Privacy Policy
1. Who We Are
This Privacy Policy describes how Vivify AI ("Vivify", "we", "us") collects, uses, shares, and protects personal information when you use the Vivify AI mobile application (iOS and Android) and our website at vivifyai.app.
Vivify provides AI-powered video and image creation tools. By using our services, you acknowledge that certain processing necessarily involves trusted partners and infrastructure located outside your country, including for cloud storage and AI inference.
Data controller: Vivify AI (independent developer). Privacy: privacy@vivifyai.app. Support: support@vivifyai.app
2. Information We Collect
Depending on how you use Vivify, we may collect the following categories of information:
- Account and identity data: email address, user identifier, authentication session data, and sign-in method metadata (processed through Supabase Auth)
- Profile and preferences: display name, language, app settings, and subscription or credit status
- User content: photos, videos, text prompts, and other files you upload or generate through the app
- Usage and technical data: features used, credits consumed, generation history, crash logs, performance diagnostics, IP address, device type, operating system, app version, and similar technical identifiers
- Purchase and entitlement data: subscription tier, product identifiers, purchase receipts, renewal status, and transaction metadata (processed through Apple App Store, Google Play, and Adapty on mobile, and through Whop on the web—we do not receive or store your full payment card number)
- Communications: messages you send to customer support
- Website data (vivifyai.app only): cookies, analytics events, browser type, and referral information where you use our marketing site or cookie banner
- Device fingerprint: a persistent hash derived from hardware identifiers (device brand, model, OS version, and available RAM) is generated and stored in our backend database linked to your account, used for abuse prevention for guest users
3. How We Collect Information
- Directly from you when you register, upload content, create AI generations, contact support, or manage your account
- Automatically when you use the app or website, including through logs and device signals
- From Apple and Google when you complete in-app purchases or subscriptions on their platforms
- From Whop when you complete a purchase or subscription on the web app
- From Adapty when we validate your mobile subscription or credit entitlements
- From our service providers when they process data on our behalf under contract
4. How We Use Your Information
We use personal information to:
- Create and manage your account and authenticate you (Supabase Auth and our backend)
- Provide AI generation features, including sending your prompts and media to AI inference providers
- Store and deliver your uploads and generated outputs (Cloudflare R2 and our backend)
- Activate subscriptions and credits, prevent fraud, and enforce plan limits (Adapty, Apple, Google)
- Operate, secure, debug, and improve the app and website
- Provide customer support and respond to your requests
- Send service-related notices (for example, policy updates or security alerts)
- Comply with law, enforce our Terms, and protect users and our rights
- Conduct aggregated or de-identified analytics that do not identify you personally
5. Legal Basis for Processing (EEA/UK Users)
Where GDPR or similar laws apply, we rely on the following legal bases:
- Performance of a contract: to provide the app, process generations, and fulfill subscriptions you purchase
- Explicit consent and contract: AI processing (including cross-border transfer to fal.ai, eachlabs.ai, and Cloudflare R2) and service-essential diagnostics are required to use the app—you accept them at registration; they cannot be turned off in Settings (only ended by deleting your account)
- Legitimate interests: to secure our services, prevent abuse, improve features, and support users (balanced against your rights)
- Legal obligation: to meet tax, accounting, fraud-prevention, or regulatory requirements
Mandatory processing in the mobile app cannot be withdrawn without deleting your account. On vivifyai.app, essential cookies always apply; analytics cookies are optional and may be refused via the cookie banner.
6. Third-Party Service Providers
We do not sell your personal information. We share information only with service providers that help us operate Vivify, under data processing terms appropriate to their role:
- Supabase: authentication and related user account infrastructure
- Adapty: in-app purchase and subscription management, entitlement verification, and related analytics (mobile)
- Whop: web checkout, memberships, and related payment processing (web app)
- Apple App Store and Google Play: payment processing and subscription billing (governed by Apple’s and Google’s respective privacy policies)
- Our backend servers: application logic, databases, and API services operated by or for Vivify
- Cloudflare R2: secure object storage for photos, videos, and related media you upload
- fal.ai: AI model inference and media processing
- eachlabs.ai: AI model inference and media processing
- Additional model providers accessed through the above platforms (which may include providers such as Google, OpenAI, Kuaishou, Lightricks, and others depending on the feature you select)
We do not negotiate individual enterprise data processing agreements. We rely on each provider's published terms, privacy policies, and standard customer or processor agreements (typical for apps using Cloudflare, Supabase, Fal.ai, EachLabs, Adapty, and app stores). Providers may process data in the United States, the European Union, Turkey, or other countries.
7. Payments and In-App Purchases
Vivify credits are sold on two channels that share the same wallet: Apple App Store and Google Play in-app purchases on mobile (Adapty maps store transactions to credits), and Whop checkout on the web app.
We do not store your payment card details. On mobile, payment information is collected and processed by Apple or Google. On the web, payment information is collected and processed by Whop according to their terms.
8. International Data Transfers
Because Vivify is a global AI product, your information—including photos and videos you upload—may be transferred to and processed in countries other than where you live, including the United States and other jurisdictions where our providers host infrastructure.
Uploads stored in Cloudflare R2 and content sent for AI processing through fal.ai, eachlabs.ai, or related model endpoints may be processed outside your country by necessity to deliver the feature you request.
Where required by law, we implement appropriate safeguards for cross-border transfers, such as standard contractual clauses or equivalent mechanisms. Contact us if you need more information about safeguards for your region.
9. Data Retention
We retain information only as long as needed for the purposes described in this policy:
- Account data: for as long as your account is active, then deleted or anonymized within 30 days after confirmed deletion, unless law requires longer retention
- Generated content in your in-app gallery: up to 7 days, with reminders before expiration
- Uploads and outputs in Cloudflare R2 and our backend: until you delete them, your account is deleted, or our retention schedule applies
- Purchase and subscription records: as needed to validate entitlements, resolve billing disputes, and meet legal and store requirements
- Support communications: typically up to 24 months unless a longer period is needed for an open issue
- Server and security logs: typically up to 12 months, unless needed for incident investigation
10. Data Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption in transit (TLS) and encryption at rest where supported by our providers
- Access controls, authentication, and least-privilege administrative access
- Monitoring, logging, and periodic security review
- Contractual security requirements for processors handling user content
No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately.
11. Your Privacy Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your information
- Restrict or object to certain processing
- Receive a portable copy of information you provided
- Withdraw consent where processing is based on consent
- Opt out of certain processing where applicable (for example, under U.S. state privacy laws)
- Lodge a complaint with your local data protection authority
In the app: Settings → export personal data (GDPR Art. 20) or Delete Account. You may also email privacy@vivifyai.app from your registered address. We may verify your identity. We aim to respond within 30 days (or the period required by applicable law). California residents: we do not sell personal information.
12. Cookies and Website Tracking
Our mobile app does not use advertising cookies in the same way as a website. The vivifyai.app website uses essential cookies always, and optional analytics cookies only after you choose Accept all or enable Analytics in Manage preferences. Essential only rejects non-essential cookies with equal prominence to accept (GDPR / ePrivacy).
You can change choices anytime via Cookie settings in the footer or your browser. We log banner decisions (hashed visitor id, no account required) for accountability under GDPR Art. 7 and KVKK.
13. Children's Privacy
Vivify is for users aged 18 and older only. We do not knowingly collect personal information from children. If you believe a minor has provided us information, contact privacy@vivifyai.app and we will take appropriate steps to delete it.
14. AI Processing and User Content
When you use AI features, the following applies:
- Your text prompts, reference images, and uploaded media are transmitted to our backend and to AI providers (including fal.ai and eachlabs.ai) to perform the generation you request
- Selected models may run in data centers in various countries; provider and model availability may change over time
- We use your content to provide the service, enforce safety rules, troubleshoot issues, and improve reliability—not to train public third-party foundation models with your private uploads without your consent
- You are responsible for ensuring you have the rights to upload and process any content you submit
- Outputs are stored temporarily in your gallery (see retention above) and may remain in backups for a limited period after deletion
15. Content Moderation
To maintain a safe environment, we use automated and manual moderation:
- Prompts and uploads may be screened for policy violations before or after processing
- Moderation signals are used to block prohibited content and protect the community
- Moderation metadata is retained only as long as needed for safety and compliance
See our Terms of Service for prohibited content rules.
16. Do Not Sell or Share My Personal Information
We do not sell personal information.
We do not sell your personal information as defined under applicable U.S. state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA). We do not share personal information for cross-context behavioral advertising in exchange for money.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page and update the "Last updated" date. For material changes, we may provide additional notice in the app or by email where appropriate.
18. Contact Us
Privacy questions and data subject requests (legal pages only):
Email: privacy@vivifyai.app
19. Account Deletion and Data Management
You can request deletion of your account and associated personal data as follows:
How to request deletion:
- In the app: Settings > Account > Delete Account
- By email: send a request to privacy@vivifyai.app with the subject "Account Deletion Request" from the email linked to your account
After verified deletion, we delete or anonymize profile data, stored prompts, uploads, and generated content within 30 days, except where retention is required by law, fraud prevention, or active billing disputes with Apple or Google.
20. Data Breach Notification
We maintain technical and administrative measures to protect your personal data. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33 and KVKK Article 12.
If the breach is likely to result in a high risk to you, we will also notify you directly using the contact information associated with your account.
Last updated: May 18, 2026