Skip to content

Legal

Privacy Policy

What we collect, why we collect it, and what you can ask us to delete.

Last updated 21 July 2026

What we collect

  • Account details. Your email address, and a name and company if you provide them. Email is required because it is how you sign in.
  • Photographs you upload. Stored privately and associated with your account.
  • Generated output. The images and clips we produce, and the settings that produced them, so a result can be reproduced or explained.
  • Billing records. Plan, credit movements and payment references. We never see or store card numbers — those go directly to the payment processor.
  • Security events. A limited audit log, retained to investigate abuse.

What we do not do

  • We do not sell your data, and we do not share it with advertisers.
  • We do not train models on your photographs. Vizydesign does not train models at all — generation runs on a third-party provider under a commercial API agreement.
  • We do not use your images in marketing without asking you first, in writing, for each image.

Who processes your data

Three sub-processors, each for one purpose:

  • Supabase — authentication, database and file storage.
  • fal.ai — image and video generation. A photograph is sent to fal when you start a generation, via a time-limited link, and the result is copied back into our own storage.
  • Vercel — application hosting.

How your files are protected

  • Every storage bucket is private. Files are never served from a public URL.
  • Images are reached only through short-lived signed links, generated per request and scoped to your account.
  • Database access is governed by row-level security, so a query can only return rows belonging to the account that issued it.
  • Uploads are checked against their real file signature, not the type your browser claims.

How long we keep things

  • Photographs and generated output are kept until you delete them, or until 30 days after your account is closed.
  • Credit ledger entries are kept for seven years. They are financial records, and they are append-only by design — including after an account closes.
  • Security audit entries are kept for 12 months.

Your rights

You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to our contact address and we will respond within 30 days.

Deleting your account removes your photographs, generated output and profile. Ledger entries are retained as described above, disassociated from your profile where the law allows.

Cookies

We set two cookies. One holds your sign-in session. The other records whether you chose the mobile or desktop experience. Both are strictly necessary for the product to work, and there are no advertising or analytics cookies — which is why you have not been shown a consent banner.

Changes

If this policy changes materially we will email account holders before the change takes effect. The date at the top always reflects the current version.