Reel Engine

Privacy Policy

Last updated 7 August 2026

This explains what Reel Engine collects, where it is kept, who else can see it, and how to get rid of it. It describes what the system actually does rather than what a template says, so it is more specific than most policies of this kind.

Who runs this service

Reel Engine ("we", "us") is operated by Paul Bourne, a sole proprietor based in Ontario, Canada. You can reach us at support@getreelengine.com about anything in this policy, including requests to see or delete your data.

What we collect

Things you give us

Things connecting an account gives us

When you connect Instagram, Facebook, YouTube or TikTok, that platform gives us an access token, your account handle and account identifier. We use these only to post the reels you approve, and to show you which accounts are connected. We do not read your messages, your followers, or anything else the platform would let us.

Things the system produces

Reel ideas, hooks, captions and finished reels made for you, along with which ones you approved, skipped or archived, and when they were posted.

What we never see

Your card details. Payments go through Stripe, who take the card directly. We are told whether your subscription is active and when it renews — never your card number.

About your fal.ai key

Reel Engine does not resell AI capacity. You connect your own fal.ai account and pay fal directly at their rates, with no markup from us. That means your key is stored on our systems so the workflow can render on your behalf.

Being straight about how it is stored. Your key is held in our database, protected by database access controls so that only your own account and our server-side processes can read it. It is not encrypted at rest. We are changing that. Until we do: if our database or server credentials were ever compromised, your fal key would be exposed along with everything else, and that key can spend money on your fal account.

You can remove your key from Settings at any time, and you can rotate or revoke it from your fal.ai dashboard whenever you like — which is the fastest way to cut off access to anyone, including us.

Where it is stored, and who processes it

The service runs on a private server we control. These are the third parties involved, and what each one gets:

WhoWhat they getWhy
SupabaseYour account, Brand DNA, content records, API keyDatabase and sign-in
Cloudflare R2Your uploads and finished reelsFile storage and delivery
StripeYour email and payment detailsTakes payment. We never see the card
fal.aiYour prompts, photos and voice samples — on your own keyGenerates images, video and voice
AI language modelsYour Brand DNA and reel topicsWrites ideas, hooks and captions
Instagram, Facebook, YouTube, TikTokThe reels you approve, and their captionsPublishing to your own accounts
JamendoNothing about youSupplies royalty-free music

Our servers are in Germany and our file storage is distributed globally by Cloudflare. Some of the services above are based in the United States, so your information is transferred and processed outside your country.

What we do not do with it

The AI providers we send prompts to have their own policies on whether they train on data sent through their APIs. Where a provider offers a setting to exclude API traffic from training, we use it.

How long we keep things

WhatHow long
Your finished reelsIndefinitely, so your library stays useful. Deleted on request
Reel ideas you never approvedExpire automatically after 7 days
Uploads, Brand DNA, avatar and voiceUntil you delete them or close your account
Your fal.ai keyUntil you remove it, or your account closes
Social access tokensUntil you disconnect, or the platform expires them
Billing recordsAs long as tax and accounting law requires

Close your account and we delete your workspace, Brand DNA, uploads, reels, stored key and social connections. Billing records are kept where the law says they must be.

Your rights

You can ask us to show you what we hold about you, correct it, delete it, or send you a copy. Email support@getreelengine.com and we will respond within 30 days. We will not charge you, and we will not make your service worse for asking.

Depending on where you live, you may also have the right to object to certain processing or to complain to a data protection regulator.

Cookies

We use a small number of strictly necessary cookies and similar browser storage to keep you signed in and remember interface preferences. We do not use advertising or tracking cookies, and there is no third-party analytics on the app.

Security

Traffic is encrypted in transit. Access to member data is restricted at the database level so one member cannot reach another's. Server access is limited to the operator. As stated above, stored API keys are not yet encrypted at rest, and we will update this policy when that changes.

No system is perfectly secure. If information of yours is ever exposed in a way that puts you at risk, we will tell you.

Children

Reel Engine is not for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.

Changes

If we change this policy in a way that meaningfully affects you, we will email you before it takes effect. The date at the top always reflects the current version.

Governing law

This policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable there.