Legal

Cookie Notice

Version 1.0
Effective date: September 8, 2026
Last updated: October 9, 2026

This notice is part of the Cutvey Privacy Policy. It explains the cookies and similar technologies Cutvey LLC uses, by category and purpose, across our web app, our marketing and product websites, our native apps and our email.

We have kept this short because there is very little to report. Cutvey puts no advertising cookies, no third-party analytics cookies and no cross-site tracking on any page we build, anywhere. That is a product decision, not a temporary state. A studio can embed something of its own choosing in a page it sends to its own client, and section 1 says what that means.

1. The web app (including custom domains and the client and crew portals)

Strictly necessary cookies only. Without them the app cannot sign you in or keep you safe.

Cookie Purpose Type Lifetime
Session cookie (cutvey_session, and cutvey_client in a studio's client portal)Keeps you signed in to your workspace, or to a studio's client portal. Signed, HTTP-only, and revocable from SettingsStrictly necessary, first partyUntil you sign out, or the session expires
Sign-in and device cookieRemembers a device you marked as trusted, so you are not asked for a code every timeStrictly necessary, first partyUntil you revoke the device
Security and anti-abuse cookieCross-site request forgery protection and rate limiting, and preventing repeat free trials. For the last of these, a browser that starts a free trial of the Service is given a random identifier (cutvey_tb). It holds nothing about you, it is HTTP-only, and it is never sent to anyone else. It is not set for visitors we believe to be in the European Economic Area, the United Kingdom or Switzerland. Where a workspace signs in through its own single sign-on, the browser that starts a sign-in is given a random value (cutvey_sso_n) for up to ten minutes, so that only that browser can finish itStrictly necessary, first partySession, or short-lived. The free trial identifier is kept for up to 2 years
Preference storageRemembers a choice you made in the app, such as the columns you chose for a list or the view you last used. Kept in your browser's local or session storage, not sent to our servers. We store it only because you chose it, and storing it is the only way to give you what you asked for. Two more values are kept in session storage, are not sent to our servers either, and record no choice of yours. They are there to keep the app working: if a page fails because the app was updated while you had it open, the time of the one automatic reload is kept so that the page cannot reload in a loop, and in a signed-in workspace that is close to or over its storage allowance, the fact that the warning was shown is kept so that it is shown onceStrictly necessary, first partyUntil you clear your browser data. The two session values until you close the tab
Preference cookies (cutvey-theme, cutvey_lang, cutvey-board-layout, cutvey_files_sort)Four settings are kept in a cookie, not only in local storage, so that our servers can draw the page the right way from its first moment instead of changing it after it loads: the light or dark theme the app is shown in, the language it is shown to you in, the layout you chose for a board, and the order you sorted Files in. Each holds that one setting and nothing about you. Being cookies, they are sent to our servers with each request, and to nobody elseStrictly necessary, first party, a record of a settingOne year. The Files sort order lasts until you close your browser or sign in again
Browser storage that is sent to usA few things kept in your browser's storage do reach our servers, each only so that the page can do what you asked of it. None of them is made by opening a page. A review link keeps the name you type for your notes (cutvey_reviewer_name, in local storage) so that you need not type it again. It is kept from the moment you type it, and it reaches us only as part of something you post, such as a note. A roadmap page a studio shares keeps nothing until you vote. Your first vote makes a random value (cutvey_voter, in local storage), which is sent with each vote so that a vote is counted once, and the list of the items you voted for (cutvey_voted) is kept beside it and is not sent. While a large upload is in progress, a reference to it is kept so that it can carry on after an interruption; it is sent with the upload and removed when the upload finishesStrictly necessary, first partyThe upload reference until the upload finishes. The others until you clear your browser data
Bot-protection token on the signup formSet by Cloudflare, Inc. (Turnstile) on our behalf, on the form where you create a Cutvey account, to confirm that a human, not a script, is signing up. The same check, on the same terms, as on the forms described in section 2Strictly necessary, third party, for securityMinutes, tied to the form submission
Referral record (cutvey_ref)Set only when you arrive through another workspace's referral link. It holds that link's referral code and nothing about you, so that if you sign up we can give you the longer free trial the link offers and credit the workspace that referred you. HTTP-only, so no script on the page can read itFirst party, set only because you followed the link30 days
Privacy signal record (cutvey_gpc)Set only when your browser sends the Global Privacy Control signal. It holds the value 1 and nothing else, and it exists so that we count your signal once rather than on every page. Section 18 of the Privacy Policy says what we do with the signalStrictly necessary, first party, a record of a choice you madeOne year
Password cookie on a page a studio sent you (cutvey_dpw_ for a delivery, cutvey_upw_ for an upload link, cutvey_fpw_ for a shared file, cutvey_gpin_ for a gallery and cutvey_gdpin_ for a gallery's downloads, cutvey_rpc_ for a review link, cutvey_rvpw_ for a review package and cutvey_pp_ for a proposal, each followed by a reference to that page)Set only after you type the password, passcode or PIN a studio put on a page it sent you, so that you are not asked for it on every visit. It holds a signed value tied to that one page and to the password in force, and nothing about you. It stops working when the studio changes the password. HTTP-only, so no script on the page can read itStrictly necessary, first party7 days for a delivery, an upload link or a shared file. 30 days for the others
Confirmed email cookie (cutvey_share)Set only after you confirm your email address with a one-time code we email you, on a delivery or a shared file that a studio limited to the people it invited. It holds the address you confirmed and an expiry time, signed so that neither can be altered, so that those pages, and any other delivery or shared file the same address was invited to, open for you in this browser without a new code each time. It does not sign you in to anything else. HTTP-only, so no script on the page can read itStrictly necessary, first party7 days
Reviewer key on a review link (cutvey_rgk_, followed by a reference to the cut)Not set by opening or watching a cut. It is set the first time you post something on a cut a studio sent you for review: a note, a reply, a reaction, or a note sent with a request for changes. It holds a random value and nothing about you, so that what you posted in this browser stays yours to change, and so that, while you are on the page, the list of who is watching can show the name you put on your latest note. HTTP-only, so no script on the page can read itStrictly necessary, first party180 days
Visitor key in a gallery (cutvey_gvk_, followed by a reference to the gallery)Not set by opening or looking at a gallery. It is set the first time you do one of these things in a gallery a studio sent you: mark a favourite, make a list, leave a note on a photo, register with your name and email address, or download from a gallery whose studio limits how many downloads each visitor may take. It holds a random value and nothing about you. Your favourites, lists, selections and notes are kept against that value so that they stay together and stay yours to change, a download limit is counted against it, and if you register, your name and address are attached to it. Once it is set, the studio's record of your later visits to that gallery and of your downloads from it is kept against it too. Until it is set, a visit is recorded for the studio as a count, the time, and how long the page stayed open, with nothing stored on your device and nothing that identifies your browser. HTTP-only, so no script on the page can read itStrictly necessary, first partyOne year
Gallery registration cookie (cutvey_gvis_, followed by a reference to the gallery)Set only after you give your name and email address to open a gallery whose studio asks visitors to register, so that you are not asked again. It holds a signed value tied to that gallery. Your name and address are kept in the studio's workspace, not in the cookie. HTTP-only, so no script on the page can read itStrictly necessary, first party90 days
Portal studio cookie (cutvey_portal_org)Set when you sign in to a studio's client portal. It holds a reference to that studio and nothing about you, and it opens nothing: it is there so that the next time you come to sign in, you are shown that studio's own sign-in page. HTTP-only, so no script on the page can read itStrictly necessary, first partyOne year
Tracking answer cookie (cutvey_track_ack_ws)Set only when we asked whether a studio may see that you opened and clicked its email, which we ask where the law where you are requires it, and you answered. We ask for each studio separately, the first time you open a tracked link in one of that studio's emails, and an answer you gave to one studio is never used for another. For each studio whose question you answered, the cookie holds a short one-way marker that stands for that studio and does not name it, your answer, yes or no, and the day you answered, and nothing else. It remembers at most 24 studios: when there are more, the oldest answer is dropped, and that studio asks again. It is sent only to the addresses that count an open or a click, so that each studio asks you once in that browser. If you answered no, your address is also put on that studio's list of people it emails without tracking. To change your answer, ask the studio, which can add your address to that list or take it off. You can also clear this cookie: a studio then asks you again on the next tracked link in one of its emails you open, unless your address is on that studio's list, in which case nothing is tracked and there is nothing to ask. An earlier cookie that held one answer for every studio (cutvey_track_ack) is no longer read, and it is removed when your browser sends it. HTTP-only, so no script on the page can read itStrictly necessary, first party, a record of a choice you madeEach answer lapses one year after the day you gave it. The cookie is kept for up to one year after your latest answer
Signing station cookie (cutvey_kiosk)Set only when a member of a studio's team turns a device into a signing station, so that people on set can sign a release on it one after another. It holds signed references to the workspace, the project, the release and the team member who started it, and the time it started, and it keeps the device on the signing screen until that team member ends it with a code we email them. Nothing about the people who sign is kept in it. HTTP-only, so no script on the page can read itStrictly necessary, first party12 hours
Support return cookie (cutvey_admin_return)Set only in the browser of a member of Cutvey's own staff, while they view a workspace as one of its users to help with a support request, so that they are returned to their own account afterwards. It is never set in a customer's or a visitor's browser. HTTP-onlyStrictly necessary, first partyUp to 4 hours

These are strictly necessary to deliver the service you asked for. Under the EU ePrivacy rules and the UK Privacy and Electronic Communications Regulations they do not require consent, which is why you do not see a cookie consent banner in the app.

We class nothing as strictly necessary that we would not defend as strictly necessary. Everything above is either what signs you in, what keeps the app safe and working, or what remembers a choice you actively made. If we ever store or read anything on your device for another reason, including measurement, we will ask you first and give you a way to change your answer.

Video in a page a studio sends you. Cutvey's own video player is served from our own systems and reports to nobody but us, and we put no third party pixel, tag or software development kit on a page where Cutvey plays video. A studio can also paste a link to a video hosted somewhere else, for example on a video sharing site, into a proposal or another page it sends you. Where it does, the page shows you a still image and the name of the company whose player it is, and that player loads only after you choose to play it. Until you do, nothing about you reaches that company and it sets nothing on your device. When you press play, that company sees the request and can set its own cookies under its own privacy policy and terms. That player is the studio's choice, not ours. We do not choose those sites, we send them nothing about you, and we receive nothing back.

2. The marketing and product websites

Our public websites are cutvey.com, cutveyoffload.com, cutveymeter.com, cutveyviewfinder.com, cutveyteleprompter.com and cutveysetrush.com, all listed at https://cutvey.com/legal. They set no analytics cookies, no advertising cookies and no third-party tracking of any kind. We put no advertising or analytics pixel, tag or software development kit on any page. We do not use Google Analytics, Meta pixels, LinkedIn Insight, TikTok pixels or anything comparable.

The only cookies you may meet come from the infrastructure that keeps the sites up and keeps bots off our forms:

Cookie Set by Purpose Lifetime
Bot-protection tokenCloudflare, Inc. (Turnstile), on our behalfConfirms that a human, not a bot, is submitting a contact, support or lead form. Cloudflare states that Turnstile does not use this data for advertising and does not track users across sites. We do not receive an advertising profile or a cross-site identifier from it, and we would not use oneMinutes, tied to the form submission
Infrastructure cookie (for example __cf_bm)Cloudflare, Inc.Tells human traffic from automated traffic so the site stays available. Strictly necessary for securityUp to 30 minutes

Lead forms in a studio's client portal. A studio's own lead-capture form, served through Cutvey, is protected the same way, using that studio's own configured keys. The studio is the controller of what the form collects.

3. The native apps

This section applies to every Cutvey native application, current and future. The Privacy Policy's product table lists them.

Native apps do not use cookies. They store what they need on your device and, where you turn it on, in your own iCloud. In practice what an app keeps on the device is some of: your settings, your own content, a sign-in token if you signed in, the record of the analytics answer you gave on first run, and a cache of what you last worked on. Each App's row in section 4 of the Privacy Policy says which of these apply to it. None of it is shared with anyone else, and deleting the app removes it from the device. Apps contain no advertising SDKs, no attribution SDKs and no cross-site or cross-app tracking technology. No app contains a third party crash reporting or analytics component. Crash and diagnostic reports go to an endpoint we operate, and we forward them from our own servers to the provider named on our subprocessor list, which may use them only to provide that service to us.

Usage data and crash reports in the apps follow section 8 of the Privacy Policy. Optional usage data and crash reports are on by default where the law allows a default. In the European Economic Area, the United Kingdom, Switzerland, throughout Canada, anywhere else whose law requires your agreement before an app reads or stores this kind of information on your device, and wherever we cannot tell which of these you are in, every app asks you on first run and collects nothing until you agree. Wherever you are, you can change the answer at any time in the App's Settings. Because there is no advertising or attribution technology in any app, you do not see an App Tracking Transparency prompt. The permission we ask for is about improving our own software, not about following you anywhere else.

4. Email

Our own email to you. Sign-in codes, receipts, invoices, notifications and security alerts record only delivery and bounce events, because we need to know the message arrived. They carry no tracking pixel.

Our product announcements do record opens and link clicks, so we can tell whether an announcement was worth sending. Measuring an open means loading a small image from our servers, which counts as access to your device under European and UK rules. So we ask for your agreement to that measurement when you subscribe, if you are in the European Economic Area, the United Kingdom or Switzerland. We do not measure opens for anyone who has not agreed. To withdraw, use the preference link in any announcement, or email contact@cutvey.com. We record your answer against your email address and apply it to every later message. Every announcement also carries a one-click unsubscribe.

Email a studio sends through Cutvey. A proposal, invoice, call sheet, release request or gallery link that a studio sends to its own client, or to the crew and cast it works with, can carry a small tracking image and click-tracked links, so the studio can tell whether it was opened. An email that carries a one-time code never does. The studio decides whether to use tracking and on whom. Our Terms require the studio to disclose it to recipients where its law requires, and to honor a recipient who asks to be emailed without tracking. We build and host the measurement, we secure the data, and we provide the off switch. Every workspace can turn tracking off for all of its outgoing mail in Settings, off for a single message when it is sent, and off for an individual recipient who asks, whoever that is: a client, a crew or cast member, somebody signing a release, or anyone else it emails. The studio adds that person's address to a list in its Settings, and no email it sends to that address through Cutvey is tracked after that. The engagement data stays in the studio's workspace and we never use it for our own marketing.

If you received such an email and do not want the open counted, most email clients can block remote images, which stops the image from loading. Blocking images does not affect link clicks: if you click a link in the message, the sender can still see that you did. To stop it entirely, ask the studio that sent it to email you without tracking. Where we ask you ourselves, because the law where you are requires it, and you answer no, that answer puts your address on that studio's list without your having to ask.

5. Controlling cookies

You can delete or block cookies in your browser settings. Blocking the strictly necessary cookies in section 1 stops you from signing in to the app, which is the whole of what they do.

Because we set nothing beyond strictly necessary on the web, there is no consent preference for you to manage there and no "reject non-essential cookies" button to press. Our native apps are different: where the law requires it they ask you on first run about usage data and crash reporting, because that involves reading information from your device, and wherever you are you control the answer in the App's Settings. If the web app ever needs the same question asked, we will ask it there too.

6. Changes and contact

We update this notice whenever the technologies we use change, and the "Last updated" date above tells you when. Material changes are notified as described in section 20 of the Privacy Policy. When this notice changes, the version it replaces will be kept at https://cutvey.com/legal/archive. How we number versions, and what counts as a change to a table row rather than to this document, is set out in section 20 of the Privacy Policy and applies to every Cutvey legal document.

Questions: contact@cutvey.com.