Veylo.ai
Sign inStart creating
Veylo.ai / Policies & rules

Privacy Policy

Google sign-in data and purpose

We request only openid and email. We verify the returned identity and store your Google account identifier (sub), verified email and associated Veylo.ai user ID to authenticate you, link your account and credits, and prevent impersonation. We do not request Gmail messages, contacts, calendars, Drive or Google Photos. Google sign-in data is not used as image or video generation input.

Credentials and account security

Authorization codes, access tokens and ID tokens are processed on the server for the current sign-in verification and are not stored as long-term tokens. We do not request offline access. Email codes are sent through Resend and stored as non-reversible verification values, valid for 10 minutes. Necessary session cookies last 7 days; signing out revokes the current session. Short-lived authorization state and rate-limit records protect against forged requests and abuse.

Creative inputs and outputs

A locally selected image may initially remain in your browser. On submission, prompts, reference images or videos and model settings are sent to the selected service. Current generation requests use fal.ai and its model providers. Model branding does not grant access to your Google account. Account task records include model, state, credits, timestamps and output URLs. Do not upload unnecessary sensitive information.

Storage and retention

Account identifiers, sign-in links, credit ledgers and task records are stored in a Cloudflare-hosted server database during account use for service delivery and accounting. Browser drafts, saved items, characters, media and task previews remain until you remove them or clear site data. Providers determine their own input and output retention; output URLs can expire, so download backups. We cannot promise deletion of third-party copies. After a verified deletion request we remove account data we control, except records required by applicable law or necessary for transactions and disputes.

Providers and disclosure

Cloudflare hosts the site, security and database; Google verifies sign-ins you choose; Resend sends sign-in codes; fal.ai and the selected model providers process submitted creative inputs; Creem processes enabled checkouts and subscriptions. We retain necessary order, subscription and credit records, not full card details. We do not sell Google user data, share it for advertising or use it to train AI models. Disclosure is limited to service delivery, security, support and legal obligations. Model providers handle creative inputs under their own policies.

Browser storage, optional sync and international processing

Necessary cookies, localStorage and IndexedDB support sign-in, settings and local work. Cloud sync sends drafts and media only when you configure your own service and initiate sync. Providers may process data outside your country. External reference websites handle visits under their own policies.

Choices and deletion

You may use email sign-in instead of Google, sign out, remove references, clear browser site data and revoke access through Google account connections. Revocation does not delete your Veylo.ai account or local work. Email us from your account address to request access, correction, unlinking, export or deletion. We verify ownership without requesting passwords or Google tokens. Account deletion affects credits and task access; local and third-party copies must be handled separately.

Safety, security and updates

AI-generated non-consensual intimate imagery (AI NCII), sexual face swaps, undressing and sexualized depictions of minors are prohibited. Explicit violating requests are restricted and available provider safety checks remain enabled. Request filtering cannot detect all image content and is not a safety guarantee. HTTPS, server-side credentials and HttpOnly session cookies protect data. The service is intended for adults aged 18 or older. Use the contact above for privacy questions or reports. Material data-use changes will update this policy and seek renewed authorization where required.