Privacy Policy
Effective date: August 27, 2026
LivingScene is built so that your work stays yours. Your decks live on your device — not on our servers — and the analytics we collect are strictly about how the app is used, never about what you make with it. This policy explains exactly what we collect, why, and what we never touch.
"LivingScene," "we," and "us" mean Living Beyond LLC, a Georgia (USA) limited liability company. We are the data controller for the personal information described here. You can reach us anytime at support@livingscene.ai.
The short version
- Your decks, scenes, and everything in them live on your device. We don't host or store your content — with one narrow exception: while you run a live audience session, the audience-facing parts of the scene you're showing are on our servers so your audience's phones can display them.
- We collect what we need to run your account: your email address, your subscription status, and usage analytics about which features get used (never what you made with them).
- Payments are handled by Stripe. Your card details never touch our servers.
- AI features are built in — you never need your own AI account or API key. When you use them, your instructions and the deck you're working on pass through our AI service to our model provider (Anthropic), are processed to fulfill your request, and are not stored. We keep only usage numbers (like token counts).
- Usage analytics is on by default and can be switched off in Settings at any time.
- We don't sell your personal information, we don't run ad trackers, and we never will.
What we collect
Account information
When you create an account we collect your email address and a password (stored only as a secure hash by our authentication provider, Supabase — we never see or store the password itself). If you sign in with Google, we receive your email address and the basic profile information Google shares instead of a password. That's the whole signup form — we don't ask for your name, company, or anything else.
Billing information
Payments are processed by Stripe. When you subscribe, checkout happens on Stripe's hosted pages: your card number and full payment details go directly to Stripe and never touch LivingScene servers. From Stripe we receive and store what we need to operate your account: a customer identifier, your subscription's status and plan, trial and billing-period dates, and the price you pay. We share your email address and account identifier with Stripe so your payments map to your account.
Usage analytics (desktop app)
The desktop app sends us feature-level usage events so we can see which features help and which get in the way. Each event carries: the event name (for example "a scene was presented" or "an AI edit ran"), a timestamp, and — where the event measures one — how long something took. Each also carries a random install identifier, a per-session identifier, your account identifier when you're signed in, the app version, whether you are running a released build or a development one, and your device's platform, architecture, OS version, and locale.
Events about a deck also carry a random identifier for that deck. It is generated for the deck and contains nothing from it — not its title, not its contents, not where it sits on your disk. It exists so we can tell one deck opened forty times from forty decks opened once. It is stripped out of any scene file you share, so a deck you hand to someone else never carries yours. Alongside it we record counts: how many scenes a deck has, and how many an edit added or removed. A session also records how long the app was actively used, as opposed to merely open.
For AI edits, the rest of the event is numbers: token counts, computed cost, the model used, duration, how many exchanges the request took, and how many scenes were touched. If the app hits an error, the report is scrubbed before sending — file paths are removed and only the error type and a short one-line summary are kept. Signing out records whether you signed out yourself or your session was ended for you.
What usage analytics never includes:
- The content of your decks or scenes
- Deck or scene titles
- Anything you type or say to the AI
- Your files, or paths to your files
Analytics is on by default. You can turn it off any time in Settings — the switch takes effect immediately, and turning it off also discards any events collected but not yet sent.
Live audience sessions
When you start a live session, your audience joins from their phones by scanning a code — they don't install anything, create an account, or tell us who they are. Running a session is the one part of LivingScene that puts your deck's content on our servers, so it is worth being exact about what goes up and what comes back.
What we upload while a session runs: the audience-facing parts of the scene you're on — the question or label text, its answer options, and the settings needed to draw it — plus which scene you're currently showing. The phones need this to render anything at all. The rest of your deck stays on your device.
What we receive from your audience: their answers, ratings, reactions and any written responses, each tagged with a random participant identifier so the counts add up. We ask your audience for no name, no email, and no account. We hold a room code, an expiry, and a hashed credential for the phone you pair as your own remote.
Your audience's answers are readable only by the account that owns the room — that is you. We don't read them, and no other room can.
Website analytics
Our marketing site (livingscene.ai) and your account dashboard (dashboard.livingscene.ai) use Vercel Analytics for cookieless, aggregate page metrics; the marketing site also uses Vercel Speed Insights for page-performance metrics. Alongside those we count a few anonymous interactions: clicks on a trial button (recording which button), clicks on a download link (recording your operating system), and votes in the demo poll on our site (recording the option chosen). Our documentation site (docs.livingscene.ai) has no analytics at all. None of this sets tracking cookies.
Support conversations
If you email support@livingscene.ai, we keep the conversation so we can help you and refer back to it if you contact us again.
Pre-launch waitlist
If you joined our waitlist before launch, we hold the email address you gave us (and the signup referral tag, if any) to send you a launch announcement. Email us and we'll remove you.
What stays on your device
LivingScene is a desktop app, and your work stays local:
- Your decks and scenes are files on your device. Outside a live audience session (above) we have no copy. (That also means we can't recover them for you — keep backups of work you care about.)
- Your sign-in session is stored encrypted using your operating system's secure storage.
When you export a scene file to share with someone, the app strips its internal identifiers, so a shared file can't be tied back to your library or your account.
AI features and your content
AI features are part of LivingScene — you don't need an account or API key with any AI provider; your subscription covers it. When you invoke an AI feature, the app sends your instructions and the content of the deck you're working on through LivingScene's AI service, which forwards them to our model provider, Anthropic, to fulfill your request. The app confines AI access to the deck you're editing; it cannot read your other files.
Two commitments about that path:
- We don't store your AI content. Your instructions and deck content pass through our AI service only to be processed — we don't log or keep them. What we do record is usage metadata (token counts, cost, model, timing), which we need to operate billing and usage limits.
- Your content isn't used to train AI models. Anthropic processes it under our agreement with them, which doesn't permit your content to be used for model training.
Cookies
The customer dashboard (dashboard.livingscene.ai) sets the cookies required to keep you signed in, plus one preference cookie remembering whether you asked us not to keep you signed in between visits. Signed-in sessions can persist for up to 400 days unless you sign out or opt out of being remembered. We set no advertising or cross-site tracking cookies anywhere.
If you pair your own phone as a remote during a live session, that phone holds one cookie carrying its session credential, on the pairing site only. It expires on its own within half a day. The audience join page sets no cookie of its own.
Service providers
We share personal information only with the providers we need to run LivingScene, only for the purposes described here:
| Provider | What they do for us | What they handle |
|---|---|---|
| Supabase | Authentication and database hosting | Email, password hash, account and subscription records, usage analytics |
| Stripe | Payment processing and billing portal | Email, payment details (held by Stripe, not us), subscription state |
| Vercel | Website and dashboard hosting; cookieless site analytics | Standard web-request data (IP address, user agent) |
| Resend | Email delivery (account and billing emails) | Email address, email content |
| Anthropic | AI model processing behind LivingScene's AI service | The deck content and instructions you send to AI features (not stored by us; not used for training) |
| GitHub | App download and update delivery | Standard web-request data when your device checks for or downloads updates |
| Cloudflare | DNS and network security | Standard web-request data |
We don't sell personal information, we don't share it for advertising, and there are no other categories of recipient — except if the law requires us to disclose something, or if LivingScene is ever part of a merger or acquisition (in which case this policy still governs your information and we'll notify you of any change).
How long we keep things
- Account information: until you delete your account.
- Billing records (including AI usage metering): as long as tax and accounting law requires (typically 7 years).
- Usage analytics: raw usage events are deleted within 180 days of collection; only aggregate statistics that can't identify you are kept longer. If you delete your account, events still inside that window are de-identified — the link to your account is severed. You can also ask us to erase them outright at any time.
- Live audience sessions: a room and everything in it — the uploaded scene parts, your audience's answers, the pairing credential — is deleted automatically once the session has expired, normally within a day or two.
- Support email: as long as useful for helping you.
- Waitlist emails: until the launch announcement is sent, or sooner if you ask.
Deleting your account, and your rights
You can delete your account from your account page, or by emailing support@livingscene.ai. Deletion removes your account record and sign-in identity and de-identifies your usage events (see "How long we keep things"); billing records we're legally required to keep are retained for the statutory period.
Wherever you live, we extend the same rights: you can access the personal information we hold about you, correct it, delete it, get a portable copy, and object to or restrict our processing of it. Email support@livingscene.ai and we'll act on it — usually within 30 days, and never with a fee.
If you're in the European Economic Area or the UK: our legal bases are performance of our contract with you (account, billing, providing the app), legitimate interests (usage analytics, security, support), and consent where we ask for it. You also have the right to complain to your local supervisory authority, though we'd appreciate the chance to fix things first.
If you're in California or another US state with a privacy law: we don't sell or "share" personal information as those laws define it, and we honor the access, deletion, and correction rights described above without discrimination.
Where your information lives
LivingScene operates from the United States, and our service providers store data in the US. If you use LivingScene from elsewhere, your information will be transferred to and processed in the US. Our providers offer contractual safeguards (including standard contractual clauses) for international transfers.
Children
LivingScene isn't directed to children. You must be at least 13 to use it, and we don't knowingly collect personal information from children under 13 — if you believe a child has given us personal information, contact us and we'll delete it.
Security
Everything travels over encrypted connections. At rest, our providers encrypt the data they hold for us. On your device, sign-in tokens are encrypted with your operating system's secure storage. Our database enforces row-level access rules so usage analytics can only be written, never read, by apps in the field. No system is perfectly secure — if we ever learn of a breach affecting your personal information, we'll notify you as the law requires and as fast as we reasonably can.
Changes to this policy
If we change this policy, we'll post the new version here with a new effective date — and for material changes we'll tell you by email or in the app before they take effect. We keep this document in lockstep with what the product actually does; if the product's data practices change, this page changes first.
Contact
Living Beyond LLC (Georgia, USA) support@livingscene.ai
Questions, requests, complaints, or something in this policy that doesn't match what you see the product doing — we want to hear about all of it.