Privacy Policy

What we collect, why, who we share it with, and your rights.

Version
2026-08-25
Effective
2026-08-25
PLACEHOLDER — NOT YET REVIEWED BY A QUALIFIED PERSON. The structure and the factual descriptions below were written from the product's actual code and infrastructure and are accurate as far as they go. The operative legal wording has not been reviewed. Do not rely on this document until that review has happened and this banner is removed.

1. What we collect

DataWhyWhere it comes from
Email addressAccount identity, sign-in, transactional mailYou, at sign-up (or from Google if you use that)
Password hashSign-inYou. We never store the password itself.
Character descriptions and promptsTo generate what you asked forYou
Chat transcriptsSo the assistant has context, and so you can return to a sessionYou
Generated images, voice clips and videoSo the product can show you your own workProduced by the service
Credit ledger and billing statusTo meter usage and manage your subscriptionThe service and Stripe
Request metadata (IP, user agent)Security, abuse prevention, rate limitingYour browser

2. What we do NOT collect

We do not accept photographs of real people, and we do not build biometric face templates of real people. Characters are generated from text. The upload route that could once have accepted a likeness photo is closed, and no such photo has ever been stored.

The service does compute a mathematical consistency signature over the images it *generates*, so that a character looks the same across shots. That signature describes synthetic output, not an identifiable person.

3. Legal basis

  • Contract — everything needed to give you the service you signed up for.
  • Legitimate interests — security, abuse prevention, and keeping the service working.
  • Consent — optional analytics cookies only. See the Cookie Notice.

4. Who your data reaches

Generating a character means sending your prompt to a model provider. The complete list of sub-processors, with what each one receives:

ProviderPurposeLocationData
SupabaseDatabase, authentication, and file storageUnited StatesAccount email, generated images and video, chat transcripts, credit ledger
RailwayApplication and background-worker hostingUnited StatesAll request data in transit; application logs
VercelWeb frontend hosting and deliveryUnited StatesRequest metadata (IP, user agent) for delivery and abuse prevention
StripeSubscription billing and payment processingUnited States / IrelandAccount email, billing details. Card numbers never reach our servers.
OpenAIChat assistant, prompt generation, and content moderationUnited StatesChat messages and generation prompts; images submitted to the moderation endpoint
RunwareCharacter image generation and voice-seed synthesisUnited States / European UnionGeneration prompts and generated media
PiAPIVideo generationUnited StatesScene prompts, generated reference images, generated video

Several are outside the UK and EU, so international transfer safeguards apply. PLACEHOLDER — the specific transfer mechanism (Standard Contractual Clauses, UK IDTA, or an adequacy decision) must be confirmed per provider by a qualified person.

5. How long we keep it

DataRetention
Account record and emailUntil you delete the account
Generated mediaUntil you delete it, or until account deletion
Chat transcriptsUntil you delete the session, or until account deletion
Credit ledgerRetained after account deletion where required for financial record-keeping
Application logsShort-term, for operating and debugging the service

6. Your rights

You can ask for a copy of your data, correction of it, deletion of it, or restriction of how it is used. Account deletion and data export are not yet self-service — request them through Support and we will action them. Building the self-service versions is tracked as work in progress.

7. Security

See the Security page.

8. Changes

New versions get a new version date at the top of this page.