Legal
Privacy Policy
Last updated: July 3, 2026
1. What We Collect
- Account data: your email address, used for sign-in and service communications.
- Video brief data: the game name, video idea, and notes you submit when generating a creative pack. This is stored to power your generation history.
- Usage data: number of generations used, billing period dates, and credit balance.
- Session data: an encrypted session cookie to keep you signed in (30-day max lifetime).
- Billing data: your payment method is stored and managed entirely by Stripe. We only store your Stripe customer ID and subscription status — never raw card details.
2. How We Use Your Data
- To authenticate you and maintain your session.
- To send you sign-in links via email.
- To generate AI-powered metadata using your video brief.
- To track your credit usage and enforce subscription limits.
- To display your generation history.
3. Third-Party Services
We share data with the following third parties to operate the Service:
- xAI (Grok): your video brief is sent to xAI's API to generate titles, tags, and descriptions. xAI's privacy policy applies to that processing.
- Stripe: handles all payment processing and stores your billing information under their privacy policy.
- Cloudflare: used to send transactional emails (sign-in links). Email addresses are transmitted through Cloudflare Workers.
4. Data Retention
Your account and generation history are retained for as long as your account is active. Session data expires after 30 days. If you cancel your subscription, your data remains accessible until you request deletion.
5. Your Rights
You may delete your account at any time from the Account page (type DELETE to confirm). That permanently removes your account, generation history, brand kit, and usage data, and cancels active Stripe subscriptions. You may also request access to, correction of, or deletion of your personal data by emailing [email protected].
6. Cookies
We use a single session cookie (httpOnly, sameSite=lax) to keep you signed in. We do not use advertising cookies or third-party tracking cookies.
7. Data Security
All data is transmitted over HTTPS. Sensitive values (session secrets, API keys) are stored as environment variables and never exposed to the client. We use parameterized database queries to prevent injection attacks.
8. Children's Privacy
The Service is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it promptly.
9. Changes to This Policy
We may update this policy from time to time. We will post the updated date at the top of this page and, where changes are material, notify you by email.
10. Contact
Privacy questions? Email [email protected].