Legal
Privacy policy
Last updated: 5 October 2026
The short version
Your project, your own files and the finished video stay on your machine. What leaves it is what a command needs: narration text, prompts, search words, a video that you send for background removal, and the audio of a reference video that you have transcribed. That content goes to our server and to the services named below, and the results are kept in your private files.
Anything that goes to the shared library becomes public once it passes review. This site has no analytics and no advertising, and it sets no cookies.
Who is responsible
Reelkit is built and run by Unit 01, a software studio in Israel. Unit 01 decides what data Reelkit holds and why, and is responsible for it. In the words of Israel's Privacy Protection Law, Unit 01 is the controller of the database.
For any question or request about privacy, write to hello@unit01.co.il.
No law requires you to give us data. Without an email address you cannot have an account, and a command that calls the server has to send what it works on.
What we keep, and why
This is everything the service stores about you or receives from you.
| What | Why | Where it is stored | Who else processes it | How long |
|---|---|---|---|---|
| Your email address, a user id, and a handle made from the part of your email before the @. | WhyTo sign you in, and to tie your files and your quota to you. | Where it is storedSupabase, which runs the sign-in and the database. | Who else processes itNo one else. | How longUntil your account is deleted. |
| For each machine you connect: the machine's name as it reports it, a login token stored only as a hash, when it was created and last used, and when it was revoked. While a login is in progress, a short code that works for 10 minutes. | WhySo that the CLI on that machine can act for your account, and so that a token can be revoked. | Where it is storedSupabase. | Who else processes itNo one else. | How longUntil your account is deleted. A revoked token's record stays, marked as revoked. A login code is removed when it is used or after it expires. |
| A record of each use: its kind (narration characters, an image, a clip, seconds of background removal, seconds of transcription, a pull from the library, an upload, a shared upload), the amount and the time. Not the content, and not which item. | WhyTo count your quotas and show them on your account page. | Where it is storedSupabase. | Who else processes itNo one else. | How longNot deleted automatically. Removed with your account. |
| The voiceovers, images, clips and cutouts made for you. | WhyTo hand them to the CLI and to list them on your account page. | Where it is storedCloudflare R2, our file storage. | Who else processes itThe service that made each one: ElevenLabs, Vercel AI Gateway, Higgsfield or Modal. | How longNo expiry. Until you ask us to delete them. |
| For each generated file: its kind, the time, its length or shape, and the first 120 characters of the narration or prompt (for a cutout, the file's name). For a clip, also a job record with the whole prompt. For a cutout, a job record with the file's name, size and length. | WhyTo label your files on your account page, and to follow a job until it ends. | Where it is storedCloudflare R2. | Who else processes itNo one else. | How longNo expiry. Until you ask us to delete them. |
| Items that go to the shared library: the file, its title, description and tags, its kind and technical details, your user id as its owner, and the outcome of the review. | WhyTo review the item, make it searchable and offer it to every user. | Where it is storedSupabase holds the record and Cloudflare R2 the file. | Who else processes itVercel AI Gateway, for tagging, search and the automated check. | How longUntil the item is removed. If your account is deleted, published items stay without a link to you unless you ask for their removal. |
| Technical details of each request, such as the IP address, the time, the address requested and the CLI's version. When something fails, our server adds a line to the log, which can include a user id or an item id. | WhyTo run the service, find faults and stop abuse. | Where it is storedVercel, which hosts this site and the server. | Who else processes itNo one else. | How longFor as long as Vercel keeps its logs. Our own database does not store IP addresses. |
What stays on your machine
The project folder, plan.json, your screenshots, logo and footage, the composition code and the rendered video stay on your machine. Rendering runs there. So does removing a green background with --green, and so do downloading a reference video with reelkit ref download and measuring it with reelkit ref analyze.
The CLI keeps your login token in a file in your home folder, ~/.config/reelkit/credentials.json, which only your user can read.
The CLI has no telemetry. It contacts the server only when a command needs it, and says which version of the CLI is calling.
What is sent for processing, and to whom
Each of these happens only when you or your agent run the command.
- Narration.
reelkit assets voiceoversends each scene's narration text to our server, which sends it to ElevenLabs to be spoken. The audio is stored in your private files and downloaded into your project. - Images.
reelkit assets gen imagesends the image prompt to our server, which sends it through Vercel AI Gateway to the provider of the image model. The image is stored in your private files, or, for a scene that your plan marks as generic, in the shared library for review. - Clips.
reelkit assets gen clipsends the clip prompt to our server, which sends it to Higgsfield, a video generation service. The finished clip is copied to your private files, or to the shared library for review when you add--share. - Background removal.
--cutoutuploads the video itself to our storage. A GPU service that we run on Modal reads it through a link that works for 30 minutes, removes the background and writes the result back. It keeps no copy when the job is over. We delete the uploaded video when the job ends. The transparent result is kept in your private files. - Reference videos.
reelkit ref downloadfetches or copies a reference video onto your machine, and it stays there: the video is never uploaded.reelkit ref analyzemeasures it on your machine and sends its audio, never the video, to our server, which sends it through Vercel AI Gateway to a speech-to-text model (OpenAI Whisper unless we change it) to be transcribed. We delete the audio when the call ends. The transcript text is kept with the job in your private area and is not shared with anyone. With--no-transcriptnothing is sent. - Search. A library search, from
reelkit assets searchor from the search box on this site, sends the search words through Vercel AI Gateway to two models: one turns the words into numbers so that items can be matched by meaning, and one judges which items fit. We do not store search words with your account. A search made on this site is remembered for 5 minutes, with no link to you, so that the same search is not ranked twice. - Sharing. A file that you share with
--shareis uploaded to our storage. Its title, description and tags, and for an image the picture itself, go through Vercel AI Gateway to a model that writes tags and a description for search. The text of an image item, not the picture, can also go to a second model that checks whether the item suits a public library.
The gateway passes each request to the company whose model we use for that job. None of these services is sent your email address.
The shared library is public
Once an item is published, anyone can see its title, description, tags and preview on this site without an account, and every signed-in user can pull the file. Your handle and your email address are not shown with it.
For a generated illustration or clip, the description is the prompt that made it. Put nothing private in the prompt of a scene that can be shared.
Removal on request stops future pulls. Copies that were already pulled stay with the people who pulled them. The licence you give when you share is in the terms of use.
Cookies and browser storage
This site sets no cookies.
It uses your browser's storage for three things:
- your sign-in session, kept by the sign-in library until you sign out
- the login code, while you approve a CLI login, kept for that tab only
- a mark that you have already seen the opening animation, kept for that tab only
There are no analytics, no advertising and no third-party scripts, and the fonts are served from this site. Besides this site, your browser contacts two services: Supabase, when you sign in, and our file storage at Cloudflare R2, for previews and downloads.
Where signing in through Google or GitHub is offered, choosing it takes you to that company's sign-in page, and we receive your email address from it.
What we do not do
We do not sell your data. We show no advertising. We do not build a profile of you.
We do not train models on your content. What the services above do with what they receive is set by their own terms.
Two things are decided automatically: the quotas are enforced by the server, and an automated check can decline to publish a generated illustration, which then stays private. If you think the check got it wrong, write to us.
How long we keep it, and deleting
Your account, your generated files and their records have no expiry. They stay until you ask us to delete them.
A video uploaded for background removal is deleted when the job ends.
A reference video's audio is deleted when its transcription ends. The transcript text has no expiry, like your other records.
An upload that was started and never finished is cleared: its record is removed once it is a day old, the next time you start an upload.
There is no delete button yet. To delete a file, a shared item or your whole account, write to hello@unit01.co.il.
Deleting an account removes its profile, login tokens and usage records, and we delete its private files. Items of yours that are already published stay in the library, with no link to you, unless you ask us to remove them too.
Security
Login tokens are stored only as hashes, so a token cannot be read back from our database.
Your private files stay private. Each one is handed out through a signed link that stops working after 10 minutes, and only to the account that owns it.
The database answers only our server, never a browser.
Access to the systems is limited to the people who run Reelkit.
No system is perfectly secure, and we hold no security certification. If a security incident puts your data at serious risk, we will tell you, and the Privacy Protection Authority, as the law requires.
Data outside Israel
Unit 01 is in Israel, but the services listed here run elsewhere, so your data is processed outside Israel, including in the European Union and the United States. By using the commands that send content, you agree to that.
Your rights
Under Israel's Privacy Protection Law you may ask to see the data we hold about you, and to have it corrected or deleted when it is wrong, incomplete or out of date. Beyond that, you can ask us to delete your account and your files at any time, and we will.
If you are in the European Union, the GDPR gives you the matching rights: to see, correct and delete your data, to restrict or object to its use, to receive a copy of it, and to complain to your data protection authority.
To use any of these, write to hello@unit01.co.il from the email address of your account. We answer within 30 days.
Your account page already shows your email address, your usage and your generated files, each with a download link.
Children
Reelkit is not meant for children, and you must be at least 16 years old to have an account. If you believe a child has opened one, write to us and we will delete it.
Changes to this policy
We may update this policy. The date at the top is the date of this version, and a material change will be announced on this site.