Privacy Policy
Effective date: March 17, 2025
1. Introduction
At Kiridot ("we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI video generation platform ("Service").
By using the Service, you consent to the practices described in this policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, username, and password when you register
- Profile Information: Optional details such as display name and profile picture
- Content & Inputs: Scripts, prompts, storyboards, images, and other creative inputs you submit for video generation
- Payment Information: Billing details processed securely through our payment provider (Stripe). We do not store your full credit card number on our servers.
- Communications: Messages you send to our support team, feedback, and survey responses
2.2 Information Collected Automatically
- Usage Data: Features used, actions taken, session duration, and interaction patterns
- Device & Browser Information: Browser type, operating system, screen resolution, device identifiers, and language preferences
- Network Information: IP address, approximate geolocation (city/country level), and referring URLs
- Log Data: Server logs including timestamps, error reports, and API request metadata
2.3 Information from Third Parties
- Authentication Providers: If you sign in via a third-party service (e.g., Google), we receive your name, email, and profile picture as permitted by that provider
- Analytics Partners: Aggregated usage insights from analytics services we use
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process your inputs, generate videos, and deliver the features you request
- Manage Your Account: Authenticate your identity, manage credits and subscriptions, and process payments
- Improve the Service: Analyze usage patterns, diagnose technical issues, and develop new features
- Communicate with You: Send account notifications, security alerts, billing updates, and (with your consent) product news and tips
- Ensure Safety & Security: Detect fraud, enforce our Terms of Service, and protect against abuse
- Legal Compliance: Fulfill legal obligations, respond to lawful requests, and protect our rights
4. AI Processing & Your Content
When you use Kiridot to generate videos, your creative inputs are processed by our AI systems. We want you to understand clearly how your content is handled:
- Purpose-Limited Processing: Your inputs are processed solely to generate your requested outputs (videos, images, audio)
- No Training on Your Content: We do not use your specific creative inputs or generated outputs to train or fine-tune our AI models without your explicit opt-in consent
- Secure Storage: Generated content is stored securely and is accessible only to you and authorized team members within your workspace
- Deletion Rights: You can delete your inputs and generated content at any time. Deleted content is purged from our active systems within 30 days and from backups within 90 days.
- Aggregated Analytics: We may use anonymized, aggregated usage patterns (not your actual content) to improve service quality and performance
5. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share information with:
- Service Providers: Trusted third parties that help us operate the Service, including cloud hosting (e.g., AWS, GCP), payment processing (Stripe), email delivery, and analytics providers. These providers are contractually bound to use your data only as instructed by us.
- Legal Requirements: When required by law, court order, or governmental regulation, or to protect the rights, safety, or property of Kiridot, our users, or the public
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred. We will notify you before your data becomes subject to a different privacy policy.
- With Your Consent: In any other circumstances where you have given explicit consent
6. Cookies & Tracking Technologies
6.1 Types of Cookies We Use
- Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
- Preference Cookies: Remember your settings, such as theme and language preferences
- Analytics Cookies: Help us understand how users interact with the Service so we can improve it. We use privacy- respecting analytics tools.
6.2 Managing Cookies
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of the Service.
6.3 Do Not Track
We currently do not respond to Do Not Track (DNT) browser signals, as there is no industry-wide standard for compliance. We will update this policy if a standard is adopted.
7. Data Security
We implement industry-standard technical and organizational measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Secure cloud infrastructure with SOC 2 compliant hosting providers
- Regular security assessments and penetration testing
- Role-based access controls limiting internal data access to authorized personnel
- Automated monitoring and incident response procedures
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to [email protected].
8. Data Retention
- Account Data: Retained for as long as your account is active, plus a reasonable period for legal and operational purposes after deletion
- Generated Content: Stored for up to 90 days after creation unless you delete it sooner. Active subscription users may have extended retention as part of their plan.
- Payment Records: Retained as required by tax and financial regulations (typically 7 years)
- Usage Logs: Retained in anonymized form for analytics; identifiable logs are purged within 12 months
You may request deletion of your account and associated data at any time by contacting [email protected].
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
9.1 All Users
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and personal data
- Data Portability: Request an export of your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing communications at any time
9.2 European Economic Area (GDPR)
If you are in the EEA, you additionally have the right to:
- Object to or restrict processing of your personal data
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with your local data protection authority
Our legal bases for processing include: contract performance (providing the Service), legitimate interests (improving and securing the Service), consent (marketing communications), and legal obligations.
9.3 California Residents (CCPA/CPRA)
California residents have the right to:
- Know what personal information is collected, used, and shared
- Request deletion of personal information
- Opt out of the sale or sharing of personal information
- Non-discrimination for exercising your privacy rights
We do not sell personal information as defined by the CCPA/CPRA.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or as required by applicable law).
10. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Compliance with applicable data transfer frameworks
11. Children's Privacy
The Service is not intended for children under 13 years of age (or the minimum age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected information from a child under the applicable age, we will delete it promptly. If you believe a child has provided us with personal information, please contact [email protected].
12. Third-Party Links & Services
The Service may contain links to third-party websites or services that are not owned or controlled by Kiridot. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes, we will:
- Update the "Effective date" at the top of this page
- Notify you via email or an in-app notice at least 30 days before the changes take effect
- Provide a summary of key changes where appropriate
Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Privacy inquiries: [email protected]
- Security issues: [email protected]
- General support: [email protected]