Privacy Policy
What VBN Studio collects, why, who it is shared with, how long it is kept, and the control you have over it.
Effective
Who we are and what this covers
This policy explains what VBN Studio, at vbnstudio.ai, does with your personal data. "We" means the small team that builds and operates it, from India.
This policy covers everything you do on vbnstudio.ai and through our APIs. It does not cover sites we link to, model providers' own services, or what you choose to do with an Output once you have downloaded it.
What we collect
Information you give us
| Data | Why we have it |
|---|---|
| Email address | It is how you sign in (a one-time code is sent to it) and how we reach you about storage deadlines, moderation decisions and receipts. |
| Display name and avatar | Optional. Shown in the interface, and on Explore if you publish. |
| Creator username | Only if you publish to Explore. It is public by design. |
| Prompts and settings | The text and options you enter to generate something. Stored with the result so your history means something. |
| Uploads | Images, video, audio, voice samples and project files you supply as inputs. |
| Support correspondence | What you write to us, so we can answer and keep a record of what was decided. |
Information generated by your use
| Data | Why we have it |
|---|---|
| Generated Outputs | The images, video and audio the models produce for you, stored in your library. |
| Credit ledger | Every grant, spend, return and expiry. It is an append-only financial record, so your balance can always be explained. |
| Operation records | Which model ran, with which options, when, what it cost and whether it succeeded. Used for delivery, billing accuracy and support. |
| Subscription and order records | Plan, billing cycle, renewal date, amount, and the Dodo Payments customer, payment and subscription references. |
| Security and technical logs | IP address, user agent, timestamps and outcome for sign-in attempts, rate-limit decisions and administrative actions. Used to protect accounts, not to profile you. |
| Explore records | What you published, its moderation status, and any reports made about it. |
What we do not collect
- No card, UPI or bank details. They go straight to Dodo Payments and never touch our systems.
- No password. There isn't one. Sign-in is a one-time email code.
- No advertising or cross-site tracking cookies, and no third-party advertising networks.
- No location data beyond your country: we read it from your connection to show prices and tax in your currency, and Dodo Payments takes it from your billing details to charge the right tax.
Why we use it
We hold each piece of data for a reason, and the reason is always running the Service you asked for, keeping it working, or meeting an obligation we cannot avoid. The second column names the lawful basis, for readers in the EU and the UK who look for it.
| Purpose | Lawful basis (EU/UK) |
|---|---|
| Give you an account, sign you in, keep you signed in | Performance of a contract |
| Run the generations you ask for and return the results | Performance of a contract |
| Store your media and let you find, use and download it | Performance of a contract |
| Take payment, grant credits, meter usage, keep a ledger | Performance of a contract; legal obligation for tax and accounting records |
| Send service notices: storage deadlines, moderation outcomes, receipts | Performance of a contract; legitimate interests |
| Protect accounts: rate limiting, abuse detection, fraud prevention | Legitimate interests; legal obligation |
| Review published content and act on reports | Legitimate interests; legal obligation as an intermediary |
| Diagnose faults and improve reliability and performance | Legitimate interests |
| Respond to lawful requests from authorities | Legal obligation |
What happens when you generate something
This is the most important thing to understand about a service like this one, so it has a section of its own.
When you run a generation, your prompt and any input files are sent to the third-party provider that operates the model you selected. They have to be: the model runs on that provider's infrastructure, not ours. We send only what the operation needs, and we do not send your email address, your name or your billing details with it.
- You choose the provider by choosing the model. Each model in the catalogue names what it is and what it runs on.
- The provider's own terms and privacy policy apply to that processing. We do not control their systems and cannot make promises on their behalf. If how a particular provider handles your data matters to you, read its policy before choosing a model that runs on it.
- Inputs sent for a generation may be briefly retained by the provider to run the job and for their own abuse monitoring, according to their policy.
- Do not send anything to a model that you could not accept a third party processing, particularly other people's personal data, health information, identity documents, or confidential material you are under a duty to protect.
Some operations also run on our own processing service for tasks like transcoding, thumbnails and format conversion. That runs on infrastructure we control and sends nothing to a model provider.
Payments
All payments are processed by Dodo Payments, which acts as the merchant of record. When you buy something, the checkout is Dodo's, the payment page is Dodo's, and the payment instrument you enter goes to Dodo.
- We never receive, store or have access to your card number, UPI ID, bank details or wallet credentials.
- Dodo Payments is an independent controller of the payment data you give it, and processes it under Dodo Payments' own privacy policy.
- Dodo tells us what was bought, whether it settled, the amount, the currency and the country, and gives us a customer reference, a payment reference and a subscription reference. We store those to provision your plan and keep your ledger accurate.
- Dodo uses the billing country you enter to calculate tax and the final price in your currency.
Who we share data with
We do not sell personal data, and we do not share it for anybody else's marketing. We use the following processors and providers to run the Service, each with access only to what their function requires.
| Provider | What it does | What it can see |
|---|---|---|
| Auth0 (Okta) | Identity: issues and verifies the one-time sign-in code, holds the session | Email address, sign-in events |
| Dodo Payments | Payments, merchant of record, tax, invoicing | Email address, payment instrument, billing country, purchase history |
| Cloudflare | Hosting, application runtime, databases, and R2 object storage for all media | All application data and stored media, at rest and in transit |
| Runware | Image and video model execution | The prompt and input files for generations routed to it |
| ElevenLabs | Voice generation, voice cloning, dubbing and transcription | Audio, scripts and voice samples for those operations |
| Groq | Speech transcription and text processing for dubbing workflows | Audio and text submitted to those operations |
| Resend | Transactional email: storage warnings, moderation notices | Email address and the content of the notice |
| Remotion | The video-rendering software that makes dubbed videos in your own browser; each render reports one usage count to Remotion under its licence | Our site's address and whether the render succeeded, and, as with any web request, your IP address and browser details. Never the video, audio or script |
Additional model providers may be added to the catalogue over time; where that happens, this table is updated. We may also share data where we are legally required to (in response to a valid order from a court or an authority, to establish or defend a legal claim, or to prevent harm) and, if the business is ever merged, acquired or sold, as part of that transaction, subject to this policy continuing to apply.
Content you publish
Publishing to Explore is optional and off by default. Nothing you generate is public unless you publish it.
When you do publish, the media, its title and description, and your creator username become visible to anybody on the internet, and may be indexed by search engines or copied by visitors. Your email address is never shown.
You can unpublish at any time. We remove the public copies, though we cannot recall anything somebody already downloaded, nor control search-engine caches, which expire on their own schedule. We retain the moderation record of a publication (what was published, what was decided and why) after removal, because that is the record that makes moderation reviewable.
Voice recordings
A voice recording can identify the person who spoke, and several laws treat it as sensitive. We handle it accordingly.
- A voice you clone is private to your account. It is not shared with other users, not added to any public library, and not offered in anybody else's picker.
- Consent is recorded. Cloning requires you to confirm the voice is yours or that you have the speaker's permission, and we store that confirmation with the voice.
- Voice samples are sent to our voice provider to build and run the synthetic voice, and are subject to that provider's terms.
- You can delete a cloned voice at any time, which removes it from your account and requests its deletion at the provider.
- We do not use voice recordings for identification, verification or biometric matching, and we do not build voiceprints for any purpose other than the synthetic voice you asked for.
If somebody has cloned your voice without permission, write to support@vbnstudio.ai and we will investigate and remove it.
How long we keep things
Retention is enforced by the system rather than left to judgement. These are the actual windows:
| Data | Kept for |
|---|---|
| Account record (email, identity binding, settings) | While the account exists, and a short period after deletion to complete the removal. |
| An upload never attached to anything | 7 days. |
| An input to a failed or cancelled generation | 72 hours. |
| Generated Outputs and project sources | While the account is in good standing and something still references them. |
| Working files inside a dubbing project | 30 days after they stop being used. |
| Media after a plan lapses | Nothing is removed for 30 days; after that each file goes 90 days after the day it was created. Resubscribing stops it. |
| Prompts and operation records | With the result they produced. Anonymised operational metrics may be kept longer. |
| Credit ledger, orders, invoices and subscription records | Kept as long as we need them for accounting, and for as long as any tax or legal obligation requires. These are financial records, so they are not deleted on request. |
| Security and sign-in logs | Up to 12 months, then deleted. |
| Explore moderation decisions and reports | Retained after removal, so a decision remains reviewable. |
| Support correspondence | Up to 24 months after the matter is closed. |
Your rights and how to use them
You have rights over your personal data, and much of it you can exercise yourself without asking us.
Directly in the app
- See your data: your media library, your generation history, and every credit movement in Settings → Usage.
- Correct your details: name and avatar in Settings → Profile.
- Delete content: remove any asset, project or cloned voice from your library.
- Unpublish anything on Explore.
- Cancel your subscription in Settings → Subscription.
By writing to us
Write to support@vbnstudio.ai from the address registered to the account to:
- Access: get a copy of the personal data we hold about you.
- Correct or complete anything inaccurate.
- Erase your account and its data, subject to the financial records we are legally required to retain.
- Object to, or restrict, processing based on legitimate interests.
- Port your data: receive it in a structured, machine-readable format, or have it sent to another provider where that is technically feasible.
- Withdraw consent at any time. Withdrawal does not affect processing already carried out, and withdrawing consent necessary to run the Service means closing the account.
- Ask us anything about what we hold and why, if the list above does not answer it.
We will get back to you as quickly as we can, and we aim to deal with any request within 30 days. We may ask you to confirm control of the account's email address first: it is the only identity check we have, and it is what protects your data from somebody asking for it in your name.
How we protect it
- Everything is encrypted in transit (TLS) and at rest in our databases and object storage.
- There is no password to steal. Sign-in is a one-time code, and sign-in attempts are rate-limited.
- Every request is authorised on the server. Each endpoint resolves who is asking and checks entitlement before touching data; the interface is never the security boundary.
- Media is served by short-lived signed links, so a URL that leaks stops working.
- Payment credentials never enter our systems at all.
- Administrative actions are logged, including who did what to which account.
- Access is least-privilege, and production secrets are held in the platform's secret store rather than in the codebase.
No system is perfectly secure, and we are not going to claim otherwise. If a breach happens that is likely to affect you, we will tell you what happened, what it touched and what to do about it, and we will tell any regulator we are required to tell.
Cookies and local storage
We use the minimum necessary, and no advertising or cross-site tracking cookies.
| What | Why |
|---|---|
| Session cookie | Keeps you signed in. Strictly necessary: the Service cannot work without it. |
| Browser local storage | Remembers interface preferences such as your last tool, tile size and draft prompts, on your device only. |
| Dodo Payments' checkout cookies | Set by Dodo Payments on its own checkout page during a purchase, to run the checkout and prevent fraud. |
Clearing your browser storage signs you out and resets preferences; it does not affect your account or your media.
Where your data goes
The Service runs on globally distributed infrastructure, and the providers listed above are based in several countries, including the United States, the United Kingdom, the European Union and the Asia-Pacific region. Your personal data is therefore stored and processed outside India, and outside whichever country you are in.
Each provider processes it under its own terms and its own privacy commitments, which are linked from their sites. If you are not comfortable with your data being processed abroad, VBN Studio is not the right tool for you: there is no configuration that keeps it in one country.
Children
VBN Studio is for adults. You must be 18 or older to use it, and we do not knowingly collect personal data from children.
Handling a child's data properly means parental consent and a set of protections we are not set up to provide, so we do not offer the Service to children at all. If we learn that an account belongs to somebody under 18, we close it and delete the data. If you believe a child has given us personal data, write to support@vbnstudio.ai and we will remove it.
Changes to this policy
We may update this policy as the Service changes or the law does. The current version is always on this page, with its effective date at the top.
Where a change materially affects how we handle your data, we will tell you by email to the address on your account, or by a notice in the Service, before it takes effect.
Contact
For anything in this policy, to exercise one of the rights above, or to complain about how we have handled your data, write to support@vbnstudio.ai from the address on your account. Questions about a charge go to billing@vbnstudio.ai; anything else to hello@vbnstudio.ai.
If we get something wrong, tell us and give us a chance to fix it: we would much rather hear it from you directly. You also keep whatever right you have to complain to the data-protection authority where you live.
Related: the Terms of Service govern your use of VBN Studio, and the Refund Policy governs payments.