Table of Contents
1 Information We Collect and How We Collect It
My Content Tools LLC limits data collection to the absolute minimum required to operate our B2B SaaS platform securely. We collect account credentials, professional production availability parameters, and anonymized subscription statuses.
2 Bifurcated Identity Processing & 2257 Firewall
To satisfy cross-border privacy mandates and data minimization principles, My Content Tools LLC enforces an absolute, structural firewall between platform access data and federal compliance records. These two pipelines are never commingled:
Platform Access (The Verify-and-Purge Gate): To verify legal majority (18+) for directory authentication, biometric and ID data is transmitted directly from the user's local device to our third-party Verification Provider. This data bypasses our servers entirely. The provider destroys the raw data immediately upon generation of an anonymized access token.
Federal Compliance (Software Infrastructure): My Content Tools LLC provides encrypted database infrastructure (the software vault) to assist independent studios in satisfying statutory recordkeeping mandates under 18 U.S.C. § 2257. Fully unredacted ID records captured during a content production workflow are encrypted and held in this isolated legal vault for seven (7) years post-production, as mandated by 28 C.F.R. § 75.2. The independent studio or creator utilizing the software remains the sole statutory Custodian of Records; My Content Tools LLC acts strictly as a secure infrastructure provider.
A user's public-facing directory profile contains strictly categorical, pre-approved commercial data and is structurally isolated from any raw compliance records held in the 2257 vault.
2a Data Handling & Security
This section describes the desktop application's data path, and is reproduced verbatim inside the application itself so the two cannot drift apart.
1. Local Encryption and Storage. Your compliance data, performer records, and identity documents are stored entirely locally on your device within an AES-256-GCM encrypted vault. We do not receive, host, or possess your videos, revenue figures, or proprietary content. All AI features operate strictly via local inference.
2. Cross-Platform Vault Security. Cryptographic keys securing your local vault are managed through your operating system’s native secure credential infrastructure (including the macOS Keychain and Windows secure storage protocols). To guarantee strict isolation and zero-knowledge security across all operating systems, vault access is additionally guarded by an independent, user-generated Custodian Passphrase and a printed recovery code. Our company possesses no mechanism to bypass this passphrase or decrypt your local vault.
3. Mobile Synchronization and Cloud Infrastructure. For users utilizing the companion mobile application for on-set capture, performer details, identification images, and signatures are temporarily routed through our secure cloud backend to synchronize with your desktop vault. Copies of these records remain in secure cloud storage until their access links are explicitly revoked by the user or the system; bringing a document into the local encrypted vault does not automatically destroy the upstream cloud copy pending that revocation.
3 Legal Compliance Workflows & Mandatory Reporting
We strictly prohibit the transmission or storage of illegal content. In the event that suspected violations of federal law (including Child Sexual Abuse Material) are reported to us or otherwise come to our actual knowledge, the associated account will be immediately terminated. We comply with all mandatory reporting obligations to the National Center for Missing & Exploited Children (NCMEC) and will preserve associated user data, metadata, and communication logs for 90 days, or as otherwise requested by law enforcement pursuant to 18 U.S.C. § 2258A.
4 Payment Processing & Financial Data Isolation
My Content Tools LLC does not collect, process, transmit, or store payment card numbers, bank account details, or raw financial data. All subscription payments and financial transactions are securely outsourced to a PCI-compliant, third-party payment processor acting as Merchant of Record. When initiating a transaction, your payment data is transmitted directly from your browser to that processor via a securely hosted checkout environment operated by them, not by us. The processors we currently use are identified in our Payment Partners schedule, which is maintained outside this Policy so that it can be kept current without altering this agreement. My Content Tools LLC receives only subscription status webhooks (for example: active, canceled, renewed) and a transaction reference identifier, used to grant or revoke platform access.
5 Data Security & Third-Party Sharing
We utilize industry-standard encryption to protect your data in transit and at rest. We do not sell your personal data to third parties. We share data only with strictly vetted infrastructure sub-processors (such as our payment gateway and age-verification providers) solely to the extent necessary to deliver the Platform functionality.
6 Third-Party Integrations
My Content Tools offers optional integrations with third-party services that you may choose to connect (for example, accounting software such as QuickBooks/Intuit). When you connect such a service and direct us to sync data, you authorize us to transmit the relevant records — which may include personal information such as names, contact details, addresses, and tax identification numbers (such as SSNs or EINs) — to that third-party service on your behalf. This transmission occurs at your direction and is subject to the third party’s own privacy policy and terms. You are responsible for your use of connected services.
My Content Tools, LLC
Privacy inquiries: privacy@mycontenttools.com
General support: support@mycontenttools.com
St. Petersburg, Florida