This Privacy Policy explains how Eyondo ("we", "us", "our") collects, uses, and shares information when you use our AI-powered image and video generation service (the "Service"). By using Eyondo you agree to the practices described here.
1. Information We Collect
Account information
- Email address (required for sign-in via one-time code or Google).
- Display name and chosen avatar palette (optional, set during onboarding).
- Session tokens issued by our authentication provider.
Generation inputs
- Prompts and descriptions you write.
- Reference images you upload (avatars, products, app screens, ad-hoc references).
- Project metadata: chosen format, aspect ratio, duration, device, language.
Billing information
- Subscription tier and credit balance, stored in our database.
- Payment method, billing address, and tax info — collected and held by our payment processor (acting as Merchant of Record). We do not store full card details on our servers.
Technical information
- IP address, browser user-agent, and approximate location, logged on signup for anti-abuse forensics.
- Bot-detection signals from a third-party security provider during sign-up.
- Operational logs (request timestamps, error traces) used to diagnose failures.
2. How We Use Information
- Provide and operate the Service — authenticate you, run generations, store projects.
- Process subscriptions and credit-pack purchases and reflect balances in your account.
- Send transactional emails (sign-in codes, billing receipts, generation completions).
- Detect and prevent abuse, fraud, and duplicate-account abuse of the free tier.
- Improve the Service — debug failures, monitor performance, and prioritise reliability work.
- Comply with legal obligations.
We do not use your prompts, uploaded images, or generated outputs to train AI models — neither ours nor any third party's. Our subprocessors may transiently process your inputs solely to return the requested output, under contractual confidentiality.
3. Public Sharing (Community)
Your generations are private by default. Publishing to the Community feed is always opt-in — nothing you create becomes public unless you explicitly publish it. When you do, the image or video becomes visible to anyone, together with attribution: your display name (or username / email handle) and your avatar as they are at the moment of publishing. Published items can be viewed, liked, and reused as prompts or references by other users, and may be cached by browsers, search engines, or third parties while public.
You can unpublish an item at any time from its viewer. This removes it from the Community feed and deletes the attribution snapshot from the item — but copies made by others while it was public may persist outside our control.
4. Cookies & Local Storage
We use a small number of essential cookies and browser storage entries:
- Authentication cookies — required to keep you signed in.
- Bot-detection cookies — short-lived signals issued during sign-up by a third-party security provider.
- Local storage — saves your in-progress prompt draft and last-seen update timestamp so the application remembers your context across sessions.
We do not use marketing or cross-site tracking cookies.
5. Service Providers
To operate the Service, we engage a limited number of trusted vendors ("subprocessors") that act only on our instructions and are bound by written agreements requiring confidentiality and security standards consistent with this Policy. Subprocessors fall into the following categories:
- Cloud infrastructure & hosting — to deliver the Service over the internet.
- Authentication & database — to store your account and project data.
- AI model inference — to generate the videos, images, voices, and storyboards you request.
- Payment processing — to collect subscription and credit-pack fees on our behalf.
- Transactional email — to deliver sign-in codes and account notifications.
- Anti-abuse & security — to detect bots, fraud, and unauthorised access.
- Performance monitoring — to detect errors and improve reliability.
We may disclose information to law-enforcement or regulatory authorities where required by valid legal process, and to successor entities in the event of a merger, acquisition, or similar transaction (in which case continued protection of your data is a contractual condition).
We do not sell or rent your personal information to advertisers or data brokers, and we do not use your prompts, uploaded media, or generated outputs to train AI models — neither ours nor any third party's.
A current list of named subprocessors is available on request to [email protected] for compliance purposes (e.g. DPAs).
6. Data Retention
- Account data: kept while your account is active. Delete your account at any time from settings — this deletes your profile, projects, generations, and uploaded files.
- Generation outputs: stored indefinitely while your account is active. Removed when you delete a project.
- Billing records: retained as required by tax and accounting law (typically 7 years).
- Sign-up forensics (IP, user-agent, anti-abuse signals): retained for up to 90 days for abuse investigation.
- Operational logs: rotated after 30 days unless flagged for investigation.
7. Your Rights
Depending on your jurisdiction (including under GDPR, CCPA, and similar laws), you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Export your data in a portable format.
- Withdraw consent for any processing based on consent.
- Object to or restrict certain processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email [email protected]. We will respond within 30 days.
8. Security
We apply industry-standard safeguards including encryption in transit and at rest, role-based access controls, server-side authorization checks, audit logging on sensitive actions, and principle-of-least-privilege for internal access. No system is perfectly secure; if you suspect unauthorized access to your account, contact [email protected] immediately.
9. International Data Transfers
Our subprocessors may store or process data in countries other than your country of residence. Where required by applicable law, we rely on Standard Contractual Clauses or equivalent legal safeguards for cross-border transfers, and require subprocessors to maintain protection consistent with this Policy and the data-protection laws applicable in your jurisdiction.
10. Children's Privacy
Eyondo is not directed at children under 18. We do not knowingly collect personal information from children. If we learn we have collected such information, we will delete it. If you believe a child has provided personal data, please email us.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above and, for material changes, notify you via email or via the Service before they take effect.
12. Contact
Privacy questions, data requests, or complaints? Email [email protected].