary video hosting, transcoding, and delivery for films uploaded directly to Awundra. Uploaded files are transferred from your browser to Bunny Stream's infrastructure for storage and playback.
- Resend: Transactional email delivery. Used to send approval notifications and other platform emails to creators. Resend processes the recipient email address and message content necessary to deliver each email.
- Embedded video providers (e.g. YouTube, Vimeo): Used for certain curated editorial content. These providers may set their own cookies and collect data according to their own privacy policies.
Each of these services processes data under their own terms and privacy policies. We select services that apply reasonable data protection standards, but we cannot guarantee their practices.
5. Cookies & Browser Storage
Awundra uses two kinds of first-party cookies and identifiers. First, session cookies strictly necessary to authenticate your account and maintain your signed-in state on the web (secure, HTTP-only); in the mobile app the same session is carried in an authorization header rather than a cookie. Second, analytics identifiers set by PostHog in cookies and localStorage (keys beginning ph_), used to recognize your browser across visits and, when you are signed in, to associate usage events with your account for product analytics. We do not use advertising cookies and do not run cross-site advertising trackers; analytics data is never used for advertising. Vercel Analytics (Section 4) operates without cookies. Third-party embedded video players (such as YouTube or Vimeo) may set their own cookies when you interact with them, in accordance with their respective privacy policies.
We also use limited browser storage (such as localStorage and sessionStorage) for operational purposes, for example, to bridge your marketing-opt-in choice between the sign-up form and the onboarding step, to attribute referrals from referral links you arrived through, to remember whether you have dismissed the welcome modal, and to avoid showing you the same recommendation twice within a single browsing session. These items are stored on your device only, are not shared with third parties, and are not used for cross-site advertising or third-party tracking.
6. Data Retention
Account and profile data is retained while your account is active. Submission records, including approved and rejected leads, are retained for platform integrity and moderation purposes even after content is removed from public view. Reports and moderation records, including the underlying report, communications with the parties involved, and internal review notes, may be retained for trust and safety, dispute resolution, legal compliance, and abuse prevention, even after the related content or accounts are removed. Payout details are retained while your account is active and are deleted when your account is deleted. Contact messages are retained while they are useful for support and abuse investigation, and are deleted when they are no longer needed. Operational logs are retained for a limited period for debugging and security purposes and are then deleted or anonymized.
7. Data Deletion
You can delete your account from inside Awundra. Open your profile, choose Delete Account, and confirm by typing your username. You can also request deletion by email at kent@awundra.com with the subject line "Data Deletion Request." Either route leads to the same outcome, which is set out below.
Films you have already published stay on Awundra as published works, and they become unattributed. Your name, your link and your director note are removed from them. The film keeps its page, its title and its player, and the video file stays hosted, because the film itself is still published. What ends is the connection between that film and you.
Your profile is deleted. So are your saved films, your votes and recommendations, your follows in both directions, your viewing history, any payout details you had entered, and any blocks you had set. This cannot be undone.
Some records are kept in redacted form rather than removed. Submission records are kept so that the reason an approved film is on the site does not disappear with the account, but the contact details, the director note and the guided answers are stripped out of them. Reports you filed, feedback you sent and messages to support are kept as moderation and safety signals, with your identity detached from them.
Please note the following limitations:
- Video files for published films remain hosted, because those films remain published. Where a video file is no longer referenced by anything on the site, removal from Bunny Stream may take additional time.
- Content that has been publicly viewed or shared may persist in third-party caches or archives beyond our control.
- Aggregate, anonymized engagement data (e.g. watch counts on videos) may be retained even after personal data is deleted, as it is no longer linked to an individual.
- We may retain records required by law or for legitimate business purposes such as fraud prevention and abuse mitigation.
One thing outlives a deleted account, and we would rather say so plainly than bury it. If an account was suspended for a safety reason before it was deleted, we keep a minimal record of that suspension: a one-way cryptographic hash of the email address, and the reason for the suspension. Nothing else. No email address, no name, no profile, no notes or answers, and none of the work that was submitted. We keep it because a suspension that disappears when someone deletes and re-registers is not a suspension, and the people it protects are other creators on this site. It is the least we can keep and still enforce the decision.
8. Security
Awundra implements reasonable technical and organizational measures to protect your data, including encrypted connections, server-side authentication, and access controls. However, no system is completely secure. We cannot guarantee that unauthorized access, data breaches, or hardware failures will never occur. In the event of a significant breach affecting your personal data, we will notify affected users as required by applicable law.
9. Children's Privacy
Awundra is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us at kent@awundra.com and we will remove the account promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by an updated date at the top of this page. Continued use of the platform after changes are posted constitutes acceptance of the updated policy. For material changes, we may notify registered users by email.
11. Contact
For privacy-related questions, data requests, or concerns, contact us at kent@awundra.com. Include "Privacy" in the subject line so we can route your request appropriately. We are a small team and will respond as promptly as we can.