Privacy Policy
This Privacy Policy explains how Sume, Inc. ("Sume", "we", "us", or "our") collects, uses, shares, and protects information when you use Sume websites, the Sume dashboard, Sume APIs, API keys, documentation, media generation services, and related account or support services (together, the "Services").
Last updated: July 3, 2026
Information we collect
- Account and authentication information, such as name, email address, user identifiers, organization or workspace details, and sign-in method.
- Google Sign-In information, if you choose Google OAuth, such as basic profile and email information needed to authenticate your account.
- API and service-account information, such as API key metadata, key prefixes, scopes, dashboard settings, request identifiers, job identifiers, webhook URLs, usage records, and rate-limit state.
- Content you submit to the Services, such as prompts, scripts, product images, uploaded media, reference files, URLs, avatar inputs, and other materials used for generation workflows.
- Generated outputs and related metadata, such as media artifacts, job status, result metadata, usage events, and public-safe URLs or asset records.
- Technical and security information, such as IP address, user agent, device and browser information, log events, diagnostics, crash reports, abuse signals, and product analytics.
- Billing information, such as credit purchases, usage charges, invoices, subscription status, payment status, and billing contact details. Payment card details are handled by payment processors and are not stored by Sume.
- Cookies, session storage, local storage, and similar technologies used to keep you signed in, remember preferences, secure the Services, measure usage, and improve product experience.
How we use information
- To authenticate users, maintain sessions, and secure accounts.
- To create and manage API keys, service accounts, workspaces, jobs, generated outputs, usage records, support requests, and dashboard features.
- To process generation requests and deliver media outputs through Sume APIs and dashboard workflows.
- To operate, monitor, debug, secure, and improve Sume websites, dashboard, APIs, and media generation services.
- To enforce rate limits, prevent abuse, investigate security issues, and protect users and infrastructure.
- To process payments, maintain credit balances, produce invoices, and administer billing or refunds where applicable.
- To provide support, communicate service updates, send administrative notices, and comply with legal obligations.
Google user data
Sume uses Google OAuth through Clerk for sign-in. The current sign-in flow requests only basic profile and email information as needed to identify you, secure your account, and operate your dashboard session. Sume does not request access to Gmail, Google Drive, Calendar, Contacts, Docs, Sheets, Slides, or other Google Workspace content. Sume does not sell Google user data or use it to train generalized AI models. Sume's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
We use service providers to operate the platform, including authentication, hosting, databases, analytics, customer support, payments, infrastructure, media storage and delivery, email, and AI generation providers. These providers may process information only as needed to provide services to Sume, comply with legal obligations, or as otherwise permitted by law. We do not disclose confidential provider routing or implementation details in public product responses.
Generation inputs and outputs
Generation workflows may require Sume or its providers to process prompts, scripts, product images, uploaded files, media URLs, references, generated outputs, and operational metadata. Do not submit sensitive personal information unless it is necessary for your authorized use of the Services. API inputs and outputs may be retained as needed to provide the Services, reproduce or debug issues, enforce policies, maintain billing and usage records, and meet legal obligations.
When we share information
- With service providers that help us operate, secure, bill, support, analyze, or improve the Services.
- With your workspace members or administrators, if you use the Services as part of an organization or team account.
- With payment processors and financial service providers for billing, credits, invoices, tax, fraud prevention, and dispute handling.
- When required by law, legal process, or to protect the rights, safety, security, and integrity of Sume, users, providers, or the public.
- In connection with a merger, financing, acquisition, reorganization, or similar corporate transaction, subject to appropriate safeguards.
Security and retention
We use administrative, technical, and organizational safeguards designed to protect information, including access controls and encryption in transit. No method of transmission or storage is perfectly secure. We retain information for as long as needed to provide the Services, maintain account and usage history, comply with legal obligations, resolve disputes, enforce agreements, investigate abuse, and maintain security. Retention periods may vary based on the type of data and the context in which it is processed.
Your choices
You may contact Sume to request access, correction, deletion, or export of personal information, subject to applicable law and security requirements. You can also manage account access through the dashboard and may revoke API keys from the API key page.
International use
Sume may process and store information in the United States and other countries where Sume or its service providers operate. These countries may have data protection laws that differ from those in your location.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the date above and provide additional notice where required by law.
Contact
Questions about this policy can be sent to dev@sume.com. See also our About page and Terms of Service.