1. Scope and controller
This draft describes information involved in using Muvi’s creative workspace and public video features. The legal entity responsible for processing, its address, privacy contact and any required regional representative must be identified before this notice becomes effective. It is not a claim that all launch compliance work has been completed.
2. Account and profile information
Muvi uses Clerk for authentication and receives account identifiers, email and available profile information such as nickname and avatar. Profile settings, account status and signup agreement records support account operation. A public nickname and avatar can identify you to other visitors; an email address is not intended as a public profile field.
3. Creative content and generation records
Muvi processes uploaded images, audio and video; character, object, location and frame descriptions; prompts, references and tags; timeline edits and timecodes; generated assets; and exported videos. Generation records can include the assembled model prompt, selected provider and model, parameters, status, errors, timestamps, costs and versions. Images and recordings may contain faces, voices or other personal information. Provide only content you have authority to use and avoid unnecessary sensitive information.
4. Usage, transactions and security
Muvi records token balances, charges, reservations, refunds, gifts and transfers, with associated users and projects. Public features use publishing records, likes, follows and view events. Application and infrastructure logs can include request, device and network information needed to operate and secure the service. Audit events record actions and responsible accounts; actions performed during administrative impersonation can identify both the account and the administrator. Access to operational records should be limited to authorized personnel.
5. Why information is used
Information supports sign-in, saving projects, resolving references, generating and rendering media, delivering files, tracking token usage, publishing at your direction, showing engagement, troubleshooting and preventing abuse. Legal and consent records support accountability and responding to legal obligations. Where applicable privacy law requires a lawful basis, processing must be mapped to contract necessity, legitimate interests, legal obligations or consent as appropriate. The final basis assessment and any required consent mechanisms remain subject to legal review; accepting terms is not blanket consent to every use of data.
6. Providers and disclosures
Clerk supports authentication; Neon stores application records; Cloudflare R2 stores media and thumbnails; Vercel hosts the application. Depending on the workflow, OpenAI may receive planning prompts and references, Google Gemini may receive image-generation inputs, Google Veo may receive video-generation inputs, and fal may process requests through selected models such as ByteDance Seedance or Sync-3. Only the services involved in a requested workflow should receive its necessary inputs. Files can be delivered to providers through temporary signed URLs. Development environments may also use local files or temporary processing copies.
Provider retention, safety review and training treatment depend on the provider, product and account configuration. Muvi does not promise zero retention or no provider training without verifying the applicable terms and settings. A final provider inventory, payment processor disclosure for live billing, and assessment of international transfers are required before launch. Information may also be disclosed when legally required or necessary to investigate misuse or protect users, with appropriate safeguards.
7. Public sharing and visibility
Creating an asset or exporting a video does not by itself publish it. If you publish, viewers may access the video, selected cover, title, description and tags, along with public creator and engagement information. Public content may be linked, copied or indexed outside Muvi. Reusable assets added to a shared library may be accessible to that library’s users; check the destination before sharing. Private files use controlled delivery rather than a promise that anyone holding a valid temporary URL cannot access them.
8. Cookies and local state
Authentication uses session technologies. Muvi also uses browser state for interface preferences and a viewer cookie for anonymous view counting, currently set with a one-day lifetime. Infrastructure providers may operate additional essential technologies. A complete cookie inventory and any required controls for non-essential technologies must be confirmed before launch; this draft does not claim that a consent banner or advertising opt-out system already exists.
9. Retention and deletion
Projects and media are kept to provide saved work and reusable assets. Deleting content invokes the relevant record and file cleanup, but copies reused in another project, published exports, accounting records, legal acceptance evidence and security logs can require separate handling. Backups, queued work, temporary URLs and provider-held copies may not disappear immediately. Unpublishing is different from deleting source files. Retention periods for account data, media, job records, financial records, logs and backups, and a verified account-deletion process, must be specified before launch. We do not promise a deletion deadline that has not been operationally validated.
10. Your choices and rights
You can edit available profile details, manage projects and choose whether to publish videos. Depending on your location, you may have rights to access, correct, delete or obtain a copy of personal information, restrict or object to processing, withdraw consent, and complain to a supervisory authority. Identity verification and lawful exceptions may apply. A working privacy request contact and any applicable regional request or appeal mechanisms must be supplied before this notice takes effect. No sale, sharing or targeted-advertising declaration should be inferred from this draft without a verified data-flow assessment.
11. Security, transfers and children
Access controls and signed media delivery reduce risk, but no service can guarantee absolute security. Providers may process data outside your country; the final notice must identify applicable transfer safeguards rather than assume a hosting region keeps all processing local. Muvi is not intended for children. Minimum-age rules, handling of suspected underage accounts and any applicable parental requirements must be confirmed before launch.
12. Updates and contact
The final notice should explain how material changes are communicated and provide the controller’s name, postal address and monitored privacy email. This version replaces neither statutory rights nor the need for a legal and operational review.