Privacy Policy
What we collect, why we collect it, who else sees it, how long we keep it, and how to get it back or have it erased.
Last updated October 10, 2026 · Operated by Ron Avidor (Israel)
The short version. We collect your email, your purchase history and the prompts and videos you generate, because the Service cannot work without them. We never see your card details. We don't sell your data or use your content to train AI models, and Google and Meta measurement only runs if you accept it. You can download everything we hold, or delete your account outright, from your dashboard in two clicks.
1. Who is responsible for your data
The data controller is Ron Avidor, a sole trader in Israel.
For any privacy question or request, write to privacy@veymu.io. We reply within 1 business day and resolve formal requests within 30 days.
Israel is recognised by the European Commission as providing an adequate level of data protection, so personal data can move from the EEA to us without additional safeguards.
2. What we collect, and why
| Data | Why we have it | Legal basis (GDPR) |
|---|---|---|
| Email address, hashed password | To create your account and let you sign back in | Performance of a contract |
| Name and profile picture, if you sign in with Google or Facebook | To identify your account. We request no other permission | Performance of a contract |
| Prompts, uploaded images and reference clips | To generate the video you asked for | Performance of a contract |
| Generated videos and their settings | So your work survives a refresh and appears in your dashboard | Performance of a contract |
| Credit ledger and purchase history | To track your balance and show what you bought | Performance of a contract; legal obligation (accounting) |
| Subscription status and the last 4 digits of your card | To show which plan you're on and which card renews it | Performance of a contract |
| IP address and request timestamps (transient) | Rate limiting, abuse prevention, and debugging errors | Legitimate interests, keeping the Service usable and secure |
| Records of prompts blocked by our safety filter | To enforce the Acceptable Use Policy and detect repeat abuse | Legitimate interests; legal obligation |
| Identity check result, only if you verify: the name and issuing country on your ID, whether you are 18 or over, and when you agreed to the check | Adding a character to your videos needs a verified person behind the account, see Identity verification | Your explicit consent |
| Your consent to these policies, with a timestamp | To be able to demonstrate that consent was given | Legal obligation (accountability) |
What we deliberately do not collect
- Card numbers, CVV, or billing addresses. Those go straight to Dodo Payments's checkout and never touch our servers.
- Analytics and advertising identifiers, unless you opt in. Google Tag Manager and the Meta Pixel stay off until you accept optional tracking cookies. See the Cookie Policy.
- Special-category data (health, biometrics, religion, politics, sexual orientation). Please don't put it in a prompt. The one exception is the optional identity check below, and even then the images of your ID and your face go to Didit, never to us.
Identity verification
Before you can add a character, a real person or an AI one, to your videos, we ask you to verify who you are once. It is optional otherwise, and nothing else in the Service needs it.
- Who runs it. Our provider Didit (EU, Spain), acting as our processor. On Didit's page you photograph your ID and take a short live selfie, and Didit checks the selfie matches the photo on the ID. That comparison uses biometric data (a scan of your face geometry).
- Only with your consent. The check never starts until you tick a box agreeing to it, and we record when you did.
- What we keep. The result, the name and issuing country on your ID, and whether you are 18 or over. Not your date of birth, not your ID number, and never the images.
- How long. We keep the result until you delete your account. Didit keeps the session, including the images, for 12 months, then deletes it. You can ask for earlier deletion at privacy@veymu.io.
- Not for training. We have opted out of Didit using our verification data to improve its models, and we never use it for anything except confirming who you are and handling reports of misuse.
3. We do not train on your content
We do not use your prompts, uploads or generated videos to train, fine-tune or evaluate any AI model, ours or anyone else's. We do not sell them, and we do not licence them to third parties.
Your prompt leaves our servers for one purpose only, to be rendered:
- To fal.ai, for most models. The prompt and any source file go to fal.ai, which runs the model you chose, purely so it can produce your video, governed by fal.ai's privacy policy.
- To BytePlus ModelArk, for the Seedance and Seedream models, which we run there directly. The same applies, governed by BytePlus's privacy policy.
Screening happens on our own servers, before that. Every prompt is checked against our Acceptable Use Policy by an automated filter that runs inside the Service, it is not sent anywhere else to be moderated. A prompt that fails screening is never sent to a model provider, and you are not charged for it.
A member of our team accesses the content of a prompt or a video only when (a) you ask us to, to investigate a problem you have reported, or (b) an automated safety signal or a report requires review under the Acceptable Use Policy.
4. Who else processes your data
These are our sub-processors. Each is bound by a data processing agreement and may use your data only to provide its service to us.
| Provider | What it does | Where |
|---|---|---|
| Dodo Payments | Merchant of Record, payments, invoicing, and sales tax/VAT | United States / India |
| Supabase, Inc. | Account database and authentication | European Union |
| fal.ai (Features and Labels, Inc.) | AI video inference and temporary asset storage | United States |
| BytePlus Pte. Ltd. (ModelArk) | AI video and image inference for the Seedance and Seedream models | Singapore / Malaysia |
| Didit | Identity verification (ID document, live selfie and face match), only if you verify to add characters | European Union (Spain) |
| Resend, Inc. | Transactional email delivery | United States |
| Render Services, Inc. | Application hosting | United States / European Union |
| Meta Platforms Ireland Ltd. | Ad measurement (Meta Pixel and Conversions API), only with your consent | European Union / United States |
| Google Ireland Ltd. | Analytics and purchase measurement through Google Tag Manager, only with your consent | European Union / United States |
| Cloudflare, Inc. | DNS and edge network | United States |
Transfers to providers in the United States rely on the EU Standard Contractual Clauses, or on the provider's certification under the EU – US Data Privacy Framework.
We will also disclose data where we are legally required to, or where it is necessary to establish or defend a legal claim. If we are ever acquired, your data may transfer to the buyer under this same policy, and we will tell you first.
5. How long we keep things
| Data | Kept for |
|---|---|
| Account details and credit balance | Until you delete your account |
| Prompts and generation records | Until you delete your account |
| A basic record of a finished render you delete: the account, the prompt, the model and the time, never the file | 12 months after you delete it, or delete your account, so we can investigate a report that a video was misused, see our Synthetic Media Policy |
| Identity check result (name, country, 18+, consent time) | Until you delete your account |
| Your ID and selfie images, held by Didit | 12 months, then deleted by Didit |
| Generated video files | Roughly 7 days on fal's CDN, download anything you want to keep |
| Server and rate-limit logs | Up to 30 days, then discarded |
| Records of blocked prompts | 12 months, for repeat-abuse detection |
| Invoices and tax records | Held by Dodo Payments as Merchant of Record for the statutory period, this is their retention duty, not ours, which is why we can erase our copy on request |
| Proof that an account was deleted | Indefinitely, as a one-way hash with no email address attached |
6. Your rights
Under the GDPR (and equivalents elsewhere) you may ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it, or hand it to another provider. You may also withdraw consent at any time, and complain to a supervisory authority.
Two of these are self-service. From your dashboard you can download everything we hold about you as a JSON file, and delete your account and all its data immediately, apart from the limited records section 5 says we keep for longer. No email, no waiting.
For anything else, write to privacy@veymu.io. We respond within 30 days, free of charge. We may ask you to confirm your identity from the email address on the account.
EU/EEA and UK residents can complain to their national data protection authority. Israeli residents may contact the Privacy Protection Authority.
California residents (CCPA/CPRA)
In the past 12 months we collected the categories described in section 2 for the purposes stated there. We have not sold or shared personal information, and we do not sell or share it now, including the personal information of anyone under 16. You have the right to know, delete, correct, and not be discriminated against for exercising those rights. Use the dashboard tools above, or email privacy@veymu.io.
7. How we protect it
- Everything travels over TLS, with HSTS so a browser will not fall back to an unencrypted connection.
- Passwords are hashed with bcrypt by Supabase Auth. We never see them, and cannot recover one for you.
- Every table is protected by row-level security in Postgres, so a query can only ever return the signed-in user's own rows.
- Session cookies are HTTP-only, Secure and SameSite, so page JavaScript cannot read them and another site cannot replay them.
- A Content Security Policy limits third-party scripts to the Google and Meta measurement tools you opt into, and the site cannot be framed by another domain.
- Administrative keys live only in server-side environment variables and are never sent to a browser.
No system is perfect. If a breach affects your personal data and is likely to pose a risk to you, we will notify you and the relevant authority within 72 hours of becoming aware of it.
8. Children
The Service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has created an account, email privacy@veymu.io and we will delete it.
9. Cookies
We set the cookies required to keep you signed in and to remember your cookie choice. If you accept optional tracking cookies, Google Tag Manager and Meta's pixel measure page activity and purchases. The full list, and the switch to turn them off, is in the Cookie Policy.
10. Changes
We will update the date at the top of this page when this policy changes, and email you before any change that materially reduces your privacy protections.
