Epitome
Document · Privacy · v1.0
Request access →
Document PRIVACY POLICY
Effective APRIL 30, 2026
Version 1.0
Applies to withepitome.com · app.withepitome.com

Your data, handled like a closed set.

This policy explains what information Epitome collects when you use our website and platform, what we do with it, and the controls you have. It applies to producers, coordinators, and crew who interact with anything we publish at withepitome.com or run at app.withepitome.com.

Contents

  1. Who we are
  2. What we collect
  3. How we use it
  4. Legal bases
  5. Controller vs. processor
  6. Who we share with
  7. Sub-processors
  8. International transfers
  9. How long we keep it
  10. Your rights
  11. California (CCPA)
  12. Europe & UK (GDPR)
  13. Cookies
  14. Security
  15. Children
  16. Changes
  17. Contact
01

Who we are

Epitome is operated by Epitome Technologies, Inc. ("Epitome," "we," "us," or "our"), a company based in the United States. We build software that helps physical-production teams in film, television, and advertising plan a shoot — from call sheet to crew grid to schedule — by combining producer prompts, uploaded crew lists, and AI-generated production documents.

Our website is www.withepitome.com. The product itself runs at app.withepitome.com.

This policy is a starting point and may be updated as the product evolves. The version and effective date at the top of this page tell you which revision is in force.

02

What we collect

We collect different categories of information depending on whether you're an account holder (a producer, coordinator, or other team member who signs in to the app) or a crew member whose information has been added by someone else for a production.

Information you give us when you sign up

  • Your name and email address.
  • Your password, stored as a one-way hash by our authentication provider (we never see the plaintext).
  • The organization, role, and team you're associated with inside Epitome.

Production data you upload or generate

  • Project briefs, scripts of work, schedules, and call sheets — typed in by you or generated by Epitome from your prompts.
  • Locations, vendors, clients, and budgets associated with a project.
  • Files you upload, including crew lists in any format we accept.

Crew personal information you provide to us

When you add crew to a project — typically by uploading a crew list or pasting one in — we process the personal information needed for that crew member to do their job. That can include:

  • Name, email, phone number.
  • Mailing address (street, city, state, ZIP).
  • Role, department, day rate, and union local.
  • Loan-out company and W-9 status.
  • Agent or representative contact information.
  • Notes, dietary restrictions, shirt size, and vehicle info attached to a project assignment.

When we receive crew information from you, we treat that crew member as a third-party data subject. You are responsible for making sure you have the right to share their information with us — see "Your rights" and our Terms of Service.

Usage and device information

  • Pages and features you use within the app, captured as event logs.
  • IP address, browser type, operating system, device identifiers, and the time of each request.
  • Errors and diagnostic traces when something goes wrong, so we can fix it.

Communication metadata

  • Delivery, open, and click events for emails we send through our transactional email provider (Resend).
  • Replies and tickets you send to producers@epitome.film or any other support address.
03

How we use it

We use the information described above to:

  • Run the service — authenticate you, save your work, and let your team see the right projects.
  • Generate the deliverables — produce call sheets, schedules, crew grids, and Excel workbooks from the prompts and files you give us. This involves passing data through large language models and enrichment APIs (see sub-processors).
  • Send transactional email — sign-in links, password resets, crew invites, and production-specific notifications.
  • Support and operate — respond to your questions, monitor for abuse, debug failures, and back up your data.
  • Improve the product — understand which features matter, in aggregate, and where the platform stumbles.
  • Stay compliant — meet legal, tax, and contractual obligations.

We do not sell personal information, and we do not use your or your crew's data to train third-party AI models for anyone else's benefit. Production content you upload is used to generate output for your own production, not as training data for general-purpose models.

04

Legal bases for processing

If you are in the European Economic Area, the United Kingdom, or another jurisdiction that requires us to identify a legal basis, we rely on:

  • Contract — to provide the service you've signed up for.
  • Legitimate interests — to keep the service secure, prevent abuse, debug failures, and improve features.
  • Consent — where required, for example for any non-essential cookies or marketing email.
  • Legal obligation — when we have to retain or disclose information to comply with the law.
05

When we are a controller, and when we are a processor

For your own account information — your name, email, sign-in events, support tickets — Epitome acts as a controller. We decide what to collect and why.

For the crew personal information you upload in order to staff a production, Epitome acts as a processor on your behalf. You are the controller; we handle the data on your instructions, the way our software is designed to. If a crew member contacts us directly to exercise a right (access, deletion, correction), we will help, but we may need to coordinate with the producer who originally added them.

06

Who we share with

We share information only as needed to operate the service. The categories are:

  • Sub-processors who host, process, or transmit data for us under written terms — see the next section for the current list.
  • Other people in your organization on Epitome, according to the access controls you configure.
  • Crew you've invited, who can see information about themselves and the productions they're staffed on.
  • Professional advisors (lawyers, accountants, auditors) under confidentiality.
  • A successor entity in the event of a merger, acquisition, or sale of the business — with notice to you.
  • Authorities when we are legally required to, such as in response to a valid subpoena or court order. We will narrow the scope where we can.
07

Sub-processors

We rely on the following companies to run Epitome. The list is current as of the effective date above and may change; material changes will be reflected in this page.

Provider Purpose Region
Supabase Authentication, Postgres database, row-level security United States
Railway Backend application hosting United States
Vercel Frontend and marketing-site hosting, edge CDN United States
Resend Transactional email delivery United States
Google Cloud (Gemini API) Crew-list extraction and natural-language production assistance United States
Google Maps Platform Geocoding, location search, weather lookup United States
logo.dev Brand and client logo enrichment United States

We require each sub-processor to handle the data we send them only for the purposes described above and to maintain commercially reasonable security.

08

International data transfers

Epitome is operated from the United States, and most of our sub-processors store data there. If you access the service from another country, your information will be transferred to and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses or equivalent mechanisms to legitimize the transfer.

09

How long we keep your data

We keep account and production data for as long as your account is active. When you ask us to delete an account, or when an account has been inactive for an extended period, we delete or anonymize the associated data within a reasonable window — typically within 90 days — except where we are required to retain it for legal, tax, or accounting reasons.

Backups are rotated continuously and are typically purged within 30 days, after which deleted data is no longer recoverable.

Aggregate analytics that contain no personal information may be retained indefinitely.

10

Your rights

Depending on where you live, you may have the right to:

  • Access a copy of the personal information we hold about you.
  • Correct information that is wrong or incomplete.
  • Delete your information, subject to legal retention requirements.
  • Port your information to another service in a structured, machine-readable format.
  • Object to or restrict certain types of processing.
  • Withdraw consent where we rely on consent.
  • Lodge a complaint with your local data protection authority.

To exercise any of these, email privacy@withepitome.com. We respond to verified requests within 30 days, or sooner if the law in your jurisdiction requires it.

11

California residents (CCPA / CPRA)

If you live in California, you have the right to know what categories of personal information we collect and disclose, the right to request deletion of your personal information, the right to correct inaccurate information, and the right to opt out of "sale" or "sharing" of personal information.

We do not sell personal information for money, and we do not share it for cross-context behavioral advertising. We do disclose personal information to the sub-processors listed above in order to provide the service.

To submit a verifiable consumer request, email privacy@withepitome.com with "California Privacy Request" in the subject line. You may also designate an authorized agent to make a request on your behalf.

We will not discriminate against you for exercising any of your CCPA rights.

12

Europe and UK residents (GDPR / UK GDPR)

If you live in the EEA, the UK, or Switzerland, the legal bases described in Section 04 apply, and you have the additional rights described in Articles 15–22 of the GDPR.

Epitome currently does not maintain an EU representative, as required activity is below the threshold; this will be revisited as our European customer base grows. In the meantime, you can contact us at privacy@withepitome.com for any GDPR matter.

13

Cookies and similar technologies

The marketing site at withepitome.com uses essential cookies only — for example, to remember whether you've dismissed a banner. The application at app.withepitome.com uses cookies and local storage to keep you signed in and to remember your preferences.

We do not currently use third-party advertising or cross-site tracking cookies. If we add analytics or product-usage cookies in the future, we'll update this section and, where required, ask for your consent before they load.

14

Security

We design Epitome with defense in depth. Data is encrypted in transit using TLS, encrypted at rest by our database provider, and protected at the row level inside Postgres so that organizations can only see their own records. Our authentication uses ES256 signed JSON Web Tokens validated against the Supabase JWKS on every request.

Access to production systems is limited to a small number of engineers, controlled by single sign-on and audited.

No system is perfectly secure. If you suspect your account has been compromised, email security@withepitome.com and we will investigate.

15

Children's privacy

Epitome is a workplace tool, not directed to children, and we do not knowingly collect personal information from anyone under the age of 16. If a production includes minor talent or crew, the producer is responsible for handling that information in accordance with the laws applicable to their jurisdiction and union rules; Epitome is not the controller of that information.

If you believe a child's information has been provided to us, contact privacy@withepitome.com and we will delete it.

16

Changes to this policy

We will update this policy when our practices change. The version and effective date at the top of the page indicate the current revision. For material changes, we'll post a notice on the marketing site and, when appropriate, email account holders before the change takes effect.

17

How to contact us

For privacy questions or to exercise any right described above:

  • Email: privacy@withepitome.com
  • General contact: producers@epitome.film
  • Postal mail: Epitome Technologies, Inc., Los Angeles · New York — address available on request.

If you're unsatisfied with our response, you have the right to complain to a supervisory authority in your country of residence.

Produced by a small team
in Los Angeles & New York.

We’re ex-line producers, ex-UPMs, and a handful of engineers who’ve shipped the kind of software set-folks actually open on their phones. Epitome is our second act.

Product

  • Call sheets
  • Crew grid
  • Schedule
  • RSVP chase
  • Crew app

Company

  • About
  • Manifesto
  • Changelog
  • Careers

Producers

  • Request access
  • Pricing
  • Security & NDAs
  • Pilot program

Legal

  • Privacy
  • Terms

Contact

  • producers@epitome.film
  • +1 (213) 555–0144
  • LA · NY
© 2026 EPITOME TECHNOLOGIES, INC. · Privacy · Terms epitome END · 01 / 01