Privacy Policy
Updated: 2026-08-14
In short: what happens to your data.
- We collect the minimum: your email and name from Google (or your Telegram account), your content in the studio, the history of your credit grants and charges, and — at sign-in — your IP address and browser (for security).
- No third-party analytics, no ad trackers. Only strictly necessary cookies — which is why there is no cookie banner.
- Your prompts and media go to AI providers only to fulfil your request.
- We do not train models on your content and do not sell personal data.
- The server is in the EU (Germany). Account and data deletion — by emailing [email protected].
1. Who is responsible for your data?
The party responsible for your personal data (its "controller", in GDPR terms) is the operator of the Vini Studio service (vinistudio.app). The service is in closed beta; the legal entity details will be published in this section before paid plans launch. For any data question: [email protected].
This policy is part of the Terms of Service.
2. What data do we collect?
Account. When you sign in with Google — your email, name, and Google account identifier. With Telegram — your Telegram identifier and username. We do not store passwords — authentication is handled by Google and Telegram.
Sessions. Signing in creates a session valid for 7 days; the IP address and browser string (user-agent) are stored with it — this is needed for account security.
Your content. Uploads (photos, videos, audio), prompts, generation outputs, and the projects themselves (the block diagrams you assemble in the studio) are stored on our server so the studio works and you don't lose your work.
Credits. The history of grants and charges: amount, generation type, model. We do not collect bank card data — when payments launch, they will be processed by a payment provider; your card details are never stored with us.
Interface language — so we don't have to ask every time.
Service-side access. The service administrator can see your account data (email or username, credit balance, and charge history) and, for support and moderation, may open your studio in read-only mode — without being able to change or run anything on your behalf.
3. Why, and on what legal basis?
| Purpose | Legal basis (GDPR) |
|---|---|
| Operating the service: account, generations, project storage | Contract (Art. 6(1)(b)) |
| Security: sessions, IP, abuse prevention | Legitimate interest (Art. 6(1)(f)) |
| Credit accounting and charges | Contract (Art. 6(1)(b)) |
| Voice cloning | Consent (Art. 6(1)(a)): for your own voice — your explicit upload of the audio; for another person's voice — that person's prior explicit consent, which you must obtain before uploading (Terms, section 4) |
| Retaining specific records required by law (e.g. financial accounting) | Legal obligation (Art. 6(1)(c)) |
4. What goes to AI providers?
Generation is performed by third-party AI model and compute providers (image, video, audio, and text models; speech transcription). We pass them your prompts and media only to fulfil your specific request — this is technically necessary; without it, generation is impossible.
- Faces. Uploaded photos containing faces are passed to providers to produce the frame or clip you requested; a provider may temporarily retain the submitted materials and outputs under its own data-processing policy. We do not create or store biometric identification templates (faceprints, voiceprints), and the service may not be used for biometric identification of people.
- Voice. Audio for voice cloning is passed to a speech-synthesis provider only upon your explicit action.
- Providers may process data outside the EU — see section 7.
5. Do we train models? Do we sell data?
No and no. We do not train AI models on your content (we have no models of our own), and we do not sell or share personal data for third-party advertising or marketing.
6. What cookies do we use?
Only strictly necessary ones — which is why there is no cookie banner.
| Cookie | Purpose | Lifetime |
|---|---|---|
avg_sid |
Sign-in session | 7 days |
avg_oauth |
Protects Google sign-in against request forgery (CSRF); set only during sign-in | 10 minutes |
lang, langBanner |
Interface language | 1 year |
There are no third-party analytics, ad pixels, or trackers on the site. To operate the service we keep internal usage records (generations, charges, studio activity) — they are never shared. External resources used by the pages: the Telegram sign-in widget (on sign-in pages and in account settings when linking Telegram) and YouTube video previews in the blog and articles (the preview image loads from YouTube's servers; the youtube-nocookie player itself loads only after a click).
7. Where is the data stored?
Our server is located in the EU (Germany, a Hetzner data centre). AI model providers may process the requests passed to them outside the EU/EEA — such transfers rely on the mechanisms provided by the GDPR (the EU Standard Contractual Clauses, SCC, or equivalent safeguards) in line with each provider's data-processing terms. We will send you the current list of providers and a copy of the applicable safeguards on request at [email protected].
8. How long do we keep data?
- Account data and content — while the account is active.
- Sessions — 7 days.
- Deletion. Email [email protected] — we will delete your account and associated data within 30 days; backups are purged shortly after. We may retain specific records longer where the law requires it (e.g. financial accounting).
9. Your rights
Under the GDPR you can: access your data and get a copy, rectify it, erase it, restrict processing, object to processing based on legitimate interest, and withdraw consent (this does not affect the lawfulness of processing before withdrawal). A single email to [email protected] is enough for any request.
If you believe we are violating your rights, you can lodge a complaint with the data protection supervisory authority in your country of residence.
10. Children, changes, contact
The service is intended for people aged 18 or older; we do not knowingly collect children's data.
We may update this policy — we will announce significant changes by email or an in-service notice. The date of the current version is shown at the top of the page.
Data questions: [email protected].
