Privacy policy

Privacy policy

This policy explains how BFC GROUP, the publisher of Micro Drama, processes personal data on microdrama.studio and in the associated Micro Drama creation services, including Story Studio. It should be read with our Security and privacy page.

1. Data controller

BFC GROUP, a French SAS with share capital of €10,748
14 rue Artaud, 69004 Lyon, France
SIREN: 830 940 979
Privacy contact: [email protected]

No Data Protection Officer has been appointed at this time.

2. Data we process

Depending on the features used, we may process:

Do not upload unnecessary sensitive data, or a person's image or voice without an appropriate legal basis and permission.

3. Purposes and legal bases

Purpose Main legal basis
Create an account, save projects and provide requested generations Contract or pre-contractual steps
Manage payments, credits, subscriptions and accounting Contract and legal obligation
Secure, diagnose and maintain the platform and prevent fraud Legitimate interest in a safe and reliable service
Answer contact requests and prepare a quote Pre-contractual steps and legitimate interest
Measure website audience with Google Analytics Consent, withdrawable at any time

4. Content and artificial intelligence

Micro Drama does not use your content to train, fine-tune or evaluate its own general-purpose AI models. We do not sell your scripts, ideas or data.

When you invoke an AI feature, only the data required for that feature is sent to the relevant provider to produce the requested result. A sensitive integration remains disabled until its service tier, exact model and confidential-processing terms have been verified.

This does not mean that no provider ever retains data temporarily: service delivery, safety controls and zero-data-retention options depend on the applicable service and contract. We favour commercial services that exclude training on customer content and enable stronger safeguards when available.

5. Recipients and processors

Only authorised BFC GROUP staff and necessary providers receive relevant data.

Category / provider Role
Google Cloud / Firebase Authentication, database, server functions, hosting and technical logs
Cloudflare, including R2 Site delivery, network protection and media storage
OpenAI On-demand writing, analysis and script doctor through a private server gateway
Anthropic On-demand writing, analysis and script doctor
Google Gemini Text, image or voice generation on a verified paid project only
fal.ai, Replicate, Luma and BytePlus Specialised image, video, audio or media processing, depending on the selected feature
Stripe Payments, subscriptions and billing
Web3Forms and Google Workspace Contact-request delivery and handling
Google Analytics Audience measurement after consent
Social networks connected by the user Publication or connection explicitly requested by the user

Model availability alone is not sufficient for activation: model-specific and service-tier terms must be compatible with this policy.

6. International transfers

Some providers may process data outside the European Economic Area, notably in the United States. Depending on the provider, transfers rely on an adequacy decision, the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, with additional measures where required. The applicable safeguards are reviewed in the processor register and provider contracts.

7. Retention and deletion

We use the following periods or criteria:

Deletion may be delayed when data is required for a legal claim, a statutory duty, or remains referenced by a shared project you asked us to retain. Contact us for complete, verifiable deletion.

8. Cookies and analytics

Google Analytics is loaded only after explicit consent. Declining does not affect access to the website. The choice is stored locally for no more than 6 months. Essential authentication and security features may use strictly necessary storage that is not used for advertising.

9. Security

Measures include authentication, owner-scoped project access, encryption in transit, infrastructure encryption at rest, server-side secrets, data-minimised logs, remote-URL controls, security headers and incident-management procedures.

No online service can guarantee zero risk. We maintain measures appropriate to the risk, remediate vulnerabilities and notify personal-data breaches where required by law. Details and limitations are published on our Security page.

10. Your rights

You may request access, correction, erasure, restriction or portability, object to certain processing, and withdraw analytics consent at any time.

Contact [email protected]. We may request limited proof where needed to prevent a third party from accessing your data. You may complain to the French CNIL at cnil.fr or your local supervisory authority.

11. Changes

We will update this page when the service, providers or safeguards change materially. The date below identifies the applicable version.

Last updated: 10 July 2026.