Last updated October 5, 2026
Privacy Policy
Effective Date: October 5, 2026 | Last Updated: October 5, 2026 Thomas Abram, LLC | privacy@abram.network
1. Overview
Thomas Abram, LLC ("ABRAM," "we," "us," or "our") operates ABRAM, production management software for film, video, and other creative productions. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Platform.
We comply with applicable privacy laws, including the GDPR (EU/EEA), UK GDPR, CCPA (California), and applicable US state privacy laws.
2. Information We Collect
2.1 Information You Provide
- Account information: Name, email address, the account type you choose during onboarding, profile photo.
- Professional profile: Skills, experience, portfolio links, availability, rates, location, and, where your organization records them, employment details such as title, department, and weekly capacity.
- Files and documents: Documents, pictures, and other files you upload, such as scripts, briefs, certifications, and portfolio materials. If you choose to import a resume into your profile, its text is processed by AI to extract your skills (Section 4.1). Video review of cuts works from a link to a video hosted on Vimeo.
- Project information: Project briefs, scripts, deliverables, work orders, schedules, call sheets, run-of-shows, wrap reports, budgets, quotes, and expenses.
- Call transcripts: Transcripts of client calls or meetings that you paste or upload so that ABRAM can summarize them and suggest changes. ABRAM does not record calls. A transcript is visible only to people who can manage the project, and it is sent to our AI provider only when one of them asks ABRAM to read it.
- Hours and attendance: Timesheet entries, hours worked, and check-ins you record in ABRAM or through Slack. ABRAM does not collect your device's location.
- Financial information: Bank account details (via Stripe), billing information, billing address (used to calculate applicable sales tax on subscription purchases), invoices, transaction records. Payments between users are processed on the payment recipient's own Stripe account; identity and banking details you provide during Stripe onboarding are collected by Stripe as the account provider, not by ABRAM.
- Communications: Messages, comments, invitations, and notifications sent through the Platform, including conversations with Clients and comments left on deliverables or video cuts.
- Imported records: Projects, tasks, and related records you bring in from a spreadsheet file or from another project management tool you choose to import from.
2.2 Information Collected Automatically
- Usage data: Pages visited, features used, time spent, click patterns.
- Device & technical data: IP address, browser type, operating system, device identifiers.
- Calendar data: Events from calendar feeds (calendar links) you choose to subscribe to, which ABRAM fetches periodically to show your availability. ABRAM also publishes a private calendar feed of your own schedule, at a link only you hold, if you choose to use it.
- Product usage events: Records of which features and pages you use in the signed-in Platform, tied to your account and organization and a per-session identifier, kept by ABRAM itself and not sent to an analytics company.
- Log data: Error logs and API call logs processed via Sentry for error monitoring.
2.3 Log Data and Diagnostics (Crash Reports)
When you encounter an error or crash while using the Platform, we automatically collect diagnostic information ("Crash Reports"). This includes your web browser type, operating system, preferred language, screen dimensions, the exact page URL you were visiting, the error message, and a technical stack trace. If you are logged into your account, this diagnostic data may be associated with your User ID to help our team debug and resolve the issue.
Crash Report data may also include React component tree information captured at the time of the error, which could in limited circumstances contain data you had entered immediately before the crash. We process this data solely to identify, diagnose, and resolve technical issues. This data is processed under Legitimate Interest (GDPR Article 6(1)(f)) as described in Section 3.
2.4 Information From Third Parties
- WorkOS: Authentication identity, organization membership, SSO session data.
- Stripe: Payment confirmation, payout status, account verification status.
- Frame.io: Project and media asset metadata when Frame.io is connected.
- Slack: Workspace identity when Slack notifications are enabled, and check-ins or replies you send to ABRAM from Slack.
- Jira, Asana, and monday.com: When your organization connects one of these tools to import work, the projects, tasks, assignees, and related details it chooses to import. People who appear as assignees are added as draft crew contacts, and nothing is sent to them. For Jira, we also periodically check with Atlassian whether imported Jira accounts have been closed or changed, so that we can erase or update that personal data as Atlassian requires.
- Calendar feeds: The events in any calendar link you subscribe to.
2.5 Marketing Site, Events, and Digital Contact Cards
Our marketing site at abram.network is a separate surface from the Platform, and some of what we collect there works differently.
Digital contact cards and conference capture. ABRAM staff use printed codes at conferences and industry events. Scanning one opens a digital contact card at an address beginning /c/. When a card is opened we record that the scan happened, together with the device type, browser family, operating system, referring page, and an identifier derived from your IP address and browser user agent by a one-way salted hash that changes daily. We do not store your raw IP address for these scans. The hash lets us tell repeat views apart from distinct ones without keeping data that identifies you.
Contact details you choose to give us. A contact card includes an optional form. If you submit it, the name, email address, and any other details you enter are stored as a prospect record in ABRAM's own customer relationship management (CRM) system, along with the event and the staff member whose card you scanned. Submitting the form is voluntary, and nothing about the card requires it.
The contact card email. Submitting the form triggers one email to the address you provide. It contains the contact details of the ABRAM staff member whose card you scanned, as an attached contact file (vCard), so you can save them. This is a one-time response to your own submission and does not add you to any mailing list.
Marketing site analytics. The marketing site uses Google Analytics and Vercel Analytics, both subject to the cookie consent choices described in Section 6. The marketing site also hosts product demonstration videos streamed by Mux, which receives playback and delivery data as described in Section 5.1.
2.6 Information an Organization Provides About You
You may appear in ABRAM without having an account, because an organization that uses ABRAM has added you. For example:
- Crew contacts: An organization may add you to its crew roster or to a production with your name, contact details, role, rates, availability, and the hours and schedule you work on its productions.
- Client contacts: An organization may record you as a contact for one of its Clients, together with the quotes, invoices, approvals, call transcripts, and messages that relate to the work it does for you.
- Equipment borrowers: An organization that lends equipment may record your name and email address and, where a school records them, your student ID number and course codes.
- Client portal visitors: If an organization shares a client portal with you, you open it from a secure link and, depending on how the organization set it up, either verify your email address with a one-time code or enter your name and email address. You do not need an ABRAM account. We record the email address and any name you enter, whether the address was verified, and when you visited, and we show that visit record to the organization that shared the portal. Comments, approvals, and other activity you leave in the portal are stored with that organization's records. If you view or sign a quote, we record your IP address, your browser's user agent, and the e-signature consent text you agreed to, as evidence of the signature.
For this information the organization is the data controller and ABRAM processes it on the organization's behalf, as described in Section 17 of the Terms of Use. If you want to access, correct, or delete it, please contact the organization first. You may also contact privacy@abram.network, and we will help you or pass your request to the organization.
3. How We Use Your Information
We use your information for the following purposes. Where ABRAM relies on legitimate interest as a legal basis, we have conducted and documented a Legitimate Interest Assessment (LIA) confirming our interests are not overridden by your rights. You may request a copy by contacting privacy@abram.network.
| Purpose | Legal Basis (GDPR) |
|---|---|
| Operate and provide the Platform | Contractual necessity |
| Process payments and payouts | Contractual necessity |
| Send transactional emails and notifications | Contractual necessity |
| AI features you use, such as brief and script analysis, call reading, crew suggestions, and document drafting | Contractual necessity / Legitimate interest |
| Train and improve AI models | Separate opt-in consent (NOT bundled with Terms) |
| Calendar sync and scheduling features | Consent (at integration connection) |
| Third-party integrations (Frame.io, Slack, Jira, Asana, monday.com) | Consent (at integration connection) |
| Monitor for fraud and security threats | Legitimate interest (LIA on file) |
| Diagnostics, crash reports, error monitoring | Legitimate interest — Art. 6(1)(f) GDPR (LIA on file) |
| Analytics and Platform improvement | Legitimate interest (LIA on file) |
| Maintain prospect and customer relationship records, including records created from event contact cards | Legitimate interest (LIA on file) |
| Send marketing email | Separate opt-in consent (never bundled with account creation) |
| Comply with legal obligations | Legal obligation |
4. AI & Automated Processing
ABRAM uses artificial intelligence and automated processing as core functions of the Platform.
4.1 What We Process With AI
Your data may be processed by AI systems to: analyze project briefs, intake requests, and scripts; read call transcripts you provide and summarize decisions, follow-ups, and changes to scope or price; suggest people for open roles on a production; extract skills from a resume you choose to import; generate call sheets, run-of-shows, schedules, and project summaries; power the ABRAM AI Assistant; and index documents into your organization's knowledge base.
Generative AI processing is performed by Anthropic, PBC (Section 5.1). To make documents searchable, ABRAM also creates numerical representations (embeddings) of document text using an open-source model that runs inside our database provider's infrastructure, so that step does not send your content to an additional company. An organization can switch AI features off for its workspace.
4.2 Web Search Within AI Features
Some AI features can search the public web to answer a request. Where that happens, a search query derived from what you asked is sent to our AI provider, which performs the search and returns results to the feature. This means text derived from your request leaves the Platform for the purpose of running that search. The query is derived from your request rather than copied from your stored records, and web search is used only where the feature needs current public information to answer you.
4.3 Internal Use of AI Over Business Records
ABRAM staff use AI tooling over ABRAM's own business records, including the CRM described in Section 5.6, for tasks such as searching, summarizing, and drafting. That processing runs through the same AI provider and under the same terms described in Section 5.1, and it is limited to what the individual staff member is already permitted to see. It does not extend to your Platform account contents or to the Organization Brain. Separately, ABRAM uses automated AI tooling, running on GitHub, Inc.'s infrastructure and the same AI provider, to triage the error reports described in Section 2.3 so that bugs can be fixed. Those reports can contain limited personal data, such as a User ID or the page you were on.
4.4 Organization Brain (Private Organizational Knowledge)
The Organization Brain is a private, organization-specific knowledge base. Data uploaded to the Organization Brain:
- is not shared with other users or organizations;
- is never used to train ABRAM's shared AI models regardless of your AI training consent setting; and
- is stored and processed solely to power AI features within your organization's account.
4.5 Automated Decision-Making & Your Rights (GDPR Article 22)
While ABRAM's crew suggestion and recommendation features involve automated processing, final hiring and engagement decisions are made by human users. If you believe an automated process has significantly and adversely affected you, you may contact legal@abram.network to request human review of the relevant automated output. We will respond to human review requests within 30 days.
5. Third-Party Integrations & Data Sharing
5.1 Service Providers and Sub-processors
We share your data with the following categories of third parties. Each of the providers below offers data processing terms addressing GDPR Article 28, which are incorporated into their standard service agreements and which apply to ABRAM's use of their services. Where a provider requires a separately executed Data Processing Agreement or Standard Contractual Clauses, we complete that step before the provider is used in production. You may ask which arrangement applies to a specific provider by contacting privacy@abram.network.
| Provider | What We Share | Why |
|---|---|---|
| Vercel Inc. | All request data transiting the Platform and the marketing site, including IP address and request headers; usage and page-view data via Vercel Analytics | Application hosting, serverless compute, and site analytics for both surfaces |
| Supabase Inc. | All data stored by the Platform and the marketing site, including account, project, and CRM records | Database, storage, and authentication infrastructure for both surfaces |
| Stripe | Payment info, transaction data, payout details | Payment processing & payouts |
| WorkOS | User identity, organization data, and the access tokens for integrations you connect (such as Frame.io, Jira, Asana, and monday.com) | Authentication, SSO, and secure storage of integration connections |
| Sentry (Functional Software, Inc.) | Error logs, stack traces, browser/device info, User ID (where logged in) | Error monitoring and crash diagnostics |
| Mux Inc. | Video playback and delivery data, including IP address and player metrics, for demonstration videos on the marketing site | Video hosting and streaming |
| Frame.io | Project IDs, media file references | Video review collaboration |
| Slack | Name, email address (to link your Slack identity), notification content, check-ins; for ABRAM's own internal workspace, new-signup notices (name, email, account type) and error alerts | Slack notifications and check-ins when connected; ABRAM's internal operations |
| Atlassian (Jira), Asana, monday.com | Requests to read the projects and tasks your organization chooses to import; for Atlassian, the identifiers of imported Jira accounts, for its personal data reporting process | Project import, only when connected |
| Resend | Email address, email content | Transactional email delivery, including client portal verification codes and data export links |
| Anthropic, PBC | User inputs and context passed through AI features, including search queries derived from your requests where an AI feature searches the web (Section 4.2), and ABRAM business records accessed by staff AI tooling (Section 4.3) | AI inference for Platform features |
| Google Analytics | Usage data, page views, device & browser metadata | Marketing site traffic measurement & analytics |
| GitHub, Inc. | Platform error reports processed by ABRAM's automated error-triage tooling (Section 4.3) | Internal engineering operations |
The current authoritative list, including the region each provider operates in, is maintained at /subprocessors.
Embedded content. Some pages load content directly from another company's servers, which then receives your IP address and browser information and may set its own cookies under its own privacy policy. Video cuts in a client portal or on a link page play in Vimeo's embedded player, served by Vimeo.com, Inc. Public link pages may also load thumbnails from YouTube and fonts from Google Fonts. Where a person has no profile photo, ABRAM may display a placeholder image generated from their initials by an outside avatar service.
Vercel and Supabase are infrastructure providers rather than optional integrations. Because they host and store the Platform and the marketing site, data you give us necessarily passes through and rests on their systems, and this cannot be switched off while continuing to use ABRAM.
Data shared with Anthropic, PBC is processed securely via their developer API. In accordance with Anthropic's commercial terms, data sent via the API is not used to train or improve their models, is stored securely, and is deleted in accordance with their data retention policies.
Sentry's privacy policy is available at sentry.io/privacy. Anthropic's privacy policy is available at anthropic.com/privacy. Stripe's privacy policy is available at stripe.com/privacy. Adobe/Frame.io's privacy policy is available at adobe.com/privacy. Slack's privacy policy is available at slack.com/trust/privacy/policy. Vimeo's privacy policy is available at vimeo.com/privacy. Use of these integrations is subject to the respective third parties' privacy policies and terms of service, and we encourage you to review them before connecting your accounts.
5.2 Google API Services User Data Policy Compliance
ABRAM Network’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5.3 Between Users
Certain profile information (name, skills, availability, profile photo, professional experience) is visible to the other members of organizations you belong to, and to people working on the same productions as you, for the purpose of crewing and collaboration. Rates are shown only to people with permission to view financial data. An organization decides what its Clients can see in a client portal, and nothing is shared there until the organization shares it.
5.4 Legal Compliance
We may disclose your information if required by law, court order, or to protect the rights and safety of ABRAM, our users, or the public.
5.5 Business Transfers
If ABRAM is acquired by or merged with another company, your data may be transferred as part of that transaction. We will notify you prior to its completion.
5.6 Transfers Between ABRAM's Own Systems
ABRAM runs the Platform and its business systems in separate databases. Both are controlled by Thomas Abram, LLC. The transfers described here are internal to ABRAM and are not disclosures to a third party.
Account records copied to our CRM. When you create a Platform account, your name, email address, the account type you chose during onboarding (if you have chosen one), your organization's identifier and name, your plan, and the date you joined are copied into ABRAM's separate customer relationship management and marketing database, where they become a contact record. We use that record to understand who is using ABRAM and to run our own sales and support work.
Creating an account is not a mailing list signup. No marketing email is sent to you as a result of creating an account. Being added to a marketing mailing list requires a separate, affirmative opt-in that you give yourself, and the same rule applies to contact records created at events under Section 2.5. Transactional email about your account, such as security and billing notices, is separate and is sent under contractual necessity.
Billing records mirrored to internal finance records. Payment and collection events, including amounts, dates, payment status, and refunds, are mirrored from the Platform's billing systems into ABRAM's internal finance and commission records. This mirror carries transaction and account identifiers and exists so that revenue, collections, and internal commission calculations can be maintained. It does not include payment card numbers or bank account credentials, which remain with Stripe.
6. Cookies & Tracking
ABRAM runs two surfaces, and each keeps its own separate consent record. The marketing site at abram.network is where our public pages, documentation, and demonstration videos live. The Platform is the signed-in application. Visiting or setting preferences on one surface does not set them on the other, and each surface shows you its own banner and its own settings control.
On both surfaces, a consent banner appears on your first visit. You may accept all, reject all, or open the preferences panel and choose category by category. Accept and reject are presented with equal visual prominence, no optional category is pre-selected, and your choice is saved in your browser's local storage rather than in a tracking cookie. You can change or withdraw it at any time using the Cookie Settings control in the footer of either surface. On the Platform, if you are signed in, your choice is also recorded against your account so that it follows you to another browser, and that record is kept as evidence of consent.
Categories on the marketing site:
- Strictly Necessary: Required for the site to function. Cannot be disabled.
- Analytics & Performance: Google Analytics and Vercel Analytics, used to measure traffic and page views. Turning this category off stops both. Vercel Analytics does not load at all until this category has been affirmatively allowed, in every region.
- Personalized Recommendations & Ads: Controls the Google Consent Mode signals
ad_storage,ad_user_data, andad_personalization.
Categories on the Platform:
- Essential: Authentication, session management, and security. Cannot be disabled without preventing core functionality.
- Analytics & Performance: Error monitoring and performance diagnostics by Sentry (Section 2.3).
- Third-Party / Integration: Reserved for optional third-party tools. None currently runs inside the Platform.
Google Analytics and Google Consent Mode are used on the marketing site only. They do not run inside the signed-in Platform.
How the marketing site's Consent Mode defaults are set. If you are in the EEA, the United Kingdom, or Switzerland, all four optional Consent Mode signals default to denied and stay denied until you opt in. Outside those regions they default to granted until you opt out, which is the opt-out model those jurisdictions permit. Either way the banner is shown, your choice always overrides the default, and once saved your choice is what applies on every later visit. Where advertising storage ends up denied, we additionally instruct Google to redact advertising data.
What happens before you choose. On neither surface do we record a consent decision before you have made one. The defaults above apply to that first visit only and are not written down as your choice. In the EEA, the United Kingdom, and Switzerland this means no analytics or advertising signal is sent from the marketing site until you opt in. Outside those regions, where the opt-out model applies, marketing site analytics may run during that first visit under the granted default and stop as soon as you opt out. Inside the signed-in Platform, no non-essential tracker starts and no preference is stored until you act on the banner, in every region. Where a region permits an opt-out model, the Platform banner may show its optional toggles already switched on to reflect that, but nothing is written or started until you choose.
We do not use advertising cookies or behavioral tracking cookies to build marketing profiles of you, and we do not sell or share personal information as those terms are defined by California law.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Personal profile data | Until account deletion, then deleted within 30 days |
| Uploaded documents and pictures | Until deleted by user or upon account deletion |
| Call transcripts | Until deleted by someone who manages the project, or until the project is deleted |
| Client portal visit records and quote signature records | Kept with the organization's related records for as long as the organization keeps them |
| Project data | Retained while active; deleted upon account deletion |
| Financial & transaction records | 7 years (anonymized) for legal and tax compliance |
| AI chat session data | 90 days, then deleted |
| Crash reports / diagnostic logs | 30 days |
| Log and error data | 30 days |
| AI training consent records | Account lifetime + 3 years (regulatory compliance evidence) |
| Cookie consent records | 3 years (regulatory compliance evidence) |
| Calendar feed data | Deleted when you remove the calendar link or delete your account |
| CRM and prospect records, including contacts created at events (Section 2.5) and from account creation (Section 5.6) | Until you ask us to delete them, or until the business relationship they document has ended and there is no continuing business or legal need to keep them, whichever comes first |
| Event scan telemetry (salted daily identifier, device and browser family, referrer) | 24 months, then deleted or aggregated |
| Internal finance and commission records mirrored from billing | 7 years for legal, tax, and accounting purposes |
You may request account deletion through your account settings or by contacting legal@abram.network. Personal data will be deleted within 30 days of the request. You may request an export of your personal data at any time through your account settings.
If you do not have a Platform account and want the CRM or prospect record we hold about you corrected or deleted, including a record created when you scanned a contact card at an event, email privacy@abram.network. You do not need an account to make that request, and we will act on it within the same timeframes.
8. Your Rights
8.1 For All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (subject to legal retention requirements).
- Data Export / Portability: Download your data in a portable, machine-readable format.
- Withdraw AI Training Consent: Withdraw at any time through account settings. Withdrawal is prospective only.
8.2 Additional Rights for EU/EEA Users (GDPR)
- Object to Processing: Object to processing based on legitimate interests.
- Restrict Processing: Request restriction of processing while a dispute is resolved.
- Automated Decision Rights: Request human review of automated processing that significantly affects you (Section 4.5).
- Lodge a Complaint: With your national Data Protection Authority — see edpb.europa.eu.
8.3 Additional Rights for UK Users
The same rights as EU/EEA users above apply under the UK GDPR. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8.4 Additional Rights for California Residents (CCPA)
- Know: The categories and specific pieces of personal information collected about you.
- Delete: Personal information we hold about you.
- Opt-Out: Of the sale or sharing of personal information (ABRAM does not sell personal data).
- Non-Discrimination: You will not be discriminated against for exercising your CCPA rights.
To exercise any of these rights, contact legal@abram.network. We will respond within 30 days (CCPA) / 1 month (GDPR).
9. Data Security
We implement the following security measures:
- Encryption of data in transit (TLS 1.2+) and at rest.
- Row-level security (RLS) on all database records via Supabase.
- Access control and permission management via WorkOS.
- Error monitoring and alerting via Sentry.
- Regular security reviews of third-party integrations.
- Least-privilege access controls for ABRAM personnel.
No method of transmission over the internet is 100% secure. While we use commercially reasonable security measures, we cannot guarantee absolute security.
10. International Data Transfers
ABRAM is based in the United States. If you are accessing the Platform from the EEA or UK, your personal data may be transferred to and processed in the United States.
We rely on the following safeguards:
- Standard Contractual Clauses (SCCs): We use the 2021 EU SCCs for transfers of personal data from the EEA to the United States.
- Transfer Impact Assessments (TIAs): Completed for each international transfer and maintained on file.
- UK IDTA: For transfers from the United Kingdom, we rely on the UK International Data Transfer Agreement or the UK addendum to the EU SCCs.
You may request information about our international transfer safeguards by contacting privacy@abram.network.
11. Data Breach Notification
In the event of a personal data breach, ABRAM will notify the relevant supervisory authority within 72 hours where required by GDPR Article 33 or applicable US state law, and will notify affected individuals without undue delay where the breach is likely to result in high risk to their rights and freedoms. All breaches are documented in ABRAM's internal breach register.
Report a potential breach: legal@abram.network
12. Children's Privacy
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. Contact legal@abram.network if you believe we have collected data from a minor.
13. Changes to This Policy
We will notify you of material changes via email and/or in-app notification at least 30 days before changes take effect. Where changes require new consent, we will obtain that consent separately. Continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
14. Contact & Data Controller
Data Controller: Thomas Abram, LLC
| Contact | |
|---|---|
| Legal & Terms | legal@abram.network |
| Privacy Inquiries | privacy@abram.network |
| Security / Breach Reports | legal@abram.network |
Based in: Washington, DC
Mailing address: 131 Continental Dr, Suite 305, Newark, DE 19713, US
EU Data Protection Representative (GDPR Article 27): Thomas Abram, LLC is in the process of appointing an EU representative. In the interim, contact privacy@abram.network.
For GDPR-related complaints, EU/EEA users may contact their national Data Protection Authority (edpb.europa.eu). UK users may contact the ICO at ico.org.uk.
© 2026 Thomas Abram, LLC. All rights reserved.