Privacy policy

What we hold about you, why, who else touches it, how long it stays, and what you can make us do about it.

Last updated September 14, 2026

Who is responsible

The controller of your personal data is Thomas BOUCARD (EI), [to be completed: postal address], SIRET 98995939000018. For anything on this page, write to thomas.bcrd1@gmail.com.

There is no data protection officer: the business is a sole trader and does not meet the conditions that require one. Your questions come to the same person who wrote this.

What we hold

CategoryWhat that is
AccountYour email address, an internal identifier, when the account was created and last used. If you sign in with Google: the email address and identifier Google returns, and nothing else from your Google account.
Your filesThe clips and photographs you upload, and the videos produced from them. Stored under an unguessable key, in a private bucket, reachable only through short-lived signed links minted after we have checked the file is yours.
GenerationsFor each run: the model, the resolution, the measured length of the clip, the credits charged, the status, the timestamps, and any error the model returned.
Credits and billingYour balance and the ledger behind it; your Stripe customer and subscription identifiers; the plan you are on and when it renews; your invoices. Never your card number — that is Stripe’s, and it does not pass through us.
TechnicalOrdinary server and platform logs: IP address, date and time, page or endpoint, user agent, error traces. Produced by the hosting and by our own error logging.
SupportWhat you write in the chat or by email, and the conversation around it.

About the faces

A photograph of a face is personal data of the person in it, and a clip of a person is too — including when that person is not you.

We process those images for one purpose: to produce the video you asked for. We do not run face recognition, we do not build a template that could identify anyone, and we do not match faces across accounts. Because the processing is not aimed at identifying a person, it does not turn the image into biometric data within the meaning of article 9 of the GDPR — but it stays sensitive by nature and is treated accordingly.

When the face is not yours, you are the one who must have a lawful basis for handing it to us, and consent is the only realistic one. The acceptable use policy puts it in plain terms; this is where the law behind it sits.

Why, and on what legal basis

What we doWhyBasis (art. 6 GDPR)
Create and run your accountYou cannot use the service without onePerformance of the contract
Store your files and run generationsThat is the servicePerformance of the contract
Take payment, grant credits, issue invoicesYou bought somethingPerformance of the contract; legal obligation for the invoices
Send service email — confirmation, password reset, notice of changesYou need to be toldPerformance of the contract
Keep logs, limit abuse, investigate misuseKeeping the service up and lawfulLegitimate interest
Act on reports of unlawful contentBecause we must, and shouldLegitimate interest; legal obligation
Keep accounting recordsFrench commercial and tax lawLegal obligation
Answer you in the chatYou opened itLegitimate interest

We do not sell your data, we do not profile you, and we send no marketing without asking you first.

Who else touches it

Only the providers the service is built on, each under contract, each acting on our instructions and for no purpose of their own:

ProviderWhat forEstablished / hosted
Vercel Inc.Hosting and delivery of the website and its APIUS
Supabase, Inc.Accounts, authentication and the databaseUS → IE
Cloudflare, Inc.Storage of your uploads and finished videosUS
Runware LtdRunning the model that produces the videoGB
Stripe, Inc. / Stripe Payments Europe, Ltd.Payments, subscriptions and invoicesUS / IE
Crisp IM SASLive chat support, when you open itFR → NL
Google Ireland LtdSign-in, only if you choose “Continue with Google”IE

Beyond them: our accountant, and any authority entitled to demand it.

Leaving the European Union

The database and the accounts are in the European Union (Ireland). The chat is hosted in the Netherlands. Some providers are established in the United States or the United Kingdom, and their infrastructure may process data there.

The United Kingdom is covered by a European Commission adequacy decision. Transfers to the United States rest on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the Commission’s standard contractual clauses, with the additional measures each provider documents. You can ask us for a copy of the clauses that apply.

How long we keep it

WhatHow long
Your files and resultsUntil you delete the generation, or close your account. Deleting removes them from storage as well as from the database.
Account and credit ledgerFor as long as the account exists. The ledger is what proves your balance, so it lives as long as the balance does.
Invoices and accounting recordsTen years from the end of the financial year (article L123-22 of the commercial code).
Technical logsTwelve months at most, kept by the hosting and storage providers under their own policies.
Support conversationsThree years after the last exchange.
A closed accountDeleted, save for what the accounting rules above require us to keep.

What you can require of us

Under the GDPR and the French data protection act you may ask for: access to your data, correction of it, erasure, restriction of processing, portability of what you gave us, and you may object to processing based on our legitimate interest. You may also leave directions about what becomes of your data after your death.

Write to thomas.bcrd1@gmail.com from the address on your account. We answer within one month; if a request is complex we tell you, and take up to two more. We may ask for proof of identity where there is real doubt about who is asking — never otherwise.

Some of it you can do yourself, faster than we can: deleting a generation removes its files, and the billing portal shows every invoice.

If you think we have got it wrong you may complain to the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — cnil.fr. We would rather you told us first.

How it is protected

  • Nothing in the storage bucket is public. Every read is a signed link that expires, minted only after the row it belongs to has been read back under row-level security.
  • The database enforces row-level security: a query can only ever see the rows of the account that made it.
  • Everything travels over TLS. Passwords are hashed by Supabase, never seen by us.
  • Credit movements go only through audited database functions, each idempotent, each writing to the ledger.

No system is perfect. If a breach occurs that is likely to result in a risk to you, we notify the CNIL within 72 hours and tell you where the risk is high.

Children

The service is for adults: you must be 18 or over to hold an account. We do not knowingly hold data about children, and we delete an account we learn belongs to one. Uploading footage or a photograph of a minor is prohibited outright — see acceptable use.

Changes

This policy changes when the service does. The date at the top says when it last did; a change that matters to you is announced by email.