Privacy policy
Updated
Scene Index is an independently operated platform based in the United Kingdom, helping people discover AI tools and workflows for game and 3D production. This policy explains how information is used on Scene Index and when you contact us.
For privacy questions or requests, contact privacy@scene-index.com.
Information we use and why
- Browsing and security. Hosting services process connection information such as IP addresses, browser details and request times to deliver pages, protect the service and investigate faults. Our interest is keeping Scene Index available and secure.
- Accounts and saved content. Where account sign-in is available, we use your email address, account identifier, chosen username, sign-in status, bookmarks, likes and creator follows to provide the account features you request. Email/password forms send credentials securely through our server to WorkOS AuthKit for authentication; Scene Index does not store or log your password. WorkOS handles password storage, email verification and password resets. If you choose an enabled social sign-in option, the provider shares basic profile and email information with WorkOS to authenticate you. Account details and saved preferences are not published as creator profiles.
- Device preferences. We store your cookie choice and, when you use them, bookmarks and other interface preferences in your browser. Account bookmarks and likes can be stored on our server so they work across devices.
- Card views and popularity. When you open a card, our service counts the view using a browser visitor identifier, stored as a hash on our server. We also use a daily hash derived from the connecting IP address to limit abuse. These first-party counts support content ranking and operate separately from Google Analytics and PostHog.
- Public source material. We collect public posts and associated creator names, handles, attribution, links, dates, engagement counts and media from sources including X, YouTube, GitHub and official websites. We use this information to summarise, categorise and connect useful game-production resources. Our legitimate interest is maintaining a useful, attributed directory. Public information can still be personal information.
- Creator directory. We curate public names, platform handles and profile links from X, YouTube and newsletters, with source-backed topics, published activities, game projects and review dates. Creator profiles remain separate from customer accounts; matching names or handles do not link them. Following a creator stores a private account preference for their indexed updates until you unfollow or delete your account. It does not follow an external account, subscribe to a channel or newsletter, or enable email notifications. You can request correction or removal using the contact above.
- Messages to us. We use the email address, message and any supporting information you send to answer questions, resolve issues and handle privacy requests. This supports our legitimate interest in running the service and, where applicable, our legal obligations.
- Optional analytics. With your consent, we measure visits and interactions and review a sample of masked sessions to understand usage, diagnose problems and improve the interface.
You can browse without an account and reject optional analytics. Email and sign-in information are needed if you choose to create an account. We do not sell personal information or use the analytics integration for personalised advertising.
Cookies and your choices
Google Analytics and PostHog stay off until you select Accept analytics. Select Reject optional to continue without it. You can change or withdraw your choice using Cookie settings at the bottom of any page. Withdrawing consent stops future optional collection; it does not erase information already collected.
Your choice is stored in this browser for 180 days, after which we ask again. Browser settings such as Do Not Track or Global Privacy Control also keep optional analytics off. If we cannot read or save your choice, optional analytics stays off.
- Necessary storage: the cookie-choice record, temporary sign-in state, secure account sessions and device preferences needed for features you request. Sign-in state expires after 10 minutes. The account cookie lasts 30 days, while application access expires after 7 days. These support the service and are separate from optional analytics.
- First-party card views:
scene_visitorlasts up to one year and lets the service avoid repeatedly counting the same card for the same browser on the same day. This current view-counting cookie is separate from the Google Analytics and PostHog choice. - Google Analytics: cookies such as
_gaand_ga_*distinguish browsers and sessions. We send page visits for the archive and tool pages after consent, without URL query strings or fragments. Advertising features are disabled. - PostHog: cookies or local storage with a
ph_prefix support analytics identifiers, session state and consent status. After consent, we record selected interactions and errors, and sample 20% of sessions for replay. Page text and input fields are masked; recording of network bodies, headers and console logs is disabled.
Google Analytics and PostHog exclude account, authentication, API, administration and privacy-policy pages. We do not send your account email or username as an analytics identity. Providers still receive technical connection and device information when their services are used.
You can also remove cookies and local storage through your browser. This may sign you out or remove bookmarks saved only on that device.
Services that process information
- Cloudflare hosts the site and database, provides delivery and security services, and routes support and privacy-contact email.
- WorkOS provides account authentication where enabled.
- Google provides optional Google Analytics, the email service used to receive enquiries, and Google sign-in when enabled and selected.
- GitHub provides GitHub sign-in when enabled and selected. This sign-in connection requests profile and email information, without repository access.
- PostHog provides optional product analytics and masked session replay. Our PostHog project uses its US service.
- Resend provides configured outgoing email delivery. Domain-level open and click tracking are disabled. A Scene Index account or privacy enquiry does not subscribe you to a newsletter.
- Logo.dev supplies tool and company logos. Loading a logo sends connection information, including your IP address and the requested logo domain, to its image service.
Some source images or media load directly from their publishers and content-delivery services. Fonts may also be served externally. These requests disclose connection information to the relevant host. Links to external sites take you to services with their own privacy practices.
We use AI-assisted processing to summarise and tag public source material. Source excerpts and media evidence may be processed through OpenAI services during this review. Summaries can be wrong; you can ask us to correct or remove information using the contact above. This content processing does not make decisions with legal or similarly significant effects about visitors.
Where information is processed
Scene Index is operated from the UK, but our providers may process information elsewhere, including the United States. A provider’s email-sending region does not mean all its data stays in that region.
Providers describe their international-transfer arrangements in their privacy notices and data-processing terms, including applicable adequacy arrangements and contractual safeguards such as standard contractual clauses and UK addenda. You can contact us for information about the arrangements relevant to your data.
How long information is kept
We retain account information and saved preferences to provide your account, and public source records while they remain relevant to the directory and its attribution. Privacy requests, corrections, ongoing security investigations and legal obligations can affect what needs to be retained.
Device bookmarks remain until you remove them or clear browser storage. The analytics choice expires after 180 days. Analytics records and recordings are subject to the retention settings of the relevant analytics service; browser identifiers may have a different lifetime from the records held by the provider.
Correspondence is kept as needed to resolve the matter and maintain a record of how it was handled. View records currently have no automatic deletion schedule. Abuse-rate-limit records are removed after their configured window: around 24 hours for sign-in buckets and 30 days for other interaction limits. Source-review files and backups may persist separately from the public site. Removing a public entry does not by itself remove every associated backup or provider record.
You can delete your account from the Account page after confirming your identity and the permanent loss of your profile, bookmarks, likes and creator follows. This removes your saved account data and requests deletion of your WorkOS sign-in account. If a provider is unavailable, the account is blocked and cleanup retries automatically. You can create a new, empty account once deletion finishes.
We keep a minimal deletion record containing the former provider user ID and deletion timestamps for 30 days after completion to prevent old requests from recreating the account. It contains no email, password or saved activity. A private deletion-status cookie lasts 24 hours. Public directory source material, unlinked analytics and provider backups are separate; contact us for requests about retained information or an export.
Your rights and requests
Depending on the circumstances, UK data-protection law gives you rights to access, correct or erase personal information, restrict processing and receive certain information in a portable form. You may withdraw analytics consent at any time using Cookie settings.
You can object to processing based on our legitimate interests, including the use of public information about you in the directory.
Email privacy@scene-index.com with your request and, for indexed content, the relevant source or Scene Index link. We may need enough information to verify that the request concerns you. Please avoid sending unnecessary sensitive information.
You can also raise a concern with the UK Information Commissioner’s Office (ICO).
Changes to this policy
We will update this page when our use of information changes and show the revision date above. If a change requires a new consent choice, we will ask for it.