Last updated: June 2026
Eaarth Ltd ("EAARTH", "we", "us", "our") is a company registered in England and Wales. We are registered with the Information Commissioner's Office (ICO) under registration number ZC173483.
We operate the EAARTH platform, an all-in-one production management system for the film and television industry, available at www.eaarth.app and associated subdomains (collectively, the "Service").
If you have a privacy question, you can contact us at any time through in-app chat. We do not publish an email address for privacy or support queries.
Depending on how you use the Service, we may collect:
We use your personal data to:
Under UK GDPR, we process your personal data on the following bases:
We do not sell your personal data. We may share it with:
What this means for EAARTH DM
Our messaging architecture is designed so that, once end-to-end encryption is live for a conversation, message content itself is not accessible to us, not even under compulsion. That is a deliberate architecture choice, not a refusal to cooperate with the law. Until that rollout is complete for a given conversation (see the DM Personal Terms, Section 3), message content is protected in transit and at rest but remains technically accessible to us, in the same way as any other data described in this policy, and could be disclosed if we are validly compelled to do so.
Your data is primarily stored on AWS servers in the EU/UK region. Where data is transferred outside the UK/EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the ICO, to protect your information.
When you use our RAM AI assistant, the content of your question is sent to Groq, and, where separately configured, Anthropic, to generate a response. Depending on where you are asking from, RAM may also draw on relevant EAARTH OS platform data, such as your studio's knowledge base, current project details, or production status, to answer accurately. RAM does not have access to EAARTH DM message content: it cannot read, and is never given, anything said in an EAARTH DM conversation. Both Groq and Anthropic are US-based service providers. This transfer relies on the same kind of safeguard described above (Standard Contractual Clauses / the UK's International Data Transfer Addendum), applied to that specific provider.
We retain your personal data for as long as your account is active or as necessary to provide the Service. After account closure:
Under UK GDPR, you have the right to:
For identity verification specifically: you can withdraw your consent at any time from your account settings. This deletes your verification data immediately and disables EAARTH DM until you re-verify, but does not delete your wider EAARTH account. To delete your account entirely, use account deletion, this deactivates your account immediately and, as described in Section 7 above, permanently deletes your identity verification records 30 days later unless you reactivate by logging back in within that window.
Automated decision-making (UK GDPR Article 22)
Our identity verification (Section 2) is a fully automated process: a liveness check, an automated reading of your ID document, and an automated match between that document's photo and your live selfie. A failed check blocks the outcome it gates, creating an account, using EAARTH DM, or a right-to-work confirmation, without a person needing to be involved in that specific decision. Under UK GDPR, you have the right not to be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you, and the right to request human review of it, to express your point of view, and to contest the outcome.
If your verification fails, you can request a human review directly from the verification screen. This creates a logged request that goes to a review queue our team monitors. A real person looks at the failure details, including which step failed, the reason given, and, where the check got that far, what was read from your document, and decides whether to approve your verification or confirm the automated result. We do not store the original selfie or ID photo (see Section 2), so a reviewer works from this failure detail rather than the original image, and may also take into account anything you tell us separately, for example through in-app chat, to help confirm your identity another way. As with other requests under this section, we aim to respond within 30 days.
To exercise any of these rights, please contact us through in-app chat. We will respond within 30 days. You also have the right to lodge a complaint with the ICO at ico.org.uk.
This section lists every cookie we actually set, no more, no less:
We do not use analytics, advertising, or tracking cookies of any kind. No third-party analytics or advertising scripts run on the EAARTH platform today. If that changes, we will update this section and ask for your consent first, as UK PECR rules require for any non-essential cookie.
You can clear or block cookies through your browser settings at any time; doing so for the essential cookies above will sign you out.
EAARTH OS is intended for professional use and requires all users to be at least 18. EAARTH DM's personal service has a lower minimum age of 16, with additional protections for users aged 16 and 17; see the DM Personal Terms of Use, Section 2. EAARTH OS and EAARTH DM share one account system, so each product's own minimum age is enforced separately: every time you use a feature belonging to a specific product, we check your age against the verified date of birth from your government ID, not simply the age you stated at signup. We do not knowingly collect personal data from anyone below the relevant minimum age for the product they are using. If you believe someone below that age has provided us with data, please contact us immediately through in-app chat.
We implement industry-standard security measures including encryption in transit (TLS) and at rest, access controls, two-factor authentication options, and regular security audits. However, no method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the ICO within the timescale UK GDPR requires (normally within 72 hours of becoming aware of it), and will notify you directly, without undue delay, where the breach is likely to result in a high risk to you.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and notify users via email or an in-platform notice for material changes. Continued use of the Service after changes constitutes acceptance of the updated policy.
For any privacy questions, requests, or concerns, if you can sign in to EAARTH, please use in-app chat, see Section 1.
If you do not have access to an EAARTH account, for example your account was permanently closed, you were never an EAARTH user, or another user's activity concerns you and you are not a user yourself, you can submit a data request directly at eaarth.app/data-request. That form covers access, deletion, and objection requests, and complaints, from anyone we cannot otherwise reach through the platform. Because we cannot verify your identity automatically the way we do for a signed-in account, a member of our team reviews and confirms identity by hand before acting on an access or deletion request submitted this way.
Eaarth Ltd
ICO Registration: ZC173483
Little Mead, Leighton Road, Great Billington, Leighton Buzzard, LU7 9BJ, England