Privacy policy
This policy explains how BFC GROUP, the publisher of Micro Drama, processes personal data on microdrama.studio and in the associated Micro Drama creation services, including Story Studio. It should be read with our Security and privacy page.
1. Data controller
BFC GROUP, a French SAS with share capital of €10,748
14 rue Artaud, 69004 Lyon, France
SIREN: 830 940 979
Privacy contact: [email protected]
No Data Protection Officer has been appointed at this time.
2. Data we process
Depending on the features used, we may process:
- account and authentication data: technical identifier, email address, display name and access rights;
- commercial data: plan, credits, billing and Stripe identifiers — we do not receive the full card number;
- project content: ideas, briefs, scripts, bibles, characters, dialogue, images, voices, videos, reference files and generated results;
- collaboration and publication data chosen by the user;
- contact requests: first name, last name, company and message;
- technical and security data: timestamp, operation type, model, volumes, status, cost, IP address and logs needed for security;
- audience data, only after consent to Google Analytics.
Do not upload unnecessary sensitive data, or a person's image or voice without an appropriate legal basis and permission.
3. Purposes and legal bases
| Purpose | Main legal basis |
|---|---|
| Create an account, save projects and provide requested generations | Contract or pre-contractual steps |
| Manage payments, credits, subscriptions and accounting | Contract and legal obligation |
| Secure, diagnose and maintain the platform and prevent fraud | Legitimate interest in a safe and reliable service |
| Answer contact requests and prepare a quote | Pre-contractual steps and legitimate interest |
| Measure website audience with Google Analytics | Consent, withdrawable at any time |
4. Content and artificial intelligence
Micro Drama does not use your content to train, fine-tune or evaluate its own general-purpose AI models. We do not sell your scripts, ideas or data.
When you invoke an AI feature, only the data required for that feature is sent to the relevant provider to produce the requested result. A sensitive integration remains disabled until its service tier, exact model and confidential-processing terms have been verified.
This does not mean that no provider ever retains data temporarily: service delivery, safety controls and zero-data-retention options depend on the applicable service and contract. We favour commercial services that exclude training on customer content and enable stronger safeguards when available.
5. Recipients and processors
Only authorised BFC GROUP staff and necessary providers receive relevant data.
| Category / provider | Role |
|---|---|
| Google Cloud / Firebase | Authentication, database, server functions, hosting and technical logs |
| Cloudflare, including R2 | Site delivery, network protection and media storage |
| OpenAI | On-demand writing, analysis and script doctor through a private server gateway |
| Anthropic | On-demand writing, analysis and script doctor |
| Google Gemini | Text, image or voice generation on a verified paid project only |
| fal.ai, Replicate, Luma and BytePlus | Specialised image, video, audio or media processing, depending on the selected feature |
| Stripe | Payments, subscriptions and billing |
| Web3Forms and Google Workspace | Contact-request delivery and handling |
| Google Analytics | Audience measurement after consent |
| Social networks connected by the user | Publication or connection explicitly requested by the user |
Model availability alone is not sufficient for activation: model-specific and service-tier terms must be compatible with this policy.
6. International transfers
Some providers may process data outside the European Economic Area, notably in the United States. Depending on the provider, transfers rely on an adequacy decision, the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, with additional measures where required. The applicable safeguards are reviewed in the processor register and provider contracts.
7. Retention and deletion
We use the following periods or criteria:
- commercial enquiries: up to 3 years after the last contact;
- invoices and accounting records: the applicable statutory period;
- account and projects: during the contractual relationship, then deleted or anonymised on request or closure, subject to legal duties;
- media and backups: while needed by a project, collaboration or publication; unreferenced items enter the deletion process and backup copies follow the provider's technical cycle;
- technical and security logs: for a period proportionate to diagnosis, fraud prevention and security obligations;
- Google Analytics: according to the configured property period, with a target maximum of 14 months; consent is requested again no later than 6 months.
Deletion may be delayed when data is required for a legal claim, a statutory duty, or remains referenced by a shared project you asked us to retain. Contact us for complete, verifiable deletion.
8. Cookies and analytics
Google Analytics is loaded only after explicit consent. Declining does not affect access to the website. The choice is stored locally for no more than 6 months. Essential authentication and security features may use strictly necessary storage that is not used for advertising.
9. Security
Measures include authentication, owner-scoped project access, encryption in transit, infrastructure encryption at rest, server-side secrets, data-minimised logs, remote-URL controls, security headers and incident-management procedures.
No online service can guarantee zero risk. We maintain measures appropriate to the risk, remediate vulnerabilities and notify personal-data breaches where required by law. Details and limitations are published on our Security page.
10. Your rights
You may request access, correction, erasure, restriction or portability, object to certain processing, and withdraw analytics consent at any time.
Contact [email protected]. We may request limited proof where needed to prevent a third party from accessing your data. You may complain to the French CNIL at cnil.fr or your local supervisory authority.
11. Changes
We will update this page when the service, providers or safeguards change materially. The date below identifies the applicable version.
Last updated: 10 July 2026.