Legal Document

Privacy Policy

Learn how Vidla AI collects, uses, and protects your personal information

Last updated:
Legal Document

Privacy Policy

Last Updated: February 14, 2026

Introduction

Welcome to Vidla AI ("we," "our," "us," or the "Company"), operated by Vidla AI. We are committed to protecting the privacy and security of your personal information. This Privacy Policy describes how we collect, use, disclose, retain, and safeguard your information when you access or use our AI-powered video generation platform, including our website at vidla.ai, our Brand Studio tools, and all related services (collectively, the "Service").

This Privacy Policy applies to all users of the Service, including registered users, guest users, and website visitors. By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this policy. If you do not agree with our policies and practices, do not use our Service.

We encourage you to read this Privacy Policy carefully and revisit it periodically, as we may update it from time to time. Material changes will be communicated as described in the "Changes to This Privacy Policy" section below.

Contact Information

For privacy-related inquiries, data requests, or complaints, please contact us at:

  • Email: privacy@vidla.ai
  • Data Protection Officer: dpo@vidla.ai (for GDPR-related inquiries)

For general support inquiries, visit our Contact Page.

Data We Collect

We collect several categories of personal information depending on how you interact with our Service. The categories below describe what we collect, the sources of such data, and the purposes for which it is used.

Information You Provide Directly

Account Information: When you create an account using Google Sign-In or Google One Tap, we receive and store:

  • Full name (display name from your Google account)
  • Email address
  • Profile picture URL (from your Google account)
  • Google account unique identifier (UID)
  • Account creation date

AI Video Generation Content: When you use our video generation features, we collect and process:

  • Text prompts, scripts, and descriptions you provide
  • Reference images and frames you upload (including base64-encoded image data)
  • Video files you upload for extension or editing
  • Generation parameters, style preferences, and configuration settings
  • Generated video output files

Brand Studio Data: When you use Brand Studio, we collect:

  • Brand kit information (brand name, colors, fonts, logo files, brand voice keywords)
  • Script templates and storyboard configurations
  • Brand compliance preferences and guidelines
  • Export settings and multi-platform format preferences (e.g., TikTok, Instagram, YouTube, LinkedIn)

Voice and Audio Data: When you use our voiceover and voice cloning features, we collect:

  • Audio samples you upload for voice cloning (minimum 30 seconds of audio)
  • Voice selection preferences and settings
  • Generated voiceover audio files

Payment Information: When you subscribe to a paid plan, we collect:

  • Email address for billing communications
  • Subscription tier and plan selection
  • Country or region (detected automatically for payment gateway selection)
  • We do NOT directly store your credit card numbers, bank account details, or full payment card data—this is handled securely by our payment processors (Stripe and Razorpay)

Contact and Communication Data: When you contact us or submit forms, we collect:

  • Your name and email address
  • Subject line and message content
  • Any attachments you provide
  • Your IP address (for rate limiting and abuse prevention)

Newsletter Subscription: When you subscribe to our newsletter, we collect:

  • Your email address
  • Subscription date and preferences

Information We Collect Automatically

Usage and Interaction Data: We automatically collect information about how you use the Service, including:

  • Pages visited, features used, and actions taken
  • Time spent on pages and across sessions
  • Scroll depth, click patterns, and form interactions
  • Video generation history, job status, and processing metrics
  • CTA interactions, download activity, and tutorial progress
  • Blog article ratings and content engagement metrics

Device and Technical Data: We collect:

  • Browser type, version, and language
  • Operating system and version
  • Device type (desktop, mobile, tablet) and screen resolution
  • IP address (anonymized for analytics; full IP used for rate limiting and country detection)
  • Referring URL and landing page

Location-Related Data: We infer your approximate location using:

  • IP address geolocation (via ipapi.co) for payment gateway selection (Stripe vs. Razorpay)
  • Browser timezone and locale settings for regional compliance detection (EU/California)
  • We do NOT collect precise GPS geolocation

Job Queue and Processing Data: When you submit video generation jobs, we collect:

  • Job metadata (status, timestamps, retry count, error messages)
  • Processing duration and resource usage metrics
  • Credit transaction records (type, amount, balance, reason)

Cookies and Similar Technologies

We use cookies, local storage, and session storage to provide and improve the Service. Our cookie usage falls into the following categories:

Essential (Always Active):

  • Authentication state and session management
  • Security tokens (CSRF protection)
  • Cookie consent preferences

Analytics (Opt-In):

  • Google Analytics 4 cookies for usage metrics
  • Page view session tracking (stored in sessionStorage)
  • Download statistics (stored in localStorage)

Marketing (Opt-In):

  • Currently, we do not use marketing cookies for advertising purposes
  • Ad personalization signals are disabled in our analytics configuration

Preference Cookies:

  • Cookie consent version and selections
  • Analytics and Clarity opt-out flags
  • Newsletter rate limiting data

You can manage your cookie preferences at any time through our Cookie Settings banner, accessible via the footer of our website. For more information on controlling cookies, see the "Cookie Management" section below.

Local Browser Storage

We store the following data locally in your browser:

  • Cookie consent preferences (your selected cookie categories and consent version)
  • Guest video data (base64-encoded video stored in localStorage; auto-expires after 24 hours)
  • Newsletter rate limiting (tracking submission frequency to prevent abuse)
  • Download statistics (aggregate download counts)
  • Analytics session data (page views per session, page engagement time; stored in sessionStorage and cleared when the browser tab closes)
  • Clarity opt-out preference (if you choose to opt out of session recording)

How We Use Your Data

We use the information we collect for the following purposes, each with a corresponding legal basis under applicable data protection laws:

Service Delivery and Operations

  • Account Management: Creating, maintaining, and authenticating your account (Legal Basis: Contract)
  • AI Video Generation: Processing your prompts, images, and parameters through Google Gemini/Veo AI models to generate video content (Legal Basis: Contract)
  • Brand Studio Pipeline: Orchestrating multi-stage AI workflows including script generation, storyboard creation, voiceover synthesis, background music generation, and video composition (Legal Basis: Contract)
  • Voice Cloning and Synthesis: Processing your uploaded audio samples through ElevenLabs to create custom voice profiles and generate voiceovers (Legal Basis: Contract with Consent)
  • Storage and Retrieval: Saving your generated videos, brand kits, voice clones, and project history in Firebase Cloud Storage and Firestore (Legal Basis: Contract)
  • Credit and Subscription Management: Tracking your credit balance, processing transactions, enforcing usage quotas, and managing subscription lifecycle (Legal Basis: Contract)
  • Multi-Platform Export: Converting and formatting your videos for specific platforms such as TikTok, Instagram Reels, YouTube, and LinkedIn (Legal Basis: Contract)

Payment Processing

  • Transaction Processing: Facilitating subscription payments through Stripe (for global/US/EU users) or Razorpay (for India and South Asian users including Bangladesh, Nepal, Sri Lanka, Bhutan, and Maldives) (Legal Basis: Contract)
  • Gateway Selection: Automatically detecting your country via timezone, locale, and IP geolocation to route payments to the appropriate processor (Legal Basis: Legitimate Interest)
  • Billing Communications: Sending payment confirmations, subscription changes, failed payment notifications, and credit alerts via SendGrid email (Legal Basis: Contract)

Service Improvement and Analytics

  • Usage Analytics: Understanding how users interact with our Service using Google Analytics 4, with IP anonymization enabled and ad personalization disabled (Legal Basis: Consent via Cookie Settings)
  • Session Recording and Heatmaps: Using Microsoft Clarity to record user sessions and generate heatmaps for UX improvement, subject to your consent and opt-out preferences (Legal Basis: Consent)
  • Performance Monitoring: Identifying and resolving technical issues, optimizing load times, and improving reliability (Legal Basis: Legitimate Interest)
  • Feature Development: Analyzing aggregate usage patterns to prioritize and develop new features (Legal Basis: Legitimate Interest)

Communication

  • Transactional Emails: Sending support ticket confirmations, auto-replies, credit warnings, subscription status updates, and payment receipts via SendGrid (Legal Basis: Contract)
  • Newsletter: Sending product updates, feature announcements, and tips to subscribers who have opted in (Legal Basis: Consent)
  • Support Responses: Responding to your inquiries submitted through our contact form (Legal Basis: Contract/Legitimate Interest)

Security and Fraud Prevention

  • Bot Protection: Using Google reCAPTCHA v3 to detect and prevent automated abuse on forms (Legal Basis: Legitimate Interest)
  • Rate Limiting: Enforcing per-user and per-IP rate limits to prevent abuse of our Service (Legal Basis: Legitimate Interest)
  • Honeypot Detection: Using hidden form fields to detect and reject automated bot submissions (Legal Basis: Legitimate Interest)
  • Input Sanitization: Scanning user prompts for malicious patterns before processing (Legal Basis: Legitimate Interest)
  • Audit Logging: Recording significant account and system events for security investigation and compliance (Legal Basis: Legitimate Interest/Legal Obligation)
  • Legal Obligations: Complying with applicable laws, regulations, and legal processes (Legal Basis: Legal Obligation)
  • Terms Enforcement: Enforcing our Terms of Service and other agreements (Legal Basis: Legitimate Interest)
  • GDPR/CCPA Requests: Processing data access, portability, deletion, and opt-out requests (Legal Basis: Legal Obligation)

How We Store Your Data

Data Storage Infrastructure

Your data is stored using Google Firebase services (Cloud Firestore, Firebase Authentication, and Firebase Cloud Storage), hosted on Google Cloud Platform infrastructure. Firebase may replicate data across multiple geographic regions for redundancy and performance. Firebase provides enterprise-grade security, high availability, and compliance certifications including SOC 1, SOC 2, SOC 3, and ISO 27001.

Data Retention Periods

We retain your data only as long as necessary for the purposes described in this policy or as required by law:

  • User Profile and Account Data: Retained while your account is active and for 30 days after account deletion request (recovery window)
  • Generated Videos and Media: Retained until you delete them or your account is deleted; subject to a 30-day soft-delete recovery window
  • Brand Kits and Projects: Retained while your account is active
  • Voice Clone Data: Retained while your account is active; deleted upon account deletion
  • Credit Transactions: Retained indefinitely as financial records for audit and compliance purposes
  • Job Queue Records: Automatically deleted 7 days after job completion or failure
  • Usage Logs and Metrics: Retained for up to 90 days
  • Audit Logs: Retained indefinitely for security and compliance purposes
  • Contact Form Submissions: Retained until manually reviewed and resolved by our support team
  • Webhook and Payment Logs: Retained indefinitely for financial reconciliation and dispute resolution
  • Guest User Video Data: Stored locally in your browser for 24 hours only, then automatically cleared
  • Newsletter Subscriptions: Retained until you unsubscribe
  • Cookie Consent Records: Retained until you clear them or reset via Cookie Settings

Data Security Measures

We implement comprehensive security measures to protect your information:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS enforced)
  • Encryption at Rest: Data stored in Firebase is encrypted at rest using Google-managed encryption keys
  • Access Controls: Strict Firestore security rules limit data access—users can only access their own data; administrative access requires verified admin privileges
  • Authentication Security: Secure authentication via Google Sign-In with token refresh management and session cleanup on sign-out
  • HTTP Security Headers: We deploy industry-standard security headers including X-Frame-Options (DENY), X-Content-Type-Options (nosniff), X-XSS-Protection, Referrer-Policy (strict-origin-when-cross-origin), and restrictive Permissions-Policy
  • Content Security Policy: A comprehensive CSP restricts script sources, style sources, and connection endpoints to prevent cross-site scripting (XSS) and data injection attacks
  • Rate Limiting: Per-user and per-IP rate limiting protects against brute-force attacks and abuse
  • CSRF Protection: Cross-site request forgery tokens protect form submissions
  • Input Validation: All user inputs including AI prompts are validated and sanitized before processing
  • Regular Monitoring: Continuous monitoring for security threats and anomalies
  • Webhook Idempotency: Payment webhooks are deduplicated to prevent duplicate processing

How We Share Your Data

We do not sell, rent, or trade your personal information to third parties. We share your data only with the following categories of service providers, and only to the extent necessary to operate and improve the Service:

AI and Video Processing Providers

Google AI (Gemini / Veo 3.1): Your text prompts, reference images, and video frames are sent to Google's generative AI models for video generation, script writing, and storyboard creation.

Google Lyria RealTime: Music genre preferences and mood parameters are sent to Google's Lyria model for AI background music generation.

ElevenLabs: Script text is sent for voiceover synthesis; audio samples are transmitted for voice cloning.

  • ElevenLabs Privacy Policy
  • Audio samples used for voice cloning are processed to create a custom voice model associated with your account

Infrastructure and Platform Providers

Google Firebase (Authentication, Firestore, Cloud Storage, Hosting, Analytics): All core platform data including your account profile, videos, projects, and usage metrics is stored and processed using Firebase services.

Payment Processors

Stripe: If you are located outside of India/South Asia, your payment is processed through Stripe. We share your email address and subscription details with Stripe. Stripe securely handles your credit card and payment information directly—we do not store it.

Razorpay: If you are located in India, Bangladesh, Nepal, Sri Lanka, Bhutan, or Maldives, your payment is processed through Razorpay. We share your email address and subscription details with Razorpay. Razorpay securely handles your payment information directly—we do not store it.

Analytics and User Experience Providers

Google Analytics 4: We use GA4 to collect anonymized usage data. IP anonymization is enabled, ad personalization signals are disabled, and Google Signals are disabled.

Microsoft Clarity: We use Clarity for session recording and heatmap analysis to understand how users interact with our interface. You can opt out at any time.

Communication Providers

SendGrid (Twilio): We use SendGrid to deliver transactional emails including contact form auto-replies, credit alerts, payment notifications, and subscription confirmations. Your email address and notification content are shared with SendGrid for delivery.

Security and Anti-Abuse Providers

Google reCAPTCHA v3: We use reCAPTCHA on forms (contact, newsletter) to distinguish human users from bots. reCAPTCHA may collect device information, browser data, and IP address.

ipapi.co: We use ipapi.co to look up your approximate country based on your IP address, solely for the purpose of selecting the appropriate payment gateway. Your IP address is transmitted to ipapi.co for this lookup.

Other Third Parties

Google Fonts: We load fonts (Audiowide, Raleway) from Google Fonts. Font requests may transmit your IP address to Google.

We may disclose your information if required by law or in good faith belief that such action is necessary to:

  • Comply with a court order, subpoena, or legal process
  • Respond to lawful requests from government authorities
  • Protect and defend our rights, property, or safety
  • Investigate potential violations of our Terms of Service
  • Detect, prevent, or address fraud, security issues, or technical problems
  • Protect the rights, property, or personal safety of our users or the public

Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred to the acquiring entity. We will provide notice before your personal information becomes subject to a different privacy policy and, where required by law, seek your consent.

Your Rights and Choices

Access and Data Portability

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Portability: Receive your data in a structured, commonly used, machine-readable format (JSON export available through your account settings or by request)
  • Correction: Request updates or corrections to inaccurate personal information

Our platform supports in-app data export, which includes your profile information, generated videos and metadata, credit transaction history, and contact submissions.

To exercise these rights, use the data export feature in your account settings or email us at privacy@vidla.ai.

Deletion and Account Closure

You have the right to request deletion of your personal data:

  • Account Deletion: You may request deletion of your account. Account deletion is scheduled with a 30-day grace period during which you can cancel the request and recover your data.
  • Permanent Deletion: After the 30-day recovery window, all associated data is permanently deleted, including your profile, generated videos, stored media files in Cloud Storage, brand kits, voice clones, and authentication credentials.
  • Individual Content Deletion: You may delete specific videos, brand kits, or projects at any time through your account dashboard. Deleted content enters a 30-day soft-delete recovery period before permanent removal.
  • Data Erasure Request: You may submit a formal data erasure request, which will be logged in our system and processed in accordance with applicable law.

Note: Certain data may be retained after deletion where required by law, including financial transaction records (credit transactions, payment logs) and audit logs maintained for legal compliance purposes.

Opt-Out Rights

You can opt out of:

  • Analytics Tracking: Disable analytics cookies via our Cookie Settings banner or enable the "Do Not Track" signal in your browser (we honor DNT signals)
  • Session Recording: Opt out of Microsoft Clarity session recording via Cookie Settings
  • Newsletter Communications: Unsubscribe via the link in any newsletter email, or contact us at privacy@vidla.ai
  • Email Notifications: Manage your email preferences through your account settings

You can control cookies and local storage through:

  • Our Cookie Settings: Click "Cookie Settings" in the website footer to manage your consent preferences at any time
  • Browser Settings: Configure your browser to block or delete cookies
  • Do Not Track: We respect the DNT browser signal—when enabled, we suppress analytics and session recording
  • Third-Party Opt-Out Tools: Use the Google Analytics Opt-Out Add-On or browser extensions to manage third-party tracking

Note: Disabling essential cookies may impair core functionality such as authentication and security.

GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local laws.

Data Controller

Vidla AI is the data controller responsible for your personal data. Our contact details are provided at the top of this policy.

We process your personal data on the following legal bases:

  • Performance of Contract (Article 6(1)(b)): Processing necessary to provide the Service you have requested, including account creation, video generation, subscription management, and content storage
  • Consent (Article 6(1)(a)): Processing based on your explicit opt-in consent, including analytics cookies, session recording, newsletter subscriptions, and voice cloning (audio sample processing)
  • Legitimate Interest (Article 6(1)(f)): Processing necessary for our legitimate business interests, including service improvement, security and fraud prevention, rate limiting, and platform analytics (where consent is not required). We have conducted balancing tests to ensure our interests do not override your fundamental rights.
  • Legal Obligation (Article 6(1)(c)): Processing required to comply with applicable laws, such as maintaining financial records and responding to legal requests

Your GDPR Rights

In addition to the rights described above, you have:

  • Right to Object (Article 21): Object to processing based on legitimate interests at any time
  • Right to Restriction (Article 18): Request that we restrict processing of your data in certain circumstances
  • Right to Withdraw Consent (Article 7(3)): Withdraw your consent at any time for consent-based processing, without affecting the lawfulness of processing prior to withdrawal
  • Right to Lodge a Complaint: File a complaint with your local data protection supervisory authority
  • Right to Erasure (Article 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements
  • Right Not to Be Subject to Automated Decision-Making (Article 22): We do not make automated decisions with legal or similarly significant effects based solely on automated processing of your personal data

Data Protection Officer

For GDPR-related inquiries or to exercise your data protection rights, contact our Data Protection Officer at: dpo@vidla.ai

International Data Transfers

Your data may be transferred to and processed in countries outside the EEA/UK, including the United States (where Google Cloud and other service providers operate). We ensure appropriate safeguards are in place for such transfers, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where available
  • Binding Corporate Rules of our service providers (e.g., Google)
  • Other legally approved transfer mechanisms under GDPR Chapter V

You may request a copy of the relevant transfer safeguards by contacting our Data Protection Officer.

CCPA/CPRA Compliance (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Categories of Personal Information Collected

We have collected the following categories of personal information within the preceding 12 months:

  • Identifiers: Name, email address, Google account ID, IP address, unique device identifiers
  • Commercial Information: Subscription tier, purchase history, credit balance, payment gateway used
  • Internet or Electronic Network Activity: Browsing history, pages visited, search queries, interactions with our Service, referral URLs
  • Geolocation Data: Approximate location derived from IP address (not precise GPS)
  • Audio, Electronic, and Visual Information: Videos you generate, images you upload, audio samples for voice cloning, voiceover recordings
  • Professional Information: Brand kit information (if brand-related content is provided)
  • Inferences: Usage preferences and patterns derived from your activity on the Service
  • Sensitive Personal Information: We do not intentionally collect sensitive personal information as defined under the CPRA (e.g., Social Security numbers, precise geolocation, racial/ethnic origin, health data)

Sources of Personal Information

  • Directly from you (account creation, content uploads, form submissions)
  • Automatically from your device and browser (usage data, cookies)
  • From third-party services (Google Sign-In, payment processors)
  • From IP geolocation providers (approximate country only)

Business Purposes for Collection

We collect and use personal information for the business purposes described in the "How We Use Your Data" section of this policy, including service delivery, payment processing, analytics, security, and legal compliance.

Your CCPA/CPRA Rights

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources, business purposes, and categories of third parties with whom we share it
  • Right to Delete: Request deletion of your personal information, subject to legal exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do NOT sell your personal information, and we do NOT share your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond what is necessary to provide the Service
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights

How to Exercise Your Rights

To exercise your CCPA/CPRA rights:

  1. Email us at privacy@vidla.ai with the subject line "CCPA Request"
  2. We will verify your identity using information associated with your account
  3. Specify which right(s) you wish to exercise

We will acknowledge your request within 10 business days and respond substantively within 45 days. If we need additional time, we will notify you of the extension (up to 90 days total).

You may designate an authorized agent to make a request on your behalf. We may require the agent to provide proof of authorization and may verify your identity directly.

Do Not Sell or Share My Personal Information

We do not sell personal information to third parties. We do not share personal information for cross-context behavioral advertising. No opt-out is necessary, but you may still submit a request for our records.

Financial Incentives

We do not offer financial incentives or price differences in exchange for the retention or sale of personal information.

Other Applicable Privacy Laws

Virginia Consumer Data Protection Act (VCDPA)

Virginia residents have rights to access, correct, delete, and obtain a copy of their personal data, as well as the right to opt out of targeted advertising, sale of personal data, and profiling. We do not engage in the sale of personal data or profiling for decisions with legal or similarly significant effects.

Colorado Privacy Act (CPA) and Connecticut Data Privacy Act (CTDPA)

Residents of Colorado and Connecticut have similar rights to those described under the CCPA/CPRA section. To exercise these rights, contact us at privacy@vidla.ai.

Brazil General Data Protection Law (LGPD)

If you are located in Brazil, you have rights under the LGPD including confirmation of data processing, access to your data, correction, anonymization, portability, deletion, and information about data sharing. Contact us at privacy@vidla.ai to exercise these rights.

AI-Specific Disclosures

How AI Processes Your Data

Our Service uses artificial intelligence to generate video content. When you submit a prompt or upload content:

  1. Text prompts and parameters are sent to Google Gemini AI for script generation, storyboard planning, and video generation via the Veo 3.1 model
  2. Reference images and video frames (encoded in base64) may be sent to Google Gemini for visual context and style reference
  3. Video buffers may be uploaded to Google's Gemini File API for video extension features
  4. Script text is sent to ElevenLabs for voiceover synthesis
  5. Audio samples are sent to ElevenLabs for voice cloning model creation
  6. Music parameters (genre, mood, duration) are sent to Google Lyria RealTime for background music generation

Data Processing by AI Providers

  • We do not use your content to train our own AI models
  • Google processes AI requests under their enterprise data processing terms. Refer to Google's Generative AI Terms for specifics on how Google handles data submitted to their AI services
  • ElevenLabs processes voice data under their privacy policy. Voice clone models are associated with your account and deleted upon account deletion
  • AI-generated outputs (videos, scripts, voiceovers, music) are stored in your account and are not shared with other users unless you explicitly choose to share them

Content Safety and Moderation

  • User prompts are scanned for potentially malicious or harmful patterns before being processed by AI models
  • Brand compliance checks verify that generated content adheres to your brand kit guidelines (colors, fonts, voice, logos)
  • We reserve the right to refuse processing requests that violate our Terms of Service or content policies

Children's Privacy

Vidla AI is not directed at and is not intended for use by children under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children under these age thresholds.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at privacy@vidla.ai. We will take steps to verify the claim and delete the child's personal information promptly.

If we become aware that we have inadvertently collected personal information from a child under the applicable age threshold, we will delete that information as soon as practicable.

Do Not Track Signals

Our Service respects the "Do Not Track" (DNT) browser signal. When we detect that your browser has DNT enabled:

  • We suppress Google Analytics tracking
  • We disable Microsoft Clarity session recording
  • We limit data collection to what is strictly necessary for service operation (essential cookies and authentication only)

Our Service may contain links to third-party websites, services, or embedded content (such as YouTube videos). We are not responsible for the privacy practices, content, or security of these third-party services.

We encourage you to review the privacy policies of any third-party service before providing personal information. Clicking a link to a third-party site or interacting with embedded content may allow that third party to collect data about you.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify affected users without undue delay and, where feasible, within 72 hours of becoming aware of the breach
  • Provide details about the nature of the breach, the categories of data affected, and the approximate number of individuals impacted
  • Describe the measures we have taken or propose to take to address the breach and mitigate its effects
  • Advise you on steps you can take to protect yourself
  • Notify the relevant supervisory authority (for GDPR-covered breaches) and other regulatory bodies as required by applicable law

We maintain an incident response plan and conduct periodic security reviews to minimize the risk and impact of data breaches.

Automated Decision-Making

We do not use your personal data for automated decision-making that produces legal effects or similarly significantly affects you. Credit and subscription management is based on your selected plan and usage, not on profiling.

AI video generation is an automated process initiated at your request and does not constitute automated decision-making under GDPR Article 22.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable laws. We will update the "Last Updated" date at the top of this policy.

For Material Changes, we will:

  • Provide prominent notice on our website (e.g., a banner or notification)
  • Notify you via email if you have an account with us
  • Where required by applicable law, seek your affirmative consent before implementing the change
  • Update the cookie consent version, which will prompt a new consent request

Your Continued Use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should discontinue use of the Service and may request deletion of your account and data.

By using Vidla AI, you consent to:

  • Collection and use of your information as described in this policy
  • Use of cookies and similar technologies (subject to your cookie preferences)
  • Transfer of your data to the service providers listed in this policy
  • Processing of your content by AI services for video generation
  • International transfer of your data with appropriate safeguards

You can withdraw your consent at any time by:

  • Adjusting your cookie preferences via Cookie Settings
  • Unsubscribing from our newsletter
  • Deleting your account
  • Contacting us at privacy@vidla.ai

Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal.

reCAPTCHA Disclosure

This site is protected by Google reCAPTCHA v3 and the Google Privacy Policy and Terms of Service apply.

reCAPTCHA is used to protect our contact form, newsletter signup, and other interactive features from spam and abuse. reCAPTCHA operates invisibly (no user interaction required) and may collect hardware and software information, such as device and application data, and send it to Google for analysis. This data is used to determine whether you are a human user and is processed in accordance with Google's Privacy Policy.

Accessibility

This Privacy Policy is available in HTML format on our website with proper heading structure, link labels, and keyboard navigation support. If you require this policy in an alternative format, please contact us at privacy@vidla.ai.

Governing Law

This Privacy Policy is governed by and construed in accordance with applicable data protection laws, including but not limited to the GDPR (for EU/EEA/UK users), the CCPA/CPRA (for California residents), and other applicable local laws. Nothing in this policy limits your rights under mandatory applicable law.

Questions and Concerns

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@vidla.ai
  • Support: Contact Page
  • Data Protection Officer: dpo@vidla.ai (for GDPR and data protection inquiries)

We will acknowledge your inquiry within 5 business days and provide a substantive response within 30 days. If we need additional time, we will notify you.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.


Effective Date: February 14, 2026

This Privacy Policy is part of our Terms of Service.

Questions about this policy?

If you have any questions or concerns about our privacy practices, please don't hesitate to contact us.

Contact Us