Privacy Policy
Last updated: 5 July 2026 · Governing law: Ontario, Canada
This Privacy Policy explains how Cinematechs AI Inc. ("Cinematechs", "we", "us") handles information for Whistle, our AI marketing assistant for small and local businesses, and for the cinematechs.ca website. Whistle is currently offered as a private beta.
Plain-language summary: We collect the minimum we need to run Whistle. When you connect a platform (Instagram, Facebook, Google, TikTok), we access only the specific permissions listed below, use that data only to deliver the features you asked for, never sell it, and delete it when you disconnect or ask us to.
1. Who we are
Whistle and this site are operated by Cinematechs AI Inc., 1 University Ave, Toronto, ON M5J 2P1. For any privacy question or request, contact privacy@cinematechs.ca.
2. What this covers
This policy covers the Whistle application (web app and beta waitlist) and the cinematechs.ca marketing website. It does not cover third-party services we link to, which have their own policies.
3. Information we collect
- You give us: your name and email (e.g. when you join the beta waitlist or create an account), messages you send to the AI, business details, and content you ask Whistle to draft or schedule.
- From platforms you connect (only with your authorization): profile and content data covered by the specific permissions in section 4.
- Automatically: basic, privacy-respecting usage analytics (via Plausible, which uses no cookies and collects no personal identifiers) and standard server logs for security.
Beta applications: when you apply for the Whistle private beta we collect the details you submit — your name, work email, business name, website, industry, size, and what you'd like Whistle to help with — solely to review your business and contact you about the beta.
4. Permissions & platform data
When you connect an account, Whistle requests only the permissions it needs for the features you use. To publish to Instagram, your Instagram account must be a Business or Creator account linked to a Facebook Page.
| Platform | Permission | What we do with it |
|---|---|---|
| Meta · Instagram | instagram_basic | Read your connected Instagram Business/Creator profile and its media to run audits and reporting. |
| Meta · Instagram | instagram_manage_insights | Read post and account insights for your audits and performance reports. |
| Meta · Facebook | pages_show_list | List the Facebook Pages you manage so you can pick the Page linked to your Instagram. |
| Meta · Facebook | pages_read_engagement | Read engagement on your linked Page for audits and reporting. |
| Meta · Instagram | instagram_content_publish | Publish content that you explicitly approve to your Instagram — never without your click. |
| Meta · Facebook | pages_manage_posts | Publish approved content to your linked Facebook Page, on your approval. |
| Google · Business Profile | business.manage | Read and update the Google Business Profile listing you connect, with your approval. |
| Google · Analytics | analytics.readonly | Read your Google Analytics metrics to include in reports (read-only). |
| Meta · Ads | ads_read | Read your ad-account performance for reporting. |
| Meta · Ads | ads_management | Draft ad campaigns for your sign-off (nothing is launched without your approval). |
| TikTok | user.info.basic | Read your basic TikTok profile to connect your account. |
| TikTok | video.upload, video.publish | Upload and publish content that you approve to your TikTok account. |
r_liteprofile | Read your basic LinkedIn profile to connect your account. | |
w_member_social | Post content that you approve to your personal LinkedIn. | |
w_organization_social | Post approved content to a LinkedIn Company Page you manage. |
Each permission is requested only when you connect that platform and enable the related feature. Confirm these scopes exactly match the reviewed app before each platform's app review. Platform data obtained through these permissions is used only to provide the features described above. We do not sell it, and we delete it when you disconnect the integration or ask us to (see Data Deletion).
5. How we use information
- To provide Whistle's features: audits, reporting, content planning, and — only on your explicit approval — publishing.
- To operate, secure, and improve the service and respond to support requests.
- To send you service and beta-related email. We use single opt-in for the waitlist and you can unsubscribe at any time.
We do not sell your personal information or platform data, and we do not use it for advertising to you.
6. Who we share with
We share information only with the sub-processors below (to run the service), when you direct us to (e.g. publishing content you approved), or when required by law. We never sell data.
7. Sub-processors
We rely on these providers, each acting under their own security and privacy commitments:
- Clerk — Authentication and account identity.
- Supabase — Database and file storage for your account data, content, and media.
- OpenAI — Text and content generation/processing.
- Higgsfield — Image and video generation.
- Stripe — Payment processing (only if you subscribe).
8. Legal bases (GDPR)
Where GDPR applies, we process data on the basis of: consent (waitlist email, connecting optional integrations), contract (delivering the service you signed up for), and legitimate interests (security, preventing abuse, product improvement) balanced against your rights.
9. Retention
We keep account data for as long as your account is active. Platform data pulled for audits/reporting is retained only as long as needed for the feature and is deleted when you disconnect the integration. Waitlist emails are kept until you unsubscribe or the beta program ends. Backups are purged on a rolling basis. You can request deletion at any time — see Data Deletion.
10. Your rights
Depending on where you live, you have rights under PIPEDA (Canada), GDPR (EU/UK), and the CCPA/CPRA (California), including to access, correct, delete, port, or object to/restrict processing of your personal information, and to withdraw consent. California residents have the right to know, delete, correct, and opt out of "sale"/"sharing" — we do not sell or share personal information, and we do not discriminate against you for exercising your rights. To exercise any right, email privacy@cinematechs.ca; we respond within the timeframes required by law.
11. International transfers
We are based in Canada and our sub-processors may process data in Canada, the United States, and the EU. Where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
12. Children
Whistle is a business tool and is not directed to children. We do not knowingly collect information from anyone under 16 (or under 13 where a lower age applies with appropriate consent). If you believe a child provided us data, contact us and we will delete it.
13. Security
We use encryption in transit, access controls, and reputable infrastructure providers. Access tokens for connected platforms are stored securely and used only for the features you enabled. No system is perfectly secure, but we work to protect your data and will notify you and regulators of breaches as required by law.
14. Changes
We may update this policy; we will change the "Last updated" date above and, for material changes, notify you. Continued use after changes means you accept the updated policy.
15. Contact
Questions or requests: privacy@cinematechs.ca, Cinematechs AI Inc., 1 University Ave, Toronto, ON M5J 2P1.
Note: This policy is provided as a working template and should be reviewed by legal counsel before you rely on it. It is not legal advice.